Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 861 Views
  • 0 replies
  • 2 Likes

CVEs for applications Unsupported Platform

We have quite a bit of different softwares installed here, many Adobe products, 7-zip etc which I know have CVEs issued. Do I need to do something to enable this feature in XDR? ALL of the software detected shows Unsupported Platform. Does this featu

...

DopedWafer_0-1737557531926.png

Linux Agent Tampering protection

Hello Palo Alto Live Community,

 

I hope this post finds you well. I’m currently exploring the tamper protection capabilities of Cortex XDR for Linux and would appreciate insights from this knowledgeable community.

 

Specifically, I am interested in

...

XQL 2 Datasets

Hello community,

I am reaching out to you after many hours of trying to get this XQL query but something is not working.

I need to join the IP address from endpoints to my query 

dataset = management_auditing
| filter description contains "SOX" and (des

...

Disable notification in user agent

Hello,
I have an exception rule on a file that is being applied correctly. The file executes because of this exception, but in the user agent you get a warning that an unusual activity has been encountered or that a malicious activity has been encount

...

Agent stops because of full storage

Hi,

 

We recently encountered an issue where an XDR agent stopped functioning, and all protections were disabled (except for tamper protection) due to a full temp folder. Has anyone experienced a similar problem and identified the root cause or poten

...

paIoaItonetworks_1-1736243068553.png

FTP Transfer Custom BIOC

Hello Palo Alto LiveCommunity,

 

I’m currently working on a task where I need to create a custom BIOC (Behavioral Indicator of Compromise) and add it to a restriction profile to block FTP command lines. Specifically, I want to prevent FTP-related com

...

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 861 Views
  • 0 replies
  • 2 Likes

LSA Protection and antimalware DLL loading

We currently have deployed LSA Protection and code integrity in Windows 11 (build 24H2).

Cortex XDR agent 8.6.0 is installed. When trying to load a DLL from another security tool (Ivanti Device and Application Control), Code Integrity is blocking the

...

error.PNG

USB drive Alert

kindly we need your support, I want to get alert when a USB drive is connected to workstation and not blocked by Symantec AV.

I have tried several times with correlation rule, I found XQL query very effective, and it is as follows:

 

 

Spoiler
config
...

  • 2308 Posts
  • 86 Subscriptions
Top Solution Authors
Top Liked Authors