Documentation — August 11, 2026
314 files changed, 354 insertions, 437 deletions — view the commit on the mirror.
Marketplace links restored on 296 data-source pages; Cloud Application Security rewritten with licensing
- 296 XSIAM data-source connector pages turned a plain-text Marketplace mention into a working link — the bulk of the day, and the only change on those pages.
- Cortex Cloud Application Security was rewritten around three use cases and now states which base licence each one needs.
- Nine Cortex XDR agent pages replaced their markdown tables with raw HTML, and several console names picked up bold.
- Outbound links in the agent guide moved from
docs-cortex.paloaltonetworks.comtoapp.gitbook.comspaces. - Nothing was added, deleted or renamed: all 316 files were modifications.
Highlights
-
Cortex Cloud Application Security now states its licence requirements
ASPM and Supply Chain Security are included with a Cloud Posture, Cloud Runtime or XSIAM Premium base licence, while Code Security requires a separate Application Security add-on purchase.
-
296 data-source pages gained a working Marketplace link
The notice that a connector is only available to tenants onboarded after July 26, 2026 now links "Marketplace" to ../../marketplace instead of naming it in plain text.
-
The agent guide's compatibility and release links now point at GitBook
Both references on the agent introduction moved from docs-cortex.paloaltonetworks.com to app.gitbook.com space URLs, and the Mac uninstall page gained a GitBook link where it previously had bare text.
-
The Azure BYOA security note was reframed from a statement of fact into a least-privilege claim
"BYOA grants the Terraform runner zero tenant-level Microsoft Graph permissions" became "BYOA mode leverages a least-privilege security model"; the mechanism described — write access through direct object ownership — is unchanged.
-
Requirements and cytool reference tables became raw HTML
Nine Cortex XDR agent pages swapped markdown pipe tables for <table> markup, which shows as a large deletion count against a single added line without any content changing.
-
The ITDR Conditional Access link was resolved out of broken-reference
It now points at the get-started-with-itdr#set-up-identity-profiles anchor, though the link text was split so only "Set up an Identity" is linked and "profile" trails outside it.
Changes
314 files listed, 15 written up and shaded below.
-
▸ ▾ Microsoft Windows Tools modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-windows-toolsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Microsoft Windows Tools# Microsoft Windows Toolshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Connect to Windows hosts to run scripts and commands remotely for tasks such as acquiring forensic data, gathering information, and remediating hosts. Uses PowerShell Remoting (built on the Windows Management Framework and Windows Remote Management) and the pywinrm library to create remote sessions and execute processes or PowerShell scripts.Connect to Windows hosts to run scripts and commands remotely for tasks such as acquiring forensic data, gathering information, and remediating hosts. Uses PowerShell Remoting (built on the Windows Management Framework and Windows Remote Management) and the pywinrm library to create remote sessions and execute processes or PowerShell scripts.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Microsoft Windows Tools {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Connect to Windows hosts to run scripts and commands remotely for tasks such as acquiring forensic data, gathering information, and remediating hosts. Uses PowerShell Remoting (built on the Windows Management Framework and Windows Remote Management) and the pywinrm library to create remote sessions and execute processes or PowerShell scripts. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Mimecast modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mimecast/mimecastRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Mimecast# Mimecasthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThe Mimecast platform offers protection against email threats and data leaks while preventing service downtime through email archiving and uptime services. Use this connector to fetch Audit and SIEM events with the Mimecast Event Collector v2, and to run automation and fetch issues with Mimecast v2.The Mimecast platform offers protection against email threats and data leaks while preventing service downtime through email archiving and uptime services. Use this connector to fetch Audit and SIEM events with the Mimecast Event Collector v2, and to run automation and fetch issues with Mimecast v2.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Mimecast Event Collector v2: Use the Mimecast Event Collector v2 integration to fetch Audit events and SIEM logs for various SIEM event types, using API 2.0 with OAuth2 authentication. This sub-capability is available with any active Cortex XSIAM license.• Mimecast Event Collector v2: Use the Mimecast Event Collector v2 integration to fetch Audit events and SIEM logs for various SIEM event types, using API 2.0 with OAuth2 authentication. This sub-capability is available with any active Cortex XSIAM license.• MimecastV2: Mimecast unified email management offers cloud email services for email security, continuity and archiving emails. Please read detailed instructions in order to understand how to set the integration's parameters. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• MimecastV2: Mimecast unified email management offers cloud email services for email security, continuity and archiving emails. Please read detailed instructions in order to understand how to set the integration's parameters. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Mimecast {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} The Mimecast platform offers protection against email threats and data leaks while preventing service downtime through email archiving and uptime services. Use this connector to fetch Audit and SIEM events with the Mimecast Event Collector v2, and to run automation and fetch issues with Mimecast v2. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Mimecast Event Collector v2](https://xsoar.pan.dev/docs/reference/integrations/mimecast-event-collector-v2): Use the Mimecast Event Collector v2 integration to fetch Audit events and SIEM logs for various SIEM event types, using API 2.0 with OAuth2 authentication. This sub-capability is available with any active Cortex XSIAM license. * [MimecastV2](https://xsoar.pan.dev/docs/reference/integrations/mimecast-v2): Mimecast unified email management offers cloud email services for email security, continuity and archiving emails. Please read detailed instructions in order to understand how to set the integration's parameters. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ MISP modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/misp/mispRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# MISP# MISPhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.MISP (Malware Information Sharing Platform) is an open-source threat intelligence and threat sharing platform. This connector retrieves and ingests threat actor information from the MISP threat actor galaxy, ingests feeds into Cortex Threat Intel Management (TIM) via an MISP instance, and enriches indicators using data from an MISP instance.MISP (Malware Information Sharing Platform) is an open-source threat intelligence and threat sharing platform. This connector retrieves and ingests threat actor information from the MISP threat actor galaxy, ingests feeds into Cortex Threat Intel Management (TIM) via an MISP instance, and enriches indicators using data from an MISP instance.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # MISP {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. MISP (Malware Information Sharing Platform) is an open-source threat intelligence and threat sharing platform. This connector retrieves and ingests threat actor information from the MISP threat actor galaxy, ingests feeds into Cortex Threat Intel Management (TIM) via an MISP instance, and enriches indicators using data from an MISP instance. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ MITRE modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mitre/mitreRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# MITRE# MITREhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.MITRE ATT\&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations of cyber security threats. Use the MITRE ATT\&CK Feed to fetch indicators from MITRE ATT\&CK in STIX format — techniques and sub-techniques as Attack Patterns, groups as Intrusion Sets, software as Tools or Malware, and mitigations as Courses of Action.MITRE ATT\&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations of cyber security threats. Use the MITRE ATT\&CK Feed to fetch indicators from MITRE ATT\&CK in STIX format — techniques and sub-techniques as Attack Patterns, groups as Intrusion Sets, software as Tools or Malware, and mitigations as Courses of Action.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # MITRE {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. MITRE ATT\&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations of cyber security threats. Use the MITRE ATT\&CK Feed to fetch indicators from MITRE ATT\&CK in STIX format — techniques and sub-techniques as Attack Patterns, groups as Intrusion Sets, software as Tools or Malware, and mitigations as Courses of Action. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Monday modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/monday/mondayRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Monday# Mondayhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud, or Cortex Cloud Runtime Security license.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, or Cortex Cloud Runtime Security license.Monday.com is a work operating system that powers teams to run projects and workflows with confidence. Collect activity logs and audit logs from Monday.com for threat detection and compliance monitoring in Cortex XSIAM.Monday.com is a work operating system that powers teams to run projects and workflows with confidence. Collect activity logs and audit logs from Monday.com for threat detection and compliance monitoring in Cortex XSIAM.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Monday {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, or Cortex Cloud Runtime Security license. Monday.com is a work operating system that powers teams to run projects and workflows with confidence. Collect activity logs and audit logs from Monday.com for threat detection and compliance monitoring in Cortex XSIAM. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ MongoDB modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mongodb/mongodbRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# MongoDB# MongoDBhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintConnect to MongoDB to search and query entries, manipulate key/value pairs, and write log data to MongoDB collections. Also fetch and manage alerts and events from MongoDB Atlas, the fully managed cloud database service.Connect to MongoDB to search and query entries, manipulate key/value pairs, and write log data to MongoDB collections. Also fetch and manage alerts and events from MongoDB Atlas, the fully managed cloud database service.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• MongoDB: Use the MongoDB integration to search and query entries in your MongoDB. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• MongoDB: Use the MongoDB integration to search and query entries in your MongoDB. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• MongoDB Key Value Store: Manipulates key/value pairs according to an incident utilizing the MongoDB collection. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• MongoDB Key Value Store: Manipulates key/value pairs according to an incident utilizing the MongoDB collection. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # MongoDB {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Connect to MongoDB to search and query entries, manipulate key/value pairs, and write log data to MongoDB collections. Also fetch and manage alerts and events from MongoDB Atlas, the fully managed cloud database service. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [MongoDB](https://xsoar.pan.dev/docs/reference/integrations/mongo-db): Use the MongoDB integration to search and query entries in your MongoDB. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [MongoDB Key Value Store](https://xsoar.pan.dev/docs/reference/integrations/mongo-db-key-value-store): Manipulates key/value pairs according to an incident utilizing the MongoDB collection. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ MxToolBox modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mxtoolbox/mxtoolboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# MxToolBox# MxToolBoxhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use MXToolbox to check for website and server issues. MXToolbox monitors and analyzes server systems around the world, and can be queried for threat intelligence information.Use MXToolbox to check for website and server issues. MXToolbox monitors and analyzes server systems around the world, and can be queried for threat intelligence information.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # MxToolBox {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use MXToolbox to check for website and server issues. MXToolbox monitors and analyzes server systems around the world, and can be queried for threat intelligence information. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ NAVEX modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/navex/navexRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# NAVEX# NAVEXhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the LockPath KeyLight integration to manage GRC tickets in the Keylight platform. Fetch records from a component as issues and manage tickets in NAVEX Global's Lockpath KeyLight.Use the LockPath KeyLight integration to manage GRC tickets in the Keylight platform. Fetch records from a component as issues and manage tickets in NAVEX Global's Lockpath KeyLight.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # NAVEX {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the LockPath KeyLight integration to manage GRC tickets in the Keylight platform. Fetch records from a component as issues and manage tickets in NAVEX Global's Lockpath KeyLight. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ NetBox modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netbox/netboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# NetBox# NetBoxhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Collect events automatically from NetBox, the network source of truth for infrastructure. You can also use the netbox-get-events command to manually collect events.Collect events automatically from NetBox, the network source of truth for infrastructure. You can also use the netbox-get-events command to manually collect events.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # NetBox {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Collect events automatically from NetBox, the network source of truth for infrastructure. You can also use the _**netbox-get-events**_ command to manually collect events. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Netcraft modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netcraft/netcraftRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Netcraft# Netcrafthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Netcraft protects organizations against cybercrime threats such as phishing, fraud, and malware. This connector integrates Netcraft's takedown, submission, and screenshot management services to report suspicious URLs, emails, and files, obtain their screenshots, and track takedowns.Netcraft protects organizations against cybercrime threats such as phishing, fraud, and malware. This connector integrates Netcraft's takedown, submission, and screenshot management services to report suspicious URLs, emails, and files, obtain their screenshots, and track takedowns.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Netcraft {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Netcraft protects organizations against cybercrime threats such as phishing, fraud, and malware. This connector integrates Netcraft's takedown, submission, and screenshot management services to report suspicious URLs, emails, and files, obtain their screenshots, and track takedowns. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Netmiko modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netmiko/netmikoRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Netmiko# Netmikohint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Netmiko provides SSH-based access to network devices, servers, and other appliances that support this method of configuration. For a complete list of supported platforms, see Netmiko Platforms.md on GitHub.Netmiko provides SSH-based access to network devices, servers, and other appliances that support this method of configuration. For a complete list of supported platforms, see Netmiko Platforms.md on GitHub.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Netmiko {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Netmiko provides SSH-based access to network devices, servers, and other appliances that support this method of configuration. For a complete list of supported platforms, see [Netmiko Platforms.md on GitHub](https://github.com/ktbyers/netmiko/blob/develop/PLATFORMS.md). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ NetQuest modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netquest/netquestRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# NetQuest# NetQuesthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.NetQuest's products are high-capacity service nodes that help security teams access and analyze network traffic. Powerful packet and flow processing features assist security tools in detecting and mitigating security threats as cost effectively as possible.NetQuest's products are high-capacity service nodes that help security teams access and analyze network traffic. Powerful packet and flow processing features assist security tools in detecting and mitigating security threats as cost effectively as possible.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # NetQuest {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. NetQuest's products are high-capacity service nodes that help security teams access and analyze network traffic. Powerful packet and flow processing features assist security tools in detecting and mitigating security threats as cost effectively as possible. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Netskope modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netskope/netskopeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Netskope# Netskopehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Netskope to retrieve alerts and events, collect events extracted from SaaS traffic and logs, and manage quarantine files, URL lists, and hash lists. With the Netskope API you can proactively respond to security threats, enforce web access policies, and administer your Netskope environment.Integrate with Netskope to retrieve alerts and events, collect events extracted from SaaS traffic and logs, and manage quarantine files, URL lists, and hash lists. With the Netskope API you can proactively respond to security threats, enforce web access policies, and administer your Netskope environment.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• netskope_api_v2: Netskope API v2 provides a powerful interface for managing and monitoring Netskope deployments. It enables users to retrieve alerts and events, manage URL lists, and control clients. With Netskope API v2, organizations can proactively respond to security threats, enforce web access policies, and efficiently administer their Netskope environment. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• netskope_api_v2: Netskope API v2 provides a powerful interface for managing and monitoring Netskope deployments. It enables users to retrieve alerts and events, manage URL lists, and control clients. With Netskope API v2, organizations can proactively respond to security threats, enforce web access policies, and efficiently administer their Netskope environment. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• NetskopeAPIv1: Get alerts and events, manage quarantine files as well as URL and hash lists using Netskope API v1. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• NetskopeAPIv1: Get alerts and events, manage quarantine files as well as URL and hash lists using Netskope API v1. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Netskope {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Netskope to retrieve alerts and events, collect events extracted from SaaS traffic and logs, and manage quarantine files, URL lists, and hash lists. With the Netskope API you can proactively respond to security threats, enforce web access policies, and administer your Netskope environment. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [netskope\_api\_v2](https://xsoar.pan.dev/docs/reference/integrations/netskope-api-v2): Netskope API v2 provides a powerful interface for managing and monitoring Netskope deployments. It enables users to retrieve alerts and events, manage URL lists, and control clients. With Netskope API v2, organizations can proactively respond to security threats, enforce web access policies, and efficiently administer their Netskope environment. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [NetskopeAPIv1](https://xsoar.pan.dev/docs/reference/integrations/netskope-ap-iv1): Get alerts and events, manage quarantine files as well as URL and hash lists using Netskope API v1. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ NIST modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nist/nistRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# NIST# NISThint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.CVE feed from the NIST National Vulnerability Database (NVD). Use this feed to create a feed of CVEs from NIST, using v2 of the NVD API and supporting the latest CVSS - Common Vulnerability Scoring System standard.CVE feed from the NIST National Vulnerability Database (NVD). Use this feed to create a feed of CVEs from NIST, using v2 of the NVD API and supporting the latest CVSS - Common Vulnerability Scoring System standard.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # NIST {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. CVE feed from the NIST National Vulnerability Database (NVD). Use this feed to create a feed of CVEs from NIST, using v2 of the NVD API and supporting the latest CVSS - Common Vulnerability Scoring System standard. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ nmap modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nmap/nmapRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# nmap# nmaphint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Nmap scans your network and discovers everything connected to it, along with a wide variety of information about what's connected, what services each host is operating, and so on. It helps you protect your network by allowing you to quickly spot security vulnerabilities in your systems. Runs nmap scans with the given parameters.Nmap scans your network and discovers everything connected to it, along with a wide variety of information about what's connected, what services each host is operating, and so on. It helps you protect your network by allowing you to quickly spot security vulnerabilities in your systems. Runs nmap scans with the given parameters.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # nmap {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Nmap scans your network and discovers everything connected to it, along with a wide variety of information about what's connected, what services each host is operating, and so on. It helps you protect your network by allowing you to quickly spot security vulnerabilities in your systems. Runs nmap scans with the given parameters. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Nutanix modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nutanix/nutanixRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Nutanix# Nutanixhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Nutanix Hypervisor abstracts and isolates the VMs and their programs from the underlying server hardware, enabling a more efficient use of physical resources, simpler maintenance and operations, and reduced costs. This integration was integrated and tested with version v2 of Nutanix.Nutanix Hypervisor abstracts and isolates the VMs and their programs from the underlying server hardware, enabling a more efficient use of physical resources, simpler maintenance and operations, and reduced costs. This integration was integrated and tested with version v2 of Nutanix.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Nutanix {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Nutanix Hypervisor abstracts and isolates the VMs and their programs from the underlying server hardware, enabling a more efficient use of physical resources, simpler maintenance and operations, and reduced costs. This integration was integrated and tested with version v2 of Nutanix. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Okta Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/okta/okta-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Okta Automation and Collection# Okta Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintOkta integrates with Cortex to help security teams understand and respond to identity threats as they emerge. It provides visibility into each user's groups, roles, and application access to streamline investigations, and enables identity-centric response actions such as suspending accounts, forcing password resets, and prompting step-up authentication. The connector also collects Okta authentication and audit logs, Okta Advanced Server Access (ASA) audit events, and Okta Auth0 logs, and supports Identity Access Management (IAM) CRUD operations for employee lifecycle processes.Okta integrates with Cortex to help security teams understand and respond to identity threats as they emerge. It provides visibility into each user's groups, roles, and application access to streamline investigations, and enables identity-centric response actions such as suspending accounts, forcing password resets, and prompting step-up authentication. The connector also collects Okta authentication and audit logs, Okta Advanced Server Access (ASA) audit events, and Okta Auth0 logs, and supports Identity Access Management (IAM) CRUD operations for employee lifecycle processes.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Okta Event Collector: Collects the events log for authentication and Audit provided by Okta admin API. This sub-capability is available with any active Cortex XSIAM license.• Okta Event Collector: Collects the events log for authentication and Audit provided by Okta admin API. This sub-capability is available with any active Cortex XSIAM license.• Okta IAM: Integrate with Okta's Identity Access Management service to execute CRUD operations to employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Okta IAM: Integrate with Okta's Identity Access Management service to execute CRUD operations to employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Okta Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Okta integrates with Cortex to help security teams understand and respond to identity threats as they emerge. It provides visibility into each user's groups, roles, and application access to streamline investigations, and enables identity-centric response actions such as suspending accounts, forcing password resets, and prompting step-up authentication. The connector also collects Okta authentication and audit logs, Okta Advanced Server Access (ASA) audit events, and Okta Auth0 logs, and supports Identity Access Management (IAM) CRUD operations for employee lifecycle processes. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Okta Event Collector](https://xsoar.pan.dev/docs/reference/integrations/okta-event-collector): Collects the events log for authentication and Audit provided by Okta admin API. This sub-capability is available with any active Cortex XSIAM license. * [Okta IAM](https://xsoar.pan.dev/docs/reference/integrations/okta-iam): Integrate with Okta's Identity Access Management service to execute CRUD operations to employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ OneLogin modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/onelogin/oneloginRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OneLogin# OneLoginhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.OneLogin provides simple customer authentication and streamlined workforce identity operations. Collect events from the OneLogin API into Cortex.OneLogin provides simple customer authentication and streamlined workforce identity operations. Collect events from the OneLogin API into Cortex.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OneLogin {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. OneLogin provides simple customer authentication and streamlined workforce identity operations. Collect events from the OneLogin API into Cortex. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OpenAI modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openai/openaiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OpenAI# OpenAIhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with OpenAI to interact with GPT models through the Chat Completions endpoint and collect OpenAI Audit logs and ChatGPT Compliance logs as events in Cortex.Integrate with OpenAI to interact with GPT models through the Chat Completions endpoint and collect OpenAI Audit logs and ChatGPT Compliance logs as events in Cortex.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OpenAI {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with OpenAI to interact with GPT models through the Chat Completions endpoint and collect OpenAI Audit logs and ChatGPT Compliance logs as events in Cortex. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OpenCVE modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opencve/opencveRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OpenCVE# OpenCVEhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.OpenCVE is a platform used to locally import the list of CVEs and perform searches on it (by vendors, products, CVSS, CWE...). Users subscribe to vendors or products, and OpenCVE alerts them when a new CVE is created or when an update is done in an existing CVE.OpenCVE is a platform used to locally import the list of CVEs and perform searches on it (by vendors, products, CVSS, CWE...). Users subscribe to vendors or products, and OpenCVE alerts them when a new CVE is created or when an update is done in an existing CVE.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OpenCVE {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. OpenCVE is a platform used to locally import the list of CVEs and perform searches on it (by vendors, products, CVSS, CWE...). Users subscribe to vendors or products, and OpenCVE alerts them when a new CVE is created or when an update is done in an existing CVE. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OpenLDAP modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openldap/openldapRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OpenLDAP# OpenLDAPhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use your OpenLDAP or Active Directory user authentication settings to log in to Cortex XSOAR. Users log in with their OpenLDAP or Active Directory username and password, and their permissions are set according to the groups and mapping defined in AD Roles Mapping. For connecting to the LDAP server with a TLS connection, it is recommended to use this integration instead of the Active Directory Authentication server integration.Use your OpenLDAP or Active Directory user authentication settings to log in to Cortex XSOAR. Users log in with their OpenLDAP or Active Directory username and password, and their permissions are set according to the groups and mapping defined in AD Roles Mapping. For connecting to the LDAP server with a TLS connection, it is recommended to use this integration instead of the Active Directory Authentication server integration.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OpenLDAP {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use your OpenLDAP or Active Directory user authentication settings to log in to Cortex XSOAR. Users log in with their OpenLDAP or Active Directory username and password, and their permissions are set according to the groups and mapping defined in AD Roles Mapping. For connecting to the LDAP server with a TLS connection, it is recommended to use this integration instead of the Active Directory Authentication server integration. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OpenPhish modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openphish/openphishRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OpenPhish# OpenPhishhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.OpenPhish uses proprietary Artificial Intelligence algorithms to automatically identify zero-day phishing sites and provide comprehensive, actionable, real-time threat intelligence.OpenPhish uses proprietary Artificial Intelligence algorithms to automatically identify zero-day phishing sites and provide comprehensive, actionable, real-time threat intelligence.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OpenPhish {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. OpenPhish uses proprietary Artificial Intelligence algorithms to automatically identify zero-day phishing sites and provide comprehensive, actionable, real-time threat intelligence. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OpenText EnCase Endpoint Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-encase-endpoint-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OpenText EnCase Endpoint Security# OpenText EnCase Endpoint Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.The EnCase Endpoint Security product includes the Enterprise Service Bus (ESB), which is a RESTful API allowing partner products to request scans of specified endpoints.The EnCase Endpoint Security product includes the Enterprise Service Bus (ESB), which is a RESTful API allowing partner products to request scans of specified endpoints.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OpenText EnCase Endpoint Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. The EnCase Endpoint Security product includes the Enterprise Service Bus (ESB), which is a RESTful API allowing partner products to request scans of specified endpoints. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OpenText Service Manager modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-service-managerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OpenText Service Manager# OpenText Service Managerhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Service Manager By Micro Focus (Formerly HPE Software).Service Manager By Micro Focus (Formerly HPE Software).This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OpenText Service Manager {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Service Manager By Micro Focus (Formerly HPE Software). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OpenText Vertica modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-verticaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OpenText Vertica# OpenText Verticahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Connect to an OpenText Vertica database to run SQL queries against your data. This integration was integrated and tested with Vertica v4.1.Connect to an OpenText Vertica database to run SQL queries against your data. This integration was integrated and tested with Vertica v4.1.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OpenText Vertica {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Connect to an OpenText Vertica database to run SQL queries against your data. This integration was integrated and tested with Vertica v4.1. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ OPSWAT MetaDefender modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opswat/opswat-metadefenderRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# OPSWAT MetaDefender# OPSWAT MetaDefenderhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.OPSWAT MetaDefender is a multi-scanning engine that uses 30+ anti-malware engines to scan files for threats, significantly increasing malware detection.OPSWAT MetaDefender is a multi-scanning engine that uses 30+ anti-malware engines to scan files for threats, significantly increasing malware detection.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # OPSWAT MetaDefender {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. OPSWAT MetaDefender is a multi-scanning engine that uses 30+ anti-malware engines to scan files for threats, significantly increasing malware detection. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Oracle modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oracle/oracleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Oracle# Oraclehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Oracle Cloud Infrastructure to fetch audit log events for security audits, tracking usage and changes to resources, and helping ensure compliance. Integrate with Oracle Identity Access Management to run CRUD (create, read, update, and delete) operations for employee lifecycle processes.Integrate with Oracle Cloud Infrastructure to fetch audit log events for security audits, tracking usage and changes to resources, and helping ensure compliance. Integrate with Oracle Identity Access Management to run CRUD (create, read, update, and delete) operations for employee lifecycle processes.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• OracleCloudInfrastructureEventCollector: Collects audit log events from Oracle Cloud Infrastructure resources. This sub-capability is available with any active Cortex XSIAM or Cortex Cloud Posture Security license.• OracleCloudInfrastructureEventCollector: Collects audit log events from Oracle Cloud Infrastructure resources. This sub-capability is available with any active Cortex XSIAM or Cortex Cloud Posture Security license.• OracleIAM: Integrate with Oracle's services to execute CRUD and Group operations for employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.• OracleIAM: Integrate with Oracle's services to execute CRUD and Group operations for employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Oracle {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Oracle Cloud Infrastructure to fetch audit log events for security audits, tracking usage and changes to resources, and helping ensure compliance. Integrate with Oracle Identity Access Management to run CRUD (create, read, update, and delete) operations for employee lifecycle processes. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [OracleCloudInfrastructureEventCollector](https://xsoar.pan.dev/docs/reference/integrations/oracle-cloud-infrastructure-event-collector): Collects audit log events from Oracle Cloud Infrastructure resources. This sub-capability is available with any active Cortex XSIAM or Cortex Cloud Posture Security license. * [OracleIAM](https://xsoar.pan.dev/docs/reference/integrations/oracle-iam): Integrate with Oracle's services to execute CRUD and Group operations for employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license. -
▸ ▾ Orca Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/orca-security/orca-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Orca Security# Orca Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.The Orca Security connector combines the deep and contextual alert findings of Orca with Cortex analytic capabilities. Import Orca alerts regarding vulnerabilities, malware, misconfigurations, lateral movement risk, authentication risk, and insecure high-risk data, with real-time threat detection as alerts are pushed from Orca. For more information, visit Orca Security.The Orca Security connector combines the deep and contextual alert findings of Orca with Cortex analytic capabilities. Import Orca alerts regarding vulnerabilities, malware, misconfigurations, lateral movement risk, authentication risk, and insecure high-risk data, with real-time threat detection as alerts are pushed from Orca. For more information, visit Orca Security.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Orca Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. The Orca Security connector combines the deep and contextual alert findings of Orca with Cortex analytic capabilities. Import Orca alerts regarding vulnerabilities, malware, misconfigurations, lateral movement risk, authentication risk, and insecure high-risk data, with real-time threat detection as alerts are pushed from Orca. For more information, visit [Orca Security](https://orca.security/). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ PacketMail.net modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/packetmail.net/packetmail.netRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# PacketMail.net# PacketMail.nethint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Wireless Innovation products.Integrate with Wireless Innovation products.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # PacketMail.net {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Wireless Innovation products. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ PacketSled modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/packetsled/packetsledRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# PacketSled# PacketSledhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Access the PacketSled playbook and command query to enumerate sensors, enumerate hosts that have issues, and retrieve metadata, files, and full packet capture (PCAP) artifacts from the PacketSled API for an investigation, based on the perspective of a user or a host.Access the PacketSled playbook and command query to enumerate sensors, enumerate hosts that have issues, and retrieve metadata, files, and full packet capture (PCAP) artifacts from the PacketSled API for an investigation, based on the perspective of a user or a host.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # PacketSled {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Access the PacketSled playbook and command query to enumerate sensors, enumerate hosts that have issues, and retrieve metadata, files, and full packet capture (PCAP) artifacts from the PacketSled API for an investigation, based on the perspective of a user or a host. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ PagerDuty Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pagerduty/pagerduty-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# PagerDuty Automation and Collection# PagerDuty Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintUse PagerDuty to manage schedules and on-call users via PagerDuty API v2. Use Rundeck for runbook automation for issue management, business continuity, and self-service operations — enabling you to install software on a list of machines or perform tasks periodically.Use PagerDuty to manage schedules and on-call users via PagerDuty API v2. Use Rundeck for runbook automation for issue management, business continuity, and self-service operations — enabling you to install software on a list of machines or perform tasks periodically.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• PagerDuty v2: This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• PagerDuty v2: This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Rundeck: Rundeck is a runbook automation for incident management, business continuity, and self-service operations. The integration enables you to install software on a list of machines or perform a task periodically. It can be used when there is a new attack and you want to perform an update of the software to block the attack. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Rundeck: Rundeck is a runbook automation for incident management, business continuity, and self-service operations. The integration enables you to install software on a list of machines or perform a task periodically. It can be used when there is a new attack and you want to perform an update of the software to block the attack. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # PagerDuty Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Use PagerDuty to manage schedules and on-call users via PagerDuty API v2. Use Rundeck for runbook automation for issue management, business continuity, and self-service operations — enabling you to install software on a list of machines or perform tasks periodically. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [PagerDuty v2](https://xsoar.pan.dev/docs/reference/integrations/pager-duty-v2): This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [Rundeck](https://xsoar.pan.dev/docs/reference/integrations/rundeck): Rundeck is a runbook automation for incident management, business continuity, and self-service operations. The integration enables you to install software on a list of machines or perform a task periodically. It can be used when there is a new attack and you want to perform an update of the software to block the attack. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ PAT Helpdesk Advanced modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pat-helpdesk-advanced/pat-helpdesk-advancedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# PAT Helpdesk Advanced# PAT Helpdesk Advancedhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Improve the effectiveness of your service provision and resources, and the quality of your IT department. This integration was integrated and tested with version 11.2.3 of PAT Helpdesk Advanced.Improve the effectiveness of your service provision and resources, and the quality of your IT department. This integration was integrated and tested with version 11.2.3 of PAT Helpdesk Advanced.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # PAT Helpdesk Advanced {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Improve the effectiveness of your service provision and resources, and the quality of your IT department. This integration was integrated and tested with version 11.2.3 of PAT Helpdesk Advanced. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ PhishLabs modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/phishlabs/phishlabsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# PhishLabs# PhishLabshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.PhishLabs (Fortra) provides 24/7 detection and rapid mitigation of email-based and digital risks. The IOC feed retrieves malicious indicators from the PhishLabs global feed and email-based issues from the user feed. Digital Risk Protection (DRP) delivers proactive detection and mitigation of digital risks across email, domain, social media, mobile, dark, deep, and open web vectors. PhishLabs EIR protects against threats that reach employee inboxes past your email security stack.PhishLabs (Fortra) provides 24/7 detection and rapid mitigation of email-based and digital risks. The IOC feed retrieves malicious indicators from the PhishLabs global feed and email-based issues from the user feed. Digital Risk Protection (DRP) delivers proactive detection and mitigation of digital risks across email, domain, social media, mobile, dark, deep, and open web vectors. PhishLabs EIR protects against threats that reach employee inboxes past your email security stack.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # PhishLabs {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. PhishLabs (Fortra) provides 24/7 detection and rapid mitigation of email-based and digital risks. The IOC feed retrieves malicious indicators from the PhishLabs global feed and email-based issues from the user feed. [Digital Risk Protection (DRP)](https://www.phishlabs.com/digital-risk-protection/) delivers proactive detection and mitigation of digital risks across email, domain, social media, mobile, dark, deep, and open web vectors. PhishLabs EIR protects against threats that reach employee inboxes past your email security stack. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Pipl modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pipl/piplRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Pipl# Piplhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Pipl provides a reputation for email addresses and identity solutions.Pipl provides a reputation for email addresses and identity solutions.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Pipl {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Pipl provides a reputation for email addresses and identity solutions. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Plainview modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/plainview/plainviewRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Plainview# Plainviewhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.Integrate with Clarizen's Identity Access Management (IAM) service to execute CRUD operations in the employee lifecycle processes. Create, update, get, and disable users in Clarizen from Cortex. For more information, refer to the Identity Lifecycle Management article.Integrate with Clarizen's Identity Access Management (IAM) service to execute CRUD operations in the employee lifecycle processes. Create, update, get, and disable users in Clarizen from Cortex. For more information, refer to the Identity Lifecycle Management article.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Plainview {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license. Integrate with Clarizen's Identity Access Management (IAM) service to execute CRUD operations in the employee lifecycle processes. Create, update, get, and disable users in Clarizen from Cortex. For more information, refer to the [Identity Lifecycle Management article](https://xsoar.pan.dev/docs/reference/articles/identity-lifecycle-management). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Proofpoint modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/proofpoint/proofpointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Proofpoint# Proofpointhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintProofpoint is an email security and threat protection platform that guards against phishing, malware, and advanced email attacks. It includes Targeted Attack Protection (TAP), Threat Response for automated issue response, Protection Server for email gateway management, Cloud Threat Response, Browser Isolation, and URL phishing validation via IsItPhishing.Proofpoint is an email security and threat protection platform that guards against phishing, malware, and advanced email attacks. It includes Targeted Attack Protection (TAP), Threat Response for automated issue response, Protection Server for email gateway management, Cloud Threat Response, Browser Isolation, and URL phishing validation via IsItPhishing.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• IsItPhishing: Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• IsItPhishing: Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Cloud Threat Response: Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSIAM for case management, and exposes commands to list and retrieve incident details. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Cloud Threat Response: Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSIAM for case management, and exposes commands to list and retrieve incident details. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Proofpoint {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Proofpoint is an email security and threat protection platform that guards against phishing, malware, and advanced email attacks. It includes Targeted Attack Protection (TAP), Threat Response for automated issue response, Protection Server for email gateway management, Cloud Threat Response, Browser Isolation, and URL phishing validation via IsItPhishing. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [IsItPhishing](https://xsoar.pan.dev/docs/reference/integrations/is-it-phishing): Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * Proofpoint Cloud Threat Response: Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSIAM for case management, and exposes commands to list and retrieve incident details. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ ProtectWise modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/protectwise/protectwiseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ProtectWise# ProtectWisehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.ProtectWise provides network security threat detection and response. When integrated, event data is received as a continuous stream that can be handled by the platform.ProtectWise provides network security threat detection and response. When integrated, event data is received as a continuous stream that can be handled by the platform.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # ProtectWise {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. ProtectWise provides network security threat detection and response. When integrated, event data is received as a continuous stream that can be handled by the platform. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Qualys modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/qualys/qualysRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Qualys# Qualyshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintQualys detects vulnerabilities and policy compliance across your network assets. Qualys VMDR lets you create, run, fetch and manage reports, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance. Qualys FIM (File Integrity Monitoring) logs and tracks file changes across global IT systems.Qualys detects vulnerabilities and policy compliance across your network assets. Qualys VMDR lets you create, run, fetch and manage reports, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance. Qualys FIM (File Integrity Monitoring) logs and tracks file changes across global IT systems.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• qualys_fim: Log and track file changes across global IT systems. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• qualys_fim: Log and track file changes across global IT systems. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• QualysV2: Qualys Vulnerability Management lets you create, run, manage reports and to fetch Activity Logs, Assets and Vulnerabilities, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on.• QualysV2: Qualys Vulnerability Management lets you create, run, manage reports and to fetch Activity Logs, Assets and Vulnerabilities, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on.Show markdown source
@@ -1,14 +1,14 @@ # Qualys {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Qualys detects vulnerabilities and policy compliance across your network assets. Qualys VMDR lets you create, run, fetch and manage reports, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance. Qualys FIM (File Integrity Monitoring) logs and tracks file changes across global IT systems. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [qualys\_fim](https://xsoar.pan.dev/docs/reference/integrations/qualys-fim): Log and track file changes across global IT systems. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [QualysV2](https://xsoar.pan.dev/docs/reference/integrations/qualys-v2): Qualys Vulnerability Management lets you create, run, manage reports and to fetch Activity Logs, Assets and Vulnerabilities, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on. -
▸ ▾ Quest KACE modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/quest-kace/quest-kaceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Quest KACE# Quest KACEhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with the Quest KACE Systems Management Appliance to manage tickets and fetch issues. This is a beta integration, tested with QuestKace version v10.0.290.Integrate with the Quest KACE Systems Management Appliance to manage tickets and fetch issues. This is a beta integration, tested with QuestKace version v10.0.290.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Quest KACE {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with the Quest KACE Systems Management Appliance to manage tickets and fetch issues. This is a beta integration, tested with QuestKace version v10.0.290. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Radware modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/radware/radwareRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Radware# Radwarehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Radware Cloud DDoS Protection Service provides a robust, multi-layered defense using advanced behavioral algorithms for swift detection and mitigation of volumetric and sophisticated application-layer DDoS threats. The service is delivered globally via a high-capacity scrubbing network, offering flexible deployment models including Always-On, On-Demand, and Hybrid. Use this connector to automate application and asset creation and day-to-day management, and to retrieve up-to-date data about Security Events and Operational Alerts.Radware Cloud DDoS Protection Service provides a robust, multi-layered defense using advanced behavioral algorithms for swift detection and mitigation of volumetric and sophisticated application-layer DDoS threats. The service is delivered globally via a high-capacity scrubbing network, offering flexible deployment models including Always-On, On-Demand, and Hybrid. Use this connector to automate application and asset creation and day-to-day management, and to retrieve up-to-date data about Security Events and Operational Alerts.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Radware {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Radware Cloud DDoS Protection Service provides a robust, multi-layered defense using advanced behavioral algorithms for swift detection and mitigation of volumetric and sophisticated application-layer DDoS threats. The service is delivered globally via a high-capacity scrubbing network, offering flexible deployment models including Always-On, On-Demand, and Hybrid. Use this connector to automate application and asset creation and day-to-day management, and to retrieve up-to-date data about Security Events and Operational Alerts. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Rapid7 modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rapid7/rapid7Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Rapid7# Rapid7hint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintRapid7 InsightIDR is a cloud-based SIEM that provides real-time alerting and investigation tools for detection and response, authentication monitoring, and endpoint visibility. Rapid7 InsightVM (Nexpose) provides vulnerability management, assessment, and response, prioritizing risk across vulnerabilities, configurations, and controls. Rapid7 AppSec manages application vulnerabilities and scans.Rapid7 InsightIDR is a cloud-based SIEM that provides real-time alerting and investigation tools for detection and response, authentication monitoring, and endpoint visibility. Rapid7 InsightVM (Nexpose) provides vulnerability management, assessment, and response, prioritizing risk across vulnerabilities, configurations, and controls. Rapid7 AppSec manages application vulnerabilities and scans.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Rapid7 InsightIDR: Rapid7’s InsightIDR is your security center for incident detection and response, authentication monitoring, and endpoint visibility. Together, these form Extended Detection and Response (XDR). InsightIDR identifies unauthorized access from external and internal threats and highlights suspicious activity so you don’t have to weed through thousands of data streams. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Rapid7 InsightIDR: Rapid7’s InsightIDR is your security center for incident detection and response, authentication monitoring, and endpoint visibility. Together, these form Extended Detection and Response (XDR). InsightIDR identifies unauthorized access from external and internal threats and highlights suspicious activity so you don’t have to weed through thousands of data streams. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Rapid7 Nexpose: Vulnerability management solution to help reduce threat exposure. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on.• Rapid7 Nexpose: Vulnerability management solution to help reduce threat exposure. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on.Show markdown source
@@ -1,14 +1,14 @@ # Rapid7 {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Rapid7 InsightIDR is a cloud-based SIEM that provides real-time alerting and investigation tools for detection and response, authentication monitoring, and endpoint visibility. Rapid7 InsightVM (Nexpose) provides vulnerability management, assessment, and response, prioritizing risk across vulnerabilities, configurations, and controls. Rapid7 AppSec manages application vulnerabilities and scans. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Rapid7 InsightIDR](https://xsoar.pan.dev/docs/reference/integrations/rapid7-insight-idr): Rapid7’s InsightIDR is your security center for incident detection and response, authentication monitoring, and endpoint visibility. Together, these form Extended Detection and Response (XDR). InsightIDR identifies unauthorized access from external and internal threats and highlights suspicious activity so you don’t have to weed through thousands of data streams. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Rapid7 Nexpose](https://xsoar.pan.dev/docs/reference/integrations/rapid7-nexpose): Vulnerability management solution to help reduce threat exposure. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on. -
▸ ▾ Razor Group modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/razor-group/razor-groupRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Razor Group# Razor Grouphint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Perch Security is a crowd-sourced threat and intelligence feed which also provides network security. Use the integration to manage alerts, indicators, and communities.Perch Security is a crowd-sourced threat and intelligence feed which also provides network security. Use the integration to manage alerts, indicators, and communities.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Razor Group {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Perch Security is a crowd-sourced threat and intelligence feed which also provides network security. Use the integration to manage alerts, indicators, and communities. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Recorded Future modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/recorded-future/recorded-futureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Recorded Future# Recorded Futurehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIngest threat intelligence from Recorded Future. The RiskList Feed downloads lists of IP addresses, domains, URLs, CVEs, or file hashes with known risk associations, including risk scores and supporting evidence, while the Event Collector fetches alerts from Recorded Future.Ingest threat intelligence from Recorded Future. The RiskList Feed downloads lists of IP addresses, domains, URLs, CVEs, or file hashes with known risk associations, including risk scores and supporting evidence, while the Event Collector fetches alerts from Recorded Future.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Recorded Future Feed: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Recorded Future Feed: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• RecordedFutureEventCollector: This integration fetches alerts from Recorded Future. This sub-capability is available with any active Cortex XSIAM license.• RecordedFutureEventCollector: This integration fetches alerts from Recorded Future. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # Recorded Future {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Ingest threat intelligence from Recorded Future. The RiskList Feed downloads lists of IP addresses, domains, URLs, CVEs, or file hashes with known risk associations, including risk scores and supporting evidence, while the Event Collector fetches alerts from Recorded Future. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Recorded Future Feed](https://xsoar.pan.dev/docs/reference/integrations/recorded-future-feed): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [RecordedFutureEventCollector](https://xsoar.pan.dev/docs/reference/integrations/recorded-future-event-collector): This integration fetches alerts from Recorded Future. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ Red Hat Ansible modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/red-hat/red-hat-ansibleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Red Hat Ansible# Red Hat Ansiblehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Red Hat Ansible is an IT automation tool for configuring systems, deploying software, and orchestrating advanced IT tasks. This connector groups Ansible-powered integrations that manage a wide range of targets directly from Cortex — Linux and Windows hosts, Cisco IOS/NXOS network devices, Kubernetes, VMware, DNS records, certificates (ACME/OpenSSL), public clouds (Azure, Alibaba Cloud, Hetzner Cloud), and Ansible Automation Platform. The Ansible engine is self-contained and pre-configured, exposing Ansible modules as commands so you can use them without needing to know Ansible.Red Hat Ansible is an IT automation tool for configuring systems, deploying software, and orchestrating advanced IT tasks. This connector groups Ansible-powered integrations that manage a wide range of targets directly from Cortex — Linux and Windows hosts, Cisco IOS/NXOS network devices, Kubernetes, VMware, DNS records, certificates (ACME/OpenSSL), public clouds (Azure, Alibaba Cloud, Hetzner Cloud), and Ansible Automation Platform. The Ansible engine is self-contained and pre-configured, exposing Ansible modules as commands so you can use them without needing to know Ansible.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Red Hat Ansible {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Red Hat Ansible is an IT automation tool for configuring systems, deploying software, and orchestrating advanced IT tasks. This connector groups Ansible-powered integrations that manage a wide range of targets directly from Cortex — Linux and Windows hosts, Cisco IOS/NXOS network devices, Kubernetes, VMware, DNS records, certificates (ACME/OpenSSL), public clouds (Azure, Alibaba Cloud, Hetzner Cloud), and Ansible Automation Platform. The Ansible engine is self-contained and pre-configured, exposing Ansible modules as commands so you can use them without needing to know Ansible. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Redmine modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/redmine/redmineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Redmine# Redminehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Redmine is a flexible, open-source project management and issue tracking web application. Written using the Ruby on Rails framework, it is cross-platform and cross-database, and provides a web-based platform for managing projects, tracking tasks, and handling various project-related activities.Redmine is a flexible, open-source project management and issue tracking web application. Written using the Ruby on Rails framework, it is cross-platform and cross-database, and provides a web-based platform for managing projects, tracking tasks, and handling various project-related activities.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Redmine {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Redmine is a flexible, open-source project management and issue tracking web application. Written using the Ruby on Rails framework, it is cross-platform and cross-database, and provides a web-based platform for managing projects, tracking tasks, and handling various project-related activities. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ReliaQuest modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/reliaquest/reliaquestRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ReliaQuest# ReliaQuesthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintReliaQuest GreyMatter DRP (Digital Shadows) minimizes digital risk by identifying unwanted exposure and protecting against external threats. The award-winning SearchLight solution provides ongoing monitoring of a customer's unique assets and exposure across the open, deep, and dark web, enabling clients to detect data loss, brand impersonation, infrastructure risks, cyber threats, and much more.ReliaQuest GreyMatter DRP (Digital Shadows) minimizes digital risk by identifying unwanted exposure and protecting against external threats. The award-winning SearchLight solution provides ongoing monitoring of a customer's unique assets and exposure across the open, deep, and dark web, enabling clients to detect data loss, brand impersonation, infrastructure risks, cyber threats, and much more.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• ReliaQuest GreyMatter DRP Event Collector: ReliaQuest GreyMatter DRP Event Collector monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web. This sub-capability is available with any active Cortex XSIAM license.• ReliaQuest GreyMatter DRP Event Collector: ReliaQuest GreyMatter DRP Event Collector monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web. This sub-capability is available with any active Cortex XSIAM license.• ReliaQuest GreyMatter DRP Incidents: ReliaQuest GreyMatter DR monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• ReliaQuest GreyMatter DRP Incidents: ReliaQuest GreyMatter DR monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # ReliaQuest {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} ReliaQuest GreyMatter DRP (Digital Shadows) minimizes digital risk by identifying unwanted exposure and protecting against external threats. The award-winning SearchLight solution provides ongoing monitoring of a customer's unique assets and exposure across the open, deep, and dark web, enabling clients to detect data loss, brand impersonation, infrastructure risks, cyber threats, and much more. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [ReliaQuest GreyMatter DRP Event Collector](https://xsoar.pan.dev/docs/reference/integrations/relia-quest-grey-matter-drp-event-collector): ReliaQuest GreyMatter DRP Event Collector monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web. This sub-capability is available with any active Cortex XSIAM license. * [ReliaQuest GreyMatter DRP Incidents](https://xsoar.pan.dev/docs/reference/integrations/relia-quest-grey-matter-drp-incidents): ReliaQuest GreyMatter DR monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ RemoteAccess modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/remoteaccess/remoteaccessRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# RemoteAccess# RemoteAccesshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Access and run commands on a terminal in a remote location over SSH. Transfer files between the platform and a remote machine, and execute commands on the remote machine.Access and run commands on a terminal in a remote location over SSH. Transfer files between the platform and a remote machine, and execute commands on the remote machine.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # RemoteAccess {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Access and run commands on a terminal in a remote location over SSH. Transfer files between the platform and a remote machine, and execute commands on the remote machine. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Retarus modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/retarus/retarusRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Retarus# Retarushint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Retarus Secure Email Gateway is a fully managed cloud service that provides comprehensive, multi-layered security for organizations. It filters all inbound and outbound traffic to defend against threats like malware, ransomware, and phishing using advanced sandboxing technology.Retarus Secure Email Gateway is a fully managed cloud service that provides comprehensive, multi-layered security for organizations. It filters all inbound and outbound traffic to defend against threats like malware, ransomware, and phishing using advanced sandboxing technology.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Retarus {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Retarus Secure Email Gateway is a fully managed cloud service that provides comprehensive, multi-layered security for organizations. It filters all inbound and outbound traffic to defend against threats like malware, ransomware, and phishing using advanced sandboxing technology. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ RSA modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rsa/rsaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# RSA# RSAhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.RSA connectors integrate RSA security products with Cortex. The RSA Archer GRC platform provides a common foundation for managing policies, controls, risks, assessments, and deficiencies across lines of business. RSA NetWitness Endpoint provides deep visibility beyond basic endpoint security solutions by monitoring and collecting activity across all of your endpoints, on and off your network. RSA NetWitness Security Analytics is a distributed and modular system that collects packet data and log data from the network infrastructure.RSA connectors integrate RSA security products with Cortex. The RSA Archer GRC platform provides a common foundation for managing policies, controls, risks, assessments, and deficiencies across lines of business. RSA NetWitness Endpoint provides deep visibility beyond basic endpoint security solutions by monitoring and collecting activity across all of your endpoints, on and off your network. RSA NetWitness Security Analytics is a distributed and modular system that collects packet data and log data from the network infrastructure.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # RSA {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. RSA connectors integrate RSA security products with Cortex. The RSA Archer GRC platform provides a common foundation for managing policies, controls, risks, assessments, and deficiencies across lines of business. RSA NetWitness Endpoint provides deep visibility beyond basic endpoint security solutions by monitoring and collecting activity across all of your endpoints, on and off your network. RSA NetWitness Security Analytics is a distributed and modular system that collects packet data and log data from the network infrastructure. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ RTIR modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rtir/rtirRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# RTIR# RTIRhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the RTIR (Request Tracker for IR) integration to manage tickets: create, search, edit, resolve, and comment on tickets, and retrieve ticket data, history, and attachments. Tested with RTIR v4.4.2 using the SDK python-rtir v1.0.11.Use the RTIR (Request Tracker for IR) integration to manage tickets: create, search, edit, resolve, and comment on tickets, and retrieve ticket data, history, and attachments. Tested with RTIR v4.4.2 using the SDK python-rtir v1.0.11.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # RTIR {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the RTIR (Request Tracker for IR) integration to manage tickets: create, search, edit, resolve, and comment on tickets, and retrieve ticket data, history, and attachments. Tested with RTIR v4.4.2 using the SDK python-rtir v1.0.11. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ runZero modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/runzero/runzeroRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# runZero# runZerohint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.RunZero is a network discovery and asset inventory platform that uncovers every network in use and identifies every device connected, without credentials. Use this connector to collect events automatically from RunZero.RunZero is a network discovery and asset inventory platform that uncovers every network in use and identifies every device connected, without credentials. Use this connector to collect events automatically from RunZero.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # runZero {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. RunZero is a network discovery and asset inventory platform that uncovers every network in use and identifies every device connected, without credentials. Use this connector to collect events automatically from RunZero. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SailPoint modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sailpoint/sailpointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SailPoint# SailPointhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace..endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.SailPoint Identity Security takes the complexity out of identity, making it intuitive for IT staff to configure and manage while enabling business users with the access they need. This connector collects events from SailPoint IdentityNow to drive identity-aware security practices.SailPoint Identity Security takes the complexity out of identity, making it intuitive for IT staff to configure and manage while enabling business users with the access they need. This connector collects events from SailPoint IdentityNow to drive identity-aware security practices.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SailPoint {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace).. {% endhint %} This sub-capability is available with any active Cortex XSIAM license. SailPoint Identity Security takes the complexity out of identity, making it intuitive for IT staff to configure and manage while enabling business users with the access they need. This connector collects events from SailPoint IdentityNow to drive identity-aware security practices. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Samhaus modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/samhaus/samhausRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Samhaus# Samhaushint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the Spamhaus feed integration to fetch indicators from the Spamhaus Project feed.Use the Spamhaus feed integration to fetch indicators from the Spamhaus Project feed.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Samhaus {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the Spamhaus feed integration to fetch indicators from the Spamhaus Project feed. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SANS DShield modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sans-dshield/sans-dshieldRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SANS DShield# SANS DShieldhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Fetches a feed from DShield summarizing the top 20 attacking class C (/24) subnets over the last three days. The number of 'attacks' indicates the number of targets reporting scans from a subnet.Fetches a feed from DShield summarizing the top 20 attacking class C (/24) subnets over the last three days. The number of 'attacks' indicates the number of targets reporting scans from a subnet.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SANS DShield {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Fetches a feed from DShield summarizing the top 20 attacking class C (/24) subnets over the last three days. The number of 'attacks' indicates the number of targets reporting scans from a subnet. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SAP modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sap/sapRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SAP# SAPhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with SAP services to manage employee lifecycle identity operations and to collect audit log events for security monitoring and compliance. SAP - IAM executes get and disable operations for employee lifecycle processes, SAP BTP (Business Technology Platform) collects audit log events from SAP's cloud platform, and SAP Cloud for Customer (C4C) collects audit events from SAP's CRM solution via the OData Analytics API.Integrate with SAP services to manage employee lifecycle identity operations and to collect audit log events for security monitoring and compliance. SAP - IAM executes get and disable operations for employee lifecycle processes, SAP BTP (Business Technology Platform) collects audit log events from SAP's cloud platform, and SAP Cloud for Customer (C4C) collects audit events from SAP's CRM solution via the OData Analytics API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• SAPBTP: SAP Business Technology Platform (BTP) is a cloud platform for building, integrating, and extending enterprise applications with data, analytics, AI, and automation. This sub-capability is available with any active Cortex XSIAM license.• SAPBTP: SAP Business Technology Platform (BTP) is a cloud platform for building, integrating, and extending enterprise applications with data, analytics, AI, and automation. This sub-capability is available with any active Cortex XSIAM license.• SAPCloudForCustomerC4C: Integrates with SAP Cloud for Customer (C4C) and collects audit events via its OData Analytics API to boost security monitoring and compliance. This sub-capability is available with any active Cortex XSIAM license.• SAPCloudForCustomerC4C: Integrates with SAP Cloud for Customer (C4C) and collects audit events via its OData Analytics API to boost security monitoring and compliance. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # SAP {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with SAP services to manage employee lifecycle identity operations and to collect audit log events for security monitoring and compliance. SAP - IAM executes get and disable operations for employee lifecycle processes, SAP BTP (Business Technology Platform) collects audit log events from SAP's cloud platform, and SAP Cloud for Customer (C4C) collects audit events from SAP's CRM solution via the OData Analytics API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [SAPBTP](https://xsoar.pan.dev/docs/reference/integrations/sapbtp): SAP Business Technology Platform (BTP) is a cloud platform for building, integrating, and extending enterprise applications with data, analytics, AI, and automation. This sub-capability is available with any active Cortex XSIAM license. * [SAPCloudForCustomerC4C](https://xsoar.pan.dev/docs/reference/integrations/sap-cloud-for-customer-c4-c): Integrates with SAP Cloud for Customer (C4C) and collects audit events via its OData Analytics API to boost security monitoring and compliance. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ Saviynt modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/saviynt/saviyntRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Saviynt# Saviynthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Saviynt Enterprise Identity Cloud (EIC) is an AI-driven, cloud-native identity security platform that unifies Identity Governance and Administration (IGA). It manages and secures user and non-human access across hybrid IT environments to help organizations reduce risk and meet compliance mandates. This connector collects Saviynt EIC audit logs.Saviynt Enterprise Identity Cloud (EIC) is an AI-driven, cloud-native identity security platform that unifies Identity Governance and Administration (IGA). It manages and secures user and non-human access across hybrid IT environments to help organizations reduce risk and meet compliance mandates. This connector collects Saviynt EIC audit logs.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Saviynt {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Saviynt Enterprise Identity Cloud (EIC) is an AI-driven, cloud-native identity security platform that unifies Identity Governance and Administration (IGA). It manages and secures user and non-human access across hybrid IT environments to help organizations reduce risk and meet compliance mandates. This connector collects Saviynt EIC audit logs. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SecurityScorecard modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/securityscorecard/securityscorecardRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SecurityScorecard# SecurityScorecardhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.SecurityScorecard provides security ratings and risk assessments for organizations by continuously monitoring their external attack surface, evaluating domains across security factors such as network security, DNS health, patching cadence, and endpoint security. This connector collects history events from SecurityScorecard for security monitoring and compliance in Cortex XSIAM.SecurityScorecard provides security ratings and risk assessments for organizations by continuously monitoring their external attack surface, evaluating domains across security factors such as network security, DNS health, patching cadence, and endpoint security. This connector collects history events from SecurityScorecard for security monitoring and compliance in Cortex XSIAM.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SecurityScorecard {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. SecurityScorecard provides security ratings and risk assessments for organizations by continuously monitoring their external attack surface, evaluating domains across security factors such as network security, DNS health, patching cadence, and endpoint security. This connector collects history events from SecurityScorecard for security monitoring and compliance in Cortex XSIAM. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Securonix modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/securonix/securonixRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Securonix# Securonixhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.A threat intelligence platform that collects and interprets intelligence data from open sources and manages indicator scoring, types, and attributes.A threat intelligence platform that collects and interprets intelligence data from open sources and manages indicator scoring, types, and attributes.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Securonix {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. A threat intelligence platform that collects and interprets intelligence data from open sources and manages indicator scoring, types, and attributes. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SentinelOne modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentinelone/sentineloneRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SentinelOne# SentinelOnehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Integrate with SentinelOne for endpoint protection. Fetch activities, threats, and alerts from SentinelOne, and use SentinelOne to receive alerts from endpoints, search for processes, block endpoints, and manage the endpoint protection policy.Integrate with SentinelOne for endpoint protection. Fetch activities, threats, and alerts from SentinelOne, and use SentinelOne to receive alerts from endpoints, search for processes, block endpoints, and manage the endpoint protection policy.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SentinelOne {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Integrate with SentinelOne for endpoint protection. Fetch activities, threats, and alerts from SentinelOne, and use SentinelOne to receive alerts from endpoints, search for processes, block endpoints, and manage the endpoint protection policy. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ServiceNow Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenow/servicenow-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ServiceNow Automation and Collection# ServiceNow Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintServiceNow is an IT service management platform that helps streamline security-related service management and IT operations. It provides a service-centric CMDB that proactively analyzes service-impacting changes, identifies issues, and eliminates outages. Cortex integrates with ServiceNow to create, update, query, and delete tickets and table records, perform Identity Lifecycle Management, collect audit and syslog events, and connect to ServiceNow MCP servers for agentic AI workflows.ServiceNow is an IT service management platform that helps streamline security-related service management and IT operations. It provides a service-centric CMDB that proactively analyzes service-impacting changes, identifies issues, and eliminates outages. Cortex integrates with ServiceNow to create, update, query, and delete tickets and table records, perform Identity Lifecycle Management, collect audit and syslog events, and connect to ServiceNow MCP servers for agentic AI workflows.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• ServiceNow CMDB: ServiceNow CMDB is a service-centric foundation that proactively analyzes service-impacting changes, identifies issues, and eliminates outages. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• ServiceNow CMDB: ServiceNow CMDB is a service-centric foundation that proactively analyzes service-impacting changes, identifies issues, and eliminates outages. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• ServiceNow Event Collector: Use this integration to fetch audits, syslog transactions, cases, and outbound HTTP logs from ServiceNow as Cortex XSIAM events. This sub-capability is available with any active Cortex XSIAM license.• ServiceNow Event Collector: Use this integration to fetch audits, syslog transactions, cases, and outbound HTTP logs from ServiceNow as Cortex XSIAM events. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # ServiceNow Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} ServiceNow is an IT service management platform that helps streamline security-related service management and IT operations. It provides a service-centric CMDB that proactively analyzes service-impacting changes, identifies issues, and eliminates outages. Cortex integrates with ServiceNow to create, update, query, and delete tickets and table records, perform Identity Lifecycle Management, collect audit and syslog events, and connect to ServiceNow MCP servers for agentic AI workflows. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [ServiceNow CMDB](https://xsoar.pan.dev/docs/reference/integrations/service-now-cmdb): ServiceNow CMDB is a service-centric foundation that proactively analyzes service-impacting changes, identifies issues, and eliminates outages. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [ServiceNow Event Collector](https://xsoar.pan.dev/docs/reference/integrations/service-now-event-collector): Use this integration to fetch audits, syslog transactions, cases, and outbound HTTP logs from ServiceNow as Cortex XSIAM events. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ Shodan modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/shodan/shodanRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Shodan# Shodanhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Shodan is a search engine for Internet-connected devices. Unlike traditional search engines that index websites, Shodan indexes information about devices connected to the internet, such as servers, routers, webcams, and other IoT devices.Shodan is a search engine for Internet-connected devices. Unlike traditional search engines that index websites, Shodan indexes information about devices connected to the internet, such as servers, routers, webcams, and other IoT devices.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Shodan {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Shodan is a search engine for Internet-connected devices. Unlike traditional search engines that index websites, Shodan indexes information about devices connected to the internet, such as servers, routers, webcams, and other IoT devices. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Skyhigh Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/skyhigh-security/skyhigh-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Skyhigh Security# Skyhigh Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Skyhigh Security is a cloud-based, multi-tenant service that enables Cloud Discovery and Risk Monitoring, Cloud Usage Analytics, and Cloud Access and Control. Skyhigh Secure Web Gateway (SWG) is a cloud-native web security solution that provides layered protection from threats and data loss with integrated RBI, CASB, and DLP capabilities, and lets you manage its block and allow lists.Skyhigh Security is a cloud-based, multi-tenant service that enables Cloud Discovery and Risk Monitoring, Cloud Usage Analytics, and Cloud Access and Control. Skyhigh Secure Web Gateway (SWG) is a cloud-native web security solution that provides layered protection from threats and data loss with integrated RBI, CASB, and DLP capabilities, and lets you manage its block and allow lists.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Skyhigh Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Skyhigh Security is a cloud-based, multi-tenant service that enables Cloud Discovery and Risk Monitoring, Cloud Usage Analytics, and Cloud Access and Control. Skyhigh Secure Web Gateway (SWG) is a cloud-native web security solution that provides layered protection from threats and data loss with integrated RBI, CASB, and DLP capabilities, and lets you manage its block and allow lists. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Slack Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/slack/slack-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Slack Automation and Collection# Slack Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintSend messages and notifications to your Slack team and integrate with Slack's services to execute create, read, update, and delete operations for employee lifecycle processes. Collect and model Slack audit logs in Cortex, and interact with the Cortex Agentic Assistant directly from Slack.Send messages and notifications to your Slack team and integrate with Slack's services to execute create, read, update, and delete operations for employee lifecycle processes. Collect and model Slack audit logs in Cortex, and interact with the Cortex Agentic Assistant directly from Slack.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Slack Event Collector: Slack logs event collector integration for XSIAM. This sub-capability is available with any active Cortex XSIAM license.• Slack Event Collector: Slack logs event collector integration for XSIAM. This sub-capability is available with any active Cortex XSIAM license.• Slack IAM: Integrate with Slack's services to execute CRUD operations for employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Slack IAM: Integrate with Slack's services to execute CRUD operations for employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Slack Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Send messages and notifications to your Slack team and integrate with Slack's services to execute create, read, update, and delete operations for employee lifecycle processes. Collect and model Slack audit logs in Cortex, and interact with the Cortex Agentic Assistant directly from Slack. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Slack Event Collector](https://xsoar.pan.dev/docs/reference/integrations/slack-event-collector): Slack logs event collector integration for XSIAM. This sub-capability is available with any active Cortex XSIAM license. * [Slack IAM](https://xsoar.pan.dev/docs/reference/integrations/slack-iam): Integrate with Slack's services to execute CRUD operations for employee lifecycle processes. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ SMB modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/smb/smbRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SMB# SMBhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Manage files and directories on an SMB server. Supports the SMB2 and SMB3 protocols.Manage files and directories on an SMB server. Supports the SMB2 and SMB3 protocols.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SMB {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. Manage files and directories on an SMB server. Supports the SMB2 and SMB3 protocols. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SMIME Messaging modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/smime-messaging/smime-messagingRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SMIME Messaging# SMIME Messaginghint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the S/MIME (Secure Multipurpose Internet Mail Extensions) integration to send and receive secure MIME data. Send S/MIME-signed, encrypted, or signed-and-encrypted messages, and decrypt or verify S/MIME messages.Use the S/MIME (Secure Multipurpose Internet Mail Extensions) integration to send and receive secure MIME data. Send S/MIME-signed, encrypted, or signed-and-encrypted messages, and decrypt or verify S/MIME messages.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SMIME Messaging {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the S/MIME (Secure Multipurpose Internet Mail Extensions) integration to send and receive secure MIME data. Send S/MIME-signed, encrypted, or signed-and-encrypted messages, and decrypt or verify S/MIME messages. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Snowflake Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/snowflake/snowflake-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Snowflake Automation and Collection# Snowflake Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.integrate with Snowflake products.integrate with Snowflake products.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Snowflake Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. integrate with Snowflake products. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SolarWinds modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/solarwinds/solarwindsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SolarWinds# SolarWindshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.The SolarWinds integration interacts with the SWIS API to fetch alerts and events, and provides commands to retrieve lists of alerts and events. It requires installation of the SolarWinds Orion Platform, which consolidates the full suite of monitoring capabilities into one platform.The SolarWinds integration interacts with the SWIS API to fetch alerts and events, and provides commands to retrieve lists of alerts and events. It requires installation of the SolarWinds Orion Platform, which consolidates the full suite of monitoring capabilities into one platform.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SolarWinds {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. The SolarWinds integration interacts with the SWIS API to fetch alerts and events, and provides commands to retrieve lists of alerts and events. It requires installation of the SolarWinds Orion Platform, which consolidates the full suite of monitoring capabilities into one platform. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Sophos modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sophos/sophosRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Sophos# Sophoshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Sophos Central is a cloud-based management platform for Sophos' cybersecurity solutions, providing centralized control and real-time visibility over endpoint, mobile, email, web, and firewall protection from a single interface. Sophos Firewall is an on-premise firewall that lets you manage your firewall, respond to threats, and monitor what's happening on your network.Sophos Central is a cloud-based management platform for Sophos' cybersecurity solutions, providing centralized control and real-time visibility over endpoint, mobile, email, web, and firewall protection from a single interface. Sophos Firewall is an on-premise firewall that lets you manage your firewall, respond to threats, and monitor what's happening on your network.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Sophos {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Sophos Central is a cloud-based management platform for Sophos' cybersecurity solutions, providing centralized control and real-time visibility over endpoint, mobile, email, web, and firewall protection from a single interface. Sophos Firewall is an on-premise firewall that lets you manage your firewall, respond to threats, and monitor what's happening on your network. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Splunk Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/splunk/splunk-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Splunk Automation and Collection# Splunk Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintRun queries on Splunk servers and fetch events from both Splunk Enterprise Security (ES) and non-ES environments. SplunkPy fetches notable events (for Splunk ES up to 8.1) and SplunkPy v2 fetches Findings and Investigations (for Splunk ES 8.2 and higher), enriching them with Asset, Identity, and Drilldown data and supporting bi-directional mirroring between Splunk and Cortex.Run queries on Splunk servers and fetch events from both Splunk Enterprise Security (ES) and non-ES environments. SplunkPy fetches notable events (for Splunk ES up to 8.1) and SplunkPy v2 fetches Findings and Investigations (for Splunk ES 8.2 and higher), enriching them with Asset, Identity, and Drilldown data and supporting bi-directional mirroring between Splunk and Cortex.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• SplunkPy: Run queries on Splunk and fetch Notable Events (Splunk ES versions up to 8.2). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.• SplunkPy: Run queries on Splunk and fetch Notable Events (Splunk ES versions up to 8.2). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.• SplunkPy v2: Run queries on Splunk and fetch Splunk ES Findings and Investigations (Splunk ES 8.2+). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.• SplunkPy v2: Run queries on Splunk and fetch Splunk ES Findings and Investigations (Splunk ES 8.2+). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Splunk Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Run queries on Splunk servers and fetch events from both Splunk Enterprise Security (ES) and non-ES environments. SplunkPy fetches notable events (for Splunk ES up to 8.1) and SplunkPy v2 fetches Findings and Investigations (for Splunk ES 8.2 and higher), enriching them with Asset, Identity, and Drilldown data and supporting bi-directional mirroring between Splunk and Cortex. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [SplunkPy](https://xsoar.pan.dev/docs/reference/integrations/splunk-py): Run queries on Splunk and fetch Notable Events (Splunk ES versions up to 8.2). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license. * [SplunkPy v2](https://xsoar.pan.dev/docs/reference/integrations/splunk-py-v2): Run queries on Splunk and fetch Splunk ES Findings and Investigations (Splunk ES 8.2+). This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license. -
▸ ▾ Sublime Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sublime-security/sublime-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Sublime Security# Sublime Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.EmailRep.io provides the reputation and reports for email addresses.EmailRep.io provides the reputation and reports for email addresses.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Sublime Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. EmailRep.io provides the reputation and reports for email addresses. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Sumo Logic Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sumo-logic/sumo-logic-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Sumo Logic Automation and Collection# Sumo Logic Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the SumoLogic integration to search for and return SumoLogic records.Use the SumoLogic integration to search for and return SumoLogic records.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Sumo Logic Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the SumoLogic integration to search for and return SumoLogic records. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ SysAid modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sysaid/sysaidRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# SysAid# SysAidhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.SysAid is a robust IT management system designed to meet all of the needs of an IT department. Fetch service records, list and search assets and users, and list, search, update, close, create, and delete service records.SysAid is a robust IT management system designed to meet all of the needs of an IT department. Fetch service records, list and search assets and users, and list, search, update, close, create, and delete service records.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # SysAid {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. SysAid is a robust IT management system designed to meet all of the needs of an IT department. Fetch service records, list and search assets and users, and list, search, update, close, create, and delete service records. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Syslog Sender modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/syslog-sender/syslog-senderRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Syslog Sender# Syslog Senderhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the Syslog Sender integration to send messages in RFC 5424 message format and mirror investigation War Room entries to Syslog.Use the Syslog Sender integration to send messages in RFC 5424 message format and mirror investigation War Room entries to Syslog.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Syslog Sender {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the Syslog Sender integration to send messages in RFC 5424 message format and mirror investigation War Room entries to Syslog. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Tanium modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tanium/taniumRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Tanium# Taniumhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Tanium to hunt, detect, investigate, and remediate threats and vulnerabilities across your endpoints. Manage questions, actions, saved questions, packages, and sensor information through the Tanium REST API, and manage endpoint processes, evidence, alerts, files, snapshots, and connections with Tanium Threat Response.Integrate with Tanium to hunt, detect, investigate, and remediate threats and vulnerabilities across your endpoints. Manage questions, actions, saved questions, packages, and sensor information through the Tanium REST API, and manage endpoint processes, evidence, alerts, files, snapshots, and connections with Tanium Threat Response.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Tanium {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Tanium to hunt, detect, investigate, and remediate threats and vulnerabilities across your endpoints. Manage questions, actions, saved questions, packages, and sensor information through the Tanium REST API, and manage endpoint processes, evidence, alerts, files, snapshots, and connections with Tanium Threat Response. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ TAXII modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/taxii/taxiiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# TAXII# TAXIIhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.TAXII connectors for exchanging cyber threat intelligence. Ingest indicators from TAXII 1.x and TAXII 2.0/2.1 servers (TAXII Feed and TAXII 2 Feed), and serve system indicators as an outbound feed over TAXII or TAXII2 (TAXII Server and TAXII2 Server).TAXII connectors for exchanging cyber threat intelligence. Ingest indicators from TAXII 1.x and TAXII 2.0/2.1 servers (TAXII Feed and TAXII 2 Feed), and serve system indicators as an outbound feed over TAXII or TAXII2 (TAXII Server and TAXII2 Server).This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # TAXII {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. TAXII connectors for exchanging cyber threat intelligence. Ingest indicators from TAXII 1.x and TAXII 2.0/2.1 servers (TAXII Feed and TAXII 2 Feed), and serve system indicators as an outbound feed over TAXII or TAXII2 (TAXII Server and TAXII2 Server). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ TeamViewer modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/teamviewer/teamviewerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# TeamViewer# TeamViewerhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.TeamViewer is a remote access and remote control computer software, allowing maintenance of computers and other devices. Use this integration to collect events automatically from TeamViewer.TeamViewer is a remote access and remote control computer software, allowing maintenance of computers and other devices. Use this integration to collect events automatically from TeamViewer.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # TeamViewer {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. TeamViewer is a remote access and remote control computer software, allowing maintenance of computers and other devices. Use this integration to collect events automatically from TeamViewer. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Telegram modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/telegram/telegramRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Telegram# Telegramhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Telegram to run automation and remediation commands. This is a beta connector, which lets you implement and test pre-release software; it might contain bugs and receive non-backward compatible updates during the beta phase.Integrate with Telegram to run automation and remediation commands. This is a beta connector, which lets you implement and test pre-release software; it might contain bugs and receive non-backward compatible updates during the beta phase.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Telegram {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Telegram to run automation and remediation commands. This is a beta connector, which lets you implement and test pre-release software; it might contain bugs and receive non-backward compatible updates during the beta phase. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Tenable modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tenable/tenableRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Tenable# Tenablehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintTenable vulnerability management for auditors and security analysts. Nessus is a vulnerability scanner by Tenable Network Security. Tenable Vulnerability Management (formerly Tenable.io) is a comprehensive asset-centric solution that accurately tracks resources while accommodating dynamic assets such as cloud, mobile devices, containers, and web applications. Tenable.sc gives you a real-time, continuous assessment of your security posture so you can find and fix vulnerabilities faster.Tenable vulnerability management for auditors and security analysts. Nessus is a vulnerability scanner by Tenable Network Security. Tenable Vulnerability Management (formerly Tenable.io) is a comprehensive asset-centric solution that accurately tracks resources while accommodating dynamic assets such as cloud, mobile devices, containers, and web applications. Tenable.sc gives you a real-time, continuous assessment of your security posture so you can find and fix vulnerabilities faster.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Nessus: Vulnerability scanner for auditors and security analysts by Tenable Network Security. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Nessus: Vulnerability scanner for auditors and security analysts by Tenable Network Security. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Tenable.io: A comprehensive asset-centric solution to accurately track resources while accommodating dynamic assets such as cloud, mobile devices, containers, and web applications. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on.• Tenable.io: A comprehensive asset-centric solution to accurately track resources while accommodating dynamic assets such as cloud, mobile devices, containers, and web applications. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on.Show markdown source
@@ -1,14 +1,14 @@ # Tenable {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Tenable vulnerability management for auditors and security analysts. Nessus is a vulnerability scanner by Tenable Network Security. Tenable Vulnerability Management (formerly Tenable.io) is a comprehensive asset-centric solution that accurately tracks resources while accommodating dynamic assets such as cloud, mobile devices, containers, and web applications. Tenable.sc gives you a real-time, continuous assessment of your security posture so you can find and fix vulnerabilities faster. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Nessus](https://xsoar.pan.dev/docs/reference/integrations/nessus): Vulnerability scanner for auditors and security analysts by Tenable Network Security. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Tenable.io](https://xsoar.pan.dev/docs/reference/integrations/tenableio): A comprehensive asset-centric solution to accurately track resources while accommodating dynamic assets such as cloud, mobile devices, containers, and web applications. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license with the Exposure Management add-on. -
▸ ▾ Thales modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thales/thalesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Thales# Thaleshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.SafeNet Trusted Access prevents data breaches, helps with compliance with regulations, and supports migration to the cloud in a simple and secure fashion. Retrieve access, authentication, and audit logs and store them for investigation and response.SafeNet Trusted Access prevents data breaches, helps with compliance with regulations, and supports migration to the cloud in a simple and secure fashion. Retrieve access, authentication, and audit logs and store them for investigation and response.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Thales {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. SafeNet Trusted Access prevents data breaches, helps with compliance with regulations, and supports migration to the cloud in a simple and secure fashion. Retrieve access, authentication, and audit logs and store them for investigation and response. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ TheHive modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thehive/thehiveRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# TheHive# TheHivehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.TheHive Project is an open source and free Security Issue Response Platform designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security issues that need to be investigated and acted upon swiftly.TheHive Project is an open source and free Security Issue Response Platform designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security issues that need to be investigated and acted upon swiftly.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # TheHive {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. TheHive Project is an open source and free Security Issue Response Platform designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security issues that need to be investigated and acted upon swiftly. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Thinkst Canary modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thinkst-canary/thinkst-canaryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Thinkst Canary# Thinkst Canaryhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.By presenting itself as an apparently benign and legitimate service, a Thinkst Canary draws the attention of unwanted activity. When someone trips one of the Canary's triggers, an alert is sent to notify the responsible parties so that action can be taken before valuable systems in your network are compromised. Fetch alerts from CanaryTools as issues and acknowledge them, get information about registered Canaries and Canary Tokens, and add IP addresses to the allow list.By presenting itself as an apparently benign and legitimate service, a Thinkst Canary draws the attention of unwanted activity. When someone trips one of the Canary's triggers, an alert is sent to notify the responsible parties so that action can be taken before valuable systems in your network are compromised. Fetch alerts from CanaryTools as issues and acknowledge them, get information about registered Canaries and Canary Tokens, and add IP addresses to the allow list.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Thinkst Canary {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. By presenting itself as an apparently benign and legitimate service, a Thinkst Canary draws the attention of unwanted activity. When someone trips one of the Canary's triggers, an alert is sent to notify the responsible parties so that action can be taken before valuable systems in your network are compromised. Fetch alerts from CanaryTools as issues and acknowledge them, get information about registered Canaries and Canary Tokens, and add IP addresses to the allow list. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ThreatConnect modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatconnect/threatconnectRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ThreatConnect# ThreatConnecthint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.ThreatConnect is an intelligence-driven security operations solution with intelligence, automation, analytics, and workflows. It fetches threat intelligence indicators from ThreatConnect (filterable by indicator owner) and fetches issues using the ThreatConnect v3 REST API.ThreatConnect is an intelligence-driven security operations solution with intelligence, automation, analytics, and workflows. It fetches threat intelligence indicators from ThreatConnect (filterable by indicator owner) and fetches issues using the ThreatConnect v3 REST API.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # ThreatConnect {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. ThreatConnect is an intelligence-driven security operations solution with intelligence, automation, analytics, and workflows. It fetches threat intelligence indicators from ThreatConnect (filterable by indicator owner) and fetches issues using the ThreatConnect v3 REST API. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ThreatMiner.org modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatminer.org/threatminer.orgRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ThreatMiner.org# ThreatMiner.orghint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.ThreatMiner is a threat intelligence portal for data mining threat intelligence, enriching indicators such as domains, IP addresses, and file hashes with related intelligence.ThreatMiner is a threat intelligence portal for data mining threat intelligence, enriching indicators such as domains, IP addresses, and file hashes with related intelligence.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # ThreatMiner.org {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. ThreatMiner is a threat intelligence portal for data mining threat intelligence, enriching indicators such as domains, IP addresses, and file hashes with related intelligence. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ ThreatX modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatx/threatxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# ThreatX# ThreatXhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the ThreatX integration to enrich intel and automate enforcement actions on the ThreatX Next Gen WAF. Add and remove CIDR ranges and IP addresses to block lists or the allow list, gather Entity metadata for intel enrichment and DBot scoring, and set Entity notes for SOC integration or further automation.Use the ThreatX integration to enrich intel and automate enforcement actions on the ThreatX Next Gen WAF. Add and remove CIDR ranges and IP addresses to block lists or the allow list, gather Entity metadata for intel enrichment and DBot scoring, and set Entity notes for SOC integration or further automation.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # ThreatX {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the ThreatX integration to enrich intel and automate enforcement actions on the ThreatX Next Gen WAF. Add and remove CIDR ranges and IP addresses to block lists or the allow list, gather Entity metadata for intel enrichment and DBot scoring, and set Entity notes for SOC integration or further automation. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Tidy modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tidy/tidyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Tidy# Tidyhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Tidy reduces the on-boarding process for new recruits to a matter of minutes. It uses Ansible to connect to a new recruit's laptop over SSH and execute predefined commands, letting you build role-based playbooks that install languages, programs, and tools and configure the machine for onboarding.Tidy reduces the on-boarding process for new recruits to a matter of minutes. It uses Ansible to connect to a new recruit's laptop over SSH and execute predefined commands, letting you build role-based playbooks that install languages, programs, and tools and configure the machine for onboarding.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Tidy {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Tidy reduces the on-boarding process for new recruits to a matter of minutes. It uses Ansible to connect to a new recruit's laptop over SSH and execute predefined commands, letting you build role-based playbooks that install languages, programs, and tools and configure the machine for onboarding. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ TOPdesk modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/topdesk/topdeskRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# TOPdesk# TOPdeskhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.TOPdesk's Enterprise Service Management software (ESM) lets your service teams join forces and process requests from a single platform. Connect to the TOPdesk portal to get information from the portal, as well as create and update issues.TOPdesk's Enterprise Service Management software (ESM) lets your service teams join forces and process requests from a single platform. Connect to the TOPdesk portal to get information from the portal, as well as create and update issues.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # TOPdesk {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. TOPdesk's Enterprise Service Management software (ESM) lets your service teams join forces and process requests from a single platform. Connect to the TOPdesk portal to get information from the portal, as well as create and update issues. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Tor Exit Adress modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tor-exit-adress/tor-exit-adressRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Tor Exit Adress# Tor Exit Adresshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Tor is free software and an open network that helps you defend against traffic analysis, a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security. This feed fetches Tor exit address indicators.Tor is free software and an open network that helps you defend against traffic analysis, a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security. This feed fetches Tor exit address indicators.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Tor Exit Adress {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Tor is free software and an open network that helps you defend against traffic analysis, a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security. This feed fetches Tor exit address indicators. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Trellix Database Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-database-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix Database Security# Trellix Database Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the McAfee Database Activity Monitoring (DAM) integration to fetch Alerts (issues) and query Alerts. This integration was integrated and developed with version 4.6.x of McAfee DAM.Use the McAfee Database Activity Monitoring (DAM) integration to fetch Alerts (issues) and query Alerts. This integration was integrated and developed with version 4.6.x of McAfee DAM.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Trellix Database Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the McAfee Database Activity Monitoring (DAM) integration to fetch Alerts (issues) and query Alerts. This integration was integrated and developed with version 4.6.x of McAfee DAM. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Trellix Email Security (ETP) modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-email-security-etpRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix Email Security (ETP)# Trellix Email Security (ETP)hint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintTrellix Email Security - Cloud is a cloud-based platform that protects against advanced email attacks. Use this connector to import messages as issues, search for messages with specific attributes, retrieve alert data, and fetch Alert, Email Trace, and Activity Log events for investigation and threat hunting.Trellix Email Security - Cloud is a cloud-based platform that protects against advanced email attacks. Use this connector to import messages as issues, search for messages with specific attributes, retrieve alert data, and fetch Alert, Email Trace, and Activity Log events for investigation and threat hunting.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• FireEye ETP: Trellix Email Security - Cloud is a cloud-based platform that protects against advanced email attacks. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• FireEye ETP: Trellix Email Security - Cloud is a cloud-based platform that protects against advanced email attacks. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• FireEye ETP Event Collector: Use this integration to fetch email security incidents from Trellix Email Security - Cloud as Cortex XSIAM events. This sub-capability is available with any active Cortex XSIAM license.• FireEye ETP Event Collector: Use this integration to fetch email security incidents from Trellix Email Security - Cloud as Cortex XSIAM events. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # Trellix Email Security (ETP) {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Trellix Email Security - Cloud is a cloud-based platform that protects against advanced email attacks. Use this connector to import messages as issues, search for messages with specific attributes, retrieve alert data, and fetch Alert, Email Trace, and Activity Log events for investigation and threat hunting. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [FireEye ETP](https://xsoar.pan.dev/docs/reference/integrations/fire-eye-etp): Trellix Email Security - Cloud is a cloud-based platform that protects against advanced email attacks. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [FireEye ETP Event Collector](https://xsoar.pan.dev/docs/reference/integrations/fire-eye-etp-event-collector): Use this integration to fetch email security incidents from Trellix Email Security - Cloud as Cortex XSIAM events. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ Trellix Email Security modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-email-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix Email Security# Trellix Email Securityhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Trellix (FireEye) email and network security products. FireEye Email Security (EX) protects against breaches caused by advanced email attacks, and FireEye Network Security (NX) detects and stops advanced, targeted, and other evasive attacks hiding in internet traffic.Integrate with Trellix (FireEye) email and network security products. FireEye Email Security (EX) protects against breaches caused by advanced email attacks, and FireEye Network Security (NX) detects and stops advanced, targeted, and other evasive attacks hiding in internet traffic.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Trellix Email Security {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Trellix (FireEye) email and network security products. FireEye Email Security (EX) protects against breaches caused by advanced email attacks, and FireEye Network Security (NX) detects and stops advanced, targeted, and other evasive attacks hiding in internet traffic. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Trellix Endpoint (HX) modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-endpoint-hxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix Endpoint (HX)# Trellix Endpoint (HX)hint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintFireEye Endpoint Security (HX) is an integrated solution that detects what others miss and protects endpoints against known and unknown threats. It provides access to information about endpoints, acquisitions, alerts, indicators, and containment, and collects FireEye HX audit events into Cortex.FireEye Endpoint Security (HX) is an integrated solution that detects what others miss and protects endpoints against known and unknown threats. It provides access to information about endpoints, acquisitions, alerts, indicators, and containment, and collects FireEye HX audit events into Cortex.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• FireEye HX Event Collector: Palo Alto Networks FireEye HX Event Collector integration for XSIAM. This sub-capability is available with any active Cortex XSIAM license.• FireEye HX Event Collector: Palo Alto Networks FireEye HX Event Collector integration for XSIAM. This sub-capability is available with any active Cortex XSIAM license.• FireEyeHX v2: FireEye Endpoint Security is an integrated solution that detects and protects endpoints against known and unknown threats. This integration provides access to information about endpoints, acquisitions, alerts, indicators, and containment. You can extract critical data and effectively operate the security operations automated playbook. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• FireEyeHX v2: FireEye Endpoint Security is an integrated solution that detects and protects endpoints against known and unknown threats. This integration provides access to information about endpoints, acquisitions, alerts, indicators, and containment. You can extract critical data and effectively operate the security operations automated playbook. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Trellix Endpoint (HX) {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} FireEye Endpoint Security (HX) is an integrated solution that detects what others miss and protects endpoints against known and unknown threats. It provides access to information about endpoints, acquisitions, alerts, indicators, and containment, and collects FireEye HX audit events into Cortex. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [FireEye HX Event Collector](https://xsoar.pan.dev/docs/reference/integrations/fire-eye-hx-event-collector): Palo Alto Networks FireEye HX Event Collector integration for XSIAM. This sub-capability is available with any active Cortex XSIAM license. * [FireEyeHX v2](https://xsoar.pan.dev/docs/reference/integrations/fire-eye-hx-v2): FireEye Endpoint Security is an integrated solution that detects and protects endpoints against known and unknown threats. This integration provides access to information about endpoints, acquisitions, alerts, indicators, and containment. You can extract critical data and effectively operate the security operations automated playbook. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Trellix ePO modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-epoRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix ePO# Trellix ePOhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with Trellix (McAfee) ePolicy Orchestrator products. Enhance protection from network edge to endpoint with McAfee Advanced Threat Defense, run queries and receive alarms from McAfee ESM, get file reputations and the systems that reference files from McAfee Threat Intelligence Exchange (TIE), and manage McAfee ePO.Integrate with Trellix (McAfee) ePolicy Orchestrator products. Enhance protection from network edge to endpoint with McAfee Advanced Threat Defense, run queries and receive alarms from McAfee ESM, get file reputations and the systems that reference files from McAfee Threat Intelligence Exchange (TIE), and manage McAfee ePO.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Trellix ePO {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Integrate with Trellix (McAfee) ePolicy Orchestrator products. Enhance protection from network edge to endpoint with McAfee Advanced Threat Defense, run queries and receive alarms from McAfee ESM, get file reputations and the systems that reference files from McAfee Threat Intelligence Exchange (TIE), and manage McAfee ePO. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Trellix Network modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-networkRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix Network# Trellix Networkhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Trellix Network (formerly FireEye) network security. FireEye Central Management (CM Series) is the threat intelligence hub that shares intelligence across the FireEye ecosystem to detect and prevent cyber attacks. FireEye Helix provides next-generation SIEM, orchestration, and threat intelligence for alert management, search, analysis, investigation, and reporting. McAfee Network Security Manager gives real-time visibility and control over McAfee intrusion prevention systems deployed across your network. FireEye (AX Series) submits malware objects and URLs for analysis.Trellix Network (formerly FireEye) network security. FireEye Central Management (CM Series) is the threat intelligence hub that shares intelligence across the FireEye ecosystem to detect and prevent cyber attacks. FireEye Helix provides next-generation SIEM, orchestration, and threat intelligence for alert management, search, analysis, investigation, and reporting. McAfee Network Security Manager gives real-time visibility and control over McAfee intrusion prevention systems deployed across your network. FireEye (AX Series) submits malware objects and URLs for analysis.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Trellix Network {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Trellix Network (formerly FireEye) network security. FireEye Central Management (CM Series) is the threat intelligence hub that shares intelligence across the FireEye ecosystem to detect and prevent cyber attacks. FireEye Helix provides next-generation SIEM, orchestration, and threat intelligence for alert management, search, analysis, investigation, and reporting. McAfee Network Security Manager gives real-time visibility and control over McAfee intrusion prevention systems deployed across your network. FireEye (AX Series) submits malware objects and URLs for analysis. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Trellix Sandbox modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-sandboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix Sandbox# Trellix Sandboxhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the McAfee DXL integration to connect and optimize security actions across multiple vendor products.Use the McAfee DXL integration to connect and optimize security actions across multiple vendor products.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Trellix Sandbox {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the McAfee DXL integration to connect and optimize security actions across multiple vendor products. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Trellix SIEM modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-siemRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix SIEM# Trellix SIEMhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Connect to McAfee Active Response (MAR) to capture and monitor events, files, host flows, process objects, context, and system state changes that may be indicators of attack (IoAs) or attack components lying dormant.Connect to McAfee Active Response (MAR) to capture and monitor events, files, host flows, process objects, context, and system state changes that may be indicators of attack (IoAs) or attack components lying dormant.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Trellix SIEM {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Connect to McAfee Active Response (MAR) to capture and monitor events, files, host flows, process objects, context, and system state changes that may be indicators of attack (IoAs) or attack components lying dormant. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Trellix Threat Intel modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-threat-intelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Trellix Threat Intel# Trellix Threat Intelhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.FireEye iSIGHT is a cybersecurity intelligence platform that provides organizations with comprehensive threat intelligence and analysis. It offers real-time monitoring and detection of emerging cyber threats, allowing businesses to proactively defend against attacks. Fetch indicators and reports from the FireEye Intelligence Feed.FireEye iSIGHT is a cybersecurity intelligence platform that provides organizations with comprehensive threat intelligence and analysis. It offers real-time monitoring and detection of emerging cyber threats, allowing businesses to proactively defend against attacks. Fetch indicators and reports from the FireEye Intelligence Feed.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Trellix Threat Intel {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. FireEye iSIGHT is a cybersecurity intelligence platform that provides organizations with comprehensive threat intelligence and analysis. It offers real-time monitoring and detection of emerging cyber threats, allowing businesses to proactively defend against attacks. Fetch indicators and reports from the FireEye Intelligence Feed. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ TrendAI modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trendai/trendaiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# TrendAI# TrendAIhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintTrend Micro security products for endpoint, server, cloud, email, and extended detection and response (XDR). Manage Apex One agents and User-Defined Suspicious Objects, administer Deep Security computers, firewall rules, and policies, protect cloud applications with Cloud App Security, analyze samples with Deep Discovery Analyzer, and collect logs and events from Trend Micro Email Security and Trend Vision One.Trend Micro security products for endpoint, server, cloud, email, and extended detection and response (XDR). Manage Apex One agents and User-Defined Suspicious Objects, administer Deep Security computers, firewall rules, and policies, protect cloud applications with Cloud App Security, analyze samples with Deep Discovery Analyzer, and collect logs and events from Trend Micro Email Security and Trend Vision One.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Trend Micro Apex: Trend Micro Apex One central automation to manage agents and User-Defined Suspicious Objects. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Trend Micro Apex: Trend Micro Apex One central automation to manage agents and User-Defined Suspicious Objects. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Trend Micro Deep Discovery Analyzer: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Trend Micro Deep Discovery Analyzer: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # TrendAI {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Trend Micro security products for endpoint, server, cloud, email, and extended detection and response (XDR). Manage Apex One agents and User-Defined Suspicious Objects, administer Deep Security computers, firewall rules, and policies, protect cloud applications with Cloud App Security, analyze samples with Deep Discovery Analyzer, and collect logs and events from Trend Micro Email Security and Trend Vision One. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Trend Micro Apex](https://xsoar.pan.dev/docs/reference/integrations/trend-micro-apex): Trend Micro Apex One central automation to manage agents and User-Defined Suspicious Objects. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Trend Micro Deep Discovery Analyzer](https://xsoar.pan.dev/docs/reference/integrations/trend-micro-deep-discovery-analyzer): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Twilio modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/twilio/twilioRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Twilio# Twiliohint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Twilio to send SMS text messages, and with Twilio SendGrid, a cloud-based email delivery platform, to collect email activity events such as deliveries, opens, clicks, bounces, and spam reports for analysis in Cortex.Integrate with Twilio to send SMS text messages, and with Twilio SendGrid, a cloud-based email delivery platform, to collect email activity events such as deliveries, opens, clicks, bounces, and spam reports for analysis in Cortex.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Twilio: Send SMS notifications. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Twilio: Send SMS notifications. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Twilio SendGrid: Twilio SendGrid is a cloud-based email delivery platform that provides email activity tracking and analytics. This sub-capability is available with any active Cortex XSIAM license.• Twilio SendGrid: Twilio SendGrid is a cloud-based email delivery platform that provides email activity tracking and analytics. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # Twilio {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Integrate with Twilio to send SMS text messages, and with Twilio SendGrid, a cloud-based email delivery platform, to collect email activity events such as deliveries, opens, clicks, bounces, and spam reports for analysis in Cortex. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Twilio](https://xsoar.pan.dev/docs/reference/integrations/twilio): Send SMS notifications. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Twilio SendGrid](https://xsoar.pan.dev/docs/reference/integrations/twilio-send-grid): Twilio SendGrid is a cloud-based email delivery platform that provides email activity tracking and analytics. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ Uptycs modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/uptycs/uptycsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Uptycs# Uptycshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Uptycs is a cloud-native security analytics platform that provides unified visibility across endpoints, cloud workloads, and containers. Use this connector to collect events and security alerts from the Uptycs platform for centralized monitoring and case response.Uptycs is a cloud-native security analytics platform that provides unified visibility across endpoints, cloud workloads, and containers. Use this connector to collect events and security alerts from the Uptycs platform for centralized monitoring and case response.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Uptycs {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Uptycs is a cloud-native security analytics platform that provides unified visibility across endpoints, cloud workloads, and containers. Use this connector to collect events and security alerts from the Uptycs platform for centralized monitoring and case response. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Vectra modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vectra/vectraRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Vectra# Vectrahint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Vectra is the leading AI-driven threat detection and response platform for the enterprise. It detects advanced attacker behaviors across hybrid and multi-cloud environments, giving security teams high-fidelity signal and rich context to prioritize, investigate, and respond to threats in real time. Learn more at Vectra Website.Vectra is the leading AI-driven threat detection and response platform for the enterprise. It detects advanced attacker behaviors across hybrid and multi-cloud environments, giving security teams high-fidelity signal and rich context to prioritize, investigate, and respond to threats in real time. Learn more at Vectra Website.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Vectra {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Vectra is the leading AI-driven threat detection and response platform for the enterprise. It detects advanced attacker behaviors across hybrid and multi-cloud environments, giving security teams high-fidelity signal and rich context to prioritize, investigate, and respond to threats in real time. Learn more at [Vectra Website](https://www.vectra.ai/). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):