commonfields: id: Cortex XDR - IR CTF version: -1 name: Cortex XDR - IR CTF display: Cortex XDR - IR CTF category: Endpoint provider: Palo Alto Networks description: Cortex XDR is the world's first detection and response app that natively integrates network, endpoint, and cloud data to stop sophisticated attacks. sectionorder: - Collect configuration: - display: Fetch incidents name: isFetch defaultvalue: "true" type: 8 required: false section: Collect - display: Incident type name: incidentType type: 13 required: false section: Collect - display: Incident Mirroring Direction name: mirror_direction defaultvalue: None type: 15 required: false options: - None - Incoming - Outgoing - Both section: Collect - display: HTTP Timeout name: timeout defaultvalue: "120" type: 0 required: false additionalinfo: The timeout of the HTTP requests sent to Cortex XDR API (in seconds). section: Collect - display: Maximum number of incidents per fetch name: max_fetch defaultvalue: "201" type: 0 required: false additionalinfo: The maximum number of incidents per fetch. Cannot exceed 100. section: Collect - display: Only fetch starred incidents name: starred type: 8 required: false section: Collect - display: Starred incidents fetch window name: starred_incidents_fetch_window defaultvalue: 3 days type: 0 required: false additionalinfo: Starred fetch window timestamp (