Platform

Cortex AgentiX
The Agentic Workforce

The next generation of Cortex XSOAR — the industry's most secure platform to build, deploy, and govern your AI agent workforce. Trained on 1.2 billion real-world playbook executions from a decade of SOAR leadership.

Overview

What is AgentiX?

From SOAR automation to autonomous agentic operations — the platform that runs your SOC at machine speed.

98%
MTTR Reduction
75%
Less Manual Work
1,300+
Prebuilt Playbooks
1,100+
Integrations

From XSOAR to AgentiX: Launched October 28, 2025, Cortex AgentiX is the direct evolution of Cortex XSOAR — the platform that defined Security Orchestration, Automation, and Response for the industry. AgentiX takes the foundational decade of SOAR leadership (1.2B playbook executions, 1,300+ playbooks, 1,100+ integrations) and layers on autonomous AI agents capable of independent reasoning, decision-making, and cross-platform action. Available natively in Cortex Cloud and Cortex XSIAM; the standalone platform arrived in February 2026. Current release is AgentiX 1.4 (July 2026), following 1.2 (February 2026) and 1.3 (May 2026). Palo Alto positions AgentiX as “the natural evolution of our market-leading SOAR platform”, while Cortex XSOAR continues to be sold standalone.

Machine-Speed Response

AI agents triage, investigate, and remediate threats autonomously — 98% reduction in MTTR with 60%+ of XSIAM customers achieving sub-10-minute resolution.

Decade of Training Data

Every agent is trained on 1.2 billion real-world playbook executions — not synthetic data. Institutional knowledge from global SOC operations baked into every decision.

Native MCP Support

Industry-first native Model Context Protocol (MCP) support enables seamless agent-to-tool communication across any MCP-compatible service — no custom connectors required.

Enhanced Case Management

Auto-groups related security issues into unified cases. Resolution Center streamlines analyst workflows. XQL (Cortex Query Language) replaces Lucene for faster, more powerful investigations.

Automation Rules

WHEN/IF/THEN automation rules, Quick Actions, and a Playbook Catalog enable rapid deployment of security workflows without deep engineering resources.

Enterprise-Grade Guardrails

RBAC, SBAC (Scope-Based Access Control), human-in-the-loop approval gates, and full auditability built in — governance that satisfies even the most demanding compliance requirements.

Prebuilt Agents

Your Agentic Workforce, Ready to Deploy

Six purpose-built AI agents covering the most critical SOC and IT workflows — deployable out of the box with no configuration required.

Threat Intelligence Agent

SOC

Autonomously aggregates, enriches, and correlates threat intelligence from internal telemetry and external feeds. Identifies emerging threat actors, TTPs, and indicators — prioritizing what matters most to your environment.

  • Automated IOC enrichment across 1,100+ sources
  • MITRE ATT&CK mapping and campaign tracking
  • Proactive hunting recommendations

Email Investigation Agent

Phishing

Fully automates phishing triage and email-based threat investigation. Detonates suspicious attachments and URLs in sandbox, traces campaign infrastructure, and remediates across the inbox fleet — all without analyst intervention.

  • Automated URL and attachment sandbox detonation
  • Campaign correlation and sender reputation analysis
  • Bulk inbox remediation with audit trail

Endpoint Investigation Agent

EDR

Autonomously investigates endpoint alerts from EDR telemetry. Traces process trees, lateral movement, and persistence mechanisms — then executes containment and remediation actions across affected hosts without waiting for analyst queues.

  • Process tree analysis and attack chain reconstruction
  • Automated isolation and malware removal
  • Cross-host lateral movement tracing

Network Security Agent

Network

Monitors network telemetry for anomalous traffic patterns, C2 communications, and data exfiltration attempts. Coordinates with firewall and NAC policies to execute dynamic network containment at machine speed.

  • C2 detection and automated blocking
  • Dynamic firewall rule orchestration
  • Exfiltration detection across 15+ PB daily telemetry

Cloud Security Agent

Cloud

Investigates cloud security alerts from AWS, Azure, and GCP environments. Identifies misconfigurations, over-privileged roles, and runtime threats — then remediates via direct cloud API actions with full change logging for compliance.

  • Multi-cloud alert investigation and triage
  • Automated IAM remediation and policy enforcement
  • Runtime threat containment via cloud APIs

IT Agent

IT Ops

Bridges the gap between security and IT operations. Automates routine IT workflows triggered by security events — access provisioning/deprovisioning, patch deployment, ticket creation, and change management — without ITSM queue backlogs.

  • Automated ITSM ticket creation and routing
  • Access revocation and provisioning workflows
  • Patch orchestration triggered by security findings

Custom Agents

Build Custom Agents — No Code Required

Every organization has unique workflows. AgentiX lets your team build bespoke agents using a GenAI-powered no-code builder — no ML expertise needed.

GenAI No-Code Builder

Describe your agent's goals in plain language. The GenAI builder translates intent into agent logic, connecting the right tools and playbooks automatically. SOC analysts — not developers — build the agents.

MCP Integrations

Connect your custom agents to any MCP-compatible tool or service. The Cortex MCP Server (Beta) exposes the entire AgentiX capability set — agents can call agents, orchestrating complex multi-step workflows autonomously.

Custom Actions from Scripts

Extend agent capabilities with custom actions built from scripts, commands, or AI prompts. Reuse existing XSOAR automation assets — 1,300+ playbooks and 1,100+ integrations are immediately available as agent building blocks.

Playbook Catalog

The Playbook Catalog surfaces community-contributed and PAN-authored playbooks as composable agent actions. Start from proven templates and customize for your environment — accelerating time-to-value from weeks to hours.

Governance

Enterprise Governance at Agent Scale

AI agents need stronger controls than human operators. AgentiX was designed governance-first — every action is scoped, logged, and auditable.

RBAC

Role-Based Access Control governs what each agent can see and do. Agents inherit permissions from the roles that deployed them — never exceeding operator authority.

SBAC

Scope-Based Access Control constrains agent actions to defined operational scopes. An endpoint agent cannot touch cloud resources. A threat intel agent cannot trigger remediation. Blast radius is bounded by design.

Human-in-the-Loop

High-stakes actions trigger mandatory analyst approval before execution. Configurable per-agent, per-action-type, or per-environment — so automation confidence grows incrementally alongside trust.

Full Auditability

Every agent decision, tool call, and action is logged with full context — what the agent reasoned, what data it saw, and what it did. Compliance-ready audit trails for SOC 2, ISO 27001, HIPAA, and more.

Customer validation — Tyson Foods: Tyson Foods CISO reported 40% more log visibility and 50% reduction in MTTR after deploying Cortex XSIAM with AgentiX. The combination of automated investigation and governed remediation allowed their SOC team to handle significantly higher alert volumes without additional headcount.

Platform Integration

AgentiX Across the Cortex Platform

AgentiX is not a standalone product — it is the agentic orchestration layer that spans XSIAM, XDR, and Cortex Cloud.

Cortex Agentic Assistant

NEW

The natural language interface to your entire AI agent workforce. Ask the Agentic Assistant to investigate an alert, hunt for a threat actor, or deploy an agent to handle an incident — it orchestrates the right agents across XSIAM, XDR, and Cortex Cloud to execute the request end-to-end.

Operators no longer need to navigate across consoles or know which agent to invoke. The Assistant understands security context and routes work to the right specialized agent automatically.

Cortex XDL 2.0

Extended Data Layer

The data backbone ingesting 15+ petabytes of security telemetry daily across 1,100+ integrations. XDL 2.0 feeds every AgentiX agent with unified, normalized context — eliminating the data silos that blind traditional SOAR.

XQL (Cortex Query Language) replaces Lucene — giving analysts and agents a unified query language across all data sources for faster, more powerful threat hunting.

Chronosphere Integration

Observability + Security

Following the January 2026 Chronosphere acquisition, the intent is for AgentiX to gain deep observability context — metrics, traces, and logs from cloud-native environments — so agents can correlate security alerts with infrastructure anomalies and remediate before customer impact. Status as of Aug 2026: the deep native integration is still planned, not GA. Chronosphere says it has "begun extending" the Temporal Knowledge Graph via a native AgentiX integration so agents can act once a root cause is identified. The two paths that work today are the Telemetry Pipeline's Cortex XSIAM destination plugin and the read-only Chronosphere MCP Server, which gives agents PromQL, log, trace, dashboard, monitor and SLO access with no write path (Chronosphere, MCP Server). See Chronosphere for the full status check.

Handles hundreds of millions of datapoints/second — purpose-built for cloud-native scale. Telemetry Pipeline reduces data volumes by 30%+ with 20x less infrastructure than legacy solutions.

Koi — Agentic Endpoint Layer

Closed Apr 14, 2026

The Koi acquisition closed April 14, 2026 (~$400M). Defines the new Agentic Endpoint Security (AES) category, securing the agentic endpoint surface — MCP servers, browser extensions, vibe coding agents, and AI plugins. Now shipping as a Cortex XDR 5.0 module, a standalone product alongside any EDR, and integrated into Prisma AIRS as a single control plane for enterprise-wide AI adoption. Gives AgentiX visibility and control at the MCP layer that no other security vendor currently provides.

MCP Server Security

Secure the protocol layer between AI agents and enterprise tools

Extension Governance

Visibility and control over AI browser extensions and plugins

Plugin Security

Audit and enforce policy on AI application plugin integrations

Traction

XSIAM Platform Metrics

The foundation AgentiX is built on — Q3 FY2026 (quarter ended Apr 30, 2026): XSIAM ARR above $600M, up 100% year over year, 740 customers, more than 17 PB ingested per day.

$600M+
XSIAM ARR
740
XSIAM Customers
17+ PB
Daily Telemetry
1,200+
Integrations

~$1M

Average XSIAM ARR per customer

60%+

Achieve MTTR under 10 minutes

119%

Net retention, platform customers

Oct '25

AgentiX GA launch date (standalone platform Feb 2026)

Releases & Licensing

AgentiX 1.4 and How It Is Licensed

Standalone platform since February 2026. Licensed per user per year, with compute units metering agent work.

AgentiX 1.2 — February 2026

First release of the standalone platform, alongside native availability inside Cortex XSIAM and Cortex Cloud.

AgentiX 1.3 — May 2026

Second standalone release on the 2026 quarterly cadence.

AgentiX 1.4 — July 2026 (current)

Frontier model choice; Automation Engineer playbook builder (private preview); Cortex XTI (Extended Threat Intelligence, also shipping in XSIAM 3.6 and XDR 5.2); FedRAMP Moderate and FedRAMP High.

Licensing — per user, per year

AgentiX Enterprise

4 users and 800 compute units per year. Includes threat intelligence management.

AgentiX Base

2 users and 400 compute units per year.

Scoping note: two variables drive the quote — user count and annual compute-unit consumption. Size compute units against expected agent run volume, not analyst headcount alone, and confirm whether the account needs FedRAMP Moderate or High, both of which AgentiX 1.4 carries.

Vision

Where This Leads

The autonomous SOC is not a distant future — it is the logical conclusion of the platform being assembled today.

Autonomous SOC Operations

AI agents handle Tier 1 and Tier 2 investigations autonomously — triaging alerts, correlating evidence, executing containment, and closing cases at machine speed. Human analysts focus on novel threats, strategic hunts, and complex escalations that genuinely require judgment.

AgentiX + Chronosphere: Find & Fix Before Impact

Combining Chronosphere's observability telemetry with AgentiX's agentic remediation creates the first platform capable of autonomous find-and-fix — detecting security and performance issues from observability signals and remediating them before any customer-facing impact occurs. This is the stated direction, not a shipped capability — as of Aug 2026 the native integration is still planned, and the working paths are the Telemetry Pipeline's Cortex XSIAM destination plugin and the read-only Chronosphere MCP Server.

Securing the Agentic Endpoint

Koi's integration closes the last open attack surface: the MCP layer itself. As every enterprise deploys AI agents, MCP servers and browser extensions become primary targets for prompt injection, supply chain attacks, and credential theft. AgentiX + Koi secures the agent-to-tool communication layer end-to-end. For the discovery questions that open this conversation, see AES Conversation Starters.

The governance imperative — 82:1: AI agent identities already outnumber human identities 82 to 1 in advanced enterprise environments. Each agent has credentials, permissions, and access to sensitive systems. Traditional identity governance was designed for thousands of human users. AgentiX's RBAC/SBAC framework — and Idira's identity platform (Idira, formerly CyberArk) — are the only enterprise-grade solutions architected for the governance challenge at this ratio.

The Destination

Every enterprise security workflow — automated with enterprise-grade guardrails

The target is not partial automation of repetitive tasks. It is complete agentic coverage of the SOC — from alert ingestion through investigation, containment, remediation, and documentation — with human oversight at the decision points that matter. AgentiX is the platform that makes this possible at enterprise scale, with the governance that boards and regulators require.

SOC Pillar
Observability Pillar
Identity Pillar
Cloud Pillar
Network Pillar

Pre-Sales

Scoping Checklist

Data points to collect before quoting Cortex AgentiX.

User Count — Licensed users needed. AgentiX Enterprise covers 4 users and AgentiX Base covers 2 users — both per year. Count everyone who will build, approve or supervise agents.
Compute-Unit Sizing — Expected annual compute-unit consumption. Enterprise includes 800 CU/yr, Base 400 CU/yr. Size against agent run volume, not analyst headcount.
Edition Selection — Enterprise vs Base. Enterprise includes threat intelligence management — confirm whether the account needs it or already licenses TIM separately.
FedRAMP Requirement — Whether the account requires FedRAMP Moderate or FedRAMP High. AgentiX 1.4 (July 2026) carries both.
Consumption Path — Standalone AgentiX platform, or AgentiX natively inside Cortex XSIAM / Cortex Cloud. This changes the commercial construct and the tenant footprint.
XSOAR Overlap — Existing Cortex XSOAR estate — version (8.13 on-prem / 8.15 SaaS), active user count, playbook inventory and renewal date. XSOAR remains sold standalone; decide co-existence vs consolidation.
Agent and Use-Case Inventory — Which prebuilt agents apply and which custom agents are required. Capture the target use cases and the systems each agent must act on.
MCP and Integration Requirements — MCP servers, custom scripts and third-party tools the agents must reach, plus any that are not yet covered by an existing content pack.
Governance Model — RBAC/SBAC design, human-in-the-loop approval points, and audit/retention requirements for agent actions.
Model Choice Constraints — Whether the customer mandates or prohibits specific frontier models. AgentiX 1.4 supports frontier model choice; confirm data-handling policy for the selected model.