Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

Browse the Community

Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

2635 Posts

Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

1307 Posts

Cortex Xpanse Discussions

Cortex Xpanse builds a system of record that is the authoritative source for an organization’s global Internet assets; it knows your attack surface so you can own it before someone else.

10 Posts

Cortex XSIAM Discussions

Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

175 Posts

Cortex Cloud Discussions

Share ideas and post questions related to Cortex Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.

479 Posts

Activity in Security Operations

Cortex XDR Policy - Executables blocked from removable media

Hi, As the name suggests, we have a policy to block executables from removable storage. While it works great, there are issues arising when a user wants to install drivers for printers, scanners etc. Since as soon as a device is connected for the first time, it gets mounted as a storage drive. Is there a way to allow only such devices to be ad...

Cortex XDR Delayed Global Protect Connection Timing.

We are transitioning from MDE to Cortex XDR and a number of users have stated that connection time takes from 2-10mins to take place after a full reboot / cold start.This is inconsistent.MDE is currently in EDR in BlockMode - which was the advice given to be the correct status during transition in that it is in Passive mode on those specific end...

RobKen by L0 Member
  • 58 Views
  • 1 replies
  • 0 Likes

Long Running Integration

Is it possible in xsiam to make a custom data collection integration use the long running integration option (https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Developer-Guide/Long-Running-Containers) or is that only available for integrations that palo alto networks provides? Is this an effective way to get over the 10min doc...

Resolved! Indicator Extraction Refresh

We're migrating from playbook task enrichment per incident to auto-extraction leveraging the TIM. One such example is a playbook !extractIndicators text=${incident.sourceip} auto-extract=inline Alternatively, I've also tried configuring the incident type to extract IP-recognized indicators automatically on Source IP field. Both options work fi...

Kevin-C1 by L0 Member
  • 141 Views
  • 2 replies
  • 0 Likes

Trial Access for Cortex XDR

We're working on integrating Cortex XDR login with our system and would like to test the access management/SSO integration before rolling it out further. Could you let us know: Whether a trial version of Cortex XDR is available that we could use for integration testing, and If not, what alternative options exist for testing the access managemen...

antons by L1 Bithead
  • 140 Views
  • 5 replies
  • 0 Likes

Multiple Cortex XDR Agent Upgrades Failing with "The installer has timed out" Error

Hi team, We are currently encountering a mass upgrade failure across multiple endpoints during both Auto Upgrade and Manual Server Upgrade attempts. While a single endpoint successfully upgraded using our standard profile and group configuration, the remaining endpoints consistently fail. Issue Summary: Symptom: The upgrade tasks transition to...

Z.Zikri by L0 Member
  • 133 Views
  • 0 replies
  • 0 Likes

Broker-VM Upgrade to Debian pre-feb 2026 Deployments

Has anyone done this to date? Eventhough we are running version 31.0.58 (latest at the current time) is there an easy way to determine if running Ubuntu without having to Live terminal to the BVM? (waiting on client to open 'https://lrc-<region>.paloaltonetworks.com' to enable live terminal access) https://docs-cortex.paloaltonetworks.co...

PA_nts by L4 Transporter
  • 167 Views
  • 1 replies
  • 0 Likes

Resolved! XSIAM Report

What do “Restricted” and “Public” actually mean in an XSIAM report template? If I set the report template I created to “Restricted,” does that mean I won’t be able to schedule the report to be sent to an external email address, and that it will only work when I manually generate it within XSIAM?

Cortex XDR greatly affects C++ build performance

I have a C++ project that I build using Visual Studio 2022. When I build it on a PC with Cortex XDR installed, the build takes more than 3 hours. It looks as if Cortex XDR is analyzing every .obj file generated during the build process. Without Cortex XDR, the same build takes slightly less than 1 hour. The Cortex XDR application and its configu...

How to Query WildFire Malware Prevention Events Not Generated as Issues

Hello We are currently operating approximately 4,800 agents. During the initial deployment, a large number of false positives were generated by WildFire Malware events, so we applied an exception to prevent these events from being generated as Issues. However, we have recently received user reports of cases suspected to be blocked by this policy...

.522643 by L1 Bithead
  • 172 Views
  • 1 replies
  • 0 Likes

I just received this alert "Script Activity - 245655498" with this description "Suspicious script with keywords written in a non-standard way." in Cor

I just received this alert "Powershell Activity - 2390140751 " with this description "Suspicious script with keywords written in a non-standard way." in Cortex multiple times related to PowerShell script execution on a developer machine. The executed scripts were different and I don't know why Cortex is blocking such executions. There is also no...

Resolved! Cortex XSIAM broker vm

Our Cortex XSIAM agents connect to the XSIAM server exclusively via the Broker VM's local agent proxy settings applet, as direct outbound internet/server access is blocked for these endpoints. If we want our agents to auto-upgrade, do we absolutely have to enable and configure the 'Agent Installer and content caching' part of the applet on the B...