Security Operations
Palo Alto Networks delivers industry-first, category-defining technologies by focusing on product development and innovation. Cortex solutions have transformed security operations by continuously bringing new features to market that boost security efficacy and disrupt the status quo.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Security Operations
Palo Alto Networks delivers industry-first, category-defining technologies by focusing on product development and innovation. Cortex solutions have transformed security operations by continuously bringing new features to market that boost security efficacy and disrupt the status quo.

Browse the Community

Cortex XDR

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all Palo Alto Networks products in one place.

49 Posts

Cortex XSOAR

Cortex XSOAR by Palo Alto Networks enables SOC analysts to manage alerts across all sources, standardize processes with Cortex XSOAR playbooks, take action on threat intel, and automate response for any security use case.

44 Posts

Cortex Xpanse

Welcome to the Cortex Xpanse LIVEcommunity! Explore how-to guides, best practices, and on-demand videos to help you get the most out of Cortex Xpanse. Have questions or insights to share? Join the conversation in our Discussions forums and connect with our Product Experts. Stay in the loop—subscribe now to get the latest product updates delivered t...

3 Posts

Cortex XSIAM

Resources for Cortex XSIAM, Palo Alto Networks’ autonomous security platform powering the Modern SOC.

1 Posts

Activity in Security Operations

XSOAR with Generative AI and Retrieval Augmented Generation

Randy Uhrlaub, Cortex XSOAR Customer Success Architect Table Of Content IntroductionRetrieval Augmented GenerationText Search Augmented GenerationAnything LLM XSOAR Content PackCustomer InfrastructureHostedCloud HostedCustomer InfrastructureSetupAnything LLM and XSOARIntegration Instance ConfigurationUse Case DevelopmentWorkspace and Docume...

image3.jpg
image4.jpg
image7.jpg
image9.jpg
RPrasadi by L4 Transporter
  • 7172 Views
  • 1 replies
  • 2 Likes

Cortex XDR and XSIAM Postman API Collection

What is Postman? Postman is the collaboration platform for API development. Postman simplifies each step of building an API and streamlines collaboration so you can create better APIs faster, you can download the postman community edition now. Why use Postman? Postman is an API client that makes it easy for developers to create, share, test ...

nhussaini_6-1634869207188.jpeg
nhussaini_0-1635298937948.png
nhussaini_1-1635298937853.png
nhussaini_2-1635298937949.png
nhussaini by L4 Transporter
  • 12678 Views
  • 2 replies
  • 6 Likes

Creating Custom Docker Images in XSOAR 8

By Brad Semma, Cortex XSOAR Customer Success Architect When to customize and when not to customize Cortex XSOAR customers love to customize their instances. If a customer decides to customize an integration, they may find the assigned docker image is not configured to handle the additional actions. In events such as these, you may need to ...

image4.png
image2.png
image3.png
image1.png
RPrasadi by L4 Transporter
  • 1716 Views
  • 0 replies
  • 1 Likes

Cortex XDR Customer Success Webinar Series Part 1: Alert Tuning Fundamental

Alert Tuning Fundamentals Watch this Customer Success webinar, where we introduce the Alert Tuning concept and share ample knowledge and best practices. We invite you to register for the second part of this series, where we will demonstrate real-world use cases to help you better understand the Alert Tuning process. You can review the second par...

Alert Tuning Options image (Part 1).png
rtsedaka by L6 Presenter
  • 2771 Views
  • 6 replies
  • 5 Likes

XSOAR 8 Cloud Content Performance Analysis

By Randy Uhrlaub, Customer Success Architect Table Of Content Review DataSettings and InfoGuardrailsSystem DiagnosticsIntegrationsDashboardsIncidentsDashboardsAutomation Performance AnalysisDashboardsPlaybook Performance AnalysisResources Review Data XSOAR has several areas in the console that provide insight into performance of the conf...

unnamed.jpg
unnamed.jpg
unnamed.jpg
unnamed.jpg
RPrasadi by L4 Transporter
  • 1605 Views
  • 0 replies
  • 1 Likes

Troubleshoot XDR Agent Degraded Operational Status with XQL

The Operational Status of your XDR Agents is a crucial aspect to monitor to ensure your environment stays protected. The Operational Status indicates whether the agent is providing protection according to its predefined security policies and profiles. By observing the operational status on the endpoint, you can identify when the agent may suffer...

Graphics Created (1).jpg
bbucao by L3 Networker
  • 9290 Views
  • 6 replies
  • 1 Likes

XSOAR 8 Migration - Everything You Need to Know!

Starting to Plan for XSOAR 8 Migration? It's time to take a deep dive into our Cortex XSOAR 8 Migration Guide! Our team crafted this comprehensive guide to ensure that you're well-prepared for the migration journey ahead. By reviewing the XSOAR 8 migration guide, you'll gain invaluable insights into migration prerequisites, features informa...

rtsedaka by L6 Presenter
  • 6071 Views
  • 2 replies
  • 0 Likes

Cortex XDR - Customer Success Webinar: Endpoint Administration - Part 1

Endpoint Administration Webinar Part 1 This webinar covers the Cortex XDR agent-related administrative tasks from installations, architecture, common issues, and our pro tips! Watch the video and use the resources that were shared during the webinar, listed below: Resources: Adding proxy list during the installation: msiexec /i c:\instal...

rtsedaka by L6 Presenter
  • 1519 Views
  • 2 replies
  • 1 Likes

Cortex XSOAR Newsletter July 2024

July 2024 UPCOMING EVENTS Customer Success Webinar: On-Prem v6 Migration to v8 SaaS Join us on July 24th to learn everything you need about the on-prem migration to the XSOAR 8 SaaS. >>Register here CS Webinar Topics Suggestion Survey We value your input! Help shape our next webinars by sharing the topic you'd like to learn more abo...

rtsedaka_0-1720800150243.png
rtsedaka_1-1720800610422.png
rtsedaka_2-1720800610411.png
rtsedaka_4-1720800923211.png
rtsedaka by L6 Presenter
  • 1837 Views
  • 0 replies
  • 0 Likes

Cortex XSOAR New Content Pack Release - June 2024

New Content Packs Release For more info on use cases, integrations, and related documentation, click on the Pack title: GoogleThreatIntelligenceAnalyze suspicious hashes, URLs, domains, and IP addresses. GitHub FeedA feed to ingest indicators of compromise from Github repositories. The feed supports general extraction of IOCs, extracting fro...

rtsedaka by L6 Presenter
  • 1805 Views
  • 0 replies
  • 0 Likes

Cortex XDR Customer Success Webinar: Threat Hunting Methodologies

Threat Hunting Methodologies with Cortex XDR This session introduces Threat Hunting, its benefits, and how to put it to use. We cover the different Threat Hunting methodologies and available add-ons for XDR as Host Insights. You may review the queries we use in the video below. (view in My Videos) Sample queries: Process Execution Huntin...

XDR Threat Hunting - Forensics artifacts.jpg
rtsedaka by L6 Presenter
  • 1214 Views
  • 0 replies
  • 3 Likes

Cortex XSOAR CS Newsletter June 2024

June 2024 UPCOMING EVENTS Customer Success Webinar Series: Proactive Threat Hunting Part 2 The event concluded on June 12, 2024. Visit our events page later this month to learn about our next event. CS Webinar Topics Suggestion Survey We value your input! Help shape our next webinars by sharing the topic you'd like to learn more about. ...

rtsedaka_0-1718312579698.png
rtsedaka_2-1718312681173.png
rtsedaka_1-1718312672198.png
rtsedaka_3-1718313454410.png
rtsedaka by L6 Presenter
  • 1607 Views
  • 0 replies
  • 0 Likes

Cortex XDR CS Newsletter June 2024

June 2024 UPCOMING EVENTS Threat Hunting with XDR Calling all incident responders and forensic investigators to join us on June 26th for a Customer Success webinar and learn about Threat Hunting! >>Register here Investigation and Threat Hunting Virtual Workshop Calling all customers to join our 3-hour virtual workshop designed to ...

rtsedaka_0-1718291285896.png
rtsedaka_1-1718291749287.png
rtsedaka_2-1718291749398.png
rtsedaka_3-1718292375472.png
rtsedaka by L6 Presenter
  • 2425 Views
  • 0 replies
  • 0 Likes

Cortex XSOAR New Content Pack Release - May 2024

New Content Packs Release For more info on use cases, integrations, and related documentation, click on the Pack title: Suspicious Domain Hunting This pack provides all the necessary tools for the Suspicious Domain Hunting use case. It uses the CertStream integration to ingest new SSL certificates and alert for type-squatting. NVD Feed 2...

rtsedaka by L6 Presenter
  • 2148 Views
  • 0 replies
  • 0 Likes

Cortex XDR Customer Success Webinar Series Part 2: Alert Tuning Use Cases

Alert Tuning Part 2 Watch the second session in our Customer Success webinar series, which covers real-world use cases. (view in My Videos) Additional read and references: Legacy Exception Rules (Pro) Legacy Exception Rules (Prevent) Alert Exclusion Alert Tuning Cheat Sheet Examination Flow Have a question? Post it on our Discussio...

Alert Tuning options cheatsheet .png
Alert Tuning PE & DLL image.png
rtsedaka by L6 Presenter
  • 1391 Views
  • 0 replies
  • 2 Likes
Register or Sign-in
Top Contributors