Palo Alto Networks Cortex

**Important**

This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../marketplace).

This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.

Unit 42 Threat Intelligence by Palo Alto Networks delivers high-fidelity threat intelligence curated by the Unit 42 research team and derived from telemetry across the Palo Alto Networks product ecosystem. Use the Unit 42 Feed integration to continuously fetch indicators and threat objects, and the Unit 42 Intelligence integration to enrich indicators (IP, domain, URL, file hash) with verdicts, threat object associations, and relationships.

This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):

* [Unit 42 Feed](https://xsoar.pan.dev/docs/reference/integrations/unit-42-feed): Unit 42 Feed integration provides threat intelligence from Palo Alto Networks Unit 42 research team.
* [Unit 42 Intelligence](https://xsoar.pan.dev/docs/reference/integrations/unit-42-intelligence): Enrich indicators with Unit 42 threat intelligence context including verdicts, threat object associations, and relationships.

To configure this connector, follow the steps outlined in the configuration wizard.