SecOps · Technical Reference
Cortex XDR —
How It Works
A technical seller's guide to prevention architecture, detection engines, automation, licensing, add-ons, and how it all connects to XSIAM. Current releases: Cortex XDR 5.2 (July 20, 2026), XDR agent 9.3 (July 26, 2026), Cortex XSIAM 3.6 (July 20, 2026).
Agent Architecture
The Cortex XDR Agent — How Prevention Actually Works
The XDR agent is not a scanner. It's a kernel-resident behavioral enforcement engine that hooks into the OS before any user-space process can act. Here's the full technical stack. Current agent release is 9.3 (July 26, 2026), and with XDR 5.2 Agentic Endpoint Security (AES) is an integral part of that agent — zero additional deployment.
Prevention Flow
From File Arrival to Forensics — The 5-Step Chain
Walk a prospect through exactly what happens when a suspicious file lands on an endpoint. Every step is a defense layer. Multiple must fail simultaneously for a breach to succeed.
Detection Layer
Detection Engines — What Runs After Prevention
Prevention catches known and near-known threats. These four engines handle everything that requires deeper analysis — behavioral correlation, ML-driven anomaly detection, and analyst-driven hunting.
Licensing Architecture
The Five License Tiers — Complete Technical Breakdown
XDR is not a single product — it's a tiered architecture. Each tier unlocks a new layer of capability without redeployment. This is the upsell ladder every seller should memorize.
| Capability | Prevent | Pro / Endpoint | Pro / GB | Cloud / Host | XSIAM |
|---|---|---|---|---|---|
| Cortex XDR Agent | Full | Full | Full | Cloud-Opt | Full |
| Prevention (Local ML) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Anti-Exploit Module | ✓ | ✓ | ✓ | ✓ | ✓ |
| Behavioral Threat Protection | ✓ | ✓ | ✓ | ✓ | ✓ |
| EDR Investigation UI | — | ✓ | ✓ | Partial | ✓ |
| XTH Data (30-day Retention) | — | 30 Days | 30 Days+ | — | 1 Year+ |
| UEBA / Behavioral Analytics | — | Endpoint | Full | — | AI-Scale |
| 3rd-Party Data Ingestion | — | — | Unlimited | — | Unlimited |
| Network Analytics | — | — | ✓ | — | ✓ |
| Identity Analytics | — | — | ✓ | — | ✓ |
| Forensics Add-On Eligible | — | ✓ | ✓ | Limited | Included |
| XSIAM Upgrade Path | License | License | Direct Path | Add XSIAM | Native |
- ✓ Full Cortex XDR agent (Local Analysis, WildFire, Anti-Exploit, BTP, Network Protection)
- ✓ AI-powered malware prevention + behavioral protection
- ✓ Anti-exploit memory defense (zero-day coverage)
- ✓ Network C2 blocking (DNS sinkholing + IP reputation)
- ✓ WildFire cloud sandbox integration
- ✓ Device control + host firewall
- ✗ No EDR investigation UI or causality chains
- ✗ No XQL threat hunting capability
- ✗ No XTH data retention (no going back in time)
- ✗ No UEBA or incident management
- ✓ Full EDR investigation UI with causality chain visualization
- ✓ XQL threat hunting across endpoint telemetry
- ✓ XTH (Extended Threat Hunting) data — 30 days of all endpoint activity, 1-year retention
- ✓ UEBA — user behavior analytics for anomaly detection
- ✓ Incident management + automated response (quarantine, kill process, block network)
- ✓ Forensics module eligibility
- ✓ NGFW logs (Palo Alto Networks — zero configuration)
- ✓ Prisma Access (SASE) logs
- ✓ Cloud logs: AWS CloudTrail, Azure Activity, GCP Audit
- ✓ DNS, proxy, and identity logs (AD, Okta)
- ✓ Third-party EDR data (CrowdStrike, SentinelOne)
- ✓ Custom log sources via API / Syslog
- ✓ Runtime protection for Linux cloud hosts
- ✓ Container and Kubernetes workload protection
- ✓ Cloud-native file integrity monitoring (FIM)
- ✓ Container escape detection
- ✓ Cloud process anomaly detection
- ✓ Integration with Prisma Cloud CNAPP posture data
- ✓ NG SIEM — ingestion + correlation at SIEM scale
- ✓ Built-in SOAR (automation playbooks, 1,300+ integrations)
- ✓ Attack Surface Management (Xpanse ASM integrated) — Exposure Management is a separate module
- ✓ Threat Intelligence Management (TIM)
- ✓ AI-driven alert triage — 85%+ auto-resolved
- ✓ AgentiX AI agent layer — autonomous investigation (current release 1.4, July 2026)
- ✓ Unified SOC case management + Cortex Copilot
- ✓ ML-driven UEBA at scale + compliance reporting
- → Cortex XSIAM NG-SIEM: SIEM-first tier on the XDR data foundation
- → XSIAM Enterprise: adds the Enterprise Runtime Security (XDR) capability set
- → XSIAM Premium: top tier — required for the full cloud posture bundle
- → Enterprise Plus is retired and grandfathered — never quote it
Response Automation
Automation — How XDR Responds
Detection is worthless without response. XDR ships with automated response actions out of the box. XSOAR and AgentiX extend automation to full playbook orchestration and AI-driven autonomous response.
Automated Response Actions
With XDR Pro per GB or XSIAM, all XDR alerts flow into Cortex XSOAR for full playbook orchestration. XSOAR playbooks can: enrich with threat intelligence, notify SOC via Slack/Teams/ServiceNow, run automated containment actions, trigger Change Advisory Board workflows, and close tickets with full documentation attached. Think of XDR as the detection engine and XSOAR as the response orchestrator — each does its job, and they talk natively. Over 1,300 integrations available out of the box.
In XSIAM, the AgentiX AI agent layer adds machine-speed autonomous response. AgentiX agents investigate alerts, run forensic XQL queries, correlate evidence across data sources, and take containment actions — all without waiting for analyst intervention. The goal: the analyst reviews summaries and approves escalations, not individual alerts. 85%+ of alerts are resolved by AgentiX before a human ever looks at them. Human-in-the-loop controls are fully configurable via RBAC, with complete audit logging of every agent action.
Extensibility
Add-Ons and Modules
Expand the XDR platform with purpose-built modules. Each add-on is a separate deal motion — qualify the need, then layer on top of the base license.
Upgrade Path
XSIAM Path — How Customers Progress
The most powerful sales motion in XDR: land at any tier, build the data foundation, graduate to XSIAM. No rip-and-replace. One agent, one data lake, five tiers of capability.
Sales Conversations
Discovery Questions for Sellers
Mix of technical and business questions. Goal: uncover the EDR gap, the SIEM cost problem, and the analyst capacity constraint — then position XDR's data foundation as the answer to all three.
Each tier has a dedicated detail page with competitive positioning, objection handling, and pricing guidance.