Connect your own Palo Alto Networks Cortex XDR tenant to manage Incidents, Alerts, Endpoints (isolate/unisolate, scan), custom IOCs, and remote script execution via the Action Center.
What this app can do
18 tools registered
Connect Cortex XdrFree
Connect your own Palo Alto Networks Cortex XDR tenant (Standard API key + key ID + tenant FQDN), verifying the credentials with a real call before saving.
List ConnectionsFree
List connected Cortex XDR tenants.
Disconnect Cortex XdrFree
Disconnect a Cortex XDR tenant, removing its stored API key.
List Incidents8 tok
List incidents on the connected Cortex XDR tenant, optionally filtered by status.
Get Incident8 tok
Read one Cortex XDR incident in full, including its related alerts.
Update Incident16 tok
Update an existing Cortex XDR incident's status, assignee, or severity. A resolve_comment is required when status starts with 'resolved'.
List Alerts8 tok
List alerts on the connected Cortex XDR tenant, optionally restricted to one incident.
List Endpoints8 tok
List endpoints (hosts) enrolled in the connected Cortex XDR tenant.
Isolate Endpoint16 tok
Isolate an endpoint from the network -- cuts almost all network access immediately except the Cortex XDR agent channel. Use only for active threat containment.
Unisolate Endpoint16 tok
Restore an isolated endpoint's normal network access.
Scan Endpoint20 tok
Trigger an on-demand malware scan on one or more endpoints.
List Iocs8 tok
List custom Indicators (IOCs) configured on the connected Cortex XDR tenant.
Create Ioc16 tok
Create a custom Indicator (IOC) on the connected Cortex XDR tenant to flag or block a hash, IP, domain, or path fleet-wide.
Remove Ioc16 tok
Remove a custom Indicator (IOC) from the connected Cortex XDR tenant.
List Scripts8 tok
List scripts available in the connected Cortex XDR tenant's Action Center library.
Run Script20 tok
Run an approved Action Center script against one or more endpoints -- executes real code on live hosts, use with care.
Get Script Run Results20 tok
Read the per-endpoint results of a previously run Action Center script by its action_id.
Audit Cortex Tenant40 tok
Build one aggregated health report across the connected Cortex XDR tenant: open incidents by severity, unassigned High/Critical incidents, and disconnected endpoints.