Cortex XDR
Cortex XDR
Cortex XDR delivers peace of mind with industry-leading endpoint security that achieved the
highest combined protection and detection scores in the 2022 MITRE ATT&CK Evaluations. The
Cortex XDR platform collects and analyzes all data, so you can gain complete visibility and holistic
protection to secure what’s next.
Get Full Visibility Across Your Entire Environment - Cortex XDR automatically stitches together
endpoint, network, cloud, and identity data to accurately detect attacks and simplify
investigations. Third-party alerts are dynamically integrated with endpoint data to reveal root
cause and save hours of analysts’ time.
Discover Threats with Analytics and Machine Learning - Using machine learning, Cortex XDR
continuously profiles endpoint and network behavior to detect anomalous activity indicative of
attacks. It provides a 360-degree view of users, including user risk scores, for user behavior
analytics (UBA).
Gain Deeper Insights with Global Analytics – XDR’s Global Analytics system harnesses
cross-customer insights for you to identify advanced threats, such as supply chain and zero-day
attacks. By applying analytics to an integrated set of data, Cortex XDR can detect evasive threats
that siloed endpoint, network, and cloud detection and response tools miss.
Investigate at Lightning Speed - Each incident within Cortex XDR provides you with a complete
picture of an attack, with key artifacts and threat intelligence details. Furthermore, XDR’s
SmartScore identifies high-risk incidents with machine learning, empowering your team to
quickly assess attack scope and impact.
Orchestrate, Automate, and Enrich with Cortex XSOAR – Cortex XDR tightly integrates with
Cortex XSOAR, enabling your teams to feed incident data for automated response based on 900+
product integrations. XSOAR playbooks can automatically ingest Cortex XDR incidents, retrieve
related alerts, and update incident fields in Cortex XDR. It also links insights to incidents in real
time, giving you unmatched visibility into the global threat landscape, and automating the
distribution of your threat intelligence at scale.
Onboarding all your data sources into Cortex XDR enables you to broaden the scope of threat
hunting and eliminate blind spots. XDR detects advanced attacks with AI, analytics, and
out-of-the-box rules, allowing your team to triage and contain threats quickly. It also simplifies
triage and investigations by automatically revealing the root cause, reputation, and attack
sequence associated with each alert. By grouping alerts into incidents, Cortex XDR slashes the
number of individual alerts to review by up to 98%, reducing alert fatigue.
Furthermore, with XDR Pro's dissolvable agent, you can collect forensics data without the need to
maintain the complete agent on your endpoint. Instead, you deploy it just once. The dissolvable
agent can be installed on the affected device, performs a one-time data collection, and then
uninstalls itself.
Manage Insider and Identity Risk with Identity Analytics and ITDR
With Cortex XDR’s Identity Analytics add-on (see data sheet), you can use advanced data
collection and analytics to identify abnormal user and entity activity to defend against
compromised user accounts and malicious insiders. Identity analytics allows you to gain visibility
by ingesting user activity data feeds (from endpoints, agents, firewalls, Active Directory, and
more). It also applies machine learning and behavioral analytics built into analytic detectors that
are continuously updated and created by Cortex threat researchers and data sciences experts.
By combining advanced detection capabilities as part of identity analytics with the new Identity
Threat Detection and Response (ITDR) Module that protects against identity threats later on
along the attack lifecycle, you can swiftly identify and investigate identity-related threats, assess
impact through scoring, visualize trends and profiles, and reduce the risk of data breaches.
With Cortex XDR, you can choose MDR services from Unit 42 as well as our extensive ecosystem of
XMDR partners.
The cloud-native Cortex XDR platform offers streamlined deployment, eliminating the need to
deploy new on-premises log storage or network sensors. You can install and upgrade the
lightweight Cortex XDR agent without rebooting your endpoints. To protect cloud workloads, you
can install the Cortex XDR agent in private and public cloud environments, including AWS,
Google Cloud, and Microsoft Azure. Kubernetes integration eases deployment to containers.
Next-Generation Antivirus ✓ ✓
Block malware, ransomware, exploits
and fileless attacks
Endpoint Protection ✓ ✓
Safeguard endpoints with device control,
firewall and disk encryption
Host Insights ✓
Find vulnerabilities and sweep across
endpoints to eradicate threats
Forensics Investigation ✓
Investigate incidents swiftly with
comprehensive forensics evidence
collection
Integrations ✓ ✓ ✓
Threat intelligence solutions, Slack, send
syslog
Security Analytics ✓ ✓
Apply machine learning and UEBA
detections to security data
Resources
Cortex XDR At-A-Glance
Cortex XDR Help Center
Customer Success Datasheet
Customer Service Portal