> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/pre-installation-steps-for-cortex-xdr-agents.md).

# Pre-installation steps for Cortex XDR agents

### Define endpoint groups

You can define an endpoint group and then apply policy rules and manage specific endpoints. If you set up Cloud Identity Engine, you can also leverage your Active Directory user, group, and computer details to define endpoint groups.

Do one of the following:

* Create a dynamic group by enabling Cortex XDR to populate your endpoint group dynamically using endpoint characteristics, such as an endpoint tag, partial hostname or alias, full or partial domain or workgroup name, IP address, range or subnets, installation type (VDI, temporary session or standard endpoint), agent version, endpoint type (workstation, server, mobile), user or operating system version.
* Create a static group by selecting a list of specific endpoints.

{% hint style="info" %}

### Note

Configuration based on user granular policy is optimized for VDI and session-persistent environments; it is not recommended for decentralized or traditional endpoint architectures.
{% endhint %}

After you define an endpoint group, you can then use it to target policy and actions to specific recipients. The **Endpoint Groups** page displays all endpoint groups along with the number of endpoints and policy rules linked to the endpoint group.

#### How to define an endpoint group

1. Select **Inventory** → **Endpoints** → Groups → **+Add Group**.
2. Select one of the following:
   * **Create New** to create an endpoint group from scratch
   * **Upload From File** using plain text files with a new line separator, to populate a static endpoint group from a file containing IP addresses, hostnames, or aliases.
3. Enter a **Group Name** and optional description to identify the endpoint group. The name you assign to the group will be visible when you assign endpoint security profiles to endpoints.
4. Determine the endpoint properties for creating an endpoint group:

   * **Dynamic:** Use the filters to define the criteria you want to use to dynamically populate an endpoint group. Dynamic groups support multiple criteria selections and can use **AND** or **OR** operators. For endpoint names and aliases, and domains and workgroups, you can use **`*`** to match any string of characters. As you apply filters, Cortex XDR displays any registered endpoint matches to help you validate your filter criteria.
   * **Static:** Select specific registered endpoints that you want to include in the endpoint group. Use the filters, as needed, to reduce the number of results.

     When you create a static endpoint group from a file, the IP address, hostname, or alias of the endpoint must match an existing agent that has registered with Cortex XDR. You can select up to 250 endpoints.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Disconnecting Cloud Identity Engine in your Cortex XDR deployment can affect existing endpoint groups and policy rules based on Active Directory properties.</p></div>
5. Create the endpoint group.

   After you save your endpoint group, it is ready for use to assign security profiles to endpoints and in other places where you can use endpoint groups.

At any time, you can return to the **Groups** page to view and manage your endpoint groups. To manage a group, right-click the group and select the desired action:

* **Edit:** View the endpoints that match the group definition, and optionally refine the membership criteria using filters.
* **Delete:** Remove the endpoint group.
* **Save as new:** Duplicate the endpoint group and save it as a new group.
* **Export group:** Export the list of endpoints that match the endpoint group criteria to a tab separated values (TSV) file.
* **View endpoints:** Pivot from an endpoint group to a filtered list of endpoints on the **All Endpoints** page where you can quickly view and initiate actions on the endpoints within the group.

### Manage endpoint profiles

Cortex XDR provides default security profiles that you can use out of the box to immediately begin protecting your endpoints from threats. These profiles are applied to endpoints by mapping them to policies and then mapping the policies to endpoints.

While security rules enable you to block or allow files to run on your endpoints, security profiles help you customize and reuse settings across different groups of endpoints. When the Cortex XDR agent detects behavior that matches a rule defined in your security policy, it applies the security profile that is attached to the rule for further inspection.

#### Related information

* [Set up malware prevention profiles](/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md)
* [Set up exploit prevention profiles](/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md)
* [Set up agent settings profiles](/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md)
* [Set up restrictions prevention profiles](/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-restrictions-prevention-profiles.md)
* [Set up exception profiles and rules](/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules.md)

### Endpoint data collection

When the Cortex XDR agent generates an issue on endpoint activity, a minimum set of metadata about the endpoint is sent to the server.

When you enable behavioral threat protection or EDR data collection in your endpoint security policy, the Cortex XDR agent can also continuously monitor endpoint activity for malicious event chains identified by Palo Alto Networks. The endpoint data that the Cortex XDR agent collects when you enable these capabilities varies by platform type.

{% hint style="info" %}

### Note

Agents with Cortex XDR Pro per Endpoint apply limits and filters on network, file, and registry logs. To expand these limits and filters requires the Extended Threat Hunting Data (XTH) add-on.

The tables below note whether specific logs require the XTH add-on.
{% endhint %}

<details>

<summary>Metadata collected for Cortex XDR agent issues</summary>

When the Cortex XDR agent generates an issue on endpoint activity, the following metadata is sent to the server:

| Field                  | Description                                                          |
| ---------------------- | -------------------------------------------------------------------- |
| Absolute timestamp     | Kernel system time                                                   |
| Relative timestamp     | Uptime since the computer started                                    |
| Thread ID              | ID of the originating thread                                         |
| Process ID             | ID of the originating process                                        |
| Process creation time  | Part of the process unique ID per boot session (PID + creation time) |
| Sequence ID            | Unique integer per boot session                                      |
| Primary user SID       | Unique identifier of the user                                        |
| Impersonating user SID | Unique identifier of the impersonating user, if applicable           |

</details>

<details>

<summary>EDR data collected for Windows endpoints</summary>

| Category                                        | Events                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Attributes                                                                                                                                                                                                                                                                                                                                                                                            |
| ----------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Mount a device (volume and hardware)            | <ul><li>Mount</li><li>Unmount</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | <ul><li>Storage device name</li><li>Storage device class GUID</li><li>Storage device class name</li><li>Storage device bus type</li><li>Storage device volume GUID</li><li>Storage device mount point</li><li>Storage device drive type</li><li>Storage device vendor ID</li><li>Storage device product ID</li><li>Storage device serial number</li><li>Storage device virtual volume image</li></ul> |
| Executable metadata                             | Process start                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | <ul><li>File size</li><li>File access time</li></ul>                                                                                                                                                                                                                                                                                                                                                  |
| Files                                           | <ul><li>Create</li><li>Write</li><li>Delete</li><li>Rename</li><li>Move</li><li>Modification</li><li>Symbolic links</li><li>Read</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                | <ul><li>Full path of the modified file before and after modification</li><li>SHA256 and MD5 hash for the file after modification</li><li>SetInformationFile for timestamps</li><li>File set security (DACL) information</li><li>Resolve hostnames on local network</li><li>Symbolic-link/hard-link and reparse point creation</li><li>File device type (regular file or Named Pipe)</li></ul>         |
| Image (DLL)                                     | Load                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | <ul><li>Full path</li><li>Base address</li><li>Target process-id/thread-id</li><li>Image size</li><li>Signature</li><li>SHA256 and MD5 hash for the DLL</li><li>File size</li><li>File access time</li></ul>                                                                                                                                                                                          |
| Process                                         | <ul><li>Create</li><li>Terminate</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | <ul><li>Process ID (PID) of the parent process</li><li>PID of the process</li><li>Full path</li><li>Command line arguments</li><li>Integrity level to determine if the process is running with elevated privileges</li><li>Hash (SHA256 and MD5)</li><li>Signature or signing certificate details</li></ul>                                                                                           |
| Thread                                          | Injection                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | <ul><li>Thread ID of the parent thread</li><li>Thread ID of the new or terminating thread</li><li>Process that initiated the thread if from another process</li></ul>                                                                                                                                                                                                                                 |
| Network                                         | <ul><li>Accept</li><li>Connect</li><li>Create</li><li>Listen</li><li>Close</li><li>Bind</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                         | <ul><li>Source IP address and port</li><li>Destination IP address and port</li><li>Failed connection</li><li>Protocol (TCP/UDP)</li><li>Resolve hostnames on local network</li></ul>                                                                                                                                                                                                                  |
| Network protocols                               | <ul><li>DNS request and UDP response</li><li>HTTP connect</li><li>HTTP disconnect</li><li>HTTP proxy parsing</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                    | <ul><li>Origin country</li><li>Remote IP address and port</li><li>Local IP address and port</li><li>Destination IP address and port if proxy connection</li><li>Network connection ID</li><li>IPv6 connection status (true/false)</li><li>External hostname</li></ul>                                                                                                                                 |
| Network statistics                              | <ul><li>On-close statistics</li><li>Periodic statistics</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | <ul><li>Upload volume on TCP link</li><li>Download volume on TCP link</li></ul><p>Traps sends statistics both when a connection is closed, and at periodic intervals while the connection remains open.</p>                                                                                                                                                                                           |
| Registry                                        | <ul><li><p>Registry value:</p><ul><li>Deletion</li><li>Set</li></ul></li><li><p>Registry key:</p><ul><li>Creation</li><li>Deletion</li><li>Rename</li><li>Addition</li><li>Modification (set information)</li><li>Restore</li><li>Save</li></ul></li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Important</strong></p><p>Registry key is collected as a real key name, and not as a symbolic link.</p><p>\*\*Example 2. \*\*null<br><br>\*\*Example 3. \*\*null<br><br></p></div> | <ul><li>Registry path of the modified value or key</li><li>Name of the modified value or key</li><li>Data of the modified value</li></ul>                                                                                                                                                                                                                                                             |
| Session                                         | <ul><li>Log on</li><li>Log off</li><li>Connect</li><li>Disconnect</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                               | <ul><li>Interactive log-on (log-on at a computer console using credentials such as a username and password)</li><li>Session ID</li><li>Session State (equivalent to the event type)</li><li>Local (physically on the computer) or remote (connected using a terminal services session)</li></ul>                                                                                                      |
| Host status                                     | <ul><li>Boot</li><li>Suspend</li><li>Resume</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | <ul><li>Host name</li><li>OS Version</li><li>Domain</li><li>Previous and current state</li></ul>                                                                                                                                                                                                                                                                                                      |
| Agent status                                    | Agent start                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                       |
| User presence                                   | User Detection                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Detection when a user is present or idle per active user session on the computer.                                                                                                                                                                                                                                                                                                                     |
| <p>RPC calls</p><p>\*Requires XTH add-on</p>    | <ul><li>RpcCall</li><li>RpcPreCall</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | <ul><li>action\_rpc\_interface\_uuid</li><li>action\_rpc\_interface\_version\_major</li><li>action\_rpc\_interface\_version\_minor</li><li>action\_rpc\_func\_opnum</li><li>action\_rpc\_func\_str\_call\_fields (optional)</li><li>action\_rpc\_func\_int\_call\_fields (optional)</li><li>action\_rpc\_interface\_name</li><li>action\_rpc\_func\_name</li></ul>                                    |
| <p>System calls</p><p>\*Requires XTH add-on</p> | Syscall types change frequently, and can be observed in each event's data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                | <ul><li>action\_syscall\_string\_params</li><li>action\_syscall\_int\_params</li><li>action\_syscall\_target\_instance\_id</li><li>action\_syscall\_target\_image\_path</li><li>action\_syscall\_target\_image\_name</li><li>action\_syscall\_target\_os\_pid</li><li>action\_syscall\_target\_thread\_id</li><li>address\_mapping</li></ul>                                                          |
| <p>Event log</p><p>\*Requires XTH add-on</p>    | See the table below for the list of Windows Event Logs that can be sent to the server.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                                                                                                                                                                                                                                                                       |
| .Net events                                     | <ul><li>.NET DLL Loaded</li><li>.NET DLL Loaded From Buffer</li><li>Amsi Bypass Attempt</li><li>Suspicious .NET To Win32 Calls</li><li>.NET To Native Shellcode Execution Attempt</li><li>Malicious C# Compilation and Execution Attempt</li><li>Powershell Script Execution</li><li>Obfuscated Powershell Execution Attempt</li><li>Deserialization Exploit Attempt</li><li>Webshell Execution Attempt</li><li>Suspicious ASPX execution</li><li>Exchange Vulnerability Attempt</li><li>SharePoint JWT Vulnerability Attempt</li></ul>   | <ul><li>DotNetCommon\_DotnetCallstack</li><li>DotNetCommon\_CLRVersion</li><li>DotNetCommon\_ContentVersion</li><li>DotNetCommon\_EdrAssemblyVersion</li><li>DotNetCommon\_AppDomainId</li><li>Other attributes may be added, depending on the event type and context.</li></ul>                                                                                                                      |

</details>

<details>

<summary>Windows event logs collected for Windows endpoints</summary>

Cortex XDR agents can send the following Windows Event Logs to the tenant.

For more information on how to set up Windows event logs collection, see [Microsoft Windows security auditing setup](/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup.md).

| Path                                                               | Provider                                                  | Event IDs and Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------------------------------------------------ | --------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Application                                                        | EMET                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Application                                                        | Windows Error Reporting                                   | Only for Windows Error Reporting (WER) events when an application stops unexpectedly                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Application                                                        | Microsoft-Windows-User Profiles Service                   | <ul><li><strong>1511</strong>: A user logged on with a temporary profile because Windows could not find the user's local profile.</li><li><strong>1518</strong>: A profile could not be created using a temporary profile</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Application                                                        | Application Error                                         | **1000**: Application unexpected stop/hang events, similar to WER/1001. These events include the full path to the EXE file, or to the module with the fault.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Application                                                        | Application Hang                                          | **1002**: Application unexpected stop/hang events, similar to WER/1001. These events include the full path to the EXE file, or to the module with the fault.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Microsoft-Windows-LDAP-client                                      |                                                           | **30**: Windows Event Collector (WEC) recommended event                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Microsoft-Windows-CAPI2/Operational                                |                                                           | <p>Windows CAPI2 logging events:</p><ul><li><strong>11</strong>: Build Chain</li><li><strong>70</strong>: A Private Key was accessed</li><li><strong>90</strong>: X509 object</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Microsoft-Windows-DNS-Client/Operational                           |                                                           | **3008**: A DNS query was completed without local machine name resolution events, and without empty name resolution events.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Microsoft-Windows-DriverFrameworks-UserMode/Operational            |                                                           | **2004**: Detection of User-Mode drivers loading, for potential BadUSB detection                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Microsoft-Windows-PowerShell/Operational                           |                                                           | <ul><li><strong>4103</strong>: Block an activity</li><li><strong>4104</strong>: Remote command</li><li><strong>4105</strong>: Start command</li><li><strong>4106</strong>: Stop command</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Microsoft-Windows-PrintService                                     | Microsoft-Windows-PrintService                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Microsoft-Windows-TaskScheduler/Operational                        | Microsoft-Windows-TaskScheduler                           | **106, 129, 141, 142, 200, 201**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Microsoft-Windows-TerminalServices-RDPClient/Operational           |                                                           | **1024**: A terminal service (TS) attempted to connect to a remote server                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Microsoft-Windows-Windows Defender/Operational                     |                                                           | <ul><li><strong>1006</strong>: Microsoft Defender Antivirus detected suspicious behavior</li><li><strong>1009</strong>: Microsoft Defender Antivirus restored an item from quarantine</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Microsoft-Antimalware-Scan-Interface                               |                                                           | **1101**: Anti-Malware Scan Interface (AMSI) content scan event                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Microsoft-Windows-Windows Defender/Operational                     |                                                           | <ul><li><strong>1116</strong>: Microsoft Defender Antivirus detected malware or other potentially unwanted software</li><li><strong>1119</strong>: Microsoft Defender Antivirus encountered a critical error when taking action on malware or other potentially unwanted software</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Microsoft-Windows-Windows Firewall With Advanced Security/Firewall | Microsoft-Windows-Windows Firewall With Advanced Security | **2004, 2005, 2006, 2009, 2033**: Windows Firewall With Advanced Security Local Modifications (Levels 0, 2, 4)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Security                                                           |                                                           | **1102**: The Security log cleared events                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Security                                                           | Microsoft-Windows-Eventlog                                | Event log service events specific to the Security channel                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Security                                                           |                                                           | <ul><li><strong>4880</strong>: Certificate Authority Service stopped</li><li><strong>4881</strong>: Certificate Authority Service started</li><li><strong>4896</strong>: Certificate Authority database rows were deleted</li><li><strong>4898</strong>: A Certificate Authority template was loaded</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Security                                                           |                                                           | <p>Routing and Remote Access Service (RRAS) events (these are only generated on Microsoft IAS server)</p><ul><li><strong>6272</strong>: User access was granted.</li><li><strong>6280</strong>: User account unlocked</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Security                                                           | Microsoft-Windows-Security-Auditing                       | <ul><li><strong>4624</strong>: Successful logon</li><li><strong>4625</strong>: Failed logon</li><li><strong>4634</strong>: Logoff</li><li><strong>4647</strong>: User initiated logoff</li><li><strong>4648</strong>: Logon attempted, explicit credentials</li><li><strong>4649</strong>: Replay attack</li><li><strong>4672</strong>: Special privileges attempted login</li><li><strong>4768</strong>: Kerberos TGT request</li><li><strong>4769</strong>: Kerberos service ticket requested</li><li><strong>4770</strong>: Kerberos service ticket renewal</li><li><strong>4771</strong>: Kerberos pre-authentication failed</li><li><strong>4776</strong>: Domain controller validation attempt</li><li><strong>4778</strong>: Session was reconnected to a Windows station</li><li><strong>4800</strong>: Workstation locked</li><li><strong>4801</strong>: Workstation unlocked</li><li><strong>4802</strong>: Screensaver was invoked</li><li><strong>4803</strong>: Screensaver was dismissed</li></ul>                                                                                                                                                                                                                                                                                      |
| Security                                                           | Microsoft-Windows-Security-Auditing                       | <ul><li><strong>4720</strong>: A user account was created</li><li><strong>4722</strong>: A user account was enabled</li><li><strong>4723</strong>: An attempt was made to change an account's password</li><li><strong>4724</strong>: An attempt was made to reset an account’s password</li><li><strong>4725</strong>: A user account was disabled</li><li><strong>4726</strong>: A user account was deleted</li><li><strong>4727, 4731, 4754</strong>: Creation of Groups</li><li><strong>4728, 4732, 4756</strong>: Group member additions</li><li><strong>4729, 4733, 4757</strong>: Group member removals</li><li><strong>4735, 4737, 4755, 4764</strong>: Group changes</li><li><strong>4738</strong>: A user account was changed</li><li><strong>4740</strong>: A user account was locked out</li><li><strong>4741</strong>: A computer account was created</li><li><strong>4742</strong>: A computer account was changed</li><li><strong>4743</strong>: A computer account was deleted</li><li><strong>4765, 4766</strong>: SID history</li><li><strong>4767</strong>: A user account was unlocked</li><li><strong>4780</strong>: ACL set on accounts</li><li><strong>4781</strong>: The name of an account was changed</li><li><strong>4799</strong>: Group membership enumeration</li></ul> |
| Security                                                           | Microsoft-Windows-Security-Auditing                       | <ul><li><strong>4616</strong>: System time was changed</li><li><strong>4821</strong>: Kerberos service ticket was denied</li><li><strong>4822, 4823</strong>: New Technology LAN Manager (NTLM) authentication failed</li><li><strong>4824</strong>: Kerberos pre-authentication failed</li><li><strong>4825</strong>: A user was denied access to Remote Desktop</li><li><strong>5058</strong>: Key file operation</li><li><strong>5059</strong>: Key migration operation</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Security                                                           | Microsoft-Windows-Security-Auditing                       | <ul><li><strong>4698</strong>: A scheduled task was created</li><li><strong>4702</strong>: A scheduled task was updated</li><li><strong>4886</strong>: Certificate Services received a certificate request</li><li><strong>4887</strong>: Certificate Services approved a certificate request</li><li><strong>4899</strong>: A Certificate Services template was updated</li><li><strong>4900</strong>: Certificate Services template security was updated</li><li><strong>5140</strong>: A network share object was accessed</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Security                                                           | Microsoft-Windows-Security-Auditing                       | **4713**: Kerberos policy was changed on a domain controller                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Security                                                           | Microsoft-Windows-Security-Auditing                       | **4662**: An operation was performed on an Active Directory object                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

</details>

<details>

<summary>EDR data collected for Mac endpoints</summary>

| Category                                     | Events                                                                                                                | Attributes                                                                                                                                                                                                                                                                                                  |
| -------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>Files</p><p>\*Requires XTH add-on</p>     | <ul><li>Create</li><li>Write</li><li>Delete</li><li>Rename</li><li>Move</li><li>Open</li></ul>                        | <ul><li>Full path of the modified file before and after modification</li><li>SHA256 and MD5 hash for the file after modification</li></ul>                                                                                                                                                                  |
| Process                                      | <ul><li>Start</li><li>Stop</li></ul>                                                                                  | <ul><li>Process ID (PID) of the parent process</li><li>PID of the process</li><li>Full path</li><li>Command line arguments</li><li>Integrity level to determine if the process is running with elevated privileges</li><li>Hash (SHA256 and MD5)</li><li>Signature or signing certificate details</li></ul> |
| Network                                      | <ul><li>Accept</li><li>Connect</li><li>Connect Failure</li><li>Disconnect</li><li>Listen</li><li>Statistics</li></ul> | <ul><li>Source IP address and port</li><li>Destination IP address and port</li><li>Failed connection</li><li>Protocol (TCP/UDP)</li><li>Aggregated send/receive statistics for the connection</li></ul>                                                                                                     |
| <p>Event log</p><p>\*Requires XTH add-on</p> | <ul><li>Authentication</li></ul>                                                                                      | <ul><li>Provider Name</li><li>Data fields</li><li>Message</li></ul>                                                                                                                                                                                                                                         |

</details>

<details>

<summary>EDR data collected for Linux endpoints</summary>

| Category                                                           | Events                                                                                             | Attributes                                                                                                                                                                                                                                            |
| ------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>Files</p><p>\*Requires XTH add-on</p>                           | <ul><li>Create</li><li>Open</li><li>Write</li><li>Delete</li></ul>                                 | <ul><li>Full path of the file</li><li>Hash of the file</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>For specific files only and only if the file was written.</p></div> |
| <ul><li>Copy</li><li>Move (rename)</li></ul>                       | <ul><li>Full paths of both the original and the modified files</li></ul>                           |                                                                                                                                                                                                                                                       |
| <ul><li>Change owner (chown)</li><li>Change mode (chmod)</li></ul> | <ul><li>Full path of the file</li><li>Newly set owner/attributes</li></ul>                         |                                                                                                                                                                                                                                                       |
| Network                                                            | <ul><li>Listen</li><li>Accept</li><li>Connect</li><li>Connect failure</li><li>Disconnect</li></ul> | <ul><li>Source IP address and port for explicit binds</li><li>Destination IP address and port</li><li>Failed TCP connections</li><li>Protocol (TCP/UDP)</li></ul>                                                                                     |
| Process                                                            | <ul><li>Start</li></ul>                                                                            | <ul><li>PID of the child process</li><li>PID of the parent process</li><li>Full image path of the process</li><li>Command line of the process</li><li>Hash of the image (SHA256 & MD5)</li></ul>                                                      |
| <ul><li>Stop</li></ul>                                             | <ul><li>PID of the stopped process</li></ul>                                                       |                                                                                                                                                                                                                                                       |
| <p>Event log</p><p>\*Requires XTH add-on</p>                       | <ul><li>Authentication</li></ul>                                                                   | <ul><li>Provider Name</li><li>Data fields</li><li>Message</li></ul>                                                                                                                                                                                   |

</details>

### Configure global agent settings

In addition to the customizable Agent Settings Profiles for each Operating System and different endpoint targets, you can configure global Agent Configurations that apply to all the endpoints in your network.

1. From Cortex XDR, select **Settings** → **Configurations** → General → **Agent Configurations**.
2. Set global uninstall password.

   The uninstall password is required to remove a Cortex XDR agent and to grant access to the agent security component on the endpoint. You can use the default uninstall **`Password1`** defined in Cortex XDR or set a new one and **Save**. This global uninstall password applies to all the endpoints (excluding mobile) in your network. If you change the password later on, the new default password applies to all new and existing profiles to which it applied before. If you want to use a different password to uninstall specific agents, you can override the default global uninstall password by setting a different password for those agents in the Agent Settings profile. The selected password must satisfy the requirements enforced by **Password Strength** indicator.

   A new password must satisfy the following **Password Strength** indicator requirements:

   * It must be 8 to 32 characters.
   * It must contain at least one upper-case, at least one lower-case letter, at least one number, and at least one of the following characters: **`!@#%`**.
3. Manage the content updates bandwidth and frequency in your network.
   * **Enable bandwidth control:** Palo Alto Networks enables you to control your Cortex XDR agent network consumption by adjusting the bandwidth it is allocated. Based on the number of agents you want to update with content and upgrade packages, active or future agents, the Cortex XDR calculator configures the recommended amount of Mbps (Megabits per second) required for a connected agent to retrieve a content update over a 24 hour period or a week. Cortex XDR supports between 20 - 10000 Mbps, you can enter one of the recommended values or enter one of your own. For optimized performance and reduced bandwidth consumption, we recommend that you install and update new agents with the latest version, and include the content package built in using SCCM.
   * **Enable minor content version updates:** The Cortex XDR research team releases more frequent content updates in-between major content versions to ensure your network is constantly protected against the latest and newest threats in the wild. Enabled by default, the Cortex XDR agent receives minor content updates, starting with the next content releases. To learn more about the minor content numbering format, refer to the [About content updates](/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/about-content-updates.md) topic.
4. Configure content bandwidth allocated for all endpoints.

   To control the amount of bandwidth allocated in your network to Cortex XDR content updates, assign a **Content bandwidth management** value between 20-10,000 Mbps. To help you with this calculation, Cortex XDR recommends the optimal value of Mbps based on the number of active agents in your network, and including overhead considerations for large content updates. Cortex XDR verifies that agents attempting to download the content update are within the allocated bandwidth before beginning the distribution. If the bandwidth has reached its cap, the download will be refused and the agents will attempt again at a later time. After you set the bandwidth, **Save** the configuration.
5. Configure the Cortex XDR agent number of parallel upgrades.

   If Agent auto upgrades are enabled for your Cortex XDR agents, you can control the automatic upgrade process in your network. To better control the rollout of a new Cortex XDR agent release in your organization, during the first week only a single batch of agents is upgraded. After that, auto-upgrades continue to be deployed across your network with number of parallel upgrades as configured.

   * **Amount of Parallel Upgrades:** Set the number of parallel agent upgrades, where the maximum is 2000 agents. When you configure this, keep in mind your organization's bandwidth usage and resource consumption.
6. Configure automated Advanced Analysis of Cortex XDR Agent alerts raised by exploit protection modules.

   Advanced Analysis is an additional verification method you can use to validate the verdict issued by the Cortex XDR agent. In addition, Advanced Analysis also helps Palo Alto Networks researchers tune exploit protection modules for accuracy.

   To initiate additional analysis you must retrieve data about the alert from the endpoint. You can do this manually on an alert-by-alert basis or you can enable Cortex XDR to automatically retrieve the files.

   After Cortex XDR receives the data, it automatically analyzes the memory contents and renders a verdict. When the analysis is complete, Cortex XDR displays the results in the **Advanced Analysis** field of the Additional data view for the data retrieval action on the **Action Center**. If the Advanced Analysis verdict is benign, you can avoid subsequent blocked files for users that encounter the same behavior by enabling Cortex XDR to automatically create and distribute exceptions based on the Advanced Analysis results.

   1. Configure the desired options:
      * Enable Cortex XDR to automatically upload defined alert data files for advanced analysis. Advanced Analysis increases the Cortex XDR exploit protection module accuracy.
      * Automatically apply Advanced Analysis exceptions to your Global Exceptions list. This will apply all Advanced Analysis exceptions suggested by Cortex XDR, regardless of the alert data file source.
   2. **Save** the Advanced Analysis configuration.
7. Configure the Cortex XDR Agent license revocation and deletion period.

   This configuration applies to standard endpoints only and does not impact the license status of agents for VDIs or Temporary Sessions.

   1. Configure the desired options:
      * **Connection Lost (Days):** Configure the number of days after which the license should be returned when an agent loses the connection to Cortex XDR. Default is 30 days; Range is 2 to 60 days. Day one is counted as the first 24 hours with no connection.
      * **Agent Deletion (Days):** Configure the number of days after which the agent and related data is removed from the Cortex XDR management console and database. Default is 180 days; Range is 3 to 360 days and must exceed the **Connection Lost** value. Day one is the first 24 hours of lost connection.
   2. Click **Save** to save the Agent Status configuration.
8. Enable WildFire analysis scoring for files with Benign verdicts.

   The WildFire analysis score for files with a Benign verdict is used to indicate the level of confidence WildFire has in the Benign verdict. For example, a file by a trusted signer or a file that was tested manually gets a high confidence Benign score, whereas a file that did not display any suspicious behavior at the time of testing gets a lower confidence Benign score. To add an additional verification method to such files, enable this setting. After this, when Cortex XDR receives a Benign Low Confidence verdict, the agent enforces the Malware Security profile settings you currently have in place (**Run local analysis** to determine the file verdict, **Allow**, or **Block**).

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Disabling this capability takes immediate effect on new hashes, fresh agent installations, and existing security policies. It could take up to a week to take effect on existing agents in your environment pending agent caching.</p></div>
9. Enable Informative BTP Alerts.

   Behavioral threat protection (BTP) alerts have been given unique and informative names and descriptions, to provide immediate clarity into the events without having to drill down into each alert. Enable to display of the informative BTP rule alert names and descriptions. After you update the settings, new alerts include the changes while already existing alerts remain unaffected.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you have any Cortex XDR filters, starring policies, exclusion policies, scoring rules, log forwarding queries, or automation rules configured for XSOAR/3rd party SIEM, we advise you to update those to support the changes before activating the feature. For example, change the query to include the previous description that is still available in the new description, instead of searching for an exact match.</p></div>
10. Configure settings for periodic cleanup of duplicate entities in the endpoint administration table.

    When enabled, **Periodic duplicate cleanup** removes all duplicate entries of an endpoint from the endpoint table based on the defined parameters, leaving only the last occurrence of the endpoint reporting to the server. This enables you to streamline and improve the management of your endpoints. For example, when an endpoint reconnects after a hardware change, it may be re-registered, leading to confusion in the endpoint administration table regarding the real status of the endpoint. The cleanup leaves only the latest record of the endpoint in the table.

    * Define whether to clean up according to **Host Name**, **Host IP Address**, **MAC Address**, or any combination of them. If not selected, the default is Host Name. When you select more than one parameter, duplicate entries are removed only if they include all the selected parameters.
    * Configure the frequency of the cleanup: every 6 hours, 12 hours, 1 day, or 7 days. You can also select to perform an immediate **One-time cleanup**.

    Data for a deleted endpoint is retained for 90 days since the endpoint’s last connection to the system. If a deleted endpoint reconnects, Cortex XDR recovers its existing data.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/pre-installation-steps-for-cortex-xdr-agents.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
