Cortex XDR by Palo Alto Networks (v6.3.36)

Automates Cortex XDR incident response, and includes custom Cortex XDR incident views and layouts to aid analyst investigations.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Endpoint

Incident fields (39)

Indicator fields (1)

Integrations (3)

Layouts (6)

Playbooks (37)

Scripts (16)

README

Cortex XDR is a detection and response app that natively integrates network, endpoint, and cloud data to stop sophisticated attacks. Responding and managing these attacks requires security teams to reconcile data from multiple sources. Valuable time is lost shuttling between screens and executing repeatable tasks while an attack continues to manifest.

This Cortex XDR content pack contains the Palo Alto Networks Cortex XDR - Investigation and Response integration that enables direct execution of Cortex XDR actions within Cortex XSOAR. The Cortex XDR Incident Handling v3 playbook enables bidirectional incident updates between Cortex XDR and Cortex XSOAR.

Note: This pack is also compatible with Cortex XSIAM when connecting to Cortex XSIAM from Cortex XSOAR.

What does this pack do?

The playbooks included in this pack help you save time and keep your incidents in sync. They also help automate repetitive tasks associated with Cortex XDR incidents:

As part of this pack, you will also get out-of-the-box Cortex XDR incident type views, with incident fields and a full layout to facilitate analyst investigation. All of these are easily customizable to suit the needs of your organization.

For more information, visit our Cortex XSOAR Developer Docs

Cortex XDR Lite - Incident Handling