Palo Alto Networks extended its Cortex XDR platform across more cloud data and added new identity analytics capabilities with the 3.0 version of its extended detection and response (XDR) product.
Specifically, the new XDR for Cloud capability extends monitoring, detection, and investigations into cloud environments beyond virtual machines running in clouds. The third-generation platform integrates data from Kubernetes environments, cloud hosts, traffic logs, audit logs, Palo Alto Networks’ Prisma Cloud product, and third-party cloud security data with non-cloud endpoint and network data sources.
Integrating this data into the XDR platform makes it easier for security operations center (SOC) teams to use it in analytical processing and run security rules against it, as opposed to just using this data to search for and investigate threats, according to the vendor.
Cortex XDR Boosts Identity AnalyticsCortex XDR Identity Analytics already detected and supported more than 30 identity tools spanning firewalls, identity and access management services, and secure web gateways. But in the 3.0 product, Palo Alto Networks added support for human resources platform Workday along with user risk scoring and a 360-degree view of user, user specific investigation, and user context across all other XDR panels.
These new identity analytics capabilities can help SOC teams better detect malicious user activities and insider threats, said Tim Junio, senior vice president of products for Cortex at Palo Alto Networks.
“For example, the Workday profile information for the employee or employees associated with that activity can show details such as department, location, and hire date,” Junio wrote in response to questions. “This HR context is critical in helping analysts assess whether any employee or employees were unintentionally misusing corporate resources or if there may have been malicious intent — or even if it was someone impersonating a user or users. The analyst can then prioritize, escalate, and investigate accordingly.”
A third new module, Cortex XDR Forensics, gives customers access to the forensic investigation tool used by the Palo Alto Networks Unit 42 security consulting group. This capability comes from Palo Alto Network’s Crypsis acquisition, and it provides the ability to gather historical evidence such as user, file, application, browser, and system activities from compromised systems. This boosts the XDR platform’s analytics capabilities for incident response.
Palo Alto Networks also added an incident management interface, which gives security analysts a comprehensive story of an incident in one place. This information, all available via the interface, includes related malicious artifacts, hosts, users, and correlated alerts mapped to the MITRE ATT&CK framework.
And finally, the platform added a third-party data engine that lets customers ingest, normalize, correlate, query, and analyze data from most outside sources. This third-party data can be correlated with threat activity and tagged with MITRE ATT&CK tactics, techniques, and procedures to provide more details about adversarial movement.
“Palo Alto Networks created the XDR category in 2019 understanding that only by integrating data from across all security sources can we detect complex threats accurately, prevent attacks automatically, and investigate them much faster,” Tim Junio, SVP of products at Palo Alto Networks, said in a statement. “With our third generation XDR solution expanding to cloud and identity analytics, Cortex XDR 3.0 has taken a large step towards being the comprehensive platform for the SOC to protect endpoints, entities, assets, workloads, and critical data.”
But while Palo Alto Networks and other security companies including Trend Micro pioneered the sector two years ago, by now most of its competitors have also jumped into the market with their own XDR products. This includes arch-rival Cisco with its SecureX platform. Just last week, FireEye rolled out its new XDR product.
Comments