Palo Alto Networks Cortex XDR Integration

Note: This integration requires Cisco XDR Advantage or Cisco XDR Premier licensing tier.

Palo Alto Networks Cortex XDR is an Extended Detection and Response (XDR) solution that includes an Endpoint Detection and Response (EDR) offering. Leveraging Palo Alto Networks EDR alerts enables you to query security detections of observables including IP addresses, process names, file names, file paths, MD5 hashes, SHA-256 hashes, registry keys, hostnames, and Cortex agent IDs. Enabling this integration also provides a target in Cisco XDR automation for automated workflows.

Note: Integration with Cortex XDR requires a Cortex XDR Pro per endpoint license.