Issue stitching

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Issue stitching

L0 Member

Hello everyone!


can someone explain me how the issues are stitched into cases in XSIAM?
Please explain me in detail.

1 REPLY 1

L4 Transporter

Hi @B.kumar873690 

 

In Cortex XSIAM, the stitching of Alerts into Issues and Issues into Cases is driven by an AI/ML-based correlation engine designed to build a unified attack narrative from large-scale security telemetry. At the first level, multiple alerts are grouped into an Issue when XSIAM identifies strong relationships such as shared entities (user, endpoint, IP address, cloud resource, or identity), temporal proximity, behavioral similarity, and process causality (parent-child process relationships). This ensures that individual alerts are not treated in isolation but are instead combined into a single meaningful security story segment representing part of an attack chain.

 

At the next level, multiple Issues are stitched into a Case, which represents the full end-to-end security incident or attack campaign. This correlation is based on broader relationships such as common entities across issues, matching threat intelligence indicators (IOCs, malware families, attacker infrastructure), and continuity across the attack lifecycle stages like phishing, execution, persistence, lateral movement, and exfiltration. XSIAM uses its ML-driven data model and continuous telemetry enrichment to understand that these separate Issues are actually part of the same coordinated attack.

 

Overall, this approach transforms fragmented security data into a single unified Case, enabling SOC teams to investigate the complete attack lifecycle in one place instead of handling multiple disconnected alerts and issues. This significantly reduces alert fatigue, improves investigation efficiency, and supports faster detection and response in modern SOC environments.

 

Reference:

https://www.paloaltonetworks.com/cyberpedia/what-is-extended-security-intelligence-and-automation-ma...

https://www.paloaltonetworks.com/resources/ebooks/cortex-xsiam

 

Please help other users by clicking ‘Accept as Solution’ if a post helps solve your problem.


Read more about how and why to accept solutions.

 

Best Regards,

Vinothkumar C 

  • 79 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!