SecOps · Technical Reference

Cortex XDR —
How It Works

A technical seller's guide to prevention architecture, detection engines, automation, licensing, add-ons, and how it all connects to XSIAM. Current releases: Cortex XDR 5.2 (July 20, 2026), XDR agent 9.3 (July 26, 2026), Cortex XSIAM 3.6 (July 20, 2026).

XDR 5.2
Current Release · Agent 9.3
2,600+
AI Models Built-In
100%
MITRE ATT&CK
85%+
Auto-Resolved (XSIAM)

Agent Architecture

The Cortex XDR Agent — How Prevention Actually Works

The XDR agent is not a scanner. It's a kernel-resident behavioral enforcement engine that hooks into the OS before any user-space process can act. Here's the full technical stack. Current agent release is 9.3 (July 26, 2026), and with XDR 5.2 Agentic Endpoint Security (AES) is an integral part of that agent — zero additional deployment.

Kernel-Level Driver
The agent installs a kernel module that intercepts system calls, network connections, process creation, file system operations, and registry changes at the OS level — before any user-space process can act. This isn't signature scanning — it's behavioral hooking at the lowest level of the OS. Operates below AV and EDR evasion techniques that target user-space.
Local Analysis Engine
On-device ML model that scores every process, file, and network connection in real time without cloud dependency. Works offline. Trained on billions of samples across the global PANW customer base. Makes a prevention/allow decision in milliseconds before execution — no WildFire round-trip needed for known verdicts.
WildFire Integration
Unknown files are submitted to the WildFire cloud sandbox for dynamic analysis. WildFire executes the file in an instrumented virtual environment across multiple OS profiles and returns a verdict (benign/malware/grayware) in seconds. Once a verdict is returned, it's shared across all 70,000+ PANW customers globally — instantly hardening every deployment.
Behavioral Threat Protection (BTP)
Post-execution behavioral engine that monitors running processes for attack patterns — lateral movement, credential dumping, privilege escalation, process injection, and ransomware behaviors. Doesn't need a signature to catch novel malware; it catches the behavior. BTP fires kernel hooks the moment a running process deviates from baseline-expected behavior.
Anti-Exploit Module
Monitors memory for exploitation techniques — buffer overflows, heap spray, return-oriented programming (ROP) chains, and process hollowing. Can terminate a process mid-exploit chain before shellcode executes. Defends against zero-days at the memory level without requiring a signature for the specific CVE. This is the primary defense layer against browser, Office, and PDF exploits.
Network Protection
Blocks outbound connections to C2 infrastructure using DNS sinkholing, IP reputation feeds, and behavioral network anomaly detection. Even encrypted C2 traffic is detected via network traffic analysis (NTA) behavioral fingerprinting — the agent identifies the pattern, not the payload. Works on-device, so protection follows the endpoint off-network.

Prevention Flow

From File Arrival to Forensics — The 5-Step Chain

Walk a prospect through exactly what happens when a suspicious file lands on an endpoint. Every step is a defense layer. Multiple must fail simultaneously for a breach to succeed.

1
Pre-Execution — Local Analysis Engine Fires
File arrives on the endpoint. Before a single byte executes, the Local Analysis Engine scores the file using an on-device ML model. Score above threshold → blocked before launch. No cloud round-trip needed. Works air-gapped, offline, and under network restriction. This single layer stops ~99% of commodity malware — signature-free.
2
Static Analysis — Hash Lookup Against Known-Bad Database
Local Analysis runs a hash lookup against the known-bad database synchronized from WildFire. If the hash is known malware: instant block, zero latency. If the hash is unknown and Local Analysis scored it below the block threshold: proceed to WildFire. This creates a second independent gate before any execution is allowed.
3
WildFire Submission — Dynamic Sandboxing in Isolated VM
Unknown file is submitted to WildFire cloud sandbox. WildFire executes the file in an instrumented virtual environment across multiple OS profiles, observes all behavior, and returns a verdict. If malicious → block immediately + verdict shared globally across all PANW customers. The same threat is now blocked everywhere within seconds of first discovery anywhere in the world.
4
Execution Allowed — BTP Kernel Hooks Monitor in Real Time
Process is allowed to start. Behavioral Threat Protection (BTP) kernel hooks are now watching every action the process takes. Lateral movement attempt, credential dump call, process injection, ransomware file-write pattern detected → process terminated instantly, alert raised. No signature needed. The behavior is the indicator.
5
Post-Execution Forensics — Causality Analysis Engine Builds the Story
If anything suspicious happened at any layer, the Causality Analysis Engine (CAE) traces the full attack story — root cause process, every child process spawned, all network connections made, every file written, every registry key touched. The analyst sees one incident with complete context: not a list of signals, but a connected narrative of how the attack unfolded. This is what eliminates the 3-hour manual investigation.

Detection Layer

Detection Engines — What Runs After Prevention

Prevention catches known and near-known threats. These four engines handle everything that requires deeper analysis — behavioral correlation, ML-driven anomaly detection, and analyst-driven hunting.

Causality Analysis Engine (CAE)
PAN's proprietary correlation engine. Stitches together events across endpoint, network, and identity into a "causality chain" — the full story of how an attack unfolded. Eliminates thousands of individual alerts; an analyst sees one incident with complete context. No manual pivoting between tools. Alert fatigue is eliminated at the architecture level, not through tuning.
Behavioral Indicators of Compromise (BIOCs)
Custom and built-in behavioral rules that detect attack patterns across the entire data lake — not just endpoint. Write XQL-based rules against any telemetry source. 2,600+ built-in BIOCs ship out of the box covering MITRE ATT&CK techniques. Sellers can show this number against CrowdStrike's IOC count to anchor the conversation on detection breadth.
ML Models (2,600+)
Supervised and unsupervised ML models running against the full data corpus. Anomaly detection for user behavior (UEBA), network traffic baselines, and cloud activity. No tuning required to reach detection-quality output — models are pre-trained against the global PANW customer dataset and continuously updated. Zero-day detection capability without analyst rule authorship.
XQL Query Language
Analyst-facing query language for threat hunting across all data sources in the Cortex Data Lake. Syntax is SQL-like with security-specific functions for process trees, network flows, and file operations. Faster and simpler than SPL (Splunk) or KQL (Microsoft Sentinel) for cross-domain investigation. Hunt across endpoint, network, cloud, and identity in a single query pane.

Licensing Architecture

The Five License Tiers — Complete Technical Breakdown

XDR is not a single product — it's a tiered architecture. Each tier unlocks a new layer of capability without redeployment. This is the upsell ladder every seller should memorize.

Legacy packaging — read before quoting. The four XDR tiers below (Prevent · Pro per Endpoint · Pro per GB · Cloud per Host) are legacy XDR 3.x tiering. They remain accurate for the installed base and for renewals, which is why the detail is kept here. On XDR 5.x the license plans are Cortex XDR Pro EP (on-premises endpoints) and Cortex XDR EP Cloud (cloud and containers), both on an Enterprise Runtime Security (XDR) + Core Analytics base with the same add-on catalog as XSIAM. “Pro per GB” is superseded by the XSIAM NG-SIEM data-tier model. New business: quote Pro EP or EP Cloud, not the four legacy tiers. There is no end-of-sale for Cortex XDR.
Capability Prevent Pro / Endpoint Pro / GB Cloud / Host XSIAM
Cortex XDR Agent Full Full Full Cloud-Opt Full
Prevention (Local ML)
Anti-Exploit Module
Behavioral Threat Protection
EDR Investigation UI Partial
XTH Data (30-day Retention) 30 Days 30 Days+ 1 Year+
UEBA / Behavioral Analytics Endpoint Full AI-Scale
3rd-Party Data Ingestion Unlimited Unlimited
Network Analytics
Identity Analytics
Forensics Add-On Eligible Limited Included
XSIAM Upgrade Path License License Direct Path Add XSIAM Native
Cortex XDR Prevent
Tier 1
Per endpoint / year · Entry-level EPP · Prevention only
What it is: EPP-tier endpoint protection. Prevention-only. No investigation, no EDR telemetry, no hunting. Same agent binary as Pro — license key determines what's activated.
  • Full Cortex XDR agent (Local Analysis, WildFire, Anti-Exploit, BTP, Network Protection)
  • AI-powered malware prevention + behavioral protection
  • Anti-exploit memory defense (zero-day coverage)
  • Network C2 blocking (DNS sinkholing + IP reputation)
  • WildFire cloud sandbox integration
  • Device control + host firewall
  • No EDR investigation UI or causality chains
  • No XQL threat hunting capability
  • No XTH data retention (no going back in time)
  • No UEBA or incident management
Organizations that need strong prevention at the lowest cost. Pure EPP replacement for CrowdStrike Falcon Go/Prevent or SentinelOne Core. Use as a land motion — upsell to Pro when the customer's first alert requires investigation.
Cortex XDR Pro per GB
SIEM Displacement
Per GB ingested / day · Data ingestion license · XDR-as-SIEM
What it is: The data ingestion license. Extends the XDR platform to ingest ANY log source — network, cloud, identity, third-party. This is what turns XDR into a SIEM alternative.
  • NGFW logs (Palo Alto Networks — zero configuration)
  • Prisma Access (SASE) logs
  • Cloud logs: AWS CloudTrail, Azure Activity, GCP Audit
  • DNS, proxy, and identity logs (AD, Okta)
  • Third-party EDR data (CrowdStrike, SentinelOne)
  • Custom log sources via API / Syslog
Pro per Endpoint + Pro per GB = near-XSIAM visibility. Every PANW NGFW customer's logs flow natively — zero configuration. This is the SIEM displacement motion. Position against Splunk, Elastic, and Microsoft Sentinel on total cost of ownership.
Customers on Pro per GB are already building the data foundation XSIAM runs on. Upgrade to XSIAM is a license change only — no data migration, no re-instrumentation.
Cortex XDR Cloud per Host
Cloud Runtime
Per cloud host / hour · VMs, containers, Kubernetes pods
What it is: Endpoint protection for cloud workloads. Same Cortex XDR agent, optimized for ephemeral cloud runtime environments. Priced per cloud host/hour — not per named endpoint — matching cloud infrastructure billing models.
  • Runtime protection for Linux cloud hosts
  • Container and Kubernetes workload protection
  • Cloud-native file integrity monitoring (FIM)
  • Container escape detection
  • Cloud process anomaly detection
  • Integration with Prisma Cloud CNAPP posture data
DaemonSet on Kubernetes · VM agent on AWS/Azure/GCP · Container image layer injection
Pair with Cortex Cloud CNAPP for full-stack cloud security — posture management + runtime protection from a single platform.
XSIAM — The AI SOC Platform
Tier 5 Platform Transformation
XDR data foundation + SIEM + SOAR + ASM + AI SOC automation — converged
XSIAM is not "more XDR" — it's a platform transformation. Built on the same Cortex Data Lake as XDR Pro per GB, XSIAM adds AI-driven analytics, full SOAR automation, and SOC workflow management on top. It replaces the SIEM, replaces the standalone SOAR, and replaces the MDR vendor — in one license.
  • NG SIEM — ingestion + correlation at SIEM scale
  • Built-in SOAR (automation playbooks, 1,300+ integrations)
  • Attack Surface Management (Xpanse ASM integrated) — Exposure Management is a separate module
  • Threat Intelligence Management (TIM)
  • AI-driven alert triage — 85%+ auto-resolved
  • AgentiX AI agent layer — autonomous investigation (current release 1.4, July 2026)
  • Unified SOC case management + Cortex Copilot
  • ML-driven UEBA at scale + compliance reporting
  • Cortex XSIAM NG-SIEM: SIEM-first tier on the XDR data foundation
  • XSIAM Enterprise: adds the Enterprise Runtime Security (XDR) capability set
  • XSIAM Premium: top tier — required for the full cloud posture bundle
  • Enterprise Plus is retired and grandfathered — never quote it
Analytics tier minimum 100 GB/day; optional Cortex Data Lake tier add-on minimum 50 GB/day.
Unit 42 Managed XSIAM (MSIAM) — Palo Alto-operated 24/7 SOC running on the customer's own XSIAM tenant. Current release MSIAM 2.0 (Feb 17, 2026), with a 250-hour Breach Response Guarantee and support for third-party EDR. See XSIAM MDR compete page.

Response Automation

Automation — How XDR Responds

Detection is worthless without response. XDR ships with automated response actions out of the box. XSOAR and AgentiX extend automation to full playbook orchestration and AI-driven autonomous response.

Automated Response Actions

Endpoint Quarantine
Isolates a compromised host from the network while maintaining the XDR agent connection for active investigation. The analyst can still remotely run queries, collect artifacts, and execute remediation scripts on the isolated host. One-click or triggered automatically by BTP or UEBA detection. The network sees the host as dead; the security team has full access.
Process Kill
Terminates malicious processes mid-execution. Can be triggered automatically by BTP behavioral detection — no analyst in the loop required. The termination is logged with full context: which rule fired, which behavior triggered it, and the complete process ancestry for post-incident review.
File Quarantine
Moves malicious files to a quarantine directory, preventing execution while preserving them for forensics. Files can be submitted to WildFire for additional analysis or restored if a false positive is confirmed. Quarantine actions are reversible — critical for maintaining analyst trust in automation.
Network Block
Blocks outbound connections to specific IPs/domains at the agent level — not at the firewall. Works even when the endpoint is off-network, traveling, or on a home connection. The block travels with the endpoint. Useful for immediately severing C2 channels without requiring a firewall policy change or IT ticket.
User Disable (UEBA-Triggered)
Disables an AD/Okta user account automatically when UEBA detects compromised credential behavior — impossible travel, credential stuffing patterns, or lateral movement via RDP. Requires Pro per GB + identity data ingestion. The most high-value automation for insider threat and account compromise scenarios.
Registry Remediation
Removes malicious registry keys, startup items, and persistence mechanisms as part of automated remediation workflows. Restores registry values to known-good state from baseline. Critical for removing attacker persistence after an incident — eliminates the class of "cleaned but still re-infected" outcomes from incomplete manual remediation.
XSOAR Integration

With XDR Pro per GB or XSIAM, all XDR alerts flow into Cortex XSOAR for full playbook orchestration. XSOAR playbooks can: enrich with threat intelligence, notify SOC via Slack/Teams/ServiceNow, run automated containment actions, trigger Change Advisory Board workflows, and close tickets with full documentation attached. Think of XDR as the detection engine and XSOAR as the response orchestrator — each does its job, and they talk natively. Over 1,300 integrations available out of the box.

AgentiX AI — Machine-Speed Autonomous Response (XSIAM)

In XSIAM, the AgentiX AI agent layer adds machine-speed autonomous response. AgentiX agents investigate alerts, run forensic XQL queries, correlate evidence across data sources, and take containment actions — all without waiting for analyst intervention. The goal: the analyst reviews summaries and approves escalations, not individual alerts. 85%+ of alerts are resolved by AgentiX before a human ever looks at them. Human-in-the-loop controls are fully configurable via RBAC, with complete audit logging of every agent action.

Extensibility

Add-Ons and Modules

Expand the XDR platform with purpose-built modules. Each add-on is a separate deal motion — qualify the need, then layer on top of the base license.

Forensics Module
Deep disk forensics on demand. Remotely extracts memory dumps, disk images, browser history, prefetch files, and full artifact collection from any managed endpoint. No need for physical access or USB boot media. Required for formal IR engagements. Pairs with Cortex XDR Pro EP (“Pro per Endpoint” on legacy 3.x contracts). Unit 42 IR teams use this in active breach response.
High Value
ITDR — Identity Threat Detection & Response
Active Directory and identity-layer threat detection. Detects DCSync attacks, Kerberoasting, Pass-the-Hash, Pass-the-Ticket, lateral movement via RDP, and credential theft patterns in real time. ITDR is the answer to "how do you detect an attacker using stolen legitimate credentials?" ITDR 2.0 shipped with XDR 5.2: Conditional Access Policies for Okta, Entra ID and on-premises AD, Active Directory Security Posture Management (AD-SPM), 17 new detectors and granular RBAC. Requires Cortex XDR Pro EP on 5.x (“Pro per Endpoint” on legacy 3.x contracts). Positioned against CrowdStrike Falcon Identity Protection and SentinelOne Singularity Identity.
Managed Threat Hunting (MTH)
Unit 42 threat hunters proactively hunt in the customer's environment on a weekly cadence. Delivers threat reports with findings and remediation recommendations. MTH closes the gap for organizations that want XDR's detection data but don't have staff to run proactive hunting. Available as an add-on to Cortex XDR Pro EP (“Pro per Endpoint” on legacy 3.x contracts). This is the non-MDR version of managed services — hunting only, not 24/7 monitoring. The 24/7 options are Unit 42 MDR and Unit 42 Managed XSIAM (MSIAM 2.0).
Extended Data Retention
Default XTH is 30-day retention with 1-year storage. Extend to multiple years for compliance requirements (HIPAA, PCI DSS, SOC 2 Type II), retroactive hunting in long-dwell breach investigations, and forensic evidence preservation. Organizations in regulated industries often need this before procurement can approve.
Cortex XDR Pro for Mobile
Mobile endpoint protection for iOS and Android. Behavioral detection, network protection (phishing, C2 blocking), certificate pinning bypass detection, and full integration into the XDR incident timeline. Mobile events appear alongside desktop events in the same causality chain — an attacker moving from a compromised mobile device to a desktop shows as one incident.
WildFire Private Cloud
For air-gapped or highly regulated environments — run the WildFire sandbox on-premises. Same multi-VM detonation and verdict quality as cloud WildFire. Zero external traffic: the file never leaves the customer's environment. Required for defense, intelligence, critical infrastructure, and some healthcare/financial deployments that prohibit cloud data egress.
XSOAR Integration Pack
Pre-built XSOAR playbooks for XDR alert ingestion, enrichment, and response orchestration. Includes playbooks for: alert triage with threat intel enrichment, endpoint quarantine with ServiceNow ticket creation, UEBA alert escalation with manager notification, and automated malware investigation workflows. Reduces XSOAR implementation time from weeks to days for XDR deployments.

Upgrade Path

XSIAM Path — How Customers Progress

The most powerful sales motion in XDR: land at any tier, build the data foundation, graduate to XSIAM. No rip-and-replace. One agent, one data lake, five tiers of capability.

1
Cortex Prevent Start Here
Protection only. Replacing legacy AV. Deploy the XDR agent across all endpoints. Get NGAV, behavioral protection, anti-exploit, WildFire, and device control. The agent is identical to Pro — this is a license limitation, not a capability limitation. Landing Prevent is the AV displacement motion. Every endpoint running the Prevent agent is an endpoint that can be upgraded to Pro with a license key change and no re-deployment.
2
XDR Pro per Endpoint Most Common Land
Add investigation, EDR, threat hunting. Upgrade from Prevent — no agent change, no re-imaging. Unlocks the full EDR investigation UI, XQL threat hunting, causality chains, 30-day XTH data retention, UEBA, incident management, and automated response. This is where customers stop using their SIEM for endpoint investigation. Trigger: first significant incident or pen test finding that requires "going back in time."
3
Add Pro per GB SIEM Displacement Begins
Ingest network, cloud, identity. SIEM displacement begins. Add Pro per GB to start ingesting NGFW logs, cloud audit logs, and identity events. The XDR data lake becomes the single pane for endpoint + network + cloud + identity correlation. This is the motion that starts replacing Splunk. The SIEM renewal conversation becomes: "Why are you paying $X/year to Splunk when XDR Pro per GB already has this data?"
4
XSIAM AI SOC Transformation
AI SOC transformation. Data foundation already built. The customer on Pro per GB already has the Cortex Data Lake, the agent coverage, and the data flows. XSIAM is a license upgrade — not a new deployment. XSIAM (current release 3.6) adds NG-SIEM, full SOAR, ASM, Threat Intelligence Management, Cortex XTI and AgentiX AI. On 5.x the equivalent land is Cortex XDR Pro EP plus the NG-SIEM data tier rather than legacy “Pro per GB”. The SOC stops triaging alerts and starts reviewing AI-generated summaries. Analyst headcount stays flat; investigation capacity grows by 10x.
5
Unit 42 Managed XSIAM Full SOC-as-a-Service
24/7 Palo-operated SOC. IR guarantee included. For organizations that want XSIAM's capabilities without the internal staff to operate it — Unit 42 Managed XSIAM puts Palo Alto Networks' own threat intelligence team behind the wheel. They operate in the customer's XSIAM tenant, 24/7, with a guaranteed IR response time. See the XSIAM MDR compete page for win strategy against CrowdStrike MDR and Arctic Wolf.

Sales Conversations

Discovery Questions for Sellers

Mix of technical and business questions. Goal: uncover the EDR gap, the SIEM cost problem, and the analyst capacity constraint — then position XDR's data foundation as the answer to all three.

01 What endpoint security product are you running today, and what does the investigation workflow look like when you get an alert? Walk me through the last incident from first detection to containment.
02 How many endpoints are you managing? Are any of them cloud workloads — VMs, containers, or Kubernetes pods — and are those protected by the same agent or something different?
03 Do you currently retain endpoint telemetry for threat hunting? If an attacker was in your environment for two weeks before detection — how far back can you go in the data?
04 What is your current mean time to detect (MTTD) and mean time to respond (MTTR)? Is that actually measured, and does your executive team see it as a KPI?
05 When a threat traverses from your firewall to an endpoint — do you see that as one incident in one console, or two separate alerts in two different tools requiring manual correlation?
06 How many security tools are your analysts correlating today across endpoint, network, and cloud? What does the investigation workflow look like when something spans multiple domains?
07 Are you using a SIEM today? What's the renewal timeline — and what's the fully-loaded annual cost including storage, ingestion overages, and analyst time to maintain it?
08 When was the last time your endpoint protection was evaluated against the MITRE ATT&CK framework? Did your current vendor achieve 100% technique detection — and have they participated in the most recent evaluation?
09 Do you have staff dedicated to proactive threat hunting, or does detection happen reactively — waiting for alerts? What would a 30-day retroactive hunt capability change about how you find attackers?
10 If I could show you a platform where a single data lake covered endpoint, network, cloud, and identity — and 85% of alerts were resolved without analyst involvement — what would that change about how your SOC operates and how many people you need to hire next year?
Continue Your XDR Research

Each tier has a dedicated detail page with competitive positioning, objection handling, and pricing guidance.