Contact sales
Details

Palo Alto Networks Cortex XDR is an Extended Detection and Response (XDR) and Endpoint Detection and Response (EDR) offering.

Palo Alto Networks Cortex XDR is an Extended Detection and Response (XDR) solution that includes an Endpoint Detection and Response (EDR) offering. Leveraging Palo Alto Networks EDR alerts enables you to query security detections of observables, including IP addresses, process names, file names, file paths, MD5 hashes, SHA256 hashes, registry keys, hostnames, and Cortex agent IDs. Note: Integration with EDR requires a Cortex XDR Pro per endpoint license.

Additionally, the integration allows you to leverage Cortex response actions to respond to incidents or proactively mitigate threats in multiple ways, including:

  • Adding files to blocklists.

  • Quarantining or unquarantining endpoints.

  • Performing malware scans on endpoints.

Capabilities
Automation
Automatic target creation for Cisco XDR automation
Health
Validates that the integration is healthy
Deliberate
Provides dispositions for observables
Observe
Provides sightings for an observable
Refer
Provides links to additional resources for an observable
Device Insights
Provides information about assets
Regions
North America
Europe
Asia-Pacific, Japan & China
Installable workflows

These are workflows that you can install in Cisco XDR automation and use with this integration. These are different from built-in workflows which are built into Cisco XDR by default for all customers.

Cisco Managed
This workflow appears in the pivot menu and allows a user to add a file hash to an allow list in Palo Alto Networks Cortex XDR.
Cisco Managed
This workflow appears in the pivot menu and allows a user to add a file hash to a block list in Palo Alto Networks Cortex XDR.
Cisco Managed
This workflow appears in the pivot menu and allows a user to isolate an endpoint in Palo Alto Networks Cortex XDR.
Cisco Managed
This workflow appears in the pivot menu and allows a user to trigger an endpoint scan in Palo Alto Networks Cortex XDR.
Cisco Managed
This workflow appears in the pivot menu and allows a user to unisolate an endpoint in Palo Alto Networks Cortex XDR.
Built-in workflows

These workflows are built into Cisco XDR automation and can be used with this integration. These are different from installable workflows, which are optional workflows you can install from Cisco and its partners.

Configuration details