0% found this document useful (0 votes)
280 views7 pages

Cortex XDR: Safeguard Your Entire Organization With The Industry's First Extended Detection and Response Platform

Uploaded by

Amanuel
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
280 views7 pages

Cortex XDR: Safeguard Your Entire Organization With The Industry's First Extended Detection and Response Platform

Uploaded by

Amanuel
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 7

Business Benefits

• Detect advanced attacks with analytics:


Uncover threats with AI, behavioral
Cortex XDR
analytics, and custom detection rules.
Safeguard Your Entire Organization
• Reduce alerts by 98%: Avoid alert fatigue
with a game-changing unified incident with the Industry’s First Extended
engine that intelligently groups related
alerts.
Detection and Response Platform
• Investigate eight times faster: Verify Security teams are inundated with inaccurate,
threats quickly by getting a complete incomplete alerts. Today’s siloed security tools force
picture of attacks with root cause analysis.
analysts to pivot from console to console to piece
• Stop attacks without degrading
performance: Obtain the most effective together investigative clues, resulting in painfully
endpoint protection available with a slow investigations and missed attacks. Even though
lightweight agent.
they’ve deployed countless tools, teams still lack the
• Maximize ROI: Use ­existing ­infrastructure
for data ­collection and control to lower enterprise-wide visibility and deep analytics needed
costs by 44%. to find threats. Faced with a shortage of security
professionals, teams must simplify operations.

Cortex by Palo Alto Networks | Cortex XDR | Datasheet 1


Prevent, Detect, Investigate, and Investigate and Respond at
Respond to All Threats ­Lightning Speed
Cortex XDR™ is the world’s first extended detection and Cortex XDR accelerates investigations by providing a complete
­response platform that integrates endpoint, network, and picture of every threat and automatically revealing the root
cloud data to stop sophisticated attacks. It unifies prevention, cause. Intelligent alert grouping and alert deduplication sim-
detection, investigation, and response in one platform for plify triage and reduce the experience required at every stage of
unrivaled security and operational efficiency. Combined with security operations. Tight integration with enforcement points
our Managed Threat Hunting service, Cortex XDR gives you lets analysts respond to threats quickly.
round-the-clock protection and industry-leading coverage
of MITRE ATT&CK® techniques.
Key Capabilities
Block the Most Endpoint Attacks Safeguard Your Assets with Industry-Best
­Endpoint Protection
with Best-in-Class Prevention Prevent threats and collect data for detection and response
The Cortex XDR agent safeguards endpoints from malware, with a single, cloud native agent. The Cortex XDR agent ­offers
­exploits, and fileless attacks with industry-best, AI-­driven a complete prevention stack with cutting-edge protection for
­local analysis and behavior-based protection. Organizations exploits, malware, ransomware, and fileless attacks. It ­includes
can stop never-before-seen threats with a single cloud-­ the broadest set of exploit protection modules available to
delivered agent for endpoint protection, detection, and block the exploits that lead to malware infections. Every file is
­response. The agent shares protections across network and examined by an adaptive AI-driven local analysis ­engine that’s
cloud security offerings from Palo Alto Networks to provide always learning to counter new attack techniques. A ­Behavioral
ironclad, consistent ­security across the entire enterprise. Threat Protection engine examines the behavior of multiple,
related processes to uncover attacks as they occur. Integration
with the Palo Alto Networks WildFire® malware prevention
Detect Stealthy Threats with service boosts security accuracy and coverage. Visit us online to
­Machine Learning and Analytics read more about endpoint protection.

Cortex XDR identifies evasive threats with unmatched ­accuracy


by continuously profiling user and endpoint behavior with
­analytics. Machine learning models analyze data from Palo
Alto Networks and third-party sources to uncover stealthy
­attacks targeting managed and unmanaged devices.

Figure 1: Cortex XDR triage and investigation view

Cortex by Palo Alto Networks | Cortex XDR | Datasheet 2


Securely Manage USB Devices Get Full Visibility with Comprehensive Data
Protect your endpoints from malware and data loss with Break security silos by integrating all data. Cortex XDR auto-
­Device Control. The Cortex XDR agent allows you to moni- matically stitches together endpoint, network, and cloud data to
tor and secure USB access without needing to install another accurately detect attacks and simplify investigations. It collects
agent on your hosts. You can restrict usage by vendor, type, data from Palo Alto Networks products as well as third-party
endpoint, and Active Directory® group or user. Granular logs and alerts, enabling you to broaden the scope of intelligent
­policies allow you to assign write or read-only permissions decisions across all network segments. Third-party alerts are
per USB device. dynamically integrated with endpoint data to reveal root cause
and save hours of analysts’ time. Cortex XDR examines logs
Protect Endpoint Data with Host Firewall and collected from third-party firewalls with behavioral analytics,
Disk Encryption enabling you to find critical threats and eliminate any visibility
Reduce the attack surface of your endpoints. With host fire- blind spots.
wall and disk encryption capabilities, you can lower your
­security risks as well as address regulatory requirements. Discover Threats with Continuous ML-Based
The Cortex XDR host firewall enables you to control ­inbound Threat Detection
and outbound communications on your Windows® and Find stealthy threats with analytics and out-of-the-box
­macOS® endpoints. Additionally, you can apply BitLocker® rules that deliver unmatched MITRE ATT&CK coverage.­
or ­FileVault® encryption on your endpoints by creating disk ­Cortex XDR automatically detects active attacks, allowing
­encryption rules and policies. Cortex XDR provides full visibil- your team to triage and contain threats before the damage is
ity into endpoints that were encrypted and lists all ­encrypted done. Using machine learning, Cortex XDR continuously pro-
drives. Host firewall and disk encryption capabilities let you files user and endpoint behavior to detect anomalous activity
­centrally configure your endpoint security policies from the indicative of attacks. By applying analytics to an integrated set
Cortex XDR management console. of data, ­including security alerts and rich network, endpoint,
and cloud logs, Cortex XDR meets and exceeds the detection
capabilities of siloed network traffic analysis (NTA), endpoint
detection and response (EDR), and user behavior analytics
(UBA) tools. Automated detection works all day, every day,
providing you peace of mind.

Figure 2: Customizable dashboard

Cortex by Palo Alto Networks | Cortex XDR | Datasheet 3


Investigate Eight Times Faster presents detailed information about your host applications
Automatically reveal the root cause of every alert. With ­Cortex and settings while Search and Destroy lets you swiftly find and
XDR, your analysts can examine alerts from any source— eradicate threats across all endpoints. Host Insights ­offers a
­including third-party tools—with a single click, ­streamlining holistic approach to endpoint visibility and attack contain-
investigations. Cortex XDR automatically reveals the root ment, helping reduce your exposure to threats so you can
cause, reputation, and sequence of events associated with each avoid future breaches.
alert, lowering the experience level needed to verify an attack.
By consolidating alerts into incidents, Cortex XDR slashes
24/7 Threat Hunting Powered by Cortex XDR
the number of individual alerts to review and alleviates alert
and Unit 42 Experts
­fatigue. Each incident provides a complete picture of an attack, Augment your team with the industry’s first threat ­hunting
with key artifacts and integrated threat intelligence details, service operating across endpoint, network, and cloud
accelerating investigations. data. Cortex XDR Managed Threat Hunting offers round-
the-clock monitoring from world-class threat hunters to
Hunt for Threats with Powerful Search Tools ­discover ­attacks anywhere in your environment. Our Unit 42
Uncover hidden malware, targeted attacks, and insider experts work on your behalf to discover advanced threats,
threats. Your security team can search, schedule, and save such as state-sponsored attackers, cybercriminals, ­malicious
queries to identify hard-to-find threats. Flexible searching ­insiders, and malware. To detect adversaries hiding in your
capabilities let your analysts unearth threats using an intui- ­organization, our hunters comb through comprehensive
tive Query Builder as well as construct advanced queries and data from Palo Networks and third-party security solutions.
visualize results with XQL Search. By integrating threat in- Detailed Threat Reports reveal the tools, steps, and scope of
telligence with an extensive set of ­security data, your team attacks so you can root out adversaries quickly, while Impact
can catch malware, external threats, and malicious insiders. Reports help you stay ahead of emerging threats.
An Asset ­Management ­feature streamlines network man-
agement and reveals potential threats by showing you all
Natively Integrate with Cortex XSOAR for
the devices in your environment, including managed and
­Security Orchestration and Automation
­unmanaged devices. Standardize and automate response processes across your
security product stack. Cortex XDR integrates with Cortex™
Coordinate Response Across Endpoint, XSOAR, our security orchestration, automation, and response
­Network, and Cloud Enforcement Points platform, enabling your teams to feed incident data into Cortex
Stop threats with fast and accurate remediation. Cortex XSOAR for automated, playbook-driven response that spans
XDR lets your security team instantly contain endpoint, net- more than 450 product integrations and promotes cross-team
work, and cloud threats from one console. Your analysts can collaboration. Cortex XSOAR playbooks can automatically
quickly stop the spread of malware, restrict network activ- ­ingest Cortex XDR incidents, retrieve related alerts, and update
ity to and from devices, and update prevention lists like bad incident fields in Cortex XDR as playbook tasks.
domains through tight integration with enforcement points.
The ­powerful Live Terminal feature lets Tier 1 analysts ­swiftly
Unify Management, Reporting, Triage, and
­investigate and shut down attacks without disrupting end
­Response in One Intuitive Console
­users by directly accessing endpoints; running Python®, Maximize productivity with a seamless platform experience.
­PowerShell®, or system commands and scripts; and managing The management console offers end-to-end support for all
files and processes from graphical file and task managers. Cortex XDR capabilities, including endpoint policy manage-
ment, detection, investigation, and response. You can quickly
Get Unprecedented Visibility and Swift assess the security status of your organization’s or individual
­Response with Host Insights endpoints with customizable dashboards as well as summa-
Understand your risks and contain threats quickly before they rize incidents and security trends with graphical reports that
can spread. Host Insights, an add-on module for Cortex XDR, can be scheduled or generated on demand. Public APIs extend
combines vulnerability management, application and system management to third-party tools, enabling you to retrieve and
visibility, and a powerful Search and Destroy feature to help ­update incidents, collect agent information, and contain end-
you identify and contain threats. Vulnerability ­Management point threats from the management platform of your choice.
provides you real-time visibility into ­vulnerability exposure
and current patch levels across your endpoints. Host ­inventory

Cortex by Palo Alto Networks | Cortex XDR | Datasheet 4


Cortex XDR

NGFW VM-
Series

Network Endpoint Cloud Third Party

Figure 3: Analysis of data from any source for detection and response

Operational Benefits
Block known and unknown attacks with powerful endpoint protection: Leverage AI-based local analysis and Behavioral
Threat Protection to stop the most malware, exploits, and fileless attacks in the industry.
Gain visibility across network, endpoint, and cloud data: Collect and correlate data from Palo Alto Networks and third-party
tools to detect, triage, investigate, hunt, and respond to threats.
Automatically detect sophisticated attacks 24/7: Use always-on AI-based analytics and custom rules to detect advanced
­persistent threats and other covert attacks.
Avoid alert fatigue and personnel turnover: Simplify investigations with automated root cause analysis and a unified incident
engine, resulting in a 98% reduction in alerts and lowering the skill required to triage alerts.
Increase SOC productivity: Consolidate endpoint security policy management and monitoring, investigation, and response
across your network, endpoint, and cloud environments in one console, increasing SOC efficiency.
Eradicate threats without business disruption: Shut down attacks with surgical precision while avoiding user or system
downtime.
Eliminate advanced threats: Protect your network against malicious insiders, policy violations, external threats, ransomware,
fileless and memory-only attacks, and advanced zero-day malware.
Supercharge your security team: Disrupt every stage of an attack by detecting indicators of compromise (IOCs), anomalous
behavior, and malicious patterns of activity.
Restore hosts to a clean state: Simplify response with recommended next steps for remediation. You can rapidly recover from
an attack by removing malicious files and registry keys, as well as restoring damaged files and registry keys.
Extend detection, investigation, and response to third-party data sources: Enable behavioral analytics on logs collected from
third-party firewalls while integrating third-party alerts into a unified incident view and root cause analysis for faster, more
effective investigations.

Cortex by Palo Alto Networks | Cortex XDR | Datasheet 5


Ease Deployment with Cloud Delivery such as Next-Generation Firewalls or Cortex XDR agents, to
Get started in minutes. The cloud native Cortex XDR ­platform ­detect and stop threats, but additional sources can eliminate
offers streamlined deployment, eliminating the need to blind spots. Easily store data in Cortex Data Lake, a scalable
­deploy new on-premises network sensors or log collectors. and ­efficient cloud-based data repository. By integrating
You can use your Palo Alto Networks products or third-­ data from multiple sources together, automating tasks, and
party firewalls to collect data, reducing the number of prod- ­simplifying management, Cortex XDR delivers a 44% cost
ucts you need to manage. You only need one source of data, savings compared to siloed security tools.

Table 1: Cortex XDR Features and Specifications


Detection and Investigation Features and Capabilities

Automated stitching of network, endpoint, and cloud


Machine learning-based behavioral analytics
data from Palo Alto Networks and third-party sources
Third-party alert and log ingestion from any source with
Custom rules to detect tactics, techniques, and procedures
­required network information
Third-party log data from Check Point, Fortinet, Cisco
ASA firewalls, Okta, PingOne, Azure Active Directory, Root cause analysis of alerts
Google Cloud, and Windows Event Collector
Host Insights add-on module, providing Vulnerability
Asset management
Management, Search and Destroy, and Host Inventory
Cortex XDR Managed Threat Hunting service Timeline analysis of alerts
Malware and fileless attack detection Unified incident engine
Detection of targeted attacks, malicious insiders, and
Post-incident impact analysis
risky user behavior
Network detection and response (NDR) and user
Dashboards and reporting
­behavior a
­ nalytics (UBA)
Endpoint detection and response (EDR) Threat intelligence integration
Native integration with Cortex XSOAR for orchestration,
Threat hunting
­automation, and response
Incident management Incident response and recovery
Endpoint Protection Capabilities

Malware, ransomware, and fileless attack prevention Customizable prevention rules (available with Cortex XDR Pro)

Behavioral Threat Protection Endpoint script execution (available with Cortex XDR Pro)
Network isolation, quarantine, process termination, file deletion,
AI-based local analysis engine
file block list
Cloud-based malware prevention with WildFire Live Terminal for direct endpoint access

Remediation suggestions for host restore (available with Cortex


Child process protection
XDR Pro)

Exploit prevention by exploit technique Public APIs for response and data collection

Device control for USB device management Credential theft protection

Host firewall Scheduled and on-demand malware scanning

Disk encryption with BitLocker and FileVault Optional automatic agent upgrades
Partner-Delivered MDR Service Benefits

24/7 year-round monitoring and alert management Reduction of MTTD and MTTR
Custom tuning of Cortex XDR for enhanced prevention, visibility,
Investigation of every alert and incident generated by Cortex XDR
and detection
Guided or full threat remediation actions Direct access to partners’ analysts and forensic experts

Cortex by Palo Alto Networks | Cortex XDR | Datasheet 6


Table 1: Cortex XDR Features and Specifications (continued)
Specification Cortex XDR

Delivery model Cloud-delivered application

Data retention 30-day to unlimited data storage

Cortex XDR Prevent subscription Endpoint protection with Cortex XDR agents

• Detection, investigation, and response across endpoint data


Cortex XDR Pro per endpoint subscription sources
• Endpoint protection with Cortex XDR agents

Detection, investigation, and response across network and cloud


Cortex XDR Pro per TB subscription
data sources, including third-party data

Cortex XDR Managed Threat Hunting subscription 24/7 threat hunting powered by Cortex XDR and Unit 42 experts

Collects process information from endpoints that do not have


Cortex XDR Pathfinder endpoint analysis service
­Cortex XDR agents; included with all Cortex XDR subscriptions

Reinvent Security Operations Operating System Support


with Cortex The Cortex XDR agent supports multiple endpoints across
Windows, macOS, Linux, Chrome® OS, and Android® ­operating
Cortex XDR is part of Cortex™, the industry’s most compre-
systems. For a complete list of system requirements and sup-
hensive product suite for security operations, ­empowering
ported operating systems, please visit the Palo Alto Networks
­enterprises with best-in-class detection, investigation,
­Compatibility Matrix. Cortex XDR ­Pathfinder ­minimum re-
­automation, and response capabilities. The suite is built on
quirements: 2 CPU cores, 8 GB RAM, 128 GB thin-provisioned
the tightly ­integrated offerings of Cortex XDR and Cortex
storage, VMware ESXi™ V5.1 or higher, or Microsoft Hyper-V®
XSOAR, enabling you to transform your SOC operations from
6.3.96 or higher hypervisor.
a ­manual, reactive model that required endless resources to a
lean, ­proactive, and automated team that reduces both MTTD
and MTTR for every security use case.

3000 Tannery Way © 2020 Palo Alto Networks, Inc. Palo Alto Networks is a registered
Santa Clara, CA 95054 ­trademark of Palo Alto Networks. A list of our trademarks can be found at
https://www.paloaltonetworks.com/company/trademarks.html. All other
Main: +1.408.753.4000 marks mentioned herein may be trademarks of their respective companies.
Sales: +1.866.320.4788 cortex-xdr-ds-110920
Support: +1.866.898.9087

www.paloaltonetworks.com

You might also like