Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Malware Profile - Ransomware Protection

Hello community, does anyone have more information pertaining to Ransomware Protection (Protection Mode) between "Aggressive" vs "Normal"?

From what I understand is that aggressive mode will have decoy files being created on the local machine. 

BoonHwee by L1 Bithead
  • 1145 Views
  • 2 replies
  • 0 Likes

CPU Utilization is high

Why does cortex XDR increase cpu usage ?

And after agent upgradation does cpu usuage increase?

what all other factors are there for high cpu utilization because of cortex xdr?

Resolved! OriginalFileName from VERSIONINFO in Cortex XDR Pro

Hey dear community, 

 

Threat actors often rename apps. Like a.exe instead of anydesk.exe. But they do not change the versioninfo. 

 

https://www.youtube.com/watch?v=oMAvSpq9fYY --> Minute 37

 

Is it possible to track this with cortex xdr pro?

 

BR

 

...

RFeyertag by L4 Transporter
  • 1035 Views
  • 2 replies
  • 0 Likes

XQL Search- to get the source of the file

I want to know the XQL query or filters which helps in the analysis of alerts & to know the source of file where it is coming into our system.

For example- whether user downloaded the file from browser or someone sent through outlook, from portable d

...

Resolved! Cortex XDR Parsing rule / SQL query

Hi All

 

I am currently creating some parsing rules and I am using split to seperate the _raw_log field into its individual fields. After my initiail split I have one a field that starts with a comma, or multple commas, depending on the log. Does any

...

URL Exception

Hi Team,

 

Does Cortex XDR support URL filtering. We have a request to whitelist a URL on XDR in order for user to be able to access it. 

 

Wondering if this is even possible by XDR or should be taken care at proxy level.

 

Thanks

Directory Sync usage

Hello everyone,

Just curious who uses the Directory Sync tool out there? If you use it would you mind sharing a quick like/dislike about it? I really want to incorporate it into our environment but not entirely sold on it... yet. Any feedback about it

...

CraigV123 by L3 Networker
  • 6514 Views
  • 9 replies
  • 0 Likes

2-Factor Authentication

Hello,

 

Can we change  authetication options while logging in to cortex xdr?

While logging in first time on cortex XDR we selected google authenticator but mistakenly google authenticator app got deleted from phone  and after re-installing it is una

...

  • 1796 Posts
  • 78 Subscriptions
Top Solution Authors