Cortex XSIAM

Resources for Cortex XSIAM, Palo Alto Networks’ autonomous security platform powering the Modern SOC.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XSIAM

Welcome to the Cortex XSIAM LIVEcommunity! Explore how-to guides, best practices, and on-demand videos to help you get the most out of Cortex XSIAM. Have questions or insights to share? Join the conversation in our Discussions forums and connect with our Product Experts.

Stay in the loop—subscribe now to get the latest product updates delivered to you.

Articles

Cortex XSIAM Use Case Definition Template Contains a hyperlink

06-16-2023 — Use Case Definition (UCD) Template This template will help you understand and leverage the UCD to benefit implementation strategy, understand how your Incident Response (IR) process fits into XSIAM, and identify integrations for ingestion/enrichment needed. The XSIAM Use Case Definition Templa... — Read more

Labels: Cortex XSIAM
114 published by in Cortex XSIAM Customer Articles
06-16-2023 edited by

Blogs

SecOps Insider-April Edition Contains an image Contains a hyperlink

04-30-2025 — Discover key insights from Sam Rubin, SVP of Consulting and Threat Intelligence at Unit 42, on the critical importance of cyber resilience highlighted in the 2025 Global Incident Response Report. Get recommendations for enhancing incident response... — Read more

Labels: Cortex Cortex XDR Cortex Xpanse Cortex XSIAM Cortex XSOAR Cybersecurity Prisma Cloud SecOps Security Operations Unit 42 XDR Xpanse
271 by in Community Blogs

Threat Brief: CVE-2024-6387 OpenSSH RegreSSHion Vulnerability Contains an image Contains a hyperlink

07-15-2024 — On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, called RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote... — Read more

Labels: Cortex XDR Cortex Xpanse Cortex XSIAM Cortex XSOAR CVE-2024-6387 incident response OpenSSH OpenSSH. RegreSSHion RegreSSHion Remote Code Execution security intelligence SOC SSH threat brief Threat Detection Vulnerability
16557 by in Community Blogs

Harnessing the Power of Cortex XSIAM for Enhanced File Management and Data Privacy Contains an image

07-15-2024 — In an era where cybersecurity threats are evolving at a breakneck pace, Extended Detection and Response (XDR) solutions have emerged as the vanguard of defense for organizations. But what if we could extend the capabilities of the Cortex XSIAM sol... — Read more

Labels: Cortex XSIAM Endpoint Security incident response security intelligence SOC Threat Detection
2179 4 by in Community Blogs

What’s Next in Cortex - New Wave of Innovations in Cortex (June 2024 Release) Contains an image Contains a hyperlink

07-03-2024 — ith the ever evolving threat landscape, security operations teams require a new level of efficiency to protect their organizations. The latest release across Cortex products aims to solve a diverse set of challenges in security operations, all whi... — Read more

Labels: Cortex Cortex XDR Cortex Xpanse Cortex XSIAM Cortex XSOAR Release Notes XDR Xpanse XSIAM XSOAR
5436 by in Community Blogs

SmartGrouping - Precision AI™-Driven Investigation Contains an image Contains a hyperlink

06-05-2024 — SmartGrouping is a crucial aspect of security operations, allowing to connect disparate alerts and paint a comprehensive picture of an attack. It's like piecing together a puzzle, where each alert represents a piece, and the complete picture revea... — Read more

Labels: anomaly detection behavioral analysis Cortex XDR Cortex XSIAM incident response machine learning XDR XSIAM
2177 by in Community Blogs

Discussions

Author Topic Views Replies
michaelsysec242
05-21-2025

Linking Issues to Cases with Command Contains a hyperlink

Hello Livecomm, I am trying to link an issue to a case using CLI/automation or similar. Right-clicking on an issue allows me to assign it to a case, ... — Read more

posted in Cortex XSIAM Discussions

44 0
PA_nts
05-20-2025

Broker-VM disconnet alert notification

Hi All, anyi dea how i can generate an alert when a broker-vm gets disconnected? Has anyone managed to create a correlation rule that will alert i... — Read more

posted in Cortex XSIAM Discussions

79 1
O.Faheem
05-18-2025

Cortex XDR Agent 8.8 Contains an attachment

Hi, We upgraded the Cortex XDR agent version to 8.8.0.10622 for MS Windows. However, in a few moments, it started detecting Netskope and Tanium as m... — Read more

posted in Cortex XSIAM Discussions

95 0
michaelsysec242
05-18-2025

Working with Multi-Select Array Field with setParentIncidentFields

Hello all, I have an array of various IPs, and I want to set them to a case field using the setParentIncidentFields command. When defining the argumen... — Read more

posted in Cortex XSIAM Discussions

79 0
michaelsysec242
05-20-2025

Solved! Creating a Custom Issue For a Case Contains a hyperlink

Hello LiveComm, I have created a custom case with a single Issue for a Use-Case. I want to create more issues with a command or script in this custom ... — Read more

posted in Cortex XSIAM Discussions

159 1

Digital Learning Courses

Access Palo Alto Networks learning platform to gain technical insights and educational materials across our full suite of products.

Please note: SSO login is necessary to access the content.

Videos

Your SOC's Efficiency & Automation Powerhouse | Cortex XSIAM

Published on Dec 17, 2022
15,641 views
124 likes