Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

Browse the Community

Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

2279 Posts

Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

1212 Posts

Cortex Xpanse Discussions

Cortex Xpanse builds a system of record that is the authoritative source for an organization’s global Internet assets; it knows your attack surface so you can own it before someone else.

9 Posts

Cortex XSIAM Discussions

Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

75 Posts

Activity in Security Operations

Resolved! Creating a Custom Issue For a Case

Hello LiveComm,

I have created a custom case with a single Issue for a Use-Case.

I want to create more issues with a command or script in this custom case which will eventually be a playbook task.  How does one do such an action?

Many thanks,

MSysec

...

Broker-VM disconnet alert notification

Hi All,

 

anyi dea how i can generate an alert when a broker-vm gets disconnected?

 

Has anyone managed to create a correlation rule that will alert if a Broker-VM gets disconnected from XSIAM?

the xsiam documentation states that 'To help you monito

...

PA_nts by L3 Networker
  • 58 Views
  • 1 replies
  • 0 Likes

Cortex XDR- Compromise Assessment

Hi, we recently moved to Cortex XDR, and I’m struggling to run a forensic script (such as AmCache) across 100 endpoints. I need to have all the results automatically combined into a single Excel sheet after the script finishes, similar to how Fidelis

...

XDR CIE

How is CIE configured in XDR MSSP? Is it only on the parent and then shared to child tenants or can it be configured differently on each of the child tenants?

Cortex XDR Agent 8.8

Hi,

 

We upgraded the Cortex XDR agent version to 8.8.0.10622 for MS Windows. However, in a few moments, it started detecting Netskope and Tanium as malicious and blocking them.

 

We have added Netskope and Tanium to the whitelist, but they are still

...

O.Faheem by L1 Bithead
  • 79 Views
  • 0 replies
  • 0 Likes

Installing Cortex Agent on Linux LXD

 

Hello everyone,

I am looking to install the Cortex Agent on a Linux system within an LXD container. Does anyone have insights or a step-by-step guide on how to install the Cortex Agent in this environment?
Additionally, is Cortex officially supported

...

Cortex Broker Mapper scans

We’re experiencing an issue with Cortex brokers related to the network mapper.
When we run network scans using the "ICMP Echo" flag, the scan completes successfully and everything works as expected.

However, when performing a "TCP SYN" scan on the foll

...

tlmarques by L4 Transporter
  • 104 Views
  • 0 replies
  • 0 Likes
Register or Sign-in
Top Liked Authors