Initiate a Live Terminal session
Initiate a Live Terminal session from the Cortex XDR management console to control the endpoint remotely.
To investigate and respond to security events on endpoints, you can use the Live Terminal to initiate a remote connection to an endpoint. The remote connection is facilitated by the Cortex XDR agent by using a remote procedure call. With the Live Terminal you can manage remote endpoints, and perform investigation and response actions on endpoints. Actions include:
Navigating and managing files in the file system.
Managing active processes.
Running operating system commands and Python commands.
Downloading files of up to 200 MB and uploading files of up to 40 MB.
Live Terminal is supported for endpoints that meet the following requirements:
Windows
Traps 6.1 or a later release.
Windows 7 SP1 or a later release.
Windows update patch for WinCRT (KB 2999226). To verify the Hotfixes that are installed on the endpoint, run the
systeminfocommand from a command prompt.Endpoint activity reported within the last 90 minutes (as identified by the Last Seen time stamp in the endpoint details).
Mac
Cortex XDR agent 7.0 or a later release.
macOS 10.12 or a later release.
Endpoint activity reported within the last 90 minutes (as identified by the Last Seen time stamp in the endpoint details).
Linux
Cortex XDR agent 7.0 or a later release.
Any Linux supported version as listed in Where Can I Install the Cortex XDR Agent? in the Palo Alto Networks Compatibility Matrix.
Endpoint activity reported within the last 90 minutes (as identified by the Last Seen time stamp in the endpoint details).
Last updated
Was this helpful?
