Palo Alto Networks this week introduced Cortex XSIAM for Cloud, which extends its threat detection and response capabilities to the cloud environments to help security operations centers (SOC) teams identify and remediate cloud threats.
Cortex XSIAM, which stands for extended security intelligence and automation management, is an artificial intelligence (AI) based platform to automate threat detection and remediation and aims to replace legacy security information and event management (SIEM) tools.
The vendor launched the XSIAM 2.0 last year, designed to provide SOC teams with a single platform that consolidates multiple tools they need for end-to-end visibility and AI automation to quickly address security threat detection and response, Gonen Fink, SVP of products for Cortex and Prisma Cloud at Palo Alto Networks told SDxCentral, adding the new feature is “taking this concept and applying this to the cloud.”
He noted that until recently, cloud security was typically purchased by cloud-focused teams, and more SOC teams were realizing they had limited visibility into the cloud.
However, traditional SOC tools, designed for on-premises infrastructure, struggled to provide comprehensive visibility and response capabilities for cloud assets. This gap in the security framework often left organizations vulnerable to threats. “Most of the SOC tools were not designed and optimized for the cloud use case,” Fink said.
He added that Cortex XSIAM for Cloud is optimized for cloud environments, offering a consolidated view of cloud assets, security coverage and potential security incidents and alerts across all of customers’ cloud service provider. This new feature is set to become publicly available later this month
Cortex XSIAM for cloud vs. XSIAM + Prisma Cloud
The new Cortex XSIAM for Cloud collects data directly from the cloud service provide, functioning without the need to purchase Palo Alto Networks cloud security platform Prisma Cloud, Fink said.
But for customers who have both XSIAM and Prisma Cloud, integrating both tools offers added value, such as enhanced contextual insights and visibility, aiding in the investigation of alerts and improving security visibility, he added.
Prisma Cloud is the vendor’s cloud-native application protection platform (cloud native application protection platform (CNAPP)), which consolidates a large number of previously siloed capabilities including runtime cloud workload protection platform (CWPP), cloud security posture management (CSPM), cloud infrastructure entitlements management (CIEM), development artifact scanning, and infrastructure-as-code (IAC) scanning.
“The Prisma cloud is focusing on preventing breaches to proper configuration, whereas XSIAM is focusing on detecting threats that are active, and then the agent itself looks for blocking security is serving both platforms,” Fink said.
Previously, XSIAM and Prisma Cloud were used by different teams, SOC teams and cloud practitioners, respectively, with limited integration, he added.
The Cortex XSIAM for Cloud now offers a unified platform that deepens the integration. This approach simplifies operations, ensures comprehensive visibility into cloud workloads and improves threat detection and response capabilities, Fink touted.
Palo Alto Networks addresses multicloud security challenges
Cortex XSIAM for Cloud aims to address multicloud security challenge by providing visibility into assets across all major cloud platforms from a single interface.
The new Cloud Command Center provides “end-to-end visibility” of all cloud assets and focuses on answering questions such as “What do I have in my cloud? What are the cloud incidents and how do I respond to them?” according to Fink.
He added cloud service providers also offer threat detection tools and visibility into whether some of the cloud workloads were breached, but that’s post-breach and not enough.
“If they want to know what they have [in the cloud] today, using the native tools from the cloud providers, they need to go into three or sometimes five different UIs,” he said. “And some of those challenges are addressed by product libraries that provide you visibility to your assets, but not at the level that is required by the SOC.”
Instead, Cortex XSIAM for Cloud provides a new cloud security agent that takes the threat prevention technology from extended detection and response (XDR) and optimizes it for use in the cloud and also incorporates technologies from Prisma Cloud to scan cloud workloads for vulnerabilities and check for compliance, Fink said.
Comments