Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 887 Views
  • 0 replies
  • 2 Likes

XDR Agent - retrieve more information events

Hi,

I have a question. I'm seeing XDR events with "Memory Corruption Exploit" generated by the XDR Agent... Cortex XDR 

 

I know this typically happens when users open a DOCX file with macros. My question is: Is there a way to collect information rel

...

tlmarques by L4 Transporter
  • 409 Views
  • 1 replies
  • 0 Likes

Broker VM - Local Agent Settings Applet Error

Hi Team,

As observed, we're getting the below error in the local agent settings applet in our broker vm's. We have three broker vm's in place and all of them are showing the same error. We have not made any changes in the configurations. Could you ple

...

SKhurana_0-1739781898751.png

Resolved! Cortex XDR folder taking up space

Hello Cortex Team,

 

On one of our server endpoint, the Dump folder located on the path : ProgramData\Cyvera\LocalSystem\Dump is taking a lot of space.

 

We already tried to clear the database of said agent, no difference. (see screenshot before and

...

Resolved! Connect New XDR Tenant with Existing Broker VM

Hello

We are migrating our existing XDR tenant due to region issue. We have got our new tenant and Basic configurations are done. 
I have a question regarding the BrokerVM. Do we need to create new broker VM for the new tenant or we can use our existi

...

Broker VM Log ingestion and forwarding

Hi,

 

My query is can we forward one broker VM logs to another broker VM.

 

Use case is I have BVM A and BVM 2,

       1. I want to ingest logs into BVM A from Agents or other log sources.

       2. Then forward logs from BVM A to BVM B.

       3. BV

...

P.Ghule by L1 Bithead
  • 658 Views
  • 3 replies
  • 0 Likes

Resolved! Need help - BIOC / Script / XQL?

Hey everyone. I need some assistance in looking at this logically.

 

We have an identified PuP in our environment that is persistent. It creates a scheduled task and if you don't remove that, your PuP that you deleted will be back in no time.

 

Is th

...

Interpreting alerts on XDR

Hi, The alerts on XDR and very much rigid and not readable even to the support personnel, whenever I raise a case they keep checking with other teams teams and higher support levels to get details, for example how to interpret the below, it says susp

...

eXtended Threat Hunting (XTH) Module

Hi team,

Got a renewal quotation with new XTH module.

Heard eXtended Threat Hunting (XTH) Module is about query the raw data for threat hunting.

Still not so sure what is the new module is used for?

What is the use case to purchase this lic in additi

...

  • 2316 Posts
  • 87 Subscriptions
Top Solution Authors
Top Liked Authors