security eye 2
– Getty Images

Palo Alto Networks' Unit 42 incident response team uses extended detection and response (XDR) technology based on the vendor’s Cortex XSIAM solution to keep up with the ever-escalating pace, scale, and sophistication of cybersecurity attacks.

Palo Alto Networks launched its XDR platform in 2018. The launch was based on the idea of being able to aggregate and augment information into a single location.

“The whole idea of XDR was to do a lot of endpoint data collection, but to augment this with a lot of additional data sources, from the network for identity systems, from the cloud, and stitch everything together to help incident responders or analysts to understand the quickest possible what's going on,” Gonen Fink, SVP of products for Palo Alto Networks' Cortex and Prisma Cloud business, told SDxCentral.

Fink explained that the vendor integrates artificial intelligence (AI) and XDR to allow security analysts to prioritize events, group multiple events into incidents, and minimize manual work to enhance the speed and accuracy of detection and remediation processes.

Palo Alto Networks recently extended XDR to the cloud, “which basically collects tons of cloud data so that when there is an attack on your cloud environment, IR [incident response] responders will have the same level of data they [have for the on-premises] and be able to investigate and respond to the threat as quickly as possible,” Fink added.

How Palo Alto Networks Unit 42 uses XDR Palo Alto

Networks' Unit 42 has more than 1,000 retainer customers worldwide, ranging from midsized, multinational corporations to public sector organizations, and the team conducts 800 to 1,000 incident responses per year, according to Sam Rubin, VP of global head of operations at Unit 42.

The team uses Palo Alto Networks' Cortex XDR in real-world incident response.

“On the [incident response] side, XDR is our core tool because of all the forensic capabilities and the investigative capabilities,” Rubin said. “What XDR has done is automate that so it's integrating on an ongoing basis, the telemetry and artifacts from the laptops and servers, the cloud telemetry and the network telemetry, and putting it together. And so for us and as responders, it's this incredible technology so we can ultimately solve the customer's problems faster.”

Based on XDR, Palo Alto Networks launched its XDR-based Cortex XSIAM platform in early 2022. The extended security intelligence and automation management product is an AI-based platform to automate threat detection and remediation and is designed to replace legacy SIEM tools.

“I think what happened over the years is that SIEM was traditionally getting alerts, so they were just used for a central repository of alerts, whereas other solutions like EDR or XDR ... were collecting much more data in doing machine learning and analytics and providing enough context for incident responders, but they were doing this in silo,” Fink said. “In XDR, we started kind of platformizing and consolidating those tools into one. And with XSIAM, we took it to the next level and added information and attack surface management and identity threat detection and threat intel management, so you have one offering that replaced your entire SOC [security operations center] that goes beyond XDR.”

Rubin explained Unit 42 uses XSIAM for broader integration capabilities with different logging sources, especially third-party security telemetry.

“[When] we drop into a large enterprise and they already have either a SIEM or a different EDR tool in place, we need to bring that in and then to add in different layers of automation for purposes of taking different actions, like integrating with an email security platform to take actions in the email account. We start to bring, those motions into our response,” Rubin said.