Documentation — August 11, 2026
314 files changed, 354 insertions, 437 deletions — view the commit on the mirror.
Marketplace links restored on 296 data-source pages; Cloud Application Security rewritten with licensing
- 296 XSIAM data-source connector pages turned a plain-text Marketplace mention into a working link — the bulk of the day, and the only change on those pages.
- Cortex Cloud Application Security was rewritten around three use cases and now states which base licence each one needs.
- Nine Cortex XDR agent pages replaced their markdown tables with raw HTML, and several console names picked up bold.
- Outbound links in the agent guide moved from
docs-cortex.paloaltonetworks.comtoapp.gitbook.comspaces. - Nothing was added, deleted or renamed: all 316 files were modifications.
Highlights
-
Cortex Cloud Application Security now states its licence requirements
ASPM and Supply Chain Security are included with a Cloud Posture, Cloud Runtime or XSIAM Premium base licence, while Code Security requires a separate Application Security add-on purchase.
-
296 data-source pages gained a working Marketplace link
The notice that a connector is only available to tenants onboarded after July 26, 2026 now links "Marketplace" to ../../marketplace instead of naming it in plain text.
-
The agent guide's compatibility and release links now point at GitBook
Both references on the agent introduction moved from docs-cortex.paloaltonetworks.com to app.gitbook.com space URLs, and the Mac uninstall page gained a GitBook link where it previously had bare text.
-
The Azure BYOA security note was reframed from a statement of fact into a least-privilege claim
"BYOA grants the Terraform runner zero tenant-level Microsoft Graph permissions" became "BYOA mode leverages a least-privilege security model"; the mechanism described — write access through direct object ownership — is unchanged.
-
Requirements and cytool reference tables became raw HTML
Nine Cortex XDR agent pages swapped markdown pipe tables for <table> markup, which shows as a large deletion count against a single added line without any content changing.
-
The ITDR Conditional Access link was resolved out of broken-reference
It now points at the get-started-with-itdr#set-up-identity-profiles anchor, though the link text was split so only "Set up an Identity" is linked and "profile" trails outside it.
Changes
314 files listed, 15 written up and shaded below.
-
▸ ▾ CYFIRMA modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cyfirma/cyfirmaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# CYFIRMA# CYFIRMAhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.CYFIRMA's core platform, DeCYFIR, combines cyber threat intelligence with attack surface discovery and digital risk protection to deliver predictive, personalized, contextual, and multi-layered threat intelligence. This connector collects Access Logs, Asset Logs, and Digital Risk Keyword Logs automatically from DeCYFIR into Cortex XSIAM.CYFIRMA's core platform, DeCYFIR, combines cyber threat intelligence with attack surface discovery and digital risk protection to deliver predictive, personalized, contextual, and multi-layered threat intelligence. This connector collects Access Logs, Asset Logs, and Digital Risk Keyword Logs automatically from DeCYFIR into Cortex XSIAM.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # CYFIRMA {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. CYFIRMA's core platform, DeCYFIR, combines cyber threat intelligence with attack surface discovery and digital risk protection to deliver predictive, personalized, contextual, and multi-layered threat intelligence. This connector collects Access Logs, Asset Logs, and Digital Risk Keyword Logs automatically from DeCYFIR into Cortex XSIAM. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Darktrace modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/darktrace/darktraceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Darktrace# Darktracehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Enrich your security operations with Darktrace's self-learning AI. This connector fetches a list of model breaches, filtered by the specified parameters, so anomalous activity across your network, SaaS, cloud, and industrial environments is available alongside your other security data. Alerts from the connector populate as issues.Enrich your security operations with Darktrace's self-learning AI. This connector fetches a list of model breaches, filtered by the specified parameters, so anomalous activity across your network, SaaS, cloud, and industrial environments is available alongside your other security data. Alerts from the connector populate as issues.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Darktrace {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Enrich your security operations with Darktrace's self-learning AI. This connector fetches a list of model breaches, filtered by the specified parameters, so anomalous activity across your network, SaaS, cloud, and industrial environments is available alongside your other security data. Alerts from the connector populate as issues. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ DeHashed modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dehashed/dehashedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# DeHashed# DeHashedhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.DeHashed checks if personal information, such as emails, usernames, or passwords, has been compromised.DeHashed checks if personal information, such as emails, usernames, or passwords, has been compromised.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # DeHashed {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. DeHashed checks if personal information, such as emails, usernames, or passwords, has been compromised. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ DHS modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dhs/dhsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# DHS# DHShint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.The Cybersecurity and Infrastructure Security Agency's (CISA's) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community. Read more about it here.The Cybersecurity and Infrastructure Security Agency's (CISA's) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community. Read more about it here.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # DHS {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. The Cybersecurity and Infrastructure Security Agency's (CISA's) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community. Read more about it [here](https://us-cert.cisa.gov/ais). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ digicert modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/digicert/digicertRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# digicert# digicerthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Vercara UltraDNS is a cloud-based DNS management platform that provides DNS services and configuration management capabilities. This connector collects DNS configuration audit logs from Vercara UltraDNS, tracking DNS record changes and user activities for security and compliance. For more information, visit https://vercara.digicert.com/resources/ultradns.Vercara UltraDNS is a cloud-based DNS management platform that provides DNS services and configuration management capabilities. This connector collects DNS configuration audit logs from Vercara UltraDNS, tracking DNS record changes and user activities for security and compliance. For more information, visit https://vercara.digicert.com/resources/ultradns.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # digicert {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Vercara UltraDNS is a cloud-based DNS management platform that provides DNS services and configuration management capabilities. This connector collects DNS configuration audit logs from Vercara UltraDNS, tracking DNS record changes and user activities for security and compliance. For more information, visit https://vercara.digicert.com/resources/ultradns. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ dnstwist modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dnstwist/dnstwistRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# dnstwist# dnstwisthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Interfaces with dnstwist to find similar-looking domains that adversaries can use for attacks. dnstwist detects typosquatting, phishing attacks, fraud, and corporate espionage, and is useful as an additional source of targeted threat intelligence.Interfaces with dnstwist to find similar-looking domains that adversaries can use for attacks. dnstwist detects typosquatting, phishing attacks, fraud, and corporate espionage, and is useful as an additional source of targeted threat intelligence.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # dnstwist {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Interfaces with dnstwist to find similar-looking domains that adversaries can use for attacks. dnstwist detects typosquatting, phishing attacks, fraud, and corporate espionage, and is useful as an additional source of targeted threat intelligence. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ DocuSign modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/docusign/docusignRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# DocuSign# DocuSignhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Docusign is a leading provider of electronic signature and digital transaction management technology, allowing individuals and organizations to sign, send, and manage documents digitally. Fetch Customer Events (Monitor API) and Audit Users (Admin API) logs from Docusign for threat detection and compliance monitoring, and run automation and remediation commands against the service.Docusign is a leading provider of electronic signature and digital transaction management technology, allowing individuals and organizations to sign, send, and manage documents digitally. Fetch Customer Events (Monitor API) and Audit Users (Admin API) logs from Docusign for threat detection and compliance monitoring, and run automation and remediation commands against the service.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # DocuSign {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Docusign is a leading provider of electronic signature and digital transaction management technology, allowing individuals and organizations to sign, send, and manage documents digitally. Fetch Customer Events (Monitor API) and Audit Users (Admin API) logs from Docusign for threat detection and compliance monitoring, and run automation and remediation commands against the service. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Dropbox modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dropbox/dropboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Dropbox# Dropboxhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Use the Dropbox Event Collector integration to get Audit and Auth logs from Dropbox using REST APIs.Use the Dropbox Event Collector integration to get Audit and Auth logs from Dropbox using REST APIs.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Dropbox {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Use the Dropbox Event Collector integration to get Audit and Auth logs from Dropbox using REST APIs. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Druva modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/druva/druvaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Druva# Druvahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.The Druva Cloud Platform integration empowers you to automate ransomware issue response playbooks and orchestrate recovery actions across both your primary and backup environments. This event collector is applicable to customers using the Realize Ransomware Recovery module with inSync and Phoenix on Druva Public Cloud.The Druva Cloud Platform integration empowers you to automate ransomware issue response playbooks and orchestrate recovery actions across both your primary and backup environments. This event collector is applicable to customers using the Realize Ransomware Recovery module with inSync and Phoenix on Druva Public Cloud.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Druva {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. The Druva Cloud Platform integration empowers you to automate ransomware issue response playbooks and orchestrate recovery actions across both your primary and backup environments. This event collector is applicable to customers using the Realize Ransomware Recovery module with inSync and Phoenix on Druva Public Cloud. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ EasyVista modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/easyvista/easyvistaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# EasyVista# EasyVistahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the EasyVista integration to search for issues and requests, and retrieve their status and information. This integration was integrated and tested with EasyVista v2016.1.300.2. For more information, visit the EasyVista REST API documentation.Use the EasyVista integration to search for issues and requests, and retrieve their status and information. This integration was integrated and tested with EasyVista v2016.1.300.2. For more information, visit the EasyVista REST API documentation.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # EasyVista {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the EasyVista integration to search for issues and requests, and retrieve their status and information. This integration was integrated and tested with EasyVista v2016.1.300.2. For more information, visit the [EasyVista REST API documentation](https://wiki.easyvista.com/xwiki/bin/view/Documentation/WebService+REST). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ElasticSearch modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/elasticsearchRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ElasticSearch# ElasticSearchhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintElasticsearch is the distributed search and analytics engine at the heart of the Elastic Stack, where the indexing, search, and analysis happens. Query Elasticsearch instances using DSL, EQL, and Lucene syntaxes, search and index documents, collect events, fetch issues with a predefined query, and fetch threat intelligence indicators from an Elasticsearch database.Elasticsearch is the distributed search and analytics engine at the heart of the Elastic Stack, where the indexing, search, and analysis happens. Query Elasticsearch instances using DSL, EQL, and Lucene syntaxes, search and index documents, collect events, fetch issues with a predefined query, and fetch threat intelligence indicators from an Elasticsearch database.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Elasticsearch v2: Search for and analyze data in real time.\• Elasticsearch v2: Search for and analyze data in real time.\Supports version 6 and later. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Supports version 6 and later. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # ElasticSearch {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Elasticsearch is the distributed search and analytics engine at the heart of the Elastic Stack, where the indexing, search, and analysis happens. Query Elasticsearch instances using DSL, EQL, and Lucene syntaxes, search and index documents, collect events, fetch issues with a predefined query, and fetch threat intelligence indicators from an Elasticsearch database. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Elasticsearch v2](https://xsoar.pan.dev/docs/reference/integrations/elasticsearch-v2): Search for and analyze data in real time.\ Supports version 6 and later. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ Email Hippo modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/email-hippo/email-hippoRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Email Hippo# Email Hippohint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Email Hippo is an email intelligence and data services provider that delivers accurate cloud-based email validation and domain profiling. Check the reputation of a given domain name or email address and return enrichment data for available indicators (observables).Email Hippo is an email intelligence and data services provider that delivers accurate cloud-based email validation and domain profiling. Check the reputation of a given domain name or email address and return enrichment data for available indicators (observables).This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Email Hippo {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Email Hippo is an email intelligence and data services provider that delivers accurate cloud-based email validation and domain profiling. Check the reputation of a given domain name or email address and return enrichment data for available indicators (observables). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Endgame modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/endgame/endgameRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Endgame# Endgamehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Endpoint protection built to stop advanced attacks before damage and loss occurs.Endpoint protection built to stop advanced attacks before damage and loss occurs.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Endgame {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Endpoint protection built to stop advanced attacks before damage and loss occurs. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Envoy modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/envoy/envoyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Envoy# Envoyhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.Integrate with Envoy Identity Access Management (IAM) services to automate user provisioning and execute CRUD operations across employee lifecycle processes. The Envoy integration uses a set of API endpoints tested with version v2 of the Envoy SCIM API.Integrate with Envoy Identity Access Management (IAM) services to automate user provisioning and execute CRUD operations across employee lifecycle processes. The Envoy integration uses a set of API endpoints tested with version v2 of the Envoy SCIM API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Envoy {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license. Integrate with Envoy Identity Access Management (IAM) services to automate user provisioning and execute CRUD operations across employee lifecycle processes. The Envoy integration uses a set of API endpoints tested with version v2 of the Envoy SCIM API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Exabeam modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/exabeam/exabeamRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Exabeam# Exabeamhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Exabeam products. The Exabeam Security Management Platform provides end-to-end detection, User Event Behavioral Analytics (UEBA), and SOAR. Exabeam Data Lake provides a searchable log management system for log collection, storage, processing, and presentation, and the Exabeam Security Operations Platform offers a centralized and scalable platform for log management.Integrate with Exabeam products. The Exabeam Security Management Platform provides end-to-end detection, User Event Behavioral Analytics (UEBA), and SOAR. Exabeam Data Lake provides a searchable log management system for log collection, storage, processing, and presentation, and the Exabeam Security Operations Platform offers a centralized and scalable platform for log management.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Exabeam {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Exabeam products. The Exabeam Security Management Platform provides end-to-end detection, User Event Behavioral Analytics (UEBA), and SOAR. Exabeam Data Lake provides a searchable log management system for log collection, storage, processing, and presentation, and the Exabeam Security Operations Platform offers a centralized and scalable platform for log management. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ExtraHop modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/extrahop/extrahopRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ExtraHop# ExtraHophint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.ExtraHop Reveal(x) 360 is a cloud-based network detection and response platform that provides complete visibility of network communications at enterprise scale, with real-time threat detections backed by machine learning and guided investigation workflows. It monitors network traffic using behavioral analytics to identify and respond to security threats in hybrid and multi-cloud environments.ExtraHop Reveal(x) 360 is a cloud-based network detection and response platform that provides complete visibility of network communications at enterprise scale, with real-time threat detections backed by machine learning and guided investigation workflows. It monitors network traffic using behavioral analytics to identify and respond to security threats in hybrid and multi-cloud environments.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # ExtraHop {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. ExtraHop Reveal(x) 360 is a cloud-based network detection and response platform that provides complete visibility of network communications at enterprise scale, with real-time threat detections backed by machine learning and guided investigation workflows. It monitors network traffic using behavioral analytics to identify and respond to security threats in hybrid and multi-cloud environments. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ F5 Automation and Remediation modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/f5/f5-automation-and-remediationRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# F5 Automation and Remediation# F5 Automation and Remediationhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Automate and remediate across F5 products. Use F5 Application Security Manager (ASM/WAF) to read information and manage web application firewall policies, F5 Firewall to manage firewall rules, and F5 Silverline to retrieve alerts and read/update threat-intelligence IP lists (allowlists and denylists).Automate and remediate across F5 products. Use F5 Application Security Manager (ASM/WAF) to read information and manage web application firewall policies, F5 Firewall to manage firewall rules, and F5 Silverline to retrieve alerts and read/update threat-intelligence IP lists (allowlists and denylists).This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # F5 Automation and Remediation {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Automate and remediate across F5 products. Use F5 Application Security Manager (ASM/WAF) to read information and manage web application firewall policies, F5 Firewall to manage firewall rules, and F5 Silverline to retrieve alerts and read/update threat-intelligence IP lists (allowlists and denylists). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Fastly modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fastly/fastlyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Fastly# Fastlyhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Fastly products. Use Fastly Feed to get assigned CIDRs and add them to your firewall's allowlist in order to enable using Fastly's services, and use the Signal Sciences next-gen web application firewall to increase security and maintain reliability.Integrate with Fastly products. Use Fastly Feed to get assigned CIDRs and add them to your firewall's allowlist in order to enable using Fastly's services, and use the Signal Sciences next-gen web application firewall to increase security and maintain reliability.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Fastly {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Fastly products. Use Fastly Feed to get assigned CIDRs and add them to your firewall's allowlist in order to enable using Fastly's services, and use the Signal Sciences next-gen web application firewall to increase security and maintain reliability. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Fidelis modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fidelis/fidelisRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Fidelis# Fidelishint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Fidelis Endpoint provides advanced endpoint detection and response (EDR) across Windows, Mac and Linux OSes for faster threat remediation. Fidelis Elevate Network automates detection and response to network threats and data leakage in your organization. Supported version - 9.2.Fidelis Endpoint provides advanced endpoint detection and response (EDR) across Windows, Mac and Linux OSes for faster threat remediation. Fidelis Elevate Network automates detection and response to network threats and data leakage in your organization. Supported version - 9.2.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Fidelis {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Fidelis Endpoint provides advanced endpoint detection and response (EDR) across Windows, Mac and Linux OSes for faster threat remediation. Fidelis Elevate Network automates detection and response to network threats and data leakage in your organization. Supported version - 9.2. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Filigran OpenCTI modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/filigran/filigran-openctiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Filigran OpenCTI# Filigran OpenCTIhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.OpenCTI is a cyber threat intelligence platform. Get lists of indicators linked to threats with additional context for your investigations, report new indicators, and update or delete existing ones. The OpenCTI Feed integration periodically ingests indicators from the OpenCTI feed.OpenCTI is a cyber threat intelligence platform. Get lists of indicators linked to threats with additional context for your investigations, report new indicators, and update or delete existing ones. The OpenCTI Feed integration periodically ingests indicators from the OpenCTI feed.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Filigran OpenCTI {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. OpenCTI is a cyber threat intelligence platform. Get lists of indicators linked to threats with additional context for your investigations, report new indicators, and update or delete existing ones. The OpenCTI Feed integration periodically ingests indicators from the OpenCTI feed. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Forcepoint modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forcepoint/forcepointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Forcepoint# Forcepointhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintForcepoint is an advanced threat protection product with added local management controls. This connector lets you create and manage custom URL/IP block-list categories in Forcepoint Web Security, centrally manage Forcepoint engines through the Security Management Center, and collect activity logs from Forcepoint DLP.Forcepoint is an advanced threat protection product with added local management controls. This connector lets you create and manage custom URL/IP block-list categories in Forcepoint Web Security, centrally manage Forcepoint engines through the Security Management Center, and collect activity logs from Forcepoint DLP.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Forcepoint: Advanced threat protection with added local management controls. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, or Cortex AgentiX license.• Forcepoint: Advanced threat protection with added local management controls. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, or Cortex AgentiX license.• Forcepoint DLP Event Collector: This sub-capability is available with any active Cortex XSIAM license.• Forcepoint DLP Event Collector: This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # Forcepoint {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Forcepoint is an advanced threat protection product with added local management controls. This connector lets you create and manage custom URL/IP block-list categories in Forcepoint Web Security, centrally manage Forcepoint engines through the Security Management Center, and collect activity logs from Forcepoint DLP. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Forcepoint](https://xsoar.pan.dev/docs/reference/integrations/forcepoint): Advanced threat protection with added local management controls. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, or Cortex AgentiX license. * [Forcepoint DLP Event Collector](https://xsoar.pan.dev/docs/reference/integrations/forcepoint-dlp-event-collector): This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ ForeScout modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forescout/forescoutRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ForeScout# ForeScouthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Forescout CounterACT is a unified device visibility and control platform for IT and OT security. Forescout EyeInspect delivers flexible and scalable OT/ICS asset visibility, giving you in-depth device visibility for the computing systems used to manage industrial operations.Forescout CounterACT is a unified device visibility and control platform for IT and OT security. Forescout EyeInspect delivers flexible and scalable OT/ICS asset visibility, giving you in-depth device visibility for the computing systems used to manage industrial operations.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # ForeScout {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Forescout CounterACT is a unified device visibility and control platform for IT and OT security. Forescout EyeInspect delivers flexible and scalable OT/ICS asset visibility, giving you in-depth device visibility for the computing systems used to manage industrial operations. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Fortinet FortiWeb VM modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortiweb-vmRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Fortinet FortiWeb VM# Fortinet FortiWeb VMhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Fortinet FortiWeb VM lets you manage web application firewall (WAF) policies and block cookies, URLs, and host names, performing controlled changes on hosted web applications.Fortinet FortiWeb VM lets you manage web application firewall (WAF) policies and block cookies, URLs, and host names, performing controlled changes on hosted web applications.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Fortinet FortiWeb VM {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Fortinet FortiWeb VM lets you manage web application firewall (WAF) policies and block cookies, URLs, and host names, performing controlled changes on hosted web applications. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Fortinet modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinetRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Fortinet# Fortinethint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Fortinet products. FortiManager is a single console central management system that manages Fortinet devices. Use FortiSIEM to fetch and update issues, search events, and manage watchlists and resource lists. FortiSandbox is an advanced security tool that combines proactive mitigation, enhanced threat detection, and in-depth reporting to counter advanced threats. FortiMail is a comprehensive email security solution offering advanced threat protection, data loss prevention, encryption, and email authentication.Integrate with Fortinet products. FortiManager is a single console central management system that manages Fortinet devices. Use FortiSIEM to fetch and update issues, search events, and manage watchlists and resource lists. FortiSandbox is an advanced security tool that combines proactive mitigation, enhanced threat detection, and in-depth reporting to counter advanced threats. FortiMail is a comprehensive email security solution offering advanced threat protection, data loss prevention, encryption, and email authentication.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Fortinet {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Fortinet products. FortiManager is a single console central management system that manages Fortinet devices. Use FortiSIEM to fetch and update issues, search events, and manage watchlists and resource lists. FortiSandbox is an advanced security tool that combines proactive mitigation, enhanced threat detection, and in-depth reporting to counter advanced threats. FortiMail is a comprehensive email security solution offering advanced threat protection, data loss prevention, encryption, and email authentication. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Fortra modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortra/fortraRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Fortra# Fortrahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Fortra products. Digital Guardian's Data Loss Prevention (DLP) platform Analytics & Reporting Cloud (ARC) solution identifies, remediates, and protects sensitive data from insider and outsider threats. Tripwire is a file integrity management (FIM) system that monitors files and folders on systems and is triggered when they have changed.Integrate with Fortra products. Digital Guardian's Data Loss Prevention (DLP) platform Analytics & Reporting Cloud (ARC) solution identifies, remediates, and protects sensitive data from insider and outsider threats. Tripwire is a file integrity management (FIM) system that monitors files and folders on systems and is triggered when they have changed.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• DigitalGuardianARCEventCollector: Digital Guardian ARC event collector. This sub-capability is available with any active Cortex XSIAM license.• DigitalGuardianARCEventCollector: Digital Guardian ARC event collector. This sub-capability is available with any active Cortex XSIAM license.• Tripwire: Tripwire is a file integrity management (FIM), FIM monitors files and folders on systems and is triggered when they have changed. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Tripwire: Tripwire is a file integrity management (FIM), FIM monitors files and folders on systems and is triggered when they have changed. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Fortra {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Fortra products. Digital Guardian's Data Loss Prevention (DLP) platform Analytics & Reporting Cloud (ARC) solution identifies, remediates, and protects sensitive data from insider and outsider threats. Tripwire is a file integrity management (FIM) system that monitors files and folders on systems and is triggered when they have changed. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [DigitalGuardianARCEventCollector](https://xsoar.pan.dev/docs/reference/integrations/digital-guardian-arc-event-collector): Digital Guardian ARC event collector. This sub-capability is available with any active Cortex XSIAM license. * [Tripwire](https://xsoar.pan.dev/docs/reference/integrations/tripwire): Tripwire is a file integrity management (FIM), FIM monitors files and folders on systems and is triggered when they have changed. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ FraudWatch modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fraudwatch/fraudwatchRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# FraudWatch# FraudWatchhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Manage issues via the FraudWatch API. FraudWatch International provides a fully managed Enterprise Digital Brand Protection Suite, including online brand management and monitoring as well as other brand protection solutions that protect organizations and their customers around the world against online brand-related abuse.Manage issues via the FraudWatch API. FraudWatch International provides a fully managed Enterprise Digital Brand Protection Suite, including online brand management and monitoring as well as other brand protection solutions that protect organizations and their customers around the world against online brand-related abuse.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # FraudWatch {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Manage issues via the FraudWatch API. FraudWatch International provides a fully managed Enterprise Digital Brand Protection Suite, including online brand management and monitoring as well as other brand protection solutions that protect organizations and their customers around the world against online brand-related abuse. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Freshworks modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/freshworks/freshworksRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Freshworks# Freshworkshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintManage and create Freshdesk tickets, and streamline security-related service management and IT operations with Freshservice. View, create, update, and delete tickets, users, vendors, software, and purchase orders; fetch and mirror tickets.Manage and create Freshdesk tickets, and streamline security-related service management and IT operations with Freshservice. View, create, update, and delete tickets, users, vendors, software, and purchase orders; fetch and mirror tickets.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Freshdesk: The Freshdesk integration allows you to create, update, and delete tickets; reply to and create notes for tickets as well as view Groups, Agents and Contacts. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Freshdesk: The Freshdesk integration allows you to create, update, and delete tickets; reply to and create notes for tickets as well as view Groups, Agents and Contacts. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• FreshworksFreshservice: Freshservice is a service management solution that allows customers to manage service requests, incidents, change requests tasks, and problem investigation. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• FreshworksFreshservice: Freshservice is a service management solution that allows customers to manage service requests, incidents, change requests tasks, and problem investigation. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Freshworks {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Manage and create Freshdesk tickets, and streamline security-related service management and IT operations with Freshservice. View, create, update, and delete tickets, users, vendors, software, and purchase orders; fetch and mirror tickets. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Freshdesk](https://xsoar.pan.dev/docs/reference/integrations/freshdesk): The Freshdesk integration allows you to create, update, and delete tickets; reply to and create notes for tickets as well as view Groups, Agents and Contacts. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [FreshworksFreshservice](https://xsoar.pan.dev/docs/reference/integrations/freshworks-freshservice): Freshservice is a service management solution that allows customers to manage service requests, incidents, change requests tasks, and problem investigation. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ Gamma.AI modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gamma.ai/gamma.aiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Gamma.AI# Gamma.AIhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Gamma.AI is an AI-powered enterprise cloud data discovery, data classification, and data loss prevention (DLP) platform. It provides 1-click automatic discovery and remediation of data loss instances across enterprise SaaS applications such as Slack, GitHub, GSuite, the Atlassian Suite, Microsoft Office 365, ServiceNow, and ZenDesk.Gamma.AI is an AI-powered enterprise cloud data discovery, data classification, and data loss prevention (DLP) platform. It provides 1-click automatic discovery and remediation of data loss instances across enterprise SaaS applications such as Slack, GitHub, GSuite, the Atlassian Suite, Microsoft Office 365, ServiceNow, and ZenDesk.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Gamma.AI {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Gamma.AI is an AI-powered enterprise cloud data discovery, data classification, and data loss prevention (DLP) platform. It provides 1-click automatic discovery and remediation of data loss instances across enterprise SaaS applications such as Slack, GitHub, GSuite, the Atlassian Suite, Microsoft Office 365, ServiceNow, and ZenDesk. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Generic API Event Collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-api-event-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Generic API Event Collector# Generic API Event Collectorhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.The Generic API Event Collector allows you to ingest data from any API endpoint into Cortex. By configuring this collector, you can gather data from various systems and bring it into the Cortex ecosystem for better analysis and correlation.The Generic API Event Collector allows you to ingest data from any API endpoint into Cortex. By configuring this collector, you can gather data from various systems and bring it into the Cortex ecosystem for better analysis and correlation.hint infohint infoThis integration is currently in Beta, and as such, it may be subject to future changes.This integration is currently in Beta, and as such, it may be subject to future changes.Show markdown source
@@ -1,14 +1,14 @@ # Generic API Event Collector {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. The Generic API Event Collector allows you to ingest data from any API endpoint into Cortex. By configuring this collector, you can gather data from various systems and bring it into the Cortex ecosystem for better analysis and correlation. {% hint style="info" %} This integration is currently in Beta, and as such, it may be subject to future changes. -
▸ ▾ Generic Intel Feed modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-intel-feedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Generic Intel Feed# Generic Intel Feedhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Fetch threat intelligence indicators from generic CSV, JSON, plain text, RSS, and public DNS feeds, with extensive configuration options to support a wide variety of feed formats. Also provides the Generic Export Indicators Service to expose a list of indicators from the system as an outbound feed (EDL) for consumption by external products.Fetch threat intelligence indicators from generic CSV, JSON, plain text, RSS, and public DNS feeds, with extensive configuration options to support a wide variety of feed formats. Also provides the Generic Export Indicators Service to expose a list of indicators from the system as an outbound feed (EDL) for consumption by external products.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Generic Intel Feed {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Fetch threat intelligence indicators from generic CSV, JSON, plain text, RSS, and public DNS feeds, with extensive configuration options to support a wide variety of feed formats. Also provides the Generic Export Indicators Service to expose a list of indicators from the system as an outbound feed (EDL) for consumption by external products. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Generic MCP modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-mcpRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Generic MCP# Generic MCPhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on.Connect securely with any MCP server and access its tools in real time. This integration automatically discovers the tools available on the connected MCP server.Connect securely with any MCP server and access its tools in real time. This integration automatically discovers the tools available on the connected MCP server.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Generic MCP {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on. Connect securely with any MCP server and access its tools in real time. This integration automatically discovers the tools available on the connected MCP server. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Generic SQL modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-sqlRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Generic SQL# Generic SQLhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Generic SQL integration for the databases MySQL, PostgreSQL, Microsoft SQL Server, Oracle, Teradata, and Trino. Run SQL queries against your database and fetch issues from it.Generic SQL integration for the databases MySQL, PostgreSQL, Microsoft SQL Server, Oracle, Teradata, and Trino. Run SQL queries against your database and fetch issues from it.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Generic SQL {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. Generic SQL integration for the databases MySQL, PostgreSQL, Microsoft SQL Server, Oracle, Teradata, and Trino. Run SQL queries against your database and fetch issues from it. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Genesys modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/genesys/genesysRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Genesys# Genesyshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Genesys Cloud is a unified, all-in-one cloud collaboration and contact center platform that provides customer interaction and operational audit event data. Fetch audit events to see changes within a Genesys Cloud organization.Genesys Cloud is a unified, all-in-one cloud collaboration and contact center platform that provides customer interaction and operational audit event data. Fetch audit events to see changes within a Genesys Cloud organization.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Genesys {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Genesys Cloud is a unified, all-in-one cloud collaboration and contact center platform that provides customer interaction and operational audit event data. Fetch audit events to see changes within a Genesys Cloud organization. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Genetec Security Center modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/genetec/genetec-security-centerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Genetec Security Center# Genetec Security Centerhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Genetec Security Center is a platform that unifies your data so that you can manage security policies, monitor events, and run investigations. This connector collects events from the Security Center Audit Trail endpoint.Genetec Security Center is a platform that unifies your data so that you can manage security policies, monitor events, and run investigations. This connector collects events from the Security Center Audit Trail endpoint.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Genetec Security Center {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Genetec Security Center is a platform that unifies your data so that you can manage security policies, monitor events, and run investigations. This connector collects events from the Security Center Audit Trail endpoint. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Gigamon modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gigamon/gigamonRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Gigamon# Gigamonhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.ICEBRG is a network security product used in conjunction with Cortex XSOAR to get events and reports produced in ICEBRG for queries. Top use cases include searching events by query and getting reports by UUID.ICEBRG is a network security product used in conjunction with Cortex XSOAR to get events and reports produced in ICEBRG for queries. Top use cases include searching events by query and getting reports by UUID.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Gigamon {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. ICEBRG is a network security product used in conjunction with Cortex XSOAR to get events and reports produced in ICEBRG for queries. Top use cases include searching events by query and getting reports by UUID. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Giphy modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/giphy/giphyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Giphy# Giphyhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Giphy provides access to the Giphy GIF library. Powered By Giphy.Giphy provides access to the Giphy GIF library. Powered By Giphy.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Giphy {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Giphy provides access to the Giphy GIF library. Powered By Giphy. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ GitGuardian modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gitguardian/gitguardianRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# GitGuardian# GitGuardianhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Collect events automatically from GitGuardian. You can also use thegitguardian-get-eventscommand to manually collect events.Collect events automatically from GitGuardian. You can also use thegitguardian-get-eventscommand to manually collect events.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # GitGuardian {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Collect events automatically from GitGuardian. You can also use the **`gitguardian-get-events`** command to manually collect events. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ GitHub modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/github/githubRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# GitHub# GitHubhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintGitHub is an internet hosting provider that uses Git for software development and version control, adding access control and collaboration features such as bug tracking, feature requests, task management, and continuous integration. This connector lets you manage GitHub issues and pull requests, provision organization membership, connect to a GitHub Model Context Protocol (MCP) server, collect organization audit logs, and publish indicators from a repository.GitHub is an internet hosting provider that uses Git for software development and version control, adding access control and collaboration features such as bug tracking, feature requests, task management, and continuous integration. This connector lets you manage GitHub issues and pull requests, provision organization membership, connect to a GitHub Model Context Protocol (MCP) server, collect organization audit logs, and publish indicators from a repository.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• GitHub: Integration to GitHub API. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• GitHub: Integration to GitHub API. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Github Event Collector: GitHub logs event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.• Github Event Collector: GitHub logs event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # GitHub {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} [GitHub](https://github.com/about) is an internet hosting provider that uses Git for software development and version control, adding access control and collaboration features such as bug tracking, feature requests, task management, and continuous integration. This connector lets you manage GitHub issues and pull requests, provision organization membership, connect to a GitHub Model Context Protocol (MCP) server, collect organization audit logs, and publish indicators from a repository. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [GitHub](https://xsoar.pan.dev/docs/reference/integrations/git-hub): Integration to GitHub API. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [Github Event Collector](https://xsoar.pan.dev/docs/reference/integrations/github-event-collector): GitHub logs event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ GitLab Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gitlab/gitlab-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# GitLab Automation and Collection# GitLab Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with GitLab, the DevOps platform for managing repositories, projects, and pipelines. Automate the creation, updating, and tracking of GitLab issues, merge requests, branches, files, and pipelines, and collect audit event logs via the GitLab API.Integrate with GitLab, the DevOps platform for managing repositories, projects, and pipelines. Automate the creation, updating, and tracking of GitLab issues, merge requests, branches, files, and pipelines, and collect audit event logs via the GitLab API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• GitLab Event Collector: This sub-capability is available with any active Cortex XSIAM license.• GitLab Event Collector: This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # GitLab Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with GitLab, the DevOps platform for managing repositories, projects, and pipelines. Automate the creation, updating, and tracking of GitLab issues, merge requests, branches, files, and pipelines, and collect audit event logs via the GitLab API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [GitLab Event Collector](https://xsoar.pan.dev/docs/reference/integrations/git-lab-event-collector): This sub-capability is available with any active Cortex XSIAM license. * [GitLabv2](https://xsoar.pan.dev/docs/reference/integrations/git-labv2): Integration to GitLab API. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Google AI modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-aiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Google AI# Google AIhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.The Google Gemini connector provides access to Google's advanced large language models for AI-powered chat conversations, text analysis, and natural language processing within Cortex XSOAR / XSIAM. It supports two authentication modes: Google AI Studio (API key) and Google Cloud Vertex AI (service account), and multiple Gemini models.The Google Gemini connector provides access to Google's advanced large language models for AI-powered chat conversations, text analysis, and natural language processing within Cortex XSOAR / XSIAM. It supports two authentication modes: Google AI Studio (API key) and Google Cloud Vertex AI (service account), and multiple Gemini models.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Google AI {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. The Google Gemini connector provides access to Google's advanced large language models for AI-powered chat conversations, text analysis, and natural language processing within Cortex XSOAR / XSIAM. It supports two authentication modes: Google AI Studio (API key) and Google Cloud Vertex AI (service account), and multiple Gemini models. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Google Cloud modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-cloudRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Google Cloud# Google Cloudhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Google Cloud Platform services to manage identity and access, compute, storage, key management, resource management, logging, messaging, and analytics. This connector groups the GCP-IAM, Google BigQuery, Google Cloud Compute, Google Cloud Functions, Google Cloud Storage, Google Key Management Service, Google Resource Manager, Google Vision AI, Google Cloud Logging, Google Cloud Translate, Google Kubernetes Engine, Google Cloud Pub/Sub, and Looker integrations.Integrate with Google Cloud Platform services to manage identity and access, compute, storage, key management, resource management, logging, messaging, and analytics. This connector groups the GCP-IAM, Google BigQuery, Google Cloud Compute, Google Cloud Functions, Google Cloud Storage, Google Key Management Service, Google Resource Manager, Google Vision AI, Google Cloud Logging, Google Cloud Translate, Google Kubernetes Engine, Google Cloud Pub/Sub, and Looker integrations.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Google Cloud {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Google Cloud Platform services to manage identity and access, compute, storage, key management, resource management, logging, messaging, and analytics. This connector groups the GCP-IAM, Google BigQuery, Google Cloud Compute, Google Cloud Functions, Google Cloud Storage, Google Key Management Service, Google Resource Manager, Google Vision AI, Google Cloud Logging, Google Cloud Translate, Google Kubernetes Engine, Google Cloud Pub/Sub, and Looker integrations. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Google SecOps modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-secopsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Google SecOps# Google SecOpshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Verodin simulations and topology.Verodin simulations and topology.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Google SecOps {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Verodin simulations and topology. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Google Services modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-servicesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Google Services# Google Serviceshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintGoogle Services groups multiple Google integrations: Apigee (Google Cloud's API management platform) for collecting Apigee Edge audit logs, Google IP Ranges Feed for GCP and Google global IP ranges, Google Safe Browsing v2 for checking URLs against Google's lists of unsafe web resources, and Google Maps for the Geocoding API.Google Services groups multiple Google integrations: Apigee (Google Cloud's API management platform) for collecting Apigee Edge audit logs, Google IP Ranges Feed for GCP and Google global IP ranges, Google Safe Browsing v2 for checking URLs against Google's lists of unsafe web resources, and Google Maps for the Geocoding API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Google Apigee: This sub-capability is available with any active Cortex XSIAM license.• Google Apigee: This sub-capability is available with any active Cortex XSIAM license.• Google IP Ranges Feed: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Google IP Ranges Feed: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Google Services {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Google Services groups multiple Google integrations: Apigee (Google Cloud's API management platform) for collecting Apigee Edge audit logs, Google IP Ranges Feed for GCP and Google global IP ranges, Google Safe Browsing v2 for checking URLs against Google's lists of unsafe web resources, and Google Maps for the Geocoding API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Google Apigee](https://xsoar.pan.dev/docs/reference/integrations/google-apigee): This sub-capability is available with any active Cortex XSIAM license. * [Google IP Ranges Feed](https://xsoar.pan.dev/docs/reference/integrations/google-ip-ranges-feed): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Google Workspace Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace/google-workspace-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Google Workspace Automation and Collection# Google Workspace Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintAutomate and collect across Google Workspace: manage users, groups, roles, and devices in the Admin console; fetch security alerts and audit logs; send and process Gmail messages; work with Calendar, Docs, and Sheets; and support archiving and eDiscovery with Google Vault.Automate and collect across Google Workspace: manage users, groups, roles, and devices in the Admin console; fetch security alerts and audit logs; send and process Gmail messages; work with Calendar, Docs, and Sheets; and support archiving and eDiscovery with Google Vault.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• G Suite Security Alert Center: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• G Suite Security Alert Center: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Gmail: This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Gmail: This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Google Workspace Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../../marketplace). {% endhint %} Automate and collect across Google Workspace: manage users, groups, roles, and devices in the Admin console; fetch security alerts and audit logs; send and process Gmail messages; work with Calendar, Docs, and Sheets; and support archiving and eDiscovery with Google Vault. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [G Suite Security Alert Center](https://xsoar.pan.dev/docs/reference/integrations/g-suite-security-alert-center): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Gmail](https://xsoar.pan.dev/docs/reference/integrations/gmail): This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ Grafana modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grafana/grafanaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Grafana# Grafanahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Grafana alerting service. Manage alerts and monitoring data from Grafana Labs: fetch alerts, get/pause/unpause alerts, manage users, teams, and organizations, list dashboards, and create annotations.Grafana alerting service. Manage alerts and monitoring data from Grafana Labs: fetch alerts, get/pause/unpause alerts, manage users, teams, and organizations, list dashboards, and create annotations.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Grafana {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Grafana alerting service. Manage alerts and monitoring data from Grafana Labs: fetch alerts, get/pause/unpause alerts, manage users, teams, and organizations, list dashboards, and create annotations. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ GraphQL modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/graphql/graphqlRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# GraphQL# GraphQLhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Generic GraphQL client to interact with any GraphQL server API.Generic GraphQL client to interact with any GraphQL server API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # GraphQL {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Generic GraphQL client to interact with any GraphQL server API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Grouped Example Connector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grouped-example-connector/grouped-example-connectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Grouped Example Connector# Grouped Example Connectorhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintPOC of Grouped Connectors / view_groups. Four mocked Microsoft-themed XSIAM integrations (EWS O365, EWS v2, Office 365 Feed, Microsoft Teams) wired to exercise:settings.grouped, split connection/configurationsview_groupsregistries, per-handlerauth_optionsview_grouppinning, one profile shared across multiple capabilities, multiple profiles bound to one sub-capability, two integrations under the same capability with duplicated field names perview_group, integration-shared params across two sub-capabilities, per-integrationengine/proxy/trust-any-certin connectiongeneral_configurations, and per-integrationintegrationLogLevelwith serializer rewrites. Appendix G + I carve-outs honored for Microsoft Teams. Every vendor / pack / capability mapping here is mocked.POC of Grouped Connectors / view_groups. Four mocked Microsoft-themed XSIAM integrations (EWS O365, EWS v2, Office 365 Feed, Microsoft Teams) wired to exercise:settings.grouped, split connection/configurationsview_groupsregistries, per-handlerauth_optionsview_grouppinning, one profile shared across multiple capabilities, multiple profiles bound to one sub-capability, two integrations under the same capability with duplicated field names perview_group, integration-shared params across two sub-capabilities, per-integrationengine/proxy/trust-any-certin connectiongeneral_configurations, and per-integrationintegrationLogLevelwith serializer rewrites. Appendix G + I carve-outs honored for Microsoft Teams. Every vendor / pack / capability mapping here is mocked.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Grouped Example Connector {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} POC of Grouped Connectors / view\_groups. Four mocked Microsoft-themed XSIAM integrations (EWS O365, EWS v2, Office 365 Feed, Microsoft Teams) wired to exercise: `settings.grouped`, split connection/configurations `view_groups` registries, per-handler `auth_options` `view_group` pinning, one profile shared across multiple capabilities, multiple profiles bound to one sub-capability, two integrations under the same capability with duplicated field names per `view_group`, integration-shared params across two sub-capabilities, per-integration `engine`/`proxy`/`trust-any-cert` in connection `general_configurations`, and per-integration `integrationLogLevel` with serializer rewrites. Appendix G + I carve-outs honored for Microsoft Teams. Every vendor / pack / capability mapping here is mocked. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [EWS O365](https://xsoar.pan.dev/docs/reference/integrations/ewso365): The new EWS O365 integration uses OAuth 2.0 protocol and can be used with Exchange Online and Office 365 (mail). * [EWS v2](https://xsoar.pan.dev/docs/reference/integrations/ews-v2): Exchange Web Services and Office 365 (mail). -
▸ ▾ GRR modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grr/grrRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# GRR# GRRhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the GRR integration to manage and communicate with the clients connected to your GRR server. This integration was integrated and tested with GRR Rapid Response v3.2.3.2.Use the GRR integration to manage and communicate with the clients connected to your GRR server. This integration was integrated and tested with GRR Rapid Response v3.2.3.2.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # GRR {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the GRR integration to manage and communicate with the clients connected to your GRR server. This integration was integrated and tested with GRR Rapid Response v3.2.3.2. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Halcyon modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/halcyon/halcyonRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Halcyon# Halcyonhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Halcyon is a device management platform that helps organizations monitor, control, and secure their network of devices. This integration fetches security alerts and operational events from the Halcyon platform and ingests them into Cortex XSIAM.Halcyon is a device management platform that helps organizations monitor, control, and secure their network of devices. This integration fetches security alerts and operational events from the Halcyon platform and ingests them into Cortex XSIAM.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Halcyon {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Halcyon is a device management platform that helps organizations monitor, control, and secure their network of devices. This integration fetches security alerts and operational events from the Halcyon platform and ingests them into Cortex XSIAM. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ HashiCorp modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hashicorp/hashicorpRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# HashiCorp# HashiCorphint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Secure, store, and tightly control access to tokens, passwords, certificates, and encryption keys for protecting secrets and other sensitive data using HashiCorp Vault. HashiCorp Terraform provides Infrastructure as Code (IaC) automation to provision and manage resources in any cloud or data center.Secure, store, and tightly control access to tokens, passwords, certificates, and encryption keys for protecting secrets and other sensitive data using HashiCorp Vault. HashiCorp Terraform provides Infrastructure as Code (IaC) automation to provision and manage resources in any cloud or data center.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # HashiCorp {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Secure, store, and tightly control access to tokens, passwords, certificates, and encryption keys for protecting secrets and other sensitive data using HashiCorp Vault. HashiCorp Terraform provides Infrastructure as Code (IaC) automation to provision and manage resources in any cloud or data center. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Have I Been Pwnd modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/have-i-been-pwnd/have-i-been-pwndRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Have I Been Pwnd# Have I Been Pwndhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Uses the Have I Been Pwned? service to check whether email addresses, domains, or usernames were compromised in previous breaches. Uses API v3.Uses the Have I Been Pwned? service to check whether email addresses, domains, or usernames were compromised in previous breaches. Uses API v3.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Have I Been Pwnd {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Uses the Have I Been Pwned? service to check whether email addresses, domains, or usernames were compromised in previous breaches. Uses [API v3](https://haveibeenpwned.com/api/v3). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ HCL BigFix modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hcl-bigfix/hcl-bigfixRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# HCL BigFix# HCL BigFixhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the BigFix integration to manage patching processes.Use the BigFix integration to manage patching processes.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # HCL BigFix {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the BigFix integration to manage patching processes. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Hostio Solutions modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hostio-solutions/hostio-solutionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Hostio Solutions# Hostio Solutionshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Enrich domains using the Host.io API. Host.io collects data about every known domain name, letting you retrieve information about any given domain, including a list of domains associated with a specific field, the domain's rank based on popularity, and the name of the server where the domain exists.Enrich domains using the Host.io API. Host.io collects data about every known domain name, letting you retrieve information about any given domain, including a list of domains associated with a specific field, the domain's rank based on popularity, and the name of the server where the domain exists.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Hostio Solutions {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Enrich domains using the Host.io API. Host.io collects data about every known domain name, letting you retrieve information about any given domain, including a list of domains associated with a specific field, the domain's rank based on popularity, and the name of the server where the domain exists. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ HPE Aruba modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hpe-aruba/hpe-arubaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# HPE Aruba# HPE Arubahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintHPE Aruba Central provides a centralized platform for managing and monitoring network infrastructure, including event collection and audit log management for network changes, user activities, and security events. HPE Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multi-vendor wired, wireless, and VPN infrastructure.HPE Aruba Central provides a centralized platform for managing and monitoring network infrastructure, including event collection and audit log management for network changes, user activities, and security events. HPE Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multi-vendor wired, wireless, and VPN infrastructure.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• HPEArubaCentralEventCollector: This is the Aruba Central event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.• HPEArubaCentralEventCollector: This is the Aruba Central event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.• HPEArubaClearPass: Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multi-vendor wired, wireless, and VPN infrastructure. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• HPEArubaClearPass: Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multi-vendor wired, wireless, and VPN infrastructure. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # HPE Aruba {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} HPE Aruba Central provides a centralized platform for managing and monitoring network infrastructure, including event collection and audit log management for network changes, user activities, and security events. HPE Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multi-vendor wired, wireless, and VPN infrastructure. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [HPEArubaCentralEventCollector](https://xsoar.pan.dev/docs/reference/integrations/hpe-aruba-central-event-collector): This is the Aruba Central event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license. * [HPEArubaClearPass](https://xsoar.pan.dev/docs/reference/integrations/hpe-aruba-clear-pass): Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multi-vendor wired, wireless, and VPN infrastructure. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ IBM QRadar modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-qradarRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# IBM QRadar# IBM QRadarhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with IBM QRadar to detect, prioritize, and respond to threats across the enterprise. IBM Security QRadar SOAR provides case management for continual issue-response improvement, while IBM QRadar v3 (SIEM) aggregates and parses logs, fetches offenses with their enriched data as issues, and lets you run QRadar actions from the platform.Integrate with IBM QRadar to detect, prioritize, and respond to threats across the enterprise. IBM Security QRadar SOAR provides case management for continual issue-response improvement, while IBM QRadar v3 (SIEM) aggregates and parses logs, fetches offenses with their enriched data as issues, and lets you run QRadar actions from the platform.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• IBM Resilient Systems: Case management that enables visibility across your tools for continual IR improvement. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• IBM Resilient Systems: Case management that enables visibility across your tools for continual IR improvement. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• QRadar v3: IBM QRadar SIEM helps security teams accurately detect and prioritize threats across the enterprise, supports API versions 10.1 and above. Provides intelligent insights that enable teams to respond quickly to reduce the impact of incidents. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• QRadar v3: IBM QRadar SIEM helps security teams accurately detect and prioritize threats across the enterprise, supports API versions 10.1 and above. Provides intelligent insights that enable teams to respond quickly to reduce the impact of incidents. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # IBM QRadar {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with IBM QRadar to detect, prioritize, and respond to threats across the enterprise. IBM Security QRadar SOAR provides case management for continual issue-response improvement, while IBM QRadar v3 (SIEM) aggregates and parses logs, fetches offenses with their enriched data as issues, and lets you run QRadar actions from the platform. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [IBM Resilient Systems](https://xsoar.pan.dev/docs/reference/integrations/ibm-resilient-systems): Case management that enables visibility across your tools for continual IR improvement. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [QRadar v3](https://xsoar.pan.dev/docs/reference/integrations/q-radar-v3): IBM QRadar SIEM helps security teams accurately detect and prioritize threats across the enterprise, supports API versions 10.1 and above. Provides intelligent insights that enable teams to respond quickly to reduce the impact of incidents. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ IBM Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# IBM Security# IBM Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with IBM Security products. IBM MaaS360 is a mobile device management solution for monitoring and managing smartphones, tablets, and other mobile devices. IBM Security Guardium is a data security platform providing visibility and protection for sensitive data across databases, data warehouses, big data platforms, and cloud environments. IBM Security Verify secures and manages user identity and access, and collects security events across your organization's network. IBM X-Force Exchange provides threat intelligence about applications, IP addresses, URLs, and hashes.Integrate with IBM Security products. IBM MaaS360 is a mobile device management solution for monitoring and managing smartphones, tablets, and other mobile devices. IBM Security Guardium is a data security platform providing visibility and protection for sensitive data across databases, data warehouses, big data platforms, and cloud environments. IBM Security Verify secures and manages user identity and access, and collects security events across your organization's network. IBM X-Force Exchange provides threat intelligence about applications, IP addresses, URLs, and hashes.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• IBMMaaS360Security: This sub-capability is available with any active Cortex XSIAM license.• IBMMaaS360Security: This sub-capability is available with any active Cortex XSIAM license.• IBMSecurityGuardium: Collect events from IBM Guardium Data Security Center. This sub-capability is available with any active Cortex XSIAM license.• IBMSecurityGuardium: Collect events from IBM Guardium Data Security Center. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # IBM Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with IBM Security products. IBM MaaS360 is a mobile device management solution for monitoring and managing smartphones, tablets, and other mobile devices. IBM Security Guardium is a data security platform providing visibility and protection for sensitive data across databases, data warehouses, big data platforms, and cloud environments. IBM Security Verify secures and manages user identity and access, and collects security events across your organization's network. IBM X-Force Exchange provides threat intelligence about applications, IP addresses, URLs, and hashes. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [IBMMaaS360Security](https://xsoar.pan.dev/docs/reference/integrations/ibm-maa-s360-security): This sub-capability is available with any active Cortex XSIAM license. * [IBMSecurityGuardium](https://xsoar.pan.dev/docs/reference/integrations/ibm-security-guardium): Collect events from IBM Guardium Data Security Center. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ IBM Storage Scale modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-storage-scaleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# IBM Storage Scale# IBM Storage Scalehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.IBM Storage Scale (formerly IBM Spectrum Scale, originally GPFS) is a high-performance, software-defined parallel file system for managing massive amounts of unstructured data across storage types, locations, and cloud environments. This connector collects Command Line Interface (CLI) audit log records from the IBM Storage Scale API, using a concurrent fetching mechanism to efficiently ingest large volumes of data from enterprise-level storage environments.IBM Storage Scale (formerly IBM Spectrum Scale, originally GPFS) is a high-performance, software-defined parallel file system for managing massive amounts of unstructured data across storage types, locations, and cloud environments. This connector collects Command Line Interface (CLI) audit log records from the IBM Storage Scale API, using a concurrent fetching mechanism to efficiently ingest large volumes of data from enterprise-level storage environments.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # IBM Storage Scale {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. IBM Storage Scale (formerly IBM Spectrum Scale, originally GPFS) is a high-performance, software-defined parallel file system for managing massive amounts of unstructured data across storage types, locations, and cloud environments. This connector collects Command Line Interface (CLI) audit log records from the IBM Storage Scale API, using a concurrent fetching mechanism to efficiently ingest large volumes of data from enterprise-level storage environments. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ iManage modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/imanage/imanageRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# iManage# iManagehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.iManage Threat Manager uses machine learning and user behavior analytics to detect unusual user behavior, prevent data loss, and ensure compliance, protecting privileged information against internal and external threat actors. Fetch and manage security alerts from iManage Threat Manager.iManage Threat Manager uses machine learning and user behavior analytics to detect unusual user behavior, prevent data loss, and ensure compliance, protecting privileged information against internal and external threat actors. Fetch and manage security alerts from iManage Threat Manager.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # iManage {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. iManage Threat Manager uses machine learning and user behavior analytics to detect unusual user behavior, prevent data loss, and ensure compliance, protecting privileged information against internal and external threat actors. Fetch and manage security alerts from iManage Threat Manager. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Imperva modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/imperva/impervaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Imperva# Impervahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Imperva security products. Imperva Skyfence is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud apps. Imperva WAF (SecureSphere) protects web applications from cyber attacks. Imperva Incapsula (Cloud WAF) manages sites and IPs.Integrate with Imperva security products. Imperva Skyfence is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud apps. Imperva WAF (SecureSphere) protects web applications from cyber attacks. Imperva Incapsula (Cloud WAF) manages sites and IPs.This connector includes the following sub-capabilities:This connector includes the following sub-capabilities:Show markdown source
@@ -1,14 +1,14 @@ # Imperva {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Imperva security products. Imperva Skyfence is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud apps. Imperva WAF (SecureSphere) protects web applications from cyber attacks. Imperva Incapsula (Cloud WAF) manages sites and IPs. This connector includes the following sub-capabilities: -
▸ ▾ InfoArmor modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/infoarmor/infoarmorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# InfoArmor# InfoArmorhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.VigilanteATI provides advanced threat intelligence. InfoArmor’s VigilanteATI platform and cyber threat services extend your IT security team.VigilanteATI provides advanced threat intelligence. InfoArmor’s VigilanteATI platform and cyber threat services extend your IT security team.• InfoArmor VigilanteATI: Provides advanced threat intelligence.• InfoArmor VigilanteATI: Provides advanced threat intelligence.Show markdown source
@@ -1,14 +1,14 @@ # InfoArmor {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. VigilanteATI provides advanced threat intelligence. InfoArmor’s VigilanteATI platform and cyber threat services extend your IT security team. * [InfoArmor VigilanteATI](https://xsoar.pan.dev/docs/reference/integrations/info-armor-vigilante-ati): Provides advanced threat intelligence. -
▸ ▾ Infoblox modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/infoblox/infobloxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Infoblox# Infobloxhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Infoblox BloxOne Threat Defense is a hybrid cybersecurity solution that leverages DNS as the first line of defense to detect and block cyber threats. This connector collects Threat Defense events, sharing threat intelligence, automated indicator enrichment, and DNS-based security controls.Infoblox BloxOne Threat Defense is a hybrid cybersecurity solution that leverages DNS as the first line of defense to detect and block cyber threats. This connector collects Threat Defense events, sharing threat intelligence, automated indicator enrichment, and DNS-based security controls.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Infoblox {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Infoblox BloxOne Threat Defense is a hybrid cybersecurity solution that leverages DNS as the first line of defense to detect and block cyber threats. This connector collects Threat Defense events, sharing threat intelligence, automated indicator enrichment, and DNS-based security controls. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Intellum modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/intellum/intellumRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Intellum# Intellumhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.Manage the identity lifecycle of users in Intellum ExceedLMS. Use this connector as part of the Identity Lifecycle Management premium pack to create, update, enable, and disable users. Tested with version v2 of ExceedLMS.Manage the identity lifecycle of users in Intellum ExceedLMS. Use this connector as part of the Identity Lifecycle Management premium pack to create, update, enable, and disable users. Tested with version v2 of ExceedLMS.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Intellum {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license. Manage the identity lifecycle of users in Intellum ExceedLMS. Use this connector as part of the [Identity Lifecycle Management](https://xsoar.pan.dev/docs/reference/articles/identity-lifecycle-management) premium pack to create, update, enable, and disable users. Tested with version v2 of ExceedLMS. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ IPInfo.io modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ipinfo.io/ipinfo.ioRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# IPInfo.io# IPInfo.iohint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the IPinfo.io API to get data about an IP address. IPinfo v2 lets you set source reliability and enriches data with IP-hostname relationships.Use the IPinfo.io API to get data about an IP address. IPinfo v2 lets you set source reliability and enriches data with IP-hostname relationships.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # IPInfo.io {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the IPinfo.io API to get data about an IP address. IPinfo v2 lets you set source reliability and enriches data with IP-hostname relationships. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ IPstack modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ipstack/ipstackRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# IPstack# IPstackhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.One of the leading IP to geolocation APIs and global IP database services.One of the leading IP to geolocation APIs and global IP database services.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # IPstack {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. One of the leading IP to geolocation APIs and global IP database services. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Ironscales modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ironscales/ironscalesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Ironscales# Ironscaleshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.IRONSCALES is an AI-powered email security platform that detects, remediates, and prevents phishing and BEC attacks while training users through integrated awareness tools. Use this connector to collect Ironscales email security event log messages, including XDM mapping for key event types.IRONSCALES is an AI-powered email security platform that detects, remediates, and prevents phishing and BEC attacks while training users through integrated awareness tools. Use this connector to collect Ironscales email security event log messages, including XDM mapping for key event types.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Ironscales {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. IRONSCALES is an AI-powered email security platform that detects, remediates, and prevents phishing and BEC attacks while training users through integrated awareness tools. Use this connector to collect Ironscales email security event log messages, including XDM mapping for key event types. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Ivanti modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ivanti/ivantiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Ivanti# Ivantihint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Ivanti IT service management products. Cherwell is a cloud-based IT service management solution where you can create, read, update, and delete business objects, together with attachments and relations operations. Ivanti Heat is the Ivanti Heat service manager.Integrate with Ivanti IT service management products. Cherwell is a cloud-based IT service management solution where you can create, read, update, and delete business objects, together with attachments and relations operations. Ivanti Heat is the Ivanti Heat service manager.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Ivanti {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Ivanti IT service management products. Cherwell is a cloud-based IT service management solution where you can create, read, update, and delete business objects, together with attachments and relations operations. Ivanti Heat is the Ivanti Heat service manager. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ iZOOlogic modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/izoologic/izoologicRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# iZOOlogic# iZOOlogichint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on.iZOOlogic is a brand protection and threat management platform. This connector fetches and manages issues from iZOOlogic, enabling automated ingestion, issue creation, and advanced filtering across threat types including phishing, brand abuse, malware, and more.iZOOlogic is a brand protection and threat management platform. This connector fetches and manages issues from iZOOlogic, enabling automated ingestion, issue creation, and advanced filtering across threat types including phishing, brand abuse, malware, and more.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # iZOOlogic {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on. iZOOlogic is a brand protection and threat management platform. This connector fetches and manages issues from iZOOlogic, enabling automated ingestion, issue creation, and advanced filtering across threat types including phishing, brand abuse, malware, and more. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Jamf modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jamf/jamfRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Jamf# Jamfhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintEnterprise Mobility Management (EMM) for Apple devices (Mac, iPhone, Apple TV, iPad) with Jamf Pro, used to control configurations via policies, install and uninstall applications, lock devices, run smart group searches, and more. Also fetches audit logs, alert events, and computer assets from Jamf Protect.Enterprise Mobility Management (EMM) for Apple devices (Mac, iPhone, Apple TV, iPad) with Jamf Pro, used to control configurations via policies, install and uninstall applications, lock devices, run smart group searches, and more. Also fetches audit logs, alert events, and computer assets from Jamf Protect.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Jamf Protect Event Collector: Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.• Jamf Protect Event Collector: Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.• jamf v2: Enterprise Mobility Management (EMM) for Apple devices (Mac, iPhone, Apple TV, iPad). Can be used to control various configurations via different policies, install and uninstall applications, lock devices, smart groups searches, and more. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• jamf v2: Enterprise Mobility Management (EMM) for Apple devices (Mac, iPhone, Apple TV, iPad). Can be used to control various configurations via different policies, install and uninstall applications, lock devices, smart groups searches, and more. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Jamf {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Enterprise Mobility Management (EMM) for Apple devices (Mac, iPhone, Apple TV, iPad) with Jamf Pro, used to control configurations via policies, install and uninstall applications, lock devices, run smart group searches, and more. Also fetches audit logs, alert events, and computer assets from Jamf Protect. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Jamf Protect Event Collector](https://xsoar.pan.dev/docs/reference/integrations/jamf-protect-event-collector): Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license. * [jamf v2](https://xsoar.pan.dev/docs/reference/integrations/jamf-v2): Enterprise Mobility Management (EMM) for Apple devices (Mac, iPhone, Apple TV, iPad). Can be used to control various configurations via different policies, install and uninstall applications, lock devices, smart groups searches, and more. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Joe Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/joe-security/joe-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Joe Security# Joe Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Access the full set of possibilities the Joe Sandbox Cloud provides via RESTful Web API v2 to detonate and analyze suspicious files and URLs and enrich indicators.Access the full set of possibilities the Joe Sandbox Cloud provides via RESTful Web API v2 to detonate and analyze suspicious files and URLs and enrich indicators.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Joe Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Access the full set of possibilities the Joe Sandbox Cloud provides via RESTful Web API v2 to detonate and analyze suspicious files and URLs and enrich indicators. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ JSONWhoIs.com modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jsonwhois.com/jsonwhois.comRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# JSONWhoIs.com# JSONWhoIs.comhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Execute queries on URLs and IP addresses, and get information for domains. Use the JsonWhoIs integration to enrich domain indicators.Execute queries on URLs and IP addresses, and get information for domains. Use the JsonWhoIs integration to enrich domain indicators.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # JSONWhoIs.com {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Execute queries on URLs and IP addresses, and get information for domains. Use the JsonWhoIs integration to enrich domain indicators. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Kafka modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kafka/kafkaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Kafka# Kafkahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Kafka is an open-source distributed streaming platform. Use this connector to manage messages and partitions, and fetch Kafka messages to create issues.Kafka is an open-source distributed streaming platform. Use this connector to manage messages and partitions, and fetch Kafka messages to create issues.Show markdown source
@@ -1,14 +1,14 @@ # Kafka {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Kafka is an open-source distributed streaming platform. Use this connector to manage messages and partitions, and fetch Kafka messages to create issues. * [KafkaV3](https://xsoar.pan.dev/docs/reference/integrations/kafka-v3): Kafka integration. -
▸ ▾ Kaspersky modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kaspersky/kasperskyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Kaspersky# Kasperskyhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the Kaspersky administration console to manage endpoints, administration groups, host and software details, and policies. This beta connector supports a subset of endpoint and API use cases.Use the Kaspersky administration console to manage endpoints, administration groups, host and software details, and policies. This beta connector supports a subset of endpoint and API use cases.• Kaspersky Security Center: Manages endpoints and groups.• Kaspersky Security Center: Manages endpoints and groups.Show markdown source
@@ -1,14 +1,14 @@ # Kaspersky {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the Kaspersky administration console to manage endpoints, administration groups, host and software details, and policies. This beta connector supports a subset of endpoint and API use cases. * [Kaspersky Security Center](https://xsoar.pan.dev/docs/reference/integrations/kaspersky-security-center): Manages endpoints and groups. -
▸ ▾ Keeper Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/keeper-security/keeper-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Keeper Security# Keeper Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Access the Keeper Security Admin Console to track and manage multiple Keeper Security products. Fetches audit logs from the Keeper Security Admin Console as events, with XDM mapping for key event types.Access the Keeper Security Admin Console to track and manage multiple Keeper Security products. Fetches audit logs from the Keeper Security Admin Console as events, with XDM mapping for key event types.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Keeper Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Access the Keeper Security Admin Console to track and manage multiple Keeper Security products. Fetches audit logs from the Keeper Security Admin Console as events, with XDM mapping for key event types. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ KnowB4 modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/knowbe4/knowb4Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# KnowB4# KnowB4hint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.KnowBe4 KMSAT provides security awareness training and simulated phishing data. Use the connector to exchange external data with the KnowBe4 console for automation, playbooks, and reports.KnowBe4 KMSAT provides security awareness training and simulated phishing data. Use the connector to exchange external data with the KnowBe4 console for automation, playbooks, and reports.• KnowBe4 KMSAT Event Collector: Collects KnowBe4 KMSAT data.• KnowBe4 KMSAT Event Collector: Collects KnowBe4 KMSAT data.Show markdown source
@@ -1,14 +1,14 @@ # KnowB4 {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. KnowBe4 KMSAT provides security awareness training and simulated phishing data. Use the connector to exchange external data with the KnowBe4 console for automation, playbooks, and reports. * [KnowBe4 KMSAT Event Collector](https://xsoar.pan.dev/docs/reference/integrations/know-be4-kmsat-event-collector): Collects KnowBe4 KMSAT data. -
▸ ▾ Koi modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/koi/koiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Koi# Koihint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on.KOI provides visibility and control over browser extensions, SaaS applications, and web-based threats. This connector ingests KOI alerts and audit logs for centralized monitoring, correlation, and threat analysis.KOI provides visibility and control over browser extensions, SaaS applications, and web-based threats. This connector ingests KOI alerts and audit logs for centralized monitoring, correlation, and threat analysis.• KOI: KOI endpoint security platform integration.• KOI: KOI endpoint security platform integration.Show markdown source
@@ -1,14 +1,14 @@ # Koi {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security with the Application Security Posture Management (ASPM) module, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license with the Attack Surface Management (ASM), Exposure Management, or Threat Intel Management (TIM) add-on. KOI provides visibility and control over browser extensions, SaaS applications, and web-based threats. This connector ingests KOI alerts and audit logs for centralized monitoring, correlation, and threat analysis. * [KOI](https://xsoar.pan.dev/docs/reference/integrations/koi): KOI endpoint security platform integration. -
▸ ▾ Koodous modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/koodous/koodousRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Koodous# Koodoushint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Check Android app samples (APK) against the Koodous API.Check Android app samples (APK) against the Koodous API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Koodous {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Check Android app samples (APK) against the Koodous API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Lastline modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lastline/lastlineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Lastline# Lastlinehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Provides threat analysts and issue response teams with the advanced malware isolation and inspection environment needed to safely execute advanced malware samples and understand their behavior. Detonate both files and URLs.Provides threat analysts and issue response teams with the advanced malware isolation and inspection environment needed to safely execute advanced malware samples and understand their behavior. Detonate both files and URLs.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Lastline {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Provides threat analysts and issue response teams with the advanced malware isolation and inspection environment needed to safely execute advanced malware samples and understand their behavior. Detonate both files and URLs. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ LevelBlue modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/levelblue/levelblueRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# LevelBlue# LevelBluehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Trustwave Secure Email Gateway (SEG) is a secure messaging solution that protects businesses and users from email-borne threats, including phishing, blended threats, and spam. It also delivers improved policy enforcement and data leakage prevention.Trustwave Secure Email Gateway (SEG) is a secure messaging solution that protects businesses and users from email-borne threats, including phishing, blended threats, and spam. It also delivers improved policy enforcement and data leakage prevention.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # LevelBlue {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Trustwave Secure Email Gateway (SEG) is a secure messaging solution that protects businesses and users from email-borne threats, including phishing, blended threats, and spam. It also delivers improved policy enforcement and data leakage prevention. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ LogRhythm modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/logrhythm/logrhythmRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# LogRhythm# LogRhythmhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with LogRhythm using its REST API to deliver security operations across your enterprise IT environment. Execute queries on logs, get host information, add new hosts and update host status, and query and update alarms. Retrieve case summaries, create new cases, or update the properties of a case; manage tags and lists; and fetch cases and alarms as issues.Integrate with LogRhythm using its REST API to deliver security operations across your enterprise IT environment. Execute queries on logs, get host information, add new hosts and update host status, and query and update alarms. Retrieve case summaries, create new cases, or update the properties of a case; manage tags and lists; and fetch cases and alarms as issues.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # LogRhythm {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with LogRhythm using its REST API to deliver security operations across your enterprise IT environment. Execute queries on logs, get host information, add new hosts and update host status, and query and update alarms. Retrieve case summaries, create new cases, or update the properties of a case; manage tags and lists; and fetch cases and alarms as issues. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ LOLBAS modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lolbas/lolbasRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# LOLBAS# LOLBAShint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.Import Living Off The Land Binaries, Scripts and Libraries (LOLBAS) into the Threat Intelligence Management (TIM) module for security investigations and threat hunting activities. "Living off the land binaries" describes malware or hacking techniques that abuse legitimate tools and processes already present on a system to blend in with normal activity and avoid detection. The LOLBAS project documents binaries, scripts, and libraries that can be used for these techniques.Import Living Off The Land Binaries, Scripts and Libraries (LOLBAS) into the Threat Intelligence Management (TIM) module for security investigations and threat hunting activities. "Living off the land binaries" describes malware or hacking techniques that abuse legitimate tools and processes already present on a system to blend in with normal activity and avoid detection. The LOLBAS project documents binaries, scripts, and libraries that can be used for these techniques.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # LOLBAS {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license. Import Living Off The Land Binaries, Scripts and Libraries (LOLBAS) into the Threat Intelligence Management (TIM) module for security investigations and threat hunting activities. "Living off the land binaries" describes malware or hacking techniques that abuse legitimate tools and processes already present on a system to blend in with normal activity and avoid detection. The LOLBAS project documents binaries, scripts, and libraries that can be used for these techniques. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Lookout modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lookout/lookoutRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Lookout# Lookouthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Lookout Mobile Endpoint Security (MES) protects mobile devices from threats such as phishing, malware, network attacks, and device vulnerabilities using AI-driven threat intelligence. Use this connector to automatically collect events from Lookout Mobile Endpoint Security. This integration was integrated and tested with version v2 of the Mobile Risk API.Lookout Mobile Endpoint Security (MES) protects mobile devices from threats such as phishing, malware, network attacks, and device vulnerabilities using AI-driven threat intelligence. Use this connector to automatically collect events from Lookout Mobile Endpoint Security. This integration was integrated and tested with version v2 of the Mobile Risk API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Lookout {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Lookout Mobile Endpoint Security (MES) protects mobile devices from threats such as phishing, malware, network attacks, and device vulnerabilities using AI-driven threat intelligence. Use this connector to automatically collect events from Lookout Mobile Endpoint Security. This integration was integrated and tested with version v2 of the Mobile Risk API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Lumu modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lumu/lumuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Lumu# Lumuhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Analyze suspicious hashes, URLs, domains, and IP addresses with Maltiverse. Enrich indicators, retrieve reputation data, and calculate reputation scores across different IOC types.Analyze suspicious hashes, URLs, domains, and IP addresses with Maltiverse. Enrich indicators, retrieve reputation data, and calculate reputation scores across different IOC types.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Lumu {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Analyze suspicious hashes, URLs, domains, and IP addresses with Maltiverse. Enrich indicators, retrieve reputation data, and calculate reputation scores across different IOC types. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Mail Utilities modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mail-utilities/mail-utilitiesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Mail Utilities# Mail Utilitieshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintMail Utilities lets you listen to a mailbox and spawn an issue from received email, and send emails including rich HTML and embedded files. It includes the Mail Listener v2 and MailListener - POP3 integrations for fetching mail, and the Mail Sender (New) integration for sending mail.Mail Utilities lets you listen to a mailbox and spawn an issue from received email, and send emails including rich HTML and embedded files. It includes the Mail Listener v2 and MailListener - POP3 integrations for fetching mail, and the Mail Sender (New) integration for sending mail.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Mail Listener v2: Listens to a mailbox and enables incident triggering via e-mail. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Mail Listener v2: Listens to a mailbox and enables incident triggering via e-mail. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Mail Sender (New): Send emails implemented in Python with embedded image support. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Mail Sender (New): Send emails implemented in Python with embedded image support. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Mail Utilities {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Mail Utilities lets you listen to a mailbox and spawn an issue from received email, and send emails including rich HTML and embedded files. It includes the Mail Listener v2 and MailListener - POP3 integrations for fetching mail, and the Mail Sender (New) integration for sending mail. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Mail Listener v2](https://xsoar.pan.dev/docs/reference/integrations/mail-listener-v2): Listens to a mailbox and enables incident triggering via e-mail. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Mail Sender (New)](https://xsoar.pan.dev/docs/reference/integrations/mail-sender-new): Send emails implemented in Python with embedded image support. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ Majestic modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/majestic/majesticRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Majestic# Majestichint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This feed integration ingests the top most common web site addresses as 'good' indicators from the Majestic Million feed.This feed integration ingests the top most common web site addresses as 'good' indicators from the Majestic Million feed.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Majestic {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. This feed integration ingests the top most common web site addresses as 'good' indicators from the Majestic Million feed. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ManageEngine modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/manageengine/manageengineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ManageEngine# ManageEnginehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Zoho Corporation products. ManageEngine Endpoint Central is a unified endpoint management (UEM) platform that manages and secures servers, desktops, laptops, and mobile devices from a single console, and serves as an event collector for audit logs. Service Desk Plus is an IT service management (ITSM) solution for fetching and managing service desk requests.Integrate with Zoho Corporation products. ManageEngine Endpoint Central is a unified endpoint management (UEM) platform that manages and secures servers, desktops, laptops, and mobile devices from a single console, and serves as an event collector for audit logs. Service Desk Plus is an IT service management (ITSM) solution for fetching and managing service desk requests.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• ManageEngine: This sub-capability is available with any active Cortex XSIAM license.• ManageEngine: This sub-capability is available with any active Cortex XSIAM license.• ServiceDeskPlus: Use this integration to manage on-premises and cloud Service Desk Plus requests. The integration allows you to create, update, and delete requests, assign groups and technicians to requests, and link/unlink requests and modify their resolution. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• ServiceDeskPlus: Use this integration to manage on-premises and cloud Service Desk Plus requests. The integration allows you to create, update, and delete requests, assign groups and technicians to requests, and link/unlink requests and modify their resolution. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # ManageEngine {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Zoho Corporation products. ManageEngine Endpoint Central is a unified endpoint management (UEM) platform that manages and secures servers, desktops, laptops, and mobile devices from a single console, and serves as an event collector for audit logs. Service Desk Plus is an IT service management (ITSM) solution for fetching and managing service desk requests. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [ManageEngine](https://xsoar.pan.dev/docs/reference/integrations/manage-engine): This sub-capability is available with any active Cortex XSIAM license. * [ServiceDeskPlus](https://xsoar.pan.dev/docs/reference/integrations/service-desk-plus): Use this integration to manage on-premises and cloud Service Desk Plus requests. The integration allows you to create, update, and delete requests, assign groups and technicians to requests, and link/unlink requests and modify their resolution. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Mattermost modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mattermost/mattermostRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Mattermost# Mattermosthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Mattermost is an open-source, self-hostable online chat service with file sharing, search, and integrations, designed as an internal chat for organizations and companies. This connector integrates with Mattermost to send messages and notifications, and to mirror investigations.Mattermost is an open-source, self-hostable online chat service with file sharing, search, and integrations, designed as an internal chat for organizations and companies. This connector integrates with Mattermost to send messages and notifications, and to mirror investigations.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Mattermost {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Mattermost is an open-source, self-hostable online chat service with file sharing, search, and integrations, designed as an internal chat for organizations and companies. This connector integrates with Mattermost to send messages and notifications, and to mirror investigations. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ MaxMind modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/maxmind/maxmindRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,13 +1,13 @@# MaxMind# MaxMindhint warninghint warningImportant\Important\This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.The MaxMind GeoIP2 integration allows you to query the MaxMind API service and retrieve a JSON of all details.The MaxMind GeoIP2 integration allows you to query the MaxMind API service and retrieve a JSON of all details.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,13 +1,13 @@ # MaxMind {% hint style="warning" %} **Important**\ -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. The MaxMind GeoIP2 integration allows you to query the MaxMind API service and retrieve a JSON of all details. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Menlo Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/menlo-security/menlo-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Menlo Security# Menlo Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.The cloud-based Menlo Security Isolation Platform (MSIP) eliminates the possibility of malware reaching user devices via compromised or malicious web sites, email, or documents. This integration collects logs from the MSIP Logging API and sends them to Cortex.The cloud-based Menlo Security Isolation Platform (MSIP) eliminates the possibility of malware reaching user devices via compromised or malicious web sites, email, or documents. This integration collects logs from the MSIP Logging API and sends them to Cortex.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Menlo Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. The cloud-based Menlo Security Isolation Platform (MSIP) eliminates the possibility of malware reaching user devices via compromised or malicious web sites, email, or documents. This integration collects logs from the MSIP Logging API and sends them to Cortex. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Meta modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/meta/metaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@# Meta# Metahint warninghint warningThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Receive threat intelligence about applications, IP addresses, URLs, and hashes from Meta's ThreatExchange, a service by Facebook.Receive threat intelligence about applications, IP addresses, URLs, and hashes from Meta's ThreatExchange, a service by Facebook.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,12 +1,12 @@ # Meta {% hint style="warning" %} -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Receive threat intelligence about applications, IP addresses, URLs, and hashes from Meta's ThreatExchange, a service by Facebook. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Azure DevOps modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-devopsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Azure DevOps# Azure DevOpshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Manage Git repositories in Azure DevOps Services. Integration capabilities include retrieving, creating, and updating pull requests, running pipelines, and retrieving Git information. Microsoft Azure DevOps Server provides version control, reporting, requirements management, project management, automated builds, testing, and release management capabilities across the entire application lifecycle.Manage Git repositories in Azure DevOps Services. Integration capabilities include retrieving, creating, and updating pull requests, running pipelines, and retrieving Git information. Microsoft Azure DevOps Server provides version control, reporting, requirements management, project management, automated builds, testing, and release management capabilities across the entire application lifecycle.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Azure DevOps {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Manage Git repositories in Azure DevOps Services. Integration capabilities include retrieving, creating, and updating pull requests, running pipelines, and retrieving Git information. Microsoft Azure DevOps Server provides version control, reporting, requirements management, project management, automated builds, testing, and release management capabilities across the entire application lifecycle. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Azure Firewall modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-firewallRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Azure Firewall# Azure Firewallhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Azure Firewall is a cloud-native and intelligent network firewall security service that provides breed threat protection for cloud workloads running in Azure. It's a fully stateful, firewall as a service, with built-in high availability and unrestricted cloud scalability.Azure Firewall is a cloud-native and intelligent network firewall security service that provides breed threat protection for cloud workloads running in Azure. It's a fully stateful, firewall as a service, with built-in high availability and unrestricted cloud scalability.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Azure Firewall {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Azure Firewall is a cloud-native and intelligent network firewall security service that provides breed threat protection for cloud workloads running in Azure. It's a fully stateful, firewall as a service, with built-in high availability and unrestricted cloud scalability. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Azure Log Analytics modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-log-analyticsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Azure Log Analytics# Azure Log Analyticshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments.Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Azure Log Analytics {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license. Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Azure Services modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-servicesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Azure Services# Azure Serviceshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Microsoft Azure services. Create and manage Azure Virtual Machines (Azure Compute), deploy and manage containerized applications with Azure Kubernetes Services (AKS), filter network traffic with Azure Network Security Groups, manage auditing and threat policies for Azure SQL, deploy and manage storage accounts, blob services, containers, file shares, tables, and queues (Azure Storage), query resources at scale with Azure Resource Graph, collect and analyze data in Azure Data Explorer clusters, and safeguard and manage cryptographic keys and secrets with Azure Key Vault.Integrate with Microsoft Azure services. Create and manage Azure Virtual Machines (Azure Compute), deploy and manage containerized applications with Azure Kubernetes Services (AKS), filter network traffic with Azure Network Security Groups, manage auditing and threat policies for Azure SQL, deploy and manage storage accounts, blob services, containers, file shares, tables, and queues (Azure Storage), query resources at scale with Azure Resource Graph, collect and analyze data in Azure Data Explorer clusters, and safeguard and manage cryptographic keys and secrets with Azure Key Vault.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Azure Compute v2: Create and Manage Azure Virtual Machines. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Azure Compute v2: Create and Manage Azure Virtual Machines. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Azure Kubernetes Services: Deploy and manage containerized applications with a fully managed Kubernetes service. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Azure Kubernetes Services: Deploy and manage containerized applications with a fully managed Kubernetes service. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Azure Services {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Microsoft Azure services. Create and manage Azure Virtual Machines (Azure Compute), deploy and manage containerized applications with Azure Kubernetes Services (AKS), filter network traffic with Azure Network Security Groups, manage auditing and threat policies for Azure SQL, deploy and manage storage accounts, blob services, containers, file shares, tables, and queues (Azure Storage), query resources at scale with Azure Resource Graph, collect and analyze data in Azure Data Explorer clusters, and safeguard and manage cryptographic keys and secrets with Azure Key Vault. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Azure Compute v2](https://xsoar.pan.dev/docs/reference/integrations/azure-compute-v2): Create and Manage Azure Virtual Machines. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Azure Kubernetes Services](https://xsoar.pan.dev/docs/reference/integrations/azure-kubernetes-services): Deploy and manage containerized applications with a fully managed Kubernetes service. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Azure WAF modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-wafRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Azure WAF# Azure WAFhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common web exploits and vulnerabilities, such as SQL injection and cross-site scripting. It operates as an application-level firewall and integrates with Azure services like Azure Application Gateway, Azure Front Door, and Azure CDN. This connector lets you control policies configured in the Azure Firewall management platform — add, delete, or update policies, and get details of a specific policy or a list of policies.Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common web exploits and vulnerabilities, such as SQL injection and cross-site scripting. It operates as an application-level firewall and integrates with Azure services like Azure Application Gateway, Azure Front Door, and Azure CDN. This connector lets you control policies configured in the Azure Firewall management platform — add, delete, or update policies, and get details of a specific policy or a list of policies.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Azure WAF {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common web exploits and vulnerabilities, such as SQL injection and cross-site scripting. It operates as an application-level firewall and integrates with Azure services like Azure Application Gateway, Azure Front Door, and Azure CDN. This connector lets you control policies configured in the Azure Firewall management platform — add, delete, or update policies, and get details of a specific policy or a list of policies. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ M365 Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/m365-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# M365 Automation and Collection# M365 Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintAutomate and collect across Microsoft 365 and Office 365 services, including Exchange Online mail (EWS and Microsoft Graph), Outlook calendars, Microsoft Teams messaging and management, the Microsoft Management Activity (O365/Azure) audit feed, unified audit-log policy and compliance search, message trace, endpoint configuration management, and the Office 365 IP/URL feed. Send messages and notifications, manage mailboxes and teams, search and remediate email, and fetch issues, indicators, and logs from your M365 tenant.Automate and collect across Microsoft 365 and Office 365 services, including Exchange Online mail (EWS and Microsoft Graph), Outlook calendars, Microsoft Teams messaging and management, the Microsoft Management Activity (O365/Azure) audit feed, unified audit-log policy and compliance search, message trace, endpoint configuration management, and the Office 365 IP/URL feed. Send messages and notifications, manage mailboxes and teams, search and remediate email, and fetch issues, indicators, and logs from your M365 tenant.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• EWS Extension Online Powershell v3: This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• EWS Extension Online Powershell v3: This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• EWS v2: Exchange Web Services and Office 365 (mail). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• EWS v2: Exchange Web Services and Office 365 (mail). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # M365 Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Automate and collect across Microsoft 365 and Office 365 services, including Exchange Online mail (EWS and Microsoft Graph), Outlook calendars, Microsoft Teams messaging and management, the Microsoft Management Activity (O365/Azure) audit feed, unified audit-log policy and compliance search, message trace, endpoint configuration management, and the Office 365 IP/URL feed. Send messages and notifications, manage mailboxes and teams, search and remediate email, and fetch issues, indicators, and logs from your M365 tenant. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [EWS Extension Online Powershell v3](https://xsoar.pan.dev/docs/reference/integrations/ews-extension-online-powershell-v3): This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [EWS v2](https://xsoar.pan.dev/docs/reference/integrations/ews-v2): Exchange Web Services and Office 365 (mail). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ Microsoft Active Directory modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-active-directoryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Microsoft Active Directory# Microsoft Active Directoryhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Access and manage Active Directory users, contacts, and computers. Run Active Directory queries, manage users, and add or remove users and computers from groups.Access and manage Active Directory users, contacts, and computers. Run Active Directory queries, manage users, and add or remove users and computers from groups.Show markdown source
@@ -1,14 +1,14 @@ # Microsoft Active Directory {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. Access and manage Active Directory users, contacts, and computers. Run Active Directory queries, manage users, and add or remove users and computers from groups. * [Active Directory Query v2](https://xsoar.pan.dev/docs/reference/integrations/active-directory-query-v2) -
▸ ▾ Microsoft Graph modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-graphRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Microsoft Graph# Microsoft Graphhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Microsoft products through the Microsoft Graph API and Microsoft Endpoint Manager (Intune). Use the Microsoft Graph API to interact with Microsoft APIs that do not have dedicated connectors, and use Microsoft Endpoint Manager (Intune) for cloud-based mobile device and operating system management.Integrate with Microsoft products through the Microsoft Graph API and Microsoft Endpoint Manager (Intune). Use the Microsoft Graph API to interact with Microsoft APIs that do not have dedicated connectors, and use Microsoft Endpoint Manager (Intune) for cloud-based mobile device and operating system management.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Microsoft Graph API: Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, for example, Mail Single-User, etc. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Microsoft Graph API: Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, for example, Mail Single-User, etc. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Microsoft Graph Device Management: Microsoft Intune is a Microsoft cloud-based management solution that provides for mobile device and operating system management. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Microsoft Graph Device Management: Microsoft Intune is a Microsoft cloud-based management solution that provides for mobile device and operating system management. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Microsoft Graph {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Microsoft products through the Microsoft Graph API and Microsoft Endpoint Manager (Intune). Use the Microsoft Graph API to interact with Microsoft APIs that do not have dedicated connectors, and use Microsoft Endpoint Manager (Intune) for cloud-based mobile device and operating system management. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Microsoft Graph API](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-api): Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, for example, Mail Single-User, etc. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [Microsoft Graph Device Management](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-device-management): Microsoft Intune is a Microsoft cloud-based management solution that provides for mobile device and operating system management. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ Microsoft Identity modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-identityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Microsoft Identity# Microsoft Identityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintManage Microsoft Entra ID (formerly Azure Active Directory) identity resources — users, groups, applications and service principals, directory roles, conditional access, and risky users — and ingest Azure public IP address and endpoint indicator feeds. Fetches Microsoft Entra ID Protection risk detections as issues and enables automation and remediation across the Microsoft Graph and Azure APIs.Manage Microsoft Entra ID (formerly Azure Active Directory) identity resources — users, groups, applications and service principals, directory roles, conditional access, and risky users — and ingest Azure public IP address and endpoint indicator feeds. Fetches Microsoft Entra ID Protection risk detections as issues and enables automation and remediation across the Microsoft Graph and Azure APIs.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Azure AD Connect Health Feed: Use the Microsoft Azure AD Connect Health Feed integration to get indicators from the feed. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Azure AD Connect Health Feed: Use the Microsoft Azure AD Connect Health Feed integration to get indicators from the feed. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Microsoft Identity {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Manage Microsoft Entra ID (formerly Azure Active Directory) identity resources — users, groups, applications and service principals, directory roles, conditional access, and risky users — and ingest Azure public IP address and endpoint indicator feeds. Fetches Microsoft Entra ID Protection risk detections as issues and enables automation and remediation across the Microsoft Graph and Azure APIs. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Azure AD Connect Health Feed](https://xsoar.pan.dev/docs/reference/integrations/azure-ad-connect-health-feed): Use the Microsoft Azure AD Connect Health Feed integration to get indicators from the feed. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [AzureFeed](https://xsoar.pan.dev/docs/reference/integrations/azure-feed): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Microsoft Intune modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-intuneRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Microsoft Intune# Microsoft Intunehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Microsoft Intune Feed collects the public IP addresses, domains, and URLs that function as endpoints for Microsoft Intune and delivers them as an indicator feed. It automates scraping this endpoint data, which Microsoft publishes as HTML rather than through a REST API, so IT and Security teams can validate the indicators before using them in enforcement points such as firewalls and proxies.Microsoft Intune Feed collects the public IP addresses, domains, and URLs that function as endpoints for Microsoft Intune and delivers them as an indicator feed. It automates scraping this endpoint data, which Microsoft publishes as HTML rather than through a REST API, so IT and Security teams can validate the indicators before using them in enforcement points such as firewalls and proxies.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Microsoft Intune {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Microsoft Intune Feed collects the public IP addresses, domains, and URLs that function as endpoints for Microsoft Intune and delivers them as an indicator feed. It automates scraping this endpoint data, which Microsoft publishes as HTML rather than through a REST API, so IT and Security teams can validate the indicators before using them in enforcement points such as firewalls and proxies. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Microsoft Security Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-security-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Microsoft Security Automation and Collection# Microsoft Security Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Microsoft products.Integrate with Microsoft products.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Azure Security Center v2: Unified security management and advanced threat protection across hybrid cloud workloads. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Azure Security Center v2: Unified security management and advanced threat protection across hybrid cloud workloads. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Azure Sentinel: Microsoft Sentinel is a scalable, cloud-native solution that provides: Security information and event management (SIEM) Security orchestration, automation, and response (SOAR). This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Azure Sentinel: Microsoft Sentinel is a scalable, cloud-native solution that provides: Security information and event management (SIEM) Security orchestration, automation, and response (SOAR). This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Microsoft Security Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Microsoft products. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Azure Security Center v2](https://xsoar.pan.dev/docs/reference/integrations/azure-security-center-v2): Unified security management and advanced threat protection across hybrid cloud workloads. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Azure Sentinel](https://xsoar.pan.dev/docs/reference/integrations/azure-sentinel): Microsoft Sentinel is a scalable, cloud-native solution that provides: Security information and event management (SIEM) Security orchestration, automation, and response (SOAR). This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.