Skip to main content

Overview

Cortex XDR Connection Guide: Connect Cortex XDR
Connection Method: API
Setup Time: 15-20 minutes
Access Required: Administrator account

Data collected

This integration provides:
  • Security event data
  • Threat intelligence
  • Asset visibility
  • Compliance information

Setup instructions

1

Log in to your account

Access your Cortex XDR dashboard with administrator credentials.
2

Create API credentials

Generate API credentials or tokens for ThreatAware integration:
  • Navigate to API or integrations settings
  • Create new API key/token
  • Copy credentials securely
3

Configure in ThreatAware

Complete the integration setup in ThreatAware:
  • Open ThreatAware and navigate to Settings > Integrations
  • Search for and select Cortex XDR
  • Enter the required credentials
  • Click Connect to establish the integration
4

Verify Connection

After connecting, ThreatAware will begin syncing data.
  • Check that the Integration Status shows as Active
  • Verify data is appearing in ThreatAware within 30 minutes

Required credentials

Field Name: Cortex XDR API Key
Type: String (encrypted)
Description: The API key or token generated in Cortex XDR
Store this credential securely in your organisation’s password manager for future reference.
Field Name: Cortex XDR Endpoint
Type: String
Description: The API endpoint or URL for your Cortex XDR instance
Format: Typically your instance URL or API endpoint
Example: https://api.cortex xdr.com or your instance URL

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the Cortex XDR integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait 30-60 minutes for the initial data sync
    • Search for known devices or assets in ThreatAware
    • Verify the Cortex XDR data is present
  3. Test Queries
    • Create a test query to filter devices with Cortex XDR data
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify the API key/token is correct and not expired
  • Check if the API credentials have sufficient permissions
  • Ensure the credentials were not modified or rotated
  • Regenerate credentials if needed and update ThreatAware
Symptoms: Integration fails to connect or times outSolutions:
  • Verify the endpoint URL is correct and accessible
  • Check firewall rules allow outbound HTTPS (443) to the endpoint
  • Confirm the Cortex XDR service is operational
  • Test the URL in a browser to ensure it’s reachable
Symptoms: Integration shows active but no data appearsSolutions:
  • Verify there is data available in Cortex XDR to collect
  • Check API permissions allow access to the required data
  • Contact support for integration logs and debugging
  • Confirm devices/assets exist in your Cortex XDR account

Additional resources

Cortex XDR API Documentation

Official Cortex XDR API documentation

ThreatAware Support

Contact support for integration assistance

Best practices

Credential Management
  • Create a dedicated API user/token specifically for ThreatAware
  • Document credentials in your organisation’s password manager
  • Rotate credentials annually or per your security policy
  • Monitor for authentication failures regularly
Security Considerations
  • Only grant minimum necessary permissions to API credentials
  • Review audit logs in Cortex XDR periodically to monitor API usage
  • Follow your organisation’s least privilege principles
  • Disable credentials immediately if they are compromised