Cortex XDR: Safeguard Your Entire Organization With The Industry's First Extended Detection and Response Platform
Cortex XDR: Safeguard Your Entire Organization With The Industry's First Extended Detection and Response Platform
NGFW VM-
Series
Figure 3: Analysis of data from any source for detection and response
Operational Benefits
Block known and unknown attacks with powerful endpoint protection: Leverage AI-based local analysis and Behavioral
Threat Protection to stop the most malware, exploits, and fileless attacks in the industry.
Gain visibility across network, endpoint, and cloud data: Collect and correlate data from Palo Alto Networks and third-party
tools to detect, triage, investigate, hunt, and respond to threats.
Automatically detect sophisticated attacks 24/7: Use always-on AI-based analytics and custom rules to detect advanced
persistent threats and other covert attacks.
Avoid alert fatigue and personnel turnover: Simplify investigations with automated root cause analysis and a unified incident
engine, resulting in a 98% reduction in alerts and lowering the skill required to triage alerts.
Increase SOC productivity: Consolidate endpoint security policy management and monitoring, investigation, and response
across your network, endpoint, and cloud environments in one console, increasing SOC efficiency.
Eradicate threats without business disruption: Shut down attacks with surgical precision while avoiding user or system
downtime.
Eliminate advanced threats: Protect your network against malicious insiders, policy violations, external threats, ransomware,
fileless and memory-only attacks, and advanced zero-day malware.
Supercharge your security team: Disrupt every stage of an attack by detecting indicators of compromise (IOCs), anomalous
behavior, and malicious patterns of activity.
Restore hosts to a clean state: Simplify response with recommended next steps for remediation. You can rapidly recover from
an attack by removing malicious files and registry keys, as well as restoring damaged files and registry keys.
Extend detection, investigation, and response to third-party data sources: Enable behavioral analytics on logs collected from
third-party firewalls while integrating third-party alerts into a unified incident view and root cause analysis for faster, more
effective investigations.
Malware, ransomware, and fileless attack prevention Customizable prevention rules (available with Cortex XDR Pro)
Behavioral Threat Protection Endpoint script execution (available with Cortex XDR Pro)
Network isolation, quarantine, process termination, file deletion,
AI-based local analysis engine
file block list
Cloud-based malware prevention with WildFire Live Terminal for direct endpoint access
Exploit prevention by exploit technique Public APIs for response and data collection
Disk encryption with BitLocker and FileVault Optional automatic agent upgrades
Partner-Delivered MDR Service Benefits
24/7 year-round monitoring and alert management Reduction of MTTD and MTTR
Custom tuning of Cortex XDR for enhanced prevention, visibility,
Investigation of every alert and incident generated by Cortex XDR
and detection
Guided or full threat remediation actions Direct access to partners’ analysts and forensic experts
Cortex XDR Prevent subscription Endpoint protection with Cortex XDR agents
Cortex XDR Managed Threat Hunting subscription 24/7 threat hunting powered by Cortex XDR and Unit 42 experts
3000 Tannery Way © 2020 Palo Alto Networks, Inc. Palo Alto Networks is a registered
Santa Clara, CA 95054 trademark of Palo Alto Networks. A list of our trademarks can be found at
https://www.paloaltonetworks.com/company/trademarks.html. All other
Main: +1.408.753.4000 marks mentioned herein may be trademarks of their respective companies.
Sales: +1.866.320.4788 cortex-xdr-ds-110920
Support: +1.866.898.9087
www.paloaltonetworks.com