Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

Browse the Community

Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

2653 Posts

Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

1309 Posts

Cortex Xpanse Discussions

Cortex Xpanse builds a system of record that is the authoritative source for an organization’s global Internet assets; it knows your attack surface so you can own it before someone else.

10 Posts

Cortex XSIAM Discussions

Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

181 Posts

Cortex Cloud Discussions

Share ideas and post questions related to Cortex Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.

479 Posts

Activity in Security Operations

XDR Alert Dump – Finding the File That Triggered the Alert

I have a question. When we perform a Dump Alert and get the ZIP file, how can we analyze it in more detail? For example, if I want to see the .ps1 file that a particular user executed on the machine and that triggered the alert, would that file be included in the dump? I’ve already searched everywhere, but I can’t find it. I can see a folder cal...

tlmarques by L4 Transporter
  • 58 Views
  • 1 replies
  • 0 Likes

Low Incident

We have integrated Cortex XDR with Elastic SIEM. Our SOC process currently creates a ticket for every Cortex XDR incident/case, including Low, Medium, and High severity incidents. Is Palo Alto's recommended best practice to create tickets for all Low severity incidents, or should Low severity alerts/incidents be monitored and correlated before t...

Create an issue when FIM events detected

Hello experts, We plan to get the FIM module on top of my XDR. Having set up with FIM Profile and Policy, we could be able to see those events successfully. with the following information: 2. Dataset and Presets for FIM Dataset: xdr_data XQL Filter:dataset = xdr_data | filter fim_event = true Console: Inventory → Endpoints → File Integrity...

Resolved! XSIAM HTTP Log Collector Testing

Hello everyone, We are currently considering to us a HTTP Log Collector. However, before this can be started, I wanted to test the collection. Now, in theory, this should not be hard, due to the examples provided after setting up the integration. Nonetheless, either the Python Example is faulty in some way, or I am being exceedingly stupi...

XDR agent reboot recover everytime

Hi guys, Recently, we identified several computers running Cortex XDR version 9.2.0.120 with Content Version 2340-38788. After the machines start, connect to the tenant, and receive the latest content/information, they start rebooting approximately every minute. The Windows message displayed is: “You’re about to be signed out”“Reinício agendado...

tlmarques by L4 Transporter
  • 64 Views
  • 0 replies
  • 0 Likes

Non-Persistent VDI – File Collection and Investigation with XDR

Hi everyone, I need some help/advice. I’ve been seeing some cases on non-persistent VDIs where we receive alerts such as “Script Engine Activity - 3121803131”. Basically, the Cortex XDR alert is related to an HTML file hosted on a ShareFile share that I don’t have access to. From what I understand, the HTML file is essentially a web-page templat...

tlmarques by L4 Transporter
  • 37 Views
  • 0 replies
  • 0 Likes

Predicting blocked alerts when switching Malware/Exploit modules from "Report" to "Block"

Hi everyone, We are currently in the process of fine-tuning our Cortex XDR tenant. At the moment, we have several modules within our Malware and Exploit security profiles set to "Report" mode. We are planning to harden our security posture and switch these modules to "Block" mode. However, before making this change, we want to assess the potenti...

Firefox crashes when opening xsiam tenant

Just gauging if just me or anyone having similar issues since a few days now.. suspect after either Windows or FF update recently. Everyone else in FF is fine.. just not XSIAM. Edge works and forced to use it now 😞 When I log into a XSIAM tenant ( i have multiple) via FF, it loads then crashes with following message: 'Gah. Your tab just cras...

PA_nts by L4 Transporter
  • 77 Views
  • 1 replies
  • 0 Likes

Cortex XDR – Automatically Resolve Alerts/Issues as "Known Issue" Using Playbook or Predefined Command

Hello Team, We are using a Cortex XDR tenant and would like to know whether there is a supported way to automatically update an alert/issue resolution to "Known Issue" using a predefined command, automation, or playbook action. Our goal is to avoid manual analyst intervention for alerts that have already been validated as known benign activity a...

Disable legacy automation rules

Hello, Currently in our xdr tenant, many issues have been getting automatically closed by legacy automation rules, rules migrated from XDR v3.x to v5,x. The problem is that these rules have conditions such as, category=Malware and detection method = XDR Agent whichr esults in legitimate security incidents being closed without analyst review. ...

Resolved! Cleanup XDR Endpoints

How can we clean up (delete/remove) the old endpoints that are still registered on Cortex XDR ? Is there any automation available for this, or do we need to remove them manually?

tlmarques by L4 Transporter
  • 158 Views
  • 1 replies
  • 0 Likes

TrendMicro Apex One Alert mapping into XSIAM

Hi All Has anyone done this to date and willing to share their Correlation XQL logic used to map alerts from Apex One into XSIAM? I have done this for a few others already like Crowdstrike, MS Graph API etc but having issues with time to navigate through all the raw log data to determine the required fields to validate and alert on what is requi...

PA_nts by L4 Transporter
  • 119 Views
  • 0 replies
  • 1 Likes

Cortex XDR JDP method instrumentation causing severe Java runtime slowness (agent 9.2.0.120) — follow-up to solved cyjagent crash thread

This is a follow-up to a previously solved thread: Cortex XDR cyjagent.dll injection causes JVM startup crash, where @susekar confirmed the known JDP/JVM conflict (CPATR-38467 / CPATR-18158). Thanks for that confirmation. Since the solution there is already accepted, raising this as a separate topic: we've now observed a second symptom from the ...

XSIAM logs from Palo Alto Firewall using syslog

https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector Why does the official guide only highlight Custom Formats for Traffic, Threat, URL, and File data logs? What about other NG...