Cortex — Agentic Endpoint Security

Cortex Agentic Endpoint Security
Powered by Koi

Secure the agentic endpoint surface — vibe coding agents, MCP servers, browser extensions, and AI plugins. The new category of protection for an AI-native enterprise. The Koi Security acquisition was announced Feb 17, 2026 and closed April 14, 2026; deal value was not officially disclosed.

Technical Deep Dive → Compete Positioning
Apr 14, 2026
Acquisition Closed (value undisclosed)
3
Deployment Modes
MCP
Layer Coverage
New
Category: AES

Overview

What is Agentic Endpoint Security?

Agentic Endpoint Security (AES) is a new category of protection introduced by Palo Alto Networks with the Koi Security acquisition, announced Feb 17, 2026 and closed April 14, 2026. Palo Alto Networks did not disclose the purchase price; Calcalist reported approximately $400M — treat that figure as press-reported, not official. The technology is branded “Koi AES” / “Cortex Agentic Endpoint Security” and is built on the Wings™ AI engine. AES secures the new attack surface created by AI agents on the endpoint: vibe coding agents like Claude Code and Cursor, autonomous AI tools, MCP servers, browser extensions, AI plugins, and the broader AI software supply chain.

Traditional EDR was not designed for autonomous software with production access. AES provides inventory, real-time risk analysis, and automated enforcement so harmful code from AI-generated tools and extensions never reaches production. As enterprises adopt AI-driven developer tools, the endpoint becomes the first place an autonomous agent can do damage. AES closes that gap.

AES went GA as an integral part of the Cortex XDR agent with XDR 5.2 (July 20, 2026) — there is zero additional deployment for customers already running the agent (current agent release 9.3, July 26, 2026). It is also folded into Prisma AIRS, and remains deployable standalone alongside a third-party EDR.

Two things to say correctly: the ~$400M price is press-reported (Calcalist) and officially undisclosed — do not quote it as fact. And AES is no longer a separate module to install on Cortex XDR: with XDR 5.2 it ships inside the XDR agent itself.

Customer Choice

Three Deployment Modes

Customers don't have to switch EDRs to get AES. With XDR 5.2 the capability is already in the agent; standalone and Prisma AIRS routes remain.

Mode 1

Inside the Cortex XDR Agent (5.2)

GA with Cortex XDR 5.2 as an integral part of the XDR agent (release 9.3). Zero additional deployment — no separate module or second agent. Findings, inventory, and enforcement actions surface inside the Cortex XDR console alongside endpoint and email findings. Best for customers already running Cortex XDR — they may already own it.

Mode 2

Standalone Product

Still deployable standalone, running alongside CrowdStrike, SentinelOne, Microsoft Defender, or any other third-party EDR. Provides AES capabilities to customers who don't run Cortex XDR but still need agentic-AI risk visibility and enforcement. Best for customers committed to a competing EDR who still need AES.

Mode 3

Prisma AIRS Integration

Koi technology is also folded into Prisma AIRS (current release 3.0, March 23, 2026) for a single control plane covering enterprise-wide AI adoption — endpoint AI tools, AI workloads, and model security in one place. Best for customers buying AIRS who want unified AI governance across the stack.

As of Today

How Koi Fits Across the Cortex + Prisma AIRS Portfolio

A single technology, three commercial paths. Pick the one that matches the customer's existing stack.

Path SKU / Packaging Where Findings Land When To Lead With This
Inside the Cortex XDR Agent (5.2) Integral to the XDR agent as of XDR 5.2. Current 5.x license plans are Cortex XDR Pro EP and Cortex XDR EP Cloud on the Enterprise Runtime Security (XDR) + Core Analytics base; “Pro per Endpoint” and “Pro per GB” are legacy 3.x tier names. Cortex XDR console alongside endpoint, identity, and email findings. Triages through existing Cortex XDR Pro EP or Unit 42 Managed XSIAM analyst workflows. Customer is already on Cortex XDR or actively buying it. Fastest deploy, smallest blast radius for change.
Standalone Product Sold as Cortex AES (Agentic Endpoint Security) standalone. Per-endpoint subscription. Native AES console plus webhook / SIEM forwarders. Coexists with CrowdStrike, SentinelOne, or Defender. Customer is committed to a competing EDR but still needs agentic-AI risk visibility on the endpoint.
Prisma AIRS Integration Bundled with Prisma AIRS as the endpoint surface for the AIRS control plane. Strata Cloud Manager / AIRS dashboards. Findings join model, runtime, and prompt-layer signals in a single AI risk view. Customer is buying or expanding Prisma AIRS. Wants one AI control plane covering model, agent, and endpoint together.

All three paths use the same Koi technology under the hood. Choose the path; the underlying capability set is consistent.

What it does

Key Capabilities

AI Tool Inventory
Discover every AI agent, browser extension, and MCP server installed across the endpoint fleet. Includes both managed and shadow-installed tools, with real-time inventory updates.
AI-Driven Risk Analysis
Evaluate every agent, extension, and tool against known threat patterns: prompt injection vectors, tool chain hijacking, memory poisoning, credential exfiltration via agent context, and unsafe file operations.
Real-Time Enforcement
Automated enforcement at the endpoint: block harmful code from reaching the device, prevent unsafe agent actions, and pause autonomous tools when their actions exceed approved scope. Policy-driven, no manual intervention required.
MCP Layer Security
Secure the Model Context Protocol communication between agents and enterprise tools. Audit every action, enforce least-privilege boundaries, and detect supply-chain attacks targeting the MCP server itself — a coverage no other vendor provides today.
Browser Extension Governance
Inventory, risk-rate, and enforce policy on every browser extension, including AI-driven extensions that increasingly act as autonomous agents. Built on the original Koi research that exposed the developer marketplace extension threat vector.
Software Supply Chain Visibility
Track every piece of software that AI agents pull onto the endpoint — npm packages, pip dependencies, browser extensions, MCP servers. Real-time analysis catches supply-chain attacks at the moment of installation, not weeks later.

Buyer Profile

When to Use

  • Customer is rolling out AI-driven developer tools (Claude Code, Cursor, Copilot, OpenClaw, internal agents) and wants visibility before scaling further.
  • Customer has had — or is worried about — a software-supply-chain incident from a malicious browser extension, npm package, or compromised dev tool.
  • CISO is being asked by the board "what do we know about agentic AI risk?" and currently has no answer.
  • Customer is adopting MCP-based agent architectures and the security team has zero visibility into what those agents can do.
  • Customer runs Cortex XDR 5.2 — AES is already in the agent, so this is an enablement and policy conversation, not a deployment project.
  • Customer is committed to CrowdStrike, SentinelOne, or Defender and won't switch EDRs but still needs AES capabilities — standalone is the fit.
  • Customer is buying Prisma AIRS and wants AI security spanning model, runtime, and now endpoint in one control plane.

Competitive Positioning

Compete — What to Know

AES is a new category, not a like-for-like EDR replacement. The closest comparisons are software supply chain scanners and bolt-on DLP with AI policies.

vs. Snyk / GitGuardian (supply chain scanners)

Where AES wins: Real-time enforcement at the endpoint where agents actually execute, not just commit-time scanning. Inventory of installed AI tools, not just code dependencies. Operates inside any EDR or as an XDR module. MCP-layer coverage that no supply chain scanner addresses.

Where to be careful: Snyk's developer-workflow integration is mature; AES is a security-team product, not a developer-experience product. Some customers will want both.

vs. Bolt-on DLP with AI policies

Where AES wins: Purpose-built for agentic and autonomous behavior — not retrofitted. Understands tool chain hijacking, prompt injection, and memory poisoning at the endpoint. Inventory and risk analysis are first-class capabilities, not extensions of DLP rules.

Where to be careful: DLP vendors have long integration histories with HR, legal, and compliance workflows. AES is newer; some customers will want continuity with existing DLP policy frameworks.

vs. Doing nothing

Many customers haven't yet recognized agentic endpoint risk as its own category. The conversation isn't "Koi vs Competitor X" — it's "what do you currently do about AI tools running on endpoints with production access?" When the answer is silence, AES is the only purpose-built product that addresses the gap.

Services Fit

Optiv Alignment

Optiv's AI Security practice and Endpoint Security services align directly with AES deployments:

  • AI tool inventory and risk assessment — discover what's already installed, score risk, prioritize what to govern first.
  • Deployment-mode selection — guide customers between the in-agent path on XDR 5.2, standalone alongside a third-party EDR, and Prisma AIRS integration based on existing tooling and governance maturity.
  • Policy design — translate enterprise risk appetite into AES enforcement rules that don't kill developer productivity.
  • Integration with existing workflows — wire AES findings into XSIAM, ServiceNow, Jira, or whatever the customer already uses for incident and exception management.
  • Operational tuning — reduce false positives, refine baselines, and report on AI risk reduction over time.

Pre-Sales

Scoping Checklist

Data points to collect before quoting Agentic Endpoint Security (Koi AES).

XDR Agent Status — Is Cortex XDR already deployed, on which version, and is the agent at 9.3 or later? On XDR 5.2 AES is integral to the agent with zero additional deployment.
AI Agent Inventory — Which AI coding and autonomous agents are in use (for example Claude Code, Cursor) and on how many endpoints.
MCP Server Inventory — Count and ownership of MCP servers in use, whether self-hosted or third-party, and which production systems they can reach.
Plugin and Extension Inventory — Browser extensions and IDE/AI plugins in the estate, plus who currently approves them and by what process.
Endpoint Count in Scope — Developer and privileged-user endpoints first, then the wider estate. Drives per-endpoint sizing on the standalone route.
Deployment Mode — In-agent on Cortex XDR 5.2, standalone alongside a third-party EDR, or via Prisma AIRS 3.0. Capture the incumbent EDR if it is staying.
License Path — Current 5.x plans are Cortex XDR Pro EP and Cortex XDR EP Cloud on Enterprise Runtime Security (XDR) + Core Analytics. Note any legacy XDR 3.x contract that needs conversion.
Enforcement Appetite — Whether the customer wants monitoring only or real-time guardrails and blocking, and who signs off on blocking a developer tool.
Findings Destination — Where AES findings must land — Cortex XDR or XSIAM console, SIEM forwarder, ServiceNow or Jira for exception handling.
Governance Owner — Who owns AI-tool policy (security, platform engineering, or an AI governance board) and what approval workflow the rollout must respect.

Customer Conversation

Discovery Questions

Eight quick openers below. For the full set — nineteen questions with what you'll hear, how to read the answer, the response to give, and where each one lands in the portfolio — see AES Conversation Starters.

1

Which AI-driven developer tools is your team using today (Claude Code, Cursor, Copilot, internal agents)?

2

Do you have visibility into which browser extensions and MCP servers are installed across your developer endpoints?

3

If a malicious extension or compromised AI tool ran on a developer's machine today, how would you know?

4

What policies do you currently have for which AI agents can install software, access data, or call external services?

5

Are you running Cortex XDR today, and are you on 5.2 with agent 9.3 or later? If yes, AES is already in the agent with zero additional deployment. If not, the standalone product runs alongside your existing EDR.

6

Has your board or audit committee asked about agentic AI risk in the last quarter?

7

Are you considering Prisma AIRS 3.0 for AI model and runtime security? AES integrates as the endpoint side of that control plane.

8

What's your current process when a developer requests a new AI tool — and how long does it take?