Skip to main content
Palo Alto Cortex XDR app icon

Palo Alto Cortex XDR

This app integrates with the Palo Alto Cortex XDRBuilt by SOAR Community
soar product badge

Default Version 1.2.1

April 28, 2025

Compatibility

SOAR On-Prem, SOAR Cloud

Platform Version: 8.7, 8.6, 8.5, 8.4, 8.0, 7.2, 7.1, 7.0, 6.4, 6.3, 6.2, 6.1, 6.0, 5.5, 5.4

Rating
0
(0)

Log in to rate this app

Support
Not Supported
Ranking

#49 in Endpoint

This app integrates with the Palo Alto Cortex XDR

Supported actions

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity using supplied configuration
  • list endpoints: List all the endpoints/sensors configured on the device
  • get policy: Get the policy name for a specific endpoint
  • get action status: Retrieve the status of the requested actions according to the action ID
  • retrieve file: Retrieve files from a specified endpoint
  • retrieve file details: View the file retrieved by the Retrieve File action according to the action ID
  • quarantine file: Quarantine file on a specified endpoint
  • unquarantine file: Restore a quarantined file on a specified endpoint
  • block hash: Add a hash that does not exist in the allow or block list to a block list
  • allow hash: Add files that do not exist in the allow or block list to an allow list
  • quarantine device: Quarantine a specified endpoint
  • unquarantine device: Unquarantine a specified endpoint
  • scan endpoint: Run a scan on selected endpoints
  • cancel scan endpoint: Cancel the scan of selected endpoints
  • get incidents: Get a list of incidents filtered by a list of incident IDs, modification time, or creation time
  • get incident details: Get extra data fields of a specific incident including alerts and key artifacts
  • get alerts: Get a list of alerts with multiple events