★ Showcase — SecOps
Cortex XSIAM 3.6
The AI-Driven SOC
Replacing legacy SIEM at machine speed. XSIAM unifies SIEM + SOAR + XDR + ASM + TIM into one AI-native platform — the fastest-growing product in cybersecurity.
Overview
What is XSIAM?
Cortex XSIAM (Extended Security Intelligence and Automation Management) is Palo Alto Networks' AI-driven SOC platform that unifies SIEM, SOAR, XDR, ASM, and TIM into a single, natively integrated solution.
Built from the ground up with machine learning at its core, XSIAM was designed to replace legacy SIEM by operating at machine speed — ingesting data from any source, correlating alerts with AI, and automating response through AgentiX-powered agentic workflows. It eliminates alert fatigue by stitching together related signals into unified cases, dramatically reducing Mean Time to Resolve.
Scale as of Q3 FY2026 (reported June 2, 2026): ARR above $600M, up 100% year over year, 740 customers, and more than 17 PB/day ingested. Palo Alto states the capabilities delivered in XSIAM 3.6 are also available across Cortex AgentiX, Cortex XDR and Cortex Cloud — one platform, several entry points.
— Nikesh Arora, CEO, Palo Alto Networks
Latest Release
XSIAM 3.6 — July 2026
GA July 20, 2026. Frontier AI model choice, Cortex XTI, and natural-language analytics across the platform.
v3.6 Release Highlights
Detailed Feature Enhancements
Expand each section to view all features added in 3.6
- Frontier AI model choice — Claude Sonnet 4.6, Claude Opus 4.8, Gemini 3.5 Flash
- Cortex XTI (Extended Threat Intelligence) — Threat Intel Library and AI-enabled threat intel
- Cortex Agentic Assistant Hub
- Personalized Agents (private preview) with Google Drive, Confluence and SOP sources
- Natural-language dashboard creation
- XQL macros, reshape operator, and free-text search
- OCI analytics support
- NDR Unmanaged Subnet Analytics
- Granular RBAC for ITDR
- Granular Jobs permissions
- Forensics public APIs
- DLP scanning up to 300 MB, including archives
- Containers-as-a-Service support — Google Cloud Run and Azure Container Instances
- JSP/JSPX runtime protection
- CrowdStrike integration for Exposure Management
- Exposure Management is now a distinct XSIAM/XDR module, separate from Xpanse/ASM
- Broker VM 32.0.51 — TLS 1.3 and independent applet upgrades
- New Device Security data collector
- The IoT Security collector is now labelled “IoT Security (Deprecated)”
Evolution
Release Timeline
The rapid evolution of XSIAM from automation-first SIEM to the complete AI-driven SOC.
- Automation-first approach with AI at the core
- Foundational SIEM + SOAR + XDR unification
- Cloud posture integration
- Cases/issues workflow & Command Center
- ASM & unified Asset Inventory
- SBAC & new automation experience
- AI-powered Exposure Management
- Advanced Email Security add-on
- Ticket Sync (Jira / ServiceNow)
- Digital Risk Protection & Global Lookup
- AgentiX — agentic AI SOAR
- Cortex MCP Server
- Federated Search in XDL (AWS/GCP/Azure)
- Forensics for Linux, ML JScript analysis
- XDR Agent for Windows ARM64
- Cortex XDL 2.0 — cost-efficient data lake tier
- Federated search with no extra ingestion or storage cost
- Native Chronosphere Telemetry Pipeline integration
- AI-driven parser generation
- XDL ingests 15+ PB/day across 1,100+ integrations
- Autonomous Playbooks and Agentic Response
- Enhanced XQL with 30+ math functions
- Case Timeline View and Natural Language Visualization
- Idira Endpoint Privilege Manager integration via Cortex Marketplace
- Enhanced Application Log (EAL) ingestion now free — cuts NGFW/Prisma SASE ingestion cost ~10–15%
- Frontier AI model choice (Claude Sonnet 4.6, Claude Opus 4.8, Gemini 3.5 Flash)
- Cortex XTI — Extended Threat Intelligence
- Natural-language dashboards; XQL macros, reshape, free-text search
- Granular RBAC for ITDR; Forensics public APIs
- Cortex Agentic Assistant Hub and Personalized Agents (private preview)
- New Device Security collector; IoT Security collector deprecated
Licensing
License Tiers
Three current tiers: Cortex XSIAM NG-SIEM, XSIAM Enterprise, and XSIAM Premium. “XSIAM Enterprise Plus” is retired — do not quote it.
| Capability | Cortex XSIAM NG-SIEM | XSIAM Enterprise | XSIAM Premium |
|---|---|---|---|
| Log Ingestion & Analytics | |||
| Detection & Hunting | |||
| Automation / SOAR | |||
| UEBA | |||
| Enterprise Runtime Security (XDR) | |||
| Host Insights | |||
| XTH (Threat Hunting) | |||
| On-Prem Discovery | |||
| Cloud Posture Security (CSPM, CIEM, AI-SPM, DSPM, ASPM) | |||
| Kubernetes / OpenShift | |||
| Cloud Runtime Security (workload rules, WAAS) | |||
| Extended Threat Intelligence (XTI) & Threat Intel Management | |||
| Attack Surface Management |
Existing Enterprise Plus customers keep Enterprise features with cloud agent features, but must upgrade to XSIAM Premium to get the full cloud posture bundle (Cloud Posture Security, Cloud Runtime Security, XTI, Threat Intel Management, Attack Surface Management). Never present Enterprise Plus as a current tier on a quote.
Analytics tier has a 100 GB/day minimum. The optional Cortex Data Lake tier add-on has a 50 GB/day minimum. Size both before quoting.
Extensibility
Add-On Modules
Current add-on catalog as of August 2026. The same catalog applies to Cortex XDR 5.x on the Enterprise Runtime Security (XDR) base.
Enterprise Runtime Security (XDR)
Endpoint, server and container runtime protection. The XDR base add-on; also the base SKU for standalone Cortex XDR 5.x.
Cloud Posture Security
CSPM, CIEM, AI-SPM, DSPM, agentless workload scanning, ASPM and CI/CD security. Included in Premium.
Cloud Runtime Security
Cloud workload rules and policies plus WAAS. Included in Premium.
Application Security
AppSec coverage for the software supply chain. Code Security is licensed separately.
Extended Threat Intelligence (XTI)
New with 3.6 — Threat Intel Library plus AI-enabled intel. Also the delivery vehicle for Unit 42 Threat Intelligence (launched Aug 3, 2026).
Threat Intelligence Management
Aggregate, correlate and operationalize threat intelligence from multiple feeds.
Attack Surface Management
Discover, evaluate and mitigate external attack surface risk continuously (Xpanse-powered).
Exposure Management
Now a distinct module, separate from Xpanse/ASM. Controls verification, residual-risk scoring, CrowdStrike integration. Requires Premium, Enterprise or NG-SIEM.
ITDR
Identity Threat Detection and Response. ITDR 2.0 adds conditional access policies and AD-SPM; granular RBAC added in 3.6.
Forensics
Deep forensic investigation and evidence collection. Public APIs added in 3.6.
Host Insights
Endpoint inventory, vulnerability and search-and-destroy visibility.
Extended Threat Hunting
Extended telemetry retention and hunting datasets for proactive hunts.
Data Retention
Extended log retention beyond the tier default for compliance and investigations.
Extended Compute Units
Additional compute for high-volume analytics, agentic workloads and automation.
Endpoint Event Forwarding
Forward endpoint events to external systems for additional analysis or compliance.
GB Event Forwarding
Volume-based event forwarding for large-scale data export and integration.
DLP
Cortex DLP for data in use, in motion and at rest. Scanning up to 300 MB plus archives as of 3.6.
Advanced Email Security
LLM-powered email security with 3 detection engines, automatic remediation, and SmartScore risk prioritization. Includes the Email Security Command Center. Requires Premium, Enterprise or NG-SIEM.
Palo's Training — Demo Zone (Learning Center)
Demo & Training
Hands-on demos, learning paths, and certifications to master XSIAM.
XSIAM SE Demo Environment
Demo Zone — Learning Center
Core Certifications
The PCNSA / PCNSE / PCSAE / PCCSE / PCSFE / PCCET / PCDRA family is retired (PCNSE, PCCSE and PCSAE ended July 31, 2025). The program is now four levels — Cybersecurity Apprentice, Cybersecurity Practitioner, Professional, Specialist — plus Architect at the top. The two SecOps credentials below are Specialist-level: XSIAM Analyst and XSIAM Engineer. There is no identity or AI certification yet.
XSIAM Engineer (Specialist)
Validates the ability to implement, configure, and operate XSIAM in production environments.
Topics Covered
- Deployment & architecture
- Data onboarding & ingestion
- Playbook creation & automation
- Detection engineering
Required For
- XSIAM onboarding engagements
- Health checks
- Managed SOC delivery
XSIAM Analyst (Specialist)
Validates SOC analyst skills for day-to-day operations using the XSIAM platform.
Topics Covered
- Incident response workflows
- Alert handling & triage
- Threat hunting techniques
Required For
- SOC teams
- MSSP analysts
- Detection validation
Pre-Sales
Scoping Checklist
Key data points to collect before every XSIAM engagement. Tier and module names current as of August 2026.
Conversations
Discovery Questions
Open-ended questions to uncover SOC pain points and build the case for XSIAM.