Services · Threat Intel & Incident Response
Unit 42
Services
Palo Alto Networks' elite threat intelligence, incident response, and cyber risk practice — 200+ responders, 1,000+ engagements a year. Organised as Respond, Assess and Transform, now including Unit 42 Frontier AI Defense — expanded with Anthropic's Claude Mythos 5 on Aug 21, 2026 — and Unit 42 Threat Intelligence (launched Aug 3, 2026).
Emergency IR hotline (NA): 866.486.4842 (866.4.UNIT42) · unit42-investigations@paloaltonetworks.com — available 24/7/365.
Why Unit 42
The Services Layer That De-Risks the Platform
Customers buy the platform; Unit 42 makes sure it actually protects them. Attaching services is what makes premium platform pricing defensible — and it's the fastest, stickiest, recurring revenue in the portfolio.
How It's Organized
Three Service Families + The Retainer
Everything Unit 42 offers falls into Respond (reactive and managed), Assess (proactive), or Transform (advisory) — all fundable through one commercial anchor: the Retainer.
Retainer
The anchor. Credits flex between IR and proactive services. Easiest recurring attach.
Respond
Reactive IR, digital forensics, Cloud IR — plus managed: Unit 42 Managed XSIAM (MSIAM), Unit 42 MDR, Managed Threat Hunting.
Assess
Proactive Cyber Risk Management — compromise, ransomware readiness, cyber risk, purple teaming, pen test, tabletop.
Transform
Advisory — IR Plan development, Security Program Design, Virtual CISO, Zero Trust Advisory, Frontier AI Defense.
Complete Catalog · As of Today
Every Unit 42 Service
Each card includes what it is and a one-line "how to sell it" hook.
Retainer — the anchor vehicle
Unit 42 Retainer
Pre-purchased credits with pre-negotiated SLAs. Credits flex between reactive Incident Response and proactive Cyber Risk Management scoped during the term.
Respond — Incident Response & Digital Forensics
Incident Response
24/7 investigate, contain, eradicate, and remediate even the most advanced attacks, using Palo telemetry across endpoint, network, and cloud.
Digital Forensics (DFIR)
Litigation- and insurance-grade forensic investigation and evidence handling, delivered globally with Cortex XDR, Xpanse, and Prisma Cloud telemetry.
Ransomware Investigation
Contain, determine root cause and window of compromise, quantify exposure; if needed, negotiate, validate decryption keys, and drive recovery.
BEC Investigation
Respond to business email compromise: contain, root cause, window of compromise, attacker activity, and quantify data exposed.
Web App Compromise
Contain web-application attacks, analyze logs and code, quantify loss of sensitive data, and recommend design-hardening countermeasures.
Structured Data Investigation
Collection and analysis of SQL and NoSQL database environments, including external logs.
M&A Cyber Due Diligence
Identify hidden cybersecurity red flags and risks in the context of a merger or acquisition.
Respond — Managed Services
Unit 42 Managed XSIAM (MSIAM)
The flagship managed offering. Current release MSIAM 2.0 (Feb 17, 2026): 24/7 Palo-operated managed SOC on Cortex XSIAM, a 250-hour Breach Response Guarantee, and support for third-party EDR.
Unit 42 MDR (on Cortex XDR Pro)
24/7 detection and response built on Cortex XDR Pro across endpoint, identity, cloud, network, and SaaS (service description dated Jan 22, 2026). Still listed, but legacy-leaning versus Managed XSIAM.
Managed Threat Hunting (MTH)
Continuous proactive hunting to uncover attackers hiding in the environment, across Palo and third-party telemetry.
Cortex XMDR Specialization
The partner-delivered MDR route. Where the customer wants their MSSP or GSI to run the SOC, the partner delivers through the Cortex XMDR Specialization rather than Unit 42 delivering directly.
Cloud Incident Response
Incident response scoped to cloud environments — investigation and containment across cloud control planes and workloads.
Threat Intelligence — new, Aug 3, 2026
Unit 42 Threat Intelligence
Launched Aug 3, 2026 and delivered two ways: through Cortex XTI (Extended Threat Intelligence) — the Threat Intel Library plus AI-enabled intel that ships across XSIAM 3.6, XDR 5.2 and AgentiX 1.4 — and through Unit 42 Threat Intel Services.
Assess — Proactive Cyber Risk Management
Cyber Risk Assessment
Assess risks, identify gaps, and build a strategic improvement plan aligned to industry or regulatory frameworks (NIST CSF, CIS, ISO 27001).
Attack Surface Assessment
Identify external attack-surface risks and remediate issues before attackers can exploit them.
Ransomware Readiness Assessment
Control enhancements, remediation recommendations, and a best-practice playbook to reach a target ransomware-readiness state.
Breach Readiness Review
Assess people, processes, and technology to respond effectively, with a strategic roadmap to a target breach-readiness state.
BEC Readiness Assessment
Targeted assessment of controls and the people, processes, and technology needed to defend against BEC and other email-based attacks.
SOC Assessment
Measure defenses against evolving threats and improve SOC maturity.
Supply Chain Risk Assessment
Evaluate vendor-based supply-chain cybersecurity risk to identify and mitigate supply-chain attack threats.
Cloud Security Assessment
Assess cloud posture and controls against real-world cloud attack techniques.
AI Security Assessment
Empower secure GenAI adoption across employee usage and AI application development.
External AI Hyperattack Assessment
Externally-scoped assessment of exposure to AI-driven hyperattacks — attacker use of frontier AI against the customer's internet-facing estate.
Compromise Assessment
Determine whether an environment is currently or was previously compromised.
Penetration Testing
Stress-test cybersecurity controls using tactics, techniques, and procedures used by real threat actors.
Purple Team Exercises
Collaborate with Unit 42 to identify alerting gaps, tune defenses, and enhance security operations practices.
Tabletop Exercises
Simulate response to a severe incident with key stakeholders using customized, industry-specific scenarios based on real breaches.
Transform — Advisory & Program Build
Incident Response Plan Development
Advisory service building your team's readiness to prevent, detect, respond to, and recover from attacks.
Security Program Design
Design governance frameworks, operating models, and an InfoSec program roadmap — policies, control framework, and a defense-in-depth strategy.
Virtual CISO
Fractional senior security leadership — strategy, board reporting, and program ownership for organisations without a full-time CISO.
Zero Trust Advisory
Expert guidance on Zero Trust — from alignment and strategy to implementation and policy design.
Unit 42 Frontier AI Defense — new, April 2026
Exposure Analysis
First of the three Frontier AI Defense offers. Establishes where the organisation is exposed to frontier-AI-enabled attack and to its own AI and agentic footprint.
Autonomous Security Blueprint
Second offer. Designs the target-state autonomous SOC and AI security architecture for the customer.
Agentic Defense Transformation
Third and largest offer. Executes the transformation to agentic, AI-driven defense.
What comes with Frontier AI Defense: all three offers include 6 months free of Cortex XDR, Cortex Xpanse and Koi — the product hook that makes this the strongest land motion in the services catalog. Backed by the Frontier AI Alliance (13 global systems integrators) and an Armadin partnership for delivery capacity.
August 2026 update — Claude Mythos 5 is now inside Frontier AI Defense
On August 21, 2026, Unit 42 announced it is expanding Frontier AI Exposure Analysis with Anthropic's Claude Mythos 5 — putting a frontier cyber model behind the entry offer, guided and reviewed by Unit 42 offensive security experts. The engagement moves past "here are your findings" to answer three buyer questions: Is this exploitable? What can an attacker reach from here? What do we fix first? Unit 42 announcement (Sam Rubin).
What Frontier AI Defense now includes — the five published components
| Component | What it does | Use it in the room |
|---|---|---|
| Leading Cyber Models | Frontier AI applied to discovery, testing and validation — now including Claude Mythos 5. | The scarcity story: Mythos access is restricted to a small set of organisations. Very few providers can put this class of model on a customer's estate. |
| Multi-Model Harness | Dynamic routing to the model best suited to each task — stronger results, wider coverage, managed cost. | Answers "aren't you locked to one AI vendor?" — the harness absorbs new frontier models as they ship. |
| Exposure Discovery | Vulnerabilities, misconfigurations, exposed credentials and unmanaged attack surface across applications and networks. | Pairs with Cortex Xpanse in the 6-months-free bundle — discovery findings justify keeping Xpanse after the trial. |
| Advanced Adversary Simulation | Live exploitability testing and end-to-end attack path validation. | This is what differentiates it from a scan or a standard pen test — validated paths, not a finding count. |
| Custom Remediation Plans | Prioritised fixes delivered into existing IT, development and security workflows. | The follow-on hook into Autonomous Security Blueprint and Agentic Defense Transformation. |
Scope spans applications, identity, cloud and infrastructure as one connected attack surface. Model output is combined with global Palo Alto Networks telemetry and Unit 42 Threat Intelligence. No public pricing or GA date has been published — scope through your Unit 42 lead.
Frontier AI Critical Defense Program
A coordination program pairing AI labs, software makers and OT vendors to protect critical infrastructure from vulnerabilities AI models now find faster than operators can patch. Existing collaborators are IBM, Red Hat (Lightwell), Microsoft (MAPP), Siemens and Idaho National Laboratory (OT Threat Research Lab); new participants are Anthropic, OpenAI, Mitsubishi Electric, Axis Communications, the Analysis and Resilience Center for Systemic Risk, Health-ISAC, EPRI and Akrites (Linux Foundation). Three pillars: embargoed vulnerability exchange, conversion into network-level protections, and anonymized exploitation telemetry back to vendors.
Unit 42 NOVA research numbers
Unit 42's autonomous discovery system NOVA found 14,090 confirmed vulnerabilities across 3,915 open-source projects in two months — 99.4% previously unreported, roughly 40% high or critical (39.7% CVSS 4.0), across six language ecosystems, with 5,421 supply-chain findings and 2,776 downstream exposures validated with working proof-of-concept exploits.
Frontier Virtual Patching (PAN-OS 12.2 Ceres)
Launched August 4, 2026. Uses frontier AI to find unknown vulnerabilities and push protections in hours, compressing the industry-average 55-day patch deployment window to near zero — no patch, reboot or downtime. Delivered as a PAN-OS software upgrade with automatic content updates, no new hardware.
Partner-architect note — read this before you position it
Frontier AI Defense is a Palo Alto Networks-delivered Unit 42 service, not an Authorized Professional Services motion. In accounts where a partner already owns pen testing, red teaming or CTEM delivery, it overlaps their scope. Position it as the frontier-model layer above partner-delivered testing — Unit 42 validates exploitable paths at machine speed, the partner owns remediation execution and ongoing operations. Delivery capacity is backed by the Frontier AI Alliance (13 global SIs) and the Armadin partnership, which is the route to a joint-delivery conversation.
Sources: Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic's Mythos 5 (Aug 21, 2026) · Redefining Network Security for the Frontier AI Era (Aug 4, 2026) · Frontier AI Critical Defense Program coverage (Aug 19, 2026) · Axios on PANW Mythos early access (May 13, 2026) · Anthropic Claude Mythos status.
Seller Playbook
How to Sell Unit 42 Services
Why it has value, when to lead with it, and the attach sequence that turns one small "yes" into a services annuity.
The value story (say this)
"Palo is priced for the platform — and the platform only pays off if it's operated and defended. A Unit 42 Retainer proves that: IR SLAs baked in, plus proactive credits to harden posture before an incident." This reframes premium platform price from an objection into a justification, and positions services as the adoption insurance the economic buyer actually wants.
The attach ladder
Lead with the Retainer
At the point of any Cortex/Strata deal. Small, recurring, low-friction — the easiest "yes" and the anchor for everything else.
Burn credits into an Assessment
A Cyber Risk, Compromise, or Ransomware Readiness assessment surfaces concrete gaps — unrun platform, detection holes, skills shortfalls.
Findings justify delivery services
Those gaps become the case for deployment, tuning, and day-to-day operations — the operate-the-platform work.
Expand at renewal
Move to Unit 42 Managed XSIAM (MSIAM 2.0) or Managed Threat Hunting, and attach Koi AES as the net-new bundle add-on. Where the partner operates the SOC, route it through the Cortex XMDR Specialization.
Who buys what
| Buyer | Cares about | Lead with |
|---|---|---|
| CISO | Board-ready risk posture, breach readiness, cyber-insurance | Cyber Risk Assessment, Breach Readiness, Retainer |
| SOC / Security Ops lead | Alert fatigue, coverage, staffing gaps | Unit 42 Managed XSIAM (MSIAM 2.0), Managed Threat Hunting, SOC Assessment |
| Incident / crisis owner | Fast response, forensic depth, recovery | Retainer, IR/DFIR, Tabletop |
| Compliance / risk | Framework alignment, audits, pen-test mandates | Penetration Testing, Supply Chain, Cyber Risk Assessment |
| Cloud / platform team | Cloud posture, AI/GenAI adoption | Cloud Security Assessment, AI Security Assessment, Frontier AI Defense |
Discovery questions
- If you had a serious incident tomorrow, who responds in the first hour — and do you have a retainer with pre-negotiated SLAs?
- When did you last validate your controls against real-world attack techniques (pen test, purple team, tabletop)?
- Are you being measured against a framework — NIST CSF, CIS, ISO 27001 — or an audit deliverable?
- Do you have the staff to operate the security platform you've invested in, 24/7?
- Does your cyber-insurance policy require ransomware readiness or IR retainer evidence?
- Which Cortex products are deployed today (Cortex XDR 5.2, XSIAM 3.6)? That determines Managed XSIAM vs Unit 42 MDR fit, and whether third-party EDR support is needed.
- Any recent breach, near-miss, or compliance finding driving urgency right now?
Objection handling
Deal Economics
Unit 42 Multiplies the Deal
Services aren't a side item — they change the size, stickiness, and win-rate of the whole opportunity.
Counts as a product family
Unit 42 is one of the four eligible families (Firewall, Unit 42, Prisma SASE, Cortex) — every attach earns incentive points and feeds the Cross-Selling Bonus. See Deal Playbook.
Recurring & sticky
Retainers and managed services are subscription revenue that renews — the annuity that anchors the account year over year.
Raises platform win-rate
Services de-risk the customer's platform bet, reducing "no-decision" losses and making premium pricing defensible.
Get named on the deal reg early. Services attach at the point of the platform sale, not after. Bring Unit 42 into discovery so it's part of the deal architecture — and so the incentive credit lands. See the Partner Architects page for how to engage.
Pre-Sales
Scoping Checklist
Data points to collect before scoping and quoting a Unit 42 services engagement.