Services · Threat Intel & Incident Response

Unit 42
Services

Palo Alto Networks' elite threat intelligence, incident response, and cyber risk practice — 200+ responders, 1,000+ engagements a year. Organised as Respond, Assess and Transform, now including Unit 42 Frontier AI Defense — expanded with Anthropic's Claude Mythos 5 on Aug 21, 2026 — and Unit 42 Threat Intelligence (launched Aug 3, 2026).

Emergency IR hotline (NA): 866.486.4842 (866.4.UNIT42) · unit42-investigations@paloaltonetworks.com — available 24/7/365.

Why Unit 42

The Services Layer That De-Risks the Platform

Customers buy the platform; Unit 42 makes sure it actually protects them. Attaching services is what makes premium platform pricing defensible — and it's the fastest, stickiest, recurring revenue in the portfolio.

200+
Threat responders & consultants
1,000+
IR engagements / year
24/7
Global response coverage
30M+
Malware samples analyzed daily

How It's Organized

Three Service Families + The Retainer

Everything Unit 42 offers falls into Respond (reactive and managed), Assess (proactive), or Transform (advisory) — all fundable through one commercial anchor: the Retainer.

Retainer

The anchor. Credits flex between IR and proactive services. Easiest recurring attach.

Respond

Reactive IR, digital forensics, Cloud IR — plus managed: Unit 42 Managed XSIAM (MSIAM), Unit 42 MDR, Managed Threat Hunting.

Assess

Proactive Cyber Risk Management — compromise, ransomware readiness, cyber risk, purple teaming, pen test, tabletop.

Transform

Advisory — IR Plan development, Security Program Design, Virtual CISO, Zero Trust Advisory, Frontier AI Defense.

Complete Catalog · As of Today

Every Unit 42 Service

Each card includes what it is and a one-line "how to sell it" hook.

Retainer — the anchor vehicle

Anchor

Unit 42 Retainer

Pre-purchased credits with pre-negotiated SLAs. Credits flex between reactive Incident Response and proactive Cyber Risk Management scoped during the term.

Sell it: The easiest recurring "yes." It locks IR SLAs, gives the customer peace of mind, and funds the assessments that open every follow-on service.

Respond — Incident Response & Digital Forensics

Reactive

Incident Response

24/7 investigate, contain, eradicate, and remediate even the most advanced attacks, using Palo telemetry across endpoint, network, and cloud.

Sell it: "Who responds in the first hour if you're hit tomorrow?" Position via the Retainer for faster SLAs.
Reactive

Digital Forensics (DFIR)

Litigation- and insurance-grade forensic investigation and evidence handling, delivered globally with Cortex XDR, Xpanse, and Prisma Cloud telemetry.

Sell it: Essential where legal, cyber insurance, or regulators are involved.
Reactive

Ransomware Investigation

Contain, determine root cause and window of compromise, quantify exposure; if needed, negotiate, validate decryption keys, and drive recovery.

Sell it: The nightmare scenario every exec fears — the highest-urgency trigger.
Reactive

BEC Investigation

Respond to business email compromise: contain, root cause, window of compromise, attacker activity, and quantify data exposed.

Sell it: The most common incident type — broadly relatable to any customer.
Reactive

Web App Compromise

Contain web-application attacks, analyze logs and code, quantify loss of sensitive data, and recommend design-hardening countermeasures.

Sell it: Pairs with app-heavy / e-commerce accounts.
Reactive

Structured Data Investigation

Collection and analysis of SQL and NoSQL database environments, including external logs.

Sell it: For data-breach scoping where DB exposure is in question.
Reactive

M&A Cyber Due Diligence

Identify hidden cybersecurity red flags and risks in the context of a merger or acquisition.

Sell it: Target corp-dev and PE-backed accounts; ties to deal timelines.

Respond — Managed Services

Managed · Flagship

Unit 42 Managed XSIAM (MSIAM)

The flagship managed offering. Current release MSIAM 2.0 (Feb 17, 2026): 24/7 Palo-operated managed SOC on Cortex XSIAM, a 250-hour Breach Response Guarantee, and support for third-party EDR.

Sell it: The premium managed tier and the correct name to use — "Cortex Pro (MDR)" is not a Palo Alto brand. Third-party EDR support means the customer does not have to rip out their existing endpoint agent first.
Managed · Legacy-leaning

Unit 42 MDR (on Cortex XDR Pro)

24/7 detection and response built on Cortex XDR Pro across endpoint, identity, cloud, network, and SaaS (service description dated Jan 22, 2026). Still listed, but legacy-leaning versus Managed XSIAM.

Sell it: The fit where the customer is staying on Cortex XDR Pro rather than moving to XSIAM. Otherwise lead with Managed XSIAM.
Managed

Managed Threat Hunting (MTH)

Continuous proactive hunting to uncover attackers hiding in the environment, across Palo and third-party telemetry.

Sell it: Upsell for customers who want proactive hunting beyond automated detection.
Managed · Partner-delivered

Cortex XMDR Specialization

The partner-delivered MDR route. Where the customer wants their MSSP or GSI to run the SOC, the partner delivers through the Cortex XMDR Specialization rather than Unit 42 delivering directly.

Sell it: Use it to keep an incumbent-MSSP account winnable — the platform still lands, the partner operates it.
Reactive

Cloud Incident Response

Incident response scoped to cloud environments — investigation and containment across cloud control planes and workloads.

Sell it: Attach wherever the crown-jewel workloads are already in AWS, Azure, or GCP.

Threat Intelligence — new, Aug 3, 2026

New · Aug 3, 2026

Unit 42 Threat Intelligence

Launched Aug 3, 2026 and delivered two ways: through Cortex XTI (Extended Threat Intelligence) — the Threat Intel Library plus AI-enabled intel that ships across XSIAM 3.6, XDR 5.2 and AgentiX 1.4 — and through Unit 42 Threat Intel Services.

Sell it: Three days old and the newest thing on the board. Product-plus-service: XTI is the licensed module, Threat Intel Services is the human layer on top.

Assess — Proactive Cyber Risk Management

Proactive

Cyber Risk Assessment

Assess risks, identify gaps, and build a strategic improvement plan aligned to industry or regulatory frameworks (NIST CSF, CIS, ISO 27001).

Sell it: The classic land-and-expand — findings justify every follow-on service.
Proactive

Attack Surface Assessment

Identify external attack-surface risks and remediate issues before attackers can exploit them.

Sell it: Great discovery hook — shows unknown internet-exposed assets; pairs with Xpanse.
Proactive

Ransomware Readiness Assessment

Control enhancements, remediation recommendations, and a best-practice playbook to reach a target ransomware-readiness state.

Sell it: Board-level topic; ties to cyber-insurance requirements.
Proactive

Breach Readiness Review

Assess people, processes, and technology to respond effectively, with a strategic roadmap to a target breach-readiness state.

Sell it: Frames a multi-service roadmap in one engagement.
Proactive

BEC Readiness Assessment

Targeted assessment of controls and the people, processes, and technology needed to defend against BEC and other email-based attacks.

Sell it: Follow-up to any BEC incident; broadly relevant.
Proactive

SOC Assessment

Measure defenses against evolving threats and improve SOC maturity.

Sell it: Pairs with an XSIAM SOC-transformation motion.
Proactive

Supply Chain Risk Assessment

Evaluate vendor-based supply-chain cybersecurity risk to identify and mitigate supply-chain attack threats.

Sell it: Timely for regulated and manufacturing verticals.
Proactive

Cloud Security Assessment

Assess cloud posture and controls against real-world cloud attack techniques.

Sell it: Attach to any Cortex Cloud / Prisma Cloud opportunity.
Proactive

AI Security Assessment

Empower secure GenAI adoption across employee usage and AI application development.

Sell it: Rides the AI wave; pairs with Prisma AIRS 3.0 and Koi AES.
Proactive · New 2026

External AI Hyperattack Assessment

Externally-scoped assessment of exposure to AI-driven hyperattacks — attacker use of frontier AI against the customer's internet-facing estate.

Sell it: The sharpest opener for the "what does AI change for us" board question; feeds straight into Frontier AI Defense.
Proactive

Compromise Assessment

Determine whether an environment is currently or was previously compromised.

Sell it: Low-friction entry point that often uncovers real findings.
Proactive

Penetration Testing

Stress-test cybersecurity controls using tactics, techniques, and procedures used by real threat actors.

Sell it: Recurring annual need; often compliance-driven.
Proactive

Purple Team Exercises

Collaborate with Unit 42 to identify alerting gaps, tune defenses, and enhance security operations practices.

Sell it: Upsell for mature SOCs; validates detection efficacy.
Proactive

Tabletop Exercises

Simulate response to a severe incident with key stakeholders using customized, industry-specific scenarios based on real breaches.

Sell it: Executive-friendly; a common first proactive engagement.

Transform — Advisory & Program Build

Transform

Incident Response Plan Development

Advisory service building your team's readiness to prevent, detect, respond to, and recover from attacks.

Sell it: Natural companion to a Retainer or tabletop.
Transform

Security Program Design

Design governance frameworks, operating models, and an InfoSec program roadmap — policies, control framework, and a defense-in-depth strategy.

Sell it: Program-level advisory for maturing security orgs.
Transform

Virtual CISO

Fractional senior security leadership — strategy, board reporting, and program ownership for organisations without a full-time CISO.

Sell it: Keeps Unit 42 in the account between projects and shapes the next year of spend.
Transform

Zero Trust Advisory

Expert guidance on Zero Trust — from alignment and strategy to implementation and policy design.

Sell it: Strategic advisory that pulls through platform architecture.

Unit 42 Frontier AI Defense — new, April 2026

New · Apr 2026

Exposure Analysis

First of the three Frontier AI Defense offers. Establishes where the organisation is exposed to frontier-AI-enabled attack and to its own AI and agentic footprint.

Sell it: The entry offer — smallest scope, fastest to close, and it sizes the other two.
New · Apr 2026

Autonomous Security Blueprint

Second offer. Designs the target-state autonomous SOC and AI security architecture for the customer.

Sell it: The bridge from assessment findings to an XSIAM/AgentiX platform decision.
New · Apr 2026

Agentic Defense Transformation

Third and largest offer. Executes the transformation to agentic, AI-driven defense.

Sell it: The multi-quarter transformation engagement — the largest services footprint in the portfolio.

What comes with Frontier AI Defense: all three offers include 6 months free of Cortex XDR, Cortex Xpanse and Koi — the product hook that makes this the strongest land motion in the services catalog. Backed by the Frontier AI Alliance (13 global systems integrators) and an Armadin partnership for delivery capacity.

August 2026 update — Claude Mythos 5 is now inside Frontier AI Defense

On August 21, 2026, Unit 42 announced it is expanding Frontier AI Exposure Analysis with Anthropic's Claude Mythos 5 — putting a frontier cyber model behind the entry offer, guided and reviewed by Unit 42 offensive security experts. The engagement moves past "here are your findings" to answer three buyer questions: Is this exploitable? What can an attacker reach from here? What do we fix first? Unit 42 announcement (Sam Rubin).

What Frontier AI Defense now includes — the five published components

ComponentWhat it doesUse it in the room
Leading Cyber ModelsFrontier AI applied to discovery, testing and validation — now including Claude Mythos 5.The scarcity story: Mythos access is restricted to a small set of organisations. Very few providers can put this class of model on a customer's estate.
Multi-Model HarnessDynamic routing to the model best suited to each task — stronger results, wider coverage, managed cost.Answers "aren't you locked to one AI vendor?" — the harness absorbs new frontier models as they ship.
Exposure DiscoveryVulnerabilities, misconfigurations, exposed credentials and unmanaged attack surface across applications and networks.Pairs with Cortex Xpanse in the 6-months-free bundle — discovery findings justify keeping Xpanse after the trial.
Advanced Adversary SimulationLive exploitability testing and end-to-end attack path validation.This is what differentiates it from a scan or a standard pen test — validated paths, not a finding count.
Custom Remediation PlansPrioritised fixes delivered into existing IT, development and security workflows.The follow-on hook into Autonomous Security Blueprint and Agentic Defense Transformation.

Scope spans applications, identity, cloud and infrastructure as one connected attack surface. Model output is combined with global Palo Alto Networks telemetry and Unit 42 Threat Intelligence. No public pricing or GA date has been published — scope through your Unit 42 lead.

New · Aug 19, 2026

Frontier AI Critical Defense Program

A coordination program pairing AI labs, software makers and OT vendors to protect critical infrastructure from vulnerabilities AI models now find faster than operators can patch. Existing collaborators are IBM, Red Hat (Lightwell), Microsoft (MAPP), Siemens and Idaho National Laboratory (OT Threat Research Lab); new participants are Anthropic, OpenAI, Mitsubishi Electric, Axis Communications, the Analysis and Resilience Center for Systemic Risk, Health-ISAC, EPRI and Akrites (Linux Foundation). Three pillars: embargoed vulnerability exchange, conversion into network-level protections, and anonymized exploitation telemetry back to vendors.

Sell it: Not a paid service — use it as the credibility layer for OT, energy, healthcare and manufacturing accounts. Protections are already flowing to joint customers, and collaborator applications are open.
Proof point · Aug 2026

Unit 42 NOVA research numbers

Unit 42's autonomous discovery system NOVA found 14,090 confirmed vulnerabilities across 3,915 open-source projects in two months — 99.4% previously unreported, roughly 40% high or critical (39.7% CVSS 4.0), across six language ecosystems, with 5,421 supply-chain findings and 2,776 downstream exposures validated with working proof-of-concept exploits.

Sell it: The single strongest stat to open the "what does frontier AI change for us" conversation. It proves the exposure window is real before you quote a single service.
Context · Product side

Frontier Virtual Patching (PAN-OS 12.2 Ceres)

Launched August 4, 2026. Uses frontier AI to find unknown vulnerabilities and push protections in hours, compressing the industry-average 55-day patch deployment window to near zero — no patch, reboot or downtime. Delivered as a PAN-OS software upgrade with automatic content updates, no new hardware.

Sell it: The product half of the same story. Services find and validate the path; Frontier Virtual Patching buys air cover while the customer works its patch cycle. Lead the two together.

Partner-architect note — read this before you position it

Frontier AI Defense is a Palo Alto Networks-delivered Unit 42 service, not an Authorized Professional Services motion. In accounts where a partner already owns pen testing, red teaming or CTEM delivery, it overlaps their scope. Position it as the frontier-model layer above partner-delivered testing — Unit 42 validates exploitable paths at machine speed, the partner owns remediation execution and ongoing operations. Delivery capacity is backed by the Frontier AI Alliance (13 global SIs) and the Armadin partnership, which is the route to a joint-delivery conversation.

PANW-delivered Not APS Frontier AI Alliance delivery No public pricing

Sources: Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic's Mythos 5 (Aug 21, 2026) · Redefining Network Security for the Frontier AI Era (Aug 4, 2026) · Frontier AI Critical Defense Program coverage (Aug 19, 2026) · Axios on PANW Mythos early access (May 13, 2026) · Anthropic Claude Mythos status.

Seller Playbook

How to Sell Unit 42 Services

Why it has value, when to lead with it, and the attach sequence that turns one small "yes" into a services annuity.

The value story (say this)

"Palo is priced for the platform — and the platform only pays off if it's operated and defended. A Unit 42 Retainer proves that: IR SLAs baked in, plus proactive credits to harden posture before an incident." This reframes premium platform price from an objection into a justification, and positions services as the adoption insurance the economic buyer actually wants.

The attach ladder

1

Lead with the Retainer

At the point of any Cortex/Strata deal. Small, recurring, low-friction — the easiest "yes" and the anchor for everything else.

2

Burn credits into an Assessment

A Cyber Risk, Compromise, or Ransomware Readiness assessment surfaces concrete gaps — unrun platform, detection holes, skills shortfalls.

3

Findings justify delivery services

Those gaps become the case for deployment, tuning, and day-to-day operations — the operate-the-platform work.

4

Expand at renewal

Move to Unit 42 Managed XSIAM (MSIAM 2.0) or Managed Threat Hunting, and attach Koi AES as the net-new bundle add-on. Where the partner operates the SOC, route it through the Cortex XMDR Specialization.

Who buys what

BuyerCares aboutLead with
CISOBoard-ready risk posture, breach readiness, cyber-insuranceCyber Risk Assessment, Breach Readiness, Retainer
SOC / Security Ops leadAlert fatigue, coverage, staffing gapsUnit 42 Managed XSIAM (MSIAM 2.0), Managed Threat Hunting, SOC Assessment
Incident / crisis ownerFast response, forensic depth, recoveryRetainer, IR/DFIR, Tabletop
Compliance / riskFramework alignment, audits, pen-test mandatesPenetration Testing, Supply Chain, Cyber Risk Assessment
Cloud / platform teamCloud posture, AI/GenAI adoptionCloud Security Assessment, AI Security Assessment, Frontier AI Defense

Discovery questions

  • If you had a serious incident tomorrow, who responds in the first hour — and do you have a retainer with pre-negotiated SLAs?
  • When did you last validate your controls against real-world attack techniques (pen test, purple team, tabletop)?
  • Are you being measured against a framework — NIST CSF, CIS, ISO 27001 — or an audit deliverable?
  • Do you have the staff to operate the security platform you've invested in, 24/7?
  • Does your cyber-insurance policy require ransomware readiness or IR retainer evidence?
  • Which Cortex products are deployed today (Cortex XDR 5.2, XSIAM 3.6)? That determines Managed XSIAM vs Unit 42 MDR fit, and whether third-party EDR support is needed.
  • Any recent breach, near-miss, or compliance finding driving urgency right now?

Objection handling

"We already have an MSSP / IR provider."
Unit 42 is built on the same Palo telemetry the customer already owns (Cortex XSIAM, Cortex XDR, Xpanse), so response is faster and better-informed, and Managed XSIAM supports third-party EDR. A Retainer can coexist — many customers keep it as their escalation tier of last resort. If the MSSP relationship is untouchable, keep the platform and route delivery through the partner-led Cortex XMDR Specialization.
"It's too expensive."
Reframe around the cost of an unoperated platform and a slow breach response. The Retainer is a small, fixed commitment whose credits are usable proactively — it's insurance that also improves posture, not sunk cost.
"We'll deal with incidents if/when they happen."
Response time is everything — retainer customers get pre-negotiated SLAs and faster containment. Without one, hour zero is spent on paperwork and scoping instead of stopping the attacker.
"We don't have budget for services this cycle."
Start with the smallest Retainer to lock SLAs, then use its credits for a proactive assessment later in the term. It gets services into the deal without a large net-new line item.

Deal Economics

Unit 42 Multiplies the Deal

Services aren't a side item — they change the size, stickiness, and win-rate of the whole opportunity.

Counts as a product family

Unit 42 is one of the four eligible families (Firewall, Unit 42, Prisma SASE, Cortex) — every attach earns incentive points and feeds the Cross-Selling Bonus. See Deal Playbook.

Recurring & sticky

Retainers and managed services are subscription revenue that renews — the annuity that anchors the account year over year.

Raises platform win-rate

Services de-risk the customer's platform bet, reducing "no-decision" losses and making premium pricing defensible.

Get named on the deal reg early. Services attach at the point of the platform sale, not after. Bring Unit 42 into discovery so it's part of the deal architecture — and so the incentive credit lands. See the Partner Architects page for how to engage.

Pre-Sales

Scoping Checklist

Data points to collect before scoping and quoting a Unit 42 services engagement.

Incident History and Current Retainer — Number and severity of incidents in the last 24 months, current IR provider or MSSP by name, and the retainer end date
Retainer Hour Bank Sizing — Target credit/hour bank for the term, and the expected reactive vs proactive split, since credits flex between Incident Response and Cyber Risk Management
IR Readiness and Plan Maturity — Whether a documented IR plan exists, date last tested, and whether a tabletop or IR Plan Development engagement is needed
Environment Scope for Assessments — Endpoint count, user count, cloud accounts/subscriptions, external IP ranges and domains, and number of business units in scope
Managed XSIAM vs Unit 42 MDR — Which Cortex platform is deployed: XSIAM 3.6 points to Unit 42 Managed XSIAM (MSIAM 2.0); a Cortex XDR Pro estate staying on XDR points to Unit 42 MDR
Third-Party EDR in Scope — Named incumbent EDR and its endpoint count. Managed XSIAM supports third-party EDR, so confirm whether it stays in place for the first term
Shift Coverage and Response SLAs — Required coverage model (24/7, follow-the-sun, business-hours-plus), target response and containment SLAs, and escalation contacts per region
Breach Response Guarantee Eligibility — Whether the customer qualifies for the 250-hour Breach Response Guarantee under Managed XSIAM, and which onboarding and telemetry prerequisites are outstanding
AI and Agentic Footprint — Count of AI models, agents, MCP servers and AI applications in use, for Unit 42 Frontier AI Defense scoping and the External AI Hyperattack Assessment
Delivery Model — Partner vs Palo — Whether the customer wants Unit 42 delivering directly or a partner delivering via the Cortex XMDR Specialization; name the partner and confirm the specialization status