Connect your own Palo Alto Networks Cortex XDR tenant to manage Incidents, Alerts, Endpoints (isolate/unisolate, scan), custom IOCs, and remote script execution via the Action Center.
connect_cortex_xdrwriteConnect your own Palo Alto Networks Cortex XDR tenant (Standard API key + key ID + tenant FQDN), verifying the credentials with a real call before saving.
list_connectionsreadList connected Cortex XDR tenants.
disconnect_cortex_xdrwriteDisconnect a Cortex XDR tenant, removing its stored API key.
list_incidentsreadList incidents on the connected Cortex XDR tenant, optionally filtered by status.
get_incidentreadRead one Cortex XDR incident in full, including its related alerts.
update_incidentwriteUpdate an existing Cortex XDR incident's status, assignee, or severity. A resolve_comment is required when status starts with 'resolved'.
list_alertsreadList alerts on the connected Cortex XDR tenant, optionally restricted to one incident.
list_endpointsreadList endpoints (hosts) enrolled in the connected Cortex XDR tenant.
isolate_endpointwriteIsolate an endpoint from the network -- cuts almost all network access immediately except the Cortex XDR agent channel. Use only for active threat containment.
unisolate_endpointwriteRestore an isolated endpoint's normal network access.
scan_endpointwriteTrigger an on-demand malware scan on one or more endpoints.
list_iocsreadList custom Indicators (IOCs) configured on the connected Cortex XDR tenant.
create_iocwriteCreate a custom Indicator (IOC) on the connected Cortex XDR tenant to flag or block a hash, IP, domain, or path fleet-wide.
remove_iocwriteRemove a custom Indicator (IOC) from the connected Cortex XDR tenant.
list_scriptsreadList scripts available in the connected Cortex XDR tenant's Action Center library.
run_scriptwriteRun an approved Action Center script against one or more endpoints -- executes real code on live hosts, use with care.
get_script_run_resultsreadRead the per-endpoint results of a previously run Action Center script by its action_id.
audit_cortex_tenantreadBuild one aggregated health report across the connected Cortex XDR tenant: open incidents by severity, unassigned High/Critical incidents, and disconnected endpoints.
Install Cortex XDR (Palo Alto Networks) and let Webbee use it across your workflow.
Open in panel