★ Showcase — SecOps

Cortex XSIAM 3.6
The AI-Driven SOC

Replacing legacy SIEM at machine speed. XSIAM unifies SIEM + SOAR + XDR + ASM + TIM into one AI-native platform — the fastest-growing product in cybersecurity.

$600M+
ARR
740
Customers
<10m
MTTR
17 PB+
Ingested / Day

Overview

What is XSIAM?

Cortex XSIAM (Extended Security Intelligence and Automation Management) is Palo Alto Networks' AI-driven SOC platform that unifies SIEM, SOAR, XDR, ASM, and TIM into a single, natively integrated solution.

Built from the ground up with machine learning at its core, XSIAM was designed to replace legacy SIEM by operating at machine speed — ingesting data from any source, correlating alerts with AI, and automating response through AgentiX-powered agentic workflows. It eliminates alert fatigue by stitching together related signals into unified cases, dramatically reducing Mean Time to Resolve.

Scale as of Q3 FY2026 (reported June 2, 2026): ARR above $600M, up 100% year over year, 740 customers, and more than 17 PB/day ingested. Palo Alto states the capabilities delivered in XSIAM 3.6 are also available across Cortex AgentiX, Cortex XDR and Cortex Cloud — one platform, several entry points.

"One of the fastest-growing products in cybersecurity."
— Nikesh Arora, CEO, Palo Alto Networks

Latest Release

XSIAM 3.6 — July 2026

GA July 20, 2026. Frontier AI model choice, Cortex XTI, and natural-language analytics across the platform.

v3.6 Release Highlights

1
Frontier AI Model Choice
Native selection of Anthropic Claude Sonnet 4.6, Claude Opus 4.8, and Google Gemini 3.5 Flash for agentic and analytic workloads.
2
Cortex XTI — Extended Threat Intelligence
Threat Intel Library plus AI-enabled threat intel. Ships across XSIAM 3.6, Cortex XDR 5.2 and Cortex AgentiX 1.4.
3
Natural-Language Dashboards & XQL
Natural-language dashboard creation, plus XQL macros, reshape, and free-text search for faster hunting.
4
Cortex Agentic Assistant Hub
Assistant Hub with Personalized Agents (private preview) sourcing from Google Drive, Confluence and SOP repositories.
5
Granular RBAC for ITDR
Granular ITDR role-based access control, granular Jobs permissions, and public APIs for Forensics.
6
New Device Security Collector
A new Device Security data collector ships; the legacy IoT Security collector is now labelled “IoT Security (Deprecated)”. Plan migrations.

Detailed Feature Enhancements

Expand each section to view all features added in 3.6

  • Frontier AI model choice — Claude Sonnet 4.6, Claude Opus 4.8, Gemini 3.5 Flash
  • Cortex XTI (Extended Threat Intelligence) — Threat Intel Library and AI-enabled threat intel
  • Cortex Agentic Assistant Hub
  • Personalized Agents (private preview) with Google Drive, Confluence and SOP sources
  • Natural-language dashboard creation
  • XQL macros, reshape operator, and free-text search
  • OCI analytics support
  • NDR Unmanaged Subnet Analytics
  • Granular RBAC for ITDR
  • Granular Jobs permissions
  • Forensics public APIs
  • DLP scanning up to 300 MB, including archives
  • Containers-as-a-Service support — Google Cloud Run and Azure Container Instances
  • JSP/JSPX runtime protection
  • CrowdStrike integration for Exposure Management
  • Exposure Management is now a distinct XSIAM/XDR module, separate from Xpanse/ASM
  • Broker VM 32.0.51 — TLS 1.3 and independent applet upgrades
  • New Device Security data collector
  • The IoT Security collector is now labelled “IoT Security (Deprecated)”

Evolution

Release Timeline

The rapid evolution of XSIAM from automation-first SIEM to the complete AI-driven SOC.

XSIAM 2.0
2024
  • Automation-first approach with AI at the core
  • Foundational SIEM + SOAR + XDR unification
XSIAM 3.0
February 2, 2025
  • Cloud posture integration
  • Cases/issues workflow & Command Center
  • ASM & unified Asset Inventory
  • SBAC & new automation experience
XSIAM 3.2
August 13, 2025
  • AI-powered Exposure Management
  • Advanced Email Security add-on
  • Ticket Sync (Jira / ServiceNow)
  • Digital Risk Protection & Global Lookup
XSIAM 3.3
November 9, 2025
  • AgentiX — agentic AI SOAR
  • Cortex MCP Server
  • Federated Search in XDL (AWS/GCP/Azure)
  • Forensics for Linux, ML JScript analysis
  • XDR Agent for Windows ARM64
XSIAM 3.4
January 25, 2026
  • Cortex XDL 2.0 — cost-efficient data lake tier
  • Federated search with no extra ingestion or storage cost
  • Native Chronosphere Telemetry Pipeline integration
  • AI-driven parser generation
  • XDL ingests 15+ PB/day across 1,100+ integrations
XSIAM 3.5
May 3, 2026
  • Autonomous Playbooks and Agentic Response
  • Enhanced XQL with 30+ math functions
  • Case Timeline View and Natural Language Visualization
  • Idira Endpoint Privilege Manager integration via Cortex Marketplace
  • Enhanced Application Log (EAL) ingestion now free — cuts NGFW/Prisma SASE ingestion cost ~10–15%
XSIAM 3.6 Current
July 20, 2026
  • Frontier AI model choice (Claude Sonnet 4.6, Claude Opus 4.8, Gemini 3.5 Flash)
  • Cortex XTI — Extended Threat Intelligence
  • Natural-language dashboards; XQL macros, reshape, free-text search
  • Granular RBAC for ITDR; Forensics public APIs
  • Cortex Agentic Assistant Hub and Personalized Agents (private preview)
  • New Device Security collector; IoT Security collector deprecated

Licensing

License Tiers

Three current tiers: Cortex XSIAM NG-SIEM, XSIAM Enterprise, and XSIAM Premium. “XSIAM Enterprise Plus” is retired — do not quote it.

Capability Cortex XSIAM NG-SIEM XSIAM Enterprise XSIAM Premium
Log Ingestion & Analytics
Detection & Hunting
Automation / SOAR
UEBA
Enterprise Runtime Security (XDR)
Host Insights
XTH (Threat Hunting)
On-Prem Discovery
Cloud Posture Security (CSPM, CIEM, AI-SPM, DSPM, ASPM)
Kubernetes / OpenShift
Cloud Runtime Security (workload rules, WAAS)
Extended Threat Intelligence (XTI) & Threat Intel Management
Attack Surface Management
“XSIAM Enterprise Plus” is retired and grandfathered.
Existing Enterprise Plus customers keep Enterprise features with cloud agent features, but must upgrade to XSIAM Premium to get the full cloud posture bundle (Cloud Posture Security, Cloud Runtime Security, XTI, Threat Intel Management, Attack Surface Management). Never present Enterprise Plus as a current tier on a quote.
Ingestion minimums.
Analytics tier has a 100 GB/day minimum. The optional Cortex Data Lake tier add-on has a 50 GB/day minimum. Size both before quoting.

Extensibility

Add-On Modules

Current add-on catalog as of August 2026. The same catalog applies to Cortex XDR 5.x on the Enterprise Runtime Security (XDR) base.

Enterprise Runtime Security (XDR)

Endpoint, server and container runtime protection. The XDR base add-on; also the base SKU for standalone Cortex XDR 5.x.

Cloud Posture Security

CSPM, CIEM, AI-SPM, DSPM, agentless workload scanning, ASPM and CI/CD security. Included in Premium.

Cloud Runtime Security

Cloud workload rules and policies plus WAAS. Included in Premium.

Application Security

AppSec coverage for the software supply chain. Code Security is licensed separately.

Extended Threat Intelligence (XTI)

New with 3.6 — Threat Intel Library plus AI-enabled intel. Also the delivery vehicle for Unit 42 Threat Intelligence (launched Aug 3, 2026).

Threat Intelligence Management

Aggregate, correlate and operationalize threat intelligence from multiple feeds.

Attack Surface Management

Discover, evaluate and mitigate external attack surface risk continuously (Xpanse-powered).

Exposure Management

Now a distinct module, separate from Xpanse/ASM. Controls verification, residual-risk scoring, CrowdStrike integration. Requires Premium, Enterprise or NG-SIEM.

ITDR

Identity Threat Detection and Response. ITDR 2.0 adds conditional access policies and AD-SPM; granular RBAC added in 3.6.

Forensics

Deep forensic investigation and evidence collection. Public APIs added in 3.6.

Host Insights

Endpoint inventory, vulnerability and search-and-destroy visibility.

Extended Threat Hunting

Extended telemetry retention and hunting datasets for proactive hunts.

Data Retention

Extended log retention beyond the tier default for compliance and investigations.

Extended Compute Units

Additional compute for high-volume analytics, agentic workloads and automation.

Endpoint Event Forwarding

Forward endpoint events to external systems for additional analysis or compliance.

GB Event Forwarding

Volume-based event forwarding for large-scale data export and integration.

DLP

Cortex DLP for data in use, in motion and at rest. Scanning up to 300 MB plus archives as of 3.6.

Featured

Advanced Email Security

LLM-powered email security with 3 detection engines, automatic remediation, and SmartScore risk prioritization. Includes the Email Security Command Center. Requires Premium, Enterprise or NG-SIEM.

Palo's Training — Demo Zone (Learning Center)

Demo & Training

Hands-on demos, learning paths, and certifications to master XSIAM.

Core Certifications

Certification program changed.
The PCNSA / PCNSE / PCSAE / PCCSE / PCSFE / PCCET / PCDRA family is retired (PCNSE, PCCSE and PCSAE ended July 31, 2025). The program is now four levels — Cybersecurity Apprentice, Cybersecurity Practitioner, Professional, Specialist — plus Architect at the top. The two SecOps credentials below are Specialist-level: XSIAM Analyst and XSIAM Engineer. There is no identity or AI certification yet.
★ Most Important

XSIAM Engineer (Specialist)

Validates the ability to implement, configure, and operate XSIAM in production environments.

Topics Covered

  • Deployment & architecture
  • Data onboarding & ingestion
  • Playbook creation & automation
  • Detection engineering

Required For

  • XSIAM onboarding engagements
  • Health checks
  • Managed SOC delivery

XSIAM Analyst (Specialist)

Validates SOC analyst skills for day-to-day operations using the XSIAM platform.

Topics Covered

  • Incident response workflows
  • Alert handling & triage
  • Threat hunting techniques

Required For

  • SOC teams
  • MSSP analysts
  • Detection validation

Pre-Sales

Scoping Checklist

Key data points to collect before every XSIAM engagement. Tier and module names current as of August 2026.

Daily Ingest Volume — GB/day across all sources. Analytics tier minimum is 100 GB/day; the optional Cortex Data Lake tier add-on minimum is 50 GB/day.
License Tier Decision — NG-SIEM, XSIAM Enterprise or XSIAM Premium. Premium is required for the full cloud posture bundle. Enterprise Plus is retired/grandfathered — never quote it.
Endpoint Count — Total endpoints by OS (Windows, macOS, Linux, mobile) for the Enterprise Runtime Security (XDR) add-on.
Cloud Estate — Count of AWS accounts, Azure subscriptions, GCP and OCI projects, plus container/Kubernetes cluster count for Cloud Posture and Cloud Runtime Security.
Incumbent SIEM & Contract End Date — Vendor, annual licence + storage spend, and exact renewal date. This sets the displacement window.
Required Add-On Modules — Which of ITDR, Forensics, Host Insights, Extended Threat Hunting, Data Retention, Extended Compute Units, Advanced Email Security, Exposure Management, XTI, Threat Intel Management, ASM, DLP are in scope.
Data Residency & Region — Tenant region required (US, EU, Canada, UK, Germany, France, Japan, India, Singapore, Australia, South Korea) and any sovereignty constraint.
Compliance Frameworks — PCI, HIPAA, SOX, NIS2, DORA, CMMC, EU AI Act, ISO/IEC 42001 — drives retention length and Data Retention add-on sizing.
Log Retention Requirement — Hot vs cold retention in months, and whether Cortex XDL federated search can cover long-tail data instead of paid ingest.
Services & Delivery Scope — Number of data sources to onboard, custom parsers/playbooks required, and whether Unit 42 Managed XSIAM (MSIAM) or a Cortex XMDR Specialization partner will run the SOC.

Conversations

Discovery Questions

Open-ended questions to uncover SOC pain points and build the case for XSIAM.

01 How many alerts does your SOC handle per day, and what percentage are actually investigated?
02 What is your current Mean Time to Detect and Mean Time to Respond for a typical incident?
03 How many separate tools does your SOC team use today, and how much time is spent pivoting between them?
04 What is your annual SIEM spend including licensing, storage, and personnel to maintain it?
05 Are you experiencing analyst burnout or difficulty retaining SOC staff due to alert fatigue?
06 How are you currently correlating data across endpoints, network, cloud, and identity sources?
07 What is your current level of automation in the SOC? Do you have playbooks, or is response mostly manual?
08 When is your current SIEM contract up for renewal, and are you evaluating alternatives?
09 Do you have visibility into your external attack surface today? How are you tracking exposed assets?
10 How important is AI/ML-driven detection to your security strategy over the next 12–18 months?
11 Are you consolidating security vendors? What does your ideal end-state platform look like?
12 How do you currently handle threat intelligence operationalization — is it manual or automated?