Cloud malware analysis and sandboxing feeding the inline services.
Analysis Engines Analysis Environment Images Reproduces multiple client operating systems for detonation — Windows XP, 7 32/64-bit and 10 64-bit, macOS, Android and Linux — and analyzes application-specific files against multiple software versions of Adobe Reader, Flash, Internet Explorer and Office in the public cloud. Bare Metal Analysis Executes samples on physical Windows hardware rather than a virtual machine so that malware which detects virtualization still exhibits its behavior during analysis. Compressed and Encoded File Decoding Decodes files compressed or encoded up to four levels by default and up to seven when raised through the CLI, forwards the matching decoded contents for analysis, processes RAR and 7-Zip archives in the cloud, and decrypts password-protected RAR archives submitted with the passwords infected or virus. Dynamic Analysis Sandbox Detonates previously unknown samples in a custom-built, evasion-resistant virtual environment and observes more than 200 behaviors including browser security changes, code injection, operating-system file modification and connections to malicious domains. Dynamic Unpacking Identifies files encrypted or packed with custom or open-source methods, decompresses and decrypts them in memory inside the dynamic analysis environment, and passes the unpacked content back to static analysis. Email Link Analysis Extracts HTTP and HTTPS links from SMTP and POP3 messages without receiving or storing the message, visits them in batches of 100 or every two minutes to determine whether the page hosts exploits or phishing, and adds malicious links to PAN-DB under the malware category. File Type Coverage Accepts and analyzes portable executables, Office documents, PDFs, APK and DEX, Java, Flash, macOS binaries and installers, Linux ELF and shell scripts, archives, images, CHM, EML email message files, and Batch, JScript, VBScript, PowerShell, Python and Perl scripts, with coverage varying by cloud region and by direct upload versus firewall forwarding. Intelligent Run-time Memory Analysis Runs cloud-based introspective detectors over sample memory at execution time — including run-time DLL emulation, family classification and stealth observation — to catch evasive malware that cloaks itself from static and dynamic analysis, with detectors updated cloud-side without content downloads. Machine Learning Sample Classification Compares malware feature sets against dynamically updated classification models in the cloud to identify variants of known threats and AI-generated threats without an existing signature. Multi-Stage Payload Analysis Extracts and independently analyzes secondary payloads referenced by multi-stage PE, APK and ELF malware packages, returning a verdict per stage and marking the overall file malicious if any stage is malicious. Network Traffic Profiling Deep-inspects packet captures generated during dynamic analysis to build network activity profiles and matches new samples against them, detecting previously unknown malware through a one-to-many profile match. Static Analysis Inspects the characteristics of a sample before execution using per-format static analyzers for PE, PDF, Office, OOXML, RTF, Java, Flash, macOS, script, phishing and archive content to identify known threats and produce an initial verdict. URL Analysis Processes URL feeds, correlated email links, newly registered domain lists, PAN-DB content and manually uploaded URLs in the global cloud to produce a URL verdict and a report containing detection reasons, evidence, screenshots and downloadable web artifacts.
Appliance Clustering Appliance Clustering Groups up to 20 WildFire appliances into a cluster of two controller nodes plus worker and server nodes over a dedicated cluster management interface, with worker nodes inheriting the controller configuration and nodes added, decommissioned or removed through the CLI or Panorama. Cluster Data Migration Redistributes the sample database, queue and stored submissions across nodes whenever cluster topology or software version changes, and reports progress and completion through the CLI; samples can also be redistributed from one node to another on demand. Cluster DNS Service Advertisement Lets the controller node act as the authoritative DNS server for the cluster, returning member addresses in random order for organic load balancing and dropping failed nodes from responses automatically. Cluster Health Monitoring Reports cluster state through CLI commands covering controller role, peer list, membership, work queue depth and an aggregated healthy, degraded or unhealthy status, with per-application and per-service state vocabularies and named diagnostic error messages for unreachable, unstable or misconfigured nodes. Cluster High Availability Pairs the two controller nodes as an active/passive high-availability pair over primary and backup control links with configurable priority, preemption and heartbeat, hello, preemption-hold and promotion-hold timers, failing over cluster control when a peer becomes unreachable. Cluster Load Balancing and Registration Pushes a registration list of every cluster node to connected firewalls so they re-register with another node if one fails, and distributes analysis, report generation, signature creation, storage and content distribution across active nodes. Cross-Cluster Signature Sync Replicates locally generated signatures between clusters and standalone nodes managed by the same Panorama, with controller nodes pulling signature events from peers over HTTPS using journal offsets, bidirectionally between clusters and one-way into standalone nodes. Panorama Cluster Management Manages up to five clusters centrally from Panorama, acting as the cluster registry that pushes membership metadata to every node, orchestrating staged rolling software upgrades with per-node precheck, install, reboot, commit and post-upgrade validation stages, and surfacing color-coded cluster health. Split-Brain Detection and Recovery Detects when both controllers in a two-node cluster lose contact and each assumes the active role, flags the condition in the CLI and Panorama, attempts automatic recovery, and supports manual recovery by rebooting the unhealthy node and merging the databases.
Data Residency & Protection Appliance Mutual TLS Authentication Authenticates firewalls and Panorama to a WildFire appliance in both directions using predefined certificates by default, or custom server and client certificates with SSL/TLS service profiles, certificate profiles and OCSP or CRL revocation checking. Appliance-to-Appliance Encryption Encrypts traffic between WildFire appliances in a cluster and between high-availability peers over IKE/IPsec using FIPS/CC/UCAPL-approved predefined certificates or compliant custom certificates, enabled automatically in FIPS/CC mode. Device Certificate Installation Fetches and installs the Palo Alto Networks device certificate used to authenticate to cloud analysis services, through a one-time password from the support portal on WF-500 appliances and automatically through the Trusted Platform Module on WF-500B. FedRAMP-Authorized Clouds Provides isolated high-security analysis environments at FedRAMP High for the Advanced WildFire Government Cloud and FedRAMP Moderate for the Public Sector Cloud and the superseded U.S. Government Cloud, each with its own onboarding process and no sharing of sample privacy data with other WildFire instances. Hybrid Cloud Forwarding Splits forwarding so sensitive file types go to the on-premises private cloud and the rest to a public cloud, with any sample matching both rule sets sent only to the private cloud. Private Cloud Appliance Hosts sandbox analysis on an on-premises WF-500 or WF-500B appliance serving up to 100 firewalls, so that samples and their verdicts never leave the network unless the administrator explicitly enables forwarding to the public cloud. Regional Public Clouds Offers a global US cloud plus regional clouds in over twenty countries, each analyzing and storing samples within its own jurisdiction while sharing resulting verdicts and signatures globally. Sample Removal Requests Accepts a list of up to 100 SHA-256 or MD5 hashes through the portal and permanently deletes the matching sample files and session data from the cloud within seven days, removing only session and upload data for samples that are not unique to the environment. Sample Retention Policy Sets how long an appliance keeps analyzed samples, with malicious and phishing samples retained indefinitely by default and benign and grayware samples for 1 to 90 days, defaulting to 14.
Logging & Reporting Analysis Reports Produces a per-sample report detailing file attributes, observed behaviors such as registry, file, process and network activity, targeted users, delivering application and command-and-control URLs, viewable inline from a log entry, on the portal or through the API and downloadable as PDF. Appliance Analysis Monitoring Reports appliance analysis activity from the CLI — samples processed over a chosen window, per-sample and per-signature status by hash, which device submitted a sample, the pending sample queue by type, per-environment analysis slot utilization, and filterable system event logs. Benign and Grayware Logging Toggle Extends submission logging beyond malicious and phishing verdicts to benign and grayware samples, which are excluded by default and never logged for email links. Email Header Fields in Logs Includes the sender, recipients and subject of a message in submission logs and analysis reports so a malicious attachment or link can be traced to the mailbox that received it, without the firewall or cloud storing message contents. Malware Alerting Forwards WildFire logs filtered by verdict to email server profiles, syslog, SNMP traps, Panorama or HTTP endpoints through a log forwarding profile attached to the forwarding security policy rule. Strata Cloud Manager Reporting Presents Advanced WildFire submission and analysis data from NGFW, Prisma Access and mobile users in a dedicated dashboard with a recent submissions widget, exposes WildFire entries through the Log Viewer as threat logs, and raises per-verdict WildFire incidents scoped to chosen devices and objects through the Unified Incidents Framework. WildFire Portal Monitoring Presents a per-firewall dashboard of malware, benign and pending sample counts, a searchable report list filterable by source and verdict, account time zone and log deletion settings, and per-verdict email notification checkboxes; the portal is being deprecated in favor of Strata Cloud Manager. WildFire Submission Logs Records a timestamped audit entry for every sample the firewall forwards once analysis completes, carrying the verdict, the allow or block action taken, a severity derived from verdict and action, the analyzing cloud, and session and email header context.
Sample Submission Blocked File Analysis Forwards files the firewall already blocked on an antivirus signature match in addition to unknown files, so the URLs, domains and IP addresses used by that malware variant are extracted, and records the matched threat log entry and threat ID in the submission log for the blocked file; files blocked by file blocking rules are not forwarded. Decrypted SSL Traffic Forwarding Forwards content the firewall has decrypted for analysis before it is re-encrypted, enabled globally or per virtual system and restricted to superuser administrators. File Forwarding Capacity and Size Limits Caps forwarding at a per-minute submission rate and reserved queue drive space that vary by firewall model from 5 files per minute on VM-50 to 300 on PA-7000 Series, and applies a configurable maximum file size per file type. Firewall File Forwarding Profiles Defines which traffic is forwarded for analysis through WildFire Analysis profile rules matched on application, file type, email links and transmission direction, attached to a security policy rule, and routed to a public cloud or private cloud analysis destination. macOS Dynamic Analysis Region Selection Enables macOS dynamic analysis forwarding and selects the preferred region among the US, EU, Japan and Singapore clouds that receives macOS samples, returning results to the configured home region after the temporary sample is deleted. Manual Sample Upload Accepts files and URLs uploaded by hand through the Strata Cloud Manager Advanced WildFire dashboard or the legacy WildFire portal, capped at five samples a day without a subscription and counted against the 1,000-sample daily limit with one. Session Information Forwarding Sends context alongside each sample — source and destination IP and port, virtual system, application, user, URL, filename and email sender, recipient and subject — with each field individually selectable and enabled by default. Submission Verification Tools Confirms a firewall is forwarding correctly through cloud connection status, per-file-type forwarding counters, per-sample upload logs split by public and private channel, and downloadable PE, APK, macOS and ELF malware test files that always return a malicious verdict.
Appliance Administration Analysis Resource Allocation Biases the appliance's concurrent analysis slots toward documents or executables instead of the balanced default, so a hybrid deployment can dedicate local capacity to the file types it keeps on premises. Appliance Content Updates Installs WildFire threat intelligence content on the appliance directly from the Palo Alto Networks update server or from an SCP-hosted package for disconnected sites, on demand or on an hourly, daily or weekly schedule with download-only or download-and-install actions. Appliance Hardware Management Manages appliance hardware from the CLI — adding, copying and removing drives in the RAID 1 pairs and reporting their state, and configuring the eth2 and eth3 interfaces including addressing, MTU, speed and duplex, permitted source addresses and ICMP. Appliance Initial Setup Brings a new appliance into service — management interface addressing and hostname, DNS, manual or NTP clock with symmetric-key or autokey authentication, support-portal registration, license fetch, and selection of the virtual machine image used for analysis. Appliance Software CLI Provides a hierarchical operational and configuration mode command line over SSH or serial console for WildFire-specific commands, with privilege levels, command option symbols, output format selection and output filtering. Appliance Software Upgrade Upgrades appliance PAN-OS one major release at a time and the guest sandbox VM images alongside it, migrating all malware samples and 14 days of benign samples during the process, with connected or SCP-based download paths. Sandbox VM Network Interface Gives samples running in the appliance sandbox isolated internet access on a dedicated interface so phone-home behavior is observable, optionally routing that traffic through the Tor network to mask the organization's public IP, and is disabled in FIPS/CC mode.
Verdicts & Signatures Appliance Local Signature Generation Generates antivirus and DNS signatures and assigns PAN-DB malware URL categories on the WildFire appliance itself from locally analyzed samples, and publishes them to connected firewalls as a private cloud content package retrievable as often as every five minutes. Early Static-Analysis Verdicts Publishes the verdict and the resulting protections for portable executables, ELF binaries, PDFs, APKs and Office documents as soon as static analysis completes rather than waiting for dynamic analysis to finish, with the fuller behavioral detail added to the analysis report afterward. Malware Signature Generation Generates antivirus signatures covering multiple variants for every sample judged malicious across web, SMTP, IMAP, POP, FTP and SMB traffic, and distributes them globally to all licensed firewalls through content releases. Private Cloud Cloud Intelligence Optionally lets a WildFire appliance query the public cloud for a verdict before analyzing locally, and submit locally discovered malware samples, analysis reports or diagnostics to the public cloud so a globally distributed signature is generated. Real-Time Signature Delivery Delivers newly generated signatures to subscribed firewalls in real time through cloud lookups cached locally, or on a five-minute publication cycle retrievable every minute, falling back to the 24-48 hour antivirus content package for unsubscribed firewalls. Verdict Change Requests Lets administrators submit suspected false positives and false negatives to the Palo Alto Networks threat team, and change a locally generated appliance verdict through the CLI or API with a comment, which regenerates or withdraws the corresponding private cloud signature. Verdict Classification Assigns each analyzed sample or link a verdict of benign, grayware, phishing, malicious or command-and-control, and shares verdicts from every public cloud region into a global threat database while keeping private cloud verdicts local.
Access & Credentials API Credential Lifecycle Management Creates, revokes and inspects cloud API credentials in Strata Cloud Manager — showing key string, product type, bound service account, expiration and a valid, expired, revoked or pending status — and migrates existing legacy keys onto service accounts in batch. API Key Authentication Authorizes API requests with a static key tied to the Customer Support Portal account and passed as a form field, retrievable from the WildFire portal or support portal, expiring with the subscription and slated for deprecation in favor of tokens. API Token Authentication Authorizes API requests with a 15-minute OAuth2 client-credentials Bearer token scoped to a Tenant Service Group ID and bound one-to-one to a Strata Cloud Manager service account, isolating submissions and results to a tenant. Appliance Administrator Accounts Creates local appliance administrators in a read-write superuser or read-only superreader role, authenticates them locally or against RADIUS, enforces an idle session timeout and failed-login lockout threshold, and holds a separate portal-admin password used to open analysis reports from the firewall. Appliance API Key Management Generates up to 100 named API keys locally on a WildFire appliance and lists, renames, enables, disables, deletes, exports over SCP and bulk-imports them in merge or replace mode from the CLI. WildFire Portal User Accounts Lets the registered device owner grant additional users portal access scoped to specific firewall serial numbers, including users without a Palo Alto Networks support account, excluding free web-mail addresses.
WildFire API API Artifact Retrieval Downloads the original sample file, the packet capture recorded during analysis for a chosen analysis platform, and the screenshots and downloaded files captured during URL analysis, with malware samples retained ten years, grayware fourteen days and packet captures ninety days. API File Submission Accepts a local file or a remotely hosted file URL for analysis and returns the detected file type and SHA-256 and MD5 hashes, with a base64-encoded filename context required for script, markup and ASP.NET submissions. API Link Submission Submits a single website URL or a text file of up to 1,000 URLs for analysis and returns the original URL with its hashes, analyzing only the specified page rather than traversing links on it. API Malware Test File Serves a PE, macOS, APK or ELF malware test file with a fresh hash on each download, without requiring authentication, for end-to-end verification of sample processing. API Report Retrieval Returns the analysis report for a sample hash as XML, PDF or MAEC, or for a web page URL as JSON with an indication of whether the match was exact or a best guess. API Verdict Retrieval Returns the verdict for a hash or URL, for a batch of up to 500 hashes in a single request, or the list of appliance samples whose verdict changed since a date within the last 30 days, using numeric codes that distinguish pending, unknown, error and invalid-hash results.
Service Connectivity Advanced Forwarding Transport Replaces the legacy cloud submission path with a pool of TLS connections established directly from every data-plane core, sized to the hardware platform, with service addresses assigned dynamically by a geographic discovery service, now configurable for Prisma Access in addition to NGFW. Cloud Connectivity Diagnostics Reports the state of the connection to cloud analysis services through CLI commands that show inline ML cloud status, discovery service job results, the assigned service FQDNs and health checks, and the active data-plane connection list. Content Cloud FQDN Selection Overrides the automatic nearest-server resolution for cloud content requests with an explicitly chosen regional endpoint from nineteen locations, to satisfy data residency or latency requirements across all services that share the connection. Inline Cloud Proxy Support Routes inline cloud analysis and forwarding traffic through an explicit proxy server configured once in the firewall service settings or through the CLI, applying to all Palo Alto Networks update and inline cloud services.
Inline Enforcement Inline Cloud Analysis Holds a portable executable in transit while cloud machine-learning detection engines analyze it in a real-time exchange, blocking never-before-seen malware per rules matched on application, file type and direction, with configurable maximum latency and an allow-or-block action on timeout. Inline ML File Classification Applies machine-learning models on the firewall dataplane to classify portable executables, ELF binaries, Office and OOXML documents, Mach-O binaries, and PowerShell and shell scripts in real time, with a per-model action of enable, alert-only or disable and file-hash exceptions for false positives. Real-Time Signature Hold Mode Holds a file transfer while the firewall performs a real-time signature cloud lookup and releases or blocks it on the result, with a global lookup timeout and an allow or reset-both action when the timeout is exceeded, enabled per antivirus profile.
Subscriptions & Licensing API Request Quotas Meters API use against a daily allowance of 150 sample uploads and 1,050 report queries per subscription that resets at 00:00 UTC, caps samples at 100MB, exposes remaining uploads and queries per credential, and charts 90 days of usage and overages per key. Standalone API Subscription Sells API-only access to the analysis cloud for SOAR tools and custom security applications without a forwarding firewall, with scalable licensed volumes of sample submissions, report queries, or a mix of the two. Subscription Tiers Gates functionality across a no-subscription basic service limited to portable executables on 24-48 hour signature updates, a WildFire subscription adding advanced file types, real-time updates, inline ML, API access and private cloud forwarding, and an Advanced WildFire subscription adding run-time memory analysis and inline cloud analysis.
The agentic automation layer — AI agents that plan and execute security workflows across the Cortex platform, with their own API and gateway.
Platform Administration API keys Issues standard or hashed advanced API keys bound to a predefined or custom role, with an optional expiry date, for authenticating API and MCP server calls. Customer Support Portal authentication Signs users in with Customer Support Portal credentials and optional two-factor authentication as the default method, with the first Super User becoming Account Admin. Data retention Retains cases, issues and Agentic Assistant chats for six months by default, dated from case last-update and issue observation time, extendable through a retention add-on. Health issues Raises and tracks health issues on tenant resources such as data ingestion and correlation rules, with guidance for investigating and resolving each one. In-product support tickets Opens a support ticket from inside the tenant through a wizard that attaches tenant and licence context, uploaded logs and an optional console recording. Licensing and add-ons Licenses the tenant per user on a yearly or multi-year term and exposes purchasable add-ons such as extended compute units and extended retention, with a fair-usage policy. Management audit logs Records every administrative and investigative action for 365 days in a filterable table, including knowledge-source changes and overridden automation exclusions. Notification forwarding Forwards cases, issues and logs on a filter to email, Slack, a syslog receiver, Amazon S3, Amazon SQS, Splunk or a webhook, after the external application is registered in the tenant. Object-level access Sets owner, shared and public access on individual user-defined objects such as playbooks, scripts, saved queries, dashboards and report templates, combining with role permissions to decide what a user may open or edit. Public REST API Exposes the tenant over REST across cases and issues, correlation rules, playbooks, scripts and script execution, datasets and lookups, XQL and saved queries, dashboards and widgets, syslog servers, the audit log, system management, and platform IAM users, groups, roles and scopes. Roles and RBAC Grants None, View or View/Edit on each product component through predefined or custom roles, which also govern which datasets a user may query, with a per-component permission reference. SAML single sign-on Authenticates tenant users through any SAML 2.0 identity provider, with documented setups for Okta and Microsoft Entra ID, and maps IdP groups onto tenant user groups. Scope-based access control Narrows what a user, group or API key can see to an assigned data scope on top of their role, enabled tenant-wide from server settings and off by default. Security settings Sets session length and restricts which email domains and IP ranges users may sign in from. Server settings Configures tenant-wide and per-user preferences including keyboard shortcuts, timezone, timestamp format, custom logos on communication-task emails, and the scope-based access control switch. Supported regions Hosts a tenant in a chosen region so its logs and ingested data stay within that country's boundaries, across the Americas, EMEA and APAC region list. Tenant activation Activates a tenant from Cortex Gateway against a support account, one activation per tenant, followed by deployment and post-deployment checklists. User groups Assigns permissions through groups that each carry a single role and can be nested, mapped to SAML groups, with a user in several groups receiving the combined highest level of access. User management Lists and administers tenant users from Cortex Gateway or the tenant Access Management page, showing status, assigned roles and group membership.
Investigation and Response AI case summaries Generates a case title and narrative description from the underlying issues and artifacts using LLM summarization, and suggests remediation actions during resolution. Asset and artifact investigation Groups the entities in a case by class, opens an asset card per entity, hands an entity to the Agentic Assistant with a generated prompt, and provides guided flows for IP addresses, file and process hashes and contributing events. Case card Presents a case as an overview of context, evidence, assets and artifacts, with a table-based Detailed View over the same data using custom layouts. Case grouping Consolidates related issues, assets and artifacts into one case using machine-learning grouping logic, and explains the linkage in a grouping graph of the shared artifacts and relationships. Case merge and issue linking Merges cases, links and unlinks issues from a case, copies issues, stars them, and closes an issue or resolves a case with a resolution reason. Case teams Assigns users and user groups to roles on a case and optionally restricts the case so only team members can view or act on it. Case timeline Records attack events, analyst activity and system actions in chronological order, viewable as a grouped journal or a detailed table, and accepts manually added records. Cases queue Lists every case with its status, severity, score, star and SLA adherence as the starting point for monitoring and triage. Evidence Collects the technical data behind an issue into a schema-based view on the case overview and the issue card, alongside analyst-added notes, mapping the attacker's path. Issue card Breaks an issue down into tabs adapted to its type, covering root cause, evidence, remediation guidance and response options while retaining the parent case context. Issue exclusion Removes an issue from the queue and future matching issues through an exclusion list, so recognised benign activity stops surfacing. Issue export Exports the filtered issues table to a tab-separated file, up to 50,000 issues per export. Issues queue Consolidates non-informational issues from every detection source in a filterable table defaulting to the last seven days, each row linked to the cases it belongs to. MITRE ATT&CK mapping Labels issues with the MITRE ATT&CK tactics and techniques they match so an investigation can be read against the framework. Notes and comments Keeps a shared Notepad of evidence and investigative steps and a Comments panel for team discussion inside the Resolution Center. Resolution Center Drives a case to closure from tabs of pending, in-progress and completed remediation actions across its issues, including agent tasks awaiting approval, with playbooks runnable in case context. War Room Gives each case and issue a ChatOps workspace holding an audit trail of every automatic and manual action, where analysts run CLI commands, playbooks and scripts and capture output as case context. Work Plan Shows the playbook running on an issue as a live graph that follows execution task by task, and lets an analyst add or adjust tasks for that specific investigation.
Automation and Playbooks AI prompts Creates, edits and reuses saved prompts that playbook AI Prompt tasks and agent actions run, with role-based access control over who may use or change each prompt. Automation Engineer Generates playbooks and automation scripts from a natural-language description, including integration wiring and trigger setup, and presents the generated changes for review. Automation exclusion policies Blocks commands and scripts from remediating assets named in a list, whether run from a playbook, a Quick Action, an agent or the CLI, with optional per-policy overrides recorded in the audit log. Automation rules Triggers a playbook, a Quick Action or an AI agent when a newly created issue matches defined conditions, with rules executed under system rather than user scope. Automation scripts Authors and runs Python, JavaScript and PowerShell scripts as playbook tasks or standalone CLI commands, with arguments, password protection, API access and a selectable Docker image. Communication tasks Sends a templated message to internal or external recipients from a playbook task and holds the playbook until the reply arrives, feeding the answer back into the workflow. Context data Holds a per-case and per-issue key-value map that carries data between playbook tasks, and supports adding, searching, extending and deleting entries from the UI or a playbook. Jobs Schedules a playbook to run on a recurring time trigger or when a feed delivers a delta, and lists past and pending job runs. Lists Stores reusable text, Markdown, HTML, CSS or JSON data that playbooks, scripts and exclusion policies read through the context path, with commands to add, edit and query entries. Playbook editor and Task Library Builds a playbook from standard, conditional, manual and section-header tasks pulled from a Task Library, including sub-playbooks and sub-playbook loops, with per-playbook settings and script error handling. Playbook filters and transformers Filters and reshapes context data inside a playbook using built-in filter and transformer categories, and accepts custom filters and transformers written as scripts. Playbook testing and troubleshooting Runs a playbook against test data to inspect task-by-task results before deployment, and reports performance problems in a running playbook. Playbooks Runs visual response workflows that query data, call integration commands and update case and issue fields, drawn from a catalog of out-of-the-box playbooks or built from scratch. Quick Actions Runs a preset single integration command against one or more issues, either manually from the issues table or from an automation rule, against all matching integration instances or a chosen one.
Cases and Issues Case and issue domains Separates work streams into built-in and custom domains so each can carry its own workflow and prioritization, with domain-aware content and grouping behaviour. Case and issue layouts Composes custom case and issue layouts from field sections and custom widgets, and applies layout rules that select which layout a record is shown in. Case and issue model Represents security work as issues raised when ingested data crosses a threshold and cases that group related issues with their impacted assets, each with its own lifecycle and statuses. Case scoring Assigns a score to a case from user-defined scoring rules and sub-rules that match issue attributes, optionally counting only the first matching issue in the case. Correlation grouping field mapping Maps fields emitted by a correlation rule onto the grouping artifacts the machine-learning grouping model uses, so issues raised by custom detections join the right case. Correlation rules Generates issues from scheduled XQL rules that correlate events across multiple data sources on a defined time window and schedule, managed under Detection Rules. Custom case and issue fields Adds custom fields to cases and issues across the supported field types, including grid fields, and edits the attributes and default values of built-in fields. Custom statuses and resolution reasons Defines custom case statuses and the resolution reasons offered when a case or issue is closed, alongside the built-in set. Field-triggered scripts Runs a tagged script whenever a case or issue field changes, optionally gated on the new value, and saves the field only once the script completes. Issue exception rules Records a time-bound decision to defer remediation of a confirmed issue, pausing its SLA timers for a grace period, routed through an approver workflow and listed on an excepted-issues view. Issue syncing Mirrors issues with tickets in external systems such as Jira or ServiceNow through sync profiles, in an outbound, inbound or bi-directional direction, and links the ticket on the issue card. Starring configurations Stars issues and their linked cases automatically when they match filter criteria such as severity, category or affected asset, respecting scope-based access control. Timers and SLAs Tracks elapsed time on cases and issues through timer fields that start, pause and stop on defined criteria, links them to SLA fields that count down, and drives them from playbooks or CLI commands.
Threat Intelligence Extended Threat Intelligence Provides a Unit 42-curated library of threat actor and malware profiles plus XTI indicators, surfaces that context on cases and issues, and makes it queryable from XQL, playbooks, the threat intel dashboard and the Threat Intel agent. External dynamic lists Hosts IP address and domain name lists of tenant indicators as text files that firewalls and other products fetch for their block and allow lists. Indicator classification and mapping Maps ingested indicators from each detection and feed method onto indicator types and fields, including custom field mapping. Indicator detection rules Generates issues when indicators or indicator traits selected for detection are observed in tenant data. Indicator exclusion Deletes indicators or adds them to an exclusion list so they are not recreated, and excludes named indicators from enrichment. Indicator expiration Ages indicators out with an expiration policy per type or source, flipping expiration status through a daily job while keeping the record searchable. Indicator export Exports indicators from the indicators table as CSV or STIX, or continuously through an export integration or playbook. Indicator extraction and enrichment Extracts indicators from War Room entries, email bodies and other text using regex, enriches them from configured reputation sources, and sets the extraction mode per playbook task or disables it for named scripts and integrations. Indicator repository Stores indicators such as IP addresses, URLs, hashes and email addresses through a defined lifecycle, with relationships between indicators and an investigation view over each one. Indicator types and fields Defines custom indicator types and fields with type profiles, formatting and enhancement scripts, and field-change trigger scripts. Indicator verdict and reputation Assigns a verdict from the highest-reliability source using the Admiralty reliability matrix and takes the worst verdict on ties, backed by reputation commands and reputation scripts. Threat intelligence feeds Ingests indicators from feed integrations installed as content packs, on a per-feed schedule and reliability, optionally routed through an engine to avoid source-IP rate limits.
Dashboards and Reporting Cloud consumption dashboard Tracks workload consumption across connected cloud accounts and providers, normalized into a single workload unit and broken down by asset type with account-level history. Custom XQL widgets Creates chart widgets from an XQL query with a chosen visualization, public or restricted visibility, and parameters that drive dashboard filters and drilldowns. Dashboard and report sharing Controls who can open or edit a dashboard or report template through role and scope permissions, per-object sharing, visibility settings and ownership transfer. Dashboard and template import/export Exports and imports dashboards and report templates as JSON files, singly or in bulk, to back up content or move it between tenants. Dashboard drilldowns Links a widget to an XQL search, a custom URL, another dashboard or a report so a click moves the viewer into the underlying detail. Dashboard global filters Adds up to four free-text, single-select or multi-select filters that change the data scope of every parameterized widget on a dashboard or report. Dashboards Builds custom dashboards from widgets and administers them in the Dashboard Manager, where they can be duplicated, renamed and deleted. Reports and report templates Generates static reports from system or custom templates, keeps them with their attachments on a Generated Reports tab, distributes them by email or Slack, and raises a notification when a run fails. Script-based widgets Renders a widget from a script so it can perform custom calculations or pull data from third-party systems, with the visual presentation set in the Widget Library. System and Command Center dashboards Ships read-only platform dashboards, including the Command Center landing view over posture, assets at risk and open cases, an Agentic Assistant dashboard and cloud security operations views, each duplicable into an editable copy. Widget Library Holds dashboard and report widgets in a shared repository that can be searched and filtered by name, type, owner or dataset and previewed before being added to a layout.
Data Sources and Connectors Classification and mapping Classifies fetched raw events into issue types on a chosen attribute and maps event attributes onto system and custom issue fields through default and per-type mappers. Connector catalog Groups each vendor's collection, automation and remediation sub-capabilities into one named connector configured through a guided wizard, with selective enablement of individual sub-capabilities. Credentials vault Stores usernames, passwords, certificates and SSH keys once and reuses them across integrations and connectors without exposing the secret in the instance configuration. Custom integration authoring Builds an integration in the tenant by importing an integration file or starting from a template, defining parameters, commands, arguments and outputs alongside Python code. Ingestion health monitoring Reports per-source ingestion volume, size and rate on five-minute aggregation windows, measures data freshness, verifies collector connectivity, and raises health issues from correlation rules over those metrics. Integration instances Configures, tests, enables and disables multiple instances of an integration against different environments from the Data Sources and Integrations page. Integration permissions Restricts the commands of an integration instance to named roles, so only permitted users and the agent actions built on those commands can run them. Issue fetching from integrations Pulls events from a configured integration instance on an interval and turns them into issues, with a first-fetch window and per-instance fetch filters. Long-running integration request forwarding Exposes long-running integrations hosted on the tenant or an engine to third-party software through forwarded inbound API requests, subject to a per-tenant request rate limit. Palo Alto Networks product connectors Ingests from and acts on Palo Alto Networks' own products, covering the Next-Generation Firewall, Panorama, Prisma, Cortex XDR, Cortex Data Lake, WildFire, IoT Security, Enterprise DLP, Threat Vault and PSIRT advisories. Standard data sources Collects raw logs and events directly from vendor APIs and files through the Data Source Onboarder, normalizing them into the Cortex Data Model.
Agentic AI Agent actions Wraps playbooks, scripts, integration commands and AI prompts as actions an agent can invoke, with more than 50 out-of-the-box system actions plus custom actions registered from the hub, the Scripts page or the AI Prompts page. Agent chat from Slack Lets a user address an agent by tagging the configured bot in a Slack thread, matching Slack email to tenant user to apply that user's permissions, with a two-week session timeout. Agent knowledge sources Grounds agents in uploaded documents or linked external pages alongside built-in Cortex product knowledge, tracking indexing status and tenant capacity and citing which source an answer drew on. Agentic Assistant chat Runs a natural-language conversation with a chosen agent, exposing the plan and the actions it is executing as it works, with conversation starters and a chat history grouped by time period that can be renamed, resumed or deleted. Agentic Assistant Hub Provides a console where agents and the actions assigned to them are listed, searched, filtered and sorted, and where an agent card shows every assigned action and whether it is enabled, disabled or blocked by missing content. Agentic Response Triggers an agent from an automation rule to run autonomously on a matching issue using a prompt bound to issue fields, exposing its reasoning, plan and run status on the issue and in the Resolution Center. Cortex MCP server Ships a downloadable MCP server, run in a container or a Python environment, that exposes tenant cases, issues, assets and endpoints as tools to any MCP client, and accepts custom tools defined in OpenAPI or Python. MCP integrations for agents Connects agents to external MCP servers over streamable HTTP with OAuth or authless configurations, rediscovering server tools hourly and registering each as an agent action scoped by integration permissions. Sensitive action approval Marks actions that change production systems as sensitive so an agent pauses and raises a pending task for an analyst to approve or deny before it continues, with the sensitive flag settable per action. System and custom agents Ships system agents for defined SOC use cases and lets users build custom private or public agents, each with a model, a set of assigned actions and instructions, executing only within the invoking user's roles and scope.
Query and XQL Natural-language querying Turns a natural-language prompt into an XQL query, runs it and returns the result as a chart, either in the Agentic Assistant chat or when creating a dashboard widget. Query Builder Builds queries without writing XQL from basic and free-text templates over the full data model, with a legacy mode that queries predefined datasets by process, file, network, registry, image-load, event-log or authentication entity. Query Center Lists every query run on the tenant and those in progress, and lets a user re-run, adjust, schedule or cancel one and inspect who cancelled it. Query Library Saves queries to a personal library and optionally shares them with other users on the tenant, alongside the queries others have shared. Query result graphing Renders XQL query results as graphs from the results page and exports the output for sharing. Scheduled queries Runs a saved query on a recurrence, listing past executions and allowing each schedule to be edited, disabled or removed. Splunk query translation Converts a pasted Splunk SPL query into XQL in the query field when the Translate to XQL toggle is enabled. XQL language Queries ingested data with the Cortex Query Language across raw datasets and the Cortex Data Model, with stages, operators, string and JSON functions, comments and cross-entity queries. XQL macros Stores reusable XQL fragments in a Macro Library that are substituted into a query by a pre-processor before compilation.
Data Management Compute units Meters XQL query API usage against a yearly compute-unit quota sized by licence, fails queries that exceed it, and raises the allowance through a purchasable add-on. Agentic and LLM usage is shown for information only and does not consume compute units. Dataset activity monitoring Reports which datasets and dataset views are being queried and how heavily, so unused or expensive datasets can be identified. Datasets Stores ingested events in datasets that XQL queries run against, with built-in and custom datasets, dataset views and presets, and per-dataset retention. Event forwarding Exports ingested and parsed event logs to an external Google Cloud Platform storage bucket with a Pub/Sub subscription, for retention outside the tenant. Lookup datasets Correlates externally supplied name-value data such as asset lists or terminated employees against ingested events, imported from file, downloadable as JSON, and expirable with a time to live.
Engines Engine container hardening Constrains engine containers through configuration keys for memory, CPU, PID and file-descriptor limits, non-root internal users and network hardening, with a check that verifies the applied settings. Engine container runtimes Runs engine workloads in Docker or Podman containers, covering installation on supported distributions, image and storage configuration, pull rate limits and migration between the two runtimes. Engine network configuration Routes engine traffic through a web proxy or an NGINX reverse proxy, bypasses the proxy for direct server calls, and installs custom certificates on the engine. Engines Installs a proxy application on a remote machine that runs playbooks, scripts, commands and integrations locally and returns results to the tenant, with load-balancing groups, upgrade and removal.
Marketplace and Content Content pack contributions Submits customer-authored content packs for review through a pull request to the public content repository, after which approved packs are published to Marketplace. Cortex Marketplace Browses and installs content packs bundling integrations, playbooks, scripts and widgets, tracks their updates and dependencies, and labels each pack with its support type. Remote repository content promotion Develops content on a marked development tenant and promotes it to production by pushing to and pulling from a built-in or private Git remote repository, reachable directly or through an engine.
Application security posture — code, pipeline and supply-chain risk taken from version-control, CI and registry data sources and traced through to the running cloud resource.
Data Source Onboarding AppSec Transporter over Broker VM Runs a Transporter applet on a Broker VM inside the customer network that opens an outbound WebSocket tunnel to the tenant and proxies scanning traffic to self-hosted version control systems and SonarQube servers on private domains, with multiple named connections per applet. AWS CodeCommit Version Control Integration Connects AWS CodeCommit through a CloudFormation template that creates a cross-account IAM service role guarded by a tenant-specific External ID and an SNS topic that pushes repository events to the platform webhook. Azure DevOps Version Control Integration Connects Azure DevOps organizations through a Microsoft Entra ID service principal, Entra ID user authentication, or a personal access token, and reports connection health separately at instance and repository scope. Bitbucket Version Control Integration Connects Bitbucket Cloud over OAuth 2.0 with automatic token refresh, and Bitbucket Data Center 8 and later over a personal access token, subscribing to repository and pull request events for both. CI Tool Onboarding for Code Scans Onboards a CI platform for code scanning through a wizard that generates a Cortex API key pair and the matching pipeline snippet, covering AWS CodeBuild, CircleCI, GitHub Actions and Jenkins. CI/CD System Onboarding Onboards CircleCI with a personal access token and Jenkins with a downloadable plugin and JWT connector so the platform can scan CI/CD instance, pipeline and repository configuration; VCS-native pipelines are covered by the VCS integration instead. CLI Pipeline Code Snippets Publishes ready-to-paste pipeline definitions that download and run the Cortex CLI on amd64 and arm64 Linux runners for AWS CodeBuild, Azure Pipelines, Bitbucket, CircleCI, GitHub Actions, GitLab Runner and Jenkins. Egress Path Configuration Defines the outbound route the tenant uses to reach third-party services on public domains and publishes the regional egress proxy IP addresses to add to a customer allow list. GitHub Version Control Integration Connects GitHub Cloud organizations through the shared Cortex GitHub App or a new or existing customer-owned GitHub App, and GitHub Enterprise Server through a registered OAuth application, selecting which repositories are scanned and provisioning the repository and organization event subscriptions. GitLab Version Control Integration Connects GitLab SaaS and GitLab Self Managed instances through an authorized application holding the api scope, selects repositories to scan, and subscribes to push, merge request, tag and note events. Integration Instance Lifecycle Management Lists every onboarded data source instance with its connection status and ownership model, and supports editing, deleting, rotating credentials on, and running repository-level actions against an instance from the Data Sources page. Private Package Registry Onboarding Connects a JFrog Artifactory Cloud or self-hosted instance with a registry URL and credentials so the SCA scanner can resolve private dependencies per package manager and build accurate dependency trees. Terraform Run Task Integration Registers a run task on HCP Terraform or Terraform Enterprise workspaces that scans the plan for IaC misconfigurations, secrets, dependency vulnerabilities and licence issues, and returns a pass or block verdict to the run. VCS Permission Requirement Checks Evaluates a customer-owned GitHub App against the permissions each feature group needs — periodic scans, pull request scans and automatic fix pull requests — and raises a warning on the integration when a permission is missing or held at too low a level.
Applications & Asset Inventory Application Criteria Engine Continuously generates and maintains applications from rules — code criteria grouping assets by VCS organization, project or repository across several providers with merge and unify options, and cloud criteria grouping resources by tag key-value within one cloud account. Application Scope-Based Access Control Restricts a user to the applications explicitly assigned to them under an implicit-deny model, scoping the assets, issues, dashboards, command center and coverage data they can see to those applications. Asset Groups Defines static or predicate-driven dynamic collections of assets that scope policy evaluation, compliance assessments and scope-based access control, manageable from the console or through Terraform. Business Applications Groups code, dependency, infrastructure and runtime assets into named business applications carrying criticality, description and business owner metadata, built manually through the application builder, by criteria, or through the public API. CI/CD Instance & Pipeline Assets Discovers CI/CD platform instances and the pipelines they execute as assets carrying provider, URL, version, definition file path, build activity, aggregated configuration risk and deployment lineage. IaC Resource Assets Registers every infrastructure resource defined in a scanned template as an asset carrying its resource type, framework, cloud provider, source file path and line range, with dashboard breakdowns by provider and framework. Repository Assets Registers every repository reached through a VCS integration in the unified asset inventory with its provider, organization, visibility, default branch, scan coverage, ownership context and deployment lineage, and exposes it through the console and the repositories API. Repository Technology Detection Analyses files during a repository scan to detect the languages, frameworks, infrastructure formats and package managers a repository uses, and reports each as a tag with its proportional share of the codebase. Software Package Assets Registers every open-source and third-party dependency declared in a scanned manifest as an asset carrying its version, licence, package manager, direct or transitive classification, operational risk rating and associated CVEs, with a dependency tree view. VCS Collaborator Assets Inventories the human and non-human identities with access to version control repositories and pipelines, flagging recently added and inactive collaborators and linking the issues associated with each. VCS Organization Assets Discovers each connected version control organization as a top-level governance asset and aggregates the security posture, repository count, scan coverage percentage and internet exposure of everything beneath it.
Risk Prioritization & Remediation Application Security Dashboard Summarizes SDLC posture with asset count cards, top issues to address, open issues by Urgency and scan type, SLA breach counts by scanner and backlog trend widgets, filterable by application, repository, pipeline and backlog status. AppSec Agentic Assistant Answers natural-language questions about a selected repository, package, IaC resource, VCS organization, pipeline or coverage figure from the asset table or side panel, respecting the asking user's role and scope restrictions. AppSec Coverage Page Measures how much of the discovered estate is under active scanning — by data source, by scan status and by scanner type — and offers an Increase Coverage action that enables missing scanners or launches the onboarding wizard. AppSec Objectives with Agentix Turns a natural-language goal into a tracked remediation objective by mapping the prompt to an asset scope and issue condition, then builds a dedicated dashboard and synchronizes remediation, detection and prevention rates and open case counts against it. ASPM Command Center Presents a prioritization funnel that carries the total findings and issues from connected sources through guardrail filtering and Urgency ranking to actionable cases, tracking SLA and MTTR and surfacing supply-chain breach alerts. Backlog & New Classification Separates pre-existing security technical debt from newly introduced issues per branch and per scanner using a historical baseline point, and exposes the classification as a filter, a policy condition and a dashboard trend. Findings Inventory Exposes raw scanner output on a Findings tab beside every issue type so scanner coverage can be audited, findings suppressed or never matched by a policy can be reviewed, and policy gaps identified. Issue Tables & Insight Widgets Gives each issue type a dedicated table with a shared column model plus type-specific attributes, topped by Urgency or severity, SLA and insight widgets that pair a risk tier with a second dimension and filter the table on selection. Issue Triage Lifecycle Deduplicates raw findings into issues when they match a policy, then carries each issue through status, assignee, backlog status, case escalation and a resolution tab offering fixes, suppression or compensating controls. SLA Tracking Applies a configurable remediation deadline per severity level and a configurable approaching threshold, then recalculates each issue's status as On Track, Approaching or Overdue on every periodic scan and surfaces it across dashboards, tables and side panels. Urgency Prioritization Ranks issues as Top Urgent, Urgent, Not Urgent or Not Applicable by combining exploit probability signals such as EPSS, CISA KEV and reachability with impact signals such as deployment status, internet exposure, application criticality, sensitive data access and runtime agent coverage.
Code Security Scanners IaC Drift Detection Compares deployed cloud resources against the IaC templates that declared them and raises a drift issue only where the runtime resource violates a security rule its template does not, so expected operational variance is not reported. IaC Misconfiguration Scanner Detects security misconfigurations in infrastructure-as-code templates before deployment across Terraform, Terraform Plan, OpenTofu, CloudFormation, Kubernetes, Helm, Kustomize, ARM, Bicep, Ansible, Dockerfile and OpenAPI definitions. License Compliance Scanner Identifies the SPDX licence attached to every open-source dependency and flags non-permissive, strong copyleft and weak copyleft obligations as licence miscompliance findings. Malicious Package Detection Matches every SBOM component against the OSV.dev malicious packages dataset and raises a dedicated Critical issue for each confirmed typosquat, backdoor or hijacked version, covering direct and transitive dependencies and packages that carry no CVE. Package Operational Risk Scanner Scores each open-source package on maintenance and popularity signals read from its registry and raises an issue for packages that are deprecated, unmaintained or unpopular, feeding the result back as a secondary signal in vulnerability Urgency. SAST Code Weakness Issues Presents static analysis findings as code weakness issues linked to a CWE identifier, detection rule, file path and line range; the detections come from ingested third-party SAST vendors and SARIF uploads rather than a native SAST engine. SBOM Generation Produces a machine-readable software bill of materials in CycloneDX and SPDX format from the native SCA scanner during branch periodic scans and from the CLI, and exposes it for programmatic download. SCA Vulnerability Scanner Inventories open-source dependencies from manifest and lock files and detects known CVEs in them, covering direct dependencies statically and transitive dependencies where a lock file is present, with root fix detection on supported languages. Secrets Scanner Detects hardcoded credentials, API keys, tokens, certificates and private keys in plaintext files using signature and keyword-anchored entropy analysis, optionally scanning Git commit history and validating whether a detected secret is still active.
Policy & Rule Governance AppSec Role & Permission Model Ships AppSec Admin, DevSecOps, SOC Analyst and Instance Administrator roles and per-surface view and edit permissions covering data sources, policies, rules, issues and each scan type, which gate every console and API action. AppSec Rules Inventory Lists the out-of-the-box and custom detection rules covering IaC, secrets, SAST, SCA and CI/CD risk, with severity, scanner, category, framework, labels, mapped compliance controls and the number of policies using each, and allows rules to be enabled or disabled. CI/CD Configuration Policies Governs CI/CD risk findings through their own policy type, filtered by severity, backlog status, provider, rule, rule label and OWASP CI/CD subcategory, scoped to pipeline, instance, collaborator and organization asset types. Custom Rule Authoring Creates IaC and secrets detection rules from scratch or by cloning an existing rule, defining severity, category, framework and detection logic through a UI builder or YAML attribute and connection-state conditions, and applies them to periodic, pull request and CI scans. Policy Efficiency & Audit Logging Reports per policy how many issues it created and how many pull requests and CI pipelines it blocked in total and over the last seven days, and records every policy creation, edit, deletion and status change in the management audit log. Policy Grace Periods Suspends a blocking action on a vulnerability for a configured number of days measured from the fix date or, where none exists, the publish date, recording the match and noting the remaining days in the pull request or CLI output. Unified Application Security Policies Defines in one policy the finding types and condition filters to match, the asset and application scope to evaluate, the triggers to fire on — pull request, CI, periodic and image scans — and the actions to take, including blocking a merge or build, commenting, creating an issue and overriding severity.
Software Supply Chain Security Agentix Package Recommendations Generates data-driven safer-alternative recommendations for a package carrying high operational risk or multiple CVEs, seeded from the package side card with a prompt scoped to the selected package and version. Artifact Trust Score Aggregates SBOM risk, vulnerabilities, malicious packages and CI/CD posture into a percentage trust score and one of four trust bands for container images, container instances, VM images and VM instances, with an evidence table ranking findings by their contribution to the score. CI/CD Risk Scanner Detects insecure configuration in version control organizations, repositories and CI/CD pipelines — poisoned pipeline execution, excessive workflow permissions, missing branch protection, unpinned images and insecure runner credentials — and classifies each against the OWASP CI/CD Top 10. Package Explorer Consolidates every open-source and operating-system package found across code repositories, registry images and runtime workloads into one inventory showing usage context, operational risk, malicious and deprecated insights, CVE exposure and licence. Supply Chain Attack Catalog Maintains a curated catalog of notable supply-chain attacks with their compromised packages, tools and CVEs, correlates each against the tenant's packages, repositories, pipelines and runtime assets to determine exposure, raises a breach banner, and offers a Block in CI action pinned to package name and version. Supply Chain Catalog Publishes a platform knowledge base of recognized supply-chain tools and their associated risk factors, to be cross-referenced against the detected tools inventory when assessing exposure or evaluating a tool before adoption. Supply Chain Tools Inventory Inventories the third-party pipeline plugins and VCS applications detected in the environment — GitHub Actions, Jenkins plugins, CircleCI orbs and Azure extensions — with creator, category, usage evidence, CVE exposure and an approved, rejected or uncategorized status.
Third-Party Findings Ingestion Checkmarx Findings Ingestion Ingests Checkmarx One SAST code weakness and SCA vulnerability and licence findings on a polling cycle, authenticating with an API key or OAuth client and mapping Checkmarx projects to Cortex repositories. Generic 3rd Party AppSec Collector Creates a named collector with its own credentials and upload endpoint that accepts SARIF 2.1.0 files from any SAST tool, validates the file structure before use, and resolves each result to an onboarded repository. Semgrep Findings Ingestion Periodically ingests Semgrep SCA and SAST scan results using a Semgrep API token with the Web API scope, producing CVE findings, software package assets and CWE-classified code weaknesses. Snyk Findings Ingestion Ingests SCA dependency vulnerabilities and SAST code findings from a Snyk organization using an organization-scoped API token, with regional API hosts for US, EU and AU tenants. SonarQube Findings Ingestion Ingests SAST findings from SonarCloud, from a directly reachable SonarQube Server, or from an on-premises SonarQube Server routed through the AppSec Transporter, mapping SonarQube projects to Cortex repositories. Third-Party Finding Normalization Normalizes ingested vendor findings into the platform data model, tags each with its originating data source, deduplicates identical detections at the issue level, and evaluates them against the same unified policies, Urgency scoring and access scoping as native scans. Veracode Findings Ingestion Ingests Veracode SAST findings from periodic and CLI scans using a Veracode access key, automatically mapping Veracode applications to Cortex repositories with an option to map future applications.
Developer Workflow Integration Automatic Fix Pull Requests Opens a pull request in the source repository carrying the suggested remediation for a detected issue, gated on the integration holding write access to repository contents and pull requests. Cortex CLI AppSec Module Scans a local directory for IaC misconfigurations, dependency vulnerabilities, licence issues and secrets from a workstation, Git hook or pipeline, evaluates the results against unified policies, and emits JSON, SARIF, CycloneDX, SPDX or JUnit XML with an exit code that gates the build. Developer Suppressions Suppresses a specific rule, CVE or licence detection from the source file itself using inline skip comments and Kubernetes annotations across Dockerfiles, manifests, CloudFormation templates and dependency files, with an optional justification. JetBrains Plugin Scans the open project across all JetBrains IDEs for the same code security categories, presenting an issue tree and per-issue details in a docked panel with inline editor markers and remediation options. Pull Request Comment Feedback Posts scan results as a pull request comment describing each detection and the required action per category, and updates the comment across commits to record fixes and regressions for previously reported findings. VS Code Extension Scans the open workspace from Visual Studio Code and VS Code-compatible editors for secrets, IaC misconfigurations, dependency vulnerabilities, licence issues and package operational risk, showing findings in a category tree with inline remediation, fixes and suppression.
Scan Execution & Health Branch Periodic Scans Runs every enabled scanner against the configured branches of each onboarded repository on a fixed schedule to establish the security baseline, and supports rescanning a repository whose scan errored or completed partially. CI Scans Evaluates the code a build pipeline is about to package when the Cortex CLI or a Terraform run task executes, returning a non-zero exit code or a blocking run-task verdict when a finding matches a policy carrying the Block CI/CD action. Data Source Instance Health Reports the health of each onboarded integration and of every repository beneath it, classifying failures by type — token, permission, webhook subscription and others — so the cause of a failed scan can be corrected before a rescan. Pull Request Scans Scans the diff of a pull request when it opens or receives a commit, returns a status check to the version control system, and blocks the merge when a finding matches a policy carrying the Block PR action. Repository Scan Configuration Sets per-repository which scanners run, which branches are scanned, whether Git history and secrets validation are enabled, whether pull request scanning runs and fails on scan error, and which paths are excluded. Scan Inventories & Triage Presents branch periodic, pull request and CI scans as filterable inventories with a side panel that breaks results down by issue category, reports scan status and scan health separately, and routes each category to its resolution workflow.
Code-to-Cloud Traceability Code-to-Cloud Asset Views Exposes lineage as a Code-to-Cloud tab on asset and issue side panels, a topology graph on business applications, and sortable forward and backward lineage columns on every asset in the unified inventory, each linking to the onboarding step that completes a broken trace. Code-to-Cloud Coverage Dashboard Converts lineage data into a per-stage SDLC map and a coverage percentage in both the code-to-cloud and cloud-to-code directions for artifact and infrastructure views, with configuration toggles, per-view filters and recommended onboarding actions per gap. Code-to-Cloud Lineage Engine Builds a queryable asset lineage graph resolving repository to pipeline to image to optional registry to runtime resource, ingesting metadata from version control, CI/CD, container and VM build tools and runtime scanners, and applying AI analysis of build logs to extract deterministic links. YOR Infrastructure Tagging Applies a YOR trace tag to IaC resources through a tagging bot so a static template can be matched to the exact cloud asset it provisioned, and prompts to enable tagging where the tag is missing and the lineage link is broken.
Compliance Mapping & Reporting CI/CD Compliance Benchmarks Assesses pipeline and version control posture against the CIS GitHub and CIS GitLab benchmarks and the OWASP Top 10 CI/CD Risks, covering pipeline risks, repository permissions and branch protection, and build credential handling. Compliance Assessment Profiles Schedules recurring compliance audits by binding an asset group to a compliance standard on a cron schedule and distributing the resulting audit-ready report, configurable from the console or through Terraform. IaC Compliance Standard Mapping Maps IaC misconfiguration rules to industry standards and control identifiers — PCI DSS, NIST, ISO 27001, HIPAA, GDPR, SOX, CCPA and the CIS benchmarks for AWS, Azure and GCP — so findings can be filtered, reported and gated by regulatory control.
Programmatic Administration API Key Authentication Issues standard and advanced API key pairs from the tenant that authenticate every programmatic caller through key ID and secret headers or a JWT, scoped by the role assigned to the key and by the tenant's regional base URL. Application Security Public API Exposes REST endpoints for data source instances, applications and grouping criteria, repositories and their scan configurations, scan triggering and results, issues and findings, unified policies, detection rules, malicious package lookups, package records and code-to-cloud coverage. Cortex Cloud Terraform Provider Manages Application Security configuration as code through the cortexcloud provider — asset groups, custom detection rules, unified policies including Terraform run task enforcement, and compliance assessment profiles — with data sources for looking up existing policies, rules, labels and compliance standards.
Cloud and Kubernetes security posture — configuration, identity and compliance risk across cloud accounts and clusters, including the Kubernetes connector.
Cloud Environment Onboarding Cloud Instance Management Manages onboarded cloud instances after setup: edit, enable, disable or delete them, resolve pending instances whose authentication template has not been executed, refresh permissions after a Cortex release, drill into instance health errors, and offboard a provider. Cloud Provider Authentication Templates Generates a provider-native template the customer executes in their own account to grant the permissions onboarding requested, using CloudFormation in AWS, Terraform in GCP and OCI and an Azure template for ARM and Entra scopes, with a manual connection path when a template cannot be run. Cloud Provider Offboarding Removes an onboarded scope and the resources onboarding created, with distinct paths for an Azure subscription, a management group or tenant scope, an Entra-only tenant and a Terraform-based deployment. Cloud Provider Permission Model Documents which provider permissions each selected security capability requires for AWS, Azure, GCP, OCI and Alibaba Cloud, separately for standard onboarding and for outposts, and what each provider's authentication and security model implies for the customer. Cloud Service Provider Onboarding Wizards Connects an AWS, Microsoft Azure, Google Cloud, Oracle Cloud Infrastructure or Alibaba Cloud environment through a guided wizard that requests the permissions for the selected security capabilities, scopes the accounts, regions and organizational units covered, and starts asset discovery. Configuration and Content Copy Copies posture, workload protection, application security and global configurations plus custom content between tenants through the Upgrade Helper, either wholesale or item by item. GCP Service Perimeter Support Monitors Google Cloud projects that sit inside VPC Service Controls perimeters by configuring the perimeter to admit the platform's access. Kubernetes Connector GitOps and Air-Gapped Deployment Deploys the connector's Helm chart across many clusters from a Git repository using ArgoCD or Flux CD with per-tenant folders, charts and overlays, and supports air-gapped clusters by mirroring the connector images into a private registry with the supplied command-line tool. Kubernetes Connector Onboarding Deploys the Kubernetes connector into a cluster through a guided wizard, across the supported managed and self-managed distributions, and manages the resulting connector instances including automatic upgrade. Management Audit Logs Records administrative activity in the tenant as audit log entries with documented message and notification formats, and provides a page for monitoring that activity. Object-Level Access Management Applies per-object access settings to user-defined objects such as playbooks, scripts, saved queries and report templates, so sensitive work can be isolated between teams under a single common access experience. Onboarding Verification and Resource Inventory Confirms an onboarding succeeded by listing the resources the process created in each provider account and running per-provider post-deployment verification checks. Prisma Cloud Migration Links an existing Prisma Cloud tenant to a Cortex Cloud tenant and carries its configuration and content across as part of an upgrade path between the two products. Scan Outposts Runs scanning inside the customer's own cloud account as an outpost rather than in the default cloud scan mode, including an Azure bring-your-own-app-registration deployment with its own prerequisites and permission model. Scope-Based Access Control Restricts what data a user sees to a defined scope of assets, expressed with the asset attributes supported for scoping, and enabled separately from role-based permissions. Security and Server Settings Configures tenant-level security settings and server settings that govern how the tenant behaves and how sessions and access to it are controlled. Single Sign-On and User Authentication Authenticates users through SAML 2.0 single sign-on with an external identity provider, documented for Microsoft Entra ID and Okta, or through the vendor's customer support portal. Supported Regions and Federal Deployment Lists the regions a tenant can be hosted in and documents the US federal deployment, including the resources a FedRAMP environment requires and the capabilities limited within it. Tenant Activation and Deployment Checklist Takes a new tenant from activation to a working deployment through a staged checklist: prepare the environment, meet per-provider prerequisites, complete onboarding, then run the post-deployment steps that finish access control and data forwarding. Tenant Connectivity Prerequisites Documents the inbound and outbound address ranges a customer must permit through their firewall for the tenant's communication servers and storage buckets, for Broker VM and syslog receivers, and for collection from SaaS and cloud environments. User Groups Assigns roles and permissions to users through membership of user groups as an alternative to direct role assignment, with each group mapped to a single role and users able to belong to several groups. User Roles and Access Management Defines predefined and custom roles with per-component view and edit permissions and assigns them to users directly or through user groups, with reference documentation of what each permission unlocks.
Asset Inventory & Lineage All Cloud Assets Explorer Aggregates the cloud footprint by provider, service, account, category, type and class, and drills from a provider summary into the individual cloud resources behind it. API Specification Inventory Imports OpenAPI specification files and extracts specifications from scanned AWS and Azure API gateways, then scans them for misconfigurations and vulnerabilities and validates live API traffic against them to surface deviations. Asset Class Hierarchy Normalizes provider-specific resource types into a Class, Category and Type hierarchy covering compute, network, data, identity, application, code and CI/CD, container image, software package, external surface, AI and API assets, so assets can be filtered and managed uniformly. Asset Groups Groups assets by shared attributes, statically or by dynamic query, so they can be addressed in bulk, used to scope policies and issue management, and used to define granular user scopes in scope-based access control. Asset Roles Continuously classifies users and endpoints into roles such as Domain Controller, Administrator and Executive User to sharpen analytics baselines, and lets administrators add, edit and exclude members of each role. Business Application Modeling Groups code-side and run-side assets into business applications, either by manually selecting starting assets and letting related assets be added automatically, or by dynamic criteria based on cloud tags or version-control hierarchy. Cloud Asset Hierarchy Paths Records the full cloud organization, folder and project path for each asset across AWS, GCP, Azure and OCI, and exposes it for filtering, sorting, asset-group building and scope-based access control. Code-to-Cloud Asset and Application Views Shows an asset's lineage as a graph in its side panel and an application's full code-build-deploy-run topology graph, with call-to-action links routed by asset type to the onboarding step that completes an incomplete trace. Code-to-Cloud Coverage API Exposes a public external-scope endpoint that returns Code-to-Cloud coverage data programmatically using a standard tenant API key. Code-to-Cloud Coverage Dashboard Converts lineage data into a per-SDLC-stage map and an overall coverage percentage across code-first and cloud-first views, with filters, configuration toggles and an insights region that recommends the onboarding action closing each gap. Code-to-Cloud Issue Tracing Adds a Code to Cloud tab to vulnerability and IaC misconfiguration issues that traces the specific defect from its code file to the impacted runtime resource, so an investigator can tell whether a defect is actually deployed. Code-to-Cloud Lineage Engine Builds a queryable asset lineage graph resolving repository to pipeline to image to registry to runtime resource, by ingesting version-control, CI/CD and runtime scanner metadata and analyzing build logs to extract deterministic links. Discovery Engine Calls cloud service provider APIs against onboarded accounts to discover assets, services and resources into the inventory, running full discovery scans, targeted rescans and event-driven updates within the configured scope. Honey User Designates a decoy user account with no legitimate purpose so that any authentication attempt against it raises an alert. KSPM Graph Maps Kubernetes infrastructure as an interactive graph that drills from global clusters down to workloads, nodes and containers, with per-node security finding categories that can each be shown or hidden. Kubernetes Resource Inventory Tracks connected Kubernetes clusters, their platform and version, and the individual resources deployed inside them, including pods and containers, within the unified asset inventory with a per-resource asset detail card. Network Boundary Configuration Defines the organization's network boundaries, including internal IP address ranges, so the inventory can separate internal from external and managed from unmanaged assets during investigation. Unified Asset Inventory Presents every discovered enterprise, multi-cloud, code and external-surface asset in one table, with a breakdown of the cases and issues attached to each asset and an asset card holding normalized attributes, raw provider JSON, related risks and comments. User and Host Risk Scores Maintains a dynamic risk score per user and host by summing the scores of the cases and alerts the entity is implicated in, with a score trend graph and the identity data driving it.
Cases & Issues AI-Generated Case Summaries Generates a case title and narrative description with an LLM so an analyst can grasp the scope of a case at a glance before investigating. Case and Issue Domains Assigns every case and issue a domain reflecting its root cause and area of operation, separating security from non-security work so cases can be routed, prioritized and excepted per domain. Case and Issue Resolution Closes cases and issues from the UI or the API with a required resolution reason, options to resolve all linked issues and create an exclusion, and automatic resolution when the underlying issues are all resolved. Case Grouping Consolidates related issues and artifacts into a single case by attack flow or shared entity, exposes the grouping logic as a graph, applies age and volume thresholds that close a case to new issues, and supports merging cases manually. Case Investigation Workspace Provides the analyst view of a case in split or legacy detailed layout, with an overview, a timeline consolidating attack events and analyst actions, evidence, associated assets and artifacts, and the ability to update title, description, assignee and star. Case Scoring and Severity Assigns each case a numeric urgency score, from user-defined scoring rules matching issue attributes or from machine-learning scoring, alongside a severity inherited from its most critical issue, both reviewable and adjustable by an analyst. Case Teams and Access Restriction Assigns users and user groups to roles within a case team and can restrict a sensitive case so only assigned team members can view or act on it. Case Timers and SLAs Tracks resolution against built-in resolution timer and SLA fields on cases and issues, and lets administrators define additional case-level timers and SLAs from templates to monitor operational KPIs. Causality Analysis Reconstructs the chain of activity behind a detection into a coherent story with its context, so analysts see how a threat entered the environment and what it did at each stage rather than isolated events. Collaborative Notes and Comments Provides notepad and comment panels inside the case so analysts record evidence, observations and investigative steps and keep a continuous shared record of the investigation. Entity Investigation Actions Pivots an investigation onto a specific entity, with dedicated views for investigating a user, an IP address, a file or process hash, an asset, and the artifacts attached to an issue. External Issue Syncing Mirrors issues with external ticketing applications such as Jira and ServiceNow, linking tickets to issues and synchronizing changes inbound, outbound or bidirectionally using sync profiles that map fields between the two systems. Issue Management Actions Provides the per-issue operations analysts use outside investigation: update fields, add and view context data, link or unlink issues from a case, exclude an issue, copy issue text or URL, export issue details to a file, and star issues in bulk by configured match criteria. Issues, Findings and Events Turns detections that cross defined thresholds into issues describing what happened, what is affected and what to do, presented through the Issues page, issue and findings cards and a chronological issue feed, with deduplication of repeated issues. MITRE ATT&CK Mapping Maps behaviors observed in a case's issues to ATT&CK tactics and techniques, with a per-tactic breakdown of how many issues exhibited each technique and an option to include low-severity insights. Resolution Center Gives case remediation a single workspace where playbooks can be opened and run in case context and remediation task status tracked, without navigating away from the case. War Room and Work Plan Records every command, script output and analyst message of an investigation in a War Room log, and shows playbook execution progress for that investigation in a Work Plan view.
Data Sources & Ingestion Broker VM Bridges the customer network and the tenant through a secured virtual machine deployed from a downloadable image onto a hypervisor or cloud platform, then registered and configured from the console to route endpoints and collect and forward logs and files. Broker VM Data Collector Applets Activates and configures the collector applets that run on a Broker VM to ingest specific data types, including the file-share data security collector, the container registry scanner for on-premises and private-cloud registries, and the secure transporter, each updatable independently of the broker. Broker VM High Availability Clusters Removes the single point of failure by placing two or more Broker VMs in a cluster with synchronized configuration, supporting cluster creation from scratch or from a standalone broker, node and applet assignment, primary-node switchover, and cluster edit and removal. Broker VM Operations Operates a deployed Broker VM from the console: upgrade it, edit or import its configuration, collect its logs, increase the storage allocated to data caching, open a remote Live Terminal, receive version and connectivity notifications, review audit logs, and export metrics in Prometheus format. Cloud Audit Log Collection Collects cloud provider audit logs through the provider's own log pipeline, including AWS Control Tower and bring-your-own-bucket layouts and the cross-account key access those require. Compute Units Meters query cost in compute units against a daily quota set by license size, consumed by API queries and cold-storage queries and expandable through a purchasable add-on, with usage tracking and query failure when the quota is exhausted. Container Registry Scanning Connects container registries, including Docker Hub, GitLab, Harbor, JFrog, Sonatype Nexus, Docker V2-compliant registries and the cloud-managed registries, then discovers their repositories and tags, scans images for vulnerabilities, malware and secrets, and re-evaluates them incrementally within a configurable scanning scope. Data Ingestion Health Monitoring Collects granular ingestion metrics to expose disruptions in the collection pipeline, raises health issues for them on a dedicated page and in the issues stream, and provides per-collector connectivity status and investigation steps. Data Retention Sets how long ingested data is kept according to the tenant's license and purchased retention add-ons, with the retention terms visible alongside the license details. Data Sources & Integrations Console Provides the single page where every ingestion point is added and operated, covering vendor connectors, standard collectors, cloud onboarding wizards and marketplace integrations, with instance edit, delete, enable, disable, log refresh, connectivity verification and error drilldown. Datasets and Dataset Management Organizes ingested data into built-in and custom datasets and presets that queries run against, with dataset views, per-dataset RBAC, and monitoring of dataset and dataset-view activity. Lookup Datasets Imports lookup tables that queries join against for enrichment, with download of the stored JSON and a configurable time to live per lookup dataset. Notification and Log Forwarding Forwards issues, cases and logs out of the tenant to an integrated external service, supporting Amazon S3, Amazon SQS, Splunk, Slack, a webhook, a syslog receiver and email, with a forwarding configuration per data type and documented formats for issue, audit, analytics and agent records. OpenShift Container Registry Discovery Discovers the container images held in an OpenShift environment's internal registry automatically when the Kubernetes Connector is deployed on that platform. Vendor Connectors Consolidates each third-party vendor's security capabilities into one connector covering log collection, automation, identity posture, SaaS posture configuration monitoring and data security, with selective onboarding of individual sub-capabilities for multi-service vendors.
Automation & Extensibility API Key Management Issues and manages the API keys that authenticate programmatic access, with per-key security levels and role scoping, and a self-service model where a primary key mints restricted task-specific CLI and IDE keys through the public API. Automation Exclusion Policies Prevents commands and scripts from taking automated remediation action against listed critical assets such as specific users, IP addresses and domains, without having to detach or edit the playbooks involved. Automation Rules Triggers playbooks or quick actions automatically when incoming issues meet defined conditions, executing as the system rather than as the rule's author. Automation Scripts Runs JavaScript, Python or PowerShell scripts as playbook tasks or standalone CLI commands, with access to platform APIs, arguments, password protection, per-script Docker image selection and access controls. Context Data, Filters and Transformers Stores task and command output as JSON context data addressable across a playbook, and manipulates it with built-in filters and transformers or custom operator scripts, including indicator extraction and enrichment from issue fields. Cortex CLI Scans source code, container images and API specifications for vulnerabilities, misconfigurations and exposed secrets from a single binary evaluated against unified policies, installed and upgraded through package managers, and runnable in CI/CD pipelines, locally, or as a Git pre-commit or pre-receive hook. Cortex Marketplace Distributes security content as content packs from Palo Alto Networks, partners and MSSPs, with review of pack contents and dependencies before installation, and install, update, revert and delete operations, plus documented support tiers and automatic upgrade of core packs at platform version upgrades. Engine Container Runtime Configuration Configures the Docker or Podman runtime the engine executes integrations and scripts in, covering image selection and sourcing, hardening, non-root users, network settings, CPU, memory, PID and file-descriptor limits, storage location, pull rate limits and reverse proxying. Engines Installs a proxy application on a remote machine inside the customer network that executes playbooks, scripts, commands and integrations locally and returns results to the tenant, with installation, upgrade, removal, certificate and proxy configuration managed from the tenant. Integration Credential Management Stores usernames, passwords, certificates and SSH keys as named credentials that integration instances reference instead of inline secrets, with permission gating on the credentials page and support for an external credentials service. Integration Instances Connects the tenant to third-party products by configuring, testing, duplicating, enabling and disabling instances of integrations delivered in content packs, with multiple instances per integration for different environments. Lists Stores reusable data as named lists of text, JSON, Markdown, HTML or CSS that playbooks and scripts read and write through the context path. Playbooks Automates response as a visual flow of tasks, built from a playbook catalog or from scratch, with standard, conditional, communication and manual tasks, sub-playbooks and loops, a task library, per-playbook settings, error handling, testing and a development checklist. Quick Actions Runs a single preset command against issues, such as creating a ticket in a third-party system, sending a chat message or changing issue severity, either manually during investigation or from an automation rule.
Query & AI Assistance Agent Builder Builds and manages custom Agentic Assistant agents that hold their creator's permissions or fewer, assembling the actions an agent may take, registering new actions, attaching knowledge sources, extending reach through MCP integrations, and sharing agents privately or tenant-wide from a central hub. Agentic Assistant Chat Answers natural-language requests by selecting a system, public or user-built agent that plans and executes actions with a visible action trail, using the user's identity, roles and conversation context, with multiple concurrent chats, a browsable chat history, and access from Slack. AI Prompt Management Creates, stores and reuses AI prompts as playbook tasks, with prompt authoring guidance, a library of existing prompts, and role-based access control over who may view and edit them. Automation Engineer Agent Generates, modifies, explains and queries playbooks and automation scripts from natural-language instructions, iterating on an existing playbook through follow-up prompts. Case Investigation Agent Embeds an agent in the case card that answers questions about the case in context, so an analyst consolidates the data behind an investigation without leaving it. Cortex Assistant Investigates entities entered in the search bar, including hosts, users, hashes, domains, IP addresses and cases, and answers questions about them to support triage, investigation and remediation. Cortex MCP Server Connects external LLM applications to the tenant over the Model Context Protocol as a downloadable server, exposing built-in tools for managing cases, issues and investigations in natural language, and supporting custom tools for specific workflows. Graph Search Queries the environment as an interactive visual graph of assets and findings, with a guided query builder, a saved query library, worked examples, result exploration, and documented asset and finding coverage, gated by dedicated access permissions. Help Center Agent Answers product how-to questions in context and opens support tickets from inside the product, attaching the conversation and the relevant tenant context to the resulting support case. Natural-Language Query and Visualization Translates a natural-language prompt into an XQL query, runs it and returns the results, and can render them as any chart type the platform supports, so users query and visualize data without knowing XQL syntax. Query Builder Builds queries over cases, issues and other entities without writing XQL, using built-in filter categories and considerations, and renders matching results including graph output. Query Center and Query Library Stores, edits, runs and shares saved queries, scheduled queries and XQL macros in a personal and shared library, with visibility and edit rights governed by role-based and scope-based access control. Quick Launcher Offers an in-context shortcut from anywhere in the product to search for a host, user, IP address, domain, file, path or timestamp and launch the matching artifact and asset views or a response action. XQL Search Queries datasets across all entities in the XQL query language, with query construction guidance, stage and field semantics, result review and export, time picker and auto-suggestion, and translation of existing Splunk queries into XQL.
SaaS, Identity & Data Posture AI Security Posture Management Inventories the AI ecosystem across cloud environments, including models, agents, data flows and supporting infrastructure over a documented set of supported services, and identifies risks in it, with dedicated datasets for deeper investigation. Cloud Identity Security Maintains an inventory of human and machine identities across cloud providers and identity providers organized by asset category, and surfaces identity risks such as over-permissive or unused access for prioritization and remediation. Data Classification Classifies stored data using data patterns that match sensitive content and data profiles that label files and tables, with built-in and custom classifiers, syntax guardrails and validation, per-item enable and disable, and false-positive reporting. Data Security Posture Management Discovers, classifies, protects and governs sensitive data across cloud, SaaS and on-premises stores, onboarding sources such as Snowflake, Databricks and Microsoft 365 and reaching on-premises file shares and databases through Broker VM applets. Effective Permission Calculation Resolves an identity's net effective cloud permissions across the many ways access is granted, including different granters, policy types, wildcards and explicit resource access, and exposes the result through simple and advanced access tables. Identity Detection Rules and Configuration Ships out-of-the-box identity detection rules and supports custom ones, alongside identity-specific configuration such as trusted domains for external sharing and role- and scope-based access control over identity data and datasets. SaaS Agent Tools and Datasets Analyzes the tool wrapper layer where an agent author configures how a tool may be used, which is where agent risk concentrates, and aggregates the datasets SaaS agents draw on to generate their outputs. SaaS AI Agent Security Inventories the AI agents deployed across enterprise SaaS platforms, onboarded per platform, and gives a cross-platform then per-platform view of active agents with activity tracking, posture assessment and targeted remediation of the risks autonomous agents introduce. SaaS Application Onboarding Connects supported SaaS applications to SaaS Security through a per-application wizard that collects the credentials and permissions needed to read that application's settings, so its posture can be scanned. SaaS Detection Rules and Remediation Ships out-of-the-box detection rules for SaaS and AI application misconfigurations and presents the resulting posture issues with a prioritized list of remediation steps for each. SaaS Provider Instances Security Check Scores the posture of every onboarded SaaS instance, aggregates them into a tenant-wide security score bucketed by severity, and lists instances for analysis and remediation. Topic Classification Classifies documents by subject matter rather than by pattern match, so sensitive material such as contracts and corporate strategy is identified where regular-expression detection would miss it. Unified Human Identities Correlates a person's separate on-premises, cloud and SaaS accounts into a single virtual identity asset so identity fragmentation does not hide risk. Unused Permission Review Analyzes audit logs to find permissions an identity never exercises and generates a least-privilege policy that revokes the excess.
Posture Rules & Policies Base Image Rules Designates registry images as organizational base images and maps derived images to them, creating a base reference relation that supports bidirectional tracing of vulnerabilities to their source and remediation at the base image level. Cloud Security Policies Binds selected cloud security rules to an asset scope so that findings on in-scope assets are promoted to issues, with rule selection by filter criteria and per-policy labels. Cloud Security Rules Defines the detection logic evaluated against cloud, code and host assets, as predefined or custom rules of several types, including configuration, graph, network exposure, identity, data, AI and attack path, each producing findings on matching assets. Cloud Workload Policies and Rules Combines cloud workload detection rules with a scope, an SDLC evaluation stage and an action into misconfiguration, malware and secret policies governing cloud runtime instances, using predefined or custom scanner-backed rules. Issue Exceptions and Exception Rules Records time-bound, documented decisions to defer remediation of confirmed issues, as exceptions created from an issue or as standalone exception rules, governed by exception admin and approver roles and an approval workflow that can be turned off. Kubernetes Security Posture Management Assesses connected Kubernetes clusters against compliance and security rules through the Kubernetes Connector, with scheduled scan cycles, on-demand per-cluster scans, and an agentless collection method that discovers clusters and their inventory and posture without deploying anything inside them. Rule and Policy Lifecycle Management Provides the common management actions on rules and policies across cloud security, cloud workload and base image surfaces: create, edit, clone as new, enable, disable, delete, and review status from the rules and policies tables. Serverless Function Posture Scanning Scans serverless functions across code and CI/CD environments for vulnerabilities, malware and exposed secrets without installing agents, after onboarding the cloud provider accounts that host them, and surfaces the results in a serverless function asset inventory. Serverless Function Rules and Policies Detects serverless risk with attack path, configuration and network exposure rule types, and scopes and actions those rules through serverless function policies that combine rules, cloud-account scope and response actions. Trusted Image Policies Evaluates container images and VM images against trusted-image criteria and scope, then allows or prevents their deployment into Kubernetes environments and raises security or posture issues for untrusted images. Workload Preventive Enforcement Blocks a violating workload rather than only reporting it, using a Prevent and Create an Issue policy action, enforced at runtime for Kubernetes workload images through the admission controller on clusters where the connector has admission control enabled.
Attack Surface & Exposure Attack Surface Attribution Attributes discovered internet-facing assets to the organization through methods including domain registration records and certificate data, and records the evidence behind each attribution so the public-facing perimeter can be reviewed. Attack Surface Rules Applies vendor-managed rules to global scan results to detect exposed or misconfigured customer-owned assets, generating findings and issues, including the default rule that flags unmanaged cloud services. Cloud Attack Surface Management Brings attack surface management to cloud posture: discovers internet-exposed cloud services that were never onboarded, confirms inadvertent internet exposure by combining outside-in scan data with inside-out detections, and can be enabled or disabled per tenant. Cloud Network Analyzer Determines which virtual machines, databases, containers and serverless functions are reachable from the internet, by checking whether a routing path exists, validating the security configuration along it, and confirming reachability, then publishes the resulting exposure findings. East-West and Outbound Exposure Detection Detects workloads whose configuration grants unrestricted access across their VPC within the same cloud account, and workloads with unrestricted outbound internet access, raising a finding for each. Exposure Investigation Investigates an exposed asset from its exposure issue or through a graph query, showing which asset is exposed and the path by which it is reachable. Externally Inferred CVEs Infers CVEs affecting an internet-facing service by matching its detected product name and version against the National Vulnerability Database, grading each match as high or medium confidence and raising issues for high-confidence matches. Internet Scanning Runs global internet scans at cadences varying by port, protocol, cloud provider range and attribution, plus open-source intelligence collection, to keep an inventory of responsive internet-facing services current. Trusted IP Ranges Designates public CIDR blocks belonging to the company, its partners or trusted services so that traffic from them is excluded from internet exposure findings.
Dashboards & Reporting Custom Dashboards Builds dashboards from a blank canvas or a template by arranging widgets, then adds global filters that rescope the data and drilldowns that link a widget to an XQL search, a URL, another dashboard or a report. Dashboard and Report Access Control Governs which dashboards, reports and widgets a user sees through role-based and scope-based access control plus public or restricted visibility, with explicit sharing to users and groups and administrator control over whether sharing is allowed at all. Dashboard Manager Lists every dashboard a user can reach, including system dashboards, Command Centers and custom dashboards, and manages them: duplicate, transfer ownership, export and import as JSON, and recover or permanently remove deleted items from the trash. KSPM Dashboard Summarizes Kubernetes security posture across the connected cluster estate, with visibility governed by the viewer's asset scope. Reports Produces point-in-time snapshots as downloadable files from report templates built on dashboards or on library widgets, generated once or on a schedule and distributed to user groups or mailing lists, with a generated-report history and a notification rule for failed runs. SaaS Security Overview and Checks Aggregates the SaaS Security pillars into an overview dashboard, and consolidates SaaS posture misconfigurations, vulnerabilities and compliance telemetry into one queryable, prioritized view for triage. System Dashboards and Command Centers Ships preconfigured views of tenant state, including the Cortex Cloud Command Center landing experience, Cloud Security Operations, Compliance Overview, cloud consumption tracking by account and provider, and an Agentic Assistant usage dashboard. Widget Library Holds the shared widget repository used by dashboards and reports, with custom widgets built from XQL queries, from scripts that can pull data from third-party systems, or generated from a natural-language prompt, plus widget parameters and public or restricted access levels.
Vulnerability & Risk Prioritization Cortex Vulnerability Risk Score Scores each vulnerability dynamically by combining organization-specific context with public vulnerability intelligence, so prioritization reflects the environment rather than the raw published severity. CVSS Score and Severity Recast Overrides the published CVSS score or severity of a specific vulnerability where its real risk in this environment differs from the original rating. Emerging Vulnerabilities Aggregates what is known about a zero-day or global attack-surface threat event alongside its measured impact on the organization, on a page built for responding to it. Vulnerability Intelligence Feed Maintains a real-time feed of vulnerability and threat-intelligence data continuously pulled from vulnerability databases, vendor advisories and other certified upstream sources. Vulnerability Management Tracks the CVEs and known software weaknesses found on assets across the estate on a dedicated Vulnerabilities page, so they can be monitored, investigated and driven to remediation. Vulnerability Management Dashboard Visualizes the most pressing vulnerability risks, how risk has changed over time, and progress against remediation. Vulnerability Policies Defines what happens to vulnerability findings that match given criteria, as predefined or custom issue-creation and prevention policies keyed on CVSS and EPSS severity and other attributes, with enable and disable, a policy listing CVEs and assets to ignore, and a grace period before prevention starts blocking.
Compliance Management Compliance Assessment Profiles Pairs a compliance standard with an asset group in a profile that runs the standard's checks against those assets on a recurring basis. Compliance Assessments and Reports Shows the latest assessment results per profile and produces compliance assessment reports for immediate viewing, download or recurring scheduled delivery, listed by standard, profile and asset group. Compliance Standards Catalog Lists the compliance standards available to the tenant with their version, controls, profiles, labels and custom status, in table or card view, and opens a per-standard panel detailing its controls. Controls Catalog Lists every built-in and custom compliance control with its details, so controls can be reviewed and associated with the detection rules that assess them. Custom Compliance Standards Creates a standard from scratch or as a copy of a built-in one, populated with built-in or custom controls mapped to detection rules, including custom cloud security rules that must also sit in a policy for assessments to be accurate.
Runtime detection and response for cloud workloads — hosts, containers and serverless — including the agent, runtime policy and cloud incident handling.
Asset inventory, exposure and vulnerabilities AI asset inventory Inventories AI models, services and supporting infrastructure across deployment modes and cloud providers, with widgets that rank AI risk. API asset inventory Inventories API endpoints and specification files observed in traffic or extracted from gateways across cloud providers and connected data sources. Asset groups Defines static and dynamic groups of assets by shared attributes so they can be targeted collectively by policies, assessments, bulk actions and scope-based access control. Asset risk scoring Assigns users and hosts a dynamic risk score aggregated from their activity and from directory and HR data, adjustable with custom modifiers, to rank which identities and machines carry the most risk. Asset roles Classifies users and endpoints into roles such as domain controller, administrator or executive user to tune behavioral baselines, and supports decoy honey user accounts that raise an alert when accessed. Attack surface rules Matches attack surface scan results against vendor-managed rules to raise findings and issues for exposed or misconfigured internet-facing assets, each carrying a default severity and enablement state. Business application modeling Groups related assets into business applications, built manually from code-side or run-side starting assets or maintained automatically by criteria, and reports the risks detected across each application. Cloud asset inventory Presents a normalized multi-cloud view of onboarded cloud resources with summary widgets over the cloud footprint, used as the foundation for cloud security posture management. Cloud attack surface management Discovers internet-exposed cloud services through global internet scanning and asset attribution, maps the organization's public-facing perimeter, and flags cloud services that were never onboarded as unmanaged. Code and CI/CD asset inventory Inventories software supply chain assets found through version control and CI/CD integrations, covering source control organizations, repositories, CI/CD instances and pipelines, infrastructure-as-code resources and declared software packages. Code-to-cloud coverage dashboard Reports the share of code-side and cloud-side assets whose lineage resolves, broken down by software lifecycle stage with recommended actions to close gaps, and exposes the same figures through a public API endpoint. Code-to-cloud lineage Correlates repositories, pipelines, artifacts, registries and runtime resources into a bidirectional lineage graph, stored as lineage fields on every asset and shown as a per-asset tab and a per-application topology graph. Compute asset inventory Inventories virtual machines, containers, container images, VM images, serverless functions and Kubernetes clusters, and scans VM images agentlessly so workload risk is assessed without installing an agent. Data asset inventory Inventories data stores discovered by the data security module, showing where sensitive data resides, how it is used and how exposed it is. Discovery engine Scans onboarded cloud accounts to discover assets, services and resources, adds them to the unified inventory and queues them for misconfiguration and vulnerability scanning. Emerging vulnerabilities Aggregates what is known about a zero-day or global threat event together with its impact on the organization's own assets on one page, so remediation can be prioritized quickly. External surface inventory Inventories internet-facing domains, certificates, services and websites attributed to the organization, and records the attribution evidence explaining why each asset is considered owned. Externally inferred CVEs Infers likely vulnerabilities on internet-facing services by matching the observed product and version against a public vulnerability database, grading each match as high or medium confidence. Identity asset inventory Inventories cloud identities together with the actions each can perform and the resources each can reach, supplying the effective-permission context that identity detection rules evaluate. Network boundary configuration Records the organization's internal network ranges and boundaries so assets and traffic can be distinguished as managed or unmanaged during investigation. Network exposure detection Builds a network topology of the cloud estate to determine which assets are reachable from the internet, have unrestricted outbound access or can move laterally within an account, evaluating routing paths against cloud-native network controls, with trusted public IP ranges excluded. Unified asset inventory Aggregates and normalizes assets collected by agent, agentless, log and API methods into one profile per asset across code, cloud, on-premise and external surfaces, organized by a class, category and type taxonomy with the full cloud hierarchy path. Vulnerability intelligence feed A real-time feed that continuously pulls vulnerability data and threat intelligence from vulnerability databases, vendor advisories and commercial providers to improve detection accuracy. Vulnerability management Groups findings by CVE across the whole estate, shows how prevalent each vulnerability is, and tracks investigation and remediation progress on a dedicated dashboard. Vulnerability risk scoring Scores each vulnerability by combining asset context, exploitability data and public vulnerability intelligence, and allows the underlying industry score and severity to be recast for the environment.
Cases, investigation and response Action center Initiates endpoint actions and tracks the progress of every investigation, response and maintenance action performed on protected endpoints. AI-generated case summaries Generates a case title and narrative description automatically so an analyst gains situational awareness without reading every linked issue. Case and issue SLAs Tracks resolution against built-in resolution timer and SLA fields and against additional case-level timers and service level agreements created for reporting on operational targets. Case grouping Consolidates issues that share an attack flow or entity into one case using machine learning, exposes the grouping logic as a graph, and allows correlation-rule issues to be tuned so they group as intended. Case scoring and severity Assigns each case a numeric score and a severity from built-in and user-defined scoring rules so analysts can prioritize, with manual override of both. Case teams and access restriction Assigns users and user groups to roles on a case team and restricts sensitive cases so only assigned members can view or act on them. Case timeline and issue feed Shows a chronological record of attack events, analyst activity and system actions on a case, and a feed of the linked issues from first detection to latest activity. Cases Groups related issues into a case representing a single problem, with manual creation, assignment, starring, merging, linking and unlinking of issues, contextual domains, grouping thresholds and a defined lifecycle from detection to resolution. Causality analysis Visualizes the full process execution chain that led to an issue, with dedicated endpoint, network, cloud audit log and SaaS causality views and an icon key for the actions taken along the chain. Endpoint response actions Contains and remediates a compromised endpoint: isolate it from the network, retrieve files and support logs, scan for dormant malware, quarantine or destroy malicious files, manage hash allow and block lists, revert malicious changes and pause protection. Entity investigation views Drill-down views for an IP address, file or process hash, user and host asset that aggregate the data collected for that entity over a 24-hour or seven-day window and offer response actions in place. Evidence, findings and artifacts Presents the evidence behind a case: the associated assets and artifacts by class, findings describing each asset's state, the adversary tactics and techniques observed, and the compliance controls a posture case violates. Forensic investigations Groups endpoint data collections, alerts and evidence into an investigation, with configurable triage collection of forensic artifacts, memory image capture, a tagged forensic timeline, export for offline analysis and per-investigation permissions. Investigation work plan Shows the playbook running on an issue as a visual task plan so analysts can monitor its progress and intervene in individual tasks. Issue exceptions Suppresses issues judged not to be threats through exception rules created from an issue or from the exceptions page, with an optional approval workflow, bounded exception periods and a view of excepted issues. Issue exclusion rules Suppresses the display of issues matching defined criteria through exclusion rules built from scratch or from an existing issue, separately from the exception rules that stop issues being created. Issue syncing with external ticketing Mirrors issue fields such as status and description with external ticketing applications using sync profiles that define the field mapping in each direction. Issues Consolidates non-informational detections from every source into an issues table and issue card carrying root-cause evidence, remediation guidance, field updates, featured fields, copy and export, and deduplication of repeated agent events. Live terminal Opens a remote shell session to an endpoint through the agent so an analyst can inspect and act on the host during an investigation. Quick launcher An in-context shortcut available anywhere in the console for searching information, running common investigation tasks and starting response actions. Resolution center A single workspace for resolving a case that lists recommended playbooks and pending, in-progress and completed remediation actions alongside shared notes and comments. Threat hunting Searches for specified artifacts across large numbers of hosts and returns hunt collections showing where and when each match occurred. War room A per-case and per-issue workspace holding an audit trail of automatic and manual actions, a command line for running system, script and integration commands, and a playground for safe testing.
Automation, playbooks and content Automation exclusion policies Prevents commands and scripts from taking automated remediation actions against nominated critical assets such as users, IP addresses and domains. Automation rules Triggers playbooks or quick actions automatically when defined conditions are met on incoming issues and events. CLI API security testing Fuzzes APIs from the command line with unexpected and malformed input to find vulnerabilities, misconfigurations and unauthorized access paths, and returns a structured scan report. CLI code security scans Scans a working directory from the command line for exposed secrets, infrastructure-as-code misconfigurations and vulnerable third-party dependencies, deriving repository and branch from the local checkout and writing results in several output formats. CLI custom checks and signature verification Loads custom policy checks from a local directory or a Git repository and optionally verifies their cryptographic signature against a supplied public key before the scanner runs them. CLI pre-commit and pre-receive hooks Runs command-line scans as version control pre-commit hooks on a developer machine and pre-receive hooks on the server so violating changes are caught before they are committed or accepted. CLI workload and image scans Scans container images from a local container daemon or an image archive for secrets, vulnerabilities and malware during continuous integration, and exports a software bill of materials for the scanned image. Content marketplace A content portal for downloading and managing content packs published by the vendor, partners and service providers, each bundling playbooks, integrations, scripts and other content, with install, update, revert and delete, dependency review and stated support tiers. Context data Stores structured key-value data on issues and cases that playbook tasks and scripts read and write, with search across the structure, extension of command output and deletion commands. Cortex CLI Command-line client that runs application security, cloud workload protection and API security scans, installed through a package manager, manual download or a console-generated command, and authenticated by config file, environment variables or flags. Credential store Saves usernames, passwords, certificates and SSH keys centrally so integrations and scripts reuse them without exposing the secret values. Engine container runtime Runs engine integrations and scripts inside Docker or Podman containers, with configurable images, storage location, memory, CPU, process and file-descriptor limits, network hardening and non-root execution. Engine image registry connection Points an engine at a private container image registry so integration images are pulled from it instead of the public registry. External dynamic lists Publishes the IP addresses and domains associated with issues as an external dynamic list hosted for a firewall to consume for access control. Indicator extraction Extracts indicators from issue fields during playbook execution and enriches them through configured commands and scripts. Integration instances Configures instances of integrations shipped in content packs so the product can exchange commands and data with third-party systems, with credential entry, connection testing and troubleshooting dashboards. Lists Stores reusable text, Markdown, HTML, CSS and JSON data containers that playbooks and scripts read and update through list commands, with per-role permissions. Playbooks Visual automation flows that orchestrate response across products, built from standard, conditional, manual, communication, sub-playbook and AI prompt tasks, with triggers, loops, versioning, a debugger and a catalog of prebuilt playbooks to adopt. Quick actions Runs preset single commands such as opening a ticket in an external system, sending a chat message or changing issue severity, from an automation rule or on demand. Remote engines Proxy servers installed in a customer network that run integrations, scripts and commands locally and return results to the tenant, with installation packages, load-balancing groups, proxy and certificate settings, upgrades and removal. Scripts Authors and runs JavaScript, Python and PowerShell scripts that call platform APIs and share data with the war room, and supplies custom filters and transformers used to shape playbook data. Self-service scan API keys Lets a developer generate role-restricted command-line and IDE API keys from a primary key through the public API, without holding administrative console permissions.
Workload and endpoint protection Agent content updates Delivers protection content packages to agents in parts rather than as a whole, with guidance and controls for staging agent and content versions to limit production risk. Agent settings profiles Per-platform profiles that customize agent behavior for groups of endpoints, alongside global agent configuration that applies to every endpoint in the tenant. Container-embedded agent Embeds the agent inside container images so container-as-a-service workloads receive malware prevention, exploit protection, vulnerability assessment and altered-binary detection where no host agent can be installed. Device control Restricts which removable USB and Bluetooth devices and which print jobs are permitted on Windows and macOS endpoints, replacing the default of allowing all of them. Disk encryption management Reports the encryption status of Windows and macOS endpoints and applies encryption rules and policies that drive each platform's native full-disk encryption. Endpoint agent deployment Creates and manages per-platform agent installation packages, then installs, upgrades, restarts, uninstalls and deletes agents, moves agents between managing tenants, pins critical-environment versions, clears the agent database and manages per-agent tokens. Endpoint data loss prevention Enforces data-in-motion rules on endpoints, including while offline, across web, local and USB channels, with application and application-group scoping, true file-type detection, inspection inside archive files and its own data security issues. Endpoint management A central endpoints page listing every machine carrying an agent, with aliases, endpoint tags created at install time or later, static and dynamic endpoint groups, and operational, upgrade and module status. Endpoint policies and exceptions Maps security profiles to policy rules and policy rules to endpoints or groups, and defines exceptions that exclude paths, hashes, signers, certificates, command lines, processes or whole modules, either per profile or globally. Endpoint protection modules and telemetry Activates the protection module matching the attack type and the configured policy, and continuously collects endpoint activity telemetry for detection and investigation when behavioral protection or endpoint data collection is enabled. Execution restriction profiles Limits the locations and media from which executables may run on an endpoint, configured per platform through restriction prevention profiles. Exploit prevention Blocks attempts to exploit flaws in browsers, applications and the operating system through protection modules aimed at specific attack techniques, applied to a published list of protected processes. File integrity monitoring Detects unauthorized or anomalous creation and modification of files and folders on an endpoint and forwards each change as an event. Host firewall Allows or blocks network traffic on Windows and macOS endpoints through hierarchical rule groups reused across host firewall profiles, with different rule sets applied according to the endpoint's current location. Host inventory Collects business and IT operational data from every endpoint, such as installed services, applications and local users, into one searchable inventory for spotting IT and security problems. Identity profiles for domain controllers Centralizes identity security controls for Windows domain controllers, unifying directory posture assessment, conditional access enforcement and directory-query protection in a single profile. Malware prevention Blocks execution of known and unknown malicious files through a layered prevention engine covering trojans, viruses, worms, ransomware, script-based attacks and grayware, configured through malware prevention profiles. Serverless function scanning Scans serverless functions and the layers they depend on for vulnerabilities, malware and exposed secrets across code and CI/CD environments, without installing an agent or disrupting the running workload. Serverless runtime protection Embeds the agent in serverless function code to monitor execution, processes, networking and filesystem activity in real time and to allow or deny those actions by policy, raising a separate issue for each violation type. Unknown file analysis Forwards unknown samples from endpoints to a cloud sandbox for behavioral analysis and applies the returned verdict, within published daily sample-upload and verdict-query limits.
Data sources, connectors and collectors Broker appliance A virtual appliance deployed inside the customer network that bridges it to the tenant, routing endpoint traffic and collecting and forwarding logs and files, with images for the major hypervisors and clouds, configuration import, storage expansion, upgrades, log collection and a remote terminal. Broker high-availability clusters Groups two or more broker appliances into a cluster with synchronized configuration and a heartbeat connection so no single appliance is a point of failure, with node addition and removal, manual primary switchover and per-cluster applet assignment. Broker monitoring and notifications Reports appliance and applet status, records activity in audit logs kept for a year, sends version, connectivity and cluster notifications to the console, and exposes local usage statistics in a metrics format an external monitoring system can scrape. Cloud audit log collection Captures cloud provider audit trail events through an event-driven pipeline of provider-native notification, queue and storage resources deployed by the onboarding template, including bring-your-own-bucket and landing-zone variants with cross-account key access. Container registry connectors Connects public and private container registries, covering the major standalone registry products, registries hosted alongside version control, and the managed registries of onboarded cloud providers, each authenticated with credentials or a token and given a scanning scope. Container registry scanning Discovers registries, repositories and tags in a connected account, extracts software bills of materials, malware indicators and secrets from each image, and re-evaluates existing results every 24 hours against updated intelligence instead of rescanning. Data source and connector catalog A catalog of every ingestion point available to a tenant, spanning vendor connectors, cloud service provider onboarding wizards, generic on-premise collectors and marketplace content pack integrations. Data source instance management Edits, enables, disables, deletes and refreshes the instances configured for each data source, and reports per-instance connectivity status grouped by integration. Data source onboarder Adds a data source and its instance through a guided flow that also installs the recommended playbooks, scripts and content and summarizes everything it configured. Dataset management Manages the datasets that every query runs against, showing storage consumption per dataset and logging dataset and dataset-view activity. Event forwarding Exports raw endpoint telemetry and parsed event logs to external destinations, including a temporary cloud storage bucket, with per-event-type control over which fields are included. Generic collector applets Vendor-neutral collector applets running on the broker appliance for syslog, Windows event logs, network flow records, relational databases, CSV files, file shares, file transfer, event streaming platforms and network mapping. Ingestion health monitoring Collects granular ingestion metrics, measures data freshness as the delay between event creation at the source and arrival in the tenant, raises health issues when collection is disrupted, and supports custom correlation rules over those metrics. Lookup datasets Imports CSV, TSV or JSON files as lookup datasets that correlate customer-supplied reference data with ingested events, with a per-entry time to live and JSON download. On-premise log collectors Collectors installed on Windows and Linux machines with installation packages, profiles defining what is collected, machine groups and policies, alias and proxy settings, scheduled parallel upgrades, bulk uninstall and their own audit logs. Per-instance integration permissions Restricts which roles may run each command on a given integration instance, so two instances of the same integration can carry different permission levels. Standard data sources Built-in ingestion mechanisms that pull raw logs and security events from third-party services and file-based sources and normalize them for correlation and analysis. Transporter for self-hosted integrations Relays traffic between the tenant and self-hosted integrations such as version control and code quality servers through the broker appliance, so private domains are reachable without exposing the internal network. Vendor connectors Consolidates a vendor's log collection, automation, remediation and posture capabilities into one named connector with a guided configuration wizard, across identity providers, cloud platforms, SaaS applications, security tools and data platforms.
SaaS, data, identity and API security AI security module Discovers AI models, agents, datasets and supporting infrastructure across cloud providers, maps the dependencies and data flows between them, detects supply-chain and configuration risk such as poisoned datasets or unsanctioned models, and reports it on a dedicated dashboard. API discovery and risk assessment Discovers APIs through traffic mirroring and gateway logs, profiles the risk of each endpoint, and surfaces shadow and abandoned APIs alongside the endpoints applications actively use. API gateway integration Connects to cloud provider and standalone API gateways to mirror traffic and analyze their logs, so security policies can be monitored and enforced across the gateways an organization already runs. API specification inventory Imports specifications in the OpenAPI format and extracts specification files from scanned cloud API gateways, then validates live traffic against the declared specification. Cloud identity entitlement management Calculates net effective permissions for every cloud and identity-provider identity, categorizes access, flags excessive, unused and inactive entitlements and role-chaining risk, and drives remediation workflows toward least privilege. Data patterns and profiles Defines the data patterns that identify sensitive values such as card numbers and national identifiers, and the data profiles built from them that label a file or table as sensitive, with built-in and custom entries that can each be enabled or disabled and false positives reported. Data security module Discovers, classifies, protects and governs sensitive data across cloud, SaaS and on-premise stores, reporting where sensitive data lives, how it is used and how exposed it is. Permission access tables Explores an identity's granted permissions and a destination asset's inbound permissions at several levels of granularity, resolving granters, policy types, wildcards and explicit resource grants. SaaS AI agent security Onboards enterprise AI agent platforms and inventories the agents running on them, the datasets they read and the tool wrappers they call, exposing overprivileged access and insecure credentials and enforcing controls on autonomous workflows. SaaS detection rules Out-of-the-box policies that identify configuration weaknesses in onboarded SaaS applications and drive the issues raised against them. SaaS remediation actions Presents a prioritized list of steps to resolve posture issues originating in SaaS applications, and delegates manual fixes to each application's own administrators by opening and tracking tickets in the organization's issue tracker. SaaS security checks A queryable, prioritized view of posture misconfigurations, vulnerabilities and compliance state across every onboarded SaaS application, used for triage, incident response and compliance auditing. SaaS security posture management Onboards SaaS applications through their APIs using administrator tokens or registered applications, scans each instance for misconfiguration, scores tenant security on a provider instances page, and aggregates posture, identity, data and agent findings on one overview dashboard. Topic classification Classifies documents by subject matter so that sensitive material such as contracts or strategy papers is recognized even when it contains no matching data pattern. Trusted domain configuration Defines which external domains the organization trusts so that discovered non-internal identities are flagged as external when their domain is not listed. Unified human identities Correlates a person's separate accounts across on-premise directories, identity providers, SaaS applications and cloud platforms into one human identity asset so risk is assessed per person rather than per account. Web and API threat protection Monitors and blocks attacks against web applications and APIs running on Linux workloads and behind integrated gateways, covering abuse of legitimate API functions, misconfiguration risk and forgotten endpoints, through agent-based protection profiles.
Access control and tenant administration API keys Issues and manages API keys that credential a user or application for API access, each scoped by the role assigned to it. Compute unit metering Meters query execution in compute units against a daily quota sized to the license, failing queries once the quota is exhausted, with a purchasable add-on that raises it. Data retention Sets how long each data type is stored, with published default retention periods per dataset and purchasable retention add-ons including cold storage. In-product support tickets Opens a support ticket from inside the console with the relevant context attached, including a console recording, uploaded logs and an automatically generated agent support file. Log and notification forwarding Forwards cases, issues and audit logs to email, a chat channel, a syslog receiver or a third-party destination such as a log platform, message queue, object store or webhook, through per-log-type forwarding configurations with documented payload formats. Management audit logs Records every administrative and investigative action across dozens of log types, retains them for 365 days, filters them in the console and forwards them to external systems in documented formats. Object-level access control Applies per-object permissions to user-defined dashboards, report templates, saved queries, playbooks and scripts so each can be restricted to named users or groups independently of role permissions. Query management controls Lets administrators set limits on running queries from a central query management page, governing what any user may execute against the data lake. Scope-based access control Restricts which assets, endpoints and datasets a user or group may see by assigning a scope, applied consistently across the inventory, policies, dashboards and queries. Server and security settings Configures tenant-wide preferences such as timezone, timestamp format, keyboard shortcuts and custom email branding, alongside session length limits and the domains and IP ranges users may sign in from. Single sign-on Authenticates users either through the vendor support portal account or through SAML 2.0 single sign-on against an external identity provider, with documented setup for the major providers. Tenant update notifications Emails administrators when a scheduled tenant upgrade or hotfix is pending and again when it completes, driven by forwarding rules over the management audit log. Users, groups and roles Creates users and user groups, assigns predefined or custom roles directly or through groups, supports nested groups, and combines role-based access to components and datasets with scope-based access to assets.
Detection, analytics and threat intelligence Adversary framework coverage A dashboard mapping the product's protection modules and detection rules onto the tactics and techniques of the industry adversary-behavior knowledge base. AI detection and response Detects AI-specific threats such as model tampering, prompt injection, model theft and training-data poisoning by combining cloud audit logs with prompt logs collected from the providers' AI services. Analytics rules management A consolidated page listing every analytics and behavioral analytics rule with the detector behind it, so analysts can review, enable and disable what the engine is allowed to raise. Behavioral analytics engine Streams logs and sensor data into a baseline built across more than a thousand dimensions and raises an issue when activity deviates from it, organizing detectors into algorithms with defined detection intervals and automatically disabling ones that generate excessive noise. Behavioral indicator rules Detects attacker behavior across process, registry, file and network activity through vendor-distributed global rules that update automatically and user-defined rules created individually or uploaded in bulk. Correlation rules Scheduled query-based rules that correlate events from several sources over a defined window to raise issues, with field replacement syntax for the generated issue, drilldown queries, pivots back to the source system and an auditing dataset recording every execution. Extended threat intelligence A curated library of threat objects and a high-volume indicator store, matched against collected logs by indicator rules with static and dynamic targeting, queryable in the search language, shown as context on cases and issues, callable from playbooks and read and written by an intelligence agent. Identity analytics Aggregates user profile information, activity and related issues behind user-based analytics detections so suspicious user behavior can be investigated in one place. Identity threat detection and response Classifies user and endpoint assets, detects identity-based attacks with behavior-based rules, scans directory infrastructure for misconfigurations and weak or compromised passwords, blocks malicious directory queries, and enforces conditional access rules from an agent on domain controllers; the CyberArk Identity Security Platform integration feeds audit events to the analytics detectors. Indicator of compromise rules Alerts on known malicious artifacts such as hashes, domains, IP addresses and paths, loaded in bulk from threat intelligence sources or defined individually, with optional rule expiry and a published capacity ceiling. User risk investigation Aggregates everything collected about a user into a risk view with graphs, tables and drilldowns, alongside a risk management dashboard for evaluating compromised accounts and insider threats.
Onboarding and cloud connections Cloud instance management Checks status, edits, enables, disables and deletes onboarded cloud instances, starts discovery scans, tracks instances still awaiting template execution, connects one manually, and drills into per-capability errors. Cloud offboarding Removes a cloud instance and decommissions the resources onboarding created, with scope-specific offboarding scripts for subscription, management group and tenant deployments and for each template type. Cloud permission updates Notifies administrators when a release requires additional cloud permissions and walks through granting them so onboarded instances keep working. Cloud service provider onboarding Connects AWS, Azure, Google Cloud, Oracle Cloud and Alibaba Cloud environments through a wizard that scopes which accounts are covered, selects the security capabilities to enable and chooses a scan mode, then hands back a template to run in the customer's own cloud. Government cloud deployment Offers government-authorized environments as isolated single-tenant instances selected during onboarding, with a published list of required network resources and the services that are unavailable in them. Kubernetes connector Deploys a connector into managed, OpenShift and self-managed Kubernetes clusters to collect cluster state and enforce admission control, with per-instance management, auto-upgrade and a published distribution support matrix. Licensing and plans Annual subscription licensing metered by the number of protected workloads, with add-ons for data collection, retention, forensics and compute units, and console views of entitlement and current consumption. Migration from Prisma Cloud Links a Prisma Cloud tenant to the new tenant and copies supported content and configuration across, covering posture, workload and application security settings and policy labels, with guidance for moving the older command-line scanners to the current one. Onboarding authentication templates Generates the infrastructure-as-code template each provider needs, whether a stack template, a declarative plan or a shell script, provisioning least-privilege roles for exactly the capabilities selected, with a refreshed template issued when the configuration changes. Outposts Deploys a dedicated set of scanning infrastructure inside the customer's own cloud account so assets are scanned locally, either as a standard outpost whose template provisions every resource or a bring-your-own-app outpost that authenticates with the customer's existing identity registration. Tenant activation Activates a tenant from the centralized gateway portal, repeated for each tenant an organization holds, and places it in one of the published hosting regions.
Query, dashboards and reporting Command center A landing dashboard summarizing account health, asset distribution and assets at risk, with preconfigured command centers for cloud security operations, cloud consumption and assistant activity. Dashboard and report access control Controls who may view or edit each dashboard, report template and widget through role- and scope-based access, public or restricted visibility, per-user sharing, ownership transfer, duplication and a trash folder for recovery. Dashboard and report import and export Exports and imports dashboards and report templates as JSON files, singly or in bulk, to back up content or move configurations between environments. Dashboards Builds dashboards from system or custom widgets on a drag-and-drop canvas, with global filters, drilldowns to a query, URL, dashboard or report, alongside system dashboards and preconfigured command centers managed from a dashboard manager. Graph search Searches assets and findings by the relationship types connecting them and renders the result as an interactive graph, with an embedded query builder, a shared and built-in query library, and the option to turn a graph query into a detection rule. Query and macro libraries Saves XQL queries and reusable macro fragments into personal and shared libraries with search, editing, sharing and visibility controls. Query builder Builds entity queries without writing syntax across process, file, network, network connection, registry, image load, event log and authentication data, and across all entities at once. Query center Lists completed and in-progress queries run on the tenant and manages scheduled and recurring queries together with their execution history. Reports Generates point-in-time reports from an existing dashboard or from a template built on library widgets, on demand or on a schedule, distributed to user groups or mailing lists and downloadable from a generated-reports list. Widget library A shared repository of dashboard and report components, holding widgets built from a query, a script or a natural-language prompt and parameterized so filters and drilldowns can act on them. XQL search Queries ingested data with the Cortex Query Language, with syntax suggestions, reusable macros, result tables, result graphing and a toggle that translates Splunk query syntax into XQL.
Security rules, policies and compliance Base image rules Designates registry images as organizational base images and maps derived images to them, giving image lineage so vulnerabilities can be traced and remediated at the base image. Cloud security policies Binds selected cloud security rules to an asset scope and an action, deciding where a rule applies and what issue is raised when it matches, through a default posture policy and custom policies. Cloud security rules Defines the detection logic evaluated against cloud, code and host assets, with rule types for configuration, identity permissions, network exposure, data, AI services, graph relationships and attack paths, built in or authored and cloned by the customer. Cloud workload policies Applies workload rules to asset groups at a chosen software lifecycle stage and sets the response, either raising an issue or preventing the violation, across misconfiguration, malware and vulnerability policy types. Cloud workload rules Defines the criteria that identify security violations on cloud workloads, using predefined rules or custom detection rules that name a scanner, the conditions to evaluate and the assets in scope. Compliance assessments and reports Runs a chosen standard against selected asset groups through an assessment profile, scores control adherence, and produces on-demand or scheduled assessment reports that can be exported, with an overview dashboard comparing posture across standards. Compliance standards and controls Provides catalogs of built-in regulatory standards and controls that can be cloned or authored as custom standards and controls and associated with detection rules; a control now carries a single category, an optional single sub-category, and can be linked to one or more custom standards. Serverless function posture rules and policies Custom attack path, configuration and network exposure rules written for serverless functions, combined into policies scoped to cloud accounts with the response taken when they match. Trusted image policies Evaluates container and VM images against trusted-image criteria and allows or prevents their deployment into Kubernetes environments, with defined precedence when policies contradict each other. Vulnerability policies Defines what happens to vulnerability findings matching given criteria, through predefined policies keyed on severity and exploit-prediction scores, custom issue-creation and prevention policies, a block grace period measured from the fix date, and an ignore list of CVEs, asset groups and assets. Workload preventive enforcement Blocks violating Kubernetes workload images at admission through the connector's admission controller and fails continuous integration stage builds when a workload policy is set to prevent.
AI assistants and agents Agent knowledge sources Grounds assistant agents in customer-supplied knowledge so their answers reflect the organization's own material rather than general information. Agentic Assistant chat Provides a natural-language chat in which a chosen agent builds a plan and executes multi-step security actions, with selection among system, public and user-built agents, saved chat history, and access from either the console or Slack. Agentic Assistant Hub Creates and manages the agents that build and execute plans, each with a model, user and conversation context and a permitted set of actions, and registers playbooks, scripts, commands and AI prompts as the actions those agents may call. Its Help Center agent diagnoses tenant security, health and workflows against product documentation and can automatically prefill a support ticket. Agentic Assistant safeguards Constrains what an assistant agent may access and act on, keeps its data handling inside tenant boundaries, and documents the transparency and accountability controls governing its behavior. AI prompt library Stores reusable large language model prompts that can be created, edited and shared, run as playbook tasks or exposed as agent actions, with role-based control over who may view and edit them. Automation Engineer agent Generates, queries and refines Python automation scripts and playbooks through a conversational agent inside the Agentic Assistant. Cortex Assistant Investigates entities entered in a search bar, including hosts, users, hashes, domains, IP addresses and cases, and returns consolidated findings and suggested next steps for triage and remediation. MCP server Connects an external language model client to the tenant over the Model Context Protocol, shipping built-in tools for fetching assets and managing cases and issues, running in a container or a virtual environment, and extensible with custom tools written against the public API. Natural-language query and visualization Translates natural-language prompts into XQL queries through a built-in text-to-XQL action, runs them, and renders the results as charts or tables so users can analyze data without writing query syntax. Outbound MCP integrations Lets assistant agents call tools hosted on third-party MCP servers so a plan can retrieve data from and act in external systems.
Discovery and protection of sensitive data across SaaS applications and cloud stores, with its own connector set for the vendor systems it ingests from.
Platform administration API keys Issues role-scoped API keys at a chosen security level that callers pass in the request header, managed from the integrations settings. Browser support Documents the supported desktop browser versions and notes that the interface is optimized for HTTP/2. Customer Support Portal authentication Authenticates users by default through their Customer Support Portal account, optionally with two-factor authentication, before a direct or group role grants tenant access. Federal compliance Offers FedRAMP High and Moderate authorized environments as isolated single-tenant instances on government cloud infrastructure, with data kept in the United States, federal egress endpoints, and documented service limitations. License expiration handling Keeps console access for a 48-hour grace period after expiry, continues monitoring and retention for 31 days, then decommissions the tenant and deletes all data, configuration and policies. License model Licenses capacity on two independent dimensions, workload units from the base license for the assets protected and a GB-per-day add-on for ingested activity logs, deployed either as a dedicated tenant or as an add-on to an existing Cortex tenant. Network access requirements Publishes the fully qualified domain names and IP ranges customers must allow, split into regional egress, inbound traffic to on-premises resources, and outbound traffic originating from engines, with firewall application identifiers where applicable. Public API Exposes tenant data and operations over an authenticated REST API, including running queries against collected data, with usage metered in compute units. Roles and access control Combines role-based access control over platform components and query datasets with scope-based access control that narrows each role to the data it needs, using predefined and custom roles. SAML single sign-on Authenticates users against any SAML 2.0 identity provider so corporate multi-factor and de-provisioning policies apply, with documented setup for Okta and Microsoft Entra ID. Supported regions Chooses the hosting region across the Americas, EMEA and Asia-Pacific, which fixes where logs and ingested data are stored and which associated services are available. Tenant activation Activates a tenant from Cortex Gateway using the activation email and a Customer Support Portal account, repeated for each tenant a customer runs. User groups Assigns roles through nestable user groups, where a user in several groups receives the combined highest level of access under both role-based and scope-based controls. User management Adds and manages tenant users created through the Customer Support Portal or single sign-on, with users lacking a role or group shown as revoked.
Dashboards and reporting AI-generated widgets Builds a visualization from a natural-language prompt, with the assistant generating and running the underlying query. Command centers Provides interactive landing views that bring discovery, classification, posture, detection and access governance into a single map, and a detection-focused command center for real-time threats. Custom dashboards Builds dashboards from a blank canvas or a template through a drag-and-drop builder, all organized and duplicated from a dashboard manager. Dashboard access control Governs dashboards, reports and widgets with role-based and scope-based access control plus public or restricted visibility, viewer and editor grants, sharing, and administrator-only ownership transfer. Dashboard import and export Exports and imports dashboards and report templates as JSON files, singly or in bulk, to back up or move configurations between environments. Deleted content recovery Holds deleted dashboards, reports and widgets in a trash folder for a retention period, from which they can be restored or permanently removed. Global dashboard filters Adds up to four free-text, single-select or multi-select filters that let any viewer change the scope of a dashboard's data. Predefined dashboards Ships out-of-the-box dashboards for data security, AI security and identity posture, each with widgets tailored to that view. Reports Generates point-in-time reports from a dashboard or a purpose-built template, one-time or on a schedule, distributed to users and mailing lists and kept as downloadable files. Script-based widgets Creates widgets backed by a script for calculations the query language cannot express or for data pulled from third-party systems. Widget drilldowns Links a widget to a query, another dashboard, a report or a custom URL so a click moves the viewer into the underlying detail. Widget library Holds every dashboard and report component in a shared repository that can be searched and filtered by name, type or owner, with each widget set public or restricted. XQL widgets Creates chart widgets from a query, including parameters that make them respond to dashboard filters and drilldowns.
Data collection infrastructure Broker VM Runs a hardened virtual machine inside the customer network that bridges local resources and the tenant, routing endpoints and collecting and forwarding logs and files for analysis. Broker VM applets Extends a Broker VM with installable collector applets that ingest different data types, activated and configured per broker or cluster. Broker VM high availability clusters Places two or more Broker VMs in a cluster with synchronized configuration and a heartbeat, providing automatic failover, manual switchover of the primary node and automatic upgrades. Broker VM images Publishes Broker VM images for the major hypervisors and cloud platforms, each with documented virtual machine compatibility requirements. Broker VM live terminal Opens a remote terminal session to a Broker VM directly from the management console. Broker VM management Manages registered brokers and clusters from the console: editing and importing configuration, adding and removing nodes, increasing cache storage, upgrading the broker and updating individual applets. Broker VM monitoring Logs Broker VM activity to the management audit log, raises version, connectivity and cluster notifications in the console, exposes a Prometheus metrics endpoint, and downloads broker logs on demand. Broker VM troubleshooting Reports per-applet connection and processing status on the brokers and clusters tabs and documents the corresponding application, connectivity and processing errors. DSPM database applet Audits on-premises PostgreSQL and MySQL databases from the Broker VM, giving visibility into the risk in their stored data. DSPM fileshare applet Connects the Broker VM to on-premises network file shares over SMB and NFS so their contents are discovered and classified. Transporter applet Establishes secure communication between the tenant and self-hosted systems such as version control servers and code quality servers.
Data discovery and classification Asset coverage catalog Documents which storage, database, disk and SaaS asset types are supported for classification on each cloud provider, including self-managed databases reachable only through an outpost scan. Custom data patterns Defines organization-specific detectors from a single regular expression plus mandatory context words, within documented complexity guardrails, and validates them before use. Data classification engine Scans discovered objects for sensitive records using hundreds of out-of-the-box classifiers for structured, semi-structured and unstructured data, extended with LLM-based classification and optical character recognition for images and PDFs. Data discovery Automatically finds data assets across cloud storage, on-premises file shares and databases, SaaS applications, DBaaS environments, code repositories and endpoints, reached by direct API or by the Broker VM. Data patterns Provides a catalog of detectable data structures such as credit card numbers, national identifiers and email addresses, each with region metadata and individually enabled or disabled for future scans. Data profiles Groups data patterns into business categories such as developer secrets or financial data, applied as a label to files and tables, with out-of-the-box profiles that can be duplicated and custom profiles that can be edited, disabled or deleted. DLP policy harmonization Connects to data loss prevention providers, extracts their policy configurations and maps them into one normalized schema so policies from every provider can be compared, filtered and sorted in a single inventory. False positive reporting Opens a structured support case from a misclassified object, collecting the matched data pattern, description and evidence for analyst review. Information protection labels Reads sensitivity labels applied by information protection frameworks on scanned files and surfaces each label's identifier alongside the platform's own classification. Scanning settings Selects which managed services, accounts, subscriptions or projects are scanned and which classification options apply to each. Topic classification Assigns a single business-relevant topic to unstructured text files in cloud locations, so documents without recognizable data patterns are still assessed for sensitivity.
Cloud onboarding Agentless Disk Scanning Permissions Grants Cortex narrowly-scoped Azure RBAC roles to scan virtual machine disks and images for vulnerabilities without installing an agent, splitting scope-wide read-only inventory and snapshot-read access from the create/delete permissions used to materialize and remove temporary disks, confined to a Cortex-owned resource group. Authentication templates Generates a CloudFormation, Resource Manager or Terraform template that the customer executes in their cloud to provision least-privilege roles scoped to the capabilities selected. Cloud audit log collection Ingests provider audit logs through an event-driven pipeline, either fully managed or from a customer-owned bucket, including cross-account key access for encrypted logs. Cloud instance management Lists connected and pending cloud instances with per-capability status, supports editing an onboarded configuration, manual connection, and drill-down into errors on an instance. Cloud offboarding Decommissions the resources onboarding created, with scripted procedures per cloud scope and deployment method, including dry-run verification. Cloud onboarding wizard Onboards a cloud provider environment through a wizard covering partition, scope, scan mode, deployment method, region and account filters, security capabilities, custom tags and audit log collection, ending in a generated template. Cloud permission updates Notifies administrators when a platform release requires new cloud permissions and guides granting them so existing capabilities keep working. Scanning outposts Deploys a scanning outpost inside the customer's own cloud tenancy, as a standard outpost or with a customer-supplied application registration, so data is scanned without leaving the environment. Service perimeter support Documents the identity and authorization values needed to monitor cloud resources that sit inside a network service perimeter.
Data sources and connectors Data source onboarder Adds a new data source through a guided flow that installs the source, sets up an instance and configures the recommended playbooks, scripts and content, then summarizes what was created. DBaaS onboarding Adds managed data platforms such as Snowflake, Databricks and MongoDB Atlas as data sources through account credentials or service accounts, enabling automated scanning, classification and risk assessment of their assets. Ingestion health monitoring Collects per-source ingestion metrics, raises health issues when collection stops or drops, and exposes the metrics to queries for tracing a specific collector. Integration command permissions Restricts which roles may run each command on an integration instance, so different instances of the same integration expose different command sets. Integration instance management Edits, deletes, enables and disables configured instances, refreshes their log data and reports per-instance connectivity status grouped by integration. Integration troubleshooting Surfaces command execution errors on a troubleshooting dashboard and supports testing an instance and downloading a debug log. Marketplace integrations Installs integrations from content packs and configures instances of them, with saved credentials, so commands and automations can act against third-party products. Standard data sources Collects raw logs and events through built-in data collectors that connect directly to vendor APIs or file sources and normalize the result into the Cortex data model. Unified connectors Configures a vendor through one named connector and a guided wizard, selecting the capabilities to enable such as log collection, security posture, identity posture, data security, agent security scanning and automation, and authenticating with stored vault credentials.
Data security posture AI Security Posture Management Inventories the AI stack across cloud and SaaS, including models, agents, training datasets and model endpoints, and identifies where sensitive data is used in training and inference. Asset management Maintains a unified inventory across asset classes such as data, identity and AI, organized by class, category and type, with each asset's attributes and relationships. Cloud storage cost optimization Surfaces redundant and stale stored data so cloud storage spend can be reduced alongside risk. Compliance monitoring Maps posture findings to security standards such as GDPR, PCI DSS, NIST and HIPAA, and verifies that data stays within its required geographic boundaries. Data inventory Presents every discovered data asset on one page with an asset card consolidating attributes, enhancements and the related cases, issues and findings, plus widgets and filtering. Data Security Posture Management Continuously discovers data assets, classifies their contents and assesses configuration and access risk for data at rest across cloud, SaaS, on-premises, DBaaS and AI environments in one classification-aware view. Risk prioritization and remediation Scores and ranks data risk across the estate and drives remediation of the highest-exposure assets.
Agentic AI assistant Agentic assistant governance Controls through role-based access who may use the assistant chat and who may view, create, edit, delete, enable and disable agents, alongside documented data handling and action transparency. Agents Hub Centralizes agent management, enabling and disabling system agents and creating custom agents with their own actions. Assistant in Slack Lets users interact with the Agentic Assistant from a chat workspace rather than the console. Cortex Agentic Assistant Provides a chat interface to system and custom AI agents that build and execute multi-step plans across the environment, with conversation starters for common tasks. Data security agent Answers natural-language questions grounded in the tenant's inventory, posture findings and detections, takes actions on what it finds, and drafts custom data patterns. MCP server Ships a downloadable Model Context Protocol server, installable locally or in a container, that lets any MCP-compatible client query the tenant, run investigations in natural language, manage cases and issues, and expose custom tools.
Data detection and response Automated remediation Runs response actions against connected services, such as revoking access or escalating a confirmed threat, using automations enabled through Marketplace content. Cases and issues Represents each policy violation or finding as an issue and aggregates related issues into a case, so teams remediate a root cause rather than isolated alerts. Data analytics detection rules Ships and maintains the analytics rules behind data detections, viewable under detection rules, with resulting detections tagged so data-specific risk can be prioritized. Data detection and response Baselines normal behaviour for human and non-human identities across cloud, SaaS and AI infrastructure and detects deviations such as mass downloads, risky sharing and ransomware behaviour, with each alert carrying what was accessed, its sensitivity and its owner. Data investigation tools Provides an investigation toolset built around the relationship between identities, cloud infrastructure and data sensitivity, so the blast radius of a threat drives remediation order. Rules and policies Separates detection logic from administrative scope: cloud security rules define what constitutes a violation, and policies decide which environments those rules apply to.
Data management and storage Compute units Meters query cost in compute units against a daily quota, expandable with an add-on, with a configurable daily consumption limit and rewarmed cold-storage results cached free for subsequent queries. Data retention Applies per-data-type retention periods to ingested and derived data, extendable with retention add-ons and visible against the tenant's license. Dataset activity monitoring Reports activity on datasets and dataset views so usage and query load can be traced. Datasets Stores ingested and normalized data in datasets and dataset views that queries, dashboards and detection run against, managed under permissioned data management settings. Hot and cold storage tiers Routes ingested data into hot storage for the licensed retention period and into cold storage for cheaper long-term retention, with period-based and per-dataset extensions that can apply retroactively. Lookup datasets Imports customer-supplied CSV, TSV or JSON data as lookup datasets that correlate with ingested events, with per-entry time to live and JSON download.
Data access governance Cross-environment access analysis Maps permissions originating in identity providers and SaaS directories onto the cloud data they grant access to, so entitlements are analyzed across environments rather than per system. Effective permission calculation Resolves each human and machine identity's IAM roles, group memberships and resource-level policies into the access it actually holds over data assets. Identity access graph Visualizes the access paths by which human and non-human identities can reach sensitive data across cloud providers. Least privilege recommendations Identifies over-privileged identities against critical data assets and recommends the reductions that enforce least privilege.
Search and query Graph search Explores assets and findings by their relationships in a visual graph, making attack paths and indirect exposure visible. XQL query language Builds queries against collected data in a query builder for ad hoc investigation, with queries that can be saved, scheduled and used to power dashboards and widgets.
Extended detection and response across endpoint, network and cloud telemetry — incidents, causality analysis and response actions — as documented for the 3.x console.
Incident Investigation & Response Action Center Tracks the progress of every investigation, response and maintenance action taken on protected endpoints, with filtered views for file quarantine and block and allow lists, and initiation of new bulk actions. Alert Timeline View Shows every event, alert, informational BIOC and correlation-rule hit involved in an attack in time order, as a fuller companion to the causality view's selected chain. Alerts Page Lists every alert with a side panel showing its source, severity, description, suppression counts and behavioural context, from which an analyst can restar or reseverity it, pivot into causality, exclude it, copy it or export the details to a file. Artifact and Asset Investigation Views Provides drill-down views for a user, host, IP address, file or process hash that aggregate the data collected about it into graphs and tables, with risk scoring, peer comparison, related incidents and threat-intelligence context. Automation Rules Matches new alerts against ordered, scope-controlled conditions and fires the configured action — email, Slack or syslog notification, alert and incident field changes, or endpoint response actions — with per-action rate thresholds and an audit log of every execution. Causality Views Visualizes the cause-and-effect chain behind an alert as an interactive node graph with an information overview, forensic highlights and an all-events table, in endpoint, network, cloud-audit and SaaS-audit variants. Endpoint Isolation Halts all network access on an endpoint except traffic to Cortex XDR, DNS and root-user DHCP and HTTPS, holding it isolated until released and blocking agent upgrades while isolated. Endpoint Script Execution Runs Python scripts on endpoints from the console using either supplied out-of-the-box scripts or user-uploaded scripts and code snippets, tracking execution and storing per-endpoint results. Featured Alert Fields Labels specific hosts, users and IP addresses as featured so that alerts containing them are flagged in the alerts table, filterable, and usable as criteria in incident scoring rules. File Allow and Block Lists Forces a file hash to always run or never run on every endpoint regardless of verdict or policy, with the lists and the actions taken against them tracked in the Action Center. File Quarantine Moves a detected malicious file from its location on a local or removable drive into an isolated quarantine folder on the endpoint, and manages and restores quarantined files from the console. File Retrieval Instructs agents to locate and upload named files, up to 20 files and 500 MB across 10 endpoints per request, packaged as one archive with a JSON status log for download from the Action Center. File Search and Destroy Searches a per-endpoint file database of paths, hashes and metadata built by the agent for a known or suspected malicious file, and deletes it from any or all endpoints where it exists. Forensic Hunt Collections Searches selected forensic artifact types across a large number of Windows and macOS hosts once, on repeat or on a schedule, returning normalized result tables that can be stacked by frequency, with per-endpoint search status. Forensic Investigations Groups hunt and triage collections under a named investigation with per-user access permissions, alerts raised on ingested collection data, a timeline of tagged evidence, derived key assets and artifacts, and export of collected data for long-term retention. Forensic Triage Collections Collects detailed system state from a single Windows or macOS endpoint — supported forensic artifacts, user-defined file paths, full drive file listings, event logs and registry hives — online through the agent or offline through a downloadable collector for hosts with no agent or network. Incident Scoring Assigns each incident a numeric urgency from user-defined scoring rules and sub-rules matched on alert attributes and assets, a machine-learning SmartScore derived from incident attributes and cross-customer insights, or a manually set value, with a breakdown of how the score was reached. Incident Starring Flags incidents for filtering on the Incidents page and the incident management dashboard, either manually or through starring configurations that automatically star any incident containing an alert matching defined attributes. Incidents Groups the alerts, assets and artifacts sharing a root cause into one incident carrying severity, status, assignee, score and star, worked from a detailed or table view of the Incidents page and closed with a required resolution reason. Live Terminal Opens a remote session to an endpoint through the agent for navigating and managing the file system, managing running processes, running operating-system and Python commands, and transferring files within documented size limits. Managed Threat Hunting Pairs the tenant with a Palo Alto Networks research team that monitors it year-round and delivers threat and impact reports into a dedicated console page, with notification-centre alerts, configurable report email recipients and two-way inquiries. Memory Image Collection Captures the memory of a single Windows endpoint and makes the image available for download so it can be analysed with external forensic tools. Quick Launcher Opens an in-context shortcut from anywhere in the console to search hosts, usernames, IP addresses, domains, filenames, file paths and timestamps with wildcard support, and to launch artifact views or response actions from the result. Remediation Suggestions Proposes and applies reversals of the file and registry changes a malicious causality chain made on an endpoint, so affected objects need not be found by hand.
Threat Detection Alert Deduplication Consolidates recurring WildFire and Local Analysis alerts for the same event on the same endpoint within a time window into a single alert using a generated fingerprint key. Alert Exclusions Suppresses alerts matching defined criteria from incidents and search results, optionally applying the rule to historic alerts, while the agent continues to raise them locally. Analytics BIOC Rules Raises alerts on a single suspicious event with an identified causality chain, using statistical or machine-learning user, endpoint and network profiles built by the Analytics Engine, tuned to the environment and delivered through content updates. Analytics Engine Builds behavioral baselines from endpoint, firewall, VPN, directory and third-party sensor data across more than a thousand dimensions, maintains peer-group and entity profiles, and raises an Analytics alert when recent activity deviates, with per-detector lookback intervals and automatic suppression of detectors exceeding 5,000 matches a day. BIOC Rules Detects behaviour across process, registry, file and network activity through user-defined rules evaluated against both historical and incoming data, alongside Palo Alto Networks global rules that can be disabled, excepted or copied as templates, and can also drive custom prevention in Restrictions profiles. Correlation Rules Runs XQL-based rules on a schedule to correlate multi-source events into alerts over a defined time frame, with field replacement syntax, drill-down to generated alerts, and execution auditing recorded in a dedicated dataset for troubleshooting failures. Detection Content Updates Delivers Palo Alto Networks content packages to the tenant and agents in parts, covering default security profiles, protected processes, local analysis logic, trusted signers, behavioral threat protection rules, global BIOC rules, event-log definitions and supported Python modules. External Dynamic Lists Hosts an IP address list and a domain name list of indicators found in alerts, published for a firewall to fetch and enforce access control against. Honey User Accounts Designates decoy user accounts with no legitimate purpose so that any activity involving them raises an alert, configured by adding accounts to the honey user asset role. Identity Analytics Aggregates directory group, organizational unit, role, login, host, alert and process-execution information for the user behind a user-based analytics alert, tagging the alerts and rules it applies to. Identity Threat Module Adds coverage for compromised accounts and insider threats through automatic asset-role classification, a behavioral analytics tab showing the deviation that triggered an alert against baseline, user and host risk views, and a risk management dashboard. IOC Rules Alerts on known malicious artifacts defined by full path, file name, domain, destination IP, MD5 or SHA256, loaded in bulk from threat-intelligence sources or defined individually, matched against past and future collected data up to a limit of 4,000,000 indicators. MITRE ATT&CK Tactic Coverage Maps the attack tactics the Analytics Engine can alert on to the MITRE ATT&CK knowledge base so detection coverage can be read against a shared taxonomy.
Collection Infrastructure Broker VM Deploys a hardened virtual appliance inside the customer network that bridges it to the tenant, with images for Alibaba Cloud, AWS, Google Cloud Platform, Azure, KVM, Hyper-V, Nutanix and VMware ESXi, self-updating software, configuration import between brokers, and disk expansion for data caching. Broker VM Agent Proxy Routes agent and XDR Collector traffic to the management server through the Broker VM as a transparent proxy, so endpoints in restricted networks receive policy and upgrades without direct internet access and without the broker decrypting the connection. Broker VM Collector Applets Activates data collector applets on the Broker VM for the source type being collected — syslog, Windows Event Collector, database, FTP, files and folders, CSV, NetFlow, Apache Kafka, Network Mapper and Local Agent Settings — each versioned and updatable independently of the broker. Broker VM High Availability Clusters Groups two or more Broker VMs into a cluster with synchronized configuration, a primary and standby nodes, a heartbeat to the tenant and automatic failover, running applets in active/active or active/passive mode and upgrading them in a rolling sequence. Broker VM Installer and Content Caching Caches agent installers and content updates on the Broker VM so endpoints fetch them locally rather than from the internet, subject to raised processor and disk requirements. Broker VM Monitoring and Troubleshooting Reports Broker VM state through management audit logs retained for 365 days, Notification Center messages for connectivity, disk usage and cluster health, downloadable broker log bundles, a remote Live Terminal into the appliance, and a local metrics endpoint. XDR Collector Installs an on-premises log collector on Windows and Linux machines that ships file, log and Windows event data to the tenant using Elasticsearch Filebeat and Winlogbeat, with installation packages, MSI and msiexec install paths, documented machine requirements and uninstall. XDR Collector Application Proxy Assigns up to ten application-specific proxy servers to an XDR Collector, chosen at random per connection, falling back to the machine's system-wide proxy and then to a direct connection. XDR Collector Machine Groups Groups collector machines statically by selection or dynamically by hostname, alias, domain, IP range, collector version or operating system, optionally drawing on Active Directory data from Directory Sync, so policy and actions can target the group. XDR Collector Monitoring Tracks collector state through an audit log retained for 365 days, connectivity verification against the required Palo Alto Networks resources, per-collector aliases and automatically created raw datasets named for the collected vendor and product. XDR Collector Profiles and Policies Defines what each collector gathers through Filebeat, Winlogbeat and settings profiles built from out-of-the-box or content-pack templates, then applies them to collector machines and groups through ordered policy rules. XDR Collector Upgrade Scheduling Upgrades XDR Collectors on a schedule, with a configurable parallel-upgrade cap of up to 500, selected days of the week and an any-time or specific-time window.
Data Ingestion & Management Cloud Asset Ingestion Pulls cloud asset inventory from AWS, Google Cloud Platform and Microsoft Azure accounts into the tenant so cloud resources appear alongside endpoints in the asset tables. Compute Units Metering Meters XQL API and cold-storage queries against an annual compute-unit quota, with an add-on to buy more, a configurable daily consumption limit and a usage page showing the cost of each query. Custom HTTP Log Collector Receives logs from unsupported vendors over HTTP in Raw, JSON, CEF or LEEF format at up to 80,000 events per second, parsing them automatically into a vendor-and-product dataset. Data Ingestion Monitoring Records per-source ingestion volume, rate and freshness-delay metrics in five-minute aggregation periods into a metrics dataset, raises health issues from them, and lets users write correlation rules against the metrics. Data Retention and Storage Tiers Splits stored data between fully searchable hot storage and cheaper cold storage, applies per-dataset retention from the tenant's storage licenses and retention add-ons, and caches rewarmed cold data for repeat queries. Dataset Management Manages the datasets and presets queries run against — dataset types, the default dataset, dataset views that expose a virtual query-defined slice of one or more datasets under RBAC, and an audit trail of dataset activity. Event Forwarding Exports ingested and parsed event logs to a customer Google Cloud Platform storage bucket over Pub/Sub for archive, compliance retention and external analytics, including a fixed-schema endpoint event export. External Alert Ingestion and Mapping Accepts alerts from any external source in CEF or LEEF format over the syslog collector or the API, and maps their fields onto the Cortex XDR alert schema through per-vendor mapping rules with field converters and regex extraction. Lookup Datasets Uploads CSV, TSV or JSON name-value tables that queries, detection rules and hunts can join against, with a configurable time to live, editing in place and download back to JSON. Palo Alto Networks Product Log Ingestion Streams logs from Next-Generation Firewall, Panorama, Prisma Access and other Palo Alto Networks products into the tenant from the Collection Integrations page, either directly or through Strata Logging Service, with a per-integration toggle for URL and File log types and a migration path between the two paths. Parsing Rules Transforms raw third-party log records at ingestion using XQL-based rules bound to a vendor and product, with default and user-defined rule views, group no-match policies, tagging, a simulator that runs rules against real sample logs, and an error list for troubleshooting. Third-Party Log Ingestion Ingests logs and alerts from a documented catalog of third-party sources across network, authentication, cloud-provider and SaaS categories — including Amazon S3, Azure Event Hub, Google Cloud Platform, Okta, Zscaler, Check Point, Cisco ASA, Fortinet, Google Workspace, Microsoft 365, Box, Dropbox, Salesforce and Workday — each with its own credential and forwarding setup.
Endpoint Agent Management Agent Application Proxy Assigns up to ten application-specific proxy servers to an agent, set at installation, from the endpoint command-line tool or from the console, falling back to the system-wide proxy and then to a direct connection. Agent Deployment and Upgrade Installs and upgrades the agent across Windows, Mac, Linux, Android and iOS, pushing a package to up to 5,000 endpoints at a time from the console, or updating mobile agents from their platform app store or an endpoint management system. Agent Installation Packages Creates named per-platform installation packages that agents register against, and edits, hides or deletes them from the Agent Installations page. Agent Maintenance Actions Runs per-endpoint maintenance from the console — restarting the agent, clearing the agent database in debugging mode, retrieving support logs and the support file password, setting an endpoint alias, and sending push notifications to iOS devices. Agent Server Migration Moves registered agents between managing Cortex XDR servers from the console, re-registering each agent with the new server as a fresh install without its previous server-side data. Agent Settings Profiles Customizes agent behaviour per platform and endpoint group — including EDR data collection, scanning, user interface, tamper protection and telemetry options — in profiles that can be imported from and exported to a file. Agent Status Monitoring Reports each agent as protected, partially protected or unprotected with the reasons behind the state, tracks upgrade status, and keeps an agent audit log for 365 days that can be forwarded to email, a syslog server or a chat channel. Agent Tokens Authorizes agent functions that would otherwise need an administrative password using per-endpoint rolling tokens regenerated every fourteen days, or temporary tokens valid for one to twenty-one days. Agent Uninstall and Endpoint Deletion Uninstalls agents individually or in unlimited bulk from the Action Center and deletes endpoints from the tenant, returning the licence to the pool immediately and purging the record after a defined retention window. Critical Environment Agent Versions Pins selected endpoints to Critical Environment agent releases, which carry the same feature set and content coverage on a slower maintenance cadence with a 24-month support window for regulated environments. Endpoint Groups Groups endpoints statically by selection or dynamically by tag, hostname, alias, domain or workgroup, IP range, installation type, agent version, endpoint type, user or operating system version, optionally using directory data from the Cloud Identity Engine. Endpoint Tags Assigns dynamic tags to endpoints at agent installation, from the endpoint command-line tool, or from the console, and uses them to build endpoint groups, policies and actions.
Endpoint Protection Automatic Endpoint Backup Turns on the endpoint operating system's own backup mechanism from the console so files can be restored after a ransomware attack. Device Control Blocks USB-connected and Bluetooth devices on Windows and macOS endpoints by device type, with per-vendor allow lists, and blocks print job types, applied per endpoint group. Disk Encryption Reports the encryption state of Windows and Mac endpoints and applies disk encryption policy rules that drive the platform's native full-disk encryption. Endpoint Exception Rules Carves exceptions out of the prevention baseline from one central page — disable-injection-and-prevention rules, disable-prevention rules, support exceptions, IOC and BIOC suppressions, global exceptions applying to every endpoint, and migrated legacy per-profile exception rules with file-hash import. Endpoint Malware Scanning Scans Windows, Mac and Linux endpoints and attached removable drives for dormant malware that is not attempting to run, on demand from the console or on a periodic schedule, applying the endpoint's malware profile settings to what it finds. Endpoint Policy Rules Attaches prevention, extension and agent settings profiles to endpoints and endpoint groups through ordered per-operating-system policy rules, with out-of-the-box defaults, scope locking, and profile and rule import and export. Exploit Prevention Profiles Blocks attempts to exploit software and operating-system flaws through endpoint protection modules covering reconnaissance, memory corruption, code execution and kernel protection, each set to block, report or disabled and applied to a documented set of protected processes. File Verdict Analysis Decides whether an executable is malicious by consulting, in order, the hash exception policy, cloud threat-intelligence verdicts for the sample, and on-endpoint local analysis, forwarding unknown samples for deep analysis within documented daily sample and size limits. Host Firewall Allows or blocks endpoint network traffic through rules applied by host firewall policy rules, with separate rule sets for endpoints inside and outside the organization network, enforced on Windows and macOS through the operating system firewall APIs. Malware Prevention Profiles Defines per-platform how the agent treats known malware, unknown files, macros and malware-like behaviour such as ransomware and script-based attacks, with each protection capability set to block, report or disabled against a supplied default. Pause Endpoint Protection Disables all protection profiles on selected endpoints while keeping the agent connected and still reporting data and accepting actions, until protection is resumed. Restrictions Prevention Profiles Limits the locations executables may run from — specific local folders, removable media and network paths — with each restriction set to block, notify, report or disabled.
Tenant Onboarding & Administration Cortex Gateway Provides one portal for activating tenants and managing the roles, user groups and users shared across every tenant on the Customer Support Portal account, restricted to the Account Admin role. In-Product Support Cases Opens a support case from the console through a wizard that attaches tenant and licence context, an optional console recording, uploaded logs and the agent technical support file for a selected endpoint. License Plans and Add-Ons Gates features and data collection by plan — Prevent, Pro per Endpoint, Pro per GB and Cloud per Host — extended by add-ons for extended threat hunting data, forensics, host insights, the identity threat module, managed threat hunting, event forwarding, compute units and retention. Multi-Tenant Central Licensing Holds endpoint and gigabyte entitlement in a main-account pool that an administrator allocates, resizes or reclaims across child tenants from Cortex Gateway, returning a deleted tenant's allocation to the pool immediately. Multi-Tenant Managed Actions Defines configurations in the parent tenant for alert exclusions, starred alerts, prevention profiles and file block and allow lists, allocates each to chosen child tenants, and executes the resulting security actions on their behalf. Multi-Tenant Management Lets a main account create and manage child tenants from Cortex Gateway with strict data segregation, switch the console to a child tenant to investigate its incidents, alerts, queries, causality and timeline, and track child tenant state on a Tenant Management page. Regional Tenant Hosting Hosts the tenant and its associated Cortex services in a chosen country region, with ingested data and logs remaining in that region and any streaming source required to sit in the same one. Required Network Access Documents the communication servers, storage buckets, IP addresses and App-IDs that agents, collectors and brokers must reach through the customer firewall, per hosting region. Security Settings Controls how long a user session lasts, which domains and IP ranges users may sign in from, which IP addresses may call the API, and the minimum TLS version used for communication. Server Settings Sets tenant-wide behaviour such as scope-based access control mode and data ingestion monitoring, alongside per-user console preferences for keyboard shortcuts, timezone and timestamp format. Tenant Activation and Onboarding Activates a tenant from the activation email through Cortex Gateway using a Customer Support Portal super-user account, and walks the deployment through a numbered onboarding checklist covering activation, agent pre-installation, agent install, configuration, data sources and health checks. Tenant Upgrade Applies purchased entitlements and major version releases to the tenant, notifying in advance and letting an eligible administrator upgrade immediately or schedule a date and time, with the schedule managed from the Notification Center.
Search & Query Cortex Query Language Queries datasets and presets through a pipe-delimited staged language with its own operators, comments and string handling, addressing hot storage by default and cold storage through a separate dataset form, including queries that span both. Query Builder Entity Queries Builds queries from guided forms for a specific entity type — process, file, network, network connection, image load, registry, event log and authentication activity — plus an all-actions search that spans every entity for a host or process. Query Center Lists every query run on the tenant with its history and currently in-progress queries, showing who ran each query and from what context, and allowing results to be reopened, queries to be edited and rerun, scheduled, or cancelled while running. Query Library Saves queries to a personal library that can be shared with other users on the tenant, labelled, and searched across name, description, creator, query text and label. Query Result Visualization Charts query results from the results page through a chart editor offering area, bubble, column, funnel, gauge, line, map, pie, scatter, single-value and word-cloud outputs. Scheduled Queries Runs saved queries on a recurring schedule, with editable frequency, a record of previous executions, and the ability to disable or remove a schedule. Splunk Query Translation Converts a Splunk SPL query typed into the search field into XQL syntax through a Translate to XQL toggle that shows the source and translated queries side by side, covering a documented subset of SPL functions. XQL Function Library Provides functions across string manipulation, arithmetic, aggregation and statistics, arrays, objects and JSON extraction, timestamp handling, IP address and CIDR evaluation, geolocation, regular expressions and window ordering. XQL Search Interface Runs XQL queries from the Query Builder with syntax autocomplete and inline definitions, preset, relative and calendar timeframe selection, streaming partial results while a long query runs, and a results table that can be exported. XQL Stage Library Provides the query stages that shape a result set — filtering and field selection, aggregation and comparison, joins and unions, sorting, deduplication, binning, transactions, windowing, views, and stages that call other queries or set query configuration.
Asset Management Asset Inventory Aggregates managed and unmanaged assets discovered from defined internal network ranges, the Broker VM Network Mapper, agents, firewall EDR data and third-party logs into all-assets and per-category views with detail side panels and right-click pivots. Asset Risk Scores Calculates a risk score for each user and host asset from the alerts and incidents associated with it, recalculated as new alerts arrive and comparable against peers over a selected timeline. Asset Roles Continuously classifies users and endpoints into roles such as Domain Controller, Administrator and Executive User from their activity, editable manually or by CSV import, and used as the peer group for analytics baselines and score comparison. Cloud Compliance Runs Center for Internet Security benchmark checks on Linux and Kubernetes endpoints and reports the resulting posture violations, once cloud compliance collection is enabled in the Linux agent settings profile. Cloud Inventory Lists cloud assets collected from Google Cloud Platform, Microsoft Azure and Amazon Web Services by category, with filtering, per-asset views, pivot actions and export to a tab-separated file. Host Inventory Records business and IT operational data from every endpoint — such as installed applications, services and autoruns — scanned by the agent every 24 hours with 30 days of history and an on-demand rescan. Network Configuration Defines the internal IP address ranges and domain names that identify the corporate network, and combines them with firewall EDR data, agent logs, ARP cache, the Network Mapper and an optional agent-driven ping sweep to place assets on it. Vulnerability Assessment Identifies and quantifies the security vulnerabilities of applications installed on each endpoint, drawing CVE severity and metrics from the NIST National Vulnerability Database so exposure can be prioritized and patched.
Access Management Customer Support Portal Authentication Signs users in to Cortex Gateway and the tenant with their Customer Support Portal username and password, optionally with two-factor authentication, as the default path when SAML is not configured. Directory Identity Source Connects on-premises, cloud or hybrid directories as one continually synced source of user and group identity, supplying the user, group and computer data that endpoint groups, scoring rules and identity analytics rely on. Management Audit Logs Records every administrative and investigative action across dozens of log types — from API keys and datasets to policy rules and response actions — retained for 365 days, filterable in the console, queryable, and forwardable to email, syslog or a chat channel. Roles and Permissions Controls access through unmodifiable Palo Alto Networks default roles and custom roles copied from them, with view and edit permissions set per console component, per pivot action, and per dataset for XQL access. SAML Single Sign-On Authenticates console users against any SAML 2.0 identity provider, configured either with an IdP SSO URL, issuer and certificate or with a metadata URL, mapping the provider's group membership to user groups, with an eight-hour session. Scope-Based Access Control Narrows a non-administrator user to specified tags and the entities beneath them in restrictive or permissive mode, applied across endpoints, policies, profiles, automation rules, starring configurations and forensic investigations. User Management Adds users from the Customer Support Portal account and grants them access by assigning a role directly or through a user group, with per-user permission editing and a users page showing effective access.
APIs & External Services API Key Management Issues Standard and Advanced API keys paired with a key ID and tenant FQDN, allows several roles per key so its permissions aggregate, and restricts which IP addresses or ranges may call the API. Broker VM API Manages registered Broker VMs programmatically from the tenant — listing brokers with their configuration, applets and metrics, editing metadata, issuing registration tokens, rebooting, shutting down and upgrading, configuring applets, and requesting remote log bundles — with a companion on-appliance API for bootstrap and network setup. Cortex XDR Public API Exposes a REST API at the tenant FQDN covering endpoints, agent distribution packages, tags and prevention profiles; incidents and alerts including CEF and parsed alert insertion; response actions; script execution; indicator upload; lookup datasets; XQL queries and quota; syslog servers; users, roles and system health — rate limited to ten requests a second per tenant. External Notification Services Registers the destinations notifications are sent to — installing the Cortex XDR app into a Slack workspace for a dedicated alert channel, and defining syslog receiver servers manageable from the console or the API. Log and Notification Forwarding Forwards alerts, agent audit logs and management audit logs to an external destination on a per-log-type configuration, sending RFC 5425 comma-separated syslog messages or a field-per-line email body, with documented field layouts for each log type. Third-Party Threat Intelligence Lookups Adds external verification sources to each key artifact in an incident, showing a third-party multi-scanner reputation score beside the artifact once the service licence key is entered in the tenant configuration.
Dashboards & Reporting Custom Dashboards Builds dashboards from a predefined template or from scratch by placing widgets in the dashboard builder, previewing with mock or real data, and managing them from the Dashboard Manager with a per-widget and whole-dashboard refresh. Dashboard Drilldowns and Filters Makes a dashboard interactive through per-widget drilldowns that change the dashboard in place or link to an XQL search, a URL, another dashboard or a report, and through fixed header filters driven by parameters defined in custom XQL widgets. Predefined Dashboards Supplies built-in dashboards covering incident management, agent management, risk and other aspects of the tenant, available according to licence, selectable as the sign-in default and usable as templates. Reports Generates reports from dashboard-based or custom widget templates, on demand or on a recurring schedule, and imports and exports report templates as JSON for transfer between environments. Widget Library Holds predefined and user-created widgets grouped by category and searchable, including XQL-query-backed widgets rendered as tables, line graphs or pie charts and free-text widgets that accept Markdown.
The 5.x generation of extended detection and response, documented in its own space with its own API and release notes, and reached from 3.x through a separate upgrade guide.
Data Ingestion & Collectors AI Prompt Log Collection Collects model invocation prompt logs from supported cloud AI services using the existing cloud collectors, configured through provider-side invocation logging and diagnostic settings. Broker VM Runs a secured virtual machine inside the customer network that bridges it to the tenant, routing endpoint traffic and collecting and forwarding logs and files for analysis, and receiving updates automatically after initial registration. Broker VM High Availability Cluster Groups two or more Broker VMs into a cluster with synchronized configuration, active/active or active/passive applet modes, load balancer health checks, automatic failover, manual switchover and scheduled automatic upgrades. Broker VM Image Deployment Publishes Broker VM images in OVA, VHD, VMDK and QCOW2 form for deployment on the major on-premises hypervisors and public cloud platforms, with a token-based registration flow. Broker VM Management Manages registered Broker VMs from the console — editing and importing configuration, upgrading the appliance, updating individual applets independently, collecting logs, opening a remote terminal, expanding cache storage, and surfacing version and connectivity notifications. Broker VM Prometheus Metrics Exposes Broker VM usage statistics in Prometheus metrics format on a local endpoint for external scraping and dashboarding, disabled by default. Cloud Messaging Ingestion Subscribes to cloud publish-subscribe and event streaming services to receive provider logs, including a deployable function for network flow log collection, normalizing them into queryable datasets. Cloud Object Storage Ingestion Collects audit, network flow and DNS logs staged in cloud object storage buckets, authenticating with a dedicated user or an assumed role, and configured either by a provided template or manually. Collector Machine Groups & Policies Groups collector machines, optionally using synchronized directory information, and applies collector profiles to them through ordered collection machine policies. Data Ingestion Metrics Records per-source ingestion volume, size, rate and freshness delay in five-minute aggregation periods into a metrics dataset and preset that can be queried in XQL to trace collection from a specific source. Data Retention & Storage Tiers Applies default retention periods per data type across hot and cold storage in the data layer, extendable with retention add-ons sized to licence and ingestion volume. Data Source Onboarder Adds a new data source through a guided onboarder that installs the data source, creates an instance and configures the recommended playbooks, scripts and other content, showing everything configured in a summary screen. Database & Event Stream Collection Pulls records from relational databases and consumes topics from self-managed Kafka clusters through Broker VM Database and Kafka Collector applets, with authenticated and unauthenticated cluster support. Dataset Management Manages the tenant's datasets and their storage duration across hot and cold storage tiers according to licence and retention add-ons, and records dataset activity in audit logs held for 365 days. Event Forwarding Forwards selected event types out of the tenant to an external destination through a cloud publish-subscribe channel, with per-event-type field inclusion and exclusion. File & Folder Log Collection Collects log files from network shares and file servers through Broker VM Files and Folders, CSV and FTP collector applets, mapping the vendor and product that name the resulting dataset. Filebeat-Based Log Ingestion Ingests file activity, container and Windows service logs from hosts running Filebeat as a system logger, with a custom Filebeat-based collector and configuration-file fields that name the vendor and product of the resulting dataset. First-Party Palo Alto Telemetry Ingestion Ingests logs, alerts and assets from Palo Alto Networks products — next-generation and cloud firewalls, Panorama, Prisma Access and its browser, Enterprise DLP, SaaS Security, WildFire, IoT and Device Security — over the cloud log collection service. HTTP Log Collector Receives logs from any sender over HTTP in raw, JSON, CEF or LEEF format at up to 80,000 events per second, automatically parsing them into a vendor and product named dataset. Ingestion Health Issues Raises health-domain issues for data ingestion, collection, correlation and automation failures, with out-of-the-box detection plus user-authored correlation rules over ingestion metrics, and drilldown to the failing source. Kubernetes Connector Onboards Kubernetes clusters as a data source and manages the resulting connector instances, showing per-cluster connectivity state from the Kubernetes Connectivity Management view. Local Agent Settings Applet Turns a Broker VM into a local proxy and cache for managed agents, serving agent installers and content locally and relaying agent communication to the cloud manager, in standalone or high-availability cluster form. Log Collection Service Device Management Lists the firewalls connected to the cloud logging and collection service for the tenant and disconnects them individually or in bulk. Log Type Filtering Selects which log types are ingested per cloud log collection source to control ingestion cost, replacing the earlier all-or-nothing URL and File log toggle with source-level selection and bulk editing. Lookup Datasets Creates reference datasets from imported CSV, TSV or JSON files that correlate customer-supplied lists such as high-value assets or terminated employees with environment events, with a configurable time to live and JSON download. NetFlow Collection Receives NetFlow v5, v9 and IPFIX flow records on configurable ports from any or specific source addresses through a Broker VM NetFlow Collector applet. Parsing Rules Overrides or extends default log parsing with an editor for rules written in XQL plus INGEST, COLLECT, RULE and CONST sections and format-specific parse functions, with parsing errors captured in a dedicated dataset. Standard Data Collectors Provides built-in collectors that pull raw logs and security events over direct vendor API connections or file collection, configured per data source with credentials and scope. Syslog Collection Receives syslog from external senders through a Broker VM Syslog Collector applet on configurable ports and protocols, parsing CEF, LEEF, Cisco, Corelight and raw formats into datasets. Third-Party Data Source Catalog Ingests logs, alerts and configuration data from a catalog of third-party vendors spanning identity providers, SaaS suites, cloud platforms, firewalls, ticketing and threat intelligence, each offered as a standard data source, a Marketplace content pack integration or a unified connector. Unified Vendor Connectors Consolidates a vendor's log collection and automation capabilities into one connector configured through a single wizard with vault-stored credentials, replacing separate Marketplace integrations for supported vendors. Windows Event Collection Collects Windows event logs from servers and domain controllers via a Broker VM Windows Event Collector applet using Windows Event Forwarding, including Windows Core hosts, with certificate issuance and renewal for the forwarding clients. Windows Security Auditing Setup Documents the Windows-side audit configuration needed before event logs can be collected — enabling audit event IDs by group policy or locally, LDAP server diagnostics logging, certificate services auditing and directory object access auditing — and how to validate the result. XDR Collector Administration Manages installed collectors from the XDR Collectors Administration page — setting machine aliases individually or in bulk, configuring an application-specific proxy, and uninstalling collectors in bulk. XDR Collector Audit Logs Records monitored XDR Collector activity as audit log entries retained for 365 days and viewable from tenant settings. XDR Collector Deployment Creates signed XDR Collector installation packages and installs them on Windows and Linux collector machines through MSI, Msiexec, RPM, DEB or shell installers, including via third-party software deployment tooling. XDR Collector Profiles Defines what a collector machine gathers through Filebeat, Winlogbeat and Settings profiles for Windows and Linux, edited as configuration files with supplied templates for DHCP, DNS, IIS and NGINX among others. XDR Collector Upgrade & Content Updates Pushes collector software upgrades from the console on a schedule with a configurable number of parallel upgrades, and distributes collector content updates that each collector retrieves within a staggered window.
Case Investigation & Response Action Center Initiates and monitors endpoint actions from one place, showing quarantined files and the allow and block lists, and tracking the status of every action requested. Case & Issue Context Data Stores structured investigation data as case and issue context that playbooks and commands read and write, searchable and deletable per key, and extendable to keep extra fields from a command's raw response. Case & Issue Schema Configuration Shapes how security data is organized and displayed by configuring case statuses and domains, custom fields and indicator types, with system-default statuses protected and domain names fixed after creation. Case & Issue SLAs Defines time-based resolution goals for cases and issues through ordered SLA rules and additional case timers, tracks status against them, and exposes built-in SLA fields for reporting. Case & Issue Starring Stars issues and their linked cases automatically from a starring configuration or manually during triage, respecting scope-based access control. Case Grouping Consolidates issues from the same attack flow or entity into a single case using machine-learning grouping over shared artifacts and context, with configurable field mapping to improve grouping of custom detections. Case Merge & Issue Linking Merges related cases into one, reconciling assignees, teams, scores and context data, and links or unlinks individual issues to and from cases across domains. Case Mirroring Sync Profiles Mirrors cases with a third-party ticketing platform through sync profiles, reflecting updates outbound, inbound or both depending on the profile type. Case Scoring Scores cases through a machine-learning scoring engine plus enabled scoring rules, so analysts can assess severity and impact and prioritize accordingly, with scope-based access taken into account. Case Teams & Access Restriction Assigns individual users and user groups to case team roles such as assignee, watcher and contributor, and restricts a sensitive case so only assigned team members can see or act on it. Case Timeline Consolidates attack events, analyst activity and system actions into a chronological record of a case that analysts extend with their own records, mark as evidence, register from playbook tasks, and arrange into custom timelines. Cases Represents a problem as a case that connects related issues, assets and key data into one story, assigned to a domain, tracked through a lifecycle with resolution statuses and reasons, and reopened automatically if a matching issue arrives soon after auto-resolution. Causality Views Reconstructs an attack as a causality chain from stitched endpoint, network, cloud and SaaS telemetry, with dedicated views for endpoint, cloud, cloud audit log, SaaS and network stories plus a grouping graph. Endpoint Response Actions Acts on a compromised endpoint from the console — isolating it from the network, pausing protection modules, scanning it for malware, retrieving files or support logs, and remediating changes made by malicious activity — with per-platform and minimum agent version support. Entity Investigation Views Drills into a single entity through dedicated views for hosts, users, assets, IP addresses and file or process hashes, each aggregating that entity's activity, risk score and related cases over a chosen window. Evidence Collects the technical data behind an issue as typed evidence with its own lifecycle, drawn from causality chains and attack-path graphs, consumable by playbooks and quick actions and retrievable programmatically or by export. External Issue Mapping Translates alerts arriving from third-party systems into cases according to a configurable mapping. Featured Fields Marks specific host, user and IP attribute values as featured so any issue containing them is flagged in the issues table for tracking. File Quarantine & Verdict Overrides Quarantines detected malware into a local folder on the endpoint with defined retention, restores or deletes quarantined files, and overrides verdicts through allow and block lists including bulk hash import from CSV. Forensic Investigations Runs named forensic investigations with their own permissions, collecting configured artifact categories from hosts into hunt and triage collections, collecting memory images, and exporting collections for offline analysis or retention. Indicator Extraction Extracts indicators from issue fields and enriches them by running commands and scripts, in configurable extraction modes that trade enrichment depth against issue creation latency. Investigation Timeline Lays out the forensic sequence of events, issues, informational BIOCs and correlation rule matches involved in an attack, complementing the narrower causality view. Issue Analysis Breaks an issue down on an issue card with evidence, findings, technical information, remediation guidance and response options, retaining case context and linking through to the War Room and Work Plan. Issue Deduplication Consolidates identical agent-based security events on the same endpoint within a time-to-live window into one issue using a deduplication key, keeping the suppressed events locatable. Issue Exceptions & Exclusions Records time-bound exceptions that defer remediation of a confirmed issue and permanent exclusions that accept it outright, created from an issue or a rule, with an optional approval workflow routed to named approvers. Issues Consolidates non-informational detections from every source on an Issues page for triage, with deduplication, per-issue fields updatable from the interface or a command, copy and export, and a chronological issue feed of case activity. Live Terminal Opens an interactive remote session to a managed endpoint or Broker VM from the console for live inspection and administrative commands. Quick Launcher Opens an in-context shortcut from anywhere in the console, by icon, menu or keyboard shortcut, for searching information, running common investigation tasks and initiating response actions. Resolution Center Provides an action-oriented workspace for resolving a whole case, organizing outstanding work into pending, recommended, in progress and done tabs rather than isolated issue views. Search & Destroy Locates a known malicious file across every endpoint using a locally built file database of paths, hashes and metadata, and destroys it on any or all of them. Threat Hunting Supports proactive hunting across collected telemetry for a known threat, turning findings into issues and investigations. Threat Intelligence Context in Cases Extracts indicators from detections at issue level, aggregates them at case level and presents the intelligence context in a dedicated tab, including behavioural threat analysis attributing activity to campaigns or cybercrime. Unified Case View Gives managed-service and multi-tenant administrators one consolidated view of cases across every child tenant, with triage and actions performed centrally. War Room Gives each case and issue a shared workspace where analysts run CLI commands, scripts and integration commands, and record collaborative notes and comments against the investigation.
Asset, Exposure & Compliance ASM Enrichment of Cloud Assets Applies attack surface management to cloud posture data, surfacing internet-exposed cloud infrastructure and flagging unmanaged cloud services and the issues raised on them. Asset Class Coverage Covers distinct asset classes with dedicated inventory views — cloud resources, compute and containers, serverless functions, VM and container images, identities, data stores, AI assets, APIs, network infrastructure, security services, code and supply chain, devices and external surface. Asset Groups Groups assets statically or by dynamic attribute rules so they can be acted on in bulk and used as the scoping unit for scope-based access control. Asset Risk Scores Assigns users and hosts an aggregate risk score, typically 10 to 100 and extendable by custom modifiers, that reflects how much security risk that identity or machine currently represents. Asset Roles Continuously classifies users and endpoints into behavioural roles such as domain controller, administrator or executive user, and lets an administrator add or exclude specific assets to correct the automatic assignment. Attack Surface Management Discovers internet-facing assets through continuous global internet scanning and open-source intelligence, attributes them to the organization with human-in-the-loop review, and maintains them as external surface inventory that customers can add to or remove from. Attack Surface Rules Matches vendor-managed rules against global scan results to detect exposed or misconfigured customer-owned assets, with per-rule severity, enablement state and deprecation handling. Attack Surface Testing Runs daily controlled exploits against approved externally facing assets to confirm CVEs, default credentials and other risks, with per-test intrusivity levels, target selection and issues raised from confirmed results. Business Application Criteria Defines business applications by grouping interconnected assets across the software development lifecycle using criteria or explicit membership, so risk can be prioritized and exported per application. Compliance Assessment Profiles Configures which standard runs against which asset group and scans those assets on a recurring cycle to check adherence. Compliance Assessments & Reports Reports compliance against a standard as a score with per-control statuses, drillable to control, rule and individual asset level, and generates assessment reports for immediate viewing, download or a recurring schedule. Compliance Overview Dashboard Presents compliance performance against industry standards and internal frameworks on an out-of-the-box dashboard with comparative views and filters across the monitored environment. Compliance Standards & Controls Ships a catalog of built-in regulatory standards and controls that cannot be edited, and lets an organization clone them or author custom standards and controls associated with its own detection rules. Cortex Network Scanner Scans specified IP ranges across on-premises and cloud environments from a Broker VM applet to identify responsive hosts, services and vulnerabilities, in authenticated and non-authenticated modes. CVSS Recasting Overrides the published CVSS score or severity of a vulnerability platform-wide so existing and future findings reflect the organization's own risk judgement consistently. Digital Risk Protection Detects brand impersonation and credential theft risks, including lookalike brand risk domains used for phishing and malware distribution, using the asset inventory plus embedded intelligence. Emerging Vulnerabilities Aggregates global attack surface threat events and zero-day exploits on one page with their assessed impact on the organization, gated behind the attack surface rules permission. Endpoint Vulnerability Assessment Identifies and quantifies security vulnerabilities on agent-managed endpoints and reports the exposure and patch status of installed applications across the network. Exposure Management Consolidates exposures from first-party sensors and third-party scanners into a normalized, deduplicated view through the data stitching engine so they can be assessed, prioritized and responded to as one set. Exposure Management Command Center Presents exposure management operations as a command center dashboard of visualizations and key performance indicators, with drilldown from most elements into filtered dashboards and pages. Externally Inferred CVEs Infers likely CVEs on external services by matching the identified product name and version against the National Vulnerability Database and grades each match by confidence. GeoIP Data Collection Collects geographic location data for discovered attack surface assets so the observed network distribution can be compared with the organization's expected global footprint. Global Lookup Queries global internet scan data for certificate hashes, IP addresses and domains, returning registration details, geolocation, related certificates, observed services, ASNs and passive DNS records. Host Inventory Collects business and IT operational data from every agent-managed endpoint on a daily scan, retains a rolling 30-day view and supports an on-demand rescan, so IT and security gaps surface in one inventory. Internal Network Configuration Defines the internal IPv4 and IPv6 address ranges and internal domain suffixes that identify owned network assets, entered manually or uploaded from CSV, and names them for use in investigation. Network Mapper Maps the internal network from a Broker VM applet, discovering hosts and reporting scan details and applet metrics. Security Controls Inventory Records which security mechanisms are deployed on which assets, detected automatically or manually attested, with control roles, compensating controls, coverage improvement and effectiveness rules that turn inherent risk into residual risk. Third-Party Vulnerability Ingestion Imports assets and CVE-linked vulnerabilities from third-party scanners through built-in integrations or a vulnerability ingest API, merging them into the asset inventory. Unified Asset Inventory Holds every discovered asset across enterprise, multi-cloud, code and external surface in one repository with a strict classification hierarchy, per-asset cards and profiles, cloud hierarchy paths, and lifecycle cleanup of stale entries. Vulnerability Intelligence Maintains a live vulnerability feed drawn from vulnerability databases, vendor feeds and commercial providers, enriched with the vendor research team's own findings on cloud and open-source projects. Vulnerability Management Identifies, assesses, prioritizes and remediates vulnerabilities across the environment through linked views of vulnerabilities grouped by CVE, individual findings, generated issues and affected assets. Vulnerability Policies Matches each new vulnerability finding against ordered policies keyed on CVSS or EPSS severity and other criteria, then takes the policy's issue-creation or prevention action, with configurable block grace periods and ignore lists. Vulnerability Risk Score Scores each vulnerability from 0 to 100 by combining public vulnerability intelligence with organization-specific context, refreshed daily and carried on findings and issues for sorting and prioritization.
Cloud & Application Security API Traffic Ingestion for API Security Streams request and response data from API gateways into the tenant using vendor-specific plugins and policies so the API security module can scan the traffic for threats and vulnerabilities. Application Security & ASPM Secures the software development lifecycle from code to cloud with detection rules and policies over code, infrastructure-as-code templates, packages and CI/CD configuration, scans of repositories, container images and pipelines, and a supply chain catalog of the security tools already in the pipeline. Asset Findings Builds per-asset knowledge from collected sources about configuration, behaviour and context as typed findings, viewable on a findings card, queryable, and convertible into issues by rules. Automated Fix Pull Requests Produces a fix suggestion for an application security issue including the original code block, remediation instructions and suggested code, then opens a pull request with the fix and tracks its status. Cloud AI Security Surveys the AI assets an organization runs regardless of deployment mode or cloud provider and prioritizes the risks attached to them from a dedicated module view. Cloud Audit Log Collection Collects cloud provider audit logs into the tenant through provider-native event pipelines at account, organizational-unit or organization scope, including automated, bring-your-own-bucket and Control Tower variants with optional key-managed encryption. Cloud Authentication Templates Generates the infrastructure-as-code template a cloud onboarding needs — CloudFormation, Terraform or Azure Resource Manager — which the customer executes in their cloud account to provision the roles, identities and resources the tenant requires. Cloud Instance Management Manages onboarded cloud instances — checking status and health, editing configuration, enabling, disabling or deleting them, initiating a discovery scan, inspecting created resources and exporting errors to a file. Cloud Instance Offboarding Decommissions a cloud instance and the resources its onboarding created, using per-scope offboarding bundles and scripts with a dry-run plan step and post-run verification. Cloud Permission Update Notifications Notifies administrators through health alerts when a release requires new permissions on an onboarded cloud instance, and guides granting them without changing the instance connection status. Cloud Scanning Scope Configuration Selects which supported cloud services and resources are scanned per instance, and authorizes scanning of resources sitting inside provider service perimeters. Cloud Security Policies & Rules Detects cloud misconfigurations and risky configuration through cloud security rules grouped into policies, managed under posture management and scoped to selected environments. Cloud Service Provider Onboarding Onboards AWS, Microsoft Azure, Google Cloud, Oracle Cloud Infrastructure and Alibaba Cloud environments through a wizard that sets partition, scope, scan mode, deployment method, region and account filters, security capabilities and resource tags. Cloud Workload Protection Policies Applies compute policies and rules to cloud workloads to hold them to a security baseline, preventing misconfiguration and reducing risk across the estate. Code-to-Cloud Coverage Measures what proportion of assets have a traceable lineage between their source code and their running cloud instance, reported as a coverage ratio on a dashboard. Container Registry Connectors Connects third-party container registries so their images are pulled in for scanning, with per-vendor connector configuration and an initial scan setting. Custom Cloud Detection Rules Authors custom detection logic tied to a custom compliance control so that organization-specific best practices and unlisted regulatory requirements raise issues, applied through a cloud security policy that scopes the rules. Data Classification Identifies, categorizes and labels sensitive data through configurable data patterns, and serves as the shared engine behind both cloud data scanning and endpoint data loss prevention detection. Data Security Posture Management Gives visibility into cloud data assets such as storage buckets, databases and backups and into the objects inside them, so sensitive data locations, usage and exposure can be assessed. Discovery Engine Scans onboarded cloud accounts to discover assets, services and resources from a published discovery catalog and adds them to the unified asset inventory. Identity Security Module Governs human and non-human identities across cloud, SaaS and on-premises environments, resolving what each identity can actually do and which resources it can reach through effective permission calculation. Least Privilege Access Recommendations Recommends a narrower set of IAM policies or roles for an asset by preserving every action it actually performed over a lookback period, and answers which resources an identity can reach and which identities can reach a resource. Least-Privilege Cloud Access Model Authenticates to onboarded cloud accounts without static keys, using OIDC workload identity federation and short-lived tokens with isolated identity flows per capability, and documents every permission each security module requests. Pending Cloud Instance Connection Holds a cloud instance in a pending state between wizard completion and template execution, and lets an administrator connect it manually when the automatic callback from the cloud environment does not arrive. Security Outposts Deploys a dedicated set of scanning infrastructure inside the customer's cloud account or on-premises environment so disk, serverless, registry and data scanning runs locally, offered as a standard Cortex-defined outpost or a bring-your-own-app variant. Software Bill of Materials Generates a software bill of materials for a repository, an asset or a whole organization in a selectable format and version with configurable included attributes. Third-Party Scan Result Ingestion Ingests code scan results from external security tools through a generic collector that exposes a per-instance API endpoint accepting supported interchange formats, alongside the built-in source-control and pipeline integrations. Unified Rules Links a cloud security rule and an application security rule into one unified rule created and deleted atomically, so the same control is enforced consistently from code through build to runtime. Web & API Security Protects web applications and APIs running on Linux workloads and behind integrated API gateways with agentless scanning, risk assessment of discovered API endpoints, threat monitoring and policy enforcement across the connected gateways. Workspace Identity Ingestion Ingests user, group and group-membership data from a cloud workspace directory into an onboarded cloud instance so permission relationships and identity risk can be resolved to real people.
Tenant Setup & Administration API Key Management Issues, lists and revokes API keys that authenticate a user or application to the tenant's APIs, with per-key actions available from the API Keys table. Application Security Contributor Metering Counts unique non-bot human contributors who committed to a billable, non-archived, scanner-enabled repository within the last 90 days, as the basis for application security billing. Child Tenant Managed Actions Creates and allocates action configurations per child tenant, then defines the specific security actions the parent may execute on that child's behalf. Cloud Identity Engine Directory Source Reads user, group and computer information from on-premise, cloud or hybrid directories through the Cloud Identity Engine so policy and event context can be expressed in users and groups rather than IP addresses. Compute Units Meters heavy query types against a free daily compute-unit quota sized to the licence, fails queries that exceed it, and exposes usage widgets and a table plus an add-on that raises the annual allocation. Console Interface Presents one workspace across dashboards, cases, investigation, search and automation with a left navigation menu, saved table views and filters, a notification center and a tenant navigator for multi-tenant switching. Cortex Gateway Provides one portal for managing tenants plus the roles, user groups and users shared across all of them, restricted to account administrators. In-Product Support Tickets Opens a support ticket from inside the console with the surrounding context attached, optionally recording the console session and uploading logs, and routes through a help agent when the assistant is enabled. Licence Allocation & Expiration Enforces the purchased agent and capability quota with a revocation policy, and on expiry grants a short access grace period, keeps protecting endpoints for a further period, then decommissions the tenant. Licence Plans & Add-Ons Offers product variants chosen by infrastructure location and workload type, extended by capability and capacity add-ons, with the tenant's entitlements visible in settings. Managed Services Configuration Governs how the vendor's managed services team operates in the tenant — a permission level per response action for server and workstation asset types, an ordered escalation contact list, and the distribution list that receives managed service reports. Management Audit Logs Records every administrative and investigative action in the tenant, retained for 365 days, filterable in the console and forwardable to an email distribution list, syslog server or chat channel. Multi-Tenant Central Licensing Lets a parent account own a pool of endpoint and storage entitlement and dynamically add, resize or delete child tenant allocations from the gateway, returning freed capacity to the pool. Multi-Tenant Management Runs a parent tenant over child tenants with strict data segregation for managed service providers and large enterprises, letting the parent view and investigate child data and track every child from a tenant management page. Network Access Requirements Publishes the FQDNs, IP addresses, ports and App-ID coverage that must be permitted per region for agent, engine, Broker VM, authentication, content update, data collection and log forwarding traffic, including a US federal government set. Object-Level Access Management Enforces least privilege on individual custom objects — dashboards, report templates, playbooks, scripts, saved queries and widgets — through per-object roles layered on role permissions and tenant-level sharing settings, and enforced on API access too. Regional ML Processing & Data Residency Keeps all tenant data processing, including generative AI features, inside the region selected at activation, covering data at rest, processing location and policy enforcement. Role-Based & Scope-Based Access Control Restricts what a user may do through per-component role permissions over the console and query datasets, and what data they may see through scope-based access control, on top of a set of predefined roles. SAML Single Sign-On Authenticates console users against an enterprise identity provider over SAML 2.0 with documented setup for the common providers, group mapping, just-in-time account creation and deprovisioning on removal. Server & Security Settings Configures tenant-wide session duration and the domains and IP ranges users may sign in from, alongside per-user presentation settings for keyboard shortcuts, timezone and timestamp format and a custom logo for outbound task emails. Staged Content & Product Rollout Rolls product and security content out in phases with quality gates, protection layers on the agent, deployment monitoring and documented rollback and remediation paths, so updates arrive quickly without risking operational continuity. Stored Credentials Stores usernames, passwords, certificates and SSH keys as reusable named credentials so integrations and administrative tasks can authenticate without exposing the secret, gated by role permissions. Support Portal Authentication Authenticates users by default through the vendor's customer support portal account with optional two-factor authentication, adding them by invitation and granting no visibility until a role is assigned. Supported Deployment Regions Hosts the tenant and its associated services in a published set of regions across the Americas, EMEA and Asia-Pacific, chosen at activation. Tenant Activation Activates a tenant from the central gateway portal against a customer support account, repeated per tenant for organizations running more than one. Tenant Version Upgrade Lets eligible administrators upgrade the tenant to a new major version immediately or schedule it for later, with the tenant briefly unavailable and the scheduled upgrade manageable or cancellable from the notification center. User Groups & Role Assignment Assigns permissions by giving a user a role directly or through membership of user groups, sourced from native local groups, dynamic identity provider group mapping or directory synchronization, with nesting and automatic revocation.
Endpoint & Email Protection Advanced Email Security Module Adds a detection, investigation and response layer over cloud-hosted email by connecting to the mail platform through secure API integrations, with protected domains, block and allow lists, phishing addresses and URL filtering configured per tenant. Device Control Restricts which external USB and Bluetooth devices may connect to Windows and macOS endpoints and whether print jobs are allowed, through device control profiles with permanent, temporary and per-profile exceptions. Disk Encryption Reports the encryption state of Windows and macOS endpoints encrypted with the native platform tools, and enforces encryption through disk encryption rules attached to policies. DLP Content Classification Identifies file content by its actual internal format rather than its extension so renamed files cannot bypass policy, and inspects the contents of compressed archives so rules apply to the files inside them. DLP Data-in-Motion Rules Defines which data may move to which applications and application groups, raising a data security issue when a rule is violated, with a recommended rollout that validates a rule on a few endpoints before widening it. Email Command Center Gives an interactive overview of email security status with metrics on incoming data, issues and cases, remediation outcomes, trending attack vectors, risky users and URL and file reputation. Email Remediation Automation Executes policy-driven actions on email threats in real time from customizable remediation response rules, and audits every automatic and manual action in a remediation action center. Email Threat Detection Flags malicious, suspicious and policy-violating messages using artifact-based, metadata-driven and LLM-powered engines, with every contributing analytics rule listed and manageable on a consolidated rules page. Endpoint Data Loss Prevention Prevents exfiltration of sensitive data by enforcing policy on the endpoint even when offline across web, local and USB channels, delivered as a module downloaded to eligible endpoints plus a browser extension, with per-endpoint module and extension status. Endpoint Extension Policies Delivers the agent's hardening capabilities as extension profiles attached to extension policies, covering host firewall, disk encryption, device control, host inventory and vulnerability assessment, each with its own exceptions. Endpoint Policy Exceptions Overrides the baseline endpoint policy from one place with legacy profile exceptions, support exceptions, disable-prevention and disable-injection rules, indicator rule exceptions and organization-wide global exceptions, matched on paths, hashes, signers, certificates or command lines. Endpoint Protection Modules Activates a set of protection modules per platform through security profiles, each targeting a different attack technique, with the module set determined by the profile and platform rather than configured individually. Execution Restrictions Limits the locations and conditions from which executables may run on an endpoint through restriction capabilities that ship with a default configuration and can be tuned per profile. Exploit Protection Stops attempts to exploit software and hardware flaws with per-technique protection modules covering memory corruption, illegal code execution and exploit kits, applied by default to a researched list of susceptible processes. File Integrity Monitoring Detects unauthorized or anomalous creation and modification of files and folders on configured paths, raising events from the agent's detection and response engine on workstations and servers alike. Host Firewall Controls inbound and outbound traffic on Windows and macOS endpoints through hierarchically enforced rule groups applied as host firewall policy rules, with network location awareness and per-endpoint activity monitoring. Mailbox Inventory Lists every active mailbox under email security protection in a single table linked to the unified asset inventory, with widgets and filters that update together. Malicious Email Inventory Presents flagged emails in a dedicated triage view showing why each was flagged, with widgets, a filterable table and quick remediation actions. Malware Protection Blocks known and unknown malicious executables, macros and scripts through a prevention engine that evaluates child process policy, restriction policy, hash verdict and malware policy in sequence, with per-operating-system mitigation methods. Prevention Profiles & Policy Rules Customizes protection through per-platform malware, exploit, restrictions and agent settings profiles that are attached to ordered policy rules and applied to endpoints or endpoint groups, with default profiles applied out of the box and profiles editable, duplicable, exportable and deletable. Profile Exceptions from Issues Creates agent prevention profile exceptions for Windows process, behavioural threat and Java deserialization issues, and adds a file path to a malware profile allow list, directly from the issues table. Serverless Function Protection Applies prevention policy to serverless functions through rules whose function-parameter filter is stored in the policy and evaluated at runtime to select matching functions. Unknown Sample Sandboxing Forwards unknown files to the cloud sandbox for detonation and verdict, checking a local agent hash cache and then the tenant before uploading, within published daily sample upload and verdict query quotas.
Detection & Threat Intelligence Active Directory Security Posture Management Scans Active Directory against known misconfiguration patterns and weak or compromised passwords, surfaces AD identities and posture detection rules, and gives specific remediation guidance for each finding. AI Detection & Response Detects threats specific to AI workloads such as model tampering, prompt injection, model theft, denial of ML service and training data poisoning, using cloud audit logs for infrastructure-level signals and prompt logs for model-level ones. Analytics Engine Profiles endpoint, network and cloud telemetry from multiple sensors to build a behavioural baseline and raises Analytics and Analytics BIOC issues when activity deviates from it. Analytics Rules Management Gives one table of every Analytics and Analytics BIOC rule that could raise an issue, with per-rule viewing, editing and enablement so detection coverage can be tuned centrally. BIOC Rules Detects tactics, techniques and procedures rather than static indicators through behavioural indicator of compromise rules built from an XQL query or an entity, alongside vendor-authored global rules delivered by content update that a tenant can override. Conditional Access Policy Evaluates live authentication requests against user security context, risk level and protocol data to allow, challenge or block access, managed through prioritized identity access rules with their own access logs. Correlation Rules Runs scheduled XQL rules that correlate events from multiple sources and raise issues, with issue field mappings, drilldown queries, writing results to a dataset or lookup, bulk import, an active-rule ceiling and an auditing dataset of every execution. Extended Threat Intelligence Operationalizes threat intelligence across the platform with a curated library of threat actors, malware families, vulnerabilities and research reports, plus high-volume indicators carrying verdicts, tags and a managed lifecycle. External Threat Intelligence Verification Adds third-party threat intelligence services as extra verification sources for each key artifact in a case, alongside the first-party sandbox verdict. Graph Detection Rules Turns a graph search into a detection rule so threats are identified from relationships between entities rather than from individual events evaluated in isolation, with the resulting graph rules viewable and manageable. Honey User Designates a decoy account that appears to hold broad access, so that any use of it raises an alert. Identity Analytics Baselines user and authentication behaviour from directory and authentication logs to detect anomalous identity activity, enabled alongside the analytics engine. Identity Profiles Centralizes identity security policy for domain controllers in a Windows-only agent profile mapped to domain controller endpoint policies, which switches on the identity posture and access control features. Indicator Exclusion List Permanently excludes named indicators such as IP addresses, domains, URLs and file hashes from indicator handling, with an exclusion reason recorded against each entry. IOC Rules Raises issues on known malicious objects by matching indicators of compromise, defined individually or uploaded in bulk from threat intelligence sources, against both historical and incoming endpoint and network data, with optional rule expiration. Malicious LDAP Query Prevention Evaluates LDAP traffic in real time in context rather than per query to separate legitimate administrative lookups from reconnaissance, and blocks the malicious ones. Managed Threat Hunting Adds round-the-clock hunting by the vendor's threat researchers as a licensed service, delivering threat reports on critical findings into the tenant for investigation. MITRE ATT&CK Coverage Maps protection modules and detection rules to MITRE ATT&CK tactics and techniques on a coverage dashboard to expose gaps, and maps observed behaviour in a case to the same framework on an issue card. Sandbox Analysis Reports Surfaces the sandbox verdict for each analyzed file together with a report of sample information and observed behaviour per testing environment, so an analyst can judge the verdict rather than accept it. Third-Party Indicator Enrichment Enriches indicators in the tenant with reputation data from an external threat intelligence service configured with its own API key. Threat Intelligence Indicator Rules Scans collected log data for known malicious IPs, domains and file hashes and raises an issue on a match, targeting either static indicator lists or dynamic attribute-based filters over threat intelligence context.
Automation & Content Agent Script Library Creates, manages and runs Python scripts directly on endpoints from the Action Center for response actions and forensic collection. Automation Engines Runs integrations and scripts on customer-hosted Linux engines that reach systems the cloud tenant cannot, installed from shell, DEB or RPM packages, grouped for load balancing, and configurable for proxies, custom certificates and private image registries. Automation Exclusion Policies Blocks automation from acting on specified assets or conditions through exclusion policies managed in an Automation Exclusion Center, optionally driven by access-controlled lists. Automation Rules & Quick Actions Triggers playbooks and Quick Actions automatically when defined conditions are met, or manually on one or more issues during an investigation, with automated executions running as the system rather than the triggering user. Engine Container Runtime Executes engine integrations inside containers on Docker or rootless Podman, with a hardening guide, per-container memory, CPU, PID and file descriptor limits, network hardening, non-root internal users, image and storage location control and a documented migration path between the two runtimes. Exposure Remediation Automation Automates enrichment and remediation of attack surface and vulnerability issues through a supplied content pack of playbooks wired up with automation rules, integrations and vulnerability policies. External Dynamic Lists Publishes IP addresses and domains found in alerts as hosted external dynamic lists that a firewall retrieves over an authenticated URL and enforces in a security policy. Filters & Transformers Shapes data inside playbooks and fields with built-in string, date and general filters and transformers grouped by category, plus custom filters and transformers written for cases the built-ins do not cover. Integration Command Execution Runs system commands, integration commands and scripts from the command line in a case or issue War Room, or in the non-production Playground, against enabled integration instances. Integration Command Permissions Restricts which roles may run each command at the integration instance level, so the same command can carry different permissions in different instances of the same integration. Integration Instance Management Configures one or more instances of an integration delivered by a content pack, then edits, copies, tests, enables, disables or deletes them and refreshes their log data from the Data Sources and Integrations page. Lists Stores reusable values as named lists, including JSON lists, readable and writable from playbooks and commands with per-role read and edit access, and duplicated or detached when they come from a content pack. Marketplace Content Packs Downloads, installs, updates, reverts and deletes content packs from a central Marketplace, resolving dependencies between objects, distinguishing vendor, partner, developer and community support tiers, and auto-upgrading core packs on version upgrade. Playbook & Script Access Control Governs automation logic at object level with per-playbook and per-script access roles, so sensitive remediation workflows are visible and editable only to authorized users while automated executions still run as the system. Playbooks Automates response workflows on a visual canvas built from standard, conditional, manual, communication, section-header and sub-playbook tasks with loops, inputs and outputs, error handling and a Task Library, sourced from a catalog or authored from scratch and testable before use. Scripts Authors and runs JavaScript, Python and PowerShell scripts that call the full API surface, act on issues and investigations and share data with the War Room, governed by per-role permissions. Threat Intelligence in Automation Exposes threat intelligence to automation through built-in playbook commands and a threat intelligence agent that reads from and writes to the intelligence dataset, automating triage, enrichment and response.
Developer & API Platform Application Security APIs Manages application security from code — applications and their asset membership, repositories and branch scan configuration, rules, policies and criteria, data sources, scans and findings, package details, fix suggestions and fix pull requests. Broker VM APIs Manages Broker VMs over two surfaces — a tenant-side API for inventory, editing, registration tokens, reboot, shutdown, upgrade, applet configuration and asynchronous log bundles, and an on-appliance API for first-boot password reset, bearer token, network and certificate configuration and a synchronous log stream. Cases & Issues APIs Searches and updates cases and issues programmatically, retrieves their artifacts and schema, reads and appends War Room entries, and reads or adds case timeline records. Cloud Onboarding APIs Onboards cloud service providers from code — creating a pending instance with a downloadable authentication template, listing available regions and approved tenants, and editing, enabling, disabling or deleting instances, accounts and outposts. Cloud Security APIs Reaches the cloud security modules programmatically — cloud workload protection policies, container registry connectors, software bill of materials reports, entitlement access queries and least-privilege recommendations, and the data security posture inventory. Compliance APIs Administers compliance standards, categories, controls and rules including bulk operations, runs and reads assessment profiles and their results, retrieves per-asset compliance findings and reports, and exports or imports standards as an asynchronous archive job. Cortex CLI Provides one command-line tool that scans cloud workload, API security and application security environments from a single installation, so checks can run inside a development pipeline. Detection & Intelligence APIs Creates and maintains detection content programmatically across BIOC, IOC, correlation, indicator and unified rules, security policies and alert notification rules, including enabling, disabling and deleting each. Endpoint & Response APIs Manages endpoints and agent configuration settings, runs response actions and scripts on them, retrieves forensic data, restores distributions and administers disable-prevention and disable-injection rules from code. Identity & Access APIs Manages users, roles, scopes, user groups, API keys and authentication settings from code, and reads the tenant audit log. Managed Services APIs Lets a managed service provider assign work, post comments, read status and retrieve managed service reports programmatically. Platform Service APIs Administers supporting platform services from code, covering the logging and collection service and the external applications registered against the tenant. Public API Surface Exposes the tenant over versioned REST APIs reached at a per-tenant FQDN and authenticated with an API key and key ID, sharing one response envelope plus common filtering, sorting and pagination conventions, and documented with per-release API notes. Search & Reporting APIs Runs XQL queries and retrieves their results, manages the query library and scheduled queries, and administers datasets, lookup datasets, dashboards, widgets, scripts, playbooks and syslog server configuration. Vulnerability APIs Retrieves vulnerabilities, findings and point-in-time findings snapshots, reads vulnerability intelligence and affected software, manages vulnerability policies, triggers an on-demand scan of a named asset, submits results from a customer-supplied scanner, and drives network vulnerability scans.
Query & Reporting Command Centers Ships pre-configured command center dashboards for cloud posture, cloud detection and response, cloud security operations, data ingestion, email security and exposure management, each with interactive drilldown into filtered views. Dashboard & Report Import/Export Exports and imports dashboards and report templates as JSON files, singly or in bulk, so configurations can be shared, backed up or migrated between environments. Dashboard & Report Sharing Keeps new dashboards, reports and widgets restricted to their owner until shared with named users or groups or made public, with administrator-only ownership transfer and access governed by role and scope controls. Dashboard Filters & Drilldowns Adds up to four global filters over parameterized widgets on a dashboard, and configures per-widget drilldowns that pass variables through to a linked page or a contextual change. Dashboards Monitors the environment through system dashboards that cannot be edited but can be duplicated, plus custom dashboards built from a blank canvas or a template, all organized in a dashboard manager with a trash folder that allows recovery. Graph Search Searches assets and findings by the relationships between them and draws the result as an interactive node-and-edge graph, built in the query interface with a library of saved, shared and built-in graph queries over a published set of supported assets and findings. Log & Notification Forwarding Forwards cases, issues and logs out of the tenant to email, a chat workspace, a syslog receiver, cloud object storage, a message queue, a SIEM or a webhook, through per-destination external application configuration, gateway egress setup and forwarding rules that select the data and log types. Query Builder Builds structured investigative queries without writing XQL across network connection, file, process, registry, image load, authentication and event log entity types, including exception values per field. Query Center Lists every query run on the tenant and those in progress, letting analysts view and re-run results, adjust and cancel queries, schedule them, and keep a personal query library. Query Management Controls Lets administrators set limits and restrictions on queries running against the tenant from a query management settings page gated by its own permission. Reports Captures a static snapshot of metrics and analytics as a downloadable file from a dashboard or a purpose-built template, generated once or on a schedule and distributed to user groups and mailing lists, with a notification rule when a run fails. Splunk Query Translation Converts an existing Splunk query into XQL syntax from a toggle in the query field, showing both forms side by side, in beta with partial coverage of the Splunk language. Threat Intelligence Dashboard Visualizes threat objects and indicators present in the environment to show data distribution and trends, usable as shipped or cloned and modified. Widgets Builds dashboard and report components in a shared widget library — XQL-query widgets with a chart editor, script-based widgets for complex logic or third-party data, and widgets generated from a natural-language prompt — with static or dynamic parameters. XQL Query Language Searches, filters and transforms collected telemetry with the Cortex Query Language across datasets and presets, returning results that can be graphed, exported or turned into detections.
Endpoint Agent Management Agent Deployment Installs agents directly or distributes packages at scale through third-party software deployment tooling, following a staged plan that moves from proof of concept to production without disrupting legitimate workflows. Agent Installation Packages Creates the signed installation packages agents register with, including a container-embedded variant built into a customer image and a serverless function package for cloud runtimes. Agent Lifecycle Actions Performs remote agent maintenance from the console — restarting an agent, clearing its local database, uninstalling in bulk, deleting endpoints from tenant views with an inactivity-based automatic sweep, and moving agents between managing tenants. Agent Operational Monitoring Shows whether each agent is protecting according to its assigned policy, tracks upgrade status per endpoint, and records agent-monitored events as audit logs reported hourly and retained for 365 days. Agent Tokens & Passwords Issues per-agent tokens that retrieve the password protecting privileged agent functions, including temporary tokens and the password for a generated tech support file. Agent Upgrade & Content Updates Controls agent version upgrades and security content updates per endpoint or globally through agent settings profiles, with planning guidance that trades update speed against production risk. All Endpoints Management Lists every agent-managed endpoint in one table from which actions can be initiated, with one-off or periodic cleanup that collapses duplicate entries down to the most recent one. Container-Embedded Agent Embeds a purpose-built agent into a customer container image so containerized and Container-as-a-Service workloads get malware prevention, exploit protection and vulnerability scanning, with the Dockerfile generated from the console or the API. Critical Environment Agent Versions Runs selected endpoints on a critical-environment agent line intended for sensitive and highly regulated estates, which carries the same feature set and full content coverage but a more conservative fix cadence, and tracks which endpoints are on it. Endpoint Data Collection Sends a minimum set of endpoint metadata with every agent-raised issue, and when behavioural threat protection or EDR collection is enabled in policy, continuously streams endpoint activity for event-chain analysis. Endpoint Groups Defines endpoint groups that policy rules and profiles are applied to, optionally built from synchronized directory user, group and computer attributes. Endpoint Tags & Aliases Segments endpoints with tags created at install time, from the agent or from the console, and gives them aliases distinct from the hostname individually or in bulk, with unused tags removable through the API and tag removal affecting scoped permissions. iOS Push Notifications Pushes a notification from the console to the agent running on an iOS device. Restore Deleted Installation Packages Restores a previously deleted agent installation package by its distribution ID, re-enabling registration for agents that still reference it.
Agentic AI Assistant Agentic Assistant Access Control Controls per-role access to the Agentic Assistant chat and to viewing, creating, editing, deleting, enabling and disabling agents and actions. Agentic Assistant Actions Registers playbooks, scripts, commands and AI prompts as actions that agents can call inside a plan, alongside out-of-the-box system actions, and manages the registered set from the Agentic Assistant Hub. Agentic Assistant Agents Builds and manages AI agents in the Agentic Assistant Hub that plan and execute sequences of assigned actions on a user's request, each with its own model, user and conversation context, and a permission ceiling no higher than its creator's. Agentic Assistant Chat Runs natural-language conversations with a chosen system, public or custom agent that plans and executes actions, showing the plan and each action as it runs, keeping multiple concurrent chats and organizing chat history by period. Agentic Assistant in Slack Lets analysts interact with Agentic Assistant agents from a chat workspace by tagging a configured bot in a thread, choosing an agent from a menu and continuing the session there. AI Prompts Adds single-step LLM reasoning tasks to playbooks and investigations that summarize logs, normalize data or classify content from issue context, using built-in or user-authored prompts governed by role-based access. AI-Generated Case Summaries Generates a human-readable case title and description from the underlying issues and artifacts using LLM summarization, so an analyst gets the scope of a case without reading it first. Automation Engineer Agent Generates, queries, iterates and refines Python automation scripts and response playbooks conversationally through the Agentic Assistant, using the automation SDK and security best practices. Cortex MCP Server Exposes the tenant to external LLM applications through a downloadable MCP server, run in Docker or a Poetry environment, with built-in tools for managing cases and issues and running investigations, plus a CLI and self-updating tool set. Custom MCP Server Tools Builds additional MCP server tools from OpenAPI definitions or Python code on top of Cortex API endpoints. Knowledge Center Sources Grounds agent responses in organization-specific material by adding uploaded files and links as knowledge sources in the Knowledge Center, and shows which source informed a result. Natural-Language Query & Visualization Translates natural-language prompts into XQL through a built-in text-to-query action, runs the query against permitted datasets and renders results as any supported chart type. Third-Party MCP Integrations for Agents Connects Agentic Assistant agents to external MCP servers over streamable HTTP with OAuth or authless configuration, exposing the server's tools as MCP tool actions the agent can call.
Attack surface management — Expander discovers, attributes and monitors an organisation's internet-facing assets and raises incidents on the risky ones.
Access & Tenant Administration Dataset Management & Retention Reports every dataset with its type, update mode and last update, and the storage duration each carries under the tenant's hot and cold storage licences and retention add-ons, enforcing retention on log-type datasets and role-based access on dataset queries. Licensing & Add-On Modules Sells the Expander base platform sized by network, with Active Response and Attack Surface Testing as separately licensed add-on modules, and exposes the licence state and a self-service 60-day Active Response trial in the tenant. List View Controls Gives every table the same controls — a multi-field filter builder with persistent state, per-column filters, pivot-based show and hide, free-text search across alert and incident fields, column and row layout management, saved and shared filters, and TSV export. Management Audit Logs Records every administrative interaction with the tenant for 365 days with the acting user, object, type, subtype, result, severity and timestamp, filterable with saved filters, exportable to file and forwardable to email, syslog or Slack. Role-Based Access Control Grants view or view-and-edit access per product component through predefined roles — Account Admin, Analyst, Group Manager, Instance Administrator, Privileged IT Admin, Security Engineer and Viewer — and through custom roles saved from a predefined one and edited. SAML Single Sign-On Authenticates tenant users through SAML 2.0 with documented setup for Microsoft Entra ID and Okta, supports more than one identity provider on a tenant, and falls back to Customer Support Portal credentials as the default method. Scope-Based Access Control Filters the data a user or group sees on the incidents, alerts, dashboards and inventory screens to the tags and business units they are permitted, complementing role-based control over which screens they can reach. Security Settings Restricts how and from where the tenant may be used — login session and dashboard expiration, inactivity logout, approved login domains and IP ranges, API access by IP, automatic deactivation of inactive users, and the domains allowed on report distribution lists. Server Settings Sets per-user display preferences such as keyboard shortcuts, timezone and timestamp format, the target mean time to resolution per incident severity used by dashboard widgets, and the role granted to vendor support when impersonating for a ticket. Tenant Activation Activates a tenant from the Cortex Gateway against a purchased serial number, setting its name, hosting region and subdomain, and manages the tenants allocated to a support-portal account thereafter. User & Group Management Provisions support-portal account holders into the tenant with a direct role or through user groups that carry a single role and scope, supports nested groups, groups imported from a directory, identity-provider group mapping, and bulk role import.
Asset Inventory Asset Investigation Workflows Documents filter recipes for finding the assets that matter — recently added assets, expired and self-signed certificates, and other hygiene conditions — using first-observed versus date-added and classification filters across the inventory tables. Asset Notes Attaches a free-text note of up to 1,024 characters to an individual asset from the inventory detail pane or an incident's Assets tab, exposed as a filterable and sortable inventory field. Asset Upload & Removal Adds domains and IPv4 ranges to the map, or removes domains, certificates and IPv4 ranges from it, by submitting a CSV request that is validated, reported on through an overlap analysis, tracked to accepted or rejected, and reversible through an undo action. Certificate Assets Inventories attributed certificates with issuer, subject, validity window, key and signature details, records whether each is still advertised on an active service, and runs cryptographic health checks for self-signed, wildcard, domain-validated and expired certificates. Cloud Asset Inventory Holds cloud compute instances ingested from connected cloud accounts and resources ingested from a cloud posture inventory, recording provider, account, region and cloud tags, and classifying each as managed or unmanaged against that inventory. Domain Assets Inventories attributed root domains and subdomains from active and passive DNS collection, recording the registrar and whether the domain currently resolves, collapsing wildcard and very large subdomain sets under their parent. Owned IP Inventory Inventories attributed IPv4 ranges, IPv6 addresses and the owned responsive IPs derived from them, carrying registration records, ASN handles, registries and countries, and linking each responsive IP back to its parent range. Service Assets Inventories every internet-facing service on a domain:port or IP:port pair with fingerprint-based active and inactive classifications, banner, header and response data, and a discovery type distinguishing directly discovered services from ones colocated on a shared IP. Unified Inventory Presents every attributed asset on one sortable, filterable and downloadable page spanning certificates, cloud compute instances, domains, owned responsive IPs and cloud resources, with a detail pane per asset. Website Assets Scans public-facing websites to inventory the server software, web technologies and third-party libraries behind them, identifying insecure and misconfigured sites and vulnerable dependencies distinctly from the underlying HTTP services.
Active Response Automation Active Response Playbook Starts one predefined playbook on every new alert regardless of type, progressing through enrichment, decision and remediation stages via sub-playbooks whose branch depends on the alert type, the configured integrations and analyst input, and can be restarted after an error. Analyst Input Workflow Pauses the playbook on alerts no remediation path rule covers and presents the analyst with the enriched context and a choice of manual remediation, automated remediation, a notification email or a ticket, then resumes and advances the alert status. Automated Remediation Actions Fixes qualifying exposures without human action — reconfiguring cloud security groups and networking, creating firewall block rules and triggering endpoint isolation — with a published matrix stating the remediation method and the criteria each attack surface rule must meet. Automation Integration Configuration Connects the enrichment, ticketing, messaging and remediation tools the playbook calls, either through a step-by-step configuration wizard or by installing the content pack from the marketplace and configuring the instance manually. Playbook Notification Templates Customizes the subject and body of the emails and tickets the playbook sends to service owners, both when an exposure is found and after it is automatically remediated, using alert-specific system variables and a configured ticketing project key. Remediation Confirmation Scanning Validates a resolution before closing an alert by rescanning the asset with the same payloads and global scanning infrastructure used for discovery, so a risk that is not actually fixed does not reappear on the next scheduled scan. Remediation Path Rules Binds an attack surface rule plus alert criteria to a remediation action so matching alerts are handled without prompting an analyst, with the available actions determined by the rule, the criteria and the configured automation integrations.
Attack Surface Rules, Alerts & Incidents Alert Exclusions Stops alerts matching user-defined criteria from being created or reopened, optionally applying the rule to historic alerts as well, and resolves any incident left holding only excluded alerts. Alert Status Model Tracks each alert through New, In Progress, Resolved and Reopened, distinguishing terminal resolutions such as contested asset and risk accepted from reopenable ones the system reasserts when the exposure is observed again, and supports custom statuses and resolution reasons. Alerts Raises an alert when a rule matches a service or asset, presenting a filterable table and a detail page carrying the affected service and website data, asset details, related incident owner, remediation guidance and a PDF export. Attack Surface Rules Ships over 700 vendor-managed rules defining the exposures to look for, each carrying a category, severity, description, remediation guidance and an estimated alert count, individually enabled or disabled to control which risks raise alerts. Incident Status Model Moves an incident through New, Under Investigation and Resolved, resolving it automatically once every related alert is resolved and reopening it when the asset is observed on the internet again, with custom statuses and resolution reasons available to playbooks. Incidents Groups the alerts on a single service or asset into an incident and presents it in a split-pane or table view carrying assignee, severity, risk score, tags, related assets and alerts, with starring, bulk actions and a PDF export. Threat Response Center Maintains a research-curated list of emerging global threat events and zero-day exploits, each with a threat summary, exploit consequences, affected software and versions, related CVEs, the relevant attack surface rules and their enablement state, and the organization's own affected incidents and alerts.
Attack Surface Testing Alerting on Confirmed Test Results Turns confirmed positive test results into alerts through four dedicated attack surface rules covering confirmed exploits, API security weaknesses, credential testing and misconfiguration testing, so testing findings enter the normal remediation workflow. Attack Surface Tests Runs benign exploits daily against selected internet-facing services to confirm or rule out CVEs and non-CVE risks, mapping each test to the service classifications it applies to and including unauthenticated default-credential login tests that never change a tested service. On-Demand Test Rescan Triggers an immediate rerun of the test behind an alert rather than waiting for the daily cycle, returns results within about 15 minutes, closes the alert automatically on a negative or two consecutive inconclusive results, and records the request in the audit log. Test Intrusivity Levels Classifies every test on a six-level intrusiveness scale from passive observation to full compromise, enables only levels 0 and 1 at first activation, and lets the tenant choose the highest level at which newly released tests are enabled automatically. Test Results & Evidence Surfaces confirmed vulnerable and confirmed not vulnerable identifiers as searchable fields on the services inventory, and shows per service the tests run, their dates and outcomes, a 14-day test history, the evidence payload returned and remediation guidance. Testing Target Selection Restricts testing to all directly discovered services or to a filtered subset chosen from the services inventory, gated behind an end-user licence agreement that grants permission to scan and behind the Vulnerability Testing edit permission.
Data Collection & Integrations API Key Management Issues standard and advanced API key pairs from the tenant, where the advanced key hashes the credential with a nonce and timestamp to prevent replay, and supports per-key role assignment, an optional expiration date and expiry notifications. Cloud Inventory Collection Ingests cloud compute instances directly from AWS through a CloudFormation-created cross-account role guarded by an external ID, from Microsoft Azure at subscription, tenant or management-group level, and from Google Cloud through the Cloud Asset API at project, folder or organization level. Cloud Posture Resource Ingestion Pulls a broader set of cloud resource types four times a day from a connected cloud posture inventory using a service-account access key, then classifies discovered cloud assets as managed or unmanaged against that inventory to expose shadow IT and rogue instances. Log Forwarding & Notifications Forwards alerts, management audit logs and generated reports outward through filter-based forwarding rules to a syslog receiver, a Slack channel or an email distribution list, with each destination supporting a documented subset of the three data types. Public API Exposes REST endpoints under a tenant-specific FQDN for asset management, incident and alert management, tag management, attack surface rules, remediation path rules, remediation scanning, vulnerability testing, audit logs and system management. Python SDK Provides a published Python interface to the Cortex Xpanse API so asset, incident and configuration data can be consumed from scripts without hand-writing HTTP calls.
Discovery & Attribution Asset Attribution Decides which discovered assets belong to an organization using IP registration records from the regional internet registries, ASN advertisement, advertised certificates, DNS records and customer-provided lists, combining machine learning models with analyst review. Attribution Evidence & Confidence Shows on every asset why it was attributed — the seed term matched, the specific scan data that matched it, whether the asset was discovered or provided, and when it was last seen — alongside a confidence label and attribution reason tags. GeoIP Data Collection Geolocates discovered assets so the observed global footprint can be compared with the expected one, surfacing infrastructure in restricted locations and informing where a remediation notification should be routed. Global Internet Scanning Scans IPv4 and IPv6 internet space with protocol-specific payloads to find responsive services, covering roughly 250 common ports twice weekly, the remaining 65,000 ports at a low background rate, and all responsive services daily, and publishes the scanner source ranges for allow-listing. Known Assets Monitoring Adds opt-in targeted scanning of customer-attributed assets — roughly 300 ports daily and 2,800 weekly — extending coverage to port and protocol pairs outside the global scan, SMB version enumeration and TLS cipher suite and protocol determination. Seed Data & Enhanced Production Map Widens the initial core production map into an enhanced map covering subsidiaries, acquisitions and business units, built from customer-supplied alternate naming conventions, governance structure and master IP and domain lists.
Remote Engines Engine Configuration Configures an engine through its local configuration file or a JSON override in the tenant, covering listening port, worker count, log level, custom certificate authorities, an outbound web proxy with a no-proxy exception list, and a reverse proxy in front of the engine. Engine Container Runtime Runs each integration and script inside a per-content container image pulled from the vendor image repository or container registry, on Docker or on rootless Podman selected automatically by the shell installer, with images downloadable for offline installation. Engine Installation Installs one or more engines inside a customer network from RPM, DEB, shell or ZIP packages on supported Linux distributions and on Windows configured for Linux containers, against published CPU, memory, storage and outbound URL requirements. Engine Load-Balancing Groups Groups engines so command execution is distributed across them, letting separate groups isolate critical integrations, internal versus hosted infrastructure, or unconnected cloud accounts, and removing a grouped engine from individual selection. Engine Management & Upgrade Lists every engine with its host, version, status and connection state, and supports downloading engine logs, upgrading shell-installed engines in place, moving an engine between load-balancing groups, and deleting an engine. Run Integrations & Scripts on an Engine Binds an integration instance or an automation script to a specific engine or load-balancing group so its commands execute inside the customer network, and allows an ad-hoc command to select the engine at run time.
Asset Organization & Scoping Asset Tagging Applies user-defined asset and IP range tags and system-applied attribution reason tags to assets, propagates them to the related services, websites, alerts and incidents, and uses them for filtering and for scope-based access control. Bulk Business Unit Import Updates business unit assignments for up to 50 domains or IP ranges in one CSV upload with append or replace semantics, validating each row before execution and returning a per-row success or failure report so only failed rows need retrying. Business Unit Management Assigns assets to a hierarchy of business units during mapping, lets users override the assignment per asset or domain subtree with a recorded change reason, propagates the assignment to services, websites, alerts and incidents, and uses it to scope user access. Inventory Tag Rules Applies rules-based tags automatically to assets matching filter criteria, including assets attributed later, for IPv4 addresses and ranges, certificates, domains and ingested cloud resources. User-Defined IP Ranges Carves a subset range or a single address out of a system-defined IPv4 range so it can carry its own business units, splitting the parent range accordingly, resolving conflicts with previously defined ranges, and reverting to the parent on deletion.
Dashboards & Reporting Compliance Violations Dashboard Maps attack surface rules to the NIST 800-53, NIST 800-171 and CMMC control families so exposures can be read as compliance impact, and publishes the controls in each framework that an external-only view cannot evaluate. Custom Dashboards Builds dashboards from a blank canvas or a built-in template by dragging widgets into place, previewing against mock or real data, then saving them as private or shared, setting one as the default, and duplicating, disabling or deleting them from the dashboards manager. Predefined Dashboards Ships ready-made dashboards covering overall attack surface trend, attack surface management, incident management, unmanaged cloud, websites and compliance violations, filterable by tag, business unit and time range. Reports Generates PDF reports from predefined or custom widget-based templates, or from a saved dashboard, over a chosen data timeframe, on demand or on a schedule, distributed by email or to a Slack workspace with optional password protection and CSV attachments of query widgets. Widget Library & XQL Widgets Holds every predefined and custom widget available to dashboards and reports, including widgets built on Cortex Query Language queries that return arbitrary data in a chosen graphical format such as table, line graph or pie chart.
Risk Prioritization Custom Risk Scoring Adjusts prioritization to local requirements by adding or subtracting points through user-defined scoring rules matched against alert attributes, by disabling the vendor score entirely, or by pinning a manual score that overrides both and stops recalculation. Inferred CVE Matching Infers the CVEs affecting a service by matching the product name and version observed in scan data against the National Vulnerability Database, labelling each match high or medium confidence according to how precisely the versions align. Risk Factors Classifies each alert against a fixed set of qualitative risk dimensions — critical systems, end-of-life software, exposed logins, IoT devices, misconfiguration-prone products and others — which feed the incident risk score and are shown on the incident Risk tab. Security Rating Reports a daily 0-100 rating of external attack surface hygiene as a weighted average of incident risk scores across all high and medium severity rules at their default severity, comparable across industry peers, business units and cloud providers. Xpanse Risk Score Scores every incident from the EPSS and CVSS of the CVEs inferred on the related service or website, whether those CVEs are weaponized or exploited in the wild and how recently, the risk factors present, and confirmed attack surface test results, recalculating as alerts and risks change.
The SOC platform that unifies detection, investigation, response, endpoint security and cloud security on one data layer, with XQL as its query language and its own analytics and automation engines.
Cloud Security API Specification Inventory Imports OpenAPI-format specification files and extracts them from scanned cloud API gateways, then scans the specifications for misconfigurations and compares live traffic against them to surface undocumented endpoints and deviations. Application Security Contributor Billing Counts the unique non-bot human committers to billable scanned repositories over the last ninety days, which is the basis on which application security is charged. Application Security Fix Suggestions Returns a remediation suggestion for an application security issue, optionally including the original code block, written instructions and a proposed code fix the developer can apply. Base Image Rules Designates registry images as approved base images and links derived images to them, creating a bidirectional lineage relation so a vulnerability can be traced to its base image and every dependent image identified. Cloud AI Security Inventories AI models, agents, data flows and supporting infrastructure across cloud accounts, maps their supply-chain dependencies into an AI bill of materials, and raises prioritized risk findings on misconfigurations and unsanctioned models. Cloud Application Security Secures applications across their lifecycle through application security posture management over connected repositories and pipelines, CI/CD supply chain security, and code scanning for exposed secrets, infrastructure-as-code misconfigurations and open-source component risk, with scan coverage tracked per repository. Cloud Data Classification Classifies discovered data objects using hundreds of built-in and custom data patterns grouped into data profiles such as PII, PHI, PCI, financial and developer secrets, and assigns unstructured documents a business topic that maps to a profile. Cloud Identity Security Inventories human, non-human, group and policy identities across cloud providers, identity providers and SaaS, calculates effective permissions, reviews unused permissions from audit logs and generates rightsized IAM policies for download. Cloud Security Policies Binds cloud security rules to an asset scope so matching findings are promoted to issues, with a default out-of-the-box posture policy and user-created policies that can be cloned, enabled, disabled or deleted. Cloud Security Rules Evaluates cloud, code and host assets against detection conditions or XQL queries to raise findings, using out-of-the-box rule content plus custom rules across configuration, graph, data, network exposure, identity, AI and attack-path rule types. Cloud Workload Policies and Rules Detects workload misconfigurations and blocks them at CI or runtime, combining predefined rules, trusted-image policies, and custom Rego or Python rules that run on the agentless disk scanner, the Kubernetes connector or the agent. Code-to-Cloud Lineage Traces the link between source repositories and the cloud assets built or deployed from them in both directions, for container artifacts and infrastructure-as-code resources, and reports the share of assets with traceable lineage. Compliance Assessments Runs a chosen compliance standard against selected asset groups on a recurring schedule through assessment profiles, producing per-control pass and fail results and a compliance score for the scope. Compliance Reporting Presents compliance assessment results in an overview dashboard and a reports table, and exports individual reports to PDF or CSV or emails them to named recipients on a configured cadence. Compliance Standards and Controls Provides a catalog of built-in regulatory and benchmark standards and their controls, and lets users create custom standards and controls and associate them with custom cloud security rules. Container Registry Scanning Discovers repositories and tags in connected container registries and scans stored images on a recurring interval for vulnerabilities, malware, exposed secrets and policy violations, covering managed cloud registries and self-hosted Docker V2-compliant registries reached through a Broker VM applet. Cortex Data Security Discovers, protects and governs sensitive data across managed cloud storage, self-managed databases, SaaS and on-premises locations, with per-account scanning scope and cadence settings for managed and self-managed assets. Network Exposure Detection Builds a network topology of cloud accounts with the Cloud Network Analyzer and identifies inbound internet exposure, unrestricted outbound access and east-west lateral reachability, showing the path and the controls along it, with a trusted IP list. SaaS AI Agent Security Inventories AI agents deployed in enterprise SaaS platforms along with the tools they wrap, and flags authentication misconfigurations, inherited excessive privileges and prompt-injection exposure in their system prompts, tools and workflows. SaaS Security Posture Scans connected SaaS application tenants against out-of-the-box detection rules, scores each provider instance, and lists prioritized posture issues with remediation guidance and evidence of the settings that caused them. SBOM Management Produces a software bill of materials for a scanned repository in the common interchange formats and versions, and exposes per-package version detail through a package explorer. Serverless Function Posture Security Scans serverless functions agentlessly on a schedule or on change for vulnerabilities, malware and exposed secrets, and applies posture policies and rules including configuration, network exposure and attack path rules scoped to functions. Serverless Function Runtime Security Embeds the agent into serverless function code to monitor process, network and filesystem activity at execution time and enforce a profile that permits or denies those actions, logging violations as issues. Unified Human Identities Correlates a person's separate accounts across on-premises directories, identity providers, cloud platforms and SaaS applications into a single identity asset keyed on email, so access and risk are assessed per human rather than per account. Unified Rules Links a cloud security rule that detects a misconfiguration at runtime with the infrastructure-as-code rule that detects the same misconfiguration before deployment, and manages the pair as one object so the control holds from code to runtime. Web and API Security Discovers APIs from gateway logs and mirrored traffic, assesses each endpoint for internet exposure, sensitive data, weak authentication and specification drift, and detects injection, exploit, authentication-bypass and bot activity against them. Web and API Security Profiles Applies agent-based detection and prevention profiles to Linux workloads running web applications and APIs, attached through workload policies, with disable-prevention, support and legacy exception rules to narrow enforcement.
Investigation & Response Action Center Tracks every investigation, response and maintenance action taken on protected endpoints in one place, with filtered views per action type including quarantine, block and allow lists, and an aggregated-by-hash view. AI Case Resolution Summarizes a case in natural language and proposes a resolution from the evidence gathered, so an analyst reviews and confirms rather than assembling the narrative themselves. Artifact Enrichment Integrations Verifies the key artifacts in a case against external threat intelligence and reputation services, adding each service's verdict as an additional source alongside the platform's own. Case and Issue Fields and Layouts Extends cases and issues with custom fields of typed and grid form, arranges them into custom layouts and widgets, applies layout rules that pick a layout per record, and runs scripts triggered when a field changes. Case and Issue SLAs Applies time-based resolution goals to matching cases and issues through SLA rules, tracks elapsed time in resolution and custom timer fields, and lets playbooks, scripts and CLI commands start, pause and update those timers. Case Grouping Groups related issues into a single case using machine-learning models over shared artifacts and context, with correlation rule fields mapped into the grouping artifacts so custom detections join the right case instead of fragmenting. Case Scoring Prioritizes cases and issues with a machine-learning score plus user-defined scoring rules and sub-rules that add weight when filter criteria such as issue source and severity match. Case Statuses and Domains Defines the workflow vocabulary for cases — custom statuses and resolution reasons, and case domains that separate cases by the security area they belong to. Case Teams and Access Assigns named analysts and roles to a case and restricts who else can open it, so sensitive investigations stay with the team running them. Cases Groups related issues, impacted assets and artifacts into one investigable problem, created automatically from incoming issues or manually, with severity and scope assessment, thresholds, merging, linking and a defined lifecycle through to resolution. Causality Analysis Stitches collected processes, files, network connections and audit records into causality chains continuously, regardless of whether anything alerted, and presents them as process, network, cloud audit and SaaS causality views. Email Security Remediation Removes or quarantines malicious messages across affected mailboxes from a dedicated remediation action center, driven manually or by remediation response rules that act automatically on matching detections. Endpoint Response Actions Acts on a compromised endpoint from the console — network isolation, malware scan, file retrieval, live terminal sessions, agent script execution, file quarantine and restore, execution blocking, search and destroy, and temporary protection pause. External Ticket Sync Links an issue to a ticket in an external application and keeps the two in step, using inbound and outbound sync profiles that map each system's field names and values, with default profiles supplied and custom ones creatable per integration. Forensics Runs deep forensic investigations on an endpoint as a licensed add-on, including memory image collection and artifact retrieval for post-incident analysis. Hunting Searches for a pattern across a large number of hosts at once and returns hunt collections showing where it occurred, tracked from creation through status to results. Indicator Extraction Pulls indicators such as addresses, domains, hashes and URLs out of case and issue content, run automatically inside playbook tasks or manually from the command line. Investigation Workspace Gives an investigation a shared surface — a War Room for running commands and sharing results, a Work Plan showing playbook task execution, a Resolution Center, a case timeline, and collaborative notes and comments. Issue Exceptions Records a time-bound decision to accept the risk of a confirmed issue through exception rules that pause its SLA timers for up to a year, routed through named approvers by email unless the approval workflow is turned off. Issue Exclusions Suppresses issues matching an exclusion rule so known-benign activity stops reaching the queue, managed separately from the time-bound exception rules that only pause remediation timers. Issues and Findings Records each detected problem as an issue carrying what happened, affected assets, contributing evidence and recommended actions, promoted from a finding or event, assigned to a domain and a case, and deduplicated, excluded, copied or exported as needed. Managed Threat Hunting Adds continuous hunting by the vendor's own threat researchers as a licensed service, delivering threat reports on critical incidents and impact reports assessing the organization's exposure to emerging threats. Starred Issues Flags issues and their linked cases automatically when they match configured attribute criteria such as severity, category or affected asset, so analysts can filter to the set an organization considers priority. Triage Collects a defined evidence set from an endpoint into a triage package for review, online or uploaded from an offline collection, and tracks each triage through its status to results.
Platform Administration Bring Your Own Keys Lets the customer import and manage the encryption keys protecting their tenant data through the central gateway, replacing the default provider-managed encryption. Child Tenant Managed Actions Creates configurations in the parent tenant and applies them on a child tenant's behalf across issue exceptions and exclusions, starring configurations, endpoint prevention profiles and allow and block lists, cloning created profiles downward. Cloud Consumption Tracking Tracks protected cloud workload consumption across every connected account and provider, normalizing different resource kinds into one unit and reporting entitlement, consumption over time and per-account detail. Console Interface Presents every product area behind one navigation menu with table filtering, saved filter views, table data export and in-product help, showing only the menu items the tenant's license covers. Dynamic License Allocation Moves endpoint, employee and volume entitlements between child tenants from the central gateway, adding and deleting tenants and returning a deleted tenant's allocation to the shared pool for immediate reuse. Engine Configuration Configures how an engine reaches the tenant and runs content — web proxy or direct connection, custom certificates, a reverse proxy in front of it, and a container runtime with hardening settings for image security, resource limits and non-root execution. Engines Runs playbooks, scripts, commands and integrations on a proxy server installed in a remote network and returns the results to the tenant, with several engines per machine supported and the engine always initiating the outbound connection. Government Cloud Tenants Offers FedRAMP High and Moderate authorized tenants for US federal use, physically and logically isolated from commercial tenants, hosted on government cloud infrastructure with all data held in the United States and federal egress endpoints. In-Product Support Tickets Raises a vendor support ticket from inside the console, carrying tenant context with it rather than requiring a separate portal visit. Integration Command Permissions Restricts which roles may execute a given integration's commands, applying to manual runs, playbook tasks and agent actions alike. Integration Credentials Stores usernames, passwords, certificates and SSH keys as named credentials that integration instances and scripts reference instead of holding secrets inline, reusable across instances and gated by their own permission. License Tiers and Add-Ons Sells the platform in analytics, endpoint and full-suite tiers extended by purchasable add-ons, with entitlement allocation, expiry handling and in-place upgrade between tiers. Managed Services Configuration Governs what the vendor's managed services team may do inside the tenant through an actions permissions matrix, and holds the report distribution list and the ordered escalation contacts they use during an incident. Management Audit Log Records every administrative and investigative action taken in the tenant for a year, filterable and with selectable fields, and forwardable to email, syslog or a messaging channel. Multi-Tenant Management Runs a main account over many child tenants that keep their data fully separated, created and configured centrally with their own add-ons, endpoint and volume allocations, while alerts across all children remain searchable from the main account. Notification Forwarding Sends selected logs, cases and issues out of the tenant to an email distribution list, a messaging channel, a syslog receiver or a webhook, and cases and issues to external storage and analytics destinations once egress is configured, governed by per-destination notification rules. Regions and Data Residency Places a tenant in one of the published hosting regions across the Americas, Europe and Asia-Pacific, determining where its data is stored and processed. Remote Repository Content Management Versions tenant content in a remote repository so it can be developed and tested on a development tenant then pushed and pulled to production tenants, using a built-in repository, a private Git repository or an on-premises one. Scope-Based Access Control Narrows what a user sees within their role to nominated asset groups, endpoints and case domains, applied in restrictive or permissive mode and off by default until scopes are assigned. Security and Server Settings Controls session length and which domains and address ranges may log in, alongside per-tenant presentation settings for timezone, timestamp format, keyboard shortcuts and custom branding on outbound task emails. SSO Authentication Authenticates console users against the organization's own identity provider over SAML 2.0 so corporate multi-factor, conditional access and de-provisioning rules apply, with support-portal authentication as the alternative. Tenant Activation and Onboarding Walks a new tenant from activation through network parameter configuration and firewall allow-listing of the published ingress, egress and engine addresses, guided by onboarding and post-deployment checklists and health checks. User Roles and Access Management Grants access through predefined and custom roles assigned to users, user groups and API keys, built from per-component permissions covering every product area, with per-object permissions on dashboards, report templates, saved queries, playbooks, scripts and datasets.
Data Ingestion & Connectors Broker VM Bridges the customer network and the tenant as a hardened virtual appliance that hosts collection and service applets, deployable on VMware ESXi, KVM, Hyper-V, Nutanix and the major public clouds, and updated automatically from the tenant. Broker VM Collector Applets Ingests on-premises data through applets activated on the Broker VM, each handling a collection mechanism rather than a vendor — syslog, NetFlow, Windows event, Kafka, CSV, FTP, database query and file-and-folder collection. Broker VM High Availability Clusters several Broker VMs so collection survives the loss of one, with members added and removed from the cluster, applets added at cluster level, and a manual switchover of the primary node. Broker VM Operations Operates deployed brokers from the tenant — upgrades, independent applet updates, configuration import and export, a live terminal, log collection, cache storage resizing, activity and notification monitoring and an external metrics endpoint. Broker VM Proxy Routes agent and collector traffic to the management server through the Broker VM for endpoints with no direct internet access, passing the encrypted session through without decrypting it and masking the originating addresses. Cloud Audit Log Collection Streams cloud provider audit logs into the tenant, supporting vendor-managed collection, landing-zone deployments and customer-owned buckets, including the cross-account key grants those require. Cloud Scanning Outposts Runs cloud scanning inside the customer's own cloud tenant instead of the vendor's, as standard outposts or outposts built on a customer-supplied application registration, for data residency or architectural constraints that rule out cloud scan mode. Cloud Service Provider Onboarding Onboards cloud accounts, subscriptions, projects and organizations by deploying a provider-native template that creates a read-only role, then selecting which security capabilities to enable per account and re-running discovery on demand. Data Ingestion Health Monitoring Records ingestion volume, size and rate metrics per data source in five-minute aggregations and raises health issues for ingestion, collection, correlation and automation failures, with correlation rules and freshness measures for custom thresholds. Data Platform Posture Connectors Connects non-CSP data and productivity platforms for posture and data-security coverage through dedicated onboarding flows, covering platforms such as Snowflake, Databricks and Microsoft 365. Data Source and Connector Catalog Presents every available ingestion point in one catalog, spanning unified vendor connectors, standard per-stream data sources, cloud provider onboarding wizards, generic on-premises collectors and marketplace integrations. Data Source Onboarder Walks a new data source through installation in one flow, creating the integration instance and installing the recommended playbooks, scripts and other content, with defaults the user can override and a summary of everything configured. Event Classification and Mapping Assigns incoming integration events to issue types with a classifier and maps their raw fields onto system and custom issue fields with a mapper, sourcing the field schema from an instance, the integration schema or an uploaded JSON sample. External Alert Ingestion Accepts alerts from any external source as CEF or LEEF over the syslog collector or pre-parsed through the alert APIs, maps their timestamp, severity, name and optional fields onto the platform schema, and stitches them into cases and causality views. Integration Instances Configures a downloaded integration into one or more running instances with their own parameters, a connection test, and a choice of always-on or on-demand execution, then enables, disables, edits, refreshes or deletes them. Kubernetes Connector Deploys a connector into Kubernetes clusters to inventory clusters and inspect namespaces, deployments, replica sets, environment variables and other resources, and manages the deployed connectors from a connectivity management page. Log Type Filtering Selects which log types are ingested per source instance rather than all or nothing, from a list that updates as new types appear, so tenants can drop low-value telemetry and control ingestion volume. On-Premises Scanning Applets Extends cloud data and code security to on-premises infrastructure through applets installed on the Broker VM, covering SMB and NFS file shares, self-hosted PostgreSQL and MySQL databases, and self-hosted version control systems. Vendor Connectors Configures all of a vendor's supported capabilities — log collection, automation and remediation, posture — from a single guided wizard, with sub-capabilities enabled individually or together and authentication drawn from the credential vault. XDR Collector Collects logs and events from Windows and Linux machines through software installed on them, forwarding Windows event logs, files, database records and other on-premises sources into the tenant, and writing its own datasets and audit logs. XDR Collector Deployment Management Manages the collector estate through installation packages for Windows and Linux, machine groups and aliases, an application proxy, scheduled and manual upgrades, content updates and uninstall. XDR Collector Profiles and Policies Defines per-operating-system profiles listing which inputs a collector gathers, then binds them to policies that target named collector machines or machine groups, falling back to a default profile where none is mapped.
Exposure & Asset Management Asset Groups Collects assets into static groups or dynamic groups defined by attribute filters, so they can be acted on in bulk, scoped in policies and used to define per-user access scopes. Asset Risk Scores Assigns users and hosts an aggregate risk score summed from the cases and issues they appear in, drawing on authentication and directory data, and surfaces it in a per-entity risk view. Asset Roles Tags assets and user accounts with roles that downstream detection, scoping and prioritization read, assigned from the inventory configuration page. Attack Surface Management Builds and maintains an inventory of the organization's internet-facing assets from continuous global internet scanning and open-source intelligence, with tiered discovery cadences and network mapping across on-premises and cloud estates. Attack Surface Rules Matches vendor-maintained rules against global scan results to raise findings and issues for exposed or misconfigured customer-owned assets, grouped into alert categories and individually enabled or disabled. Attack Surface Testing Runs daily controlled exploits against externally facing assets, with the customer's approval, to confirm or rule out an inferred vulnerability, raising issues only where a test comes back positive. CVSS Score Recasting Overrides the published score and severity of a vulnerability for this organization so downstream prioritization and policies use the recast value. Digital Risk Protection Detects brand-impersonating domains registered against the organization and credentials leaked outside it, and drives mitigation of both from the asset inventory. Discovery Engine Populates the asset inventory from onboarded cloud accounts with full API-driven scans every twelve hours, on-demand scans, and event-assisted ingestion that re-scans a single resource when audit logs show it changed. Exposure Management Consolidates exposures from the platform's own sensors and third-party scanners into one normalized, deduplicated view, prioritizes them, and groups them into fix-oriented cases so one remediation closes many findings. External Surface Attribution Explains why each internet-facing asset is attributed to the organization, recording whether it was discovered or provided, whether it is registered to the organization or carries its content, and the seed term and scan data that matched. Externally Inferred CVEs Infers vulnerabilities on external services by matching the detected product and version against public vulnerability data, raising issues for high-confidence matches and findings for partial ones. Global Lookup Queries the vendor's global internet scan data for any address, domain or certificate hash, not only the customer's own, returning registration, geolocation, ASN, observed services and passive DNS across a six-month window. Host Inventory and Vulnerability Assessment Builds an inventory of the applications, services, drivers, users and other host detail the agent observes on each endpoint, and assesses the installed software against known vulnerabilities. Network Discovery and Scanning Scans defined IP ranges from a Broker VM applet to find responsive hosts, unmanaged devices, services and vulnerabilities across on-premises and cloud networks, with unauthenticated and credentialed scan modes, feeding results into the asset and vulnerability views. Security Controls Records which security mechanisms are deployed in the environment and how effective each is against a given finding, so risk is reported as residual after existing defenses rather than inherent. Third-Party Asset and Vulnerability Ingestion Pulls assets and CVE findings from third-party scanners through built-in integrations, and accepts them from any other scanner through an asynchronous import API that validates each submission and reports accepted counts, landing both as generic device assets and per-vendor raw datasets. Unified Asset Inventory Holds every discovered asset in one inventory with typed detail cards per asset kind — device, domain, certificate, website, API, service, VM image, and code and supply chain — and records each cloud asset's full organization, folder and account path for filtering, grouping and scoping. Vulnerability Intelligence Feeds detection with continuously updated vulnerability data from public databases, vendor feeds, commercial providers and the vendor's own research, carrying metadata, affected packages and versions, and exploit availability and maturity. Vulnerability Management Consolidates vulnerability findings across endpoints, cloud workloads, containers and external surface into one workflow for investigation and remediation, tracking each from detection through fix. Vulnerability Policies Decides which vulnerability findings become issues and at what severity, using predefined policies keyed on scoring systems and confirmed test results plus custom policies keyed on asset groups and organizational criteria. Vulnerability Risk Score Scores each vulnerability finding from 0 to 100 daily by combining asset context, exploitability and vulnerability intelligence, and shows the contributing risk factors on the issue.
Endpoint Security Agent Content Updates Distributes detection content and agent updates to the endpoint estate on a managed cadence, with configurable rollout guidelines for keeping agents and their content current. Agent Deployment Creates named agent installation packages per platform, pushes and monitors upgrades across thousands of endpoints, pins a critical-environment version where upgrades must be held, enforces a global uninstall password, restores deleted packages so their agents can register again, and moves or deletes registered agents. Agent Operational Status Reports per endpoint whether the agent is protecting as configured, partially protected, unprotected or constrained by local resources, so misconfiguration and technical failures surface without inspecting the endpoint. Agent Settings Profiles Controls the agent's own behaviour per operating system and endpoint target — resource use, connectivity, user-facing behaviour and agent tokens — alongside global agent configurations that apply to every endpoint. Cloud File Analysis Submits unknown samples to the vendor's cloud sandbox for a verdict the agent then enforces, checking a local hash cache first and operating within per-tenant daily upload, query and sample-size limits. Container Workload Protection Extends agent-based endpoint protection to containers-as-a-service workloads and Kubernetes nodes, so the same profiles and policies cover them as cover conventional endpoints. Cortex XDR Agent Runs on managed endpoints to enforce prevention policy locally and stream activity back to the tenant, across Windows, macOS, Linux, Android and iOS, reporting its own operational state to the console. Device Control Restricts which removable media and peripheral devices may connect to a managed endpoint, enforced by the agent through a policy profile with per-device exceptions. Disk Encryption Reports which Windows and macOS endpoints are encrypted and drives the operating system's own full-disk encryption through disk encryption rules and policies applied from the console. Endpoint Data Collection Sends endpoint metadata with every agent-raised issue and, when behavioural threat protection or EDR collection is enabled in policy, continuously streams activity chains whose contents vary by platform. Endpoint DLP Stops sensitive data leaving a managed endpoint by classifying content, identifying a file's true type regardless of extension, inspecting nested archives, and enforcing data-in-motion rules across web, local and USB channels even while offline. Endpoint Exception Rules Narrows enforcement where protection breaks a legitimate application, through global policy exceptions, indicator and behavioural rule exceptions, disable-injection and prevention rules, support exceptions, and allow lists of file paths and imported hashes. Endpoint Groups and Tags Targets policy at sets of endpoints through static lists or dynamic groups matched on tag, hostname, domain, address range, installation type, agent version, endpoint type, user or operating system, with tags applied at install time or afterwards. Endpoint Profiles and Policies Packages protection settings into reusable per-platform profiles — malware prevention, exploit prevention, restrictions and exceptions — attaches them to policy rules, and maps those rules to endpoints or groups, with default profiles supplied for immediate protection. Exploit Protection Interrupts exploitation of software vulnerabilities with endpoint protection modules targeting distinct stages of the exploit chain, including reconnaissance, memory corruption, code execution and kernel protection, scoped to a list of protected processes. File Integrity Monitoring Raises an event whenever a watched file or folder is created or modified on a workstation or server, using the same agent already installed for detection and response. Host Firewall Applies inbound and outbound network rules on Windows and macOS endpoints from a centrally managed profile, so connectivity is controlled at the host rather than only at the network edge. Malware Protection Blocks known and unknown malicious files on the endpoint through layered controls that vary by operating system, covering ransomware behaviour, credential theft, web shells and script-based attacks alongside file verdicts. Mobile Endpoint Protection Protects Android and iOS devices through agent apps installed from the public app stores or pushed by an endpoint management system, with notifications sent to an iOS device from the console.
Detection & Analytics Active Directory Posture Management Scans on-premises directory infrastructure against known misconfiguration patterns and weak or compromised passwords, discovers human, non-human, group and policy identities, and issues posture detections with remediation guidance. Advanced Email Security Connects to cloud-hosted mailboxes through an API rather than the mail flow, ingests message and identity telemetry, detects email-borne threats with its own analytics rules, and inventories mailboxes and malicious messages found. AI Detection and Response Gives visibility into AI service usage in the cloud and detects AI-specific threats such as model tampering and prompt injection, fed by prompt logs collected from the supported cloud AI services. Analytics Engine Builds behavioural baselines for the users and endpoints it identifies from streaming network, endpoint and directory data, and raises analytics issues when activity deviates, with configurable detection time intervals and per-source sensors. BIOC Rules Detects behaviours rather than known artifacts by matching process, registry, file and network activity, using vendor-delivered global rules that can be disabled or excepted plus customer-authored rules, evaluated against historical and incoming data. Conditional Access Policy Evaluates live authentication requests against user context, risk level and protocol data on domain controllers and allows, blocks or forces a multi-factor challenge through the configured identity and MFA providers. Correlation Rules Generates issues from XQL-based scheduled rules that correlate events across multiple sources within a defined time window, running every few minutes up to a custom cadence, with field replacement syntax, run monitoring and error troubleshooting. Extended Threat Intelligence Adds a curated intelligence library and its indicators to the tenant, with rules that act on them, an agent that answers intelligence questions, and access to them from playbooks and XQL queries. Honey User Decoy Accounts Marks nominated accounts as decoys with no legitimate purpose, so the identity threat detection content raises an alert on any activity involving them. Identity Analytics Aggregates a user's profile, group and organizational-unit membership, logins, hosts, alerts and process executions alongside user-based analytics issues, so a detection is read against that user's normal behaviour. Identity Threat Detection and Response Detects identity-based attacks through behaviour-based rules over directory and authentication telemetry, with a user risk view, a risk exposure dashboard, automated asset-role classification, and real-time analysis of directory query traffic, now including a CyberArk Identity Security Platform integration that collects audit events for the analytics detectors. Indicator Customization Defines custom indicator types and fields with their own layouts, classification and mapping from incoming feeds, field-trigger and enhancement scripts, and indicator type profiles. Indicator Export Publishes selected indicators as an external dynamic list endpoint that enforcement points fetch, so blocking decisions made in the platform reach devices that cannot query it directly. IOC Rules Raises issues when known-malicious file paths, file names, domains, destination addresses or hashes appear in collected endpoint and network data, loaded in bulk from intelligence sources or defined individually, matched retroactively and going forward. MITRE ATT&CK Coverage Maps issues and detection content to attack tactics and techniques and reports which parts of the framework the tenant's enabled detections cover. Threat Intel Management Holds the tenant's indicator repository and manages each indicator through its lifecycle — extraction, enrichment, reputation scoring and verdict, relationships to other indicators, exclusion from enrichment, expiry and deletion. Threat Intelligence Feeds Populates the indicator repository from configured third-party intelligence feed integrations alongside the vendor's own intelligence, on a per-feed schedule.
Query, Dashboards & Reporting Command Centers Ships read-only cross-domain landing dashboards for the whole tenant and for individual modules, combining asset visibility, risk levels and active threats without the user assembling widgets. Dashboard and Report Sharing Controls who can see and edit each dashboard and report template through visibility settings and role- and scope-based access, transfers ownership, imports and exports definitions between tenants, and restores deleted content. Dashboards Assembles widgets into interactive dashboards for real-time monitoring, with system-supplied and user-created boards, a dashboard manager, global filters, parameters and drilldowns from a widget into the underlying records. Graph Search Queries the relationships between assets and findings rather than flat records, over a supported set of asset and finding types, with a saved query library, worked examples and detection rules built directly on a graph query. Notebooks Provides an in-product notebook environment combining Python, XQL queries and visualizations in one shareable document, with dataset and external-dataset management and scheduled execution, for custom analytics and machine-learning models over security telemetry. Query Builder Builds queries without writing XQL through typed builders for process, file, network, network-connection, registry, authentication, image-load and event-log searches, started from supplied templates or a natural-language phrase translated to XQL. Query Center Lists the tenant's running and completed queries with their results, and lets users re-edit, re-run or cancel them. Reports Produces static snapshots for historical tracking, auditing and distribution from report templates built from scratch or duplicated, generated on a schedule with a notification rule when generation fails. Scheduled Queries Runs saved queries on a recurring schedule, with the frequency editable and each execution's history viewable, and the schedule disabled or removed when no longer needed. Widgets Supplies a library of prebuilt widgets and lets users add their own backed by an XQL query or a script, generated from a natural-language description if preferred, with per-widget access control. XQL Query Language Queries any ingested dataset or preset with the Cortex Query Language — a documented stage-based syntax with operators, string and JSON functions, free-text search, reusable macros, graph-rendered results and a personal library of saved queries. XQL Query Management Lets administrators cap user-generated queries — concurrent queries per user and related limits — warning users as they approach the cap and blocking new queries beyond it until running ones finish or are cancelled.
APIs & Developer Tooling API Keys Issues per-role API credentials in a standard form and an advanced form that hashes the key with a nonce and timestamp to defeat replay, presented in request headers and verified before access is granted. Content Development Environments Supports local, containerized and cloud-hosted development setups for content work, with an editor extension supplying autocompletion, virtual environment setup and the SDK commands for linting, formatting and validation. Content Development SDK Provides a Python library and command-line tool that validates content entities, formats packs and moves them between a development setup and the tenant, with code generation from JSON samples, OpenAPI specifications and API collections. Content Pack Contribution Lets customers, partners and individual contributors publish content packs to the marketplace, with defined support tiers, pack structure and dependency rules, pull request conventions, a file checklist and documentation standards for README files, release notes, images and videos. Content Testing Tooling Validates content before release through unit tests, test playbooks, linting and interactive debugging, with sample settings for exercising an integration against a live instance. Cortex CLI Runs code, application, API and cloud workload security scans from the command line or a developer's pipeline, installed as pre-commit and pre-receive hooks, authenticated with self-service API keys and extensible with custom checks and signature verification. Custom Integration Authoring Builds a new integration in the tenant by importing an integration file or filling in a template with parameters, commands, arguments, outputs and Python code, for data sources the marketplace does not cover. Integration Development Framework Defines how an integration or script is built — metadata and description files, typed parameters, commands and arguments, context outputs and standards, reputation scoring conventions, feed and event-collector types, long-running containers, scheduled commands, credential fetching and result caching. Long-Running Integration Endpoints Accepts inbound API calls from third-party software to long-running integrations hosted on the tenant or on an engine, subject to a per-minute request limit and the tenant's approved IP ranges, with custom certificates supported on engines. Marketplace Content Packs Distributes bundled integrations, playbooks, scripts, widgets, dashboards and correlation rules as installable content packs from the vendor, partners, service providers and customers, with a set pre-installed and versions upgraded in place. Public API Exposes documented REST endpoints covering the platform's objects and operations so tenants can drive it programmatically, authenticated with API keys and governed by per-component permissions.
Automation & Orchestration Automation Exclusion Policies Blocks remediation commands and scripts from acting on critical users, addresses, domains and asset groups named in exclusion lists, wherever the command runs, with an optional override parameter that is recorded in the audit log. Automation Rules Runs a playbook, quick action or AI agent automatically against issues matching preset criteria, expressed as a WHEN trigger, an IF condition and a THEN action. Automation Scripts Writes, edits and runs JavaScript, Python or PowerShell scripts that call the platform APIs, take arguments, share results in the War Room and can be password protected, usable in playbook tasks or standalone from the CLI. Autonomous Playbooks Runs vendor-maintained playbooks and matching automation rules on analytics issues without user configuration, updating them automatically as new content ships, across a fixed set of detection domains and a per-hour run limit. Context Data Stores structured key-value data on a case or issue that playbook tasks and scripts read and write, letting users add, search, extend and delete context entries and reference them in task inputs and field mappings. Jobs Schedules a playbook to run at defined times or whenever a feed delta arrives, and manages the resulting job definitions and their run history. Lists Stores reusable data containers of text, Markdown, HTML, CSS or JSON referenced by playbooks and scripts through a context path, with list commands and transforms that extract, filter and convert subsets of the stored data. Playbook Editor Composes a playbook on a visual canvas from a task library of AI prompts, integration commands and scripts, sub-playbooks and loops, manual, communication, conditional and header tasks, with settings, error handling and a test run. Playbook Filters and Transformers Filters and reshapes data as it moves between playbook tasks using built-in filters and transformers by category, with user-defined custom filters and transformers where the built-in set does not fit. Playbooks Runs a defined sequence of tasks against an issue or case to investigate and respond, adopted from a catalog of out-of-the-box playbooks or built from scratch, and triggered by automation rules, jobs or manual execution. Quick Actions Runs a single preset integration command against one or more issues, manually from the issues table or through an automation rule, optionally pinned to a chosen instance and populating parameters from the asset inventory attributes.
Agentic AI Agent Knowledge Sources Grounds agents in uploaded organizational documents such as standard operating procedures and policies alongside built-in product knowledge, cites the source used in responses and logs every upload, deletion and agent connection. Agentic Actions Wraps playbooks, scripts, integration commands and AI prompts as actions an agent can call, using over fifty system actions or custom ones registered by users, and marks sensitive actions as requiring explicit approval before execution. Agentic Assistant Chat Answers natural-language prompts by having the selected agent plan and execute the relevant actions, generating and running XQL queries and rendering the results as charts, with saved chat history and access from a messaging client. Agentic Assistant Hub Manages the AI agents available in the tenant, enabling or disabling system agents, building custom agents with their own instructions, and assigning each agent the actions it may use within the invoking user's permissions; the Help Center system agent now diagnoses a tenant's security, health and workflows and can prefill support tickets. Agentic Response Triggers an AI agent from an automation rule to run an investigation autonomously against an issue, drawing its inputs from the issue fields and the prompt, and pausing for approval before any action marked sensitive. AI Prompts Creates and edits reusable AI prompts with defined inputs and outputs that run as playbook tasks or registered agent actions, starting from existing prompts or written from scratch. Automation Engineer Agent Generates, modifies and explains playbooks and Python automation scripts from natural-language chat requests inside the assistant, acting on the item currently open in the editor. Case Investigation Agent Runs a system agent specialized in case and issue investigation that gathers context, queries data and proposes next actions inside the assistant chat. Cortex MCP Server Exposes tenant case, issue and investigation operations as Model Context Protocol tools from a downloadable server run locally or in a container, connectable from any MCP client and extensible with custom tools. Third-Party MCP Integrations Connects agents to external MCP servers over streamable HTTP using OAuth or authless access, discovering the server's tools and generating agentic actions from them, through per-vendor content packs or a generic MCP integration.
Data Management Archived Data in Cold Storage Imports historical data into cold storage in a defined format and makes it searchable with XQL archived-data queries for analysis, compliance and audit. Automatic Data Enrichment Adds context to mapped data at ingestion without manual mapping, including geolocation for addresses and normalized user identity, and stores the result for later queries. Compute Unit Management Meters query execution against a daily compute-unit quota sized by license, blocks queries once it is exhausted, and lets administrators raise or lower the daily consumption limit and buy additional units as an add-on. Data Model Rules Maps each dataset onto the unified Cortex Data Model schema through default rules shipped in content packs or user-defined rules, written in an editor with autocomplete and mapping suggestions, optionally generated by AI from sampled logs. Data Tiering and Federated Search Splits ingested logs between an analytics tier that receives real-time detection processing and a cheaper data lake tier, and queries external sources in place through federated search rather than ingesting them at all. Dataset Management Manages the datasets every query runs against, including dataset views that expose a query-defined virtual slice for access segregation, default dataset selection, and per-dataset retention across hot and cold storage licenses. Event Forwarding Exports ingested and parsed event logs to a customer-owned cloud storage bucket through a publish-subscribe subscription for long-term archive and compliance retention, with the fields included selectable per event type. Lookup Datasets Uploads user-supplied CSV, TSV or JSON tables as cached name-value datasets that queries, detection rules, hunts and playbooks join against, with a configurable time to live and JSON download. Parsing Rules Transforms raw logs at ingestion with XQL-based rules bound to a vendor and product, dropping unneeded data, tagging records and emitting zero or more rows per log, with grouped rules governed by a no-match policy and an editor that tests rules against real logs.
The previous XSOAR architecture, documented as separate administrator, installation, multi-tenant and threat-intel-management guides per 6.x version.
Threat intelligence management Exclusion list Holds values, regular expressions and CIDR ranges that the system refuses to create as indicators or draw into automated flows, scoped to all or selected indicator types. File indicator merging Represents a file as a single indicator keyed on one hash with its other hashes and file attributes as fields, and merges two file indicators when a shared hash proves they are the same file. Indicator enrichment Enriches indicators through reputation commands and batch enrichment against configured third-party services, caching results for a per-type expiry period to protect API quotas. Indicator expiration Expires indicators by manual action, automation command, feed setting or indicator-type default, and flips expiration status through a job that runs on a schedule. Indicator export Exports selected indicators to CSV or STIX, and publishes query-driven indicator lists as a hosted list, an external dynamic list or a TAXII collection for a SIEM or firewall to pull. Indicator extraction Extracts indicators from incident fields, War Room entries, playbook tasks and command line commands by indicator-type regex, per incident type and per field, in inline, out-of-band or disabled modes. Indicator field trigger scripts Runs a tagged automation in batch when a nominated indicator field changes, such as verdict or expiration status, so the change can drive downstream action. Indicator fields Adds custom indicator fields modelled on the STIX 2.1 domain and cyber-observable object structure, associated with one indicator type or all of them. Indicator formatting, reputation and enhancement scripts Attaches tagged scripts to an indicator type that normalize the extracted value, override the verdict, or run on demand to pull extra detail about a single indicator. Indicator layouts Customizes the summary, quick view and new or edit form of each indicator type, including tab order, viewing permissions per role, display filters and script-driven dynamic sections. Indicator relationships Links indicators to each other and to campaigns, threat actors and malware, created automatically by supporting feeds or manually, and revocable when no longer true. Indicator search and query Searches indicators in a modified Lucene syntax across type, verdict, reliability, source brand and instance, tags and comments, with wildcard and regex terms and saved queries reusable in playbooks. Indicator timeline Shows an indicator full history as dated events covering first and last seen, verdict changes, traffic light protocol and field edits, with per-type and size limits. Indicator types Defines the indicator types the system recognizes, each with a matching regex, formatting, reputation and enhancement scripts, reputation commands, expiration method and cache expiry. Indicator verdict and source reliability Scores each indicator unknown, benign, suspicious or malicious from the highest-reliability source, and merges conflicting field values down a manual, script, enrichment and feed reliability hierarchy. Manual indicator management Creates, edits, bulk-edits, tags, deletes and excludes indicators from the Threat Intel page, uploads a STIX file to add them, and opens an incident populated from selected indicators. Threat intel feed ingestion Fetches indicators from feed integrations on a per-instance interval, applying a reputation, source reliability, expiration method, tags and an exclusion-list bypass to everything the feed returns. Threat intel playbooks Runs playbooks whose input is an indicator search query, processing matched indicators in automatic batches of a thousand with quiet mode on to keep the War Room clear. Threat intel report customization Defines threat intel report types, custom report fields and per-type layouts with tabs, sections, relationships and script-driven dynamic sections, contributable back to Marketplace. Threat intel reports Authors threat intelligence reports in a markdown body against a chosen type, restricts read and write access by role, generates a PDF, and publishes a read-only shareable version.
Deployment and installation Cloud VM deployment Documents supported instance types, disks, inbound ports and snapshot-based backup for running the server on AWS EC2, Azure Virtual Machines and GCP Compute Engine. Database backend selection Stores incidents, indicators and content either in the embedded Bolt database or in an external Elasticsearch or OpenSearch cluster addressed by URL and credentials, with configurable shards, replicas, refresh intervals and index prefix. Deployment health check Verifies a new or upgraded installation through a health endpoint, container sub-system checks, reputation command tests and a failed-instance listing. Development and production environments Pairs every licensed production instance with a lower-specification development instance for building and testing content before promotion. Disaster recovery and live backup Mirrors a production server to a standby server over a configured host and port, and transitions the standby to active when the primary is lost. Elasticsearch migration Migrates an existing Bolt database to Elasticsearch with a standalone tool that copies partitions oldest to newest, supports single server, distributed and multi-tenant sources, allows skipping old partitions, and validates the result. FIPS mode Offers a vendor-affirmed FIPS build that uses the BoringCrypto module validated against FIPS 140-3, for single server, multi-tenant and high availability deployments. High availability Runs multiple identical app servers against a shared Elasticsearch index behind a load balancer so requests fail over between them without a restore. Hosted service Runs Cortex XSOAR as a Palo Alto Networks-operated instance in a customer-selected AWS region, with published ingestion, indicator and retention limits, managed backups and a 99.9% availability target. HTTPS certificates Serves the web interface over HTTPS using a self-signed certificate or a CA-issued certificate and private key, and exposes cipher, HSTS, same-site cookie and content-security-policy settings. Licensing Applies a license file through the UI or the server filesystem, enforces user entitlements per tier, syncs the license across app servers and backup servers, and falls back to community edition on expiry. Migration to Cortex XSOAR 8 Migrates data, configuration, settings, incidents and indicators to Cortex XSOAR 8 Cloud through a built-in wizard, covering hosted, on-premises single-tenant and MSSP multi-tenant sources depending on the version. Offline installation Installs the server on an air-gapped machine from pre-downloaded operating system dependencies and a container image archive, then switches Marketplace to offline mode. Performance tuning Diagnoses slow systems against memory, CPU, disk and database symptoms and tunes worker counts, partition sizes, index settings and playbook data volume accordingly. Proxy configuration Routes server, container and engine outbound traffic through an HTTP or HTTPS proxy set as server configuration, with bypass rules and separate keys for multi-tenant host, tenant and websocket traffic. Reverse proxy support Documents fronting the server with an NGINX reverse proxy so the proxy sits in the DMZ and the server on a private subnet, including websocket route handling and engine redirection. Server upgrade Upgrades an existing installation in place, detecting prior configuration, upgrading core content packs and enforcing a two-version maximum jump per run. Single server deployment Installs the app server and its database on one Linux machine from a shell installer, with flags for data directory, database, external address, signed packages and purge.
System administration Audit trail Records user and system actions in a searchable audit log with configurable server-side retention, and supports reindexing it separately from the main database. Audit trail syslog export Streams audit entries in CEF to an external syslog service over TCP, UDP, TCP with TLS or a UNIX socket, with configurable tag, format, filter and priority. Branding customization Replaces the full-size and collapsed logos, sets a login-page message, names the SOC used in communication tasks, and rewrites the subject and body of each system email type. Cloud artifact storage Stores incident attachments and artifact files in a Google Cloud Storage, Amazon S3 or S3-compatible bucket instead of the local filesystem, and writes the file URL into incident context. Data archiving Frees disk space by moving monthly incident, entry and indicator partitions, artifacts and attachments out of the live data directory into compressed archives, or by snapshotting and deleting the equivalent Elasticsearch indices. Database backup and restore Runs scheduled daily, weekly and monthly database backups to a configurable directory and restores the database or an individual partition from a backup archive. Database reindexing Rebuilds the whole search index, a named index, the audit log or War Room note, chat and evidence entries by passing restore arguments at server or tenant start. Elasticsearch snapshots Backs up and restores Elasticsearch indices through registered snapshot repositories, scheduled with a snapshot lifecycle policy or taken manually before a change. Global search Searches incidents, indicators, entries, evidence, investigations, jobs, playbooks and automations using a Bleve query syntax with field terms, ranges, boolean operators and wildcards, from each page query bar or the global search box. Markdown formatting Renders a Cortex XSOAR flavour of markdown, with a GUI editor and preview, in threat intel reports, the command line, automation output, playbook tasks, widgets, fields and lists. REST API and API keys Exposes a documented REST API over incidents, investigations, indicators, playbooks, scripts, integrations, content packs, dashboards, widgets, reports, evidence, audit logs and system management, authenticated with revocable API keys that inherit the creator permissions, and guarded by optimistic version locking on writes. Server configuration keys Exposes an administrator-editable key and value store for advanced server settings, covering timeouts, limits, interface behaviour, logging and feature toggles. Server data migration Moves the data, artifact and version control directories to another path on the server or to a new machine of the same version by copying the data tree, certificates and license and repointing the configuration file. Server logging Writes server, Elasticsearch, engine and HTTP access logs with configurable level, filename, rolling size and retention, and packages the wider log set into a downloadable bundle for support. System diagnostics Reports CPU, memory, storage, container-runtime and oversized-task health against configurable thresholds, mails a daily digest to nominated roles when something is at risk, and exports the same data as JSON for support. System notifications Sends system notifications through a nominated mail-sender integration instance, with per-user control over which categories arrive on which channel. Telemetry Collects anonymous product usage data, enabled by default and reported in the log bundle, and can be disabled outside the hosted service.
Playbooks and automation Automation scripts Runs user-written Python, PowerShell and JavaScript automations inside a container against shared common-server libraries, with run-as and role permissions, and special tags that bind a script to a surface such as post-processing, field change, condition or dynamic layout section. Communication and data collection tasks Sends a form to internal or external recipients from a playbook task and, when required, authenticates the recipient against SAML or Active Directory before showing the form. Context data and extend context Stores task and command output as incident context, and extends it with additional fields from a command raw response under custom keys, including DT expressions, from a task or the command line. DBot machine learning scripts Ships pre-built machine learning automations that find similar and duplicate incidents, detect email campaigns, and predict whether a URL is phishing from its page content and domain data. Filters and transformers Extracts a subset of context data with filters and reshapes values with ordered transformers, in playbook tasks and in instance mapping. Jobs Runs a playbook on a schedule or when a nominated feed finishes a fetch that changed indicators, and tracks each run as an incident with its own work plan and War Room. Lists Stores reusable text, CSV and JSON lists that playbooks and automations read, parse and filter, with a configurable separator character. Machine learning models Trains a phishing classification model on the organization own past incidents, mapping existing classification values onto verdicts, with from-scratch or fine-tune algorithms and per-language filtering. Playbook authoring Builds playbooks in a visual editor from standard, conditional, data collection and section-header tasks, with sub-playbooks and loops, inputs and outputs, field mapping, per-playbook roles, quiet mode, and attach or detach against content pack updates. Playbook debugger Steps through a playbook against a mock incident, the playground or an existing incident, with breakpoints, task skipping and per-session input and output overrides that do not alter the saved playbook. Playbook error handling Sets retry count and interval per task and chooses whether a failing task stops the playbook, continues, or branches down a dedicated error path. Playbook polling Blocks a parent playbook on a generic polling sub-playbook that repeatedly checks a long-running remote process, such as a sandbox detonation, until it completes or times out. Scheduled commands Schedules a War Room command to run once or on a recurring frequency set in a readable form or a cron expression, with start and end times.
Incident configuration Classification and mapping Classifies events fetched from an integration into incident types by a chosen key and maps the incoming JSON onto incident fields, per integration instance. Evidence fields Defines custom fields that appear when an analyst marks an artifact as evidence, capturing structured detail on the evidence board for audit and regulatory purposes. Fetch incidents from integrations Polls third-party integration instances on a configurable interval for events and turns them into incidents that trigger playbooks, and notifies nominated users when an instance transitions from a successful fetch to a failing one. Incident deduplication Identifies and closes duplicate incidents manually, through pre-process rules, or through text-similarity, rule-based and machine-learning scripts driven by out-of-the-box playbooks. Incident field trigger scripts Runs a tagged automation when a nominated incident field changes, receiving the old and new value and the user who changed it, so the change can adjust other fields or notify a responder. Incident fields Adds custom incident fields across text, number, date, grid, HTML, markdown, multi-select, role, tag, timer and user types, with placeholders, values and per-type association. Incident layouts Customizes the incident summary tabs, new and edit form, close form and quick view with sections, fields, action buttons, per-role viewing permissions, display filters and script-driven dynamic sections. Incident mirroring Keeps an incident and a record in a third-party case system in step in both directions, including file attachments, through incoming and outgoing mappers and mirroring commands. Incident types Defines the incident types an organization handles, each binding a default playbook, layout, SLA, reminder, post-processing script and indicator extraction rules. Post-processing scripts Runs a tagged script when an incident is closed, receiving the close reason, notes and closing user, and blocks the close if the script errors. Pre-process rules Acts on events at ingestion by filter, dropping them, linking or closing them against an existing incident, or updating that incident, with ordered rules testable against a sample event. SLA and timer management Counts down SLA fields and counts up timer fields against a per-field duration and a global risk threshold, and runs a tagged script when an SLA breaches.
Incident response Command line interface Accepts integration commands, automations and built-in commands prefixed with an exclamation mark, system operations prefixed with a slash, and user tagging prefixed with an at sign. DBot canvas suggestions Suggests which related incidents and indicators to pull onto the investigation canvas from malicious verdicts, malicious ratio, shared context and hash similarity, and can populate the canvas automatically against a tunable similarity distance. Evidence board Pins War Room entries and other artifacts as evidence with details, collecting the key artifacts of an investigation in one board. Incident access control Restricts an investigation to its team members, and grants named roles read/write or read-only access to an incident from the layout, a command or a playbook. Incident export and summary reports Exports an incident to CSV or JSON, and builds a per-incident summary report from any incident tab as PDF, Word or CSV, saveable as a reusable template. Incident queue Lists incidents with status, type, severity and owner alongside summary charts, and assigns, edits, reruns, marks duplicate, runs commands on and closes them individually or in batch. Incident search queries Filters the incident queue with a saved query, date range, custom table columns and chart panel, and shares a saved query with all users. Incident tasks Tracks the playbook tasks awaiting attention and ad hoc to-do tasks created on an incident, each with an owner, due date and tags, without blocking closure. Investigation canvas Lays incident entities and indicators on a graph where an analyst expands an indicator to pull in its related indicators, campaigns and threat actors, or auto-populates the graph from related and linked incidents and shared indicators. Related incidents Scores other incidents for similarity on shared indicators, labels and custom fields and plots them on a time-and-similarity map from which they can be linked or paired as duplicates. War Room Gives every incident a ChatOps timeline where analysts run commands, playbooks and scripts, converse, and edit, tag, attach, download or filter each entry. Work plan Shows the running playbook as a task-by-task plan for the incident and lets analysts insert ad hoc automation or playbook tasks into that iteration and re-run it.
Multi-tenant management Content propagation labels Tags content items and tenant accounts with matching propagation labels so only labelled content is eligible to sync, pulling in dependencies regardless of their own labels. Cross-tenant operations Views incidents, indicators and dashboards from any tenant in the main account and runs one command locally on incidents across several tenants at once. Host management Adds, renames and deletes host servers and high availability groups from downloadable host installer packages, and promotes an existing host into a highly available group. Locked content restrictions Stops tenant-local users cloning, detaching, downloading or viewing the code of custom locked automations, integrations and playbooks pushed from the main account. Multi-tenant communication and security Carries main-to-host and host-to-tenant traffic over TLS on a configurable port with an internal API key, and supports unidirectional tunnelling and per-deployment certificate validation settings. Multi-tenant deployment Runs many isolated tenant processes across a main account and proxy hosts, keeping each tenant incident data on its own partition or index and none of it on the main account. Shared indicator index Publishes a tenant indicators to a dedicated Elasticsearch index on a query and interval, and lets other tenants ingest that index as a feed. Tenant account management Adds, edits, moves, blocks, stops, deletes and exports tenant accounts from the main account, sets which roles may reach each tenant, and forwards named server configurations to all of them. Tenant backup and maintenance Backs up, restores, reindexes and War Room-indexes an individual tenant by stopping and starting that tenant process from the main account. Tenant content sync Pushes content from the main account to selected tenants, showing what will be added, overridden and removed for review before the sync runs.
Users, roles and authentication Directory authentication Authenticates users against an external directory through an Active Directory or LDAP integration instance and maps directory groups onto Cortex XSOAR roles. Password policy Enforces password complexity, expiry, reuse prevention over the last thirty passwords and lockout after repeated failed attempts, shipping a FIPS-compliant default policy. Role-based access control Grants access through roles carrying none, read or read/write permission levels on each component and page, with built-in administrator, analyst and read-only roles, per-role default queries and roles definable per tenant. SAML single sign-on Authenticates users against a SAML 2.0 identity provider with documented setups for Okta, AD FS, Microsoft Entra ID and Duo, mapping provider groups onto Cortex XSOAR roles and supporting single logout. Self-service read-only users Lets authenticated users with no role raise incidents, view and annotate only their own, and open dashboards an administrator has shared with them. Shift management Defines shift periods on roles and assigns analysts to them, so incidents can be routed and owners suggested based on who is on shift, their workload and machine learning recommendation. User data erasure Clears a removed user data from open incidents and optionally from version control commits, run from the command line, a playbook or a scheduled job against a list of usernames. User lifecycle management Invites users by email, edits their roles, resets passwords, locks and unlocks accounts, and temporarily disables or permanently removes them. User preferences Lets each user set their own profile details, availability status, default landing page, theme, time zone, date format and notification channels.
Marketplace and content management Content marketplace Browses, installs, updates, reverts and deletes content packs of integrations, playbooks, scripts, layouts and dashboards, resolving required and optional dependencies, with reviews, support tiers and an offline install path. Content pack contributions Packages custom content into a content pack, validates it with a lint and validate automation, and submits it to Marketplace for review or downloads it for a pull request on the public content repository. Content pack update notifications Subscribes a user per installed content pack to daily update notices delivered by email or a messaging integration, with configurable delivery hours and release-note length and a global opt-out. Content version control Saves named versions of playbooks and other content items with a commit message and author, and restores an earlier version from the version history. Custom content export and import Exports all custom content to a downloadable bundle and imports it back, and takes an automatic bundle backup whenever repository settings change. Deployment wizard Walks an administrator through standing up a use case after installing its content pack, configuring the fetching integration, the main playbook inputs and the supporting integrations in order. Remote content repository Connects a development instance and a production instance to a shared Git repository over SSH so content is authored, pushed, pulled, conflict-resolved and installed as a controlled update.
Engines and container runtime Container hardening Restricts automation containers with non-root internal users, memory, CPU, PID and file-descriptor limits, iptables network rules, a SELinux policy for PowerShell, and custom certificate trust. Container image management Pulls automation images from the vendor Docker Hub organization or the authenticated Cortex XSOAR private registry, pins an image per script or integration, builds custom images, and loads images offline or from the server to an engine. Container runtime Runs every Python and PowerShell automation and integration in an isolated Docker or Podman container, choosing the runtime automatically from the operating system and supporting rootless Podman. Engine load-balancing groups Groups engines so command execution for the integrations assigned to a group is distributed across its members, with separate groups per site, tenant or critical integration. Remote engines Installs engines on Linux or Windows machines inside remote or customer networks that proxy integration and script execution back to the server over an outbound connection, with per-engine configuration, in-place upgrade and several engines per host.
Dashboards and reporting Custom widgets Defines a widget from a JSON definition or from an automation script that returns the data, for cases the widget builder does not cover such as disk partition usage or a custom currency. Dashboards Builds and edits dashboards of widgets, and shares them read-only or read-write with selected roles. Reports Composes reports from widgets, generates them as PDF, Word or CSV in a chosen orientation, paper size and time zone, and schedules them to run and mail to recipients under selected roles. Widgets Provides a widget library of charts, tables, numbers and text over incident, indicator and system data, addable to dashboards, reports and incident layouts.
Integrations and credentials Integration command permissions Assigns the roles permitted to run each command of each integration instance, blocking unpermitted users from the command line, playbook tasks and pending work plan tasks. Integration instances Configures named instances of third-party integrations with credentials, fetch settings, proxy and engine assignment, and tests connectivity from the instance page.
The customer-hosted edition of XSOAR 8, adding cluster installation, node and engine operation, and upgrade paths the SaaS edition does not document.
Threat intelligence management Enhancement scripts Runs analyst-triggered scripts from the indicator quick view or the CLI to gather extra data about an indicator and return it to the War Room. Formatting scripts Validates extracted indicator values and normalizes how they display, for example refanging defanged IP addresses. Indicator classification and mapping Classifies indicators arriving from feeds, extraction and manual creation and maps incoming feed fields onto indicator fields, including custom fields. Indicator enrichment Enriches extracted indicators through the commands and scripts defined for their type, drawing detail from third-party services such as VirusTotal and IPinfo. Indicator exclusion Deletes indicators or adds them to an exclusion list so they are neither created nor enriched again. Indicator expiration Expires indicators by type, feed or script on a configurable method, updates expiration status through a daily job, and supports manual expiry. Indicator export Exports indicators to CSV or STIX and publishes them as a hosted external dynamic list through the Generic Export Indicators Service for consumption by firewalls and SIEMs. Indicator extraction Extracts indicators by regex from incident fields, War Room entries and other text, in none, inline or out-of-band modes, with per-incident-type extraction rules on creation and on field change. Indicator fields Creates typed indicator fields modelled on STIX 2.1, scoped to one or all indicator types, with optional field trigger scripts. Indicator layouts Customizes the tabs, ordering, visibility and content of the layout shown for each indicator type. Indicator management Lists ingested indicators on the Threat Intel or Indicators page with actions to create, tag, comment on, delete and act on them. Indicator relationships Records typed connections between indicators, created manually or automatically by feeds that supply relationship data, and explores them from the incident or indicator view. Indicator timeline Shows recent and historical changes to an indicator in a chronological timeline for licensed Threat Intel Management tenants. Indicator types Defines out-of-the-box and custom indicator types with their regex, formatting script, reputation command and script, verdict logic, layout and fields, including file hash handling. Indicator verdict Assigns each indicator a verdict from reputation commands, reputation scripts, manual override and a configurable global risk threshold. Sessions and submissions Searches firewall sessions and sandbox submissions associated with an indicator for tenants licensed for Threat Intel Management. Threat intel feeds Ingests indicators from feed integrations such as AlienVault, TAXII and Office 365, with the number of active feeds and stored indicators gated by the Threat Intel Management license. Threat intel processing playbooks Runs playbooks over an indicator search query to tag, enrich, verdict and prepare large volumes of feed indicators for review. Threat intel reports Creates, reviews, publishes and generates threat intelligence reports with their own report types, fields and layouts, gated by role-based access.
Playbooks and automation Automation scripts Creates and edits JavaScript, Python and PowerShell automations in the tenant and reuses the Base and Common Scripts libraries from playbooks and the CLI. Data collection and survey tasks Sends single-question ask tasks or multi-question surveys to internal and external users and feeds their answers back into the playbook and the incident. Extend context Saves additional fields from a command's raw response into context, or the same command's output into different context keys. Filters and transformers Filters and reshapes context data with built-in or custom filters and transformers before it is used in later tasks. Guard rails warnings Flags service-limit warnings and errors that would degrade playbook or tenant performance on a dedicated Guard Rails page. Inline playbook documentation Shows author-written guidance on individual tasks and section headers directly inside the playbook editor. Jobs Runs a playbook on a schedule, including cron expressions, or when a feed fetch produces a change in its indicators. Lists Stores reusable Text, Markdown, HTML, CSS or JSON lists with per-role read and edit permissions and version history, and consumes them from playbooks and scripts. Playbook builder Builds automated response workflows visually, either from scratch or by detaching and customizing an out-of-the-box playbook from a content pack. Playbook debugger Steps through a playbook in a test environment showing what each task writes to context and which indicators it extracts, including sub-playbooks. Playbook error handling Chooses whether a task error stops the playbook, continues it, or routes execution down a dedicated error path. Playbook polling Pauses a playbook while a long-running third-party operation such as sandbox detonation completes, using the GenericPolling playbook to poll for status. Playbook tasks Composes playbooks from standard, conditional and section-header tasks that run scripts and commands, branch on built-in or scripted conditions, group steps and track phase timing. Playbook versioning and edit locking Saves commented playbook versions for rollback and locks a playbook to a single editor, releasing the lock on save, close, logout or session expiry. SLAs and timers Provides timer and SLA incident fields that playbooks, scripts or the CLI start, pause and stop, with scripts that fire on breach. Sub-playbooks Nests a playbook inside another as a task, passing inputs and returning outputs so common flows can be reused across use cases.
System administration Audit log and syslog forwarding Records management and content-lifecycle activity in a management audit log and forwards audit notifications to customer syslog servers over TCP or TLS with connection status and test messages. Backup and restore Runs one-time or scheduled encrypted backups of object metadata and volume data to external storage and restores them on demand into a matching cluster. Browser support Documents the web browsers supported for the Cortex XSOAR console. Custom content import and export Uploads a full custom content bundle or individual content types into the tenant and exports all custom content as a compressed file for sharing. External storage connections Connects the tenant to Amazon S3, S3-compatible buckets such as MinIO, or NFS as the destination for backups and incident exports. Keyboard shortcuts Provides keyboard shortcuts for fast navigation and for copying, cutting, pasting and deleting playbook tasks. Log bundles Downloads a bundle of system logs covering the previous ten days from the product UI or the textual UI for support tickets and debugging. Platform search Searches incidents, entries, evidence, investigations and indicators using Bleve query syntax or a global free-text box, with saved and shared queries. REST API Exposes a REST API authenticated with a generated API key and key ID for creating and updating incidents and driving tenant operations programmatically. Server configuration keys Applies tenant-level key and value server configurations covering engines, incidents, indicators, integrations, notifications, playbooks, proxy, reports, scripts, SLAs and widgets. Support sessions Opens a time-limited elevated shell for support or engineering, authenticated against the tenant license and closed when they log out. System and security settings Configures session expiration, approved domains and IP ranges, and disabling of inactive users, plus server-level timezone, timestamp format, logo, login message and SOC name. System diagnostics Charts system health trends over selectable windows from one hour to seven days on the System Diagnostics page so administrators can catch issues before they become critical. System email templates Customizes the subject, body and HTML format of the system emails Cortex XSOAR sends for mentions, invitations and other events. Telemetry controls Collects product usage telemetry across playbooks, integrations and content, and lets administrators limit or disable collection beyond what the license requires. User notifications Sends system notifications to users through a mail sender integration or a messaging integration such as Slack or Microsoft Teams, with per-user choice of channel.
Incident configuration Close reason customization Replaces the default incident close reasons with organization-specific values through a server configuration. Dynamic fields Drives which fields and which single- or multi-select values appear in layouts and forms from a script evaluated against other field values. Field trigger scripts Runs a tagged script when an incident field changes so the change can update other fields or notify responders. Incident classifiers Classifies fetched events into incident types based on an attribute of the raw JSON, built from a live instance, a schema pull or an uploaded JSON sample. Incident context data Holds command, script and playbook output for each incident as a structured JSON context that passes data between tasks and feeds incident fields and layouts. Incident deduplication Detects duplicate incidents manually from the incidents table or automatically through pre-process rules and playbook scripts. Incident export and deletion Exports incidents with their context, investigation, War Room entries and optional attachments as JSON to external storage, and deletes them, on demand or on a schedule. Incident fields Defines custom incident fields of typed kinds that hold data ingested from integrations or entered by analysts, and attaches them to layouts and mappers. Incident layouts Customizes which tabs and sections an incident type shows, their order, who may view them, and lets scripts render charts and custom content inside the layout. Incident mappers Maps third-party event fields onto incident fields on the way in and incident fields onto third-party fields on the way out, per incident type or as common mapping. Incident mirroring Keeps incident fields, comments and file attachments in sync in both directions with a third-party system such as ServiceNow or Jira. Incident types Creates and duplicates incident types that carry their own field set, layout and default playbook, and detaches content-pack types for editing. Post-processing scripts Runs a script when an incident is closed to perform closing actions such as updating an external ticket, sending mail or blocking closure without an owner. Pre-process rules Drops, deduplicates, links or closes incoming incidents against configurable criteria after classification and mapping but before the incident is created, and tests rules against existing incidents.
Incident response Command line interface Runs system commands, integration commands and automation scripts from an in-product CLI with autocomplete, and records plain-text or Markdown notes into the incident. Evidence handling Marks War Room entries as evidence and collects them on an evidence board that records what justified the investigation's conclusions. Incident creation Creates incidents from the Incidents page, from an indicator, from a JSON file, through the REST API or from an integration feed. Incident export to file Exports selected incidents from the incidents table to Excel or CSV, with UTF8-BOM handling for non-Latin character sets. Incident investigation Opens an investigation automatically when a playbook is attached or manually from the queue, drives remediation through the Work Plan and moves the incident through pending, active and closed states. Incident linking Links related incidents or marks one as a duplicate of another, from the table, the incident view or the CLI. Incident queue Lists every incident with filtering, sorting, ownership, severity and status changes and bulk actions from the Incidents page, gated by role permissions. Incident retention Marks up to a thousand incidents for permanent retention so they cannot be deleted manually or through the API. Incident summary report Generates a PDF summary of an investigation for sharing with team members. Investigation access control Restricts an investigation to named users or roles, limits which roles can act on incident actions, and grants read-only access. Investigation canvas Lays out incidents, indicators and War Room entries on a visual canvas to show how the elements of an investigation connect. Scheduled commands Schedules a War Room command once or on a recurring interval or cron expression, with start and end times in the tenant timezone. War Room Gives each incident a ChatOps war room that records every automatic and manual action, runs commands and playbooks in place, captures notes and mentions, and suggests analysts and command sets from machine learning.
Deployment and installation High availability Replicates data across a three-node cluster behind a virtual IP or ingress address so the tenant keeps running when a node fails. Installation troubleshooting Diagnoses failed or degraded installations from the textual UI with log bundles, license upload, graceful per-node shutdown and reboot, and documented limitations and fixes. License management Uploads a per-user Cortex XSOAR license to the tenant and reports license type, expiration, licensed and active user counts, and paired child tenants. Load balancing Distributes tenant traffic across cluster nodes using the built-in virtual IP, or through an external load balancer with sticky sessions and cookie-based persistence. Resource scaling Scales the deployment between CPU, memory and disk tiers from the textual UI and automatically expands persistent volume claims when disk usage passes a threshold. Standalone and cluster topology Installs as a single-node standalone tenant or a three-node Kubernetes cluster, and adds, taints, drains, uncordons or removes nodes from the textual UI. Textual UI administration console Provides an SSH and VM-console menu for host and network configuration, NTP and proxy settings, cluster installation, node trust, scaling, upgrades, shutdown and reboot. TLS certificate management Serves the tenant over HTTPS with a self-signed or customer-supplied certificate covering the cluster, API and external hostnames, and syncs custom CA roots across the cluster for outbound integrations. Version updates Checks for new versions several times a day, notifies administrators, and applies the upgrade including operating system patches from the product UI or the textual UI. Virtual appliance deployment Deploys Cortex XSOAR as a self-contained virtual appliance from OVA, VHD or QCOW2 images onto VMware vSphere, Microsoft Hyper-V, KVM, AWS and Oracle Cloud Infrastructure, including image and license download from Cortex Gateway.
Integrations and credentials Credential management Stores usernames, passwords, certificates and SSH keys as reusable named credentials for integration instances, and can read them from an external credentials vault instead. Custom integration authoring Creates and edits integrations inside the tenant, defining commands, parameters and the image they run on. Fetch error notifications Notifies administrators and listed users when an integration instance fails to fetch incidents, optionally collapsing multiple mail-sender instances into one message. Incident fetching Polls an integration instance for third-party events on a configurable fetch interval and turns them into Cortex XSOAR incidents. Integration command permissions Restricts which roles may run an integration's commands, per instance or per individual command, across the CLI, playbook tasks and pending work-plan tasks. Integration image selection Selects which container image an integration or script runs on from the published image registry. Integration instances Configures one or more instances of an integration to connect and exchange data with a third-party product over REST APIs, webhooks and other transports, one-way or two-way. Integration troubleshooting Tests an instance's connection, downloads a debug log for a single test run, enables verbose logging and reviews sortable integration logs. Long-running integrations Runs listener-style integrations continuously and forwards inbound requests to them. Private image registry Pulls integration and script images from a customer-controlled private registry, directly or through an engine.
Multi-tenant management Content sync to child tenants Pushes content from the main tenant to child tenants, adding, overriding or removing items and reporting tenants that were disconnected during the sync. Cross-tenant incident view Shows incidents from every child tenant on the main tenant and pivots into the owning tenant to act on one. Cross-tenant indicator view Shows indicators and threat intel reports from every child tenant on the main tenant's Threat Intel page, with pivot into the owning tenant. Cross-tenant user and role sync Defines users, roles and user groups on the main tenant and syncs them to the child tenants each group makes available. Main tenant users in investigations Adds main-tenant users to a child tenant's investigation as team members or owners so both sides can work the incident together. Multi-tenant deployment Installs a main tenant and multiple child tenants from the same image for managed security service providers that need data segregation with shared practices. Multi-tenant engines Creates engines on the main tenant and propagates them to child tenants, with per-tenant encryption handshakes routed through the main tenant. Propagation labels Labels child tenants and individual content items so only matching content syncs to each tenant. Tenant management console Manages paired tenants from the main tenant's Tenant Management page, showing connection state and running a batch command across all child tenants. Tenant pairing Pairs a child tenant to the main tenant using the child URL and a pairing token so the two can communicate and share content.
Marketplace and content management CI/CD content pipeline Manages content through an external CI/CD pipeline using the XSOAR CI/CD content pack. Content pack contributions Builds a content pack from items created in the tenant, validates it, submits it for review and resubmits changes against the existing pull request. Content pack lifecycle Installs, updates, reverts and deletes content packs while resolving required and optional dependencies, and shows content, version history and installation status before installing. Content pack update notifications Sends daily notifications about available updates per installed content pack, by email or another configured notification service. Content packs Bundles integrations, playbooks, scripts, incident types, layouts, widgets and dashboards into Marketplace packs, with a set of core packs pre-installed in every tenant. Content versioning Saves named versions of playbooks, scripts and integrations with commit messages and restores an earlier version. Deployment wizard Walks through configuring the fetching integration, the main playbook and its parameters, and supporting integrations for the Malware Investigation and Response and Phishing content packs. Development to production content push Pushes selected content from a development tenant to the remote repository for production tenants to install, with per-item include and exclude control. Remote content repository Connects the tenant to a private Git repository on GitHub, GitLab, Bitbucket or an on-prem host so development and production tenants share content.
Engines and remote execution Container hardening and image security Limits container CPU, memory, file descriptors and network access through engine configuration keys, and publishes image provenance, nightly package data and continuous scanning for the shipped images. Container runtime for integrations and scripts Runs Python and PowerShell integrations and scripts in Docker or Podman containers that package their dependencies, with documented migration from Docker to Podman and rootless Podman on Red Hat. Engine certificates Replaces the engine's default self-signed key and certificate with customer-supplied files. Engine configuration Sets engine properties such as log level, log file, engine URLs and bind address through the d1.conf file or, for shell installations, from the product UI. Engine management Lists engine name, host, status and connection on the Engines page and upgrades, removes, groups engines for load balancing, and propagates them to tenants. Engine proxying Routes engine traffic through an HTTP or HTTPS web proxy and supports NGINX as a reverse proxy so the engine can sit on a private subnet behind a DMZ. Engine troubleshooting Downloads engine logs from the Engines page and surfaces the d1.log field with connection state and errors for debugging. Remote execution engines Runs integration instances, scripts and commands on remote Linux machines so Cortex XSOAR can reach on-prem resources, with shell, DEB, RPM, zip and air-gapped installation options.
Users, roles and authentication Directory authentication Authenticates users against Active Directory or OpenLDAP and derives permissions by mapping directory groups to Cortex XSOAR user groups. Password policy Enforces password complexity and rotation rules for locally authenticated users. Roles and role-based access control Defines predefined and custom roles with view or edit permission per component, page access, preset role queries and shift management, and assigns them to users or groups. SAML single sign-on Authenticates users against any SAML 2.0 identity provider, with documented setups for Okta, Microsoft Entra ID and PingOne and group-to-user-group mapping. User groups Assigns users to groups that each carry one role, supports nesting and multiple group membership, and maps SAML or LDAP groups onto them. User management Creates local users and lists user type, role and group membership, adding SSO and LDAP users automatically on first login with the role mapped to their group.
Dashboards and reporting Automation ROI widget Estimates the money saved by automated actions across all incidents and users in the Saved by DBot widget. Custom widgets Defines widgets from an uploaded JSON file or from a JavaScript, Python or PowerShell script, including script-based widgets added to the War Room by command. Dashboards Creates and edits dashboards over a chosen date range from system and custom widgets and shares them with selected roles. Reports Builds reports from widgets and schedules them with an incident time range, recipients, timezone, page size and PDF or CSV output. Widget builder Defines widget data, type and appearance with live preview in the Widgets Library, and saves an incident or indicator query result as a widget.
Security orchestration, automation and response — playbooks, incident management, integrations and the automation engine — as run by Palo Alto in its own cloud.
Threat intelligence management Enhancement scripts Runs analyst-invoked scripts from the indicator quick view or CLI that gather extra data about an entry, write it to context and return entries to the War Room. Formatting scripts Validates and normalizes an extracted indicator value before it is stored, controlling how the indicator appears in the War Room and reports. Indicator classification and mapping Classifies ingested indicators by detection method and maps source attributes onto indicator fields, including automatic mapping of custom fields. Indicator enrichment Enriches extracted indicators using the commands and scripts defined for their type, with per-indicator and per-feed exclusions from enrichment. Indicator exclusion Maintains an exclusion list of indicators the system ignores during extraction and automated flows, and deletes indicators from the tenant. Indicator expiration Sets when indicators move from Active to Expired, by interval or explicit date, with a daily job updating expiration status and manual expiry available per indicator. Indicator export Exports indicators as CSV or STIX from the indicators table, and publishes them as a hosted external dynamic list through the generic export indicators service on the tenant or an engine. Indicator extraction Extracts indicators from incident fields, War Room entries and other text by regex, in none, inline or out-of-band mode, configurable per incident type, per playbook task and per script. Indicator fields Creates indicator fields modelled on the STIX 2.1 field structure, scoped to one indicator type or all of them, optionally driven by a trigger script when a value changes. Indicator layouts Customizes which tabs, sections and data appear for each indicator type and who may view them. Indicator management Lists ingested indicators on the Threat Intel page with actions to create, edit, tag, enrich, delete, exclude and export them. Indicator query Queries indicators by type, value, verdict, source, expiration and other fields, with quick and full views of a selected indicator. Indicator relationships Records and displays typed connections between indicators, created manually or automatically by feeds and enrichment integrations, and surfaces them during an investigation. Indicator timeline Shows recent and historical changes to an indicator so analysts can see how its data evolved. Indicator types Defines out-of-the-box and custom indicator types whose profile sets the recognition regex, formatting script, reputation command and reputation script, including a single File type carrying all hashes. Indicator verdict Assigns an indicator's verdict from the source with the highest reliability, scaled on the Admiralty reliability matrix, and resolves ties between equally reliable sources. Reputation commands and scripts Obtains an indicator's reputation from built-in or custom reputation commands against external intelligence services, and applies custom scoring logic through reputation scripts. Threat intel feeds Ingests indicators from feed integrations installed as content packs, with the number of concurrent feeds and indicator volume gated by the Threat Intel Management license. Threat intel processing playbooks Runs playbooks over an indicator search query to process large volumes of incoming feed indicators, assigning verdicts and pushing results to downstream systems. Threat intel report customization Defines threat intel report types, fields and layouts so reports carry organization-specific structure and data. Threat intel reports Creates, reviews, publishes and generates threat intelligence reports that communicate research to internal and external stakeholders.
System administration API keys Issues standard or nonce-hashed advanced API keys scoped to a role, with optional expiration dates and in-product expiry notifications, paired with a key ID and tenant FQDN. Audit log and syslog forwarding Forwards management audit logs, integration logs and Guard Rails notifications, optionally filtered, to an email distribution list or a registered syslog server whose TLS connection is health-checked. Browser support Documents the desktop browsers the Cortex XSOAR web interface is supported on. Custom content import and export Uploads and downloads a full custom content bundle, or individual content types such as playbooks, so content moves between tenants without a repository. External storage connections Registers Amazon S3, S3-compatible or Azure Blob buckets under External Storage and configures egress in Cortex Gateway so the tenant can write to them. Guard Rails warnings and errors Reports misconfigurations detected during incident ingestion, investigation and response so automation settings can be corrected before performance degrades. Integration logs Collects logs from integrations and scripts running with verbose or debug logging, giving visibility into calls between Cortex XSOAR and external systems. Keyboard shortcuts Provides Mac and Windows shortcuts for fast navigation, focusing the CLI and other frequent actions across pages. Management audit logs Records every administrative user interaction with system objects, filterable and sortable by user, type and object, with savable filters and configurable columns. Markdown support Accepts Markdown, with an editor and preview, in threat intel reports, the CLI, scripts, playbook tasks, widgets, incident fields and lists. Optimistic locking and versioning Rejects API writes against a stale object version, with an explicit override that forces newer data to be overwritten. Platform search Searches across incidents, indicators, entries, chats and titles using Bleve query syntax, a search box, free text or a general search. REST API Exposes a public REST API covering incidents, indicators, investigations, entries, evidence, playbooks, scripts, integrations, jobs, lists, dashboards, widgets, reports, engines, syslog servers, content packs, remote repository, audit log and multi-tenant content. Server configuration keys Sets tenant-level key and value server configurations that change platform behaviour, such as script timeouts, close reasons, export encoding and UI options. System and security settings Configures session expiration, approved login domains and IP ranges, automatic disabling of inactive users, plus branding, login message, timezone and timestamp format. System email templates Overrides the subject and body of each system-generated notification email and chooses whether it is sent as HTML. Telemetry Collects product usage data that Palo Alto Networks analyzes to guide improvements and roadmap decisions. User notifications Delivers system, incident, playbook and task notifications through a built-in or replaceable mail sender and through messaging integrations, with each user choosing their channels. User preferences Lets each user set their own name, password, notification channels, timezone, timestamp format and keyboard shortcut behaviour without affecting other users.
Incident response Command line interface Runs system commands, integration commands and scripts from an in-product CLI with auto-complete, and records plain-text or Markdown analyst notes in the incident. Evidence handling Marks War Room artifacts as evidence, collects them on an Evidence Board and highlights analyst notes explaining why actions were taken. Incident creation Creates incidents from the Incidents page, from an indicator, from a JSON file, through the REST API or automatically from an integration instance. Incident export to file Exports one or more incidents from the incidents table to Excel or CSV, with a server setting for UTF8-BOM output. Incident investigation Opens an investigation on an incident, automatically or manually, and runs the playbook associated with its incident type. Incident linking Links related incidents and marks one as a duplicate of another from the incidents table. Incident queue Lists every incident in the tenant with filtering, column configuration and bulk actions such as assignment, severity change, duplicate marking and closure. Incident retention Retains incidents for six months from creation by default, extendable with retention licenses, and allows a bounded set of incidents to be exempted from deletion. Incident search Searches incidents with Bleve query syntax across fields, entries and free text, with queries that can be saved and shared. Incident summary report Generates a PDF summary of a single investigation for sharing with team members. Incident tasks Tracks the tasks users must complete during an investigation, separated into playbook tasks and ad-hoc tasks, with owners and status. Investigation access control Uses role-based permissions to restrict which analysts can view an investigation or take specific incident actions such as changing status or managing the Work Plan. Investigation canvas Builds shareable attack diagrams that link incidents and indicators, with suggested entities and static snapshots of the graph. Scheduled commands Schedules a War Room command to run once or on a recurring interval between a start and end time, in the tenant's timezone. War Room Gives each incident a ChatOps workspace that records every automatic and manual action as an audit trail and offers machine-learning suggestions for analyst assignment and commands. Work Plan Shows the running playbook for an incident as a navigable plan where analysts follow progress, complete manual tasks and add ad-hoc tasks for that investigation.
Playbooks and automation Automation scripts Creates and edits JavaScript, Python and PowerShell scripts that run in playbook tasks and the War Room, take arguments, access the Cortex XSOAR APIs and can be password protected. Data collection and survey tasks Sends surveys to internal or external recipients to collect data during an incident and feeds their answers back into the playbook as task inputs. Extend context Saves additional fields from a command's raw response into context when the integration's default output omits them. Filters and transformers Selects and reshapes JSON data flowing through playbooks using categorized built-in filters and transformers, or custom ones written as scripts. Inline playbook documentation Attaches guidance to section headers and tasks that renders inside the playbook editor so the intent of each step is visible to later editors. Jobs Runs a playbook on a schedule or when a feed fetch produces a change, for recurring work such as indicator processing, reporting and cleanup. Lists Stores reusable text, Markdown, HTML, CSS or JSON data with per-role read and edit permissions, readable from playbooks, scripts and the CLI through list commands. Playbook builder Composes playbooks as a visual flow of tasks, conditions and loops, from scratch or by customizing an out-of-the-box playbook, with settings for tags, access, incident-type association and quiet mode. Playbook debugger Runs a playbook in a test environment showing what each step writes to context and which indicators it extracts, and analyzes task input and output storage when performance degrades. Playbook error handling Sets per-task behaviour when a script errors, so the playbook stops, continues or follows an error branch. Playbook inputs and outputs Declares the data a playbook or task consumes and produces so outputs of one step become inputs to later steps. Playbook polling Pauses a playbook and re-checks a third-party process, such as a detonation or scan, until it completes before continuing. Playbook tasks Provides standard manual and automated tasks, conditional tasks that branch a playbook, and section headers that group tasks and time-track investigation phases. Playbook versioning and edit locking Saves playbook versions for restore and allows only one user to edit a playbook at a time. SLAs and timers Provides out-of-the-box and custom Timer/SLA fields set on incident types, started and stopped from playbooks, scripts or the CLI, with a configurable global risk threshold and breach scripts. Sub-playbooks Runs one playbook as a task inside another so common response logic is written once and reused across parent playbooks.
Incident configuration Close reason customization Replaces or extends the default incident close reasons through a server configuration key. Evidence fields Defines custom fields, independent of incident type, that capture structured detail about any artifact marked as evidence during an investigation. Incident classification and mapping Classifies ingested events into incident types and maps their raw attributes onto incident fields, using incoming and outgoing mappers that can be reused across integration instances. Incident context data Stores command, script and playbook results as a structured JSON context per incident that passes data between tasks and populates layouts. Incident deduplication Identifies duplicate incidents manually from the incidents table or automatically through pre-process rules and playbook scripts. Incident export to cloud storage Exports incidents as JSON, with context, investigation data, War Room entries and optional attachments, to Amazon S3, S3-compatible buckets or Azure Blob, on demand or on a retention-driven schedule. Incident field scripts Attaches scripts to incident fields to compute displayed values dynamically or to act when a field value changes, written in JavaScript, Python or PowerShell. Incident fields Creates and edits custom incident fields of varying types that accept ingested data, appear in layouts and are populated through classification and mapping. Incident layouts Customizes the tabs, order, contents, permissions and presentation of the layout shown for each incident type, including script-driven sections. Incident mirroring Synchronizes incident fields, comments and attachments in both directions between Cortex XSOAR and a third-party ticketing or case system. Incident types Defines incident types that determine which fields, layout, playbook and SLA apply to an incident, including duplicating and detaching types delivered by content packs. Inline field editing controls Controls whether inline edits to values in incidents, indicators and threat intel reports save immediately or require explicit confirmation. Post-processing scripts Runs a script when an incident is closed, so actions such as closing an external ticket or requiring an owner happen before closure completes. Pre-process rules Applies rules to ingested incidents after classification but before creation to drop, deduplicate, link or close them, with the option to test a rule against existing incidents.
Engines and remote execution Container hardening and image security Applies engine configuration keys that limit container CPU, memory, process and file-descriptor use, and documents how Cortex XSOAR sources and builds its container images. Container runtime for integrations and scripts Runs Python and PowerShell integrations and scripts in Docker or Podman containers on the engine, including rootless Podman, relocatable container storage and Docker-to-Podman migration. Engine certificates Replaces the engine's self-signed certificate with customer-supplied certificates and adds custom trusted CA bundles so containerized integrations validate TLS. Engine configuration Sets engine properties through the d1.conf file or the UI, including log level, log file locations, container keys and proxy behaviour. Engine installation Installs engines on Linux using shell, RPM or DEB installers, with documented CPU, memory, disk and operating-system package requirements per environment size. Engine management Lists engines and load-balancing groups with host, status and connection detail, and supports creating, upgrading and removing engines from the Engines page. Engine network proxying Routes engine traffic through a web proxy, allows bypassing the proxy for tenant calls, and supports fronting the engine with an NGINX reverse proxy on a DMZ subnet. Engine selection for execution Selects a specific engine or load-balancing group to run an integration instance or a script, and targets one per command with the using argument. Engine troubleshooting Downloads engine d1.log files from the Engines page and documents the common engine, container-runtime and integration failure modes. Load-balancing groups Groups multiple engines so integration instances and scripts distribute their execution workload across them. Remote execution engines Runs a proxy application on a remote customer machine so playbooks, scripts, commands and integrations can reach on-premises resources and return results to the hosted tenant.
Onboarding and tenant deployment Data encryption Encrypts all traffic between platform components and to third-party tools with TLS, and encrypts stored data at rest, including passwords and API keys. Development and production tenants Supports one production tenant plus one or more development tenants for building and testing content, with user licensing limits not enforced on development tenants. High availability and backup Runs every tenant with data redundancy across two zones in the selected host region and relies on Palo Alto-managed backups and tested restores rather than customer-run backup jobs. License management Applies per-user yearly or multi-year licenses updated automatically in the backend, counts a user as active on login, and adds incident retention licenses in monthly increments. Managed tenant health monitoring Surfaces each tenant's alerts on a centralized dashboard that the Cortex team monitors continuously and acts on for platform and cloud-infrastructure issues. Managed upgrades Upgrades tenants automatically on a roughly quarterly major release cadence across four staggered upgrade groups, with maintenance releases and weekly hotfixes. Network access requirements Publishes the destination URLs and IP ranges a customer firewall must allow for tenant communication, storage, engine outbound traffic, in-app help, email notification and login. Service limits Documents the tenant's supported ceilings for production and development tenants, indicator volume, feed count and related capacity, split by whether a Threat Intel Management license is held. Supported host regions Chooses the Americas, EMEA or JPAC host region at activation, which fixes where logs and ingested data are stored and which Cortex services are available. Tenant activation Activates a Cortex XSOAR tenant from Cortex Gateway using the activation email and a Customer Support Portal account, repeated for each tenant a customer runs. Tenant offboarding Removes access two days after a license expires and offboards the tenant thirty days after expiry, deleting its data with no long-term snapshots retained.
Multi-tenant management Child tenant management Creates, views and deletes child tenants from Cortex Gateway, subject to license, including pairing a main tenant with child tenants in other geographic regions. Content sync to child tenants Pushes content authored on the main tenant, or arriving through a remote repository, down to child tenants, adding, overriding or removing items as configured. Cross-tenant command execution Batch-runs a command from the main tenant against incidents in several child tenants, executing it locally on each and writing results to that tenant's War Room. Cross-tenant incident view Shows incidents from every child tenant on the main tenant's Incidents page, with actions taken centrally or by pivoting into the owning tenant. Cross-tenant indicator view Shows indicators and threat intel reports from every child tenant on the main tenant's Threat Intel page, with pivoting into the owning tenant to investigate. Incident retention license allocation Allocates purchased incident retention licenses to new or existing child tenants from Cortex Gateway, each license adding a month to that tenant's retention. Main tenant users in investigations Adds main tenant users to a child tenant's investigation so central analysts can work a case alongside the tenant's own team. Multi-tenant deployment Runs a main tenant alongside child tenants that each get separate compute, storage and database, for MSSPs and enterprises needing strict data segregation with shared practices. Multi-tenant engines Creates engines from the main tenant and propagates them to child tenants, where each child connects back through the main tenant with its own encryption handshake. Propagation labels Tags child tenants and content items with labels so only the matching playbooks, scripts, integrations, fields, types and layouts sync to each tenant.
Marketplace and content management CI/CD content pipeline Builds content from a customer's own private repository using external CI tooling, with version control, code review, linting, validation and automated testing before deployment. Content pack contributions Packages content created in the tenant into a content pack and submits or resubmits it for Palo Alto Networks review and publication to Marketplace. Content pack lifecycle Installs, updates, deletes and reverts content packs, showing pack contents, version, author, support status and required and optional dependencies before installation. Content pack update notifications Sends daily notifications about available content pack updates, enabled per pack and delivered through each user's chosen channel. Content versioning Saves versions of content items in the tenant so revisions can be compared and restored without an external repository. Cortex Marketplace Provides a catalog of content packs contributed by Palo Alto Networks, partners, MSSPs and customers, browsable inside the tenant or on the public Marketplace site. Deployment wizard Walks an administrator through configuring the fetching integrations, incident mapping and main playbook for a supported use-case content pack. Development to production content push Pushes content from a development tenant to production, where an administrator chooses whether to install it and how to resolve conflicts with local content. Remote content repository Backs content development with either the built-in repository, which needs no Git knowledge, or a private Git repository such as GitHub, GitLab or Bitbucket.
Integrations and credentials Credential management Stores usernames, passwords, certificates and SSH keys as reusable credential objects that integration instances reference instead of holding secrets inline. Fetch error notifications Notifies administrators and listed recipients when an integration instance fails to fetch incidents, with the option to consolidate multiple mail-sender instances into one message. Incident fetching Polls a third-party integration instance for events at a configurable interval and turns them into Cortex XSOAR incidents. Integration command permissions Restricts which roles may run each command on an integration instance, so different instances of the same integration can expose different command sets. Integration image selection Changes the container image an integration or script runs, and authenticates the tenant or an engine against a private image registry to pull custom images. Integration instances Configures instances of content-pack integrations that connect Cortex XSOAR to third-party products over REST APIs, webhooks and other transports, one-way or two-way. Integration troubleshooting Tests an integration instance from its configuration screen and downloads a debug log of the resulting requests and errors. Long-running integrations Exposes long-running integrations hosted on the tenant or an engine to third-party software through forwarded HTTPS requests, subject to a per-tenant request rate limit.
Dashboards and reporting Automation ROI widget Estimates the dollar value saved by automated actions across all users and incidents and displays it as the Saved by DBot return-on-investment widget. Custom widgets Creates widgets from a JSON definition or from a JavaScript, Python or PowerShell script, including script-based widgets rendered on demand in the War Room. Dashboards Presents out-of-the-box and user-created dashboards of tenant activity, with a configurable date range and refresh rate, reorderable widgets, and sharing to selected roles. Reports Builds widget-based reports that can be scheduled, emailed to recipients and generated as PDF or CSV, with configurable incident time range, page size and timezone. Widget builder Defines and previews widgets in the Widgets Library without writing code, including widgets saved directly from an incident or indicator query.
Users, roles and authentication Customer Support Portal authentication Authenticates users by default through their Customer Support Portal account, optionally with two-factor authentication, before role or group assignment grants tenant access. Roles and role-based access control Defines predefined and custom roles that set None, View or View/Edit permission per component, plus page access, preset role queries and shift management. SAML single sign-on Authenticates users against any SAML 2.0 identity provider, with documented setup for Microsoft Entra ID and Okta and mapping of provider groups to roles. User groups Assigns roles through nestable user groups, where a user in several groups receives the combined highest level of access. User management Adds and manages tenant users created through the Customer Support Portal or SSO, and shows their roles, groups and activity from the tenant or Cortex Gateway.
Application Security Application Criteria Defines the code-side and cloud-side matching criteria that assign assets to applications automatically, with creation, retrieval and deletion of criteria and a refresh status showing when a criteria set was last evaluated. AppSec Data Sources Connects version control systems, CI/CD platforms and third-party scanner vendors as AppSec data sources using OAuth or personal access tokens, and lists, updates and removes those connections along with their ingestion state. AppSec Policies Defines which AppSec findings become issues and what happens when they do, with policies scoped by condition and scope fields and triggering build, deploy, CI image and registry actions. AppSec Remediations Returns a suggested fix for a finding, opens a pull request applying that fix against the source repository, and reports the status of the triggered fix. AppSec Repositories Lists onboarded source repositories and their scan configuration, and selects which branches are scanned and how often, per repository. AppSec Rules Creates and manages custom detection rules for secrets, infrastructure-as-code and software composition findings, with labels for organizing them and a validation endpoint that checks a rule before it is saved. AppSec SBOM Management Returns the software bill of materials for a single repository or for every repository in an organization. AppSec Scan Management Reports which repositories have never been scanned and returns the periodic branch, pull request and CI scan history with the issues and findings each produced, and reruns a repository scan on demand. ASPM Applications Models a deployed application as a named set of code and cloud assets, listing which assets can be added or removed, applying membership changes, and recording and reverting manual overrides of automatic asset assignment. Cortex CLI Repository Hooks Installs the CLI as a pre-commit hook in a developer's working copy or a pre-receive hook on a self-managed version control server so that secrets, infrastructure-as-code misconfigurations and vulnerable dependencies block a commit or a push before they land. Third-Party AppSec Collector Ingests static analysis results from third-party security tools as SARIF v2.1.0 uploads, parsing them into code findings that policies can elevate to issues.
Identity & Access App Custom Roles and Permissions Creates an app-specific role from granular permissions or by cloning an existing role, then edits or deletes it, which strips the permissions from everyone holding it, and alternatively grants individual permissions directly to selected users on one app instance, optionally saving that set as a reusable role. Console Sign-In and App Launch Signs a user in to the Activation Console with Customer Support Portal credentials, locks the account for 60 minutes after ten failed attempts, presents each activated app as a launchable tile, and refuses sign-in to a user holding no role. Custom Roles Builds a role from individual permissions when the predefined set is too coarse, either from scratch or by cloning a predefined or custom role, and edits or deletes it later, with the role scoped to the tenant service group where it was defined and its name reserved across that branch of the hierarchy. FedRAMP Administrative Hardening Separates Account Administrator from Instance Administrator duties for FedRAMP tenants, isolates an instance administrator from other tenants, restricts Account Administrator permissions to global management keys, and requires another Account Administrator to revoke the role before a holder can be deactivated. Platform Roles & Permissions Lists, creates and deletes tenant roles built from the available permission configurations, distinguishing custom roles from predefined ones and recording whether a role was defined in the Gateway or in the tenant. Platform User Groups Creates, lists, edits and deletes tenant user groups, including groups sourced from a directory, as the recommended way to carry a role to many users. Platform Users Lists tenant users, returns a single user's details and edits the roles and attributes attached to them. Predefined Roles Ships a catalog of built-in roles that can be assigned as they are or copied and narrowed, with each component set to no access, view, or view and edit, and higher roles nesting the permissions of lower ones. Predefined Roles and Permissions Assigns built-in roles such as Superuser, Multitenant Superuser, IAM Administrator and View Only Administrator to users or service accounts, scoped either to all apps and services or to one named app, combining as a union across scopes, inherited by child tenants, and assignable one at a time or in batch. Support Account Role Administration Defines the fixed role tiers governing an app in the console's support account view, being Account Administrator, App Administrator, Instance Administrator and No Role, and grants them to up to 100 selected users at the account, all-instances or single-instance level, blocking assignment on conflicting privileges. Tenant User Access Management Grants and revokes a user's access at a chosen node of the tenant hierarchy, with access inherited by every child tenant, and blocks removal of the last user on a tenant, of inherited access, which must be removed at the parent, and of federated users, who must be removed at the identity provider.
Licensing & Entitlement AppSec Billing Contributors Reports which repositories and contributors count toward Application Security consumption for a billing period. Enterprise License Agreement Activation Activates an enterprise license agreement add-on onto a tenant service group from either the Activation Console or the Customer Support Portal, creating the product tenant URL subdomain and choosing the firewall deployment region, then applies the agreement to firewalls through device associations. License Allocation Across Tenants Directs a claimed subscription to a recipient tenant and pins its data region, then increases or decreases that allocation later, returning reduced quantity to the pool, enforcing minimum and increment rules, adjusting dependent add-ons, and blocking commits until the configuration matches the reduced entitlement. Product Deactivation Deactivates a single product or every product in a tenant so the tenant can be reused and the license reallocated, removing dependent add-ons with it, emailing superusers at each stage, and allowing cancellation within a 24-hour grace period. Product License Activation Claims a purchased entitlement from an emailed activation link into a tenant by choosing the Customer Support Account, target tenant and deployment region and accepting terms, creating a default tenant on first activation with the activating user as its Superuser, and sending a Request Access message when the requester lacks access. Service Provider Backbone Licensing Claims one Service Provider Backbone license per root tenant so a provider can route Prisma Access egress over carrier backbones such as BT, Orange or AT&T and let subtenants use it, and edits it afterward to add or remove a backbone and to exclude named regions, which fall back to public-cloud backbones. Software NGFW Credits Licensing Activates credit-based software firewall entitlements against a deployment profile created in the Customer Support Portal, covering Panorama-managed and Strata Cloud Manager-managed VM-Series and their bundled cloud subscriptions, and shows the deployment profiles consuming the credits alongside the licensed products. Subscription and Add-On Management Lists a tenant's purchased and trial entitlements with activation status, allocated versus total quantity, expiration date, entitlement group ID and available add-ons, searchable and filterable by those attributes, and marks subscriptions expiring within thirty days and those already expired. Subscription Renewal and Conversion Extends or renews an expiring subscription and converts a trial or evaluation entitlement to a production license from an emailed activation link, onto either the existing tenant or a new one, replacing the trial license and carrying forward the support account and region. Tenant License Information Returns a tenant's purchased entitlements, covering agent counts, ingestion volume and per-product license tiers, across the Cortex products activated on it.
Product & App Administration Agent Configuration Settings Reads and updates the tenant-wide agent settings governing content update management, agent status timeouts, automatic upgrades, sandbox analysis submission, informative behavioral-threat issues, log collection, action expiry, critical environment versions, advanced analysis and endpoint record cleanup. App Instance Activation Activates an app instance from the Activation Console's support account view, which auto-provisions it and adds its tile on completion, and deactivates it, deleting the instance along with the internal Cortex resources and data-access permissions it held. Device Associations Attaches firewalls and Panorama appliances from the Customer Support Account to a tenant service group, associates activated products with those devices and removes either association, filtering selectable devices by hardware model and license type so incompatible production, evaluation, lab, NFR and trial devices never appear. Endpoint Management Lists and deletes endpoints, returns the policy and security profiles applied to each, sets an endpoint alias, creates and assigns or removes tags, reports policy violations, upgrades agents and starts forensic triage from the endpoint record. Partner App Activation Lists third-party vendor apps built on Cortex data and activates them alongside first-party apps, requiring registration with the partner that owns and hosts the service and an explicit grant of access to your data. Product Instance Management Views, launches, renames, deletes and shares activated product instances with child tenants from Products in a single-tenant deployment or Tenant Management in a multitenant one, showing activation status, deployment profiles and contract serial numbers, and copies product information for a support case. Security Policy Rule Targeting Restricts a container-scoped Strata Cloud Manager security policy rule to a named list of NGFW serial numbers at push time, the Strata Cloud Manager equivalent of Panorama's existing rule-targeting; migrated Panorama device-group rule targets convert to this format and land disabled for review. Tenant and Support Account Views Splits the Activation Console into a tenant view listing app instances that have moved to tenant service groups and a support account view holding instances that are not yet compatible, and toggles between them while instances migrate on a rolling basis. Tenant System Information Reports a tenant's health check result and its identifying information for use by automation. Tenant Telemetry Settings Sets the telemetry tier at the tenant level, which every device associated with that tenant inherits, defaulting to enabled at the full tier when a product is activated.
Vulnerability Management Affected Software Lookup Returns the software packages and versions a given vulnerability affects. Asset SBOM Returns the software bill of materials recorded for a specified asset. Asset Scan Coverage Reports which assets are covered by scanning and which are not, as a filtered list or as a histogram. Bring Your Own Scanner Imports assets and vulnerability findings produced by an external scanner into vulnerability management as an asynchronous job, with status polling. Network Vulnerability Scans Creates scan definitions from templates, launches scan runs against an asset group, reports run status, and pauses, resumes or aborts a scan already in flight. Vulnerability Findings Returns per-asset CVE finding records by paginated filtered search or by platform identifier. Vulnerability Findings Export Exports the full vulnerability findings set in bulk as a snapshot backed by XQL. Vulnerability Management Policies Defines the policies that decide which vulnerabilities matter on which assets and what happens when one is found, and triggers an on-demand scan of a named asset.
Data Collection & Forwarding Broker Log Bundles Streams a Broker VM's diagnostic log bundle directly from the appliance, or requests collection from the tenant side asynchronously, polls the request status and downloads the most recent bundle. Broker VM Appliance Setup Bootstraps a Broker VM from its own appliance API by replacing the factory-default admin password, issuing a short-lived bearer token, and activating the appliance against the Cortex tenant. Broker VM Collection Applets Activates, configures and deactivates the collection applets a Broker VM runs, covering syslog, Kafka, database query, FTP, shared folder, CSV, Windows Event Collector, NetFlow, network mapping and local agent proxy, and issues the client certificate or triggers the immediate scan an applet needs. Broker VM Fleet Management Lists the Broker VMs registered to a tenant and edits, reboots, shuts down, upgrades or removes them, generates the registration token a new broker needs, and returns a signed download URL for an install image in OVA, QCOW2, VHD, Azure VHD or VMDK form. Broker VM Network Configuration Configures or disables a Broker VM's physical network interfaces and sets its container internal subnet, outbound HTTP or SOCKS proxy, NTP servers, serving SSL certificate and trusted CA bundle. External Application Integrations Registers the outbound destinations a tenant sends data to, covering Splunk, Amazon SQS, Amazon S3, syslog and webhook targets, and creates, reads, replaces, enables and deletes them with credentials masked on read. Logging & Collection Service Device Management Lists the firewalls forwarding logs into the Cloud Logging and Collection Service and disconnects them in bulk.
Detection & Response Analytics Prevalence Lookups Reports how common a command line, domain, file hash, IP address, process or registry key is across the environment, as context for triaging a detection. Behavioral Indicators of Compromise Creates, updates, retrieves and deletes behavioral indicator rules that match on process, file, network and registry activity. Detection Rules Creates, updates, retrieves and deletes detection rules whose XQL queries identify misconfigurations, compliance violations and risks across cloud resources, carrying their own compliance metadata and asset scope. Indicators of Compromise Adds, updates, retrieves and deletes atomic indicators such as hashes, domains and addresses that the platform matches ingested data against. Prevention Exception Rules Defines the exceptions that stop endpoint prevention and process injection acting on a named process or module, retrieved with filtering and pagination and added, edited or disabled per rule. User & Host Risk Scoring Returns the risk score computed for a named user or host and the ranked lists of the riskiest users and hosts in the tenant.
Posture & Compliance Asset Compliance Results Returns the compliance standards and controls a single asset passes or fails, with filtering, sorting and pagination over the result set. CIEM Access Analysis Answers which resources a given identity can reach, which access a permission-granting entity confers, and which identities can reach a given resource, across onboarded cloud accounts. CIEM Least Privilege Recommendations Recommends a narrowed permission set for a cloud identity by comparing granted entitlements against observed use, returning the suggested policy snippet and a verdict per permission. Compliance Reports Returns the archived reports produced by past compliance assessments. Compliance Standard Import & Export Moves compliance standards between tenants as ZIP archives through asynchronous import and export jobs, with status polling and a download step for the generated archive.
Cloud Onboarding Cloud Account Management Lists the individual cloud accounts contained in an onboarded instance and enables or disables coverage per account. Cloud Instance Onboarding Onboards an AWS, Azure, GCP, OCI or Alibaba Cloud estate by generating a deployment template, then retrieves, edits, enables, disables or deletes the resulting instance, with commercial or government partitions, account, organization-unit or tenant scope, managed or outpost scan mode, region selection, custom resource tags and audit log collection. Container Registry Onboarding Connects self-hosted or cloud-hosted container registries from vendors including Docker Hub, Harbor, JFrog, Sonatype and OpenShift, choosing whether scanning runs in the cloud, through an outpost or through a broker, and manages those connectors over their lifetime. Outpost Management Creates and edits the templates that place a scan environment inside the customer's own cloud, and lists the outposts already deployed, so that scanning runs without data leaving that estate.
Data Query & Analytics XQL Function Library Provides the built-in functions XQL queries call, covering string and array manipulation, math and bitwise operations, type conversion, hashing, JSON extraction, IP address handling, timestamp parsing and formatting, and aggregate and windowed comparison functions. XQL Query Execution Starts an XQL query, retrieves its results by page or as a stream, and reports the remaining query quota for the tenant. XQL Query Library Saves named, tagged XQL queries that can be listed, updated and deleted, and referenced from other queries. XQL User Datasets Defines user datasets that XQL can query, and lists or deletes the ones already created.
Federated Identity Authentication Settings Configures SAML single sign-on per email domain from an identity provider metadata URL or from an explicit SSO URL, issuer and certificate, maps IdP attributes onto user fields, returns the service provider metadata, and lists or removes the settings for a domain. Identity Federation and SAML SSO Federates a DNS-verified enterprise domain to a third-party SAML identity provider such as Okta, Azure, Ping, OneLogin, SecureAuth, Google Workspace or AD FS, configured manually, by metadata upload, by profile URL or by cloning, with downloadable service provider metadata and owner delegation, deactivation and deletion. SAML Authorization Mapping Sources authorization from the identity provider instead of the platform, either by mapping a federation onto selected tenants so the assertion carries an accessPolicies attribute of PAN Resource Names encoding role, tenant service group, app and resource scope, or by mapping the provider's own group attribute values to roles. SCIM User and Group Provisioning Switches the authorization source to SCIM so user and group lifecycle is driven by the third-party identity provider against the /iam/v1/scim endpoint, after which no access change is permitted in the platform, with connectors for SailPoint and Oracle Cloud Infrastructure identity domains.
Tenant Lifecycle Egress Configurations Governs which outbound destinations a tenant may reach by having an administrator submit a per-flow path for a named service, approving it into the tenant's egress table and removing it later, with removals retained for audit. Tenant Activation Activates a Cortex XDR, XSIAM or XSOAR tenant from the Gateway against the serials on a support account, including child tenants for managed service providers, and then hands the administrator into the new tenant. Tenant Hierarchy Management Adds, edits and deletes tenants in a nested hierarchy of tenant service groups, converting a single-tenant deployment to multitenant when the first child is added, refusing deletion of a tenant that still holds products, child tenants or allocated licenses, and enforcing depth and size limits on the hierarchy. Tenant Move and Acquisition Moves an internal tenant to a different parent within the hierarchy and acquires a root-level external tenant from outside it through an emailed acquisition key that an administrator of the target approves, listing the inherited and custom roles that would be lost before the move is confirmed.
Automation & Orchestration Cortex Commands Provides a shared command library callable from playbooks and the War Room across cases, issues, timelines, endpoints, files, assets, indicators, scans, AppSec policies, users and API keys, with per-command arguments and outputs and availability set by the tenant's product license. MCP Integration Framework Lets a contributor build an integration that bridges Cortex agentic AI to a third-party MCP server, using a shared API module for protocol handling, token, bearer, OAuth authorization-code and dynamic-client-registration authentication, and the required test, list-tools and call-tool commands, so discovered tools become agentic actions automatically. Remote Script Execution Runs a stored script or an ad hoc code snippet on selected endpoints, then reports execution status and returns the results and any files the run produced.
Case & Issue Management Alert Notification Rules Routes matching alerts to a forwarding destination through filter-based rules that can be created, edited, enabled, disabled and deleted. Case Timeline & War Room Reads and appends the chronological record of what happened on a case, covering both timeline records with their own filter fields and free-form War Room entries. Managed Services Reporting Lets a Managed Threat Hunting or Managed Detection and Response child tenant retrieve the reports written for it by source, incident or status, comment on them, change their status and reassign them.
Platform Access Cortex API Platform Publishes one REST API surface per Cortex product behind a shared tenant FQDN and header authentication scheme, with a getting-started path, a first-call walkthrough and per-release API change notes. Platform API Keys Issues Standard or Advanced API keys paired with a key ID for authenticating API and CLI calls, and lets an administrator create a custom role carrying only the permission a given automation needs before generating the key against it. Service Accounts Creates non-human identities for API automation, issuing a client ID and one-time client secret that combine with the tenant service group ID to obtain an OAuth 2.0 access token under the client-credentials grant, with secret reset, detail editing and removal, and inheritance by child tenants.
Asset Management Data Security Posture Inventory Returns the inventory of sensitive data discovered across cloud stores, broken down by data pattern, by field and by file.
Operational Visibility Activation Console Dashboard Summarizes the last 30 days of network activity across whichever apps are active, with widgets that drill into Explore or the underlying app, blending Prisma Access and SaaS Security data to show unsanctioned SaaS usage, threats found, externally and publicly shared files, and a comparison with industry peers.
Data loss prevention applied inline across network and SaaS traffic.
Detection Methods Archive File Inspection Extracts and inspects the contents of 7z, bzip2, cab, gzip, iso, rar, tar and zip archives up to 8 nesting levels, 1024 sub-files and 125 MB of extracted text, and matches a predefined Archive Scan Threshold Exceeded pattern when a forwarded archive exceeds those limits. Contextual Secrets Inspection Detects passwords shared in chat by pairing a request message with a reply sent within 60 minutes in the same channel or thread and evaluating the reply against credential detection patterns. Custom Document Types Detects an organization's own documents by fingerprinting uploaded files with indexed document matching or training a supervised classifier on positive and negative document sets, then scoring inspected files by content overlap and letting administrators test candidate documents against the type. Custom Regex Data Patterns Defines sensitive content with basic or weighted regular expressions built in a query builder, scored against a weight threshold, and refined with proximity keywords and a configurable proximity distance that sets the detection confidence level. Data Dictionaries Matches curated keyword and phrase lists by exact literal string, uploaded per tenant with category, region and case-sensitivity settings and editable in place, alongside a shipped set of dictionaries for medical, financial, professional, government and social terminology. Data Pattern Archive and Restore Archives custom data patterns that are no longer in use after confirming they are unreferenced, and restores them later with an optional rename that propagates to historical incidents. Available in Strata Cloud Manager but not Panorama, which the published platform matrix records alongside create, read, update and delete support. Exact Data Matching Matches inspected traffic against specific records from a customer database by hashing and encrypting CSV or TSV datasets locally with a CLI application before upload, indexing them in a regional bucket, and evaluating primary and secondary field combinations within a configurable proximity distance. CSVs take comma or pipe delimiters; CLI 6.2 adds CJK and Thai datasets. False Positive Reporting Submits selected snippets from an incident back to Palo Alto Networks as a false positive against a predefined machine-learning data pattern so the detection models are retrained, retaining the shared snippets for 90 days. File Property Data Patterns Matches on file metadata rather than content — Microsoft Purview and AIP sensitivity labels, asset name, author, company, comments, copyright, description, keywords, title, publisher, file extension, file type signature, file size, SHA-256, text watermarks, and extended or custom document properties. Non-File Traffic Inspection Inspects sensitive data posted outside of file uploads — web forms, collaboration and SaaS app content, GenAI prompts and WebSocket persistent streams — subject to configurable minimum and maximum payload sizes. Optical Character Recognition Finds sensitive data inside images by extracting text for regex evaluation and by inspecting the image directly with machine-learning patterns, across images embedded in supported file types including handwritten and scanned content, and in Endpoint DLP data-at-rest scanning on managed endpoints. Predefined Data Pattern Library Ships a maintained catalog of regex and machine-learning data patterns for identifiers such as national IDs, bank and IBAN numbers, credit cards, driver licenses, passports, health identifiers, secret keys and source code, tagged by relevant geography and recommended business category, and marked per pattern for ML augmentation and local detection support. Predefined Document Types Classifies common sensitive document formats with shipped machine-learning classifiers covering bank statements and bankruptcy filings, tax and financial forms, legal agreements and filings, and dozens of programming languages. Predefined Pattern Customization Clones a predefined regex data pattern so an administrator can add proximity keywords and include or exclude match criteria based on how a detected value starts or ends. Structured Data Clustering Raises detections in spreadsheets and CSV files to high confidence when repeated values of the same type cluster in a row or column, optionally predicting a missing header row only when a column meets a configurable data uniformity threshold. Supported File Type Coverage Parses and inspects a published catalog of document, spreadsheet, presentation, image, source code, archive and email file formats, identifying a file by its true file type signature rather than its extension so a renamed file is still inspected.
Data Profiles Data Profile Archive and Restore Archives custom data profiles once they are removed from every referencing policy rule and parent profile, listing the blocking references, and restores archived profiles to active status under a unique name. Data Profile Sync Conflict Resolution Detects configuration drift between data filtering profiles held by the Panorama plugin and data profiles in Strata Cloud Manager, shows the differing local and remote values, and applies the chosen side on the next commit. Data Profile Testing Runs a data profile against an uploaded sample file before deployment and reports matched and unmatched patterns with high, medium and low confidence occurrence counts and snippets. Data Profiles Combines data patterns, dictionaries, document types and EDM datasets into the match criteria a policy evaluates, using AND, OR and NOT operators, nested criteria groups, occurrence conditions with counts and unique-occurrence counting, confidence levels, and separate primary and secondary rules for alerted and blocked traffic. Granular Data Profiles Groups multiple data profiles under one Security policy rule while keeping separate inspection settings and response actions, file types, directions and log severities for each child profile. Local Detection Coverage Marks a data profile as cloud-only or cloud-and-local, filtering the selectable detection methods to those the browser can evaluate on the endpoint and converting an existing profile by stripping cloud-assisted criteria. Match Scope Selection Selects which part of the payload a profile inspects — file or message content including watermarks, the file name, free-text file metadata fields, and the URL string. Nested Data Profiles Consolidates multiple data profiles into a single profile that carries one set of rule settings, so one Security policy rule can cover match criteria that would otherwise need several rules. Predefined Data Profiles Provides ready-to-use profiles assembled for common regulatory and protection use cases including HIPAA, GDPR, CCPA, GLBA, SOX, PIPEDA, POPIA, PHIPA, the Australian Privacy Act, intellectual property, secrets and credentials, and profanity or self-harm content.
Ecosystem Integrations Cloud Identity Engine Integration Resolves directory identity for policy scoping and incident context, supplying user names, emails, groups, department, location and manager from the connected identity provider. End User Alerting with Cortex XSOAR Uses a Cortex XSOAR playbook to message the user whose upload was blocked over Slack, Microsoft Teams or email, ask them to confirm whether the file is sensitive, grant a time-limited self-service exemption, and keep a per-file response history that persists across later uploads. Gmail Integration Routes outbound Google Workspace mail through a regional host route and SMTP relay entry with enforced TLS, acts on verdicts through content compliance transport rules for quarantine, rejection and encryption, and installs a Marketplace app scoped to chosen users so administrators can download inspected messages. ICAP Forwarding Sends inspected files on to an on-premises third-party DLP server over ICAP or ICAPS with an uploaded CA certificate and a required connectivity test, while the service continues its own inspection and enforcement. NGFW and Prisma Access tenants forward once per unique file hash against a 90-day inspection cache; SaaS Security forwards every file. Microsoft Exchange Online Integration Routes outbound Exchange Online mail through the service with an outbound and inbound connector over enforced TLS, and acts on returned verdicts through transport rules for hosted quarantine, administrator approval, manager approval, message encryption and rejection. Proofpoint Encryption Integration Forwards messages that receive an encrypt verdict to a customer Proofpoint gateway through a dedicated connector or route with a signalling header, instead of using the mail platform's native encryption. SaaS Security Policy Recommendation Applies a data profile to SaaS application traffic by attaching it to a SaaS Security policy rule recommendation for discovered applications. Supported Application Coverage Recognizes named SaaS, web and generative AI applications through App-ID and records for each one which inspection modes apply — file upload, file download, non-file traffic and large file inspection — with the catalog extended on a rolling basis through content updates. Syslog Forwarding Forwards incident and audit records to a third-party SIEM, SOAR or ticketing system in LEEF or CEF over UDP or TCP through log forwarding profiles scoped by channel and region, buffering up to 30 days of records while the connection is down and alerting a named recipient on loss and restoration.
Incident Management & Logging Audit and Push Logs Records who created, read, updated or deleted each configuration object and who viewed an incident snippet, with a field-level before and after diff, alongside push logs showing each endpoint policy distribution and its outcome. Automatic Incident Case Management Applies assignee, status, priority and notes automatically to new incidents matching a rule scoped by action, severity, channel, data profile, data pattern, region, asset or URL domain, with a preview of recent matching incidents. Email Processing Logs Captures records of every email the smart host receives — scan results, policy decisions, delivery statuses and deferred attempts — and lets admins retry or purge emails stuck in the outbound deferred queue. Incident Case Management Tracks an incident through assignment, priority, status and investigative notes, individually or in bulk across selected incidents, with an audit history of every step. Incident Details and Snippets Shows the full context of a single incident — severity, channel, action, asset, direction, risk score, user and session attributes, matched exception rule — together with the matched data patterns, their total and unique occurrence counts by confidence, and masked snippets of the detected values. Inspection Failure Reporting Writes a reason code to the file or data filtering log whenever traffic matched a profile but could not be inspected, distinguishing size and latency limits, resource exhaustion on the enforcement point, corrupted or password-protected files, unsupported protocols, missing profiles and rate limiting. Service Health and Telemetry Reports the real-time operational status of the DLP cloud service as operational, degraded, unavailable or in planned maintenance, with a last-updated timestamp. Unified Incident Dashboard Consolidates incidents from every enforcement channel into one list with summary, top-incident and violations widgets and a distribution-over-time graph, filtered by time, action, channel, severity, priority, status, data profile, detection type, region, asset, source and URL domain or by SQL-like advanced filter expressions, and exportable to CSV.
Policy & Enforcement Configuration Push and Synchronization Propagates configuration changes to enforcement points through a Strata Cloud Manager push scoped to all administrators or a Panorama full or partial commit and push that must include the reserved plugin administrator to keep both management planes in sync. DLP Exception Rules Overrides a rule's action for selected users, groups, applications or URLs within a granular data profile, matching destinations with Ant-style wildcard URL patterns and assigning its own action and log severity. DLP Rules Sets what a data profile match does at the enforcement point — file and non-file match criteria, an include or exclude file type scan mode, traffic direction, an alert or block action, and the log severity of the resulting incident. GenAI App Data Protection Allows generative AI applications while inspecting prompts and uploads to them by targeting the app through App-ID in a Security policy rule or SaaS policy recommendation with non-file inspection enabled. Inspection Exclusion Lists Excludes selected URL categories, external dynamic lists, application filters and application groups from being forwarded for inspection, with a predefined application exclusion filter for commonly exempted apps. Legacy Data Pattern Visibility Re-exposes the pre-existing data patterns and data filtering profiles that the plugin hides on installation so they can still be edited and referenced in Security policy rules. Role-Based Access and Service Accounts Controls administrative access to Enterprise DLP through predefined and custom roles and through service accounts whose client ID and secret authenticate programmatic uploads, with optional AES encryption of those credentials and secret rotation. Security Policy Integration Attaches a data profile to enforcement by adding it to a shared profile group or Panorama profile settings and binding that to a Security policy rule, alongside a companion file blocking profile for unsupported file types.
Data Risk & Discovery Data Asset Explorer Inventories every sensitive file, message and non-file payload detected across enforcement channels in one view, with interactive aggregation by application, data type, asset type, policy action, data profile, channel and user, and per-asset detail covering matches, incidents, matching policies and user activity. Data Risk Dashboard Presents the organization's risk summary, its trend over 7, 30 or 90 days against an industry average, and a drill-down risk breakdown across data profiles, application instances, applications and control points down to the riskiest individual assets. Data Risk Recommendations Surfaces contextual remediation actions ranked by their impact on the organization's risk score, linked to the applications and assets driving each one. Data Risk Scoring Calculates a quantified risk score for each discovered asset and for the organization overall from weighted data, application and user risk factors, using a framework modeled on the NIST Cyber Risk Scoring approach and recalculated every 24 hours. Risk Model Configuration Tunes how risk is calculated by setting the score ranges that define each risk level, the importance weighting of each data, application and user risk factor, and a severity per data profile, each resettable to defaults. Shadow Data Discovery Summarizes unstructured documents at rest in onboarded SaaS applications into machine-generated categories mapped to broader groups that an administrator can reassign or define, scores each file for sensitivity, rescans as the underlying apps are rescanned, and turns a chosen category into a custom document type for enforcement.
Endpoint DLP Data at Rest Scanning Scans configured folder paths on managed Windows and macOS endpoints with the agent's local regex and OCR detection engine, running a full scan then delta scans driven by file system events, re-scanning each file after its verdict expires at 90 days, and queueing incidents while the endpoint is offline. Data in Motion Policy Forwards files moving between an endpoint and a peripheral device for inspection and alerts on or blocks the transfer when sensitive data is found, reusing an existing verdict by file hash and quarantining blocked files locally on macOS for 90 days. Endpoint Agent Deployment and Policy Push Distributes the endpoint agent and its required extensions through mobile device management, enables the Endpoint DLP service on it, and pushes policy rules, peripheral definitions and settings to enrolled endpoints with a recorded push scope. Peripheral Control Policy Allows or blocks endpoint access to USB devices, printers, network shares and desktop apps independently per peripheral type, scoped to selected or excluded users, groups or desktop app peripheral groups, and ordered by evaluation priority. Peripheral Inventory and Groups Registers individual USB devices, printers, network shares and desktop apps (Google Drive and OneDrive, with optional domain-based filtering to target specific corporate account instances) by identifiers such as serial number, vendor and product ID, server address or app type, and collects them into peripheral groups that policy rules act on.
Evidence & Configuration Portability Configuration Export and Import Exports selected objects or the entire tenant configuration as JSON and imports it into another tenant, auto-creating missing dependencies, skipping identical objects, prompting to overwrite same-named objects that differ, and keeping an export history and audit trail. Evidence File Download Retrieves the stored copy of an inspected file, non-file payload or email from the connected storage by its report ID, in its original format for files, plain text for non-file traffic and message format for email. Evidence Storage Writes a copy of traffic that generated an incident to customer-owned SFTP, AWS S3 with optional KMS encryption, or Azure blob storage, as region-specific buckets that keep evidence within a regional boundary or a single all-regions bucket, and emails the connecting administrator every 48 hours while the connection is down. Snippet Storage and Masking Controls whether snippets of matched sensitive values are retained for incident review and whether they display unmasked, partially masked or fully masked, configured separately per enforcement channel. Third-Party DLP Policy Migration Imports exported Symantec DLP policy rules, grades each as compatible, partially compatible or incompatible, lets an administrator strip the unsupported match criteria, and creates equivalent data patterns, data profiles and disabled SaaS Security data asset policy rules.
Licensing & Activation Enforcement Point Support Matrix States which enforcement points — NGFW, Prisma Access, Prisma Browser, Email DLP, Endpoint DLP and SaaS Security — support each detection method and feature, and the license, PAN-OS release and plugin version each one requires. License Options Offers the service as a standalone per-enforcement-point subscription in one, three and five year terms or bundled within the cross-platform CASB, Prisma Access CASB, Data Security, AI Access Security and enterprise license agreements, with Email DLP and Endpoint DLP as add-ons. Panorama Management Plugin Installs on a Panorama management server, optionally across a high-availability pair, to manage the configuration and push it to managed firewalls, creating a reserved credential-less administrator for its changes and exposing CLI commands to provision the tenant, set the cloud mode and reset the plugin. Tenant Activation and Device Association Activates a tenant from an emailed activation link for single-tenant or multi-tenant support accounts, allocates the subscription to a tenant or subtenant in a hierarchy, and associates individual firewalls, virtual firewalls and Prisma Access tenants with the service.
Service Connectivity & Limits Advanced Forwarding Transport Establishes a pool of TLS connections directly from firewall data plane cores to the inline cloud analysis service, with a discovery service that assigns service addresses by geography and a configurable refresh interval and retry count, replacing the single-process legacy transport. Data Transfer Limits and Failure Actions Sets the maximum inspection latency, the minimum and maximum file and non-file payload sizes, and whether the enforcement point allows or blocks traffic when a threshold is exceeded, an inspection error occurs or an endpoint is offline, configured independently for inline, email and each endpoint peripheral type. Regional Failover and Resiliency Monitors the health and speed of dependent services and reroutes inspection traffic to a healthy US region during a regional failure without administrator action, falling back to the tenant's configured allow or block action when no region is reachable. Regional Processing and Residency Directs inspection, incident generation and dataset storage to a chosen regional cloud content server rather than the nearest one so processing stays inside a required jurisdiction, with separate government cloud endpoints for FedRAMP Moderate and High environments.
Email DLP Email DLP Inline Inspection Inspects outbound email subject, body and attachments including nested message files in line before delivery, stamps inspection and verdict headers so an inspected message is not re-scanned, and applies configurable maximum message size and evaluation timeout behavior. Email DLP Policy Rules Evaluates outbound mail against a data profile scoped by sender and recipient domain, group and address conditions and by which email components to evaluate, then monitors, blocks, quarantines, encrypts, or forwards the message for manager or administrator approval, with incident assignment and notification recipients. Email Domain Onboarding Onboards one or more mail domains by proving ownership through a DNS TXT token, registering each domain's relay host and port, and optionally enabling custom routing through an existing mail security chain with a source IP allow list.
End User Coaching End User Exemption Requests Lets a blocked user request an exemption with a stated reason from the notification itself, granting it automatically or routing it to an administrator who approves or denies it from the incident, for a configurable validity period. End User Notification Templates Builds the message shown to a user who triggers an incident, as a dismissable modal or an auto-dismissing toast, with per-event-type titles and bodies, substitution variables for file, app, peripheral, policy and action, and optional localization into the user's device language.
The endpoint agent providing VPN and always-on secure connectivity.
User Authentication Biometric Sign-In Lets the user unlock saved portal and gateway credentials with a fingerprint on Windows, macOS and Android or Face ID on iOS after signing in with a username and password, available only when the administrator saves user credentials behind a trusted fingerprint template. Client Certificate Authentication Authenticates the user or endpoint from a client certificate validated against a certificate profile, selecting the certificate by issuing CA, extended key usage OID and configured store, using shared, per-user or machine certificates, reading the native certificate store on Linux and the login keychain on macOS, and letting the user pick from valid certificates when several are present. Cloud Identity Engine Authentication Authenticates users and maps them to groups through the Cloud Identity Engine using SAML, OIDC or client certificates, with multi-authentication profiles that route users to a method and an option to skip the SSO hub page on Windows. Cookie Authentication Issues an encrypted authentication cookie to the endpoint with independently configured lifetimes for the portal and for individual gateways, so users are not re-prompted until the applicable cookie expires. Credential Forwarding Control Controls per app configuration which portal and which classes of gateway receive forwarded portal credentials and which prompt for their own, so components protecting sensitive resources can demand a separate password or one-time password. External Authentication Services Authenticates users against LDAP, Kerberos, RADIUS or TACACS+ services through a server profile and authentication profile referenced by the portal and each gateway, which may use different profiles from one another. Group Mapping Retrieves user-to-group mappings from LDAP directories on a configurable interval so agent configurations and security policy can be written against groups, with include lists, LDAP-filter custom groups, configurable user and group attributes, and optional fetching of managed device serial numbers. In-App Password Change Prompts the user to set a new password from within the mobile app when the current one has expired or the directory requires a change at next login, for users authenticated against RADIUS with PEAP-MSCHAPv2. Local User Authentication Authenticates GlobalProtect users against accounts held on the firewall itself, without an external identity source. MFA Notifications for Non-Browser Applications Receives UDP authentication prompts sent by gateways when a session matches an authentication policy rule and displays a configurable message with the authentication portal link, accepting prompts only from a trusted gateway list on a configurable port. RADIUS Vendor-Specific Attributes Sends endpoint source IP, operating system, hostname, user domain and app version to the RADIUS server as vendor-specific attributes during authentication, enabled per attribute from the CLI. SAML Authentication Authenticates users against a SAML 2.0 identity provider for portal and gateway access, including deployments where the portal is externally reachable on a non-standard port and a customizable ACS landing page. SAML Browser Selection Chooses in the client authentication configuration whether SAML and Cloud Identity Engine logins run in the system default browser or the app's embedded browser, which uses Microsoft Edge WebView2 on Windows and WKWebView on macOS and supports FIDO2 methods. Saved User Credentials Saves the user’s portal and gateway credentials on the endpoint so on-demand and always-on connections re-establish without a prompt, and clears them on demand when the user signs out of the app or runs the Linux remove-user command. Single Sign-On Reuses the user's operating system login credentials to authenticate to the portal and gateway automatically, and can wrap third-party credential providers so Windows users authenticate through them. Smart Card and PIV Authentication Authenticates users with common access cards and smart cards against a certificate profile holding the issuing root CA, offering a parallel credential profile when the card is unavailable, and reusing the Windows logon smart card PIN for the portal and gateway so the PIN is entered once, with the cached PIN cleared on sign-out or PIN change. strongSwan Client Authentication Extends gateway access to third-party strongSwan IPsec clients on Ubuntu and CentOS using extended authentication with a group name and password, certificate authentication, or a two-factor combination. Two-Factor Authentication Requires users to satisfy two mechanisms before access is granted by combining a certificate profile with an authentication profile, or by pairing credentials with a one-time password delivered through a token service or software token application.
Secure Connectivity Component Certificate Management Issues, imports, exports and renews the CA, portal, gateway, client and machine certificates that GlobalProtect components present to each other, including generating a root CA on the portal to sign gateway certificates and replacing expired third-party certificates. Connect Before Logon Lets the user establish a GlobalProtect connection from the Windows logon screen before signing in, with GlobalProtect acting as a Pre-Login Access Provider credential provider and authenticating by smart card, SAML, or username and password through LDAP, RADIUS or a one-time password, so credentials can be validated against a domain controller reachable only over the tunnel. Connect Methods Sets when the app connects through the portal agent configuration, as user-logon always-on, on-demand user-initiated, pre-logon always-on, or pre-logon then on-demand. FIPS-CC Mode Operation Runs the firewall and app in a FIPS-CC compliant mode that restricts the available cryptographic and configuration surface, including requiring mutual SSL authentication between the portal and a SCEP server. IPsec and IKE Crypto Profiles Restricts and orders the encryption and authentication algorithms the app may use for IPsec and IKEv2 tunnels, with the gateway answering the app's proposal using the first matching algorithm in the profile. IPsec and SSL Tunnel Modes Establishes the VPN tunnel over IPsec, IKEv2 or SSL, attempting IPsec first and falling back to SSL when the IPsec tunnel cannot be built. Post-Quantum Cryptography Negotiates ML-KEM post-quantum key exchange groups such as X25519_MLKEM768 on TLS 1.3 connections between the app and the portal or gateway, at a configurable security level. Pre-Logon Machine Authentication Builds a tunnel authenticated by the endpoint's machine certificate before any user logs in, so startup and domain scripts can run, then renames the tunnel on Windows or rebuilds it on macOS once the user authenticates, including a user-initiated variant started from the logon screen. SCEP Certificate Enrollment Requests server and per-endpoint client certificates from an enterprise PKI over SCEP using a per-component profile that carries the server URL, fixed or dynamic challenge, subject and SAN settings, key parameters and a CA fingerprint check. SSL/TLS Service Profiles Binds a server certificate to a portal or gateway and constrains the SSL/TLS version range and resulting cipher suites for connections between GlobalProtect components, up to a maximum of TLS 1.3. Strict Certificate Validation Enforces from the portal agent configuration that Windows and macOS endpoints connect only to portals and gateways presenting a certificate signed by a trusted CA, without per-device changes. Tunnel Mode Enforcement Restricts the app to a single approved tunnel type through one portal setting, so it stays disconnected rather than falling back when the required IPsec-only or SSL-only tunnel is unavailable.
App Deployment & Management App and Portal Customization Customizes what end users see, including which app tabs and options are available, the welcome and notification messages, and a custom portal landing page in place of the default. App Software Distribution Hosts GlobalProtect app packages on the portal and controls which version Windows and macOS endpoints download and whether upgrades are prompted, transparent or blocked. GlobalProtect for IoT Devices Extends tunnelled access and policy enforcement to headless IoT devices running Android, Raspbian, Ubuntu or Windows IoT Enterprise, authenticating them with client certificates and targeting them with IoT-specific client settings and HIP objects. Linux App and CLI Installs on Fedora, Ubuntu, Debian, CentOS and Red Hat Enterprise Linux from DEB, RPM or TAR packages as a graphical or command-line-only build including ARM variants, and drives connect, disconnect, disable, gateway selection, certificate import, HIP resubmission, credential clearing, log collection and status queries from the CLI, handing off to the default browser for SAML authentication. Mobile App Store Distribution Distributes the mobile app through the Apple App Store for iOS, Google Play for Android and Chromebooks, and the Microsoft Store for Windows UWP endpoints. Mobile Device Management Deployment Deploys the app and its configuration through third-party endpoint management systems including Workspace ONE, Microsoft Intune and Jamf Pro, and lets those systems check devices in for HIP retrieval. Multi-Platform Endpoint Support Runs the app on Windows, macOS, Linux, iOS, Android, Chrome OS and Windows 10 UWP endpoints, with the supported feature set per operating system published in the compatibility matrix. Transparent App Settings Deployment Predeploys app behavior settings to endpoints as Windows registry keys or macOS plist entries, applied at install time or through a system image, for options not delivered by the portal configuration. Windows 365 Cloud PC Deployment Installs and runs the app on Windows 365 Cloud PCs pushed as a Win32 app from Microsoft Intune, with a user-switch tunnel rename timeout and documented exclusions that keep the RDP stream to the Cloud PC outside the tunnel.
Portal & Gateway Infrastructure GlobalProtect Portal Authenticates endpoints on first contact and distributes the client configuration to them, including the list of available gateways, client certificates, app settings and the app software itself, with per-user and per-group configuration matching. Intelligent Portal Selection Selects the best available portal for the app automatically based on real-time network conditions and portal availability, for Always-On, Always-On pre-logon and undefined-portal Connect Before Logon deployments. Interface and Zone Configuration Hosts portals and gateways on Layer 3 or loopback interfaces and terminates VPN tunnels on logical tunnel interfaces placed in dedicated security zones, so remote traffic can be scoped by zone-based policy and User-ID. Internal and External Gateways Terminates endpoint connections and enforces security policy on their traffic, as external gateways that build a VPN tunnel for remote users or internal gateways that authenticate and check posture on the corporate network without a tunnel. Internal Host Detection Determines whether an endpoint is on the internal or external network so the app connects to internal or external gateways accordingly, and re-triggers discovery when a third-party VPN agent establishes its tunnel first. IPv6 Connectivity Supports IPv6 addressing on portal, gateway and tunnel interfaces for both external and internal gateways, and carries IPv6 traffic in the tunnel. Multiple Gateway Selection Selects which of several configured gateways an endpoint connects to using configured priority, gateway load and measured response time, with a TCP-handshake response-time criterion that isolates network latency from endpoint load, and manual-only gateways that are never chosen automatically. Tunnel IP Address Assignment Assigns tunnel IP addresses to connected endpoints from static gateway IP pools or from an enterprise DHCP server via a DHCP server profile, falling back to the static pool on DHCP timeout and supporting dynamic DNS registration of assigned addresses.
Traffic Policy Enforcement App Disable Restrictions Controls whether users may disconnect or disable the app at all, and for how long and how many times, optionally requiring them to state or select a reason, enter an administrator-issued passcode, or exchange a ticket request number with the help desk for a ticket number first. Captive Portal Handling Detects a captive portal on the joined network and opens its login page in a GlobalProtect-spawned embedded browser on Windows or the native captive network assistant on macOS, so authentication completes without disabling connection enforcement, and closes the browser automatically once login succeeds. Consistent User-ID Enforcement Keeps User-ID mappings and HIP-based policy consistent for a user working remotely or on the corporate network by authenticating to the external gateway and internal gateways simultaneously and submitting HIP reports to both. Endpoint Traffic Policy Enforcement Blocks inbound connections arriving outside the tunnel and stops applications from binding directly to the physical adapter or users from editing the routing table to bypass the tunnel, scoped to TCP/UDP matching the tunnel address family, all TCP/UDP, or all protocols. Enforce GlobalProtect for Network Access Blocks all endpoint traffic until a tunnel to a gateway is established, so traffic cannot reach the internet through a proxy or direct path without inspection, with IP and FQDN exception entries and configurable grace and exception timeouts. No Direct Access to Local Network Prevents a connected endpoint from reaching local subnet resources and proxies directly, dropping local traffic on the physical adapter unless it matches a configured split tunnel exclusion. System Extension Tamper Protection Marks the macOS GlobalProtect system extensions as non-removable through mobile device management so end users cannot disable the extensions that split tunneling, split DNS and traffic enforcement depend on.
Endpoint Posture Endpoint Quarantine Adds a compromised, lost or stolen endpoint to a quarantine list that blocks users from logging in from that device and prevents it from establishing VPN connections. HIP Checks and Policy Enforcement Collects host data from the endpoint, generates a Host Information Profile report at the gateway, and matches it against HIP objects and profiles used as conditions in security policy rules to allow or deny access by device state. HIP Patch Exceptions Excludes named security patches from the endpoint's HIP report for a specified duration or permanently, so frequently updated patches do not fail the HIP check. HIP Process Remediation Runs a remediation script on the endpoint when a HIP process check fails and resubmits the HIP report immediately rather than waiting for the next hourly check, rerunning the script up to a configured retry count within a configured timeout. HIP Report Redistribution Redistributes HIP reports between firewalls and gateways acting as redistribution agents, clients and collectors so posture data is available where policy is enforced. Managed Device Identification by Serial Number Identifies whether a connecting endpoint is corporate-managed by matching its serial number against serials bound to machine accounts and prefetched from the directory server, and enforces HIP-based policy on that basis.
End-User App Experience App Connection Controls Lets the end user connect, disconnect, refresh the connection, add, edit and delete saved portals and switch between them, and change the gateway or star one as a preferred gateway that is used automatically on later connections, subject to what the agent configuration permits. App Settings Panel Gives the end user a settings panel showing the connected gateway with its IP address, location, session uptime, tunnel and authentication status and any proxy in use when the administrator enables the advanced view, plus the endpoint’s Host Information Profile with a manual resubmit and per-gateway submission detail, sign-out, and the installed version with a check for updates. Connection Status and Notifications Shows the user the current connection state through the tray icon and status panel, including pre-logon internal, connected or not-connected status on the Windows logon screen, traffic blocking notifications while enforcement is active, a welcome page on successful login, and a notifications list carrying administrator messages and a login-lifetime expiry warning that offers to extend the session. Report an Issue Lets the end user submit a problem report from the app on each supported platform, uploading troubleshooting logs and optional end-to-end diagnostic test results to the administrator’s Strata Logging Service instance rather than sending files by hand. Reveal Password on Windows Logon Screen Displays the typed password in plain text behind a reveal icon on the Windows logon and change-password screens, alongside the GlobalProtect connection status and gateway, enabled through a registry key.
Monitoring & Troubleshooting App Log Collection Collects GlobalProtect app logs from an endpoint centrally through Panorama or Strata Logging Service for troubleshooting, with the user able to trigger collection and raise the logging level to debug or dump from the app’s Troubleshooting tab, without having to send files. App Log Retention Control Sets how many rotating 5 MB log files each GlobalProtect process keeps on Windows and macOS endpoints, from 2 to 20, through a registry key or plist value that survives app upgrades. Autonomous DEM Endpoint Agent Installs, updates or removes the Autonomous DEM endpoint agent alongside the app from the portal configuration and runs user experience tests from the endpoint, optionally letting the user turn the tests on or off, while heartbeat alerts continue to be forwarded even when GlobalProtect is disconnected. GlobalProtect Logs and Monitoring Records GlobalProtect connection and system events for querying, lists currently connected remote users per gateway, and lets administrators recover a client's pre-tunnel public IP by filtering traffic logs or portal-prelogin system log events.
Clientless Access Clientless VPN Application Publishing Defines clientless applications and application groups and maps them to users and user groups, presenting each user a landing page of the applications they may launch and optionally a URL bar for unpublished corporate applications. Clientless VPN Session Security Constrains clientless sessions through TLS version, key exchange, encryption and authentication algorithm settings for connections to published applications, blocking actions for expired, untrusted or unverifiable server certificates, and login lifetime, inactivity timeout and concurrent user limits. Clientless VPN Web Application Access Serves published enterprise web applications to a browser through the portal acting as a reverse proxy that rewrites returned pages and URLs, with a rewrite exclude domain list and optional upstream proxy servers per domain set.
Traffic Steering Proxy-Aware Forwarding Sends endpoint traffic through an explicit proxy including Prisma Access explicit proxy, using a PAC URL deployed from the portal and an agent proxy mode on the endpoint. Split DNS Resolves the internal domains you specify through the gateway's DNS servers and sends all other queries to the endpoint's local resolvers, on Windows, macOS, Linux and iOS. Split Tunneling Includes or excludes traffic from the tunnel by access route, destination domain, endpoint application process path with wildcard matching, or HTTP/HTTPS video streaming application, supporting up to 200 entries per list.
Licensing & Activation GlobalProtect Gateway License Gates advanced capabilities behind an annual per-firewall subscription — HIP checks, mobile, Linux and IoT clients, IPv6 external gateways, clientless VPN, domain, application and video split tunneling, split DNS, quarantine, HIP redistribution and DHCP-based address assignment — while basic gateway and desktop VPN access needs no license. License Expiry Behavior Warns daily in the system log for 30 days before a subscription expires, then withdraws the licensed capabilities at midnight GMT while leaving basic gateway and Windows and macOS app access working.
Discovery, identification and policy for unmanaged and IoT devices.
Third-Party Integrations Alert and Vulnerability Ticketing Sends a security alert or vulnerability instance to a ticketing, maintenance management or IT service management system as a ticket, incident or work order with an assignee, priority and comment, creates them in bulk through a scheduled job, records the resulting ticket identifier in the item event history, and reflects the closure of that ticket back onto the alert or vulnerability. Asset Discovery Integrations Learns device attributes from industrial asset discovery products such as Rockwell Automation FactoryTalk AssetCentre and from active polling over more than thirty industrial, building-automation and IT protocols including Modbus, BACnet, Siemens S7, EtherNet/IP, Profinet, SNMP and WinRM, adding polled devices with a MAC address to the inventory and IP-only results to IP Endpoints. Asset Management Integrations Exchanges device inventory and attributes with maintenance management, IT asset management, mobile device management and CMDB systems, through Cortex XSOAR or the ServiceNow Service Graph Connector with customizable field mappings, so records reconcile in both directions and inventory gaps become visible, and sends remote commands such as locking a Jamf Pro managed device. Cortex XSOAR Integration Engine Runs third-party integrations through a complimentary cohosted limited Cortex XSOAR instance, a customer-operated full Cortex XSOAR server loaded with the Device Security content pack, or a full instance calling the Device Security API, with an on-premises engine bridging network segments the instance cannot reach; some integrations connect directly over the vendor API instead. Endpoint Protection Integrations Exchanges device and endpoint agent data with endpoint detection and response products, surfaces EDR isolation status, operational status and group name as device inventory columns, imports application inventory, installed patches and CVEs where the vendor supports it, and triggers endpoint actions such as isolating a host, over Cortex XSOAR or a direct API connection configured in the portal. Identity Integrations Retrieves user, directory and endpoint management data from identity providers, including Cloud Identity Engine and Microsoft Entra ID with its Intune managed-device records, to attribute devices to users and enrich device context. Integration Instance and Job Management Lists integration instances with an Active, Disabled, Error or Inactive status and counts of successful and failed calls, launches Cortex XSOAR to add, test, enable and disable one, downloads its logs and playbook work plans, alerts daily when integration jobs fail, and defines data-transfer jobs that run on demand or on an interval with a chosen playbook, polling window and target IP scope. Integration Recommendations Detects third-party tools already present on the network from App-ID traffic, HTTP user agents and device fingerprints and recommends the matching unconfigured integrations daily on the deployment checklist. Integration-Specific Device Attributes Stores attributes learned from each third-party system under a source-prefixed name, maps them to Device Security common attributes where one applies, and exposes them as inventory table columns, Query Builder terms and a per-integration section on the Device Details page. IP Address Management Integrations Learns IP blocks, subnets, names, VLANs, descriptions, gateways and site assignments from IP address management systems and records them as the source of those network elements. Network Access Control and Wireless Controller Integrations Shares device identity and generated access control lists with NAC platforms and wireless LAN controllers and sends them commands to quarantine devices with vulnerabilities or open alerts. Network Management Integrations Learns connected switch, wireless access point, subnet and device data from network management and monitoring platforms and shows the connected switch on subnet detail. Public API Exposes a public REST API for device, alert and vulnerability data, authenticated with access keys that administrators create, download and delete and with service accounts that inherit their assigned role permissions. SIEM Integration Forwards Device Security alerts, device data and vulnerability data to security information and event management platforms. SNMP Switch Discovery via XSOAR Engine Runs an on-premises Cortex XSOAR engine that walks SNMP object identifiers on an entry-point switch and its CDP and LLDP neighbors on a configurable discovery and refresh schedule to add device MAC and IP addresses and switch topology to the inventory. Vulnerability Scanner Integrations Imports vulnerability findings from third-party scanning engines and records the scanner as the vulnerability source alongside Device Security's own detections.
Asset Discovery & Inventory Custom Device Attributes Creates user-defined device attributes whose values are set automatically when a conditional statement matches or entered manually per device, and shows them as columns in the device inventory. Device Application Discovery Compiles a daily list of the applications that IoT devices on the network use and annotates each with Applipedia category, subcategory, risk level, standard ports, technology and security characteristics. Device Attribute Source Precedence Resolves conflicting values for a device attribute by source, taking the latest value for most attributes but holding network-traffic-derived values above integration-derived ones for model, vendor, OS group, OS version, firmware, serial number, wired or wireless, VLAN, hostname and Active Directory domain. Device Change History Records dated changes to a device's attributes and keeps the history of its past IP addresses, viewable from the Device Details page. Device Details Page Shows one device's attributes, risk score breakdown, network traffic topology, applications used, software components from software bills of materials, and a network usage Sankey diagram from which a policy can be created. Device Inventory Lists all discovered and monitored devices with a summary chart and an inventory table whose columns, ordering, search and saved custom filters the user controls, and downloads the filtered inventory or a dated change log as a file. Device Profiles Groups devices of the same vendor, make and model into a device profile and summarizes the profile's device count, risk score, alerts, vulnerabilities and policy sets against the same profile in other Device Security tenants. Device Tags Defines tags that are applied to devices automatically by rule or manually per device or in bulk, and removes them from individual devices or from the tenant. Industrial OT Device File Parsing Uploads and parses industrial OT device files such as PLC configuration, program and inventory files to enrich the asset inventory, flags devices missing an IP or MAC address, and keeps a downloadable parsing history. IP Endpoints Tracks traffic sources whose MAC address is unknown and whose behavior is not stable enough to treat as a static IP device, promotes them to the device inventory after seven days without an attribute change, and keeps a history of the last ten identity changes. Machine-Learning Device Identification Analyzes session and enhanced application log metadata with a three-tier profiling system to assign each discovered device a category, profile, vendor, model and operating system, and calculates a 0-100 confidence score for the identification. Manual Device Attribute Editing Edits one or more devices' type, category, profile, vendor, model, operating system, location, asset tag, serial number and description as definitive values, feeds the corrections back into model retraining, and requests new device categories. Mobile Device Attribute Discovery Reads GTP, PFCP and RADIUS-derived logs from firewalls with GTP Security enabled, and devices reported by the Prisma SASE 5G add-on, to record mobile device attributes such as IMEI, IMSI or SUPI, MSISDN, APN, radio access technology, base station, network slice and mobile country and network codes for devices on 3G, 4G and 5G networks. Multi-Interface Devices Recommends and merges separately discovered devices that share attributes such as hostname or serial number into a single multi-interface device with a primary interface, and supports editing, adding, removing and unmerging interfaces. Static IP Device Handling Detects devices with static IP addresses from ARP logs and traffic patterns, and accepts user-supplied static IP device and static-only subnet declarations entered manually or uploaded as CSV files.
Risk, Vulnerability & Compliance China Tenant Deployment Prepares a firewall to send telemetry to a Device Security tenant hosted in China, covering the firewall-only deployment path where no Prisma Access or Panorama component is present. Compensating Controls Defines system- and user-defined compensating control types and applies controls matched to an asset scope and a specific risk so that mitigations already in place lower the affected devices' risk scores. Compliance Framework Dashboards Maps the device estate's security posture to HIPAA safeguards and IEC 62443-3-3 requirements in prebuilt dashboards, and clones them into user-defined compliance controls built on the Query Builder. Device Recalls Lists U.S. Food and Drug Administration recalls that affect medical devices found on the network, with the number of recalled devices and a link to the corresponding FDA recall record. Device Vulnerability Detection Matches discovered device attributes against published vulnerability databases, the Device Security research team's own database and the device software library to raise confirmed and potential vulnerability instances, and ingests findings from integrated third-party scanners. FedRAMP Authorized Deployment Offers a separate FedRAMP Moderate and High authorized cloud instance with access limited to FedRAMP-authorized personnel, administrator IP allow-listing, on-premises FIPS-compliant Cortex XSOAR for integrations, and Device-ID enforcement for firewalls in FIPS mode. MDS2 Community Shares reviewed MDS2 documents with other Device Security tenants and applies matching community-contributed files to local devices, resolving duplicates by a fixed exclusion, manual-selection, ownership, release-date and format-version precedence. MDS2 Document Management Uploads and parses Manufacturer Disclosure Statement for Medical Device Safety files in 2004 through 2019 formats, matches them to devices by vendor, profile and model, allows correction of misparsed mapping values, and uses the disclosed data when assessing device risk and vulnerabilities. Risk Score Customization Defines vulnerability matching rules that set a vulnerability's risk score, adjusts the score contributed by each alert severity level and by each other risk factor, and changes a device's asset criticality to amplify or reduce its overall score. Risk Scoring Calculates daily risk scores for devices, device profiles, sites and the organization from vulnerabilities, security alerts and other risk factors such as end-of-support operating systems and external exposure, ranks them into severity levels, and raises an alert when a score crosses a level threshold upward. Virtual Patching Identifies vulnerabilities on hard-to-patch OT and IoT devices for which a threat signature exists and walks the user through creating a Security policy rule on the affected assets to block exploitation at the network layer. Vulnerabilities Inventory Lists detected vulnerabilities with priority, severity, CVSS and EPSS scores, exploit and APT status, CVE attack metrics, Threat Prevention coverage, and confirmed, potential, addressed and critical-asset instance counts. Vulnerability Details and Instance Workflow Shows a vulnerability's summary, impact, affected devices and recommended mitigations, and moves each instance through Detected, Investigating, Remediating and Resolved states. Vulnerability Threat Intelligence Attaches threat actor campaigns, actor profiles, targeted industries and regions, and indicators of compromise to vulnerabilities so they can be queried and prioritized, and links each indicator to a threat search in Strata Cloud Manager.
Deployment & Data Collection Data Quality Diagnostics Reports the count and share of IP endpoints and low-confidence devices over the past 30 days and recommends changes that would improve the quality of the data Device Security receives. DHCP Server Syslog Ingestion Configures a firewall to receive syslog from DHCP servers over TCP, UDP or SSL and forward the messages as enhanced application logs, extending IP-to-MAC visibility where the firewall does not see DHCP traffic directly. ERSPAN Mirrored Traffic Collection Receives switch-mirrored device traffic encapsulated in GRE tunnels at a firewall so that traffic never routed through the firewall still produces logs for Device Security. Firewall Deployment Options for Device Visibility Supports Layer 2, Layer 3, Tap and Virtual Wire firewall interface deployments for seeing unicast and broadcast DHCP traffic, and documents which combinations generate the enhanced application logs Device Security needs. Firewall Integration Status Shows which subscribed firewalls are sending logs, per-log-type live data status, log event volumes and average and maximum latency over the selected time range, plus PAN-OS, device dictionary and application content versions, license type and site reassignment. Log Forwarding Configuration Applies a log forwarding profile with enhanced application logging to Security policy rules, so firewalls send traffic, threat, WildFire, DHCP, ARP and GTP metadata to the logging service that streams it to Device Security, with a per-zone metadata collection profile narrowing the forwarded fields and service routes that reach those services and the update server over a data interface. Network Discovery CLI Diagnostics Runs Network Discovery diagnostics from the firewall command line to isolate polling and connectivity problems without opening a support case. Network Discovery Plugin Polling Installs a plugin on Panorama or PAN-OS that polls network devices over configurable protocols, ports, timeouts and IP scopes and crawls switch topology over SNMPv2c or SNMPv3 from designated entry-point switches with per-site scoping, credentials and service routes. On-Demand Packet Capture Authorizes the Device Security research team to collect packet captures through the OpenConfig plugin on telemetry-enabled firewalls, with captures encrypted in transit and at rest, kept in the tenant's cloud region, deleted after 120 days, and unavailable in FedRAMP and China-region tenants. Prisma Access Integration Status Reports Prisma Access as a single site and firewall entity on the Sites and Firewalls pages, shows system alerts for its policy recommendation and IP-address-to-device mapping requests, and covers the purchased add-on with its required pairing of Prisma Access, Strata Logging Service and Device Security regions and optional Prisma SD-WAN telemetry for traffic that stays within a site. Security Telemetry Gateways for Isolated Segments Chains an OT and an IT next-generation firewall as security telemetry gateways so firewalls in isolated network segments can reach the logging service, Device Security and the update server through controlled outbound paths.
Network & Site Organization Device-to-Site Mapping Assigns discovered devices to sites either by the IP address block they fall in or, for tenants onboarded before March 2022, by the location of the firewall that reported them, with a one-way switch from firewall-based to IP-based assignment. Network and Device Context Segments Associates firewalls, and in PAN-OS-managed device context segments individual virtual systems, with a segment and a site so that devices reusing a shared IP block are told apart, with reset, delete, restricted device context sharing and migration of segment ownership to Panorama. Network Inventory Organizes subnets, IP blocks and remainders into a navigable hierarchy with per-element VLAN, zone, source, device counts, IP endpoint counts and firewall security rules, and accepts manually added or uploaded blocks and subnets alongside those discovered from traffic or learned from integrations. Network Visualization Maps Builds one- or two-layer maps that group devices by device attribute such as subnet or profile, by Purdue level, or by process zone, and supports hover, drill-down, node repositioning, protocol filtering and breadcrumb navigation of device communications. Physical Device Location Shows a device's last known physical location and its position on a floor plan imported from an integrated wireless or location platform, along with the access point that last saw it, and lists all devices by floor plan on a Location page. Process Zones Groups operational technology devices into IEC 62443 process zones with criticality and target security level, displays the conduits between them on visualization maps, and exposes the zone as a device attribute in filters, queries, dashboards and reports. Sites and Site Groups Creates and manages sites and arranges them into a group hierarchy up to five levels deep that scopes what appears on the Sites and Devices pages and defines the scope of reports. Subnet Monitoring Control Starts and stops monitoring of an IP block or subnet, propagates the status to its child networks, and removes the associated devices, IP endpoints, alerts and vulnerability instances while monitoring is off, restoring them when it resumes. Subnet-Site Mapping Source Priority Sets a global prioritization order across the sources that supply subnet-to-site mappings so that conflicting mappings resolve to the highest-priority source.
Dashboards & Reports Custom Dashboards and Widgets Creates custom widgets as bar, pie, line, table, statistic or paragraph displays over a defined scope and assembles them with system widgets into custom dashboards with a shared global time range that can be pinned to the Dashboard tab. Data Export Downloads inventory tables, IP endpoint lists, chart data and query results as CSV, XLSX or ZIP files reflecting the filters currently applied. Insights Center Presents risk-posture charts, topology visualizations and recommended actions over an ad hoc or saved query scope, and lets each recommendation be viewed, dismissed or snoozed and filtered by that state, suppressing recommendations already covered by a compensating control. Medical Device Utilization Analytics Reports how medical devices are used through the Utilization and Biomed dashboards, classifying devices as used, online only or offline within site, category and time-range filters and exporting the underlying data as a spreadsheet. Predefined Dashboards Provides a landing dashboard summarizing the device landscape, risk and recommended actions, plus system dashboards for device inventory, organization risk score and active vulnerabilities and a vulnerability overview dashboard with key statistics, a configurable vulnerabilities-of-interest query, an instance distribution Sankey chart and an instance trend chart. Reports Generates Summary, Discovery, New Device, Risk, Inventory Gap, Utilization and Filtered Inventory reports plus user-built templates cloned from system ones or converted from custom dashboards and scoped with the Query Builder, on demand or on a daily, weekly or monthly schedule, delivers them by email as PDF or CSV, and tracks each run in a history where a report can be retried or deleted. Traffic and Threat Log Access Shows the ten most recent traffic logs for a device filtered by time range and direction, and opens the Strata Cloud Manager Log Viewer prefiltered to a device or to an alert's addresses, threat identifier and surrounding 24 hours, for tenants licensed for Strata Logging Service. Vertical-Themed Portals Presents an Enterprise, OT or Medical portal theme that determines which dashboards, pages and example query templates appear, such as the Utilization, BioMed, FDA recall and MDS2 surfaces in the medical theme, and lets a tenant owner switch between the themes their subscriptions cover.
Threat Detection & Alerts Alert Mapping to Security Frameworks Maps each security alert to MITRE ATT&CK ICS and Enterprise tactics and techniques and to IEC 62443 security requirements, shows them on the Alert Details page, and exposes them as filter and search attributes on the alert inventory. Alert Notifications Sends email and SMS notifications for security alerts on monitored devices and for system alerts about firewalls, to recipients the tenant owner controls. Alert Overview and Inventory Presents an alert overview dashboard of top-priority alerts, risk analysis and alert trends, an All Alerts list filtered by site, device category, time range and response status, and an Alert Details page showing the client, server, protocols and connection state of the incident. Alert Response Workflow Moves alert instances through Detected, Investigating, Remediating and Resolved states, assigns them to users with comments, records notes on the alert events list, and resolves or reactivates alerts individually or by alert group. Alert Suppression Suppresses future occurrences of an alert for the triggering device or for all devices sharing its profile, category or type, either indefinitely or for a set period. Behavioral Anomaly Detection Baselines each device's normal network behavior and raises security alerts when observed activity indicates attack or reconnaissance, using threat signatures and machine-learning detections. Custom Alert Rules Defines rules that combine traffic-pattern and change-event conditions in nested AND/OR condition sets against selected target devices and trigger an alert, user notification or network access restriction at most once per device per day, seeded by vertical-specific example templates and tracked by hit count. OT Process Variable Monitoring Reads process variables such as temperature, pressure and flow rate from OT protocol traffic, shows each variable's current value, trend and read and write history on the Device Details page, and raises an alert at a chosen severity when a value crosses a user-set high or low threshold within a time window.
Licensing, Activation & Onboarding Activation Workflow Activates Device Security from the activation email, Customer Support Portal or enterprise license agreement auth code by choosing the support account, allocating the product to a recipient tenant, selecting the data ingestion region, optionally adding Strata Logging Service, and naming the tenant app subdomain. Guided Onboarding Workflow Walks a new tenant through selecting an Enterprise, OT or Medical vertical portal theme, generating the one-time password and pre-shared key for device and logging service certificates, associating firewalls with the tenant, and verifying that logs are reaching the portal. License Lifecycle Renews licenses before expiry, converts trial licenses to production and between subscription types under defined midterm upgrade rules, deactivates licenses from firewalls and transfers them to other firewalls or Customer Support Portal accounts, and lets subscriptions expire and offboard. Subscription Licensing Offers per-firewall Enterprise, Medical and OT subscriptions and per-device Device Security X subscriptions, each in variants that do or do not require Strata Logging Service, alongside Precision AI bundle and Prisma Access add-on entitlements, trial and evaluation terms, and the Enterprise and Enterprise Plus feature tiers. Tenant and Subtenant Allocation Allocates a subscription across a tenant hierarchy for managed security service providers and distributed enterprises, assigns a share of device licenses per tenant service group, and creates a one-time 30-day trial tenant for up to five firewalls. VM-Series Onboarding with Software NGFW Credits Onboards Device Security on VM-Series firewalls using Software NGFW credits, including VM-Series bootstrapped in virtual metadata collector mode.
Policy Recommendations & Enforcement Device Profile Behaviors Shows the inbound and outbound network behaviors of devices in a profile as a filterable table and Sankey chart, separating applications common across tenants from those unique to the local environment and showing each application's risk level and alert count. Device-ID Attribute Enforcement Publishes a device dictionary that firewalls, Panorama and Prisma Access download from the update server and supplies IP-to-device mappings for high-confidence devices, so Security policy rules can match on device category, vendor, model, profile and OS or on Advanced Device-ID objects of up to thirty attributes, and holds a verdict for a confirmed static IP until a new address is seen in traffic. Network Access Restriction Marks a device of concern as Restricted so that firewalls matching on that Device-ID attribute deny its traffic, and applies Device-ID rules that limit what a device may reach during its onboarding period. Policy Rule Recommendations Generates inbound and outbound Security policy rule sets per device profile or per device from the observed behaviors of high-confidence devices locally and across tenants, allowing rules to be deselected, manually added, condensed by application grouping, scoped by source and destination device profiles, IP addresses and FQDNs, and pre-populated with tags, security profiles, zones and services. Policy Set Import into Panorama and Firewalls Fetches active policy recommendations into Panorama or a firewall and inserts them into the pre-rulebase or post-rulebase at a chosen position, automatically creating the device, service and address objects the rules require. Policy Set Lifecycle Saves, activates one policy set at a time per device profile, deactivates, edits, downloads and deletes policy rule sets and Cisco ISE ACL rule sets, and flags new and unexpected behaviors observed since the active set was last updated.
Users & Access Control Administrator Audit Logs Records administrator activity such as configuration changes, with owners able to review the audit log for all users and other roles able to review only their own. Custom Role-Based Access Control Defines custom roles in Strata Cloud Manager identity and access management that set Read Write, Read Only or No Access per Device Security entity such as devices, alerts, networks, policies and vulnerabilities, and assigns one or more of them to a user or service account with the most permissive permission winning. Scope-Based Access Control Creates named scopes covering all sites, no sites, or a manual selection of sites and site groups and assigns them to users so they see only the devices, alerts, vulnerabilities and risk data belonging to those sites, with multiple scopes unioned and unscoped tenants retaining full access. User Account Management Creates and views Device Security user accounts through the Customer Support Portal and Common Services, invites users, and lets each user set contact details, time zone, idle session timeout, alert sound, display theme and SMS and email notification preferences. User Authentication Authenticates administrators with the Palo Alto Networks SSO or a customer-managed third-party identity provider including Active Directory SAML, taking role assignments from the identity provider, from the portal, or the higher of the two. User Roles Grants portal privileges through Owner, Administrator and Read-only roles in the legacy portal, Superuser and View-only Administrator roles in Strata Cloud Manager, and the common App Administrator and Instance Administrator roles, with owner-only controls for idle timeout, site access, scanning permissions and notification recipients.
Queries & Filters Global and Custom Filters Applies site, device type and time-range filters that persist across pages, saves named custom filters over device characteristics that can optionally carry the global filter values, and searches devices by full or partial name. Portal Global Search Searches by keyword across devices, alerts, vulnerabilities and external destinations from a single field in the portal title bar. Query Builder Builds queries that start from a devices, alerts or vulnerabilities domain and narrow by domain-specific attributes and values, adds a secondary cross-domain filter so alerts and vulnerabilities can be filtered by device attributes, supports time-based and exact-set-match operators, validates them, and runs them from the query library or as the global query on inventory pages. Saved and Scheduled Queries Saves queries to a library for reuse, schedules them to run on a recurring basis, edits or deletes them, and reviews past runs and downloads their results from the query log.
Automation & Action Center Action Center Action Sets Builds action sets that pair a schedule, event or one-time trigger with a scope query and one or more main and fallback actions, including actions delivered through third-party integrations, and activates, disables, inspects or deletes them from a list page.
Palo Alto's core network security platform — the PA-Series hardware, software firewalls and the PAN-OS operating system they run, documented together as the current NGFW surface.
Networking, Routing and VPN Aggregate Ethernet Interfaces Combines up to eight Ethernet interfaces of matching bandwidth and type into an 802.1AX aggregate group that load balances traffic and survives member failure, with LACP mode, transmission rate, port priority and system priority, and aggregation of HA3 packet-forwarding links on supported models. Auto VPN Creates a hub-and-spoke VPN cluster from Strata Cloud Manager in which a designated gateway firewall automatically builds route-based IPSec tunnels to branch firewalls, with pre-shared keys that can be refreshed without rebuilding the cluster. BGP Runs BGP with a router ID and 2-byte or 4-byte local AS, peer groups of IBGP, EBGP or confederation peers carrying MP-BGP IPv4 and IPv6 address families, import and export rules matching AS path, community and prefix, conditional advertisement, route aggregation, redistribution rules, route reflectors, confederations, dampening, graceful restart and fast external failover. Bidirectional Forwarding Detection Detects a failure in the path to an adjacent peer faster than routing protocol hellos and withdraws the affected routes, through BFD profiles setting active or passive mode, minimum transmit and receive intervals, detection multiplier, hold time and multihop TTL, applied to static routes and to BGP, OSPF, OSPFv3 and RIP, with per-session summary and detail statistics. Bonjour Reflector Forwards Apple Bonjour mDNS traffic between Layer 3 Ethernet, aggregate Ethernet and subinterfaces so devices and services remain discoverable across segmented networks. Breakout Port Interfaces Splits a high-speed Ethernet port into individual broken-out ports that each behave as a standard interface in tap, virtual wire, Layer 2 or Layer 3 mode and can carry subinterfaces. Cellular Interfaces Terminates a 4G LTE or 5G WAN connection on a cellular interface with radio and GPS control, dual SIM slots and failover, DHCP relay across the cellular WAN, and APN or DNN profiles that carry the carrier name, PDP type, authentication credentials and 5G network slice identifiers. DHCP Server, Client and Relay Runs an interface as a DHCP server with automatic, dynamic or static allocation from configurable pools, lease terms, reserved addresses, standard and custom options and inheritance from an upstream DHCP or PPPoE client, as a DHCP client that can install a default route, or as a relay agent forwarding to up to eight IPv4 and eight IPv6 servers with optional gateway and subnet overwrite. DNS Proxy Answers DNS queries on selected interfaces from a cache or by forwarding to default servers, routes queries for named domains to specific servers through proxy rules, serves static FQDN-to-address mappings, supports encrypted DNS toward clients and servers, tunes caching and retries, and through DNS server profiles gives each virtual system its own servers and service route. Dynamic DNS Registration Registers IPv4 and IPv6 address changes on a firewall interface with a dynamic DNS provider on address change and at a configured interval, so domain-name-to-address mappings stay accurate for clients reaching the firewall and the services behind it. Equal-Cost Multipath Routing Installs up to four equal-cost routes to the same destination in the forwarding table and balances new sessions across them by IP modulo, IP hash, weighted round robin or balanced round robin, with symmetric return that sends replies out the ingress interface and a strict source path option that pins firewall-originated IKE and IPSec traffic to the tunnel source interface. Fail Open Ports Passes traffic through designated port pairs on supported hardware models when the firewall loses power or the operating system fails, disabled by default and enabled per device. Firewall Interface Configuration Configures the settings common to every data interface — name and numeric suffix, interface type, comment, link speed, duplex and state, MTU and TCP MSS adjustment, NetFlow profile, interface management profile, and assignment to a virtual or logical router, virtual system and security zone — including the slot selection that PA-7000 Series chassis interfaces require. Global Session and TCP Settings Sets firewall-wide session behaviour including rematching newly committed security rules against sessions already in progress, IPv6 firewalling and geolocation, ICMPv6 error rate limiting, ERSPAN termination, and TCP stack handling such as out-of-order queue overflow, challenge ACKs, null timestamp options and asymmetric-path tolerance. Global Session Timeouts Defines how long TCP, UDP, ICMP, SCTP and other sessions remain open without activity and how long a session denied by security policy remains in discard state, as device-wide defaults that per-application timeouts override. GlobalProtect App Distribution Downloads and activates a GlobalProtect app version on the portal-hosting firewall for connecting endpoints to retrieve, with the portal configuration deciding whether upgrades are automatic, prompted or prohibited, and an app settings panel showing connection, host profile, notification and log-collection state on the endpoint. GlobalProtect Clientless VPN Publishes HTML, HTML5 and JavaScript enterprise web applications, defined as clientless application objects and groups, on a portal landing page reached from an SSL-enabled browser without the GlobalProtect app, with URL rewriting to a nominated hostname, a security zone controlling access, a DNS proxy, and login lifetime and inactivity timeouts. GlobalProtect Gateway Terminates GlobalProtect app VPN connections on a selected interface, authenticating clients per operating system with authentication and certificate profiles, and assigns tunnel settings over IPSec with SSL-VPN fallback, a client IP pool, access routes and split tunnelling, DNS and WINS servers, login lifetime and inactivity timeouts, video-streaming exclusions and HIP notification messages. GlobalProtect MDM Integration Connects a gateway to a Mobile Security Manager over HTTPS with a client certificate and trusted root CA to retrieve host information profile reports for managed mobile endpoints. GlobalProtect Portal Authenticates endpoints against an SSL/TLS service profile, certificate profile and authentication profile per operating system, then delivers each one an agent configuration selected by user, group, OS, machine account or certificate and registry checks, listing internal and external gateways with priorities and regions, trusted root certificates, app behaviour and HIP collection scope. GRE Tunnels Terminates point-to-point GRE tunnels to a router or another firewall over an Ethernet, aggregate, loopback, VLAN or cellular source interface with a configurable TTL, ToS header copy and keepalive, and decapsulates ERSPAN mirrored traffic delivered through the tunnel for inspection. IKE and IPSec Crypto Profiles Defines the ordered Diffie-Hellman groups, authentication hashes, encryption algorithms and key lifetimes offered during IKE Phase 1 and Phase 2 negotiation, as separate IKE Crypto, IPSec Crypto and GlobalProtect IPSec Crypto profiles selecting ESP or AH and optional perfect forward secrecy. IKE Gateways Negotiates IKE Phase 1 with a peer gateway in IKEv1-only, IKEv2-only or IKEv2-preferred mode over an IPv4 or IPv6 interface with a static, dynamic or FQDN peer address, pre-shared key or certificate authentication, NAT traversal, passive mode, IKE fragmentation, dead peer detection, strict cookie validation and post-quantum key exchange. IKEv2 Half-Open SA Protection Limits IKEv2 half-open security associations per firewall and triggers cookie validation above a configurable threshold, and caps the number of peer CA certificates cached for the IKEv2 hash-and-URL feature. Interface Management Profiles Restricts which administrative services and network services a dataplane interface answers — Telnet, SSH, HTTP, HTTPS, ping, HTTP OCSP, SNMP, User-ID and the User-ID syslog listener — and limits them to a list of permitted source addresses. IP Multicast Routing Forwards IPv4 multicast using PIM and IGMP — static mroutes, RPF lookup mode, static, candidate and remote rendezvous points, interface groups sharing group permissions for any-source and source-specific multicast, IGMP version and timers, a per-group shortest-path-tree switchover threshold and route age-out — with FIB, IGMP and PIM runtime tables. IPSec VPN Tunnels Establishes IKE Phase 2 site-to-site IPSec tunnels on a tunnel interface using automatically negotiated or manually entered keys, with proxy IDs that double as IKEv2 traffic selectors, anti-replay protection and window size, copied ToS header, tunnel monitoring, and per-tunnel status, enable, disable, restart and refresh. IPv6 Neighbor Discovery Runs IPv6 Neighbor Discovery on Layer 3 interfaces, reporting each neighbor's IPv6 and MAC address, User-ID attribution, reachability status and last report time, and provisioning hosts with recursive DNS server and DNS search list options in router advertisements. Large Scale VPN Builds hub-and-spoke IPSec VPNs between Palo Alto Networks firewalls in which a GlobalProtect portal distributes configuration to satellite firewalls that establish tunnels with up to twenty-five gateways, using static access routes or OSPF and BGP dynamic routing over point-to-multipoint tunnel interfaces. Layer 2 Switching Operates the firewall as a hardware Layer 2 switch through a Layer2 Switch interface type with access or trunk ports, per-port access and native VLAN tags, link aggregation, storm control for broadcast, unknown unicast and multicast traffic, and MSTP spanning tree configured globally, per instance and per port through STP profiles. Link Layer Discovery Protocol Exchanges LLDP frames with neighbouring devices to map topology and capabilities, with a global transmit interval, transmit delay, hold time multiple and notification interval, per-interface profiles selecting mode and the optional port, system and management-address TLVs, SNMP and syslog notification on MIB change, HA passive pre-negotiation, and per-interface peer and error statistics. Logical Routers and Advanced Routing Engine Provides the Advanced Routing Engine routing instance, enabled device-wide and requiring a reboot, in which each logical router holds its own interfaces, administrative distances, static routes and protocol configuration, and draws its settings from reusable routing profiles for BGP, OSPF, OSPFv3, RIPv2, multicast and BFD. LSVPN Satellite Enrollment and Certificates Authenticates satellites to the LSVPN portal by serial number, serial number and IP address, or username and password with a reissued satellite cookie, then issues each satellite a server certificate from the portal's root CA or a client certificate obtained from an enterprise SCEP server, and refreshes the satellite configuration on an interval. Multicast Source Discovery Protocol Peers a logical router's rendezvous point with rendezvous points in other multicast domains over MSDP so it learns active multicast sources outside its own domain. NAT Policy Translates source and destination addresses and ports for IPv4, NAT64 and NPTv6 traffic using static, dynamic IP, dynamic IP and port, and persistent DIPP pools, matched by zone, address, destination interface and service. NAT64 Translation Translates between IPv6 and IPv4 addressing on Layer 3, subinterface and tunnel interfaces — stateful many-to-one translation for IPv6-initiated sessions against a well-known or network-specific prefix supplied by an external DNS64 server, and static IPv4-initiated bindings with optional port rewrite — with hairpinning, a configurable IPv6 minimum MTU and path MTU discovery. NDP Proxy Answers IPv6 neighbor solicitations on behalf of addresses, subnets and ranges configured on an interface, selecting the longest prefix match and skipping negated entries and addresses already in the neighbor discovery cache, so hosts behind the firewall are reachable at prefixes the firewall translates. Network Packet Broker Forwards decrypted TLS, non-decrypted TLS and cleartext traffic matched by policy to an external chain of third-party security appliances over dedicated Layer 3 or transparent-bridge interfaces, distributing sessions across multiple chains and monitoring path and HTTP latency health. NPTv6 Prefix Translation Statelessly translates one IPv6 prefix to another in both directions through NPTv6 rules, leaving the host identifier and port numbers unchanged, with checksum-neutral mapping, an optional bi-directional rule, restriction to a chosen service, and support for a dynamically assigned prefix from DHCPv6, PPPoEv6 or a cellular interface. OSPF and OSPFv3 Runs OSPFv2 for IPv4 and OSPFv3 for IPv6 with a router ID, normal, stub and not-so-stubby areas with summary ranges and default-route origination, per-interface broadcast, point-to-point and point-to-multipoint link types with priorities and timers, simple, MD5 and ESP or AH authentication profiles, export rules, SPF and LSA timers, and graceful restart with helper mode and strict LSA checking. Policy-Based Forwarding Overrides the routing table to send matching traffic to a specified next hop and egress interface, to another virtual system, or to be discarded, with path monitoring and symmetric-return enforcement. Power over Ethernet Supplies power to connected devices from PoE-capable ports with a reserved power allocation per interface, and reports per-port operational status, class, allocated, used and consumed power, faults and blacklist reasons against the chassis power budget. PPPoE Client Runs a Layer 3 interface or 802.1Q-tagged subinterface as an IPv4 or IPv6 PPPoE client that learns its address, credentials and routing information from an ISP. Proxy ARP and DHCP Relay Overwrite Redirects traffic between devices sharing one Layer 2 broadcast domain through the firewall by answering ARP requests for configured addresses, subnets and ranges on a Layer 3 interface, and by replacing the subnet mask and default gateway in relayed DHCP offers, so intra-VLAN traffic is subject to security policy. Quality of Service Enforcement Shapes egress traffic by enabling QoS on a physical, aggregate or subinterface with an interface egress maximum, separate default profiles for clear text and tunneled traffic and per-tunnel overrides, QoS profiles defining guaranteed and maximum bandwidth and priority for up to eight classes, and real-time per-class bandwidth, application, user and matched-rule statistics. RIPv2 Runs RIPv2 on selected interfaces in normal, passive or send-only mode with split horizon options, default-route advertisement and metric, simple password or MD5 authentication profiles, update, expire and delete timers, export rules and per-peer statistics. Route Redistribution Advertises static, connected and other protocols' routes into RIP, OSPF, OSPFv3 and BGP through prioritized redistribution profiles that match on route type, interface, destination, next hop, OSPF path type, area and tag or BGP community, then redistribute or suppress the route with a new metric and protocol-specific attributes. Routing Filters and Route Maps Builds the reusable access lists, prefix lists, AS-path access lists, community lists and route maps that Advanced Routing profiles reference to control which routes are accepted into the RIB, advertised to peers, conditionally advertised, aggregated or redistributed, and what attributes are set on them. Routing Runtime Statistics Reports a router's operational state — the unicast and multicast route table with per-route protocol, metric, flags and age, the forwarding table with selected paths and MTU, static route monitoring status, and per-protocol summary, peer, peer group and route views for BGP, RIP, multicast and BFD. SD-WAN Interfaces and Link Profiles Groups Layer 3 Ethernet or VPN tunnel interfaces going to the same destination into a virtual SD-WAN interface, and classifies each physical link with an SD-WAN interface profile carrying a link tag, link type, upstream and downstream speeds, path monitoring frequency and VPN data tunnel support, created manually or generated by Panorama Auto VPN. SD-WAN Path Selection Selects and swaps the WAN link for each application using path quality, SaaS quality, traffic distribution and error correction profiles referenced from SD-WAN policy rules, failing over on latency, jitter or packet-loss thresholds and applying forward error correction or packet duplication. Security Zones Groups interfaces of one type into tap, virtual wire, Layer 2, Layer 3, tunnel or external zones that an interface cannot process traffic without, allows intrazone traffic and requires a rule for interzone traffic, and carries the per-zone zone protection profile, packet buffer protection and User-ID and Device-ID enablement. Service Routes Sends firewall-originated traffic for services such as DNS, updates, LDAP, Kerberos, RADIUS, TACACS+, MFA, email, SNMP traps, syslog, HTTP, the User-ID agent and Panorama out of a chosen source interface and address or to a custom destination, globally or per virtual system, with a PA-7000 Series logging card carrying per-virtual-system log traffic on its own subinterfaces. Session Distribution Policy Selects how a firewall with multiple dataplane processors assigns new sessions to them, through policies suited to different traffic mixes such as large-scale source NAT, and reports per-processor session counts and utilization. Static Routes Adds IPv4 and IPv6 static routes with a destination prefix or address object, an egress interface and a next hop given as an address, FQDN, another router, discard or none, an administrative distance and metric, a target unicast or multicast route table, an optional BFD profile, and path monitoring that withdraws the route when monitored destinations stop responding. Tap, Virtual Wire, Layer 2 and Layer 3 Interface Modes Deploys each Ethernet port in tap, virtual wire, Layer 2 or Layer 3 mode, and defines subinterfaces under them that classify traffic by VLAN tag, or by VLAN tag and IP address, range or subnet, into their own zones and virtual systems. Tunnel and Path Monitor Profiles Monitors an IPSec tunnel or a policy-based forwarding next hop with a heartbeat interval and loss threshold, then either waits for recovery or fails traffic over to a backup path while renegotiating IPSec keys. Virtual Routers Provides the legacy routing instance the firewall assigns Layer 3, loopback and VLAN interfaces to, each with its own routing and forwarding tables and per-protocol administrative distances for static, OSPF, IBGP, EBGP and RIP routes. VLAN and Virtual Wire Objects Binds Layer 2 interfaces into an 802.1Q VLAN with an optional VLAN interface for routing out of it and static MAC-to-interface overrides, and binds two virtual wire interfaces into a virtual wire with an allowed tag list, optional multicast firewalling and link state pass-through. VLAN, Loopback and Tunnel Interfaces Creates logical interfaces that carry no physical port — VLAN interfaces that route out of a Layer 2 domain, loopback interfaces, and tunnel interfaces that terminate IPSec, GRE and GlobalProtect tunnels — each with its own addressing, MTU, MSS adjustment, router, zone and management profile. Web Proxy Operates the firewall as an explicit or transparent web proxy, or as a Palo Alto Networks service proxy forwarding downstream firewall traffic upstream, with a listening and upstream interface, proxy address, connect timeout, DNS proxy object, authentication service and a check that the CONNECT request and TLS SNI name the same domain.
Platform Operations and Maintenance Administrative Task Manager Lists administrator-initiated and firewall-initiated jobs, scheduled reports and log requests since the last reboot with their status and messages, and cancels queued commits. Air-Gapped Deployment Operates a firewall with no route to the update server by registering it as an offline device, uploading each license key file by hand, and uploading and installing PAN-OS and dynamic content images downloaded separately, then verifying that internal hosts are reachable and external ones are not. Asset Lifecycle Management Tracks registered hardware against an enterprise agreement's estate cap with consumption summaries and trend graphs, accepts asset transfers, applies device tags, exports the asset list, and permanently decommissions assets singly or in bulk. Banners, Message of the Day and Logos Customizes the login banner with optional forced acknowledgement, coloured header and footer banners, a message-of-the-day dialog and the logos shown on the login page and interface header. Cloud and Central Management Onboarding Connects a firewall to Panorama or Strata Cloud Manager for centrally pushed policy and device configuration scoped by folders and snippets, and surfaces conflicts between locally held and pushed objects with a configuration diff and conversion of local configuration into shared snippets. Commit, Validate and Preview Activates pending configuration changes through a queued commit that first validates them and can preview the difference, and can restrict the commit to changes made by named administrators, to specific locations or to selected configuration objects. Configuration Audit Compares two configuration versions and summarizes which objects and rules were added, deleted or modified in a commit, with an XML diff for changes too large to summarize. Configuration Backup and Revert Saves named or default snapshots of the candidate configuration and versions of the running configuration, exports them to an external host, and reverts the candidate configuration to the running configuration or to any saved version. Configuration Table Export Exports filtered policy, object, network and device configuration tables and security profile signature exceptions to PDF or CSV for external review and audit, logging each export. Content and Software Update Scheduling Schedules antivirus, applications-and-threats and WildFire content updates on a recurrence with a download-only or download-and-install action, an age threshold, a separate waiting period for releases containing a new App-ID and synchronization to the HA peer, and schedules PAN-OS upgrades and downgrades for groups of firewalls matched by folder, model and label. Custom Response Pages Replaces the HTML pages the firewall serves to users for events such as application blocks, antivirus blocks, authentication portal challenges and decryption opt-out, per virtual system, by importing and exporting templates. Factory Reset Returns the firewall to factory default settings from maintenance mode over a console connection, removing all configuration and logs. Firewall Bootstrapping Brings a factory-default firewall into service from an init-cfg.txt file and optional bootstrap.xml, supplied on a USB flash drive, that sets management addressing, hostname, Panorama servers, template and device group and licensing. Firewall Registration and Day 1 Configuration Registers a firewall and its line cards to a Customer Support Portal account by serial number or authorization code with device name, tags, location and support-agreement membership, and optionally generates a best-practice Day 1 configuration snapshot to import as a starting configuration. Global Find Configuration Search Searches the candidate configuration for a string such as an address, object name, rule name, threat ID, UUID or job ID and returns grouped, linked results showing every place it is referenced, with a usage-ranked optimized search mode. Initial Device Setup Brings a factory-default firewall into service over the console port or the default management address by forcing a new administrator password and setting the management interface addressing and permitted services, DNS and NTP servers with optional NTP authentication, hostname, domain and login banner. Maintenance Recovery Tool Boots the appliance into a recovery environment that reverts PAN-OS or content to a previous version, runs file system diagnostics, gathers system information and logs, and switches the operational mode. Management and Auxiliary Interface Configuration Sets the addressing, speed and MTU of the out-of-band management interface and of the auxiliary SFP+ ports on supported platforms, selects which administrative services and network services including SNMP, ping, HTTP OCSP and the User-ID syslog listeners the interface answers, and restricts access to a list of permitted IP addresses. Management DNS, Update Server and Proxy Settings Resolves firewall-originated queries through primary and secondary DNS servers or a DNS proxy object, optionally over DNS-over-HTTPS or DNS-over-TLS with unencrypted fallback, and sets the update server address, whether its certificate is verified, and an outbound proxy server, globally or per virtual system. Object Move, Clone, Override and Revert Moves or clones a policy rule or object into another virtual system, device group or the shared location with reference validation, and in a nested device group hierarchy overrides an inherited object's values, reverts it to the inherited values, disables overriding for it, or replaces all overrides with ancestor values. Panorama Centralized Management Provides a single management server, available as an M-Series appliance or a virtual appliance, that manages firewalls and Log Collectors, switches context into an individual firewall web interface, and scopes views by access domain, device group and template. Panorama Commit and Push Operations Commits pending Panorama changes and pushes the running configuration to device groups, templates, Collector Groups and WildFire clusters, filtered by administrator or location, with validate, preview and automatic commit on reboot. Panorama Configuration Backup and Scheduled Export Retains a configurable number of automatic backups of every configuration committed to a managed firewall for restore, and exports all Panorama and firewall running configurations to an SCP or FTP server on a daily schedule. Panorama Firewall License Management Activates, refreshes and deactivates licenses and subscriptions on managed firewalls, including VM-Series capacity licenses, and displays per-firewall license status, with a token file for air-gapped deactivation. Panorama Managed Device Administration Adds firewalls to Panorama by serial number or CSV import, associates them with device groups and template stacks, tags and filters them, displays their connection and update state, and issues device registration authentication keys for mutually authenticated onboarding. Panorama Plugins Installs, upgrades, uninstalls and removes the configuration of bundled and cloud-services plugins that extend Panorama with third-party and cloud integrations. Panorama Scheduled Config Push Pushes device group and template configuration to selected managed firewalls at a one-time or recurring scheduled time and records per-device success, failure and revert counts in an execution history. Panorama Software and Content Deployment Downloads, uploads and installs PAN-OS, Panorama and GlobalProtect software and dynamic content updates on managed firewalls and Log Collectors, schedules recurring content updates from the update server or an SCP server, reverts content versions, and orchestrates staged upgrades of HA pairs. Panorama Templates and Template Stacks Pushes common device and network settings to managed firewalls through templates and ordered template stacks, with per-template, per-stack and per-device variables substituting addresses, interfaces, HA identifiers and SD-WAN values. Policy Match and Connectivity Tests Runs security, NAT, QoS, policy-based forwarding, decryption, authentication and DoS policy match tests against supplied traffic attributes and connectivity tests for routing, ping, traceroute, update server, external dynamic lists, Threat Vault, WildFire, log collectors and cloud services, from the firewall or across selected Panorama-managed devices. SCP File Upload Allows a superuser administrator to upload PAN-OS software, plugin versions, dynamic content updates, configuration files and license keys to the firewall over SCP from the CLI instead of the web interface. Subscription Licensing and Activation Activates the support license and each feature subscription by authorization code, by retrieving keys from the license server, or by manually uploading a key file on a disconnected firewall, warns daily in the system log for thirty days before expiry, and degrades each subscription to a defined reduced capability once it expires. Support Status and Diagnostic Files Shows support entitlement status and expiry alongside production and application-and-threat alerts retrieved for the serial number, and generates a tech support file for troubleshooting and a stats dump of the last seven days of traffic used to produce a Security Lifecycle Review. Upgrade Check Reports Generates a pre-upgrade report of named checks with an OK, informational or critical status, remediation links and a summary count, and compares any two reports generated for the same device. Vehicle ignition monitoring Enables, configures and monitors the Vehicle Ignition Monitoring System on ruggedized firewalls, using IGN+ and BATT+ inputs to detect vehicle ignition state and manage firewall power draw from the vehicle battery. VMware NSX Integration Registers the VM-Series firewall as a partner security service on an NSX Manager through service managers and service definitions, auto-generates traffic steering rules, and notifies device groups of virtual machine changes so dynamic address groups stay current. Web Interface Access Provides a browser-based management console over HTTPS on the management interface and other permitted interfaces, with login by password, certificate or single sign-on and message-of-the-day acknowledgement. Web Interface Language Selection Displays the management web interface in the browser language by default and lets an administrator switch it to French, Japanese, Spanish, Simplified Chinese or Traditional Chinese. WildFire Appliance and Cluster Management Adds WildFire appliances to Panorama as standalone nodes or as members of clusters of up to 20 nodes, imports and pushes their configuration, and sets their analysis environment, content update and cloud server settings. Zero Touch Provisioning Onboards a firewall that has never been configured by claiming it with its serial number and printed claim key against a support account and tenant, after which it requests a device certificate on first internet connection and receives its management address and configuration from the ZTP service.
Monitoring, Logging and Reporting Alarms Raises CLI, web and audible alarms when a security rule group is matched above a threshold within a time period, when encryption or decryption failures exceed a count, or when a log database reaches a percentage of its maximum size, and tracks acknowledgement of each alarm. App Scope Reports Charts change in network behaviour over a chosen period through Summary, Change Monitor, Threat Monitor, Network Monitor, Threat Map and Traffic Map views that rank gainers, losers, new and dropped items by session or byte count, plot threats and traffic geographically, drill into the ACC, and export as PNG or PDF. Application Command Center Summarizes applications, users, URLs, threats and content from firewall logs across network activity, threat activity, blocked activity, tunnel, GlobalProtect and SSL tabs of interactive widgets, with local and global filters, sanctioned-application and risk-factor views, drill-down to the underlying logs, custom tabs that can be exported and imported, and PDF export. AutoFocus Intelligence Summary Connects the firewall to an AutoFocus portal so an IP address, URL, filename, user agent, threat name or hash in a log entry opens a summary of threat intelligence findings and statistics for that artifact and an expanded search, with a configurable query timeout. Automated Correlation Engine Matches Palo Alto Networks-authored correlation objects delivered by content updates against traffic, threat, data filtering and URL logs to raise severity-rated correlated events identifying likely compromised hosts, each carrying the match evidence, and aggregates them in the ACC compromised hosts widget. Blocked IP List Lists the source addresses the firewall is currently blocking as a result of a vulnerability protection block-IP action or a classified DoS protection rule, marks whether each is enforced in hardware or software, reports list utilization, and offers a whois lookup per address. Botnet Report Correlates threat, URL and data filtering logs against malware URLs in PAN-DB, dynamic DNS providers, newly registered domains, IRC traffic and unknown applications over a 24-hour window to score each host from one to five for likelihood of botnet infection, with configurable event thresholds and query filters. Custom Reports Builds reports over summary or detailed log databases by selecting columns, time frame, sort and group criteria and a query builder expression, started from a predefined template, run on demand or nightly, and paired with an automatically created log view report. Dashboard Shows firewall state on a widget grid covering software and content versions, interface status, CPU, dataplane and session utilization, HA status, logged-in administrators, configuration locks, ACC risk factor and the most recent threat, config, system, data filtering and URL filtering log entries, with per-administrator widget selection and a selectable refresh interval. Device Telemetry Collects health, performance, configuration and threat metrics on fixed intervals and uploads them to Strata Logging Service in a selected region to power telemetry apps and threat intelligence, with per-category selection, dedicated service routes, transmission status monitoring and a downloadable sample bundle. Email Alerts Emails log events through email server profiles holding up to four servers, using unauthenticated SMTP or SMTP over TLS with a certificate profile and selectable authentication method, per log type and severity, with a customizable message format. Enhanced Application Logs Collects DNS query, HTTP user-agent and DHCP assignment records that are not viewable on the firewall and forwards them through Strata Logging Service to Palo Alto Networks apps such as Cortex XDR and IoT Security, enabled globally and per security rule through a log forwarding profile. External Log Viewing Displays threat, system, policy, agent and configuration logs ingested from an external endpoint security manager into Panorama-managed Log Collectors through a log ingestion profile attached to a Collector Group. HTTP/S Log Forwarding Sends a log-triggered HTTP or HTTPS API request to a third-party service using a server profile with configurable method, TLS version, certificate profile and credentials, and a predefined or custom URI, header, parameter and payload format per log type, and can register IP-tag mappings to User-ID. IoT Device Inventory and Visibility Presents the device inventory IoT Security builds from firewall traffic logs as a summary of top device categories, profiles and operating systems and a searchable asset inventory that accepts bulk CSV or individual static-IP device entries, and ingests DHCP server syslog as enhanced application logs where the firewall is not in the DHCP path. Log Collection and Viewing Records traffic, threat, URL filtering, WildFire submission, data filtering, HIP match, GlobalProtect, IP-tag, User-ID, decryption, tunnel inspection, SCTP, authentication, configuration, system, correlated-event and unified logs locally and presents them as filterable tables with selectable columns, detailed log views, role-based visibility, export, per-type storage quotas and expiration periods. Log Collectors and Collector Groups Manages Dedicated and local Log Collectors and groups of up to 16 of them, configuring their interfaces, RAID logging disks, authentication, certificate-based communication and per-log-type storage quotas and retention, and redistributing logs across collectors and disks. Log Forwarding Card Forwards all dataplane logs from a PA-7000 Series firewall to Panorama, a data lake or a syslog server over dedicated 40G or 80G card interfaces, leaving only management logs on the firewall itself. Log Forwarding Profiles Forwards logs to Panorama or external services through log forwarding profiles whose match lists filter on any log attribute and select syslog, SNMP trap, email or HTTP server profiles per log type and severity, attach to security rules and zones, and can trigger built-in tagging or GlobalProtect quarantine actions. NetFlow Export Exports unidirectional NetFlow Version 9 records for traffic ingressing selected Layer 3, Layer 2, virtual wire, tap, VLAN, loopback and tunnel interfaces to up to two collectors per profile, using standard or PAN-OS enterprise templates that add App-ID and User-ID fields, with configurable active timeout and template refresh rate. Packet Capture Captures packets on the dataplane by filter and processing stage, on threat detection from antivirus, anti-spyware and vulnerability protection profiles as single or extended captures, for named or unidentified applications, for GTP events, and on the management interface through tcpdump, with hardware offload disablement and export for external analysis. Panorama Managed Device Health Monitoring Collects time-trended CPU, memory, session, throughput, logging and environmental metrics from managed firewalls, correlates them with commits and updates, and flags firewalls deviating from their calculated baseline. Panorama SD-WAN Management Defines SD-WAN hub and branch devices and VPN clusters from Panorama, displays path and link health across clusters and sites, and generates application and link performance reports over a configurable period. Predefined Reports Generates about forty daily application, traffic, threat and URL filtering reports viewable by date and exportable to PDF, CSV or XML, with individual reports disableable, a configurable run time and expiration period, and adjustable local report storage capacity. Report Groups and Scheduled Delivery Aggregates up to eighteen predefined or custom report elements into a PDF summary report, combines predefined, custom, summary and log view reports into a report group compiled as one PDF, and emails the group on a daily or weekly recurrence with optional override recipients. SaaS Application Usage Report Produces a two-part PDF comparing sanctioned and unsanctioned SaaS application usage by bandwidth, users and data transferred, flags applications with risky hosting characteristics, and details per-application users, blocked file types, threats and WildFire verdicts by subcategory. Scheduled Log Export Exports the previous day of logs of a selected type as CSV to an FTP or SCP server at a daily start time through named export profiles, with an SCP host-key connection test. Session Browser Lists the sessions currently running on the firewall with the same filtering controls as the log viewer so an administrator can inspect live traffic rather than completed sessions. Session Resource Diagnostics Identifies the sessions consuming the most on-chip packet descriptor per slot and dataplane with their source addresses and App-ID, and ends or permanently discards a chosen session without a commit. SNMP Monitoring and Traps Answers SNMPv2c and SNMPv3 GET requests for system statistics such as interface state, session counts, temperature and uptime, and forwards logs as traps to up to four SNMP managers per profile, using published standard and Palo Alto Networks enterprise MIBs. Syslog Monitoring Sends every log type to up to four syslog servers per profile over UDP, TCP or TLS in BSD or IETF format with a selectable facility and optional client authentication, and documents the field layout and severity mapping of each log type for custom log and event formats. Transceiver Monitoring Reports digital optical monitoring diagnostics for installed transceivers on supported hardware, including temperature, supply voltage, bias current, transmit power and receive power, through CLI summary and detail commands. Unified Incident Framework Raises and clears predefined incidents for firewall and Cloud NGFW faults across hardware and drive failures, resource and capacity thresholds, HA and management connectivity loss, certificate and license expiry, outdated content, and tunnel and routing failures, each carrying an incident code, severity, category and threshold-based raise and clear conditions, presented in a single incidents view. User and Group Activity Reports Reports the application and web activity of a named user or user group from User-ID data, including URL categories, optional detailed browsing logs and an estimated browse time derived from configurable average browse time and page load thresholds.
Threat Prevention and Security Profiles Advanced IP Defense Profiles Evaluates session source or destination IP addresses against cloud-delivered dynamic IP attributes and direct-to-IP detection rules, caches verdicts locally, and alerts, blocks or denies matching traffic at the security zone. Anti-Spyware Profiles Detects command-and-control and spyware traffic using severity- and category-based signature policies, DNS security signatures and domain sinkholing, with per-signature exceptions, IP exemptions and packet capture. Antivirus Profiles Scans traffic per protocol decoder for viruses and sets separate actions for standard signatures, WildFire signatures and WildFire inline ML detections, with application and signature exceptions and optional hold for real-time signature lookup. Content-ID and URL Filtering Settings Sets Content-ID behaviour including URL continue and admin override timeouts and per-virtual-system override passwords with transparent or redirect delivery, category lookup holding and timeout, trailing-slash handling for custom categories, private PAN-DB servers, HTTP/2 connection logging, and the transport used for inline cloud analysis submissions. Custom Data Patterns Defines the sensitive content that data filtering profiles scan for as predefined patterns such as credit card and social security numbers, regular expressions evaluated by a classic or enhanced pattern-matching engine, or file property and value matches, scoped to selected file types. Custom Spyware and Vulnerability Signatures Defines spyware and vulnerability signatures in the firewall's own threat ID ranges from regular expression patterns over protocol decoder contexts, with severity, direction, affected system, CVE and vendor references, a default action and an optional threshold per interval, for use in Anti-Spyware and Vulnerability Protection profiles. Custom URL Categories Defines named URL categories as a list of URLs entered or imported from a text file with wildcard support, or as a category match of two to four existing categories, for use in URL filtering profiles and as policy rule match criteria. Data Filtering Profiles Scans allowed traffic for configured data patterns such as credit card or social security numbers and blocks or alerts when thresholds are exceeded, optionally capturing the matched data. DoS Protection Profiles and Policy Rules Applies flood thresholds and maximum concurrent session limits to named critical resources through DoS Protection policy rules matched on zone, interface, address, user and service with a protect, allow or deny action, using aggregate profiles that count a whole group or classified profiles that count each device, and placing offending addresses on the block list for a block duration. Enterprise DLP Cloud File Scanning Uploads files to the Enterprise Data Loss Prevention cloud service for scanning with configurable maximum latency and file size and an allow or block action when either is exceeded or an upload error occurs, and logs files that could not be scanned. File Blocking Profiles Blocks, alerts on, or prompts users to continue when specified file types are uploaded or downloaded by a given application in a given direction. HTTP Header Logging Captures selected or all HTTP request and response headers and response status codes in URL filtering logs on decrypted traffic, with per-header length limits and truncation controls. L3 and L4 Header Inspection Detects vulnerabilities in IP, IPv6, ICMP, ICMPv6, TCP and UDP headers using custom rules defined in a Zone Protection profile, each with its own threat ID, log severity and interval, CVE and vendor references, packet capture setting, exempt addresses and an allow, alert, drop or reset action, enabled globally and per security zone. Mobile Network Protection Performs stateful inspection and protocol validation of GTPv1-C, GTPv2-C, GTP-U, PFCP and 5G HTTP/2 traffic, inspects user data inside GTP-U tunnels, filters sessions by APN, IMSI and RAT, and prevents end-user IP spoofing. Non-IP Protocol and Security Group Tag Protection Blocks or allows non-IP protocols such as LLDP, Spanning Tree and GOOSE between and within Layer 2 and virtual wire zones through an include or exclude list of up to sixty-four EtherTypes, and drops Cisco TrustSec frames carrying Layer 2 security group tags listed in an exclude list. Packet Buffer Protection Defends existing sessions that overwhelm the dataplane packet buffer by applying random early drop when buffer utilization or dataplane latency crosses alert and activate thresholds, then discarding the session or blocking the source address for a block duration once the block hold time expires, configured globally and enabled per ingress zone. Packet-Based Attack Protection Inspects IP, TCP, ICMP, IPv6 and ICMPv6 headers at the ingress zone and drops packets with undesirable characteristics such as malformed, spoofed, source-routed, split-handshake and mismatched overlapping segments or strips options such as the TCP timestamp, optionally generating a threat log for each drop. PAN-OS Shield Inspects inbound control traffic destined for the management plane for vulnerability exploits in a dedicated internal virtual system, using a read-only vulnerability protection profile and security policy delivered by content updates, generating threat logs on a match and accepting per-threat-ID exceptions with their own action and packet capture settings. Reconnaissance Protection Detects TCP and UDP port scans, host sweeps and IP protocol scans against a zone using an event count and interval threshold, then allows, alerts or blocks the source for a set duration tracked by source or by source and destination, with up to twenty addresses excluded for internal penetration testing. SCTP Protection Validates and filters SCTP chunks against RFC conformance, filters by operation code and payload protocol identifier, limits IP addresses per multi-homed endpoint, and logs SCTP events. Security Profile Groups Combines antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking and data filtering profiles into a named group that can be attached to a security policy rule as a unit. Software and Runtime Integrity Enforcement Runs Integrity Measurement Architecture in enforcement mode so only binaries cryptographically signed by Palo Alto Networks execute and modification of PAN-OS binaries is blocked, logs each violation as a critical system log, runs software integrity checks at boot and on a schedulable daily time, and either keeps running or reboots to maintenance mode on a violation. Threat Signature Details and Threat Vault Lookup Opens a threat details view from a threat log, ACC threat activity or an anti-spyware or vulnerability protection profile showing the signature name, ID, severity, CVE reference and current exception state, and looks the signature up in the Palo Alto Networks Threat Vault database. Tunnel Content Inspection Inspects the contents of cleartext GRE, GTP-U, non-encrypted IPSec and VXLAN tunnels, including tunnels nested inside other tunnels, so security, DoS protection and QoS policy apply to the inner traffic. URL Filtering Profiles Sets per-category site access and user credential submission actions across predefined, custom and external-dynamic-list URL categories, and enforces strict safe search on supported search engines. URL Inline Categorization Analyses web page contents in real time using firewall-local machine learning models and optional cloud analysis to detect phishing variants and JavaScript exploits, with URL exceptions. User Credential Detection Detects submissions of valid corporate credentials to web pages using IP-to-user, group-mapping or domain-credential matching and blocks submission to untrusted URL categories. Vulnerability Protection Profiles Applies signature collections that detect buffer overflows, illegal code execution and other exploit attempts against client and server vulnerabilities, with per-severity actions and per-signature exceptions. WildFire Sample Analysis Forwards unknown files and email links matched by a WildFire Analysis profile to the WildFire public, regional or private cloud for detonation, returns a malicious, phishing, grayware or benign verdict recorded in the submissions log, and retrieves the resulting signatures, with the unlicensed tier limited to portable executables and daily signature delivery. Zone Flood Protection Measures new connections per second entering an ingress zone for SYN, UDP, ICMP, ICMPv6 and other IP floods against alarm, activate and maximum thresholds in a Zone Protection profile, mitigating with random early drop or, for SYN floods, with SYN cookies.
Authentication and Certificate Management Authentication Policy and Portal Evaluates authentication policy rules before security policy to challenge end users through Authentication Portal and MFA login pages, applies per-rule and per-factor timeouts from recorded timestamps, and feeds the resulting identity to User-ID. Authentication Profiles and Sequences Defines per-user-set authentication settings in an authentication profile bound to a local or external service, and chains profiles into a sequence the firewall walks until one authenticates the user. Authentication Testing and Diagnostics Tests an authentication profile against a real username and password from the candidate configuration before commit, and reports locked accounts, pending requests and per-server request statistics for troubleshooting. Certificate Generation and Lifecycle Generates self-signed root CA and leaf certificates with RSA, ECDSA or post-quantum key algorithms, requests certificates from an external CA by CSR, imports certificates and private keys from an enterprise CA, and exports, renews and revokes them. Certificate Profiles Binds a set of CA certificates, username field mapping and revocation-checking behaviour to a service so certificates presented for that service are validated and non-conforming sessions are blocked. Certificate Revocation Checking Verifies certificate revocation status through cached CRLs or OCSP with OCSP preferred and CRL as fallback, can act as an OCSP responder itself, and can route status checks through a web proxy. Default Trusted CA Store Ships a preinstalled store of well-known certificate authority certificates, updated with major PAN-OS releases, whose entries can be reviewed, enabled, disabled or exported. Device Certificate for Cloud Services Installs and automatically renews a 90-day device certificate fetched from the Customer Support Portal that authenticates the firewall to Palo Alto Networks cloud services, with manual restoration when renewal fails. External Authentication Services Authenticates administrators and end users against external LDAP, RADIUS, TACACS+ and Kerberos servers through server profiles, using vendor-specific attributes to assign administrator roles and access domains, with configurable connection timeouts and retries. FIPS-CC Operational Mode Switches the appliance into a FIPS 140-2/140-3 and Common Criteria mode that enforces TLS 1.2 access, minimum password length, lockout, idle and absolute session limits and restricted cryptography, and can scrub swap memory before decommissioning. Hardware Security Module Key Storage Stores and generates private keys used for SSL forward proxy and inbound inspection on an external HSM, optionally encrypts the master key with an HSM-held wrapping key, and manages the HSM client connection and its high availability. Kerberos Single Sign-On Authenticates administrators and Authentication Portal users from an existing Kerberos V5 login using a keytab, falling back to another configured service when single sign-on fails. Local Authentication Authenticates administrators and end users against accounts held on the firewall, either in a local user database of users and groups with plaintext or hashed passwords, or as administrative accounts without a database. Master Key Encryption Encrypts all private keys and passwords in a configuration with a master key, including per-tenant custom keys configured and synchronized centrally through Strata Cloud Manager with bootstrap deployment, rotation tracking, grace period and auto-renew settings. Multi-Factor Authentication Challenges users for additional authentication factors after the first, integrating with MFA vendors through RADIUS or vendor APIs and recording a separate timestamp per vendor for authentication policy timeouts. Passwordless Authentication Delegates a Kerberos ticket on behalf of an already-authenticated user through a delegation profile so users reach applications matched by a custom URL category without logging in again. Private Key Export Blocking Permanently prevents export of a private key at the moment its certificate is generated or imported, including for IKE gateway certificates, so no administrator including a superuser can extract it. Quantum Key Distribution Retrieves quantum-safe encryption keys for IPSec VPN connections from key management entity appliances through QKD profiles that carry the KME URL, the firewall security application entity ID and the local, CA and KME certificates used to authenticate the connection. SAML Authentication Authenticates administrators and end users through a SAML 2.0 identity provider with signed messages, metadata-based registration, single sign-on and single logout, and SAML attributes that assign administrator roles and access domains. SCEP Certificate Enrollment Automates issuance of unique client certificates from an enterprise SCEP server through a SCEP profile with optional fixed or dynamic challenge-response, for GlobalProtect users and inter-device authentication. SSH Service Profiles Restricts the ciphers, key exchange algorithms and message authentication codes offered on management and high-availability SSH connections, regenerates host keys, and sets session rekey thresholds. SSL/TLS Service Profiles Defines the server certificate, allowed TLS protocol versions and cipher suites for connections to firewall-hosted services such as the management interface, Authentication Portal and GlobalProtect portals and gateways. TACACS+ Accounting Sends RFC 8907 start, stop and update accounting records for administrative sessions to a TACACS+ accounting server defined in a dedicated accounting server profile.
Security Policy and Objects Address Objects and Address Groups Names IPv4 and IPv6 addresses, ranges, subnets, FQDNs and wildcard masks as reusable address objects, and collects them into static address groups or into dynamic address groups whose membership is resolved at match time from tag-based filters. Device Objects and Device Dictionary Holds the device metadata that Device-ID policy matches on — category, profile, model, vendor, OS and OS family for legacy device objects, and IoT Security-defined matching criteria for Advanced Device-ID objects — kept current through Device-ID content updates, with local Advanced Device-ID objects clearable when unused. Device Quarantine List Holds compromised devices identified by host ID, with serial number, reason, source and timestamp, so GlobalProtect blocks them from connecting to a gateway, and supports adding, listing and removing entries. Dynamic User Groups Defines a policy source-user group whose members are resolved from boolean tag match criteria rather than a directory, with users registered against tags from a chosen source and an optional timeout that removes them again. External Dynamic Lists Imports lists of IP addresses, URLs, domains, IMEIs or IMSIs from a web server or from Palo Alto Networks predefined feeds and makes them referenceable in policy rules, URL filtering profiles and DNS sinkholes, refreshing them on a configured interval. Host Information Profile Objects and Profiles Matches endpoint posture reported by the GlobalProtect app against HIP objects covering host information, mobile device state, patch management, firewall, anti-malware, disk backup, disk encryption, data loss prevention, certificates and custom registry, plist and process checks, combines them into boolean HIP profiles used as security rule match criteria, and notifies users on match or mismatch. IoT Security Policy Rule Recommendations Lists the security policy rules IoT Security derives from observed device-profile behaviour, imports selected rules into a chosen virtual system or device group before or after local rules, tracks which were imported and updated, and removes the policy mapping when it is no longer wanted. Mobile Network Subscriber and Equipment Objects Defines named IMSI subscriber and IMEI equipment objects, individually or as groups of up to 5,000 members, so mobile subscribers and handsets can be referenced directly in security policy rules. Panorama Device Groups and Shared Policy Groups managed firewalls and virtual systems into a hierarchy of up to four nested device group levels and pushes shared and per-group pre-rules, post-rules and overridable default rules to them, with a combined rules preview before the push. Policy Rule Audit Comment Archive Records an audit comment on each policy rule change and displays the comment history, the configuration logs generated between commits, and a comparison of two rule configuration versions. Policy Rule Usage and Hit Counts Counts and timestamps traffic matches per security, NAT, QoS, policy-based forwarding, decryption, tunnel inspection, application override, authentication and DoS protection rule so unused or over-provisioned rules can be found, filtered, reset, and deleted, disabled, enabled or tagged in place. Policy Rulebase Hygiene Controls Requires a tag, description or audit comment matching a regular expression on every new or edited policy rule and optionally fails the commit when they are missing, and selects how overlapping wildcard-mask source and destination addresses are matched. Policy Schedules Defines daily, weekly or non-recurring date and time ranges and applies them to security policy rules so a rule is in effect only during those windows. Region Objects Selects built-in countries or defines custom regions from IP address ranges and geographic coordinates for use as source and destination match criteria in security, decryption and DoS policy rules. Rulebase Group Tag Views Displays a policy rulebase grouped by group tag while preserving evaluation order, and moves, reorders, clones, deletes or appends every rule in a selected tag group as a unit. Security Policy Rules Evaluates traffic top-down against security rules matching on zone, address, user, application, service and URL category, allows or denies it with the configured action and attached profiles, and supports intrazone, interzone and universal rule types plus overridable predefined default rules. Service Objects and Service Groups Defines named TCP and UDP port and port-range objects, combines them into service groups, and uses them to restrict which ports an application may run on in a policy rule. Tags Creates named, colour-coded tags and applies them to address objects, address groups, applications, zones, services and policy rules for sorting, filtering and visual grouping. VM Information Sources Polls VMware ESXi and vCenter servers, AWS VPCs and Google Compute Engine projects for guest attributes and registers up to thirty-two tags per IP address so dynamic address groups follow workloads as they are created and changed, with per-source update intervals, disconnect timeouts and connection status.
High Availability and Clustering Active/Active Address Sharing and Redundancy Shares gateway addressing across an active/active pair using floating IP addresses with virtual MAC addresses that move on failure or can be bound to the active-primary firewall, ARP load-sharing in which each peer answers a hashed or modulo subset of ARP requests, or route-based redundancy that advertises each peer's own address through OSPF or BGP. Active/Active NAT Device Binding Binds a NAT rule to one device ID or to both in an active/active pair so each peer translates with its own source address pool, or so both peers answer ARP requests for a shared destination NAT address. Active/Active Session Ownership and Setup Splits per-session work across an active/active pair by electing a session owner that performs Layer 7 inspection and logging and a session setup firewall that performs Layer 2 to Layer 4 setup, selected by first packet, primary device, IP modulo or IP hash and exchanged over the HA3 link. HA Clustering Joins up to sixteen firewalls, which may themselves be HA pairs or standalone, into a Layer 3 or virtual wire cluster that synchronizes all sessions over an HA4 link when a member joins and fails sessions over to another member, with per-platform member limits and configurable synchronization timeout and monitor hold-down. HA Configuration and Runtime Synchronization Synchronizes committed configuration and runtime state such as sessions, forwarding tables, IPSec security associations and ARP tables between peers, while leaving management, service, SNMP and other per-device settings to be configured on each firewall separately. HA Link and Path Monitoring Declares failover conditions by grouping physical interfaces into link groups and destination IP addresses into path groups per virtual wire, VLAN, virtual router or logical router, each with any-or-all failure conditions, ping interval and ping count. HA Links and Backup Links Carries HA traffic over an HA1 control link, HA2 data link, HA3 packet-forwarding link and HA4 cluster link with backup links for each, using dedicated HA, HSCI or auxiliary ports where the platform has them and data or management ports where it does not, with selectable Ethernet, IP or UDP transport. HA Suspend and Failover Verification Suspends HA on a peer for maintenance or failover testing and returns it to a functional state from the firewall's operational commands or from Strata Cloud Manager, with peer state visible in the high availability dashboard widget. HA Timer Profiles Sets the heartbeat, hello, promotion, preemption, monitor-fail hold and flap-max timers that govern failure detection and failover through a Recommended, Aggressive or Advanced profile whose defaults vary by hardware model. High Availability Pairs and Failover Runs two firewalls as an active/passive or active/active pair that share a group ID and virtual MAC addresses, move through defined HA states, and fail over on heartbeat loss, link or path failure, monitor hold-down expiry or device-priority preemption, configured from PAN-OS, Panorama or Strata Cloud Manager. Hyperscale Security Fabric Fronts a pool of auto-scaling VM-Series dataplane nodes with fixed-capacity gateway nodes that both inspect traffic and distribute it across the pool without an external load balancer, failing sessions over to healthy instances, scaling instance count on session utilization, upgrading in a rolling sequence with rollback, and appearing as one cluster in Panorama. NGFW Cluster MACsec Encryption Encrypts and integrity-protects the HSCI inter-firewall links between NGFW cluster nodes with 802.1AE MACsec, using a crypto profile that sets the cipher, confidentiality offset, anti-replay window and SAK rekey interval and a pre-shared key profile whose CKN and CAK must match on both ends of each link. NGFW Cluster Summary and Monitoring Reports cluster and per-node state, config and node-flow-table sync status, throughput, connections per second, session count, dataplane and management CPU and memory, logging rate and interconnect status from Panorama, and sets the minimum functional network and data processing cards below which a node moves to degraded or failed state. NGFW Cluster Template Migration Converts an existing Panorama non-clustering template and the device groups referencing it into a clustering template whose interface references become cluster Ethernet interfaces, so a firewall's configuration can move onto clustered PA-7500 Series nodes. NGFW Clustering Pairs two PA-7500 or PA-5500 Series firewalls over HSCI links into a single logical device with dual active dataplanes and one active control plane that neighbours see as one Layer 2 or Layer 3 node, supports multichassis link aggregation and fails over in under a second, configured through Panorama with a clustering plugin. Panorama High Availability Pairs two Panorama management servers as primary and secondary with encrypted management-link communication, configurable monitor hold and election timers, preemption and path monitoring.
User and Device Identification Client Probing Probes Windows clients over WMI at a configurable interval, and on demand for an unmapped address, to confirm or obtain the logged-in username, disabled by default and advised against on high-security networks. Cloud Identity Engine Sources user, group and device attributes from on-premises or cloud directories through a Cloud Identity Engine instance for user- and group-based policy enforcement, refreshing on a configured interval. Directory Server Monitoring for User Mapping Reads login events from the security logs of Active Directory domain controllers, Microsoft Exchange servers and Novell eDirectory servers over WMI, WinRM with basic authentication or WinRM with Kerberos to map IP addresses to usernames, with automatic domain controller discovery by DNS and a configurable polling frequency. Group Mapping Queries LDAP directories through an LDAP server profile to build and periodically refresh a local user-to-group mapping table, selects the primary username and alternate username, email and group attributes, limits which groups are available in policy through an include list, and defines custom groups from LDAP filters. PAN-OS Integrated User-ID Agent Performs the same user mapping collection as the Windows agent directly on the firewall against servers defined in its own server monitoring list, using a service account for server access and a certificate profile for connection security, without deploying any external agent. Syslog-Sourced User Mapping Parses login and logout messages from wireless controllers, 802.1x devices, proxies and other authenticating services with regex or field-identifier Syslog Parse profiles, predefined or custom, to create and delete user mappings, listening over SSL or UDP on an interface enabled for the User-ID syslog listener. Terminal Server User Mapping Identifies individual users on multi-user systems that share one IP address by allocating each user a source port block, through the Terminal Server agent installed on Windows and Citrix servers or through XML API multi-user-system messages for other platforms, so policy matches on an IP address, port and user mapping. User and Group-Based Policy Enforcement Matches security rules on specific users and groups or on the known-user and unknown categories once User-ID is enabled on a zone, and shows the resolved username in traffic logs and user activity reports. User Mapping Scope Controls Restricts which subnetworks User-ID maps through include and exclude network lists and suppresses mapping for named accounts such as kiosks through an ignore user list of up to five thousand wildcard-capable entries. User-ID Data Redistribution Shares IP-to-user mappings, IP tags, user tags, HIP data, quarantine lists and authentication timestamps between firewalls, Panorama and Windows agents acting as redistribution agents and clients over a defined number of hops, filtered by included and excluded networks and secured with custom certificates. User-ID Hub for Virtual Systems Designates one virtual system as a hub that holds the User-ID sources and shares its IP-to-username and user-to-group mappings with the other virtual systems on the firewall, which query the hub only when a local mapping is absent. User-ID Verification and Diagnostics Verifies that mapping works by listing current IP-to-user mappings and their source, group mapping and agent statistics, monitored server connection status and per-user collected attributes, refreshes the group mapping cache on demand, and traces the redistribution path a mapping travelled. Windows Log Forwarding and Global Catalog Aggregation Reduces the number of User-ID agents a large directory needs by collecting login events from many domain controllers on a single Windows event collector the agent monitors, and by reading group membership from Global Catalog servers instead of individual domain controllers. Windows-Based User-ID Agent Runs User-ID collection as a Windows service on a domain member server that monitors up to a hundred servers and forwards the resulting mappings to connected firewalls, authenticated to each firewall with a certificate profile, and adds a credential service component installed on a read-only domain controller for credential-phishing detection with one agent per domain or forest. X-Forwarded-For User Attribution Extracts the originating client address from the X-Forwarded-For header when a proxy sits between users and the firewall so User-ID maps that address to a username for policy and logging, optionally zeroing the header value after use. XML API User Mapping Ingest Accepts login, logout and group membership messages posted to the firewall as XML so systems with no native User-ID integration, such as third-party VPNs and 802.1x wireless networks, can supply and withdraw IP-address-to-username mappings.
Application Identification (App-ID) App-ID Cloud Engine Downloads a cloud-delivered catalog of App-IDs for applications that would otherwise be identified as ssl or web-browsing, requests full signatures from the cloud on first sighting, and makes those App-IDs usable in security policy rules. App-ID Traffic Classification Identifies the application behind a session using application signatures, protocol decoding and heuristics rather than port or protocol, re-applies signatures to decrypted flows, and detects applications tunneled inside other protocols. App-ID Update Safeguard Records a Previous App-ID attribute for reclassified applications and performs a secondary policy lookup against it so a content update does not silently block traffic, with ACC widgets showing which rules and applications rely on it. Application Dependency Resolution Allows applications that a permitted application depends on implicitly where the firewall can determine them, and surfaces unresolved dependencies during rule creation and commit so they can be added to the rule. Application Level Gateways Acts as an application-level gateway for dynamic-port applications by opening temporary pinholes and rewriting NAT payloads, with per-application ALG disablement for SIP, SCCP, Teredo and Unistim. Application Objects, Groups and Filters Groups applications into reusable application objects, application groups and dynamic application filters built from category, subcategory, risk, characteristic or content-delivered and custom tags, and uses them as match criteria in policy rules. Application Override Policy Bypasses App-ID classification for traffic matching a zone, address, protocol and port and assigns it a specified custom or predefined application instead. Application-Default Port Enforcement Restricts an allowed application to the ports Palo Alto Networks defines as its defaults by setting a rule's service to application-default, differentiating encrypted from cleartext variants of the application. Custom and Unknown Application Handling Defines custom application signatures with their own characteristics, ports and timeouts for internal applications, and controls traffic the firewall reports as unknown TCP, UDP or non-syn-TCP. HTTP Header Insertion Inserts predefined or custom HTTP headers, including the authenticated username and domain, into requests to nominated domains from a URL filtering profile so SaaS applications restrict access to sanctioned tenants. HTTP/2 Inspection Classifies and enforces policy on HTTP/2 traffic stream by stream when decryption is enabled, and can be turned off for targeted traffic by stripping ALPN or disabled globally. New and Modified App-ID Management Reviews the App-IDs a content release introduces or changes, shows which policy rules they affect, disables or enables individual or all new App-IDs, previews upcoming App-IDs as threat signature indicators, and matches the newest App-IDs with a New App-ID rule characteristic. Policy Optimizer Identifies port-based and over-provisioned security rules from observed application usage and migrates them to application-based rules by cloning, matching usage or adding applications, and reports apps allowed against apps seen per rule. SaaS Policy Recommendation Import Imports security policy rule recommendations pushed from SaaS Security, creating the referenced application groups, tags and HIP profiles, and tracks updated or deleted recommendations against the local rulebase. Service-Based Session Timeouts Overrides an application's default session timeout for traffic matching a rule by setting custom TCP, UDP and TCP half-closed timeouts on the service object the rule uses.
Administrative Access and Multi-tenancy Admin Role Profiles Defines custom administrative roles that enable, disable or make read-only each area of the web interface, REST API, XML API and CLI, scoped to the whole device or to specific virtual systems, including commit and validate rights, operations privileges and end-user privacy restrictions on logs and reports. Administrator Access Domains Restricts an administrator to a named set of virtual systems by returning an access domain from a RADIUS, TACACS+ or SAML server through vendor-specific attributes, ignored when administrators are authenticated locally. Administrator Activity Auditing Generates an audit log for every web interface navigation and CLI operational command an administrator performs and forwards it to a syslog server. Administrator Login Activity Indicators Shows the last successful login and a summary of failed login attempts with account, reason, source address and time so an administrator can spot credential misuse or brute-force attempts. API Key Lifetime and Revocation Sets an expiry period for the API keys that authenticate XML and REST API calls, makes regenerated keys unique, and expires all currently valid keys at once when they may be compromised. Certificate-Based Administrator Authentication Authenticates administrators to the web interface with client certificates validated against a certificate profile instead of a username and password. Configuration and Commit Locks Takes a config or commit lock, optionally scoped to a virtual system or the shared location and annotated with a comment, that blocks other administrators from changing or committing the candidate configuration until released. Firewall Administrator Accounts Creates per-person administrative accounts with a predefined dynamic role such as superuser, deviceadmin or devicereader or a custom role, an authentication method, password profile and a limit on concurrent administrative sessions. Inter-Virtual-System Communication Passes traffic between virtual systems inside the firewall through an external zone per virtual system that is made visible to its peers, with each direction requiring its own security rule and each transit consuming two sessions. Password Profiles and Complexity Requirements Sets per-account password change periods, expiration warnings, post-expiration login counts and grace periods through password profiles, over a device-wide minimum password complexity policy, with defined username and password character rules that reject commonly used passwords. Shared Gateway Lets several virtual systems reach the internet over one shared interface and IP address without the App-ID and security policy evaluation another virtual system would add, supporting NAT and policy-based forwarding but not security, DoS, QoS, decryption, application override or authentication policy. SSH Key Administrator Authentication Authenticates administrators and automated scripts to the CLI with Ed25519 or RSA public keys imported onto the account, with a configurable fallback authentication method. Virtual Systems Divides one firewall into separately administered logical firewalls, each with its own interfaces, zones, policies, objects, certificates, server profiles, User-ID and logs, with per-virtual-system limits on sessions, each rule type and VPN tunnels, shared objects that apply to all of them, and a base number of instances per platform extendable by license.
Automation, API and CLI API Authentication Authenticates API requests with a key generated from administrator credentials and passed in the X-PAN-KEY header or as a query parameter, or with basic authentication, and can encrypt the key with a self-signed device certificate so keys are invalidated when the user, password, certificate or lifetime changes. API Exploration Tools Shows the request types, nodes and XPaths of the XML API in a browser at the firewall's api endpoint and prints the XML API equivalent of any CLI command when CLI debug mode is on. Dynamic Tag Registration Registers and unregisters IP-address-to-tag and username-to-tag mappings through the API, with an optional timeout of up to thirty days, so dynamic address groups and dynamic user groups gain and lose members without a configuration change or commit. PAN-OS Command-Line Interface Provides an SSH or serial command line with operational and configuration modes, hierarchy browsing, keyword command search and inline syntax help, selectable default, set, XML or JSON output, a scripting mode for pasted configuration, full and partial commits, XPath-based partial configuration loads, and SCP import and export of configurations and log databases. PAN-OS REST API Provides versioned JSON or XML CRUD endpoints for objects, policy rules, network and device resources on the firewall and Panorama, scoped by location, virtual system or device group query parameters, with a self-hosted reference document and structured error responses, leaving the commit to the XML API. PAN-OS XML API Exposes almost all firewall and Panorama functionality over HTTPS through typed requests for key generation, configuration, commit and commit-all, operational commands, reports, logs, file import and export and User-ID updates, addressing configuration by XPath with set, edit, delete, rename, clone, move, override and multi-object actions, and returning a job ID for long-running requests.
Decryption and TLS Inspection Decryption Exclusions Leaves traffic encrypted for hostnames matched by wildcard against the client SNI or server certificate common name, through a Palo Alto Networks-maintained predefined exclusion list delivered by content updates whose individual entries can be disabled, and custom exclusions defined by hostname or by application, source, destination, URL category or service. Decryption Policy Matches traffic by zone, address, user, service and URL category and decrypts it as SSL Forward Proxy, SSL Inbound Inspection or SSH Proxy, or exempts it, attaching a decryption profile and controlling handshake logging. Decryption Port Mirroring Copies decrypted traffic out of a dedicated Decrypt Mirror interface to an external packet collection tool for archiving, forensics or data loss prevention, enabled by a free license and configured per decryption profile with an option to mirror only traffic forwarded after security policy enforcement. Decryption Profiles Blocks or allows sessions the firewall decrypts or deliberately does not decrypt based on server certificate expiry, issuer trust, revocation status and name mismatch, on unsupported TLS versions, cipher suites and client authentication, on SSH version and algorithm errors, and on decryption resource availability, with protocol version bounds and algorithm selection per profile. Forward Proxy Certificate Generation Generates an impersonation certificate for each SSL forward proxy session by copying the destination server certificate, with the key size and hashing algorithm either derived from the destination or pinned to a configured size. SSL/TLS Handshake Inspection Sends SSL/TLS handshake messages to the content and threat detection engine so URL category policy is enforced during the handshake of a decrypted session and the connection is reset before a response page would be served.
The firewall operating system, documented as per-version administration guides separate from the current NGFW tree.
Networking & Traffic Delivery Aggregate Interface Groups Combines up to eight Ethernet interfaces into one 802.1AX aggregate group that load balances traffic and survives member failure, optionally running LACP in active or passive mode with fast or slow transmission, hot-spare standby members and high-availability port priority. BGP Runs interior and exterior BGP with peer groups and peers, MD5 authentication, keepalive, hold and advertisement timers, import and export route policies, route aggregation, conditional advertisement, route flap dampening, graceful restart, route reflection, confederations, maximum-prefix limits and redistribution from static, connected, OSPF and RIP routes. Bidirectional Forwarding Detection Detects failure of the bidirectional path to a routing peer faster than link monitoring by exchanging control packets at negotiated intervals, applied through profiles to static routes and to BGP, OSPF, OSPFv3 and RIP globally or per interface, with active and passive modes, detection multipliers, hold time, and single-hop and BGP multihop operation. Bonjour Reflector Forwards Apple Bonjour multicast DNS advertisements and queries between selected Layer 3 Ethernet and aggregate interfaces and subinterfaces so segmented networks can still discover devices and services regardless of TTL limits. Cellular Firmware Updates Downloads carrier-specific modem firmware from the update server or support portal and installs it on a chosen cellular interface immediately or on a schedule, with high-availability peer synchronization and per-interface version verification. Cellular Interfaces Provides a primary or backup internet connection over 5G with automatic fallback to 4G or 3G on integrated-modem platforms, with primary and secondary SIM slots, PIN protection and switchover, APN/DNN profiles with CHAP or PAP authentication, IPv4 and IPv6 addressing, SD-WAN participation, weighted round-robin load balancing, and views for signal, modem, network and location detail. DHCP Server, Relay and Client Runs an interface as a DHCPv4 server with automatic, reserved and fixed address allocation, lease control and predefined or custom options including 43, 55 and 60 with multiple values, as a DHCP relay agent for IPv4 and IPv6, or as a DHCPv4 or DHCPv6 client with prefix delegation on data and management interfaces, and reports server and client lease and address state. DNS Proxy Acts as a DNS server for selected interfaces by answering from a proxy cache and otherwise forwarding each query to the DNS server matched by proxy rules, domain FQDN matching or static entries, with per-virtual-system or shared proxy objects and DNS server profiles that set the servers, inheritance source and source address used for firewall-originated queries. Dynamic DNS Registration Registers a changing interface IPv4 or IPv6 address with a dynamic DNS provider such as DuckDNS, DynDNS, FreeDNS Afraid.org or No-IP on a configured update interval and certificate profile so clients keep resolving the firewall and the services behind it. Fail-to-Wire Bypass Puts paired interfaces on ruggedized firewall models into a bypass state so traffic keeps flowing through the device when the firewall loses power or fails, enabled or disabled per interface. GRE Tunnels Terminates point-to-point GRE tunnels on a tunnel interface over IPv4 or IPv6 transport with a configured tunnel key, keepalive interval and retry count and TTL and type-of-service handling, so traffic can be routed or forwarded into a partner or cloud network. Interface Management Profiles Restricts which management services — ping, HTTP, HTTPS, SSH, Telnet, SNMP and others — a Layer 3 interface or the management interface answers, and limits the source addresses permitted to reach them. Interfaces and Security Zones Configures physical and logical interfaces as Layer 2, Layer 3, virtual wire, tap, VLAN, loopback, tunnel or aggregate types and groups them into security zones that policy rules are enforced between, with optional zone protection profiles, packet buffer protection and User-ID and Device-ID access control lists per zone. IPv4 Multicast Routing Forwards IPv4 multicast using PIM with static and candidate rendezvous points, group permission access lists, designated-router priority, neighbor filters, source-specific multicast ranges and shortest-path-tree thresholds, IGMPv2 and IGMPv3 receiver interfaces with group filters and per-interface group and source limits, and static multicast routes. IPv6 Neighbor Discovery Provisions IPv6 hosts through router advertisements carrying recursive DNS server and DNS search list options so hosts resolve names without a separate DHCPv6 server, and maintains the neighbor discovery cache the firewall uses to reach IPv6 neighbors. Large Scale VPN Provisions hub-and-spoke IPSec VPNs between a portal and satellite firewalls without per-tunnel configuration, distributing gateway lists, certificates and routes to satellites that authenticate by username and password, satellite cookie, or serial number and IP address. LLDP Exchanges Link Layer Discovery Protocol data units with neighboring devices to advertise and learn chassis, port, system and management-address TLVs, stores them in MIBs an SNMP manager can read, and raises syslog messages and SNMP traps on neighbor changes, with per-interface profiles and clearable statistics. Logical and Virtual Routers Maintains separate routing information bases per router, as virtual routers on the legacy engine or logical routers on the Advanced Routing Engine, assigning interfaces, per-protocol administrative distances, equal-cost multipath with round-robin, hash, modulo or weighted selection, symmetric return options and route-map filtering, with a guided migration from virtual to logical routers. Multicast Source Discovery Protocol Peers rendezvous points across multicast domains over TCP to exchange Source-Active messages about locally known multicast sources, with MD5 authentication, keepalive and connection-retry timers, per-peer source-active caps and inbound and outbound source-active filters. Multiprotocol BGP Extends BGP to carry IPv6 unicast prefixes and IPv4 multicast routes and to peer over IPv6 addresses, maintaining separate unicast and multicast route tables that import, export, conditional advertisement, redistribution and aggregation rules can each target. NAT Policy Rules Translates source and destination addresses and ports through ordered NAT rules matched on zone, interface, address and service, supporting static IP, dynamic IP and dynamic IP-and-port source translation with persistent and fallback options, destination translation with port forwarding and DNS rewrite, bi-directional and U-turn translation, NAT exemption, and proxy ARP for translated pools. NAT64 Translates bidirectionally between an IPv6-only network and IPv4 hosts for IPv6-initiated and IPv4-initiated sessions with or without port translation, resolves IPv4-embedded IPv6 addresses through a DNS64 server, drops hairpinning loop attacks, and performs path MTU discovery across the translation. Network Packet Broker Forwards selected decrypted TLS, non-decrypted TLS and non-TLS traffic out dedicated interface pairs to chains of third-party security devices, using packet broker profiles that set routed Layer 3 or transparent bridge chains, traffic direction, health monitoring and session distribution, and policy rules choosing which traffic goes to which chain and whether to bypass or block when a chain fails. NPTv6 Prefix Translation Statelessly translates one IPv6 prefix to another without changing ports, with checksum-neutral mapping, bi-directional or service-specific policies, statically or dynamically assigned prefixes, and an NDP proxy that answers neighbor solicitations for the translated addresses. OSPFv2 and OSPFv3 Runs OSPF for IPv4 and OSPFv3 for IPv6 with normal, stub and not-so-stubby areas, area ranges and prefix summarization, area border router import, export and prefix filtering, broadcast, point-to-point and point-to-multipoint interfaces, virtual links, password, MD5 or IPSec authentication, graceful restart with helper mode, and redistribution from static, connected, BGP and RIP routes. Power over Ethernet Supplies power to connected devices over PoE-capable ports within a per-model power budget, with per-port enablement and priority, and dashboard widgets showing port status, allocated and used power and remaining budget. PPPoE Client Establishes a PPPoE session to an ISP access concentrator from a Layer 3 interface or an 802.1Q-tagged subinterface, learning its IPv4 or IPv6 address, DNS servers and MTU from the provider. PVST+ BPDU Rewrite Rewrites the port VLAN ID in inbound Cisco PVST+ and Rapid PVST+ bridge protocol data units to the outbound VLAN ID on Layer 2 interfaces so spanning-tree loop detection works across the firewall, with a configurable VLAN tag and the option to drop the BPDUs instead. Quality of Service Shapes and prioritizes egress traffic by assigning matching sessions to QoS classes through QoS policy rules and applying per-class priority and guaranteed and maximum bandwidth from a QoS profile on an egress interface, with clear-text and tunnel-specific settings, live per-class statistics, and a lockless mode that dedicates CPU cores to QoS on supported platforms. RIPv2 Runs RIPv2 with per-interface split horizon, poison reverse, active, passive and send-only modes, password or MD5 authentication, update, expire and delete timers, inbound and outbound distribute lists with metrics, and redistribution from static, connected, BGP and OSPF routes. Routing Filters and Route Maps Provides the match and set primitives that routing protocols reference, including IPv4 and IPv6 access lists, prefix lists with length ranges, AS path access lists, regular, large and extended community lists, BGP route maps and redistribution route maps, to control which routes are accepted, advertised, aggregated, suppressed or redistributed and what attributes they carry. SD-WAN Selects and fails over between WAN links per application using link tags and typed ISP connections, path quality monitoring of latency, jitter and packet loss, and traffic distribution profiles, with VPN clusters of hub and branch firewalls, per-link bandwidth monitoring and IPv6 support. Session Settings and Timeouts Governs how the dataplane handles flows through global session settings such as per-protocol TCP, UDP and ICMP timeouts, rejection of non-SYN first packets, checksum strictness, maximum segment size adjustment, split-handshake drop, half-closed and time-wait timers, ICMP rate limiting, hardware session offload, IPv6 firewalling, session rematch on commit and session distribution across dataplanes. Site-to-Site IPSec VPN Terminates site-to-site IPSec VPN tunnels on a tunnel interface through IKE gateways running IKEv1 or IKEv2 over IPv4 or IPv6, statically or dynamically addressed, authenticated by pre-shared key or certificate, with IKE and IPSec crypto profiles, tunnel and transport mode with proxy IDs, tunnel monitoring, and post-quantum pre-shared keys mixed into the key exchange for quantum-resistant tunnels. Static Routes and Path Monitoring Defines IPv4 and IPv6 routes with a chosen egress interface, administrative distance and metric and a next hop given as an IP address, FQDN, another logical router, a discard action or none, and withdraws a route from the routing and forwarding tables when ICMP path monitoring of any or all monitored destinations fails, reinstalling it after a preemptive hold time. Tunnel Content Inspection Inspects and applies policy to traffic inside GRE, VXLAN, GTP-U and non-encrypted IPSec tunnels without terminating them, with tunnel inspection policy rules that set the permitted encapsulation depth and strict-header and unknown-protocol handling, tunnel acceleration that can be disabled, and tunnel identifiers carried into logs, custom reports and the tunnel activity views. Web Proxy Terminates user web traffic on the firewall as an explicit proxy that browsers are pointed at or as a transparent proxy that intercepts requests inline, authenticating explicit-proxy users through Kerberos, SAML, the Cloud Identity Engine or basic authentication with configurable exemptions.
Device Setup & Configuration Operations Administrative Task Manager Lists every administrator-initiated and firewall-initiated job, report and log request since the last reboot with status, messages and queue position, and cancels pending commits individually or as a whole queue. Banners, Message of the Day and Logos Displays a login banner with optional forced acknowledgement, colored header and footer banners, a message-of-the-day dialog that appears without a commit, and replacement login-screen and header logos. Configuration Audit Compares two configuration versions and presents the differences as a change summary or XML diff, recording who committed each version and when. Configuration Backup and Export Saves default or named snapshots of the candidate configuration to persistent storage, exports running and candidate configurations to an external host, and restores a saved version. Configuration Commit, Validate and Preview Activates pending candidate configuration changes after validating them for blocking errors and warnings, previews the differences before activation, scopes a commit to selected administrators, locations or individual configuration objects, and queues concurrent commit requests with firewall-initiated commits prioritized. Configuration Locks Blocks other administrators from changing or committing the candidate configuration through manual config and commit locks scoped to a virtual system or shared location, with an option to acquire a commit lock automatically on any change. Configuration Revert Replaces the candidate configuration with the running configuration, an earlier committed version or a saved snapshot, optionally filtering the pending changes reverted by administrator or by location. Configuration Table Export Exports filtered policy, object, network, device and signature-exception table data to a PDF or CSV file for audit and review, splitting PDFs beyond 50,000 rows and recording a system log for each export. FIPS-CC Operational Mode Switches a firewall or appliance into a FIPS 140-2/140-3 and Common Criteria mode that resets it to factory defaults and enforces a fixed set of security functions covering TLS versions, password length, lockout, idle timeout and session length. Firewall Bootstrapping Brings a factory-default firewall online from a USB flash drive carrying an init-cfg.txt basic configuration and an optional full bootstrap.xml, including licensing and Panorama registration values. Global Find Searches the candidate configuration for every location that references an object, zone, rule, username, address or UUID, launched from the search icon or from a configuration item, with UUID-only and template-reference scoping, optimized result batching and per-administrator search history. Initial Device Setup Brings a new firewall online through the console or the default management address — forced admin password change, static management IP, DNS and NTP settings, zero touch provisioning disable — including an air-gapped path that uploads license keys, software and content updates manually. Maintenance Recovery Tool Provides a boot-time console tool that reverts the device to factory defaults, rolls back PAN-OS or a content update, runs file system diagnostics, extracts logs and switches the operational mode. Management Interfaces Administers the firewall through the web interface, an operational and configuration mode CLI over SSH, Telnet or console, an XML API addressing the configuration tree by XPath, and a versioned REST API of per-resource URIs with standard methods and documented error codes, both authenticated with a generated API key. PAN-OS Software Patches Applies critical bug and CVE fixes to the installed PAN-OS version as a patch that takes effect by refreshing the web interface, restarting processes or rebooting the device depending on its patch type, and reverts an applied patch to the previously applied or base version. PAN-OS Upgrade and Downgrade Moves a device between PAN-OS releases along a determined upgrade path for a standalone firewall, a high-availability pair upgraded manually or through an orchestration workflow, or a cluster member, skipping up to three software versions from PAN-OS 10.1 and later, and downgrades by loading the configuration automatically saved when that release was left. Panorama Management Connection Registers the firewall with a Panorama management server, enables or disables that connection from the firewall CLI, and shows the policy rules, objects, network and device settings pushed to it from device groups and templates. Partial Configuration Load Copies a named section of a saved, imported or running configuration into the candidate configuration by XPath in append, merge or replace mode, and pastes blocks of set commands from a text file using CLI scripting mode. Service Routes for External Services Directs the firewall's own connections to external services such as DNS, update servers, licensing, syslog and HTTP log destinations out of an in-band data port instead of the management interface, using a per-service source interface and address. Software and Content Updates Downloads and installs PAN-OS software versions and dynamic content updates such as applications and threats, antivirus, WildFire and GlobalProtect data files, on demand, on a per-update-type recurring schedule with installation and new-App-ID thresholds, or through the API, reverting to a previously installed content version, and showing preferred releases and their base versions. Swap Memory Scrub Removes cryptographic security parameters from swap partitions during restart or shutdown of a FIPS-CC mode device using a Department of Defense or NNSA scrub pattern, and reports the result in the system log. Upgrade Check Report Runs pre-upgrade readiness checks on a device during an upgrade or on demand and reports each flagged check with its warning or critical status, affected objects and remediation guidance, compares a pre-remediation report against a later one, and exports the report as PDF or CSV. Virtual and Container Form Factors Runs PAN-OS as a VM-Series virtual firewall on x86 and ARM instances across hypervisors and public clouds or as a CN-Series containerized firewall in Kubernetes, with flexible vCPU-tier licensing, per-form-factor interface and virtual system limits, and session state kept in an external cache so clustered cloud instances survive an instance failure. Zero Touch Provisioning Brings a factory-default firewall into service without on-site configuration by having it connect to a management server on first power-on, install the target PAN-OS release while walking the intermediate releases on its upgrade path, and receive its pushed configuration.
Security Policy & Enforcement Address Objects and Address Groups Represents one or more IP addresses as a reusable object of type IP netmask, IP range, IP wildcard mask or FQDN, groups those objects into static address groups and geographic regions, and references them across security, NAT, decryption, QoS, policy-based forwarding and other rules, with a top-down match mode for overlapping wildcard masks. Application Objects, Groups and Filters Groups applications into reusable objects, static application groups and dynamic filters built from category, subcategory, risk or content-delivered tags, so rules enforce sets of applications that update as new App-IDs arrive. Application Override Policy Bypasses Layer 7 application identification and threat inspection for matching traffic and applies stateful Layer 4 inspection instead, intended for SIP application-level gateway and low-performance SMB cases. Auto-Tagging from Logs Tags a source or destination IP address or user automatically when a log matches a filter in a log forwarding profile or log setting, registering the mapping locally or to a remote User-ID agent over an HTTP server profile and unregistering it after a configurable timeout. Device Quarantine List Holds compromised devices identified by host ID and serial number on a per-virtual-system quarantine list, added and removed manually, by a log forwarding action or through the API, so quarantined devices are blocked from connecting and the list can be redistributed to other firewalls. Dynamic Address Groups Resolves address group membership at runtime from a logical filter over static and dynamically registered tags so policy adapts to servers being added, moved or removed without a configuration change. Dynamic IP Address and Tag Registration Registers IP-address-to-tag mappings from the XML API, the User-ID agent, VM information sources and the CLI so dynamic address groups resolve rule membership at runtime, with commands to list, filter, audit and clear registrations by tag, source or address. Dynamic User Groups Resolves user group membership at runtime from tag match criteria registered by the XML API, the User-ID agent, Panorama or the web interface, redistributes the tags to other firewalls and expires membership on a timeout so policy responds to user behavior without manual changes. External Dynamic Lists Imports IP address, domain, URL, equipment-identity and subscriber-identity entries from an externally hosted text file or a Palo Alto Networks feed on a scheduled interval and enforces policy on them without a commit, with server and client authentication, per-list exclusions, on-demand refresh, evaluation ordering and per-model capacity limits. HTTP Header Insertion Inserts predefined or custom HTTP headers into requests to listed domains from a URL filtering profile, so a SaaS application allows only sanctioned tenants or restricted content. Object Tags and Tag Browser Applies up to 64 named, optionally colored tags to policy rules, address objects, address groups, user groups, zones and service groups, and manages the rulebase through them by viewing it as tag groups or through a Tag Browser that applies, removes, filters, reorders and adds rules by tag. Policy Match Testing Evaluates the running configuration against synthetic traffic from the web interface troubleshooting page or the CLI to report which security, NAT, authentication or decryption rule a flow would match. Policy Optimizer Identifies port-based rules, over-provisioned rules with unused applications and rules matching newly downloaded cloud App-IDs, and migrates them to application-based rules by cloning rules or adding applications, with sorting, filtering and hit-count statistics to prioritize the work. Policy Rulebases Evaluates traffic against ordered Security, NAT, QoS, policy-based forwarding, decryption, application override, authentication, denial-of-service and zone protection rulebases that allow, deny, prioritize, forward, decrypt, authenticate or reset connections, treating IPv4 addresses as a subset of the IPv6 address space during matching. Policy-Based Forwarding Overrides the route table for matching traffic by forwarding it out a named egress interface, to another virtual system, or discarding it, with next hops given as IP address or FQDN, ICMP path monitoring that disables or fails over the rule when the target is unreachable, and symmetric return enforcement for asymmetric-route environments. Rule Description, Tag and Audit Comment Enforcement Requires a description, tag, audit comment or any combination before a policy rule can be added or modified, constrains the audit comment to a regular expression, and keeps an audit comment archive with configuration log history and version comparison per rule. Rule Numbers and UUIDs Numbers rules by evaluation order within each rulebase and assigns every rule a persistent universally unique identifier that survives renaming, appears in traffic, threat, URL filtering, configuration and other logs, and can be regenerated when importing a configuration. SaaS Policy Recommendation Import Imports security policy rule recommendations pushed from SaaS Security, applies subsequent updates to those rules, and removes the local mapping when the recommendation is deleted upstream. Service Objects and Session Timeouts Defines TCP or UDP service objects with custom session timeout values and applies them through a policy rule so specific applications keep non-default timeouts. VM Information Sources Polls VMware ESXi and vCenter, AWS VPCs, Microsoft Azure and Google Compute Engine for virtual machine inventory and collects a predefined set of instance attributes as tags that dynamic address groups match on, with up to ten sources per firewall or virtual system. X-Forwarded-For Header Handling Takes the client address from the X-Forwarded-For header of traffic arriving through an upstream proxy and uses it either for User-ID mapping or for security policy enforcement, records it in logs and custom report templates, and optionally strips the header from outgoing requests after enforcement.
Authentication & User Identity Authentication Policy Challenges end users for one or more authentication factors before granting access to a service or application, using per-factor timestamps and a configurable timeout to decide when to re-challenge. Authentication Portal Presents a web form that collects the first authentication factor from end users, records authentication timestamps, and creates or updates the resulting IP-address-to-username mapping. Authentication Profiles and Sequences Binds an authentication service and its settings to a set of users as an authentication profile, and chains profiles into a ranked sequence the firewall tries in order until one succeeds. Authentication Server Timeouts Sets how long the firewall keeps trying to reach an authentication server, through per-server-profile timeouts, a global web server timeout and an Authentication Portal session timeout. Authentication Testing and Troubleshooting Tests an authentication profile against a named user from the CLI before commit and exposes commands and authentication logs that separate user error, server reachability and configuration problems. Device-ID Attaches a device identity to traffic from an inventory of network-connected devices built by Device Security, showing device categories, profiles and operating systems in the firewall interface, importing inbound and outbound device policy rule recommendations into the Security rulebase, and querying switches over SNMP for ARP, LLDP and CDP data where the firewall does not see the traffic. External Authentication Services Authenticates administrators and end users against external LDAP, RADIUS, TACACS+, Kerberos and SAML servers through server profiles, including Kerberos and SAML single sign-on and single logout and vendor-specific attributes that assign administrator roles and access domains. Local Authentication Authenticates users against a local user database of accounts and groups on the firewall, or against local administrator credentials without a database, including support for imported password hashes. Multi-Factor Authentication Adds additional authentication factors from MFA vendors reached through RADIUS, SAML or vendor APIs, recording a separate timestamp per vendor and triggering the extra factors from authentication policy rules. Pre-Logon Followed by SAML Authentication Establishes a machine-certificate VPN tunnel before user login and then reassigns that tunnel to the user after they authenticate to a SAML identity provider. Subscriber and Equipment Correlation Maps mobile subscriber and equipment identifiers to the IP addresses of user equipment, learned from GTP-U, PFCP or RADIUS on 5G and LTE interfaces, so security policy rules and logs can match on subscriber and equipment identity. TACACS+ Accounting Sends start, stop and update accounting records for administrative sessions to a TACACS+ accounting server using an accounting server profile. Terminal Server User Mapping Distinguishes users sharing one IP address on multi-user systems by allocating each user a source port block, using the Palo Alto Networks Terminal Server agent on Windows and Citrix hosts or XML API messages from non-Windows terminal servers, and enforcing policy on the resulting IP-port-to-user mappings. User and Group Based Policy Enforcement Matches security and authentication rules on individual users, directory groups, or the known-user and unknown categories, and handles users holding several accounts on one endpoint through group membership and the agent ignore list. User Mapping through the XML API Accepts user login and logout events submitted as XML over HTTP from applications and devices that no standard mapping method covers, authenticated with a firewall API key. User-ID Data Redistribution Distributes IP-user mappings, IP tags, user tags, GlobalProtect host information and quarantine lists from collecting firewalls to consuming firewalls in hub-and-spoke, multi-hub or hierarchical layouts with per-type selection, include and exclude networks and custom certificate trust, and shares mappings between virtual systems by designating one as a User-ID hub. User-ID Group Mapping Queries LDAP directory servers through a server profile to build a refreshed user-to-group table used for group-based policy, reports and log queries, selecting the primary username attribute, limiting which groups are available in policy and defining custom groups from LDAP filters. User-ID Server Monitoring Maps IP addresses to usernames by reading login events from Active Directory domain controllers, Exchange servers and Novell eDirectory servers using either a Windows-based User-ID agent or the PAN-OS integrated agent over WMI or WinRM, with domain controller auto-discovery, poll frequency, include and exclude networks, an ignore-user list and optional WMI client probing. User-ID Syslog Listening Creates and removes user mappings by parsing login and logout syslog messages from wireless controllers, 802.1x devices, proxies and other network access services, using predefined or custom Syslog Parse profiles built from regular expressions or field delimiters, over SSL, TCP or UDP listeners enabled through an interface management profile. Username Insertion in HTTP Headers Adds the mapped domain and username as a Base64-encoded header to outgoing web requests for listed domains through a URL filtering profile, so downstream appliances can enforce user-based policy without a separate identity deployment.
Monitoring, Logging & Reporting App Scope Reports Charts changes in application and threat activity over a selected period through summary, change monitor, threat monitor, network monitor and geographic threat and traffic map views, each exportable as an image or PDF. Application Command Center Summarizes log data graphically across network, threat, blocked, tunnel, GlobalProtect and SSL activity tabs, with widgets that sort by bytes, sessions, threats, content and URLs, widget-local and global filters, a time selector, sanctioned-application and risk-factor views, custom tabs that can be exported and imported, and PDF export. Dashboard Presents per-administrator widgets covering software and content versions, interface status, system resource and session utilization, top and top high-risk applications, HA status, logged-in administrators, configuration locks and recent threat, config, data filtering, URL filtering and system log entries, on a selectable refresh interval. Device Telemetry Collects device health, performance, configuration and threat metrics on fixed intervals and uploads them to Strata Logging Service, with per-category selection, a regional destination, dedicated service routes, per-category status monitoring and a downloadable sample bundle. Email Alerts Emails log-triggered alerts through an email server profile using unauthenticated SMTP or SMTP over TLS with a certificate profile and selectable authentication method, with configurable sender, recipients, gateway and custom message format. Enhanced Application Logs Collects DNS query, HTTP user-agent and DHCP assignment records that Palo Alto Networks cloud applications consume but the firewall does not display, enabled globally and per security rule through a log forwarding profile, and requiring a Strata Logging Service subscription. HTTP/S Log Forwarding Sends an API request to a third-party HTTP or HTTPS service when a log matches a filter, with a server profile controlling protocol, port, TLS version, certificate profile, HTTP method and credentials, and predefined or custom URI, header, parameter and payload formats per log type, optionally registering IP-address tags to User-ID. Log Card Forwarding Forwards dataplane logs on PA-7000 Series appliances over a dedicated Log Processing Card or Log Forwarding Card instead of management-plane service routes, with per-virtual-system subinterfaces, VLAN tags and default gateways on the log card. Log Forwarding Profiles Forwards selected logs to syslog, email, SNMP trap and HTTP destinations through log forwarding profiles whose match lists filter by log type, severity or WildFire verdict and can trigger automatic actions, attached to policy rules and zones or set per log type in device log settings. Log Storage Quotas and Export Scheduling Allocates disk quota and expiration periods per log type, schedules recurring log exports to an SCP or FTP server, and adjusts the storage reserved for generated reports on supported platforms. Log Types and Log Viewer Records traffic, threat, URL filtering, WildFire submission, data filtering, HIP match, GlobalProtect, IP-tag, User-ID, decryption, tunnel inspection, SCTP, GTP, configuration, system, audit, authentication and correlation logs, and presents them in filterable tables with configurable columns, a detailed log view, per-entry packet captures, AutoFocus artifact lookup and CSV export. NetFlow Export Exports unsampled NetFlow Version 9 records for traffic ingressing Layer 3, Layer 2, virtual wire, tap, VLAN, loopback, tunnel and aggregate Ethernet interfaces to up to two collectors per profile, using standard or PAN-OS enterprise templates refreshed on a time and record threshold. Packet Captures Captures packets at the receive, firewall, transmit and drop stages using defined filters, on threat detection through security profiles, per application, automatically for unidentified applications, on the management interface through tcpdump, and for GTP events, with a command to disable hardware offload so offloaded traffic is captured. PDF Summary Reports and Report Groups Aggregates up to eighteen predefined and custom report elements into a PDF summary report, combines reports into report groups compiled as a single titled PDF, and schedules daily or weekly email delivery with optional recipient overrides. Policy Rule Usage Records hit count, first hit, last hit, created and modified data for Security, NAT, QoS, policy-based forwarding, decryption, tunnel inspection, application override, authentication and DoS protection rules, persists it across reboots and upgrades until reset, and filters a rulebase by usage so unused rules can be tagged, disabled or deleted. Predefined and Custom Reports Generates over forty daily predefined application, traffic, threat and URL filtering reports and custom reports built from a summary or detailed log database with selected columns, sort and group criteria, time frame and a query builder, run on demand or nightly, with a configurable run time, expiration period and the option to disable unused predefined reports. SaaS Application Usage Report Compares sanctioned against unsanctioned SaaS application use by application count, bandwidth, users and user groups, lists applications with risky hosting characteristics, and details per-application users, blocked file types, threats and WildFire verdicts by subcategory. SNMP Monitoring and Traps Answers SNMPv2c and SNMPv3 statistics requests for interface, session, resource, chassis, GlobalProtect and log collector objects and forwards log data as traps to up to four managers per profile, using a published set of standard and Palo Alto Networks enterprise MIBs and a documented interface-index scheme. Syslog Monitoring Sends every log type to up to four external syslog servers per profile over UDP, TCP or TLSv1.2 in BSD or IETF format with a selectable facility, header format and client authentication, and supports a custom per-log-type message format alongside the documented default field layouts and severity mappings. User and Group Activity Reports Summarizes the web activity of an individual user or user group with URL category browsing summaries and an estimated browse time derived from configurable average browse time, page load threshold and maximum row settings, run on demand or scheduled for email delivery.
Threat Prevention & Content Inspection Anti-Spyware Profiles Detects compromised hosts beaconing to command-and-control servers, applies default or strict predefined severity handling with per-signature exceptions, blocks an offending IP address for a set period, and forges DNS responses for known malicious domains through DNS sinkholing. Antivirus Profiles Scans allowed traffic for viruses, worms, trojans and spyware downloads with a stream-based engine across per-protocol decoders, including inside compressed files and decrypted content, and sets an allow, alert, drop or reset action per decoder or signature. Automated Correlation Engine Matches content-delivered correlation objects against application statistics, traffic, threat, data filtering and URL filtering logs to detect escalation patterns that indicate a compromised host, logging severity-rated correlated events with match evidence and aggregating them in a compromised hosts widget. Botnet Report Correlates threat, URL and data filtering logs against malware URLs, dynamic DNS providers, newly registered domains, IRC traffic and unknown applications over 24 hours to score each host from one to five for likelihood of botnet infection, with configurable event thresholds and query filters. Content Decoding and Evasion Controls Decompresses Brotli-encoded HTTP traffic for inspection on supported platforms and blocks sessions whose base64, BDAT-chunk, chunked-transfer, quoted-printable, UTF, uuencoded, zip or Brotli content fails to decode, so encoding errors cannot be used to evade inspection. Data Filtering Profiles and Data Patterns Prevents sensitive content from leaving the network by matching custom data pattern objects built from predefined regulated-identifier patterns, regular expressions or file properties including third-party classification labels, and alerting or blocking above per-rule occurrence thresholds. DoS Protection Profiles and Policy Rules Protects named individual devices or groups of devices against session floods and session-exhaustion attacks through classified or aggregate profiles that set per-flood-type thresholds, a block duration and a maximum concurrent session limit, applied by policy rules that match on source, destination, user and service and take a protect, allow or deny action on a schedule. File Blocking Profiles Blocks, alerts on, or requires user acknowledgement for named file types over selected applications and transfer directions, with predefined basic and strict profiles and customizable response pages. Inline Machine Learning and Cloud Analysis Classifies files and traffic in real time as they pass through the firewall using local machine-learning models for portable executable, Office Open XML, shell script and other file types and cloud-based detection engines reached through a lightweight forwarding mechanism, blocking never-before-seen malware and malicious pages before a signature exists. Packet Buffer Protection Protects the firewall from single-session attacks that exhaust its packet buffers by applying random early drop and then discarding sessions or blocking source addresses once buffer utilization or dataplane latency crosses alert, activate and block thresholds, configured globally and enabled per ingress zone. Security Profiles and Profile Groups Attaches scanning profiles to allow-action security rules so permitted traffic is still inspected, and bundles profiles commonly used together into a security profile group that can be named default so it is applied to new rules automatically. Session Resource Diagnostics and Discard Reports the sessions consuming the largest share of the on-chip packet descriptor per slot and dataplane with their source addresses and applications, and permanently discards a named session from the CLI without a commit. URL Filtering Profiles Controls how users reach web content over HTTP and HTTPS by dynamic URL category, with a default blocking profile, custom allow and block lists, per-category actions including continue and override, and controls on where users may submit corporate credentials. Vulnerability Protection Profiles Blocks attempts to exploit system flaws entering the network such as buffer overflows and illegal code execution, using severity-graded signature actions with per-signature exceptions and IP blocking. WildFire Sample Forwarding Forwards unknown files and email links to the WildFire public, regional or private cloud for verdict analysis through a WildFire Analysis profile attached to a security rule, with per-file-type forwarding rules and size limits, and a basic tier limited to portable executables when no WildFire subscription is present. Zone Protection Profiles Defends an ingress zone against aggregate SYN, ICMP, UDP and other IP floods with alarm, activate and maximum connections-per-second thresholds and a SYN cookie or random early drop action, and adds reconnaissance protection against port scans and host sweeps, packet-based attack protection for malformed headers, non-IP protocol lists, and dropping of Cisco TrustSec security group tags.
Decryption Decryption Exclusions Leaves selected traffic encrypted through a Palo Alto Networks predefined exclusion list, a custom hostname exclusion list, an automatically populated local cache that ages entries out after twelve hours, and policy-based no-decrypt rules. Decryption Logging and Reporting Records per-session TLS handshake detail, error categories and error indexes for decrypted and no-decrypt sessions, optionally including successful handshakes, and feeds scheduled or on-demand custom decryption reports. Decryption Policy Rules Selects the traffic to decrypt or leave encrypted by source, destination, user, service and URL category and sets the decryption type, mirroring and logging applied to matching sessions. Decryption Port Mirroring Forwards a copy of decrypted traffic out a dedicated interface to an external archiving or analysis device, gated by a free per-firewall license. Decryption Profiles Defines the protocol versions, cipher suites, certificate verification checks, session mode checks and failure checks applied to decrypted and no-decrypt sessions, in separate profile types for forward proxy, inbound inspection, SSH proxy and no-decryption. Decryption Troubleshooting Tools Diagnoses decryption failures from the Application Command Center and decryption logs — expired, revoked, pinned and untrusted certificates, incomplete certificate chains, weak protocols and unsupported cipher suites — and verifies from traffic logs which sessions are actually being decrypted. Post-Quantum Cryptography Detection and Control Detects post-quantum and hybrid post-quantum key exchange in TLSv1.3 sessions, prevents negotiation of algorithms it cannot decrypt, and records the activity in decryption logs. SSH Proxy Decrypts inbound and outbound SSH sessions using a key the firewall generates at boot, and identifies and blocks applications tunneled inside SSH channels. SSL Decryption Opt-Out Page Presents a customizable response page that tells users their HTTPS traffic will be decrypted and lets them continue for 24 hours or decline and be blocked from HTTPS for a minute. SSL Forward Proxy Decrypts outbound SSL/TLS traffic by proxying the session with forward trust and forward untrust certificates that impersonate the destination server, with a configurable key size for the generated certificates. SSL Inbound Inspection Decrypts inbound SSL/TLS traffic destined for internal servers using those servers' certificates and private keys, supporting up to twelve certificates on a single decryption policy rule. Temporary Decryption Suspension Suspends and resumes SSL/TLS decryption from the CLI without editing rules or committing, reverting to decryption automatically on reboot. TLS 1.3 Decryption Decrypts TLSv1.3 sessions for forward proxy, inbound inspection, network packet broker traffic and port mirroring when a decryption profile sets TLSv1.3 as a supported version.
Certificates & Keys Certificate Generation, Import and Renewal Generates self-signed root CA and leaf certificates on the firewall, imports certificates and private keys from an enterprise CA, requests certificates from an external CA through a signing request, and exports, renews and revokes them. Certificate Profiles Defines which CA certificates authenticate users and devices for a given service and how revocation status is checked and enforced for that service. Certificate Revocation Checking Verifies certificate revocation status using certificate revocation lists and OCSP with fallback between them, supports the firewall acting as its own OCSP responder, and can route OCSP requests through an HTTP proxy. Default Trusted Certificate Authorities Ships a store of preinstalled trusted CA certificates, updated with major PAN-OS releases, whose individual entries can be viewed, enabled, disabled or exported. Device Certificate Installation Installs and automatically reinstalls the 90-day device certificate that authenticates the firewall to Palo Alto Networks cloud services, using a one-time password from the customer support portal. Hardware Security Module Key Storage Stores and generates private keys used for TLS decryption and encrypts the master key on an external hardware security module, and exposes HSM status, support files and configuration reset. Management Traffic Certificate Replacement Replaces the certificate the firewall auto-generates for HTTPS access to the web interface and XML API with one issued for the organization. Master Key Encryption Encrypts the keys and passwords stored on the device with a master key using AES-256-CBC or AES-256-GCM, and tracks master key lifetime and reminders so it is rotated before encryption values repeat. Private Key Export Blocking Permanently prevents export of a private key at the moment its certificate is generated or imported, with commands to list and verify which certificates have blocked keys. SCEP Certificate Enrollment Automates generation and distribution of per-user or per-device client certificates from an enterprise PKI through a Simple Certificate Enrollment Protocol profile with an optional challenge-response. SSH Service Profiles Restricts the ciphers, key exchange algorithms and message authentication codes offered on management and high-availability SSH connections and sets host key regeneration thresholds. SSL/TLS Service Profiles Specifies the server certificate, allowed TLS protocol version range and cipher suites for connections to firewall-hosted services such as the management interface, Authentication Portal and GlobalProtect portals and gateways.
Administrative Access & Roles Admin Role Profiles Grants or denies an administrator access per functional area across the Web UI, CLI, REST API and XML API, including node-level control of the Policy tab and privacy settings that hide end-user IP addresses and usernames. Administrator Accounts Creates per-person administrative accounts with a role and authentication method, defined locally on the firewall, on an external server, or both. Administrator Activity Auditing Generates an audit log to a syslog server for each web interface navigation and each operational CLI command an administrator executes. Administrator Authentication Methods Authenticates administrators by local or external credentials, by client certificate to the web interface, or by SSH public key to the CLI, with authorization optionally managed on the external server. Administrator Login Activity Indicators Shows each administrator their last login timestamp and a caution indicator summarizing failed login attempts since that login, including the account name, failure reason, source address and time of each attempt. API Key Lifetime and Revocation Sets an expiry period for the API keys that authenticate XML and REST API calls, expires all currently valid keys at once when one is suspected compromised, and optionally encrypts the key with a nominated RSA certificate so that adding or changing that certificate invalidates every existing key. External Zones and Shared Gateways Connects virtual systems to each other and to the internet without leaving the appliance by way of an external zone per virtual system that policy is written against, or a shared gateway that lets several virtual systems reach the internet through one routable interface and address. SCP Upload for Administrators Lets a superuser administrator upload software versions, content updates, plugins, configuration files and license keys to the firewall over SCP instead of the web interface. Virtual Systems Runs multiple independently administered firewall instances on one appliance, each with its own interfaces, VLANs, virtual wires, routers, zones, policies, objects, certificates, server profiles, User-ID configuration and logs, with per-instance resource limits, shared objects, virtual system and device administrator roles, and commands and commits scoped to a single instance.
App-ID Application Identification App-ID Cloud Engine Downloads a cloud-maintained catalog of App-IDs for cloud applications the firewall would otherwise classify as ssl or web-browsing, submitting unmatched payloads to a machine-learning engine that mints new App-IDs, and can be enabled or disabled per appliance. App-ID Traffic Classification Identifies the application behind a session regardless of port, protocol or encryption by applying application signatures, protocol decoders and heuristics, and re-applies signatures to flows after decryption. App-ID TSID Preview Delivers upcoming App-IDs a month early as informational threat signature indicators so administrators can test and adjust policy before the App-ID ships. Application Dependency Handling Allows dependent applications implicitly where the firewall can determine them and surfaces unresolved dependencies during rule creation and commit so an administrator can add them to a rule. Application Level Gateways Acts as an application-level gateway for dynamic-port protocols such as SIP, H.323 and FTP by opening temporary pinholes and rewriting NAT payloads, with per-application ALG disabling for clients that handle NAT traversal themselves. Application-Default Port Enforcement Restricts an allowed application to the default ports Palo Alto Networks defines for it, distinguishing cleartext from encrypted variants of the same application. Custom and Unknown Application Handling Defines custom application signatures with their own characteristics, category, risk, port and timeout, and provides ways to control or submit traffic the firewall classifies as unknown TCP or UDP. HTTP/2 Inspection Inspects and enforces policy on HTTP/2 traffic stream by stream when decryption is enabled, with options to downgrade or disable HTTP/2 inspection for targeted traffic or globally. New and Modified App-ID Management Reviews the App-IDs a content release introduces or changes, shows how they affect existing rule enforcement, disables or enables individual App-IDs, and matches the New App-ID characteristic in rules and reports so recently categorized applications stay allowed.
High Availability Active/Active High Availability Runs both firewalls in a pair as active peers in virtual wire or Layer 3 deployments, assigning each session an owner and a setup firewall by IP modulo, IP hash, primary device or first packet, forwarding packets between peers over the HA3 link and preserving egress interface selection across ECMP paths on failover. Active/Passive High Availability Pairs two firewalls so one secures traffic while the peer stays synchronized and ready to take over, supported in virtual wire, Layer 2 and Layer 3 deployments, with the passive peer running routing protocols, monitoring links and paths and pre-negotiating LACP and LLDP for sub-second failover. Floating IP and ARP Load-Sharing Shares gateway addressing across an active/active pair through floating IP addresses bound to a device ID that move to the surviving peer on failure, and through a LAN-side shared IP address answered by whichever peer a hash or modulo of the requester selects, each backed by a generated virtual MAC address and gratuitous ARP. HA Clustering Synchronizes session state across up to sixteen firewalls sharing a cluster ID over dedicated HA4 and HA4 backup links so sessions survive the loss of any member, supporting Layer 3 and virtual wire deployments with a mix of standalone members and HA pairs and a per-model member limit. HA Configuration and Runtime Synchronization Copies committed configuration from the active peer to its partner and synchronizes runtime state such as sessions, forwarding tables, IPSec security associations and ARP entries, excluding a documented set of device-specific settings, with CLI commands to trigger and inspect synchronization. HA Failover Triggers and Timers Triggers failover from heartbeat and hello loss, link group failures, path monitoring of destination IP groups or packet path health faults, arbitrated by device priority, preemption, flap limits and recommended, aggressive or advanced timer profiles, and reports the resulting initial, active, passive, active-primary, active-secondary, tentative, non-functional and suspended firewall states. HA Links and Backup Links Carries HA control, data, packet-forwarding and cluster session traffic over dedicated HA1, HA2, HSCI and auxiliary ports or over data and management ports configured as HA interfaces, with backup links on separate subnets and ports and optional SSH encryption of the control link. NGFW Clustering Runs two supported chassis as a single logical device over one High Speed Chassis Interconnect connection with dual active data planes and a single active control plane, presenting one Layer 2 or Layer 3 node to neighbors, supporting multichassis link aggregation and failing over in under a second.
Licensing & Subscriptions Device Registration Associates a firewall serial number or authorization code with a Palo Alto Networks support account so it can receive licenses, content updates and support, including offline registration, device naming and tagging, physical location, line card and component registration and Enterprise Support Agreement enrollment. Hardware Consumption and Asset Management Tracks registered hardware estate against an Enterprise Agreement cap with contract summaries, a six-month peak consumption graph and CSV export, and manages the asset inventory through device tags, incoming transfers, component registration and individual or bulk decommissioning. License Activation Activates subscription licenses on a registered firewall by retrieving them from the license server or by manually uploading downloaded license key files on an air-gapped device. License Expiration Handling Warns daily in the system log for thirty days before a subscription expires and then degrades each service to a documented reduced state at midnight GMT, keeping installed signatures, custom categories and cached data available while withdrawing updates, cloud lookups and advanced file handling. VM-Series Capacity Licensing Moves a VM-Series firewall from an evaluation to a production license or to a larger model with more capacity by allocating hardware resources, installing a license API key and reactivating the license, since the serial number is derived from the instance UUID and CPU ID.
Central management for firewalls, policies and logs across a fleet.
Centralized Configuration Device Group Hierarchy Nests device groups so that shared rules and objects at the top are inherited down an ancestor chain to descendant device groups, and evaluates pre-rules, post-rules and default rules in a defined order across that chain. Device Groups Groups managed firewalls and virtual systems into up to 1,024 device groups that share a set of policy rules and objects, with each firewall or vsys belonging to one device group at a time. Firewall Device Group Reassignment Moves a managed firewall to a different device group, or reassociates it, changing which policies and objects it inherits and removing those from the previous group. Move and Clone Rules and Objects Moves or clones policy rules and objects between device groups in a single operation, carrying referenced objects along and validating references in the destination. Object Inheritance and Overrides Overrides an inherited object's values in a descendant device group, reverts an overridden object back to its ancestor values, and optionally reverses the default precedence so ancestor values replace all overrides on the next push. Policy Rule Tagging Assigns tags to policy rules centrally and groups, filters and bulk-manages the rulebase through a tag browser without changing rule evaluation order. Policy Rule Targeting Sets a policy target on a shared or device group rule so it applies only to specified firewalls or virtual systems within the device group, or excludes specific ones. Rule Audit Comment Archive Records audit comments and configuration log history per policy rule and compares two versions of a rule, with an option to require a comment whenever a rule is created or modified. Shared and Device Group Objects Defines address, service, security profile and similar objects once in the Shared location or in a device group and reuses them in any rule in that device group or its descendants. Template Disable and Removal Stops managing a firewall with a template or template stack, either copying the pushed values into the firewall's local configuration or deleting them. Template Stacks Combines up to eight templates into a template stack, in a defined inheritance order, and adds stack-level configuration so a full device configuration can be pushed to every firewall assigned to the stack. Template Value Overrides Overrides a value pushed from a template by setting it locally on the firewall, by overriding it in the template stack, or by defining a stack-level or firewall-specific variable. Template Variables Substitutes IP addresses, ranges, FQDNs, interfaces, hostnames, IPv4 and IPv6 subnets, group IDs and pre-shared keys in template and stack configurations through named variables, which can be bulk-overwritten by CSV import. Templates Defines reusable base network and device configuration — interfaces, VLANs, virtual wires, IPSec tunnels, DNS proxy and virtual systems — in up to 1,024 templates that Panorama pushes to managed firewalls. Unused Object Push Control Limits the shared address and service objects Panorama pushes to managed firewalls to only those referenced by rules, reducing object counts and commit times on capacity-constrained platforms. User-ID and Timestamp Redistribution Redistributes User-ID mappings and authentication timestamps through Panorama to managed firewalls so every firewall enforcing policy or generating reports has the required data.
Appliance Operations & Diagnostics Appliance Resource Scaling Increases the vCPU count, memory and system disk of a Panorama virtual appliance on each supported hypervisor and cloud platform to meet the resources required by a deployment mode or management capacity. Custom Logos Uploads images for the login screen background, web interface header and PDF report title page and footer, and hides the default Panorama background header. Diagnostic and Tech Support Files Generates and downloads a tech support file of Panorama system activity for upload to a support case. M-Series Appliance Setup Performs initial configuration of an M-200, M-300, M-500, M-600 or M-700 appliance over the MGT interface or console port — admin password, management IP, DNS and NTP — including a variant procedure for air-gapped appliances that receive licenses, software and content updates by manual upload. Management Interface Segmentation Assigns Panorama services — device management, log collection, Collector Group communication, and licensing and software updates — to separate appliance interfaces instead of the MGT interface, with LACP aggregation supported on the M-700. Panorama Appliance Migration Moves a Panorama configuration between M-Series models, between M-Series and virtual appliances and between hypervisors, using an intermediate virtual appliance where PAN-OS versions do not overlap, guided by a pre-migration checklist of prerequisites. Panorama Deployment Modes Runs an M-Series or virtual Panorama appliance in Panorama mode with a local Log Collector, in Management Only mode as a dedicated management server, or in Log Collector mode as a Dedicated Log Collector, and switches an appliance between those modes. Panorama Management Interfaces Provides administrative access through a web interface organized into Dashboard, ACC, Monitor, Device Groups, Templates and Panorama tabs and through a command line interface, with a Global Find search that locates a string across the Panorama configuration including UUIDs and template references. Panorama System Diagnostics Diagnoses Panorama system conditions — a suspended state from duplicate serial numbers, mismatched modes, priorities or versions, file system integrity check progress, a critical system log prompting reboot when the configd process exhausts memory, registration and serial number errors, and content version mismatches that break reporting. Panorama Virtual Appliance Deployment Installs the Panorama virtual appliance on VMware ESXi, vCloud Air, Microsoft Hyper-V, KVM, AWS, AWS GovCloud, Azure, Google Cloud Platform, Oracle Cloud Infrastructure and Alibaba Cloud, with per-platform image, resource and network prerequisites and an initial configuration procedure. Policy Match and Connectivity Tests Tests from Panorama whether the running configuration on managed firewalls, Log Collectors and WF-500 appliances matches the intended policy for given traffic and whether those devices can reach Log Collectors, external dynamic lists, the update server, WildFire, Threat Vault and routing destinations, with results exportable to PDF. Reboot and Shutdown Restarts Panorama gracefully or halts and powers off the system from the web interface. Update Storage Management Alerts when the space Panorama reserves for stored software and content updates reaches 90 percent, and sets from the CLI how many updates of each type to keep while deleting stored updates to free space.
Log Collection Infrastructure Collector Groups Operates 1 to 16 Log Collectors as one logical log collection unit that distributes logs across their disks by a hash algorithm, assigns which firewalls send logs where through a preference list or round-robin, and supports moving collectors and removing firewalls between groups. Log and Report Storage Quotas and Expiration Sets a percentage storage quota and a maximum retention in days for each log type on Panorama and per Collector Group, plus a report expiration period and daily report run time, overwriting the oldest entries when a quota fills. Log Collector Health Status Reports the overall health of each managed Log Collector and the health of its individual log collection processes. Log Collector Scaling Designates which Log Collectors in a Collector Group are master-eligible to cut election overhead, supporting ingestion above one million logs per second across sixteen M-700 appliances. Log Forwarding and Buffering Modes Selects buffered or live log forwarding from firewalls to Panorama and which Panorama HA peer receives logs, with firewalls buffering and resuming from the last position when the connection drops. Log Forwarding to External Destinations Forwards firewall, Panorama and Log Collector logs onward to syslog, email, SNMP trap and HTTP-based services through server profiles assigned to Panorama log settings and Collector Groups, converting each log to the destination's format. Log Forwarding to Panorama Configures managed firewalls through templates and device groups to forward their logs to Panorama or its Log Collectors, optionally filtered by log attributes such as threat type or source user, and verifies that forwarding succeeded. Log Redundancy Writes a second copy of each log to a different Log Collector in the Collector Group so no logs are lost or hidden from queries when one collector becomes unavailable. Log Storage Expansion Expands log storage capacity by adding or upgrading RAID drive pairs on an M-Series appliance and by adding up to twelve 2TB virtual logging disks to a Panorama virtual appliance in Panorama mode without losing logs on existing disks. Log Storage Recovery and Migration Recovers and relocates collected logs — replacing failed physical or virtual disks, regenerating RAID pair metadata, migrating logs and Log Collectors to new M-Series appliances including HA pairs, resolving zero log storage for a Collector Group, verifying port usage and viewing log query jobs. Managed Collectors Adds Log Collectors to Panorama as managed collectors, either local to an M-Series or virtual appliance in Panorama mode or as Dedicated Log Collectors in Log Collector mode, reachable over IPv4 or IPv6. Strata Logging Service Forwarding Forwards managed firewall logs to the cloud-based Strata Logging Service through the cloud services plugin, alongside or instead of on-premises Log Collectors. Syslog Forwarding over Ethernet Sends syslog from a Panorama management server or Dedicated Log Collector over a dedicated Ethernet interface instead of the management interface to avoid log loss at high log rates.
Administrative Access Access Domains Scopes a device group and template administrator to specific device groups, templates and firewalls through up to 4,000 access domains, which also govern which firewall web interfaces that administrator can switch context to. Admin Role Profiles Defines custom roles that set read-write, read-only or disabled access per functional area of the web interface, CLI and XML API, including the object-level privileges that allow an administrator to push other administrators' committed changes. Administrator Accounts Creates Panorama administrator accounts of a chosen type — superuser, dynamic, custom, or device group and template admin — each bound to an authentication method and to role and access domain assignments. Administrator Activity Tracking Generates an audit log for every web interface navigation and every CLI operational command on Panorama, managed firewalls and Log Collectors and forwards it to a syslog server. Certificate-Based Administrator Authentication Authenticates administrators to the Panorama web interface by digital signature instead of a password, disabling username and password login for all administrators once enabled. External Administrator Authentication Authenticates administrators against RADIUS, TACACS+, SAML 2.0, LDAP or Kerberos server profiles, and reads vendor-specific attributes or SAML attributes to assign roles, access domains and user groups from the directory, including RADIUS-based multi-factor authentication and SAML single sign-on and single logout. Firewall Context Switching Opens the web interface of a managed firewall from within Panorama through a context drop-down, using a device admin role named in the administrator's Panorama role profile. Log Collector AAA Accounting Assigns a TACACS+ accounting server profile to a Log Collector so it forwards session start and stop records, and config, auth and audit logs, for every administrator session. Managed Appliance Administrator Accounts Creates and pushes administrator accounts and RADIUS, TACACS+ or LDAP authentication profiles for Dedicated Log Collectors, WildFire appliances and WildFire clusters from Panorama, overwriting locally configured administrators on each push. Password Profiles and Complexity Enforces server-wide password complexity requirements and per-account password profiles that set change period, expiration warning, post-expiration grace period and post-expiration login count. SCP Uploads for Administrators Lets superusers upload PAN-OS software, dynamic content updates, plugin versions, configuration files and license keys to Panorama over Secure Copy instead of the web interface, logging each success or failure. SSH Key-Based CLI Authentication Authenticates administrators to the Panorama CLI with SSH public keys, optionally protected by a passphrase, so scripts can access the CLI without sending passwords over the network.
Commit & Push Control Automated Commit Recovery Has each managed firewall test its connection to Panorama after every commit, and at 60-minute intervals, and revert to its previous running configuration if the configured number of attempts fail. Commit and Push Commits pending changes to the Panorama configuration and pushes the running configuration to firewalls, Log Collectors and WildFire appliances, either as separate operations or as one combined commit and push, with an editable push scope and a queue that runs commits in initiation order. Commit and Push Failure Diagnostics Triages failed commits and pushes, covering pending local firewall changes, disabled template or device group objects on the firewall, firewall object capacity limits exceeded through device group inheritance, and configuration diffs for firewalls that automatically reverted. Commit and Push Validation Validates the candidate configuration, and separately a device group or template push, returning the errors and warnings an actual commit or push would produce. Commit Preview and Change Summary Displays the candidate configuration beside the running configuration with additions, modifications and deletions colour-coded and a configurable number of context lines, plus a per-setting change summary grouped by type or administrator. Configuration Locks Takes config or commit locks scoped to Shared, a template or a device group to block other administrators from changing the candidate or running configuration, released manually or automatically after the commit, with an option to acquire a commit lock automatically. Merge with Device Candidate Config Commits pending local firewall configuration alongside the configuration pushed from Panorama, and can be disabled so local changes are managed independently of the pushed configuration. Multi-VSYS Push Bundling Bundles the commit jobs for multiple virtual systems of the same multi-vsys firewall into a single job on that firewall when a device group push affects more than one of its vsys. Multi-VSYS Shared Object Optimization Pushes device group objects into the shared location of a multi-vsys firewall rather than replicating them per virtual system, with a full optimization mode that also covers external dynamic lists, custom URL categories and security profiles. Scheduled Configuration Push Pushes device group and template configuration to selected managed firewalls at a set date and time, once or on a recurring schedule, and records an execution history of impacted, succeeded, failed and auto-reverted firewalls. Selective Commit Commits only chosen device group and template stack configuration objects, filtered by administrator or by location, so incomplete work from other administrators stays uncommitted. Selective Push Pushes only the committed changes made by selected administrators to managed firewalls, gated by an admin role profile that grants object-level push privileges, and generates a system log on success.
Plugins & Integrations Cloud Services Plugin Enables Strata Logging Service and Prisma Access from Panorama once an auth code is activated and a log region is selected. Cloud Workload Monitoring Plugins Collects workload metadata as tags from AWS VPCs, Azure subscriptions, Google Kubernetes Engine clusters, Nutanix Prism Central, VMware vCenter and VMware NSX and registers them to managed firewalls for use as dynamic address group match criteria. CloudConnector and SCM Configuration Sync Establishes a secure channel from Panorama to Strata Cloud Manager, authenticated by a Thermite device certificate and routed to the regional admin cluster, so Strata Cloud Manager can synchronize snippet configurations into Panorama device groups and templates. Enterprise DLP Plugin Adds cloud-backed Enterprise Data Loss Prevention configuration for Panorama and managed firewalls, held as shared configuration objects that a configuration restore must preserve. IPS Signature Converter Converts Snort and Suricata rules into custom Palo Alto Networks threat signatures and registers them on the firewalls in specified device groups for use in Vulnerability Protection and Anti-Spyware profiles. Network Discovery Plugin Discovers devices on the network by querying switches over SNMP or by actively polling devices that speak industrial OT protocols. Network Fabric Endpoint Plugins Monitors endpoints in Cisco ACI fabrics through the APIC and in Cisco TrustSec environments through up to sixteen pxGrid servers, converting endpoint groups and security group tags into tags pushed to notify groups of firewalls, in bulk-sync or pub-sub mode. Plugin Architecture Installs, upgrades, reinstalls and removes optional Panorama plugins that add integrations without a new PAN-OS release, and pushes IP-to-tag updates from multiple installed plugins into dynamic address groups on managed firewalls. Plugin Bundling Downloads compatible plugin versions automatically with the PAN-OS base image and presents them in a single Plugins interface, removing the manual version-matching step before installation. Prisma Access Management Manages a Prisma Access deployment from Panorama — activation and onboarding, remote network, mobile user and service connection configuration, and its policy and log surfaces — as an alternative to managing it in Strata Cloud Manager. SD-WAN Plugin Configures software-defined WAN across managed firewalls from Panorama so multiple internet and private links are used as a dynamic WAN in place of dedicated WAN appliances. VM-Series Plugin Management Installs the VM-Series plugin on Panorama to configure the public cloud and hypervisor integrations of managed VM-Series firewalls, including metric publishing, and pushes those settings to device groups.
Visibility & Reporting Aggregated Log Viewer Views and filters traffic, threat, data filtering, HIP match, WildFire submissions and User-ID logs aggregated from managed firewalls, including packet capture download from a threat log entry. Application Command Center and AppScope Summarizes network activity across all managed firewalls by application, user, URL category and threat, sourced either from the Panorama database or queried live from the firewalls, with AppScope threat and traffic maps and a threat monitor of top threats, attackers and victims. Centralized Reporting Runs more than 40 predefined reports plus custom reports and report groups over aggregated logs or by querying firewalls directly, on demand or on a recurring schedule with email delivery. Configuration Size Monitoring Reports total candidate and running configuration size against the platform maximum on the dashboard and from the CLI, breaks it down by device group and template, and alerts administrators when a configuration nears or exceeds the supported limit. Device Health Monitoring Stores 90 days of session, environmental, interface, logging, resource and high-availability metrics for each managed firewall, computes a seven-day baseline and standard deviation per metric, and lists firewalls whose metrics fall outside their normal operating range. Panorama System and Config Logs Records every configuration change in Config logs and every system event with a severity level in System logs for Panorama and its managed collectors, filterable by type, receive time or severity. Policy Rule Usage Reports which firewalls in a device group have traffic matching each pushed policy rule, with created and modified dates and a customizable time frame, persisting across reboots, dataplane restarts and upgrades. SNMP Monitoring Answers SNMP GET requests for Panorama and Dedicated Log Collector statistics — HA mode, state, version, average logs per second, retention, log disk usage and per-firewall forwarding status — and sends SNMP traps or email alerts when a monitored metric crosses a threshold. Stats Dump File Generation Generates a set of XML reports summarizing the last seven days of network traffic for one or all managed firewalls, downloadable locally or exportable to an SCP or TFTP server, as input to a Security Lifecycle Review. Task Manager Lists every operation initiated by an administrator, by Panorama or by a managed firewall since the last reboot, filtered by running or all and by reports, log requests or jobs, with detail messages and the ability to cancel pending commits. Traps ESM Log Ingestion Receives Traps ESM endpoint security logs over syslog on TCP, UDP or SSL and correlates them with firewall logs to generate match evidence for an incident.
Configuration Backup & Audit Candidate Configuration Snapshots Saves the candidate configuration to persistent storage as the default snapshot or a custom-named snapshot, optionally scoped to selected device groups, templates and template stacks or filtered by administrator. Configuration Audit Compares any two configuration versions with a side-by-side XML diff and a change summary that lists each affected object and whether it was set, edited, renamed, moved or deleted, over a configurable number of retained versions. Configuration Backup Retention Stores a backup of the Panorama running configuration and of each managed firewall's running configuration on every commit, up to a configurable number of versions. Configuration Export and Import Exports named snapshots, running configuration versions and a combined Panorama-and-devices configuration bundle as XML to an external host, and imports them back, including pushing an imported device config bundle to a firewall. Configuration Revert Replaces the candidate configuration with the running configuration, a saved snapshot, a stored running configuration version or an imported configuration, filtered by administrator or by device group, template and template stack. Firewall Configuration Import Imports a managed firewall's configuration into Panorama, creating a template for its network and device settings and a device group per firewall or virtual system, either whole or as a partial load of selected settings. Load a Configuration Backup to a Firewall Pushes a saved or committed configuration version stored on Panorama to a managed firewall, overwriting that firewall's candidate configuration. Scheduled Configuration Export Exports the Panorama and managed firewall configuration backups daily as a single gzip file to an SCP or FTP server at a scheduled time, with an SCP connection test.
Managed Device Lifecycle Add a Firewall as a Managed Device Onboards a firewall by pairing its serial number and a device registration authentication key with the Panorama address configured on the firewall, and optionally assigns it a device group, template stack, Collector Group and Log Collector and pushes configuration on first connection. Managed Device Connectivity Recovery Restores the connection between Panorama and a managed firewall, Dedicated Log Collector or WildFire appliance that has disconnected, been factory reset, or failed to reconnect after a management migration. RMA Firewall Replacement Replaces a failed firewall by swapping its serial number on Panorama and restoring configuration from a partial device state bundle that Panorama generates on request from the pushed configuration plus the firewall's last local configuration. Switch Between Panorama and Cloud Management Changes a managed firewall's management platform from Panorama to cloud management, and back from cloud management to Panorama. Transition a Firewall to Panorama Management Migrates locally managed firewalls and firewall HA pairs to Panorama management, either reusing the imported configuration or overwriting it with a newly built device group and template stack, and can localize a pushed configuration back onto the firewall to leave Panorama management. WildFire Appliance Management Onboards and centrally configures up to 200 standalone WildFire appliances and cluster nodes from Panorama — content update and cloud servers, logging, data retention and analysis environment settings — and removes them back to local CLI management. WildFire Cluster Management Builds WildFire appliance clusters from Panorama with a high-availability controller node pair and worker nodes, configures general cluster settings and appliance-to-appliance encryption, displays cluster health status, and imports or removes cluster configuration from Panorama management. Zero Touch Provisioning Onboards firewalls shipped directly to branch sites by registering Panorama with the ZTP cloud service through the ZTP plugin and claiming firewalls by serial number and claim key, individually or by CSV import, including active/passive HA pairs and a restricted installer administrator account.
Device Trust & Keys Automatic Master Key Deployment Provisions a configured device master key to every newly registering firewall in an enabled device group on its first connection, without per-device configuration. Custom Certificate Mutual Authentication Replaces the predefined certificates used for SSL connections between Panorama, managed firewalls, Log Collectors, WildFire appliances and clusters and HA peers with custom server, client and CA certificates and certificate profiles, optionally enforcing custom certificates only, including a shared certificate across a WildFire cluster and procedures to replace expired or revoked certificates. Device Certificate Deployment Installs the 90-day Palo Alto Networks device certificate on Panorama itself, on Dedicated Log Collectors and on one or many managed firewalls, reinstalls it 15 days before expiry, and restores it manually when automatic reinstallation fails. Device Registration Authentication Keys Generates keys with a defined lifetime, use count and optional serial number restriction that a firewall, Dedicated Log Collector or WildFire appliance must present for mutual authentication on its first connection to Panorama. Master Key Management Deploys and renews the AES-256-CBC master key that encrypts sensitive configuration elements on Panorama, managed firewalls, Log Collectors and WildFire appliances, supporting a unique key per firewall so one compromised key does not expose the whole deployment. SC3 Certificate Migration Collects the Secure Common Criteria trust infrastructure from a source Panorama into an encrypted bundle and restores it on a replacement Panorama so managed firewalls onboarded with an authentication key reconnect without re-onboarding.
Licensing & Update Deployment Device Management Capacity Licenses a Panorama appliance to manage 25, 100 or 1,000 firewalls, and raises the ceiling to 5,000 firewalls on M-600, M-700 and ESXi-hosted appliances or 2,500 on other virtual appliances in Management Only mode when stated CPU, memory and disk requirements are met. Firewall License Management Retrieves license keys with an authentication code and pushes them to managed firewalls, refreshes license status for firewalls with and without direct internet access, and checks in with the licensing server daily to retrieve and push renewals. HA Firewall Pair Upgrade Orchestration Upgrades or downgrades PAN-OS on high-availability firewall pairs from Panorama in one job of up to 200 pairs, running connectivity, configuration-sync and HA-link pre-checks and sequencing the passive-peer upgrade, reboot and failover automatically. Panorama License Conversion Converts an evaluation Panorama virtual appliance to a production, VM-Flex or ELA-licensed appliance by replacing its serial number and auth code and resynchronizing its managed firewalls, with separate handling when a local Log Collector is configured. Panorama Registration and Licensing Registers a Panorama appliance with the Customer Support Portal and activates its support license and firewall management license, on internet-connected appliances by retrieving keys from the license server and on isolated appliances by manual key upload. Software and Content Update Deployment Downloads PAN-OS software and dynamic content updates once on Panorama and installs them on managed firewalls and Dedicated Log Collectors, including devices with no direct internet access and no web interface.
Panorama High Availability Cross-Hypervisor HA Pairs Panorama virtual appliances running on different hypervisors or clouds in private-private, private-public and public-public combinations, subject to plugin version, content version and dynamic address group parity requirements. HA Configuration Synchronization Synchronizes the running configuration on each commit and the candidate configuration on each save or just before failover, while leaving peer-specific settings such as management interface, HA configuration, scheduled exports, disk quotas and the admin password unsynchronized. HA Failover Triggers Fails over when heartbeat polling and hello messages go unanswered or when monitored path destinations become unreachable, and logs preemption events to the System log. HA Logging Failover Notifies managed firewalls of each Panorama HA state change over their SSL connections to both peers so they forward logs to the right Log Collectors, and buffers logs on the firewall while the connection is down. HA Split Brain Recovery Resolves the state where both Panorama peers are active and each manages a disjoint set of firewalls, by restoring peer connectivity and synchronizing configuration from the peer that holds the intended changes. Panorama HA Pair Runs two identical Panorama servers as an active-primary and passive-secondary pair with priority settings, preemption, manual suspension, a tested manual failover, and a defined split of what each state and priority can do.
Cloud-delivered secure access (SASE) for remote users and branches.
Mobile User Access Agent and GlobalProtect Coexistence Switches an endpoint between the Prisma Access Agent and the GlobalProtect app from the agent interface or the PACli command-line tool, disabling one service as it starts the other. Agent Forwarding Profiles Steers endpoint traffic into or outside the tunnel with ordered forwarding rules matched on source application, destination FQDN or IP subnet and DNS handling, plus enforcement options that block unmatched, LAN and inbound connections. Agent Settings Administration Sets the behavior the agent applies on endpoints — connect method, proxy handling, DNS servers and suffixes, inbound MFA prompt handling, support page, sign-out permission, anti-tamper unlock password and quarantined-device login blocking. Agent Staged Rollouts Upgrades the Prisma Access Agent in ordered rings whose membership is matched on username, group and operating system version, removing the need for mobile device management to drive agent upgrades. App-Based Microsoft 365 Support Supports the desktop application versions of Microsoft 365 through Explicit Proxy in addition to the browser-based versions, which need no extra configuration. Automatic Tunnel Restoration Reestablishes an interrupted agent tunnel without user action for up to thirty minutes after network changes, sleep and resume, service restarts or reboots, falling back to the best location when a chosen location stays unreachable. ChromeOS Endpoint Support Connects Chromebook endpoints to Explicit Proxy using a PAC file hosted in Prisma Access or in the customer network. Clientless VPN Publishes internal and SaaS web applications to a browser through the GlobalProtect portal without an installed agent, rewriting responses and passing through Gzip-encoded content. Explicit Proxy Secures user traffic without a tunnel by publishing a proxy FQDN that endpoints reach through a PAC file or forwarding profile, authenticating users over designated authentication domains. Explicit Proxy with GlobalProtect or Third-Party VPN Combines Explicit Proxy for internet and SaaS traffic with a split-tunnel GlobalProtect or third-party VPN for private-app traffic, defining how each client decides which path a request takes. GlobalProtect App Settings Customizes GlobalProtect app behavior for end users through global app settings and match-criteria app configurations targeted at specific users, devices or regions, including the portal address. GlobalProtect App Version Control Selects the active GlobalProtect app version for a Prisma Access deployment, decides whether users may upgrade themselves, and staggers app updates across the user base. GlobalProtect Mobile User Access Terminates agent-based tunnels from endpoints running the GlobalProtect app at Prisma Access gateways, using a default or custom portal domain and operating in tunnel, proxy or tunnel-and-proxy mode across selected Prisma Access locations. GlobalProtect Pre-Logon Establishes a tunnel from an endpoint using a machine certificate before any user logs in, so domain scripts and management tasks run at power-on. GlobalProtect Proxy and Tunnel-and-Proxy Modes Runs the GlobalProtect app as a proxy client that forwards traffic to Explicit Proxy using PAC-file rules, either instead of a tunnel or alongside one that carries private-app traffic. GlobalProtect Tunnel Settings Defines the VPN tunnel the GlobalProtect app builds to Prisma Access, including split tunneling by access route, domain or application, blocking direct local-network access, and authentication-override cookies. On-Premises GlobalProtect Gateway Integration Runs Prisma Access gateways alongside existing on-premises GlobalProtect gateways, setting per-gateway priority by country or region and letting users select a gateway manually. PAC File Hosting and Customization Hosts and customizes the proxy auto-configuration file that steers endpoint browser traffic to Explicit Proxy, either from Prisma Access or from a customer-hosted web server, with defined bypass and exclusion rules. Prisma Access Agent Provides a Windows and macOS client that signs users in to a Prisma Access server, connects them to the best or a chosen location, lets them switch projects, servers and preferences, and can be temporarily disabled or uninstalled. Prisma SASE 5G Secures 5G-connected devices without an agent or inline hardware by mapping 5G network authentication to Prisma Access policy, with flexible traffic routing and multitenant management for service providers. Private Web Application Access for Secure Agentless Access Gives unmanaged users browser-based access to internal HTTP and HTTPS applications reached over a service connection, ZTNA Connector or Colo-Connect, with optional Remote Browser Isolation applied through a custom URL category and URL Access Management profile. Proxy Chaining and Third-Party Proxy Interop Chains Explicit Proxy to an upstream or downstream third-party proxy and supports SOCKS5 with basic authentication so existing proxy architectures can stay in the path. Proxy Mode on Remote Networks Secures outbound internet traffic for headless devices and users at branch sites through Explicit Proxy over a PAC-based connection under a site-based license rather than per-user mobile licenses. Public Web Application Access for Secure Agentless Access Renders third-party SaaS applications for unmanaged users in a cloud-hosted isolated browser that cannot be disabled, selecting isolated domains through URL categories, targeting isolation only at unmanaged users, and maintaining managed certificates for the access domain. Secure Agentless Access Publishes an HTML5 browser portal on a default or custom domain that authenticates unmanaged users through the Cloud Identity Engine and gives them their assigned applications without an agent, with portal branding, concurrent-connection limits, idle and maximum session timers, split-tunnel handling, and an admin view that terminates active connections. Secure Agentless Access Profiles and Policies Grants named users and user groups access to specific Secure Agentless Access applications and application groups through portal policies, and binds each policy to a profile that enables or disables copy, paste, file upload, file download and audio passthrough per RDP, SSH and VNC session type. Secure Agentless Access Remote Protocol Applications Defines the RDP, SSH and VNC applications reachable from the Secure Agentless Access portal by destination FQDN or IP address, port and stored credentials, lets end users add their own apps when permitted, groups applications for policy reuse, and transfers files to and from the remote host over SFTP or a transient drive. SOCKS5 Proxy Support Accepts SOCKS5 connections with basic authentication on port 1080 so non-web TCP traffic from servers and endpoints without an agent can be secured through Prisma Access. Static IP Address Allocation for Mobile Users Assigns a persistent IP address to an individual mobile user so applications that authorize access by source IP address continue to work. Third-Party Enterprise Browser Integration Authenticates and authorizes users of a third-party enterprise browser through Explicit Proxy by exchanging an uploaded public certificate and an encoded tenant identifier, so those browsers reach SaaS and private web applications over the same secured path as the Prisma Browser. Ticket Request to Disable GlobalProtect Requires a user who wants to disable the GlobalProtect app to request a code that an administrator generates against an agent override key.
Identity, Authentication & Compliance Posture Authentication Methods and Profiles Authenticates users through SAML, RADIUS, TACACS+, LDAP, Kerberos, multi-factor and local database services bound into authentication profiles, with single sign-on and authentication sequences across methods. Authentication Rules and Portal Specifies which traffic requires authentication and which profile applies to it, presenting an authentication portal to users who match a rule and recording the resulting IP-to-user mapping. Certificate Profiles and Revocation Checking Validates client and machine certificates against configured certificate authorities with CRL and OCSP revocation checks, timeouts, username-field extraction and rules for blocking sessions whose certificate status is unknown, unreachable or issued to another device. Cloud Identity Engine Authentication Authenticates mobile users against a SAML 2.0 identity provider through the Cloud Identity Engine, with metadata-driven profile setup, a selectable username attribute, a SAML test action and directory-sourced user group mapping. CloudHSM Support Stores the private keys used for SSL decryption certificate signing in a customer-owned AWS CloudHSM cluster instead of in the Prisma Access configuration, with per-service HSM provider profiles, active and backup profiles per location group, health checks and connectivity tests for mobile user, remote network and Explicit Proxy traffic. FedRAMP Deployment Runs Prisma Access in FedRAMP Moderate and High environments with FedRAMP-specific activation paths, plugin and dataplane requirements. HIP Redistribution Forwards host information reports collected by Prisma Access to on-premises gateways, next-generation firewalls and Panorama so HIP-based policy is enforced consistently, and collects HIP data from internal gateways for remote network users. Host Information Profile Checks Collects endpoint host data on connection and hourly thereafter, matches it against HIP objects and Boolean HIP profiles used in security rules, supports custom registry, plist and process checks, and shows users a pop-up or tray notification on match or non-match. Kerberos Authentication for Explicit Proxy Authenticates Explicit Proxy users transparently against Active Directory using a generated Kerberos keytab. Log Storage Region Selection Pins a tenant's Strata Logging Service storage to a chosen region at activation, with all tenants that are monitored together required to share that region. Multiple Portals with Separate Authentication Publishes a second GlobalProtect portal on port 8443 that inherits the primary portal's configuration but uses a different authentication profile, so one tenant can offer two authentication methods. Prisma Access China Deployment Operates a single-tenant deployment managed by a Panorama located in mainland China, using China-specific images, update servers, support-portal endpoints and a China log-storage region. Prisma Access Local Authentication Authenticates mobile users against a local profile of users and groups held in the tenant when no external identity provider is used. Quarantine List Redistribution Adds compromised devices to a quarantine list automatically or manually and redistributes it among mobile user locations, service connections, Panorama and on-premises firewalls so a quarantined device is blocked wherever it reconnects. Re-Authentication and Session Timers Controls how often agent users must re-enter credentials through a refresh-token lifetime, an advance notification window with a custom message, a separate gateway session timeout, and an aggressive mode that forces re-authentication on reconnect, reboot and session extension. User-ID Mapping and Redistribution Shows live user-to-IP and user-to-group mappings, controls which service connections redistribute those mappings, and preserves pre-NAT User-ID and Device-ID identity to downstream next-generation firewalls. Windows Hello for Business Authentication Signs Prisma Access Agent users in with a PIN or biometric on Microsoft Entra ID-joined Windows devices by detecting the Primary Refresh Token, optionally suppressing the embedded browser.
Network & Traffic Services App Acceleration Optimizes individual user sessions in real time to raise throughput for mobile user and remote network traffic, generating per-domain certificates from an imported root CA to accelerate SaaS applications and reporting the gain as real user metrics, now available across additional Prisma Access locations including Bahrain, Ireland, and Sweden. App Edge Network Policies Scopes App Acceleration and Private App Security to selected traffic through up to ten ordered policy slots covering port inclusion or exclusion, IP, subnet and port exclusions, multipath TCP bypass and AWS FSx multi-availability-zone compatibility. BGP Routing Controls Peers Prisma Access with customer premises equipment over eBGP and tunes the exchange with peer and local addressing, MD5 secrets, an MRAI timer, mobile user route summarization, no-export community tagging, default-route origination, route filtering and metrics, and advertisement suppression. Compute Location Management Remaps a deployed Prisma Access location onto a newly introduced compute location to improve latency, reissuing gateway, portal and service endpoint addresses in the process. Context-Driven IP Address Manager Assigns IP addresses to mobile users, remote networks, service connections and ZTNA Connectors according to export-control and jurisdiction context so traffic stays within permitted regions. Country and Backbone Routing Options Routes traffic between sites over the Prisma Access backbone or a service provider backbone, and secures cloud desktop traffic such as AWS WorkSpaces through PAC files or a site-to-site tunnel. DNS Resolution and Proxy Resolves internal domains through customer DNS servers and external domains through a cloud default or custom server, proxying requests per rule for mobile user, remote network and ZTNA Connector deployments with defined caching, retry and pending-request limits. Dynamic DNS Registration Writes A and PTR records for connected GlobalProtect endpoints into an enterprise DNS server over authenticated NSUPDATE using TSIG or Kerberos keys, with fallback or override domain handling and secondary-server failover on DNS error codes. IP Address Allocation and Retrieval Assigns and exposes the addresses a deployment uses — mobile user client IP pools, static per-user allocation, loopback, egress, public and service endpoint addresses — with capacity planning by city, egress IP allow lists and notifications when addresses change. IP Optimization Reduces the number of public egress addresses a mobile user or Explicit Proxy deployment consumes so fewer addresses need to be allow-listed at SaaS providers. IPv6 and Dual-Stack Support Runs the infrastructure subnet, mobile user pools, service connections and remote networks with IPv6 addressing alongside IPv4, including native IPv6 IPSec tunnels and IKE gateways and the choice of exchanging IPv4 and IPv6 routes over IPv4, IPv6 or separate BGP sessions. Mobile User IPv6 Sinkhole Assigns dual-stack endpoints an IPv6 address, routes their IPv6 traffic into Prisma Access and discards it with a built-in policy so endpoints fall back to inspected IPv4. No Default Route Network Support Secures internet access for branch networks that carry no default route by combining proxy-mode agents, internally hosted PAC files, internal DNS records and destination NAT to the Explicit Proxy and portal addresses. Prisma Access Service Infrastructure Establishes the backbone that carries traffic between mobile users, branch sites and service connections from an RFC 1918 infrastructure subnet, an infrastructure BGP autonomous system number and an internal domain list. Prisma Access Zone Mapping Maps the zones used in security policy to the trust, untrust and Clientless VPN zones Prisma Access maintains internally, since the cloud infrastructure has no administrator-configured interfaces to bind zones to. SASE Resilience and Business Continuity Deploys Prisma Access and its integrated services such as Cloud Identity Engine and Enterprise DLP across multiple regions per tenant, failing traffic over transparently when a cloud provider region fails. Traffic Replication Copies mobile user and remote network traffic at selected compute locations into encrypted PCAP archives in customer-owned Google Cloud storage buckets, optionally after applying decryption policy, with Pub/Sub notifications and a 72-hour retention window.
Security Policy & Threat Prevention Advanced URL Filtering Classifies sites with the PAN-DB cloud into URL categories and enforces web access and decryption policy on them, including restricting where users may submit corporate credentials and customizing the URL response page. Advanced WildFire Analysis Forwards files, executables and email links to the WildFire cloud and applies inline machine-learning analysis to block malware, including inline prevention of AI-generated malware on Explicit Proxy traffic. Country-Based Connection Blocking Drops inbound login attempts to GlobalProtect, Explicit Proxy and remote network deployments from specified countries using named pre-rules tagged for embargo enforcement, matched on geolocation of the source address. DNS Security Analyzes DNS requests in real time with machine learning and distributes DNS signatures to block malware using DNS for command and control and data theft. Enterprise Data Loss Prevention Detects and acts on sensitive content with predefined and custom data patterns, data profiles with confidence levels, optical character recognition of images, exact data matching against structured sources, and a DLP incident dashboard. Explicit Proxy Block Settings Blocks Explicit Proxy destinations at the DNS resolution stage based on DNS Security categories, URL filtering categories or external dynamic lists, returning a block page on the initial connection request. Explicit Proxy Traffic Restrictions Restricts Explicit Proxy internet traffic to specific destination addresses using special objects and customizes the block pages users see. File Hash-Based Blocking Blocks specific files traversing Explicit Proxy by matching their hash values. IoT Security Identifies connected devices from their network behavior using machine learning, maintains a context-aware device inventory, and raises alerts when a device deviates from its baseline. Remote Browser Isolation Executes browsing sessions for selected website categories away from the user's device, defining which browser actions are permitted and applying a session theme, and can hand off to a third-party isolation provider. The Prisma Access gateway hosting RBI now supports Oracle Cloud Infrastructure in addition to Google Cloud Platform. SaaS Security Inline Discovers sanctioned and unsanctioned SaaS applications and user activity from Prisma Access logs, scores their risk, adds SaaS security posture management, identifies which SaaS tenant a session belongs to so corporate instances are allowed while personal ones are blocked, and feeds App-ID rule recommendations into the web access policy. Security Policy Rules Allows or denies traffic with pre-rules, post-rules and default rules matched on App-ID, User-ID, Device-ID, zone, address and service, blocking private application access unless a rule explicitly permits it. Device-ID matching covers remote networks and mobile users. SSL Decryption Decrypts TLS sessions under forward-proxy rules and profiles so inspection services can read the traffic, including hybrid post-quantum key-exchange sessions, with bypass lists, ALPN stripping for HTTP/2 uploads and best-practice defaults applied during onboarding. Threat Prevention Applies antivirus, anti-spyware and vulnerability protection profiles backed by frequently updated Palo Alto Networks threat intelligence, with Threat Vault coverage lookup available in the management console. Unsanctioned Application Sync from Microsoft Defender Syncs up to 25,000 applications marked unsanctioned in Microsoft Defender for Cloud Apps into a custom URL category and automatically generates the web access and pre-rule security policy that blocks them inline. URL Response Page Customization Generates and customizes the block and notification pages users see when policy restricts a URL, including organization branding, messaging and acknowledgment or redirect options.
Branch & Site Connectivity Bulk Remote Network Onboarding Exports an onboarded remote network configuration to CSV and reimports an edited file to onboard up to 100 further sites with their IPSec tunnel and IKE gateway settings. High-Bandwidth Remote Site Aggregates several remote network connections at one location onto separate IPSec termination nodes and load balances them from the customer equipment with ECMP and BGP for outbound internet access. Primary and Secondary IPSec Tunnels Terminates a remote network site on a primary and an optional secondary IPSec tunnel, falling back to the secondary while the primary is down and returning when it recovers. Prisma Access for Clean Pipe Gives a service provider a per-tenant dedicated instance that secures the tenant's outbound internet traffic arriving over a Google Cloud Partner Interconnect, onboarded in fixed bandwidth increments with optional ingress QoS and redundant availability zones. Prisma Access Internal Gateway Turns remote network instances into GlobalProtect internal gateways so on-site users authenticate and submit host information without a tunnel, with optional cloud-hosted internal host detection using PTR records on the remote network DNS proxy. Public Cloud Virtual Network Onboarding Onboards an AWS VPC, Azure virtual network or Google Cloud VPC as a remote network over an IPSec tunnel with static or BGP routing, so security policy applies to cloud-hosted resources without backhauling their traffic to a data center. Remote Network Bandwidth Allocation Allocates licensed remote network bandwidth either per compute location or per individual location, and migrates an existing deployment between the two allocation models. Remote Network Onboarding Connects a branch site to Prisma Access over one or more IPSec tunnels defined by site type, primary and secondary locations, active/active or active/passive tunnel mode, circuit count and static or BGP routing. Remote Network QoS Applies QoS profiles to remote network and Clean Pipe traffic to shape and guarantee bandwidth per site, with the guaranteed bandwidth adjustable after onboarding. SASE Private Location Runs Prisma Access capacity inside a customer-operated VMware ESXi environment using a hypervisor resource profile, for locations that must stay on customer premises. Secure Inbound Access for Remote Sites Publishes applications hosted at a branch site to internet users by allocating public IP addresses and mapping them to private IP, port and protocol combinations, with optional dedicated IPs, source NAT and SYN and ICMP flood thresholds. Service Provider Interconnect Remote Networks Onboards a branch or campus site over a service provider interconnect using the PA Connect transport type instead of an IPSec tunnel, taking native IP ingress with the interconnect connection and bandwidth prefilled, static routing to branch CIDRs, and interconnect status and CNAT loopback address shown in the remote network list. Shared Desktop and Terminal Server Support Integrates shared-desktop VDI environments with Prisma Access through a terminal server so multiple users on one host are identified and secured individually. Third-Party SD-WAN Integration Connects third-party SD-WAN fabrics to Prisma Access either as manually built IPSec tunnels per site or through API-driven integrations that provision tunnels, exchange routing data and align policy, with on-demand site discovery that finds newly added SD-WAN networks and turns them into remote networks.
Private Application Connectivity Colo-Connect Attaches Prisma Access to a colocation performance hub over Google Cloud dedicated or partner interconnects, providing up to 100 Gbps per compute region through paired links, VLAN-attachment connections and Colo-Connect service connections in active/active or active/backup mode. Colo-Connect MACsec Encryption Encrypts traffic on dedicated Colo-Connect links with IEEE 802.1AE MACsec using up to five scheduled pre-shared keys per link and an optional fail-open setting. Managed Cloud WAN NCC Gateway Integration Connects Prisma Access to a Google Cloud Network Connectivity Center gateway using a Secure Access Connect realm pairing key, then onboards Managed Cloud WAN service connections and remote networks of up to 10 Gbps that carry mobile user, branch and east-west traffic over direct peering interconnects instead of IPSec tunnels. Multi-Connection Data Center Bandwidth Combines more than two service connections to one headquarters or data center location, with routing preferences and a designated backup connection, to raise available private-app bandwidth. NGFW ZTNA Connector Integration Turns Panorama-managed hardware and VM-Series next-generation firewalls into ZTNA Connectors, with the Cloud Services plugin registering each firewall and pushing generated IPSec, BGP, NAT, loopback and DNS proxy configuration so private applications behind them are reachable, including applications in overlapped IP networks. Service Connection Multi-Cloud Redundancy Backs a service connection with an in-country alternate cloud provider location so private app access survives the loss of a single provider region. Service Connections Builds IPSec connections from Prisma Access to a headquarters or data center so mobile users and branch sites reach private resources, with predefined branch-device crypto templates, primary and backup tunnels, static or BGP routing and optional source NAT of user and infrastructure addresses. Traffic Steering Redirects internet-bound or project-scoped traffic to a designated service connection with ordered rules matched on source users and addresses, destinations and services, including dedicated-connection zone mapping. ZTNA Connector Connects private applications to Prisma Access through customer-deployed connector virtual machines that auto-tunnel to the nearest location, exposing applications as FQDN or wildcard targets with reachability probing and hidden private addresses. ZTNA Connector Active Directory Support Supports Microsoft Active Directory Domain Services behind ZTNA Connector by resolving DNS SRV queries end to end, prepopulating the TCP and UDP ports Active Directory services need on a target, and keeping the domain controller's data center IP address so traffic to it is not destination-NATed. ZTNA Connector Application Tags Assigns up to five tags to FQDN, wildcard and IP subnet application targets, propagates a wildcard's tags to applications discovered under it, and turns the tag-to-IP mappings into address objects that keep dynamic address groups used in security policy current without a commit. ZTNA Connector Deployment Platforms Runs the ZTNA Connector virtual machine on Amazon Web Services, Microsoft Azure, Google Cloud Platform, VMware ESXi, KVM and Hyper-V, and discovers application targets automatically from Cloud Identity Engine or private AWS environments. ZTNA Connector Server-Initiated Traffic Lets data center servers open TCP, UDP and ICMP sessions toward GlobalProtect users, remote network hosts and other connector data centers through a connector group, source-NATing the flows to the connector tunnel address and advertising the destination prefixes to the data center router statically or over BGP. ZTNA Connector Upgrades Upgrades the connectors in a connector group immediately or on a schedule, either in parallel or as a rolling upgrade that drains each connector within a configurable timeout while the remaining connectors carry new sessions.
Monitoring, Logging & Digital Experience Activity Dashboards and Reports Presents interactive dashboards of applications, threats, users and security subscriptions, offline and scheduled reports, and artifact search over file hashes, URLs, domains and IP addresses with threat-intelligence context. App Security Visibility Shows App Security detections through a Command Center overview, Policy Insights pages that rank policies by hits with impacted users, apps and geography, and an Application Insights dashboard that drills from application down to individual blocked requests. Autonomous Digital Experience Management Measures end-to-end experience for real and synthetic application traffic across mobile users and remote sites without extra agents or appliances, and in its AI-powered tier automates diagnosis to shorten time to resolution. Connectivity and Tunnel Status Monitoring Reports the provisioning, configuration-sync, tunnel and BGP state of remote networks, service connections, Clean Pipes and Colo-Connect links and connections, with throughput, bytes transferred, peak and 95th-percentile bandwidth and disconnection counts. Incident Settings Customization Enables, disables or suppresses for a time range the incidents a tenant receives, at either incident category or individual incident code level, scoped to selected sites and associated notification profiles. Incidents and Alerts Raises alerts when a monitored condition persists, correlates them into incidents carrying severity, affected users and sites, remediation playbooks, metrics and parent-child relationships, clears them automatically when the underlying condition recovers, and documents every Prisma Access and AI-Powered ADEM incident and alert code. Log Forwarding to External Destinations Forwards logs held in Strata Logging Service to external SIEM and storage destinations through syslog profiles in CEF format or HTTPS profiles with per-destination authorization, filtered by log type and tested for connectivity before activation. Notification Profiles Delivers selected incident and alert categories to email recipients, authenticated webhook endpoints with a documented JSON schema, or ServiceNow tables with mapped fields and optional bidirectional status sync, scoped per subtenant and recorded in a subscription log and ServiceNow audit log. Prisma Access Logs Records system, configuration and network events for all Prisma Access traffic in Strata Logging Service and presents them in the Log Viewer in Strata Cloud Manager and in the Panorama that manages Prisma Access. Strata Cloud Manager Insights and Command Center Summarizes deployment state across applications, users, branch sites, data centers, ZTNA connectors, network services such as GlobalProtect authentication and DNS, and per-location health in a single interactive console. Subscription Usage Visibility Reports consumption against the base subscription and add-ons — unique users connected, remote network bandwidth consumed and service connections deployed. Third-Party Branch Infrastructure Visibility Pulls device inventory, health and alerts from a third-party LAN and WAN edge platform into the SASE Health dashboard using that vendor API, mapping its branch sites to Prisma Access locations by active tunnel and adding its access points, switches and WAN edges as segments in the site experience view. Third-Party Log Ingestion Ingests logs and telemetry from external sources such as cloud providers, identity systems, endpoint tools and third-party firewalls into Strata Logging Service so they can be analyzed alongside Prisma Access logs.
Licensing, Activation & Onboarding Add-On License Catalog Offers optional entitlements alongside the base subscription — App Acceleration, Autonomous DEM, Enterprise DLP, IoT Security, SaaS Security Inline, CASB, Remote Browser Isolation, ZTNA Connector, Colo-Connect, Private App Security and additional service connections. Guided Onboarding Workflows Walks a new deployment through first-time setup of GlobalProtect, Explicit Proxy, site-based remote networks, service connections and ZTNA Connector with best-practice defaults and automatically created Day 0 security policy. License Activation Through Common Services Claims a purchased Prisma Access subscription through Common Services, creating the tenant, Strata Logging Service instance and Cloud Identity Engine instance for either Strata Cloud Manager or Panorama management, including the mainland China and Prisma SD-WAN bundle variants. License Allocation and Sharing Distributes a subscription's mobile user, bandwidth, service connection, location and log-storage quantities across a tenant hierarchy, and later increases or reallocates those quantities from the tenant or subscription tables. License Editions and Unit Metering Sells Prisma Access as Secure Web Gateway, ZTNA or Enterprise editions metered in units, where one unit is one mobile user or 1 Mbps of remote network bandwidth, and gates which security capabilities a tenant may configure. License Reset and Transfer Moves a Panorama-managed Prisma Access license between Panorama appliances or upgrades it from evaluation to production while preserving deployed instances and public and loopback IP addresses. License Validation and Compliance Check Shows the active license edition, its included services and expiration, and flags configuration that the current license no longer covers so the administrator can correct it. Panorama Account Verification Binds a Panorama appliance to a Prisma Access tenant by generating a one-time password in Common Services or the support portal and entering it in the Cloud Services plugin to establish the secure control channel. Site-Based Remote Network Licensing Licenses branch sites by predefined bandwidth tier from Very Small to X-Large instead of by aggregate compute-region bandwidth, with egress NAT and regional redundancy included in each site license.
Service Lifecycle & Operations Configuration Commit and Push Saves configuration locally and pushes it to the Prisma Access infrastructure with a selectable push scope per component and admin scope, reporting job progress and outcome. Connectivity Diagnostics Troubleshoots reachability and traffic handling with ping, traceroute and nslookup tools for ZTNA Connector applications, the PACli command-line tool for agent traffic rules and connection logs, and remote shell access to a managed endpoint. Panorama Cloud Services Plugin Adds the Cloud Services menu to Panorama through which Prisma Access is deployed, configured and monitored, installed and upgraded either from the support portal or directly from Panorama. Panorama High Availability for Prisma Access Pairs two Panorama appliances as active-primary and passive-secondary so management of Prisma Access survives the loss of one appliance, tying both serial numbers to the same subscription auth codes. Panorama to Strata Cloud Manager Migration Migrates an existing Panorama-managed Prisma Access configuration to Strata Cloud Manager management through an in-product workflow. Predefined IPSec Device Templates Supplies IKE and IPSec cryptographic profiles preconfigured for common third-party IPSec and SD-WAN branch devices so service connections and remote networks onboard without hand-built crypto settings. Proxy Server Support for the Management Plane Supports a customer proxy server between Panorama, the Prisma Access infrastructure and Strata Logging Service, with defined behavior for onboarding, log queries and certificate revocation checks. Release and Upgrade Management Publishes Preferred and Innovation release types on a defined software and content update cadence, upgrades the dataplane separately, exposes the running software versions and sends upgrade alerts. Site Access Issue Reporting Accepts user reports of websites that block Prisma Access egress IP addresses and returns the resolved address and status for the reported URL.
Tenancy & Administrative Control Configuration Snippets Groups a reusable base configuration into a labeled snippet with automatic or manual object-name prefixes, associates it with a configuration folder and scope, and pushes it to project deployments. Dynamic Privilege Access Defines projects as a user group plus an IP pool and Prisma Access location group so an authorized user reaches only one customer project at a time, assigning project addresses from a built-in DHCP server and signing the user out of the previous project on switch. Panorama Multitenancy Hosts up to 200 independent Prisma Access tenants on one Panorama appliance, giving each its own access domain, templates, template stacks and device groups, migrating an existing single-tenant configuration into the first tenant, and supporting tenant deletion and deprovisioning. Project Admin Role and Scopes Delegates project definitions and project-specific agent settings to a Project Admin identity bound to a management scope, preventing that administrator from viewing or changing other projects' configuration. RBAC for Secure Agentless Access Restricts who can view, create, modify or delete Secure Agentless Access configurations using predefined or custom Strata Cloud Manager roles, requiring both an All Apps & Services role and a Cloud Identity Engine role assignment before the feature becomes visible to a user. Tenant Log Separation Separates logs by tenant in a multitenant deployment by filtering on device group, and maps device group hierarchy IDs in forwarded logs back to the owning tenant. Tenant-Level Administrative Roles Scopes an administrator to a single tenant with a Device Group and Template admin role bound to that tenant's access domain, and withholds Cloud Services plugin access from administrators who must not view or change Prisma Access configuration.
APIs & Automation Clean Pipe API Creates Clean Pipe instances for tenants and retrieves their allocated IP addresses using a generated API key. IP Address Change Notifications Notifies subscribers when Prisma Access IP addresses change so downstream allow lists and peer configurations can be updated before traffic breaks. IP Address Retrieval API Returns and pre-allocates the public, loopback and egress addresses a deployment uses so allow lists can be updated ahead of a change, with legacy scripts retained for older integrations. Prisma Access and Insights APIs Exposes REST APIs for managing Prisma Access and for querying Prisma Access Insights data programmatically. Third-Party Device-ID API Accepts, queries and deletes device verdicts from third-party device identification sources, with endpoints for verdict statistics, per-IP lookup and creation of the certificate and token used to authenticate.
Web Application & API Security App Security Behavioral Analysis Learns each front-ended application's normal behavior, detects anomalies against that baseline and generates recommended mitigation policies that an administrator can vet, mute for thirty days or disable per application. App Security Policies Evaluates traffic against time-bounded Bypass policies, Custom policies expressed as Common Expression Language rules or rate limiters, and OWASP Core Rule Set policies with tunable paranoia level, anomaly threshold, content parsing, ignore patterns and exceptions, each held in Recommended, Preview or Enforced state. App Security Service Adds a web application firewall layer at inspection nodes colocated with Prisma Access compute locations, protecting private applications already in the traffic path and public applications routed to it through customer CNAME records and uploaded per-domain certificates, now available across additional Prisma Access locations including Bahrain, Ireland, and Sweden. Protected Application Definitions Defines the applications App Security protects — added manually with their destination domains or adopted from continuously discovered unprotected domains — and bundles them into application groups that share a policy.
The secure enterprise browser acquired with Talon.
Client platform & customization Browser behavior customization Sets startup behavior, default search provider, search suggestions, page translation, incognito availability, user-agent string, default-browser prompting, DNS client and external app launching. Browser branding Applies an organization's logo, name, theme and brand colors, and custom dialog text to user-facing browser elements. Browser control pane Gives the end user an in-browser panel for posture status, locking the browser, switching profiles, logging out and toggling the sidebar. Browser localization Presents browser menus, settings and Prisma-specific dialogs in nineteen fully supported languages, with partial machine translation for others. Captive portal sign-in window Opens a sandboxed Wi-Fi sign-in window so users can complete captive portal authentication without bypassing browser policy. Client diagnostics page Exposes proxy status, routing type, update service state and integration diagnostics on an in-browser troubleshooting page. Client installation and distribution Distributes the browser through Jamf, Intune, Workspace ONE, IGEL App Portal, Linux package repositories, online and offline installers, or a self-service download page. Desktop browser client Runs a Chromium-based managed browser on Windows, macOS, Ubuntu, Fedora and IGEL OS with defined minimum OS and architecture requirements. End-user onboarding wizard Shows new users a configurable first-run sequence of up to eight pages covering welcome, personalization, data import and feature orientation. Mobile browser client Runs the managed browser on iOS and Android sharing the same policy rules, with a documented subset of controls supported on mobile. Mobile web app notifications Raises native iOS and Android system notifications for web applications such as Outlook and deep-links them back into the managed browser. New tab and home page Configures the landing surface users see on startup — home page, managed shortcuts, background image, admin messages, custom notices and identity-provider-synced application tiles. Prisma Browser Extension Applies a subset of Prisma Browser policy inside consumer Chromium browsers on Windows, macOS and ChromeOS, deployed by MDM, registry or Google Workspace. Profile portability Carries a user's bookmarks, settings, passwords and extensions between machines through cloud profile sync or Windows roaming profile files. Update channels and upgrade management Controls how clients take weekly Chromium-aligned updates through default or long-term-support channels, pinned versions, deployment delays and relaunch grace periods. Version rollback control Forces Windows clients running a newer build to downgrade to a selected pinned version on next relaunch.
Visibility & analytics Account usage analytics Builds an inventory of application accounts from successful logins, scored for risk and spotlighted for non-SSO, shared, unknown-app, risky and generative AI usage. Administrative audit log Records every management console action — rule, profile, application, device, user, integration, API key and live session changes — with the acting administrator, client IP and timestamp. Application usage analytics Reports per-application active users, access and data events and transferred volume over selectable time frames across web, private and desktop applications. Dashboards Presents overview, web security, data leakage prevention, assets, policy and user behavior dashboards with rearrangeable widgets filterable by time frame and user group. Device health view Shows a single device's identification, metadata, posture detail and monitored service diagnostics from its last reported telemetry. Event forwarding Streams browser and audit events through Strata Logging Service to external destinations including Syslog, AWS S3, Amazon Security Lake, Splunk, Microsoft Sentinel and Snowflake. Event taxonomy and logging levels Defines the event categories, common and context fields, actions and severities the browser emits, and sets per-rule logging to off, anonymized, full or enhanced with evidence collection. Events log Records browser activity as searchable events filterable by time, category, type, URL, application, action, user, device, policy rule and MITRE technique, with drill-down detail and CSV export. Extension history collection Gathers URLs and download history from the thirty days preceding extension installation on in-scope devices and surfaces them in dashboards and events. Forensic investigations Reconstructs the hour around a suspicious event as a chronological activity chain with per-minute histogram, session metadata, raw event data and attached visual evidence. Live session streaming Requests a user's consent to watch their tab, window or screen in real time for up to thirty minutes and saves a recording of the session. SaaS tenant visibility Detects which tenant a user signed into for Google Workspace, Microsoft 365, Slack and AWS and records the tenant identifiers on the event. Secure Browser Vision console Gathers every Prisma Browser page into a dedicated Strata Cloud Manager view organized as command center, insights, canvas, configuration and system settings. Session recording and evidence capture Records full browsing sessions within named applications and attaches screenshots or short video recordings to events generated by rules using enhanced logging. Sign-in rule check analysis Explains a sign-in decision by listing evaluated rules in priority order and comparing each device group's required attributes against the values the device reported.
Data protection controls Camera and microphone controls Allows or blocks matched websites from accessing the device camera and microphone. Clipboard controls Allows or blocks copying data out of and pasting data into a rule's web applications, with optional prompts and bypass windows. Content inspection and data profiles Conditions data controls on detected content using predefined data profiles and patterns, custom regular-expression content types, and on-device or cloud-assisted scanning with adjustable confidence. File transfer controls Governs file download and upload per rule — allow, browser-protected, non-protected only, redirect to organizational cloud storage or block — filtered by size, type, hash or sensitivity label, with prompts and step-up authentication. GenAI prompt controls Allows or blocks prompts submitted to standalone and embedded generative AI applications, optionally only when the prompt matches a data profile. Print controls Allows or blocks printing from matched pages and restricts output to an administrator-defined list of printers. Read-only webpage Lets users read and download from a matched web application while blocking input into editable page elements, optionally excluding login fields. Request header modification Adds a custom HTTP header or appends a user-agent component to browser requests for matched applications. Screen capture and sharing controls Blocks or selectively permits screenshots, screen recording and screen sharing, including a built-in snipping tool and a curated list of conferencing web apps allowed to share a tab. Typing guard Scans text a user types into HTML form fields in real time and sanitizes content matching the rule's sensitive data definitions before submission. Webpage data masking Replaces sensitive text on matched pages and frames with masking characters, optionally leaving leading or trailing characters visible. Webpage element removal Strips named HTML elements from a page before render using CSS selectors captured with an in-browser element selector tool. Webpage watermarking Overlays pages holding sensitive content with a configurable watermark of company logo, user and timestamp text, or a per-load QR code.
Integrations Advanced WildFire integration Submits transferred files to Advanced WildFire reputation, static and dynamic analysis with size-tiered wait behavior and brute-force unlocking of password-protected archives. Certificate-based browser enforcement Issues each browser a tenant-signed client certificate that Google Workspace context-aware access or an F5 gateway checks so protected applications only open in Prisma Browser. Cloud storage integration Connects Microsoft OneDrive or Google Drive as a download destination through a registered app or service account, with an API for zero-downtime credential rotation. Enterprise DLP integration Applies Palo Alto Networks Enterprise DLP data profiles, machine-learning classifiers, exact and indexed data matching and OCR to browser activity, returning incidents, data snippets and evidence to a shared console. Identity provider application sync Pulls each user's assigned applications from Microsoft Entra ID or Okta and places them as shortcuts on the new tab page. IP-based browser enforcement Routes identity provider authentication through a tenant-dedicated egress gateway in five regions so conditional access rules in Okta, Entra ID, PingOne, OneLogin, JumpCloud or Workspace ONE can reject other browsers. MDM-managed mobile enforcement Passes a per-vendor management key to the mobile browser through standard MDM AppConfig so only enrolled devices match the corresponding device group and can sign in. Microsoft 365 encrypted document integration Opens Microsoft 365 encrypted Office documents inside the browser through a registered Azure application. Microsoft Information Protection integration Reads Microsoft Purview sensitivity labels on files during upload and download so policy can act on the label. Okta device posture provider Returns Prisma Browser device posture attributes to Okta in a SAML assertion so Okta device assurance and app sign-in policies can act on them. Third-party file scanning integrations Registers CrowdStrike Falcon Intelligence, OPSWAT MetaDefender, Votiro, YazamTech SelectorIT or Symantec DLP as alternative file scanning and sanitization engines. WebDriver automation Permits Playwright and Selenium scripts to drive the browser in CI pipelines when an automation token bound to a local service account is present in the environment. Windows account-based SSO Authenticates browser login and web application sign-in against the locally signed-in Active Directory or Entra ID account, including the Microsoft Enterprise SSO plug-in on macOS.
Policy engine & policy objects Administrator roles Assigns Prisma Browser administrators scoped read-write roles for access and data policy, customization, security, device posture, permission requests or read-only analytics. Application directory Maintains the App-ID catalog alongside administrator-defined custom, private, remote-connection and desktop applications, and groups them for policy reference. Application tags and classification Labels applications with custom tags and a sanctioned, tolerated, unsanctioned or unclassified trust level, in bulk or individually, and surfaces them on events. Draft mode and configuration versions Holds policy, application and device group changes in an isolated draft, shows a reviewable diff with authorship, and publishes them as a numbered configuration version that can be rolled back. Permission requests and rule bypass Lets a blocked user proceed with a warning, a stated reason, or an administrator-approved request valid for a configured window, and queues those requests for review. Policy rule types and evaluation Evaluates access and data control, browser security and browser customization rules in priority order, merging matched controls with higher-priority rules winning conflicts. Reusable policy profiles Stores control configurations outside a rule so the same data, security or customization control set can be attached to multiple rules. Rule organization and bulk actions Groups rules into collapsible sections and changes priority, mode or deletion across many rules at once, including move-to-position operations. Rule scoping Restricts a rule to combinations of users, user groups, device groups, public IP networks and device geolocation resolved from OS location services or GeoIP. Sign-in rules Allows, blocks or prompts browser sign-in for users and devices matching a scope of user groups, device groups, networks and locations. Tenant-based policy enforcement Applies a rule only to a named tenant of a multi-tenant SaaS application, identified by domain, account ID, workspace, resource host or region. User and group directory Syncs selected user groups from Cloud Identity Engine directories, supports locally defined groups, and merges duplicate identities across identity providers. Web access control Allows, prompts or blocks access to applications, URL categories and specific URLs, optionally requiring step-up authentication or redirecting extension users into the full browser.
Threat protection Advanced browser protection Validates WebAssembly memory access at the browser's translation layer and terminates writes outside permitted ranges to stop in-memory remote code execution exploits. Keylogging protection Prevents other processes on the device from reading keystrokes typed inside the browser. Live page scanning Runs detection models inside the browser against page runtime, scripts, iframes and service workers to catch evasive web threats without decrypting traffic, blocking high-confidence detections locally and escalating uncertain ones to cloud analysis. Malicious extension detection Classifies each extension version as malicious or low, medium or high risk using taint analysis, JavaScript deobfuscation and threat intelligence, and removes versions carrying a malicious or unknown verdict. Malicious file protection Scans transferred files with Advanced WildFire or a configured third-party engine and blocks or logs malicious verdicts, with an administrator-defined fallback when scanning is unavailable. Malicious URL classification Classifies visited URLs against PAN-DB, real-time URL analysis, advanced DNS and hosts-file sources and blocks phishing, malware, botnet, spyware and keylogger categories. PIN brute-force detection Raises a high-severity event when repeated failed PIN attempts on a device's local browser profile indicate a brute-force attempt. Tamper detection Detects modification of browser binaries, internal files, processes, trust store certificates and infrastructure messages, plus emulator, Frida and integrity-attestation failures on mobile. Windows browser self-protection Loads a Windows kernel-mode driver that protects the running browser process from local interference, with a configurable response when the driver cannot start.
Identity, credentials & session Account protection Appends a browser-held secret to a user's password during reset so accounts on non-SSO applications can only be used from Prisma Browser, including shared accounts. Application login controls Governs how users authenticate to web applications by form, passkey, SAML identity provider, consumer social provider or mutual TLS client certificate, allowing or blocking each by domain with prompts and step-up MFA. Browser session controls Locks the browser after idle time, flushes selected browsing data on close or on a timer, caps concurrent signed-in devices per user, and forces periodic re-authentication. Enterprise password manager Stores, generates, autofills, imports and exports credentials for applications outside SSO from a browser side panel, with optional sharing between colleagues and step-up MFA on retrieval. Identity provider integration Authenticates users through Cloud Identity Engine against Entra ID, Okta, Google Workspace, PingOne and PingFederate, or a local CIE directory, and syncs the permitted user groups. Password saving and autofill controls Permits or blocks the browser from saving website passwords, form autofill data and credit card details. Step-up authentication factor Defines the single factor — PIN code, passkey or identity provider re-authentication — used for MFA prompts, browser unlock and password manager access. Synced data encryption Encrypts each user's synced browser data with a per-identity key held in a secret store that neither vendor staff nor tenant administrators can read, and logs every key access.
Device posture & remediation Desktop posture attributes Checks Windows, macOS and Linux endpoints for OS version, disk encryption, screen lock, endpoint protection, firewall, client certificate, serial number, device management, system integrity, boot mode, processes, files, registry keys, browser version and location, positively or negatively. Device directory Lists enrolled devices with user, OS, browser version, posture state, group membership and last-seen time, filterable and exportable to CSV. Device groups Builds dynamic groups of desktop, mobile, extension and Chromebook devices from posture attributes combined with AND logic inside a group and OR logic across groups. Extension posture attributes Checks devices running the browser extension for operating system version and host browser brand and minimum version. Mobile posture attributes Checks iOS and Android devices for root or jailbreak status, active screen lock, OS version and patch level, device type and manufacturer. Posture remediation wizard Shows a blocked user which posture attributes failed, the current versus required value, customizable step-by-step fixes, shortcuts into OS settings and alternative compliance paths. User and device suspension Revokes browser access for a single desktop device or all of a user's devices immediately, optionally wiping local browser data, with abort and resume paths.
Application access & connectivity Desktop application control Extends allow and block policy to Windows desktop applications through a kernel driver that identifies executables by their embedded original file name. Internet Explorer compatibility mode Renders listed legacy URLs as Internet Explorer 11 inside the browser. Prisma Access integration and traffic routing Routes all traffic, private application traffic only, or no traffic through Prisma Access explicit proxy, with proxy auto-configuration files and internal network detection. Private application access Reaches internal web and non-web applications through ZTNA connectors over MASQUE with HTTP/2 fallback, targeting them by FQDN or wildcard without a full Prisma Access deployment. Remote desktop and shell connections Opens RDP, SSH and VNC sessions inside the browser to administrator-defined or user-created targets, with optional stored credentials, RDS gateways and SFTP file transfer.
Browser hardening Browser hardening controls Restricts browser surfaces attackers reuse — developer tools, casting, native messaging hosts, JavaScript from the address bar, popups, notifications, task manager process termination and external app launching — and encrypts cookies at rest and in memory. Guest mode Opens an ephemeral unmanaged Chromium window from the login page on Windows endpoints where a registry key enables it, with all session data discarded on close. Network protection controls Hardens transport behavior against interception by controlling SSL error bypass, DNS over HTTPS, trusted certificate authorities, basic authentication over HTTP, insecure mixed content, forced HTTPS, post-quantum key agreement, Kerberos delegation and integrated-authentication server allowlists. Privacy storage controls Controls whether cookies, third-party cookies and browser history are stored, kept only for the session, or prevented from being deleted. Protected browsing attack surface reduction Disables exploitable web platform components — JIT and WebAssembly, WebRTC, WebGL, File System Access, Sensors, WebSerial, WebBluetooth, WebUSB, WebHID, PDFium, print preview, QUIC, Clipboard API, local fonts — with per-domain exclusions and strict origin isolation.
Browser extension governance Extension allow and block policy Permits or denies extensions by identifier or risk level through allow-all, block-all, allow-list and block-list rules resolved by a documented precedence model, with bulk ID import from CSV or text. Extension force install Installs and keeps named extensions enabled from the Chrome Web Store or a custom URL, with toolbar pinning, incognito availability and JSON configuration. Extension inventory Lists extensions installed across the fleet with installing users and devices, versions, permissions, publisher statistics and a computed risk score. Extension permission controls Blocks extensions that request named permissions and restricts the host permissions an extension may exercise, globally or per domain.
Onboarding & licensing Guided tenant onboarding Steps an administrator through user onboarding, Prisma Access integration, routing, SSO enforcement, client distribution and first browser policy. License activation and seat allocation Activates Prisma Access bundle or standalone Prisma Browser licenses through Common Services and allocates seats partially across multiple tenants. Managed service provider multitenancy Creates child tenants beneath an MSP root tenant that draw from a shared license pool while keeping users, policy and telemetry isolated per customer.
The next-generation mobile access agent for Prisma Access and NGFW deployments — agent lifecycle, tunnel behaviour and gateway selection on the endpoint.
User Authentication Authentication Browser Selection Presents the SAML login page either in a browser embedded in the agent, which manages cookies, certificate warnings and client certificate selection and closes on success, or in the endpoint's default system browser, selectable through the config file, agent settings or the command line in that order of precedence. Authentication Override Cookie Generates and accepts encrypted endpoint-specific authentication cookies with a selectable encryption certificate and a configurable lifetime, so a user supplies credentials once, and exports that certificate to let agents authenticate to on-premises NGFW gateways on a coexistence tenant. Captive Portal Support Detects captive portals on hotel, cafe and airport networks using predefined URLs and network probes, opens the portal login page in the embedded browser and connects automatically once the user authenticates, with a tap-to-open notification fallback on per-app iOS deployments. Client Certificate Authentication Authenticates users with a client certificate through Cloud Identity Engine, alone or combined with SAML as either-or or both, and selects which certificate to present by restricting the search to the user store, machine store or user-then-machine and by filtering on Extended Key Usage OIDs. Device Single Sign-On Signs users in with their existing device credentials — macOS Platform SSO through an MDM-deployed single sign-on extension profile, and Windows Hello for Business using the Primary Refresh Token in the TPM with a PIN or biometric — falling back to SAML when the token is unavailable. Dynamic Privilege Access Projects Scopes a user's access to the projects they belong to on Dynamic Privilege Access tenants, letting them list, log in to and switch projects from the app or the command line, with an Aggressive Authentication option that tightens session extension behavior. Endpoint Manager Enrollment Enrolls the agent with the cloud Endpoint Manager at first login, after which the endpoint receives its configuration, its list of connectable gateways, an optional client certificate and the access tokens it presents to gateways. Inbound MFA Prompts Receives and acknowledges inbound UDP authentication prompts from multi-factor authentication gateways on a configurable port, accepting them only from a trusted host list, and displays a customizable message with a suppression interval for repeated prompts. LDAP Authentication Authenticates users against existing directory servers through the GlobalProtect portal using LDAP or LDAPS server profiles with optional TLS and server certificate verification, receiving an authentication override cookie the management plane exchanges for access tokens. Re-authentication Timers Sets how often users must explicitly present credentials, which directly controls the refresh token lifetime, plus the advance warning interval and custom message, and separately the gateway session timeout that governs how long an established gateway connection stays valid. Refresh Token Sessions Renews expiring access tokens in the background from a refresh token so the tunnel stays up without user action, notifying the user ahead of expiry and completing renewal silently where the identity provider or LDAP session is still valid. SAML Authentication Authenticates users with SAML 2.0 through Cloud Identity Engine against the customer's identity provider, using authentication profiles with a configurable clock-skew tolerance and an allowlist of the users and groups permitted to authenticate.
Traffic Forwarding Connectivity Options Routes matched traffic direct to the physical adapter, blocks it at the endpoint, bypasses it, or sends it to the nearest gateway with fail-safe or fail-open behavior, and lets administrators build custom connectivity objects combining tunnel, proxy and DNS-resolver methods with a block-or-direct fallback. Container Traffic Support Detects container bridge network subnets on Linux at tunnel startup, including user-defined bridges, injects routes so outbound container traffic goes through the tunnel for policy enforcement, and lets containers resolve names through the host DNS the agent manages. Forwarding Profiles Evaluates an ordered set of forwarding rules against every connection's source application, user location, destination and traffic type and applies the first match's connectivity method, with predefined video-streaming, default and implicit rules and per-group assignment in agent settings. IPv6 Dual-Stack Support Operates on dual-stack networks with a virtual adapter carrying both protocols, IPv6 address pools and DNS servers, tunnels over IPv4 or IPv6 transport, and evaluates forwarding rules against IPv6 destinations; on Linux it instead drops unroutable tunnel-bound IPv6 so applications fall back to IPv4 in milliseconds. IPv6 Sinkhole Assigns the endpoint an IPv6 address, routes all mobile-user IPv6 traffic to Prisma Access and discards it with a built-in policy so endpoints fall back to IPv4, reducing the IPv6 attack surface while leaving link-local and DHCPv6 traffic alone. Local Proxy Interception Runs a local proxy from installation until removal that intercepts every outbound connection, reports the source application, destination and protocol to the routing service, and allows, blocks or redirects it onto the tunnel or a physical adapter, on a configurable port with automatic fallback if taken. MTU Optimization Discovers the optimal path MTU for the tunnel's virtual interface automatically, accounting for SSL and IPSec overhead, to avoid fragmentation and retransmission across intermediate networks, with a manual override in a bounded byte range. Split DNS Applies a forwarding rule to DNS traffic only, network traffic only, or both, so DNS queries for a domain can resolve inside or outside the tunnel independently of that domain's application traffic, and appends tunnel search domains to local ones on macOS. Third-Party Agent Bypass Marks selected traffic as bypassed so the agent does not intercept or modify it and another remote-access agent on the same endpoint can route it, covering DNS, network traffic or both, and falling through to the tunnel or the destination when no other agent handles it. Traffic Objects Defines the reusable objects forwarding rules match on — source applications by executable path with single-component wildcards, destinations as validated FQDNs with optional ports and IPv4 or IPv6 routes in CIDR notation, and user locations by internal host detection or source IP — with CSV bulk upload and predefined destination sets. Transparent Proxy Support Routes outgoing TCP connections through the local proxy to Prisma Access explicit proxy servers as a connectivity method in forwarding profiles, usable instead of the tunnel or as its fallback, with proxy-aware settings for per-connection detection and tunnel-over-proxy behavior.
Agent Deployment Agent Package Download Downloads the installer for each platform — Windows MSI, macOS PKG, Linux AppImage per architecture and a NixOS installer bundle — together with the tenant's deployment configuration file, from the Endpoint Management page. Deployment Configuration File Reads a JSON configuration file, or equivalent Windows MSI properties, at install time to set the server URL and tenant ID, disable the remote shell permanently, enable pre-logon, unload an installed GlobalProtect app, choose the external browser, and set certificate lookup store and Extended Key Usage filters. EDR Process Allow Listing Publishes the macOS and Windows agent executable and system-extension paths that antivirus, EDR and firewall software must allow-list before installation to avoid false positives. Endpoint DLP Packaging Ships separate macOS and Windows installer variants that bundle the Endpoint DLP agent and its system extensions alongside standard packages that do not, deployable only through MDM, with DLP inactive until its own license is activated and the matching variant carried forward on upgrade. Endpoint Platform Support Runs on Windows, macOS on Intel and Apple silicon, iOS, Android, ChromeOS and eight Linux distributions across x86_64 and ARM64, supporting the GNOME and KDE desktop environments and the Wayland and X11 display servers, with a published first-supported agent release per platform. Enrollment CA Certificate Requirements Requires a named root and intermediate certificate authority pair in the endpoint trust store before the agent can enroll with the Endpoint Manager, and documents the Windows, Linux and virtual-machine cases where it must be pushed manually. macOS Configuration Profiles Publishes unified macOS configuration profiles, with published hashes and a manual authoring path, that pre-authorize the content filter, notification, privacy preferences, system extension and VPN payloads so installation needs no end-user approval, plus a separate Endpoint DLP profile. Manual Installation Installs, upgrades and uninstalls the agent by hand on Windows, macOS and Linux, with a self-contained AppImage package that detects the desktop environment and installs only the tray dependencies it needs, and a declarative prerequisite path for NixOS. MDM Deployment Distributes and pre-configures the agent through qualified mobile device management software — Microsoft Intune for Windows, macOS, iOS and Android, and Jamf Pro for macOS — using app assignments, app configuration policies, device profiles, and always-on, lockdown and per-app VPN profiles.
Monitoring & Diagnostics Access Experience Integration Installs, leaves alone or removes the Autonomous DEM Access Experience app alongside the agent, lets users start and stop experience tests, surfaces a per-endpoint experience score in the device inventory, and shows in-app remediation notifications. Agent & Management Logging Sends agent activity and administrator management logs to Strata Logging Service, where the log viewer queries them by field with operators and saved filters and exports results to CSV, covering authentication stages, tunnel establishment and protocol, anti-tamper events and remote shell activity. Endpoint Insights Captures diagnostic snapshots of endpoint and agent state on a daily schedule, on predefined events such as agent disablement or SSL fallback, on administrator demand, and when a user reports an issue, with rate limiting, optional user consent, and a retention period configurable from a week to two years. Insights Analysis Lists the diagnostics collected for a device with their trigger and timestamp and opens each one in the console or as downloadable JSON, showing device and agent details, the active forwarding profile, and a troubleshooting bundle containing agent logs, OS logs, routing table and DNS resolver state. PACli Command Line Provides an on-endpoint command-line tool covering agent status and version, connect and disconnect, gateway list and connection history, tunnel state, HIP, MDM compliance, forwarding rules and connection logs, local proxy, browser choice, projects, endpoint insights, log level, config import and export, and agent enable and disable. Programmatic Agent Control Exposes a documented command sequence returning structured JSON with error codes so another application can drive the agent without user interaction — setting the Endpoint Manager address, switching authentication to CLI mode, retrieving the SAML URL to open, polling enrollment status, and connecting or disconnecting. Remote Log Collection Requests the full agent log bundle from a device without user involvement, with the agent zipping and uploading it to the Endpoint Manager for download, and a verbosity level set per endpoint from the command line. Remote Shell Opens a live terminal session on a macOS or Windows endpoint from the console after the user accepts the request, so an administrator can run diagnostic and agent commands, with every command and its output logged and the session exportable to a file. Self-Healing Applies remediation automatically when a user reports a connectivity problem, first refetching configuration and refreshing the gateway connection locally, then applying further actions chosen by analysis of the uploaded diagnostics, and asking the user afterwards whether the fix worked.
End-User App Experience Agent App Sign-In Lets a user sign in to complete first-time enrollment and connect, connect or disconnect on demand with the lock icon, and sign out where the administrator permits it, on desktop and mobile clients alike. Agent Notifications Signals connection state through a menu-bar or taskbar icon in light and dark mode and raises pop-up notifications for warnings, errors, imminent outages, inbound authentication prompts and approaching session expiry, with an in-app banner the user clicks to extend the session. App Settings Window Shows the user their user ID, connected location, assigned IPv4 and IPv6 addresses, server and agent version, and lets them toggle desktop notifications, open the privacy policy and the administrator-set support page, and disable the agent if allowed. GlobalProtect App Switching Lets a user move between Prisma Agent and an installed GlobalProtect app from the agent app or the command line, disabling the outgoing agent first, with the documented behavior of tunnel, notifications, enforcer, experience monitoring, remote shell and anti-tamper across the switch. Linux System Tray Renders the agent's tray icon and menu on Linux across GNOME and KDE on both Wayland and X11, using the native notifier protocol on KDE and an indicator extension on GNOME, with per-distribution setup steps where the extension is not present. Mobile App Experience Provides the Android and iOS client flows — installing from the public app stores on unmanaged devices or by MDM push, granting notification and VPN-profile permissions and the device passcode or biometric, connecting under always-on, on-demand, per-app or connect-rule configurations, picking a location, viewing settings and connection statistics, sharing logs, signing out and uninstalling. Tenant Server Switching Lets a user add up to twenty Prisma Agent server addresses and move the agent between tenants, reauthenticating on the new server, restricted to unmanaged devices on mobile and to the login window on Linux, and lets administrators forbid editing the server FQDN so users cannot connect to an unauthorized server. User Issue Reporting Lets a user describe a connectivity problem in the app or with a command-line flag to start diagnostic collection and, where enabled, self-healing, then rate whether the remediation worked, and works even when signed out by applying local steps only.
Endpoint Posture HIP Data Collection Collects host information from the endpoint on connection and hourly thereafter and submits it to the gateway, with a configurable maximum wait time, custom checks that add or exclude specific data, a certificate profile for matching the machine certificate, and automatic retries when submission fails. HIP Notifications Shows the user a pop-up or system-tray message on HIP profile match or non-match explaining why access was allowed or denied and pointing at remediation, configurable per profile. HIP Objects & Profiles Builds HIP objects that match categories of the raw host data, such as anti-malware presence and definition age or disk encryption, and combines them into HIP profiles that security policy rules use to gate access on device posture, generating a match log entry on each check. HIP Report Retrieval Requests and downloads the latest host information profile report as XML for up to 20 selected devices from the console, as a queued job with a time-limited download link, so administrators can see which posture check failed. MDM Compliance Enforcement Treats the customer's mobile device management system as the authority on device compliance, polling it with configured API credentials at set intervals and on demand, and blocking tunnel establishment or tearing down active tunnels for devices that are unenrolled or failing compliance. Quarantined Device Blocking Prevents users from logging in from devices marked as quarantined and notifies them why, with the setting shared between Prisma Agent and the GlobalProtect app.
Service Infrastructure Agent Service Infrastructure Setup Provisions the Prisma Agent environment on a tenant by setting the agent domain name that endpoints connect to, per-region client DNS resolution and internal domain resolve rules, and the client IP address pools assigned to connected endpoints. Gateway Configuration Registers the internal and external gateways agents may connect to, each with an FQDN or IP matching its certificate common name, source regions and a priority used in gateway selection, alongside the Prisma Access locations available by default. GlobalProtect Coexistence Tenant Onboards Prisma Agent onto a tenant that already runs GlobalProtect, sharing client DNS and IP pool settings and the service connections behind them so both endpoint agents run from one tenant during migration. Management Plane Support Supports three deployment shapes — Prisma Access managed by Strata Cloud Manager, Prisma Access managed by Panorama, and NGFW managed by Panorama — inheriting infrastructure, gateway and authentication settings from the management plane while agent-specific settings stay in Strata Cloud Manager. Multi-Region Service Continuity Runs the Endpoint Manager across multiple regions and reroutes management traffic to a healthy region during an outage without reauthentication or re-enrollment, resumes staged rollouts afterwards, and keeps agents enforcing their last cached policy for up to seven days offline. Supported Control-Plane Locations Runs the Prisma Agent control plane in a published set of country locations across the Americas, EMEA and Asia-Pacific, from which administrators choose the one nearest their users.
Tunnel Connectivity Automatic Tunnel Restoration Watches for network status changes, sleep and resume, service restarts and reboots and rebuilds the tunnel without user action or reauthentication for up to 30 minutes, retrying the pinned location before falling back to the best location in always-on mode. Connect Modes Connects either automatically at every device logon, only when the user chooses, or for a nominated set of managed apps on mobile, plus on-demand connect rules that bring the tunnel up when the user reaches a named domain, with an Android lockdown option that blocks all network traffic until the tunnel is established. Gateway Selection Picks the best gateway automatically from latency, availability, source region and priority, or lets the user pin a preferred location from the app that persists across reconnects, reboots, sleep and wake and token expiry until cleared, with internal gateways and a grace period overriding the preference. Internal Host Detection Determines whether an endpoint is on the corporate network by reverse DNS lookup of a configured address and hostname and suppresses the tunnel when it is, additionally validating the internal gateway's TLS certificate so a spoofed DNS response cannot make an external network look internal. Pre-Logon Device Tunnel Builds a tunnel authenticated by a machine certificate before any user logs in so managed devices can be patched and administered unattended, then hands over to the user tunnel immediately, after a configurable timeout, or only once the user authenticates. Tunnel Protocol Fallback Attempts an IPSec tunnel first and switches transparently to SSL over TCP port 443 when IPSec is blocked or fails, logging each fallback so administrators can see where it happens.
Agent Fleet Management Device Detail View Shows one endpoint in detail — hostname, private and public IP, host ID, platform, user and last-seen time, current and previous agent version and ring, ADEM and Endpoint DLP status, anti-tamper state and the device's one-time passwords — with per-device troubleshooting actions. Device Inventory Search Filters and searches the agent inventory by time range, hostname, operating system and version, agent version and status, public and private IPv4 and IPv6 address, upgrade ring, user, DLP status, MDM compliance status and project. Endpoint Management Console Presents one page for the deployed fleet showing agent counts by connected, disconnected and offline status, the agent version rolled out, upgrade progress overall and per ring, and a device table with configurable columns, sorting and paging. Selective Upgrade & Downgrade Upgrades or rolls back the agent on up to 20 selected devices outside the staged rollout, downgrading only to the immediately preceding release, as a queued job whose status moves through requested, pending, completed or failed. Staged Upgrade Rollouts Staggers agent upgrades through up to five upgrade rings matched on username, user group or operating system plus a default ring for missed devices, each ring active for a fixed window, with start and stop control, per-ring progress, and automatic selection of the DLP or standard installer variant.
Agent Integrity & Enforcement Advanced DNS Security Resolver Intercepts DNS queries when the tunnel is disconnected and forwards them over DNS-over-HTTPS to Palo Alto resolvers that apply the tenant's DNS security profile and domain overrides, selected per application and domain through forwarding profiles and authorized by user or device tokens. Anti-Tamper Protection Stops users, including local administrators, from stopping, killing, uninstalling or spoofing the agent by protecting its files and folders, services and HIP processes, and its Windows registry keys or macOS plist, and by refusing disable and protection-off commands from the command line without a credential. Privileged Access Controls Governs who may perform protected operations using per-device, single-use one-time passwords scoped to privileged access, disabling or uninstalling, plus an administrator-set emergency token, a configurable window during which further operations need no reprompt, superuser-only visibility, and a disallow, allow or allow-with-OTP disable policy. Traffic Enforcement Blocks outbound access to the local network, inbound connections from the tunnel, and non-TCP and non-UDP protocols such as ICMP, GRE, IGMP and IPSec while the tunnel is connected, enforced in the kernel on Windows and macOS, with an option to keep ICMP available for diagnostics.
Agent Configuration Agent Settings Rules Defines agent configuration rules that match on endpoint operating system and user entities from cloud directory attributes, and assign that group its connect mode, disable policy, support page, session timeout, proxy, MTU, MFA prompt and advanced authentication and anti-tamper settings. Configuration Push Pushes saved agent and infrastructure configuration to Prisma Access or NGFW as a named, scoped job whose progress is tracked in a jobs dialog, after which the settings reach endpoints, and flags a stale configuration when saved changes have not yet been pushed. Global Agent Settings Applies tenant-wide settings across every agent — authentication override cookie behavior, re-authentication timers and notification text, diagnostic data retention, and whether quarantined devices may log in.
Licensing & Activation NGFW Deployment Licensing Licenses Prisma Agent on firewalls through platform-specific and high-availability-pair SKUs, an enterprise license agreement, or software NGFW credits, with renewal SKUs and a 90-day evaluation; installing it replaces the GlobalProtect Gateway license and entitles both agents. Prisma Access Licensing Requires a Prisma Access license with the Mobile User subscription plus a Strata Logging Service license, and a ZTNA or Enterprise Edition license where users connect to other connected networks through a corporate access node. Prisma Agent Activation Turns the Prisma Agent feature on for a tenant, with self-service enablement in Panorama-managed deployments, deactivation, and a 60-day data retention window after deactivation.
AI runtime security — inspection and policy for AI applications, models and agent traffic.
AI Red Teaming Agentic Red Teaming Scans Uses an LLM attacker that infers the target's purpose, crafts attack goals and adapts prompts conversationally, either fully automated or augmented with a supplied base model, use case, goals or system prompt. AI Red Teaming Dashboard Summarizes red teaming activity in Strata Cloud Manager with counts of targets added, targets scanned and total scans, and a breakdown of scanned apps, agents and models by high, medium and low risk profile. Attack Library Scans Runs a curated library of attack prompts across security, safety and compliance categories with per-attack severities, refreshed on a two-week cadence, and repeats each prompt to account for non-deterministic model behavior. Compliance Framework Mapping Maps attack outcomes to the OWASP Top 10 for LLMs, MITRE ATLAS, NIST AI RMF and DASF v2.0 and presents filtered views by framework. Custom Prompt Set Scans Uploads and maintains user-supplied prompt sets, validates each prompt's attack goal automatically or manually, and runs the validated prompts against a target alongside the built-in attack library. Custom Target Adapters Runs user-written Python adapters in a sidecar to reach targets with non-standard transports, exposing pre-process/post-process and call-target patterns, authentication and session hooks, error signals, and an in-product editor that validates the adapter end to end before activation. File-Based Attack Modality Delivers attacks embedded in PDF and Markdown documents alongside a carrier prompt to targets that accept file uploads, testing whether instructions in a document's text layer alter the system's behavior. Live scan progress Shows real-time error rate, estimated completion and a per-phase progress tracker while a red teaming scan is running, varying the tracker by attack library, agent or custom prompt set scan type. Memory poisoning attacks Tests whether an AI agent will accept, store and later act on false information injected through normal conversation, scoring results on a dedicated three-level vulnerability scale. Multi-Turn Attacks Runs attacks that span several conversational turns against targets with multi-turn enabled, carrying conversation history for stateless targets and server-side session state for stateful ones. Multilingual Scans Runs attacks in a selected target language across French, German, Hindi, Japanese, Portuguese, Spanish and Thai in addition to English, and renders prompts and responses in that language's native script throughout reports while keeping the executive AI summary in English. Network Channels Routes scan traffic to targets on private networks through a customer-deployed Helm-installed network channel client, with client version and upgrade management. Partial Scans and Error Logs Tracks simulation and response collection separately to classify a scan as failed, in progress, partially complete or complete, exposes error logs during and after the run, and generates a report marked with its response percentage from a partial scan. Red Teaming Reports Produces a per-scan report with an AI summary, risk score, attack success rate, severity and category breakdowns, full attack conversations and remediation recommendations, downloadable as CSV or executive PDF, and lets a reviewer read the judge's reasoning for each verdict, override the success status and re-evaluate the derived scores. Red Teaming Targets Registers models, applications and agents as scan targets over connection methods including OpenAI, Hugging Face, Databricks, AWS Bedrock, REST, streaming, WebSocket, Microsoft Copilot Studio and n8n, with rate limits, guardrail error codes and request JSON structure validated before use. Target Authentication Authenticates to target APIs using static headers, payload credentials or the OAuth 2.0 client-credentials flow, storing secrets separately and refreshing tokens proactively and on authentication failure. Target Background and Agentic Profiling Captures a target's industry, use case, competitors and policy documents, and optionally probes the endpoint with an autonomous agent to build a profile that later agent scans use.
Firewall Deployment & Lifecycle Auto-Execute Deployment Provisions security VPCs or VNets, firewall instances, load balancers and traffic-redirection routes directly from Strata Cloud Manager in AWS and Azure without the operator running Terraform. Cloud NGFW Deployment Launch Starts a Palo Alto Networks-managed Cloud NGFW deployment for AWS or Azure from the Strata Cloud Manager firewall deployment wizard. Deployment Template Management Lists generated deployment templates with their status, cloud, region, managing platform and associated firewalls, and downloads, deletes or decommissions them along with the cloud resources and licenses they created. Deployment Without Discovery Generates a firewall deployment template from a supplied cloud image identifier without first onboarding the cloud account for discovery. Device Certificate and Auto-Registration Generates a registration PIN in the support portal that a launching firewall uses to obtain its device certificate, register itself and retrieve site licenses. Firewall Image Upgrade Downloads and installs a new AI Runtime firewall image through the PAN-OS web interface, the PAN-OS CLI or Panorama device deployment. Managed AIRS for AWS Runs Prisma AIRS as a Palo Alto-managed firewall service inside AWS using a dual-data-plane architecture, deployed and policed from Strata Cloud Manager, securing VPC and Amazon EKS traffic and billed against Software NGFW credits. Manual Bootstrap Bootstraps a manually launched firewall from an init-cfg file, cloud user data or AWS Secrets Manager, setting management addressing, management server, device group, template stack and auto-registration credentials. Post-Deployment Network Configuration Configures the deployed firewall's Layer 3 and loopback interfaces, zones, logical routers and static routes, and NAT policies so VM and Kubernetes workload traffic is routed through it and health probes succeed. Private Cloud Deployment Runs the AI Runtime firewall on ESXi, KVM, OpenShift and Rancher from OVA or qcow2 images, standalone or in an active/passive pair, managed by Strata Cloud Manager or Panorama. Strata Cloud Manager and Panorama Management Manages deployed firewalls from either Strata Cloud Manager folders or a standalone or high-availability Panorama with device groups and template stacks, including the plugin prerequisites and serial-number provisioning each path requires. Terraform Deployment Workflow Walks through firewall placement, applications, instance sizing, addressing, licensing and management in Strata Cloud Manager and emits a downloadable Terraform template that builds the security VPC or VNet, load balancers and routing in AWS, Azure or GCP. Universal Firewall Image Ships a single PAN-OS image that runs as either a VM-Series or a Prisma AIRS firewall depending on the applied license, on x86 and ARM, removing separate images per firewall type. VM-Series Deployment Deploys VM-Series firewalls for non-AI and non-cluster traffic through the same Strata Cloud Manager Terraform workflow used for AI Runtime firewalls. VM-Series to AI Runtime Firewall Migration Converts an existing deployment profile between VM-Series and Prisma AIRS firewall types in the support portal and refreshes licenses on standalone, Panorama-managed and Strata Cloud Manager-managed firewalls, including high-availability pairs, without redeploying.
AI Threat Detection AI Agent Threat Detection Detects function schema extraction, direct tool invocation and memory manipulation against agents built on low-code platforms, using model-based detection plus framework-specific patterns when an agent framework is declared. AI Gateway Guardrails Applies basic and third-party guardrails, including language checking and gibberish detection, to traffic routed through the AI Gateway. Contextual Grounding Detection Evaluates a model response against supplied context and returns a grounded or ungrounded verdict when the response asserts facts absent from or contradicting that context. Custom Topic Guardrails Detects whether a prompt or response falls inside administrator-defined allowed or blocked topics, each described by a name, description and examples. Database Query Security Detects database queries generated by AI models and applies separate actions to create, read, update and delete operations. Malicious Code Detection Analyzes code snippets generated by LLMs in JavaScript, Python, VBScript, PowerShell, Batch, Shell and Perl and returns a verdict with SHA-256, file type and malware analysis detail. Malicious URL Detection Extracts URLs from model input and output, categorizes them against predefined and custom URL categories, and applies a default action with per-category exceptions. MCP Tool Threat Detection Scans Model Context Protocol tool definitions, inputs and outputs through the sync and async scan APIs to detect context poisoning and credential leakage, returning per-tool detection entries and a verdict. Multilingual Detection Coverage Runs prompt injection, toxic content and contextual grounding detection across English, Spanish, Russian, German, French, Japanese, Portuguese, Italian and Simplified Chinese, with Hindi and Traditional Chinese in preview. Prompt Injection Detection Inspects prompts sent to LLMs for injection attempts and returns an alert or block verdict, applied through either the inline network intercept or the scan API. Sensitive Data Detection Scans prompts and responses for sensitive data using predefined patterns or an Enterprise DLP profile, and can replace matched values with masking characters in the API response. Source Code Detection Flags source code present in prompts, responses and tool payloads, adding a code_found indicator to scan reports and a Source Code Detected incident subtype to logs. Toxic Content Detection Classifies prompts and model responses as toxic across sub-categories including violent crimes, self-harm, weapons, hate, sexual content, regulated substances and cybercrime, with per-category actions and moderate or high confidence thresholds.
AI Model Security AI skill package scanning Scans uploaded AI skill packages with static analysis and returns an Allowed or Blocked verdict against configurable rules, with per-version trust to exempt accepted findings. Custom Model Security Rules Defines tenant-level rules that combine scan labels and managed-rule outcomes with AND/OR conditions, emit custom violation and remediation text, and are assigned to security groups as blocking, allowing or disabled, with archive and unarchive. Model Format Coverage Introspects and scans models stored in more than fifty serialization and archive formats including PyTorch, TensorFlow, Keras, ONNX, GGUF, safetensors, pickle, joblib, NeMo and compressed archives. Model Metadata Governance Rules Validates model metadata against approved file formats, approved storage locations, license existence and license allow lists, Hugging Face organization verification, and blocked model or organization lists. Model Registry and Version Tracking Catalogs scanned models under a display name and computes a content-based fingerprint so identical artifacts resolve to the same model version across storage locations while modified artifacts register as new versions. Model Scan Labels Attaches up to fifty key-value labels to a model scan at creation or afterwards, and filters scan lists with a label query supporting AND, OR and single-level grouping. Model Scan Results Returns an allow or block evaluation outcome per scan with per-rule findings, the offending files, JSON output and remediation guidance, retrievable by scan ID from the CLI, SDK or Strata Cloud Manager. Model Scan Sources Scans models from Hugging Face, local disk and object storage in Amazon S3, Google Cloud Storage, Azure Blob Storage, JFrog Artifactory and GitLab Model Registry, with include and exclude file patterns and configurable download and polling behavior. Model Security Groups Binds a set of enabled rules to a single model source type and applies them at scan time, with a pre-created default group per source and per-rule blocking, non-blocking or disabled states. Model Security SDK and CLI Ships a Python package providing a command-line interface and SDK client that authenticate with service-account credentials and drive scans, security groups, rules, labels and result retrieval. Model Threat Intelligence Sources model vulnerability detections from the Huntr researcher community and continuous scanning of public Hugging Face models, and publishes findings in an Insights database where users can dispute or report threats. Model Threat Rules Evaluates model artifacts for load-time and runtime arbitrary code execution, architectural backdoors, unknown framework operators and suspicious components, returning per-violation threat identifiers and remediation steps.
Security Policy & Access Control AI Security Profile Groups AI model, application and data protections into a named profile that is attached to a security policy rule and pushed to network-intercept firewalls from Strata Cloud Manager or Panorama. API Security Profile Defines which detections the scan API runs and whether each allows or blocks, versions each revision with its own identifier, and can be linked automatically to an application so calls resolve a default profile. Custom Error Response Returns an HTTP error to the client when a policy blocks AI traffic instead of dropping the packet and sending a TCP reset. Custom Model Inspection Scope Forwards all traffic matching a security profile to the AI security cloud service rather than only traffic to recognized model endpoints, so proprietary and self-hosted model endpoints are inspected. Custom Topic Management Creates and edits the named topics, descriptions and examples that topic guardrail detection evaluates against, up to twenty topics per profile. Customer-Managed Encryption Keys Gives direct control over the keys encrypting stored AI security scan data, supporting key rotation to a new primary version and per-version disable and enable that revokes or restores read access to data encrypted under that version. Inline Latency Controls Caps how long inline or API threat detection may take and applies an allow, alert or block action when that threshold is exceeded, with asynchronous reporting of late verdicts. Model Groups Scopes protection settings to a named set of target AI models, sets an allow or block access-control action for the group, and configures separate request and response protections, with a default group covering unassigned models. Roles and Service Accounts Assigns superuser or custom roles scoped to individual Prisma AIRS applications and issues service accounts with client credentials for API and SDK access. Security Policy Rules and Profile Groups Attaches AI security profiles to profile groups and security policy rules and pushes the resulting configuration to managed firewalls from Strata Cloud Manager or Panorama. Traffic Objects for Zone-Based Policy Maps a Kubernetes cluster ID or VPC endpoint ID to a sub-interface and zone so security policy rules can be scoped to traffic from specific clusters or endpoints.
Logging & Monitoring AI Gateway Logging Separates gateway telemetry into structured event logs exportable to OpenTelemetry-compatible endpoints and Strata Logging Service, and full prompt logs retained natively for a year and exportable to a customer-owned S3 bucket in hybrid deployments. AI Sessions and Applications Views Groups scan API calls sharing a transaction identifier into sessions and rolls sessions up per application, showing violation counts and trends, linked security profiles, and the prompts and responses of individual transactions. API Scan Logs Summarizes scan API activity with counts of records, calls and threats and per-scan detail including scan and report identifiers, profile, model, verdict and action, filterable by time with configurable columns. API Violations View Lists blocked scan requests with a Sankey distribution by content type, detector and severity, and opens a transaction flyout showing violation metadata and the specific snippets each detector flagged. Cloud Tracer Traces the hop-by-hop path between two endpoints within or across AWS and Azure, evaluating firewall policy, security groups, NACLs and NSGs at each hop and marking where and why traffic would be dropped. Log Forwarding to SIEM Forwards Prisma AIRS API and firewall logs from Strata Logging Service to an external SIEM through a log forwarding profile, enriching API scan logs with a session URL that deep-links to the conversation in Strata Cloud Manager. OCI Kafka Log Streaming Streams traffic, threat and URL logs from firewalls in Oracle Cloud Infrastructure into an OCI managed Kafka cluster over mutual TLS using local syslog ports and custom JSON log formats. OCI Metric Forwarding Pushes firewall data-flow, system, customer and App-ID metrics directly to an OCI Kafka topic over mutual TLS instead of polling, with CLI commands to verify configuration, connectivity and pipeline statistics. Security Lifecycle Review Deploys firewalls in packet-mirroring mode in AWS and Azure, centrally behind a gateway load balancer or per application VPC, and produces downloadable PDF risk assessment reports of workloads, traffic flows and detected threats with scheduling and email sharing. Threat and AI Security Logs Records inline detections as threat logs with an ai-security subtype or, with Strata Logging Service, as AI security logs carrying incident type and subtype, model name, profile and a report containing the payload snippets that triggered each detector.
Discovery & Inventory AI Agent Discovery Inventories enterprise AI agents built on AWS Bedrock and Azure AI Foundry or OpenAI, capturing their foundation models, knowledge bases, tools and collaborators, parsing invocation logs into agent-to-model, tool, knowledge-base and agent interactions, and marking each agent protected once it is covered by the API intercept. AI Posture Management Connects a Cortex Cloud AI-SPM tenant to surface posture issues, severities, compliance-framework mappings, dataset data classification and per-asset security coverage alongside the AI asset inventory and its dependency graph. Cloud Account Onboarding Connects AWS, Azure and GCP accounts to Strata Cloud Manager through a generated Terraform template that creates a scoped service principal or role, with selectable discovery, orchestration, traffic-redirection and IP-tag permissions, configurable application boundaries, and tenant-level multi-subscription onboarding for Azure. Cloud Asset Discovery Enumerates VM workloads, Kubernetes clusters and pods, serverless functions, AI and non-AI applications, AI models and datasets, and their network traffic from cloud flow and audit logs. Cloud Asset Map Renders discovered regions, VPCs, subnets and applications as an infrastructure and topology view and marks each VPC protected, partially protected or unprotected based on which traffic flows are inspected. Discovery Data Management Deletes the collected asset, flow and audit data for a cloud account while keeping manually deployed firewalls inspecting, and enables or disables monitoring of onboarded accounts. Network Risk Analysis Views Breaks discovered traffic into model, internet and user views with per-asset threat summaries and protecting-firewall detail, and offers an add-protection action from the same view. Private Cluster Discovery Discovers Kubernetes clusters whose endpoints are not publicly reachable by collecting their metadata through an in-network tag collector, including across separate cloud accounts. SaaS Agent Security Onboards SaaS AI agent platforms such as Microsoft Copilot Studio and ServiceNow, reports each agent's configuration and posture, and offers remediation actions to pause, deactivate or terminate risky agents.
API Intercept & Developer Surface API Rate Limiting Enforces per-tenant requests-per-second and tokens-per-minute ceilings derived from the subscribed monthly token quota, returns HTTP 429 when exceeded, and supports operator overrides. Applications and API Keys Onboards AI applications with their cloud provider, environment and agent framework, generates and rotates the API keys bound to them, and issues an embeddable code template. OAuth 2.0 Token Authentication Issues OAuth 2.0 tokens with lifetimes from one hour to thirty days as an alternative to API keys for scan submissions, bounded by the underlying key's expiry. Prisma AIRS MCP Server Hosts a Model Context Protocol server that exposes inline and batch scan tools over streamable HTTP or SSE so AI agents can invoke Prisma AIRS detections without code changes, authenticated by API key or OAuth token. Python SDK Publishes a PyPI package that wraps the scan API with synchronous and asynchronous scanning, authentication, retry strategies, typed models and error handling. Regional API Endpoints Serves the scan and MCP endpoints from region-specific hosts in the Americas, Germany, India, Singapore and Japan, with API keys usable only in the region they were created in. Scan API Accepts prompts, model responses and tool events over synchronous and asynchronous REST endpoints and returns a verdict, per-detection flags, scan and report identifiers, and the action to take. Transaction and Session Identifiers Accepts a caller-supplied transaction identifier alongside legacy session and tr_id fields, or generates one, and echoes it through scan responses, results, reports and downstream messages so calls can be correlated into conversations.
Traffic Interception Cloud Mesh Builds an Auto VPN cluster of tunnels between firewalls in different clouds or regions at deployment time and advertises selected routes so cross-cloud traffic is inspected in transit. Container Traffic Inspection via CNI Chaining Installs a secondary CNI plugin by Helm chart alongside the cluster's primary CNI and tunnels annotated pod traffic out to the firewall for inspection on EKS, AKS, GKE, OpenShift, Rancher and self-managed Kubernetes. Inline Network Traffic Inspection Inspects inbound, outbound, east-west and application-to-model traffic in line on a deployed AI Runtime firewall and enforces the attached AI security profile. IP-Tag Harvesting Collects IP-address-to-tag mappings from cloud workloads and Kubernetes clusters and populates dynamic address groups that security policy rules reference. Microperimeter Workload Agent Installs the pan-redirector agent on a Linux workload to encapsulate ingress and egress packets in a GENEVE tunnel to a Prisma AIRS firewall for L7 inspection, with 5-tuple steering exceptions, health checks, telemetry and diagnostic bundles. Namespace Traffic Steering Restricts cluster inspection to named CIDR ranges or bypasses them, per namespace, using per-namespace Helm charts and pod annotations. SSL/TLS Decryption Decrypts traffic between AI applications and AI models with an SSL forward proxy decryption policy so AI security detections can inspect the payload. Tag Collector for Private Clusters Deploys a tag collector agent inside an AWS or Azure network to reach private Kubernetes cluster endpoints and forward their IP and tag metadata, including across account boundaries.
Licensing & Tenant Administration AI Gateway Budget and Rate Limits Caps spend and call velocity per workspace with cost- or token-based budgets on weekly or monthly reset cadences and request- or token-based rate limits per minute, hour or day, and applies discount or markup multipliers so reported cost reflects negotiated provider rates. Deployment Profiles Creates per-product profiles in the Customer Support Portal that declare planned capacity, issues the auth code, and associates the profile with a tenant service group to activate the bundled Strata Cloud Manager, Strata Logging Service and Enterprise DLP instances. HSF Offline Licensing Licenses air-gapped cluster nodes by uploading Customer Support Portal air-gap license files to the Panorama Software Firewall License plugin, which distributes licenses to P-Nodes and S-Nodes from separate profiles at bootstrap and releases them on delicense. Regional Tenant Placement Selects the region in which a tenant's data is processed and stored at deployment-profile activation and publishes which detection features are available in each region. Software NGFW Credit Licensing Funds every Prisma AIRS component from a Software NGFW credit pool under a bring-your-own-license model, with credit admin roles, credit transfer between pools, and credit reclamation when instances are delicensed or scaled in. Token-Based API Licensing Meters scan API and AI Gateway usage in monthly billions of tokens at four characters per token, resetting the quota each calendar month and reporting consumption in Strata Cloud Manager.
Scale & Availability Firewall Autoscaling Scales firewall instances between a minimum and maximum on cloud metrics such as dataplane CPU, packet buffer, session and throughput utilization, reclaiming licenses on scale-in, configurable at deployment or through the Strata Cloud Manager API for existing deployments. High Availability Pairs Runs firewalls as active/passive pairs in private and public clouds and keeps them paired through license migration and management platform changes. HSF Cluster Monitoring Shows cluster state, node status, config sync, interconnect health and throughput, session, CPU and memory utilization for firewall clusters in Panorama, and exposes node state and leader information through CLI commands. HSF Cluster Orchestration Deploys, updates, recovers and undeploys HSF clusters from the Panorama Software Firewall Orchestration plugin on ESXi, and from Strata Cloud Manager-generated Terraform on KVM, including node sizing, interface mapping and bootstrap parameters. HSF Rolling Upgrade Upgrades cluster nodes one at a time starting with P-Nodes, waiting for each to return online, and reverts already-upgraded nodes when rollback is enabled and an upgrade fails. Hyperscale Security Fabric Clusters Runs up to ten firewall instances as one cluster of fixed P-Nodes and elastic S-Nodes with a built-in load balancer, session failover and a single ECMP-exposed IP, scaling past 200 Gbps and auto-scaling S-Nodes on session utilization.
Platform Integrations AI Gateway Fronts LLM, MCP and agent-to-agent traffic with a centrally managed gateway offering per-provider integrations, custom hosts and headers, model allowlists and workspace-scoped provisioning, run either as a Palo Alto Networks-hosted service or as a self-hosted Helm-deployed data plane. AI Model Provider Coverage Recognizes and inspects traffic to named models on Google Vertex AI, Amazon Bedrock, Azure OpenAI and OpenAI, including fine-tuned and provisioned-throughput endpoints treated as other models. Anthropic Inference Hooks Integration Receives signed prompt frames from Anthropic inference hooks before the model reads a message and returns an allow or deny verdict that Anthropic enforces, with a webhook secret, signature tolerance window and configurable verdict timeout. Microsoft Foundry Integration Registers Prisma AIRS as a guardrail integration in Microsoft Foundry so prompts and model responses in Foundry projects are scanned natively using a key-vault-stored API key and a managed identity. OpenAI Codex Integration Routes every developer prompt in an OpenAI Codex Enterprise organization through the scan API at the admin API layer, blocking prompts before they reach the model or a connected MCP server without per-developer configuration.
Software-defined WAN built on the ION appliance family.
Sites & Connectivity Branch and Data Center Sites Models the WAN as branch sites and data center sites, each holding one or more ION devices, with the data center acting as the transit hub for branch connectivity to applications, the internet and third-party services. Branch DNS Service Runs a caching, forwarding, and authoritative DNS service on branch ION interfaces through DNS service roles and profiles controlling per-domain and per-prefix server selection, domain-to-address mapping, cache sizing and TTLs, DNSSEC proxy or validation, and response rewriting, so branch name resolution survives loss of the data center. Branch Gateway Full Mesh Topology Deploys ION devices as Branch Gateways in a full-mesh topology with standard branches and data centers, routing branch-to-branch traffic through interconnected Branch Gateways instead of the data center and falling back to the data center when no direct path exists. Branch Gateway Sites Configures a hybrid site type that combines data center hub services such as policy transit and link quality measurement with branch visibility and path selection, and auto-forms VPN tunnels to branch sites in its domain. Bypass Pairs Pairs a LAN-facing and a WAN-facing port as a hardware, virtual or software cellular bypass pair with fail-to-wire relay behavior, and optionally propagates a LAN port's link state to its paired WAN port. Cellular Connectivity Runs 4G and 5G cellular interfaces as primary or backup WAN links with dual SIMs and automatic switchover, carrier auto-detection, custom and automatic APN profiles, SIM PIN protection and carrier-specific modem firmware selection. Circuits and Circuit Categories Defines internet and private WAN circuits with bandwidth, cost, QoS, BFD, and probe settings and groups them into reusable circuit categories that also control which circuits carry controller connections and reachability probes. Controller Connectivity Ports Dedicates one or two controller ports, or any Layer 3 interface marked used-for-controller on newer platforms, as the source interface for the device's connection to the controller. Data Center Clusters Groups data center devices into clusters that determine which branch sites peer with which data center, with default cluster selection, device assignment, and a soft branch-count limit. DHCP Relay Forwards DHCP requests received on a LAN, controller port or sub-interface to configured DHCP servers and relays the responses back to the client. DHCP Server Runs an IPv4 or IPv6 DHCP server on the branch ION device with per-subnet scopes, lease times, remote unicast relay-agent support, and custom vendor-class and PXE boot options. Integrated Layer 2 Switching Provides integrated LAN switch ports on supported ION models with VLANs and switch virtual interfaces, access and trunk modes, spanning tree, storm control, MAC table and switch statistics, and Layer 2 to Layer 3 mode change. IP Directed Broadcast Broadcasts traffic arriving over a fabric VPN onto a LAN subnet through the subnet's broadcast address on a Layer 3 LAN interface. IPSec Termination Node Selection Enumerates the IPSec termination nodes behind a Prisma Access compute region, reports their bandwidth utilization, and pins a site's tunnels to a specific node by name or ordinal. LLDP Neighbor Discovery Exchanges LLDP and LLDP-MED TLVs per port to discover attached endpoints and their capabilities, and reports neighbor entries and LLDP frame activity. Loopback Interfaces Creates Layer 2 loopback interfaces that emulate a WAN port so a physical LAN port can form a bypass pair, and Layer 3 loopback interfaces that stay up independently of physical port state for management and overlay services. Port Channels (LAG/LACP) Aggregates multiple Layer 3 LAN or WAN ports into a single logical port channel with optional LACP negotiation for added bandwidth, redundancy and load balancing. Power over Ethernet Ports Delivers 802.3bt power to attached devices on PoE-capable ports with per-port and system-level power usage thresholds that raise an incident when exceeded, and reports power consumption. PPPoE Interfaces Attaches PPPoE to a physical WAN port so a DSL circuit authenticates to the provider and presents a logical underlay interface for path selection, statistics and policy. Secure Fabric Overlay Establishes and maintains the automatic encrypted VPN mesh between branch and data center ION devices over every transport, rotating per-VPN session keys hourly for up to 72 hours without the controller and declaring paths down through configurable keep-alives at fabric link, circuit and circuit category level. Site Deployment Modes Runs a branch in analytics mode for traffic visibility only, control mode for path selection and policy enforcement, or disabled mode for pass-through, and switches an existing site into control mode. Standard VPN Tunnels Builds IPsec or GRE tunnels from an ION interface to non-fabric endpoints using reusable IPsec profiles, including responder-only data center to data center interconnects, and monitors them for reachability and path selection like any other path. Sub-Interfaces Divides a physical port, virtual interface or bypass pair into multiple VLAN-tagged sub-interfaces that carry user traffic and branch services such as DHCP, SNMP and device access. Underlay Link Quality Aggregation Derives an internet or private WAN underlay link quality value from selected data centers using a minimum, maximum, or average aggregation method for use in charts and dynamic path selection. Virtual Interfaces Combines two physical ports of the same type into one logical interface so connectivity survives the failure of a single port or cable, commonly used for controller port redundancy. WAN and LAN Interface Configuration Configures internet, private WAN and Layer 3 LAN interfaces with circuit labels, static or DHCP IPv4 and IPv6 addressing, local or global prefix scope, external NAT address and port, MTU, security zone binding, secondary IP addresses and static ARP entries.
Monitoring & Analytics Application Insights Scores application health per path from application round trip time and packet loss and lists underperforming applications with impacted sites, traffic volume, new flow rates and TCP connection statistics, drilling into per-path detail. Autonomous DEM for Remote Networks Registers an SD-WAN site with the Autonomous DEM service so the ION device runs synthetic application tests across Prisma Access, secure fabric, and direct internet paths without an added appliance or agent. Cellular Analytics Charts cellular module telemetry per site, device, carrier, APN and circuit including signal strength and quality, radio technology in use, traffic volume, packet drops and errors, GPS location and cell tower switches, plus module and packet counters. Chatbot Network Queries Answers natural-language and structured chat commands about site health, device inventory, paths, interfaces, applications, and events, and pushes alarm notifications to a chat channel. Command Center Integration Feeds Prisma SD-WAN traffic and security events into the Strata Cloud Manager Command Center, which classifies sources, platforms and application types across SASE and standalone deployments from centrally logged data. Controller Diagnostics and Tech Support Dump Generates a downloadable tech support bundle of controller service configuration, logs, thread dumps, and audit logs, and documents installation and upgrade error scenarios with their remedies. Device Activity Monitoring Reports CPU, memory, disk and per-interface bandwidth, error and drop metrics for branch and data center ION devices, alongside a device inventory showing connectivity, model, software version distribution and end-of-life or end-of-support badges. Flow Browser and Flow Details Lists recent network flows per site and exposes end-to-end session detail for each flow, including the path, QoS, NAT, performance, and security policies applied, the path decision data, and the decision bitmap explaining path selection. Guided Incident Troubleshooting Presents ordered remediation steps for a raised incident code from the incident itself and hands off to support ticket creation or device return when the steps do not resolve it. Incident Management and Correlation Acknowledges and synchronizes incidents between controller and device, classifies them as critical, warning or informational, and correlates, aggregates, suppresses, dampens, re-prioritizes or escalates them through ordered incident policy rules matching on incident codes and resources, grouped into site-level policy sets of which one is active at a time. IPFIX Collector Contexts, Filter Contexts, and Prefixes Defines collector contexts, filter contexts, and global or local IP prefixes and binds them to device interfaces and sites to set the IPFIX export source interface and scope which flow records are exported. IPFIX Flow Export Exports per-flow and options records from ION devices to third-party IPFIX collectors using global profiles, selectable export templates and their information elements, collector definitions, filters, and sampling, applied globally or overridden per device. Link Quality Monitoring Measures MOS, packet loss, jitter and latency by actively probing secure fabric and private WAN underlay paths, presents them per site, circuit and path with distribution and time-series views, and feeds them into path selection for real-time applications. Multi-Tenant Monitoring Presents an MSP-level view across all managed tenants of open incidents by priority and code, device-to-controller connectivity, and branch and link health scores, with drill-through into an individual tenant. Network Dashboard Summarizes the fabric on one screen with device-to-controller connectivity, application utilization, bandwidth utilization, weekly network insights, top sites by alarms and aggregate link quality, refreshed every five minutes. Predictive Analytics Classifies sites, applications and links as good, fair or poor from AI/ML health scores and forecasts future branch bandwidth capacity from the previous three to six months of utilization. SASE Health Dashboard Presents one Strata Cloud Manager view of a combined Prisma SD-WAN and Prisma Access deployment, with a map of sites and Prisma Access locations, per-site connectivity and experience scores, application availability and trend charts. Site Map and Topology View Places branch and data center sites on a map colored by alarm state or computed connectivity, filters them by domain, tag, type, mode and status with persisted settings, and opens a per-site graph of secure fabric and standard VPN overlay connections that new links can be added from. Site Summary Dashboard Shows a branch site's health score, consumed versus configured bandwidth, per-circuit connectivity and health, secure fabric link metrics, and machine-generated insights such as excessive loss, excessive latency or a recommended bandwidth upgrade. SNMP Agent and Traps Enables a read-only SNMP v2c and v3 agent and up to sixteen trap destinations per version on an ION device, with community strings, v3 users, authentication and encryption settings, and VRF-aware source interfaces. Syslog Export Forwards device events, alarms, authentication logs, and RFC 5424 per-flow logs carrying firewall classification results to up to sixteen syslog servers over UDP, TCP, or TLS, configured through reusable syslog profiles or per device with severity filtering. WAN Clarity Reports Generates periodic branch, data center and aggregate bandwidth reports covering traffic distribution by path type, utilization quadrants and thresholds, heatmaps, hotspots, top-N breakdowns and per-circuit application volume for capacity and policy planning.
Traffic Policy App Acceleration Accelerates dynamic SaaS content and adapts transport behavior to device, network and application context to raise throughput under packet loss and congestion, and reports acceleration statistics. Circuit Capacity Bandwidth Allocation Allocates the share of circuit bandwidth given to each priority class and traffic type, with several allocation schemes selected by configurable link-capacity breakpoints. Coffee Shop Deployment Policies Uses auto-generated, auto-updating Prisma Access mobile user and explicit proxy prefix lists in a default path policy set so branch mobile-user and explicit-proxy traffic routes directly to the internet instead of through the remote network tunnel. Custom Applications and System Application Overrides Defines enterprise applications by Layer 3/4 port and prefix rules or Layer 7 domain matching and overrides attributes of built-in system applications such as category, path affinity, transfer type, idle timeout, and unreachability detection. Device-ID Based Policy Rules Matches security and path policy rules on the device identity of branch endpoints discovered as OT, IoT and other device types, alongside App-ID and User-ID match criteria. Global and Local Policy Prefixes Defines named IPv4 and IPv6 address groups, globally across all sites or locally per branch, for use as match criteria in path and QoS policy rules. Metered Link Usage Minimization Reduces traffic on metered cellular circuits by adjusting circuit and circuit-category settings for monitoring, keep-alives, cost, controller connections, and probes, and by referencing those circuits only as Layer 3 failure paths. NAT Policy Translates addresses through simple or advanced NAT stacks of ordered policy sets and rules bound to sites, matching on NAT zones, global and local prefixes, protocols and port ranges, and acting as source, destination, static source, static destination, no-NAT or ALG disable using NAT pools bound to device interfaces. NAT Protocol Translation Translates between IP address families without explicit configuration, supporting NAT64 with DNS64, XLAT464, NAT46 and NAT66 based on the address families of the LAN and WAN interfaces. Network Contexts Labels LAN interfaces with a network context so different policy rules apply to the same application on different network segments. Original Policy Sets and Migration to Stacked Policies Maintains the pre-stacking flat path, QoS, and security policy format for existing tenants and converts those original policy sets into stacked sets by cloning them, which is required before upgrading devices past the release that introduced stacking. Path and Application Probes Runs always-on ICMP, DNS, HTTP and HTTPS probe configurations grouped into probe profiles bound to circuits and circuit categories to measure latency, loss, jitter and transaction failure across transports, and probes application reachability dynamically when a TCP handshake or DNS response fails. Path Policy Rules Defines per-application forwarding rules that select active, backup, and Layer 3 failure paths by overlay and circuit category using SLA-compliant or best-path selection, matching on contexts, prefixes, applications, users, and devices, including an IPv6 default rule. Performance Policy Defines application and network SLAs as ordered rules in performance policy sets and stacks bound to sites, matching on applications, transfer types, path types, circuit categories and data center groups against link quality, application, system health and probe thresholds. QoS and Priority Policy Rules Assigns application traffic to platinum, gold, silver, and bronze priority classes with transfer-type sub-queues and sets DSCP marking and DSCP-to-priority mappings for queuing decisions. QoS CIR for Aggregate Bandwidth Applies QoS profiles and per-tunnel committed information rate guarantees to remote-network traffic sharing a Prisma Access compute location's aggregate bandwidth, set through a guaranteed-bandwidth ratio and per-interface or per-circuit QoS tags. SLA Remediation Actions Acts when a performance SLA is violated by moving new or existing flows to a compliant path in graceful or forced mode, applying forward error correction or packet duplication either always-on or adaptively, and raising an incident. Stacked Policy Stacks and Sets Organizes path, QoS, NAT, and performance policy rules into ordered policy sets and simple or advanced stacks bound to sites, with cloning, templates, and default rule sets. User-ID Based Policy Rules Matches path, QoS, and security policy rules on user or user-group identity by importing IP-to-user mappings from a PAN-OS User-ID agent or Cloud User ID and group mappings from the Cloud Identity Engine.
Device Lifecycle Controller Image and AppDef Management Uploads ION software bundles and application definition packages to the Operator console, records them as software inventory, and allocates them to tenants. Device Allocation Across Tenants Allocates ION devices from a parent tenant's inventory to client tenants and returns, re-allocates or revokes them, individually or in bulk by sales order. Device Onboarding Brings an ION device into the tenant by connecting it to the controller over the controller or internet port and claiming it, which downloads tenant certificates and moves the device from unclaimed to claimed and online. Device Shell Pre-Staging Creates a virtual placeholder element that holds a site's device configuration before the physical ION is available, then transfers that configuration to the device when one is assigned to the shell. ION Software Upgrade Schedules download and upgrade of ION device software immediately or in a chosen window, with maximum download and upgrade times, selected download interfaces, upgrade status tracking and bulk upgrades across devices. LAN Zero Touch Provisioning Onboards branch switches and access points automatically by pushing DHCP, VLAN, and wireless network settings to a site and provisioning devices as they connect. NTP Time Synchronization Configures up to ten NTP time sources per ION device through tenant-level NTP templates, falling back to an implicit controller time source. On-Premises Controller Deployment Installs a self-hosted Prisma SD-WAN controller on customer virtual machines through an installer web interface or CLI scripts, using sizing templates, hardware prerequisites, tenant creation, and administrator and operator console access. On-Premises Controller Upgrade Upgrades the on-premises controller from the Operator console using a staged image bundle and pre-upgrade script, and rolls back to one of the retained prior images. On-Premises Device Bootstrap and Allocation Registers ION devices to an on-premises controller through a zero-touch bootstrap service reached by static host entry, DNS, or DHCP option 43, then creates and allocates the device in the Operator console, including reprovisioning previously cloud-managed devices. RMA Device Replacement Replaces a failed ION device through a guided wizard that snapshots the old device's configuration, unassigns it from the site, assigns the replacement and copies the configuration across, and returns the failed unit to Palo Alto Networks. Site Configuration Templates Builds a parameterized site template from an existing site or an import, then deploys many branch and data center sites at once from a CSV data file with per-site deployment jobs. Site Snapshot Export and Import Exports a site's current configuration to a YAML snapshot and imports a YAML file to deploy or redeploy a site, tracking job status in both directions. Virtual ION Deployment Runs the ION device as a virtual machine on hypervisors and public clouds including VMware ESXi, KVM, AWS, Azure and Google Cloud, with SR-IOV passthrough on supported Intel network adapters and paired deployment across cloud availability zones.
Routing & Segmentation BGP Route Filtering Filters and rewrites advertised and received routes with ordered route maps that match on prefix lists, AS path regular expression lists and IP community lists and permit, deny, continue or redistribute. BGP Routing Peers branch and data center ION devices with LAN and WAN routers over BGP using classic, core and edge peer types, 4-byte AS numbers, MD5 authentication, timers, per-peer global or local scope and prefix advertisement modes, and reports peer state, prefixes and reset operations. Branch Microsegmentation Isolates hosts at the branch by enabling switch port isolation and wireless client isolation so wired and wireless hosts in a segment cannot reach each other. DC Symmetric Return with Branch Gateway Co-existence Maintains symmetric return routing when a branch and a Branch Gateway hold separate connections to different ION devices in a clustered data center, adjusting route advertisements by VPN path state and applying metric 30 to the transit path as backup. Hop Count-Based Path Selection Uses hop count as the primary routing metric on Branch Gateways so traffic takes the fewest-transit-site path, filtering candidate paths to the lowest hop count before applying standard path policy, and correcting routing asymmetry on WAN-to-WAN flows. Host Reachability Tracking Tracks reachability of a designated IP address beyond the data center core from a data center ION device and deactivates its tunnels so branches reroute to an alternate data center device when tracking fails. Intra-Cluster Tunnel Tunnels traffic between the two data center ION devices in a cluster so a device receiving traffic for a branch it does not serve forwards it to the peer that holds the active VPN instead of blackholing it. Multicast Routing Forwards PIM-SM multicast on branch LANs and from data centers to branches over the fabric, with IGMP membership, static and dynamically learned rendezvous points, WAN multicast profiles bound to sites, and LAN, WAN and flow statistics. OSPF Routing Runs OSPF on branch and data center LAN interfaces to learn and advertise routes with Layer 3 switches, redistributing between OSPF and BGP peers and reporting discovered neighbors. Route Distribution to Fabric Selects which branch sites receive the prefixes a data center learns dynamically over BGP or OSPF on its LAN. Security Group Tag Propagation Parses Cisco metadata headers to extract security group information and preserves the tags across the SD-WAN fabric, with static tag assignment at site and port level for device-originated traffic. Site and Enterprise Prefixes Declares IPv4 and IPv6 prefixes at the site level to advertise reachability into the fabric and at the tenant level to mark additional public ranges as enterprise traffic. Static Routing Configures IPv4 and IPv6 static routes per device with local or global scope and an optional next-hop reachability probe that withdraws the route when ICMP probes to the next hop fail. VRF Segmentation Isolates WAN traffic into virtual routing and forwarding segments defined in VRF profiles bound to sites and interfaces, carries the segment identifier across the fabric, and supports controlled route leaking, direct internet access per segment and multiplexing of custom VRFs onto global service links.
Administrator Access & Audit 802.1X and MAC Client Authentication Requires endpoints on ION switch ports to authenticate to a RADIUS server by 802.1X or MAC address before reaching the network, honoring returned attributes such as dynamic VLAN, re-authentication and idle timeouts, and reports server and client authentication statistics. Audit Logs Records administrator configuration changes and login attempts with owner, time and scope, queryable by resource, operation type, status, operator, source IP and date range with regular expressions, version-to-version comparison and CSV export. Custom Roles Builds roles by assembling system roles with explicitly allowed and disallowed permissions, scoped down to individual API resources and their get, post, put, delete and query actions. Device Offline Access One-Time Password Restores device toolkit access on an offline ION through a console challenge phrase and a controller-generated one-time password, with configurable attempt limits and expiry. Device Toolkit Access Creates tenant-level or device-level accounts with super, read-only or monitor roles that authorize direct login to ION devices, and assigns which devices each account may access. SAML Authentication for the Operator Console Authenticates non-local Operator console users against an external SAML identity provider using exchanged service-provider and identity-provider metadata and role attribute mappings. System Roles Provides predefined roles such as multitenant superuser, superuser, IAM administrator, network administrator, security administrator and view-only that can be mapped to groups in an enterprise identity provider for single sign-on. TACACS+ Device Authentication Authenticates, authorizes and accounts for device and SSH access against up to four TACACS+ servers in a profile associated with a device, falling back to local authentication when no server is reachable. Tenant Access Restrictions Restricts which source IP addresses may reach the tenant web interface and APIs, and sets password composition and expiry requirements for local users. User and Role Assignment Adds users and service accounts as identities and assigns them one or more system or custom roles per application, including identities created by a parent tenant to operate inside a child tenant.
Device CLI & APIs CLI Network Diagnostics Runs reachability and path tests from the ION device itself, including ping, ping6, traceroute, traceroute6, tcpping, arping, DNS lookups with dig and dig6, HTTP requests with curl, outbound SSH, controller reachability checks, and bandwidth and speed tests on a WAN interface. Device Log Access and Log Levels Dumps, tails and follows the ION device log files from the CLI and sets the logging verbosity of individual facilities, including the log agent, service link and multicast routing daemons. Device Process and Power Control Starts, stops, restarts and reports the status of individual software processes on an ION device and bounces an interface, reboots or shuts the device down from the CLI. Device Support Bundle and File Export Collects device configuration, runtime state, logs and core dumps into a support file on the ION device, then lists, removes and exports log, core and capture files to an external destination over SCP while reporting available storage space. ION Device Toolkit CLI Exposes a device-local command set over console, SSH or a remote browser session with clear, config, debug, dump and inspect command families and monitor, read-only and super access levels, letting an operator configure the box, display configuration and runtime state, and filter any command output with grep options. On-Demand Packet Capture Captures packets on a selected ION interface from the device CLI with source, destination, host, port and protocol filters, prints them to the console or saves them to a named pcap file, and reads that file back on the device. Remote CLI Sessions Opens a CLI session to an online claimed ION device from the web interface using console and device credentials, capped at 10 concurrent sessions per device and 30 per account, and lists active sessions by session, element or operator alongside a session history that an administrator can close sessions from. Runtime State Clearing Clears live device state and counters from the CLI, including flow and ARP tables, connections, routing adjacencies and OSPF and multicast statistics, DHCP leases and relay counters, switch MAC address entries, the dynamic application map, application probe prefixes, QoS queue snapshots and User-ID agent statistics. SD-WAN REST API Exposes tenant configuration and monitoring resources over public REST endpoints that automation can call and that custom roles scope permissions against.
Integrations & CloudBlades CloudBlade Lifecycle Management Configures, versions, installs, enables, pauses, disables, and uninstalls a CloudBlade, controlling whether the objects it provisioned are reconciled, retained, or deleted. CloudBlade Object Tagging Drives CloudBlade behavior from tags on sites, circuit categories, interfaces, devices, static routes, and LAN networks, selecting which objects are provisioned, targeting regions, controlling route advertisement and ECMP exclusion, and naming the objects created in the partner service. CloudBlade Status Monitor Reports each integration's deployment and connectivity state, site onboarding and tunnel summaries, region and node allocation, tag validity, processing statistics, activity logs, and coded error messages. PAN-OS NGFW as Data Center Enables a cloud-managed PAN-OS next-generation firewall to act as a Prisma SD-WAN data center device, with orchestrated logical routers, circuit and interface configuration, optional HA pairing, and CLI troubleshooting. Prisma Access Link Monitoring Monitors the health of tunnels to Prisma Access with link quality metrics and liveliness probes per endpoint, and optionally applies link quality monitoring to non-hub paths at circuit or circuit category level. Prisma Access Site Onboarding Onboards branch sites to Prisma Access natively without a CloudBlade by building IPsec tunnels from each site circuit to a primary and optional secondary Prisma Access location under either aggregate bandwidth or site-based licensing, for both cloud-managed and Panorama-managed deployments. SASE Connectivity Settings Sets the one-time parameters for connecting sites to Prisma Access, including the ION peering local AS number, deployment mode governing route propagation, tunnel inner IP pool, security zone binding and IPsec profile synchronization. Service and Data Center Groups Abstracts service endpoints such as Prisma Access regions and data center transit points into groups and domains bound to sites, so one policy rule resolves to different endpoints depending on where the site is.
Platform Security & Compliance Certificate Management Imports, generates, inspects and deletes custom certificates including forward trust, forward untrust and trusted root CA certificates used to secure device communication and decrypt traffic for application acceleration. China In-Country Deployment Runs a dedicated controller and tenant inside mainland China with a locally contained fabric and locally stored telemetry on hardware certified for in-country sale, for customers with data localization requirements. Controller Regions and Data Residency Hosts a tenant controller, its API endpoints and its statistics store in a chosen region across the Americas, EMEA and Asia-Pacific, including Indonesia, so control-plane and data-plane data stay within that jurisdiction. FedRAMP Moderate Deployment Runs new tenants in a FedRAMP Moderate environment on FedRAMP-specific SKUs and FIPS-validated hardened ION devices, with a documented list of the features supported and unsupported in that environment. FIPS and FIPS-CC Mode Runs ION devices in FIPS or FIPS-CC mode with an approved cipher and algorithm set, OCSP revocation checking, authenticated NTP, key zeroization, and a supported path for switching between FIPS and non-FIPS modes. Management Plane TLS Secures the device-to-controller management connection with TLS 1.3 by default, including hybrid post-quantum key exchange groups, negotiating automatically and falling back to TLS 1.2 where an intermediate component lacks support. Post-Quantum Cryptography for VPN Protects standard VPN tunnels against harvest-now-decrypt-later attacks with post-quantum pre-shared keys and additional ML-KEM key exchange rounds negotiated over IKEv2 alongside classical algorithms. VPN and Fabric Cipher Configuration Selects the AES-GCM and AES-CBC algorithms permitted for secure fabric tunnels per site, with the controller negotiating the strongest common cipher between site pairs, and selects the IKE and IPsec algorithms used for standard VPN tunnels.
Branch Security Policy Device Management Access Policy Controls which source prefixes may reach management services such as ping, SSH, SNMP, DHCP, traceroute, BGP, and HA sync on each ION device interface. Security Policy Rules Defines allow, deny, and reject rules matching on source and destination zones, prefixes, applications, protocols, and port ranges, evaluated in administrator-set order above the implicit self-zone, intra-zone, and catch-all deny rules, with editing, disabling, reordering, cloning, and change history. Security Policy Stacks and Sets Organizes branch firewall configuration into simple stacks holding one policy set or advanced stacks evaluating several sets plus a default set in order, with set creation, cloning, policy stance selection, and binding of one stack or set per site. Security Prefix Filters Creates global and site-bound local IP prefix groups reusable across security policy rules to restrict traffic to specific addresses or subnets within source and destination zones. Security Rule Monitoring Shows per-rule hit counts over a selectable time interval for one site or all bound sites, with rule detail summaries and audit logs, monitored per stack, per set, or per rule. Security Zones Creates zone-based firewall enforcement boundaries and binds them to site circuits and to device LAN, WAN, sub-, PPPoE, bypass-pair, and tunnel interfaces, with device-level bindings overriding site-level bindings and unbound interfaces dropping all traffic.
Licensing & Tenancy Child Tenant License Allocation Allocates all or part of an activated subscription to a child tenant in the hierarchy, leaving the remainder with the parent tenant. License Activation Activates a purchased Prisma SD-WAN subscription against a tenant through a one-time magic link or the Customer Support Portal, selecting the customer support account, recipient tenant and deployment region. Multi-Tenant Hierarchy Organizes deployments as a hierarchy of tenant service groups with parent MSP tenants and child client tenants, and lets a parent tenant enter a child tenant and grant user access within it. Subscription Models and Add-Ons Offers data center and branch subscriptions priced per device, per site, as aggregate bandwidth or by device sizing family, with add-on entitlements for WAN Clarity reporting, Clarity Network DVR, zone-based firewall, IoT Security, ADEM and Strata Logging Service. Subscription Usage Reporting Reports monthly bandwidth consumed per branch site and per tenant against the licensed amount, with top-site and top-application breakdowns, purchase history and CSV export.
Resiliency & Recovery Branch High Availability Pairs two branch ION devices in an HA group that elects an active and backup device by priority with optional preemption, VRRP advertisement intervals and interface tracking, over a dedicated HA control interface configured on a port, sub-interface or switch virtual interface, and supports a documented wiring topology for each platform generation. Controller High Availability and Configuration Backup Deploys the on-premises controller as a multi-node cluster behind a TCP load balancer and schedules periodic configuration backups with a retention window. Device Thermal Protection Samples CPU, board, cellular modem and PSE temperature sensors on an ION device every five minutes, raises an incident when a sensor exceeds its safe threshold, and shuts the device down when a high reading persists across consecutive samples. HA-Aware Upgrade Procedure Upgrades an HA pair without downtime by upgrading the backup device, promoting it through priority and preemption, verifying tunnels and traffic, then upgrading the former active device. ION Recovery and Debugging Procedures Guides recovery from specific ION failure modes with CLI diagnostics and escalation points, covering hardware watchdog reboots, HA split brain, out-of-memory reboot loops, lost controller connections, dropped BGP sessions, missing interfaces and failing VPN tunnels.
Threat Prevention & Device Identification IoT Device Discovery and Identification Discovers and identifies devices on branch networks through site-bound SNMP discovery profiles, SNMP start nodes, a selectable discovery source interface, and DHCP and ARP traffic logging forwarded for device identification. Security Profile Groups for Branch Security Bundles anti-spyware, vulnerability protection, DNS security, and URL access management profiles pushed from Strata Cloud Manager into a subscription-licensed group attachable to a branch security policy rule for inline threat and URL enforcement on the ION device. Site Protection Flow Limits Throttles active flows per source IP address against a configurable percentage of the device concurrent flow limit and raises an incident when the threshold is exceeded.
AI Assistance Copilot Answers natural-language questions about network health, device utilization and security from the tenant's own data combined with Palo Alto Networks documentation, suggests context-sensitive prompts, keeps conversation history and opens support cases. Troubleshooting AI Agent Diagnoses network issues autonomously by gathering incident and configuration context, building a troubleshooting plan, invoking backend analyzer tools and correlating the results into a root cause analysis with reasoning steps, leaving remediation to administrator approval.
CASB — discovery, posture and inline control for SaaS applications.
Incidents & Remediation Asset Owner Outreach Emails an asset owner directly from an incident using reusable templates whose subject and body substitute administrator name, cloud app name and file owner name. Automatic Remediation Actions Applies a configured action when a data asset policy matches — quarantine to the user or admin folder, change sharing, delete the asset, notify the file owner, apply a classification, notify via bot, send an administrator alert, or log the incident only. Custom Incident Categories Adds organization-specific incident categories under the open or closed state for filtering and audit trail, alongside the undeletable defaults. Incident Asset Download Downloads a password-protected compressed copy of an asset that has a current or past incident, including quarantined assets, for offline inspection. Incident Assignment Assigns a single incident or up to 1000 incidents at once to another administrator, with review notes attached to the asset for context. Incident Filtering Narrows the incident list by status, date found, cloud app, matched policy rule, assigned administrator, asset owner and last activity date. Incident States and Categories Creates an incident for each policy match and tracks it through open categories New, Assigned, In Progress and Pending and closed categories No Reason, Business Justified, Misidentified, In The Cloud and Aperture. Incident Status Changes and Closure Changes the status of one incident or up to 1000 at a time and closes incidents that are not threats under a chosen closed category. Manual Remediation Quarantines an asset or permanently deletes it from the asset or incident view when a policy did not act automatically. Quarantine Management Moves compromised assets into an admin or user quarantine folder, leaves a customizable tombstone file in the original location, and lets administrators filter, open, restore, delete or download quarantined assets subject to per-app support and role permissions. Remediation Activity Logs Records every automatic and manual remediation action with the actor, action, policy and asset, filterable by search, duration, action, actor and policy and exportable to CSV. Remediation Email Digest Sends asset owners and cloud app administrators a daily digest listing the files needing review, the recommended action for each, and the actions already taken automatically, with configurable sender name, reply-to address, logo and body copy. Security Control Incident Detail Shows the severity, date, application, user, setting name and violated rule behind a security control violation, with actions to email the responsible party or dismiss the incident. Sharing Remediation Removes public and direct sharing links and external collaborators from an asset, and optionally from the parent folders that expose it through inheritance, automatically by policy or manually from the asset detail view. Slack Notification Alerts Sends administrator and end-user notifications through a Slack bot to a validated private channel or to the affected user when an asset is deleted or quarantined, with a default message set per policy and an override composed at the moment of action.
Posture Management Compliance Posture Dashboard Summarizes passed and failed posture rules against CIS Critical Security Controls v8, the EU AI Act, HIPAA, ISO 27001, NIS 2, NIST 800-53, the NIST AI Risk Management Framework, the NIST Cybersecurity Framework, PCI DSS and SOC 2, drills from a standard into per-app compliance reports and the non-compliant settings behind them, and emails a CSV export link. Identity Security Posture Scans supported SaaS apps for human and non-human accounts and applies detectors for dormant, expiring- and unrotated-credential, guest, overprivileged, local and weak-or-absent-MFA accounts with day thresholds, resolves a user's accounts into a unique identity through Okta or Microsoft Azure, renders an access graph of the apps each identity reaches, and files tickets on the threats found. Meeting Bot Security Detects meeting bots present in Zoom and Microsoft Teams meetings and the users who synced a bot to a Google or Outlook calendar, reports meetings with bots, unique bots, external and guest attendees and a 1 to 5 bot app risk score, and revokes a bot's calendar access manually or automatically on detection. Misconfiguration Detection and Remediation Continuously compares sanctioned app settings against built-in best practices, categorizes the resulting misconfigurations by severity, offers one-click or guided remediation, and locks a corrected setting so it cannot drift again. Plugin Access Control Policies Names third-party plugins that are not allowed in the environment and periodically rescans marketplace apps for them, automatically revoking or blocking access where the marketplace API permits and otherwise raising a Jira or ServiceNow ticket or sending an email or webhook notification. Risky Account Detection Flags accounts in a supported app that were not provisioned through the organization's identity provider, and lets an administrator delete them in the app through a redirect link or defer review by one week or one month, after which the account returns to Not Reviewed. SaaS Agent Security Inventories the AI agents deployed on onboarded agent platforms such as Microsoft Copilot Studio and ServiceNow, monitors their configuration and posture for disabled authentication and overly permissive access, recommends and enforces remediation including pausing, deactivating and terminating an agent, and generates governance reports. SSPM App Onboarding Connects more than 90 SaaS apps to SaaS Security Posture Management through OAuth 2.0, direct administrator credentials, or an admin account reached through Azure AD or Okta single sign-on with a TOTP MFA secret key, names each instance and assigns an owner, supports reduced-permission onboarding and instance deletion that purges the app data, plus a manual entry path for further AI applications. SSPM App Owner Assignment Assigns an administrator holding the IT App Owner role to each onboarded app so posture violations, scan-health digests and misconfiguration alerts for that app route to them, and transfers ownership at any time. SSPM Application Settings Policies Creates administrator-defined policies that name specific settings on specific app instances for SSPM to monitor, carrying a severity level, and marks the policy Failed in Security Configurations when any monitored setting is misconfigured, alongside the predefined best-practice rules. SSPM Issue Tracker Ticketing Links SSPM to a Jira site or ServiceNow instance over OAuth 2.0 so an administrator can raise a ticket for a misconfigured setting or a third-party plugin from within SSPM, and unlink the instance later without deleting the tickets. SSPM Scan Health Monitoring Runs config, risky account, third-party plugin, identity and meeting scans at regular intervals per onboarded app, reports each scan and the app overall as Up, Unhealthy, Down or Scanning with the likely cause, and includes the status in a daily digest to the app owner. SSPM Webhook Notifications Posts SSPM notifications for app onboarding and deletion, first scans and detected configuration changes to a Slack or Microsoft Teams channel or a Webex space through an incoming webhook URL, with a connectivity test and Active, Registered, Unhealthy, Disabled and Down status tracking. Third-Party Plugin Catalog Provides a Plugin Library listing the plugins available from the supported SaaS app marketplaces, with publisher and app information, so a plugin can be judged before it appears in the environment. Third-Party Plugin Discovery Scans marketplace apps including Atlassian, Google Workspace, Microsoft SharePoint and Teams, Office 365, Salesforce, ServiceNow and Zoom for installed third-party plugins, shows the granted access scopes, a scope-derived severity, the app risk score, active and installing users and review status with unsanctioned and GenAI filters, and revokes plugin access for all or individual users.
Visibility & Reporting App Attribute Research Maintains the attribute values behind app risk scores by reading vendor documentation, examining app domains for TLS support and DMARC and SPF records, and analyzing traffic for HTTP security headers, with monthly additions and accuracy checks and quarterly refreshes. App Risk Scoring Assigns each discovered app a 1 to 5 risk score as the weighted average of more than 55 compliance, identity access management and security and privacy attribute values, and for generative AI apps blends a separately weighted GenAI risk score covering input and output data types, interface, model training use and popularity. App Tagging Applies default and custom tags to discovered apps to separate sanctioned from unsanctioned use, and recommends the Sanctioned tag for apps that Cloud Identity Engine shows as enterprise applications in Azure AD or Okta, with accept, re-tag and ignore responses. Application Dictionary Provides a searchable catalog of known SaaS apps with their category, attribute values and detection method, whether or not they have been seen on the network. Data Security Dashboard Summarizes scan results in eight interactive widgets covering assets by exposure and data type, top data profiles, top asset owners, open incidents by severity, user activity and security control violations, incidents by status, top policies and top external domains. Discovered App Filtering Filters discovered applications and the application dictionary by risk score, category, default tags, custom tags and applied policy rule recommendations, with relevance-ranked search. Newly Discovered App Notification Flags apps observed on the network for the first time within a rolling seven-day window on the dashboard and isolates them in a dedicated view for review. Risk Score Customization Overrides the risk score of an individual app without changing the calculation, or reassigns 0 to 100 weights across the underlying attributes so every app's score is recalculated, with a reset to defaults in both cases. SaaS App and User Discovery Identifies the SaaS apps and users on the network from NGFW and Prisma Access logs held in Strata Logging Service, recognizing more than 74,800 apps through machine-learning classification and presenting them as discovered applications and discovered users. SaaS Security Report Generates a PDF summarizing app, user and usage metrics, risk distribution, top categories, riskiest apps, highest-volume unsanctioned apps and top AI apps by usage, and schedules, shares or downloads it from the Strata Cloud Manager reports page. SaaS Visibility Dashboard Summarizes unsanctioned SaaS usage over a 7, 30 or 90 day range with applications by risk as a graph or table, the top ten categories by application and the top ten applications by usage, and a banner linking to apps first seen in the last seven days. Service Health Monitoring Continuously health-checks the Core, DLP, WildFire and URL analysis services, shows colour-coded availability, and emails a consolidated alert to configured recipients when a service is degraded or down. SSPM Dashboard Presents posture metrics across all sanctioned apps — rules by status, misconfigurations and risky accounts by app, and the apps with the most unreviewed third-party plugins — each linking through to the failing rule or plugin. Tenant-Level App Detection Identifies the specific tenant, workspace, organization or account users access within a supported app — roughly 45 apps including Box, GitHub, Slack, Microsoft 365, ChatGPT, Claude and Amazon Bedrock — using additional HTTP header logging or firewall session tracking, and surfaces them in a tenant details view. User Activity Monitoring Retrieves per-app user activity logs and presents monitored users with owned and collaborated asset counts and risk analysis charts, plus an activity explorer filtered by date, one of 36 action types, cloud app, target type and user, exportable to CSV.
App & Directory Connectors API Throttling Backlog Queues assets into a scan backlog when a cloud app vendor's API rate limit delays event delivery and processes them later while preserving original event timestamps. Azure Active Directory Integration Connects directly to an Azure Active Directory app registration with directory and group read permissions to retrieve up to 100 user groups, including nested groups, for group-based visibility. Cloud Identity Engine Integration Sources users, groups and dynamic user groups from Okta, Microsoft Azure Active Directory or Google Directory through Cloud Identity Engine for use in scanning scope, policy matching and policy rule recommendations. Connector Health Monitoring Reports a healthy, warning or critical status per connected app with a named cause, alongside assets ingested and scanned, P95 processing-time bucket, rate limits hit, incidents generated and remediated, and exposure counts. Connector Instance Customization Names each instance of a connected app and sets app-specific options such as an alternative quarantine account, Google organizational units to scan, or a per-instance request rate limit. Connector Lifecycle Actions Starts scanning, reauthenticates, verifies permissions, rescans and deletes a managed cloud app instance from the applications page. Connector Onboarding Validation Runs app authentication and permission validation checks between onboarding and scanning, blocks scanning until they pass, and reports sample assets and activities or a named error code when they fail. Directory Service Management Refreshes, reauthenticates and deletes a connected directory instance, with automatic user and group refresh every 24 hours. Group-Based Incident Visibility Limits an incident management administrator to incidents for assets owned by selected directory groups. Group-Based Policy Scoping Matches data asset policy rules on the file owner's directory group, including a Not Available case, and automatically closes incidents when a group or user is removed from the directory. Group-Based Selective Scanning Includes or excludes specific directory groups, or Google organizational units, from backward and forward scans of a connected app, configured before scanning starts. Read-Only Connector Mode Onboards a connector with read-only permissions so the service performs data discovery and user activity monitoring but cannot take remediation or post-remediation actions on the app. Sanctioned App Onboarding Connects a sanctioned SaaS app to Data Security through an app-specific administrator authorization so the service receives an API token and can scan the app's content, covering 28 supported applications across collaboration, storage, CRM, ITSM, HR and GenAI categories including Office 365, Google Drive, Box, Salesforce, Slack, ServiceNow and object storage on Amazon S3, Azure and Google Cloud.
User Behavior Analytics Behavior Threat Incidents Records each detected anomaly as a severity-rated incident with the contributing activity sequence, application names, timestamps and asset detail, filterable by time range, severity and originating policy and exportable for reporting. Dynamic Behavior Policies Detects anomalies against a machine-learning baseline built from up to 90 days of a user's and their peers' activity, covering hourly activity spikes, multi-hour bulk activity, abnormal or inactive-user activity hours, abnormal access locations and unusual access to files carrying Enterprise DLP data patterns. Dynamic User Group Enforcement Shows a user's Cloud Identity Engine dynamic user group membership on their detail page, registers Behavior Threats as a risk source in Cloud Identity Engine, and adds or removes the user from risk-based groups in near real time as their score changes or is reset. LLM User Risk Summary Generates a language-model narrative of unusual activity, data access patterns and security concerns for the top 0.1% of risky users, including users with no recorded incidents. Multi-Channel DLP Aggregation Correlates data loss prevention violations for a single user across Endpoint DLP, NGFW, Email DLP, Prisma Access, SaaS API and Prisma Access Browser and raises a Behavior Threats incident when the daily count exceeds a configurable threshold, filtered by channel, severity, enforcement action and data profile. Policy Weight Management Assigns a weight from 1 to 10 to each static policy and to the machine-learning baseline, or reverts to defaults, and recalculates existing user risk scores immediately on apply. Static Threat Policies Detects fixed-threshold threat indicators — impossible travel, risky IP addresses including Unit 42 malicious addresses and Tor exit nodes, unsafe VPNs, unsafe countries, consecutive login failures, inactive account access and malware interaction — with per-policy severity, user and IP or subnet exclusions, and email notification actions. User Activity Timeline Lists every policy violation that contributed to a user's score in chronological order with its detection rule, severity and percentage risk contribution, alongside a 90-day score trend chart, directory attributes and policy and severity filters. User Risk Score Reset Resets one or more users' risk scores to the baseline with a required justification, excludes all prior incidents from future calculation, and records the reset in the audit log and the user's timeline. User Risk Scoring Computes a 5 to 100 risk score per user from policy weights, incident count and severity and the watchlist risk amplifier, applies exponential decay that halves an incident's influence roughly every 30 days, and maps the result to Very Low through Critical severity bands. Users Risk Dashboard Presents the top three risky users, a risk score distribution chart, watchlist summary cards and a filterable table of monitored users with bulk score reset and watchlist actions and CSV download. Watchlists and Risk Amplifiers Groups users into four predefined watchlists — Departing Users, High Exec, Vendors and High Risk Users — plus up to six custom watchlists, each carrying a risk amplifier from 0.1 to 2 that multiplies policy violation impact, with the highest amplifier applying when a user belongs to several.
Inline Policy Enforcement App-ID Cloud Engine Delivers App-IDs on demand from the cloud for apps a firewall would otherwise classify as ssl, web-browsing, unknown-tcp or unknown-udp, so those apps can be named in Security policy instead of waiting for the monthly content release. Device Posture Conditions Conditions a recommendation on mobile device managed and compliant status, generating a Host Information Profile object when the recommendation is imported as a policy. DLP Profiles in Recommendations Attaches predefined or custom Enterprise DLP data profiles to a policy rule recommendation so sensitive data movement through the named apps is blocked. Identity-Scoped Rules Targets a recommendation at users, Active Directory groups or Cloud Identity Engine dynamic user groups, switching between log-discovered and Cloud Identity Engine identity sources and emitting the username and group-name formats the firewall expects. Inline On-Demand Scan Triggers an immediate delta scan of Strata Logging Service logs across all discovered applications instead of waiting for the daily 12:00 UTC cycle, applying a 30-minute buffer for log-forwarding delay and allowing one scan at a time. Internet Access Rule Authoring Creates SaaS enforcement directly as Strata Cloud Manager Internet Access rules, using the predefined SaaS-Inline policy recommendation snippet and folder configurations, instead of the hand-off recommendation workflow. Predefined Policy Recommendations Supplies five default recommendations — Block Access, Block Personal, Block Download, Block Upload and Prevent Share — whose name, description, activity and response are fixed but to which apps, users and groups can be added, with one-click block and unblock from the discovered applications list. SaaS Policy Rule Recommendations Authors block recommendations naming apps and user activities, pushes them to NGFW or Prisma Access for an administrator to import and commit, and supports enabling, modifying, monitoring for sync drift and deleting them afterwards. Tenant-Level Policy Control Scopes a recommendation to up to 30 named app tenants rather than the whole app, supporting Block for every tenant-detectable app and Allow with an Any wildcard for the subset that permits it, together with the policy ordering rules the firewall administrator must follow. User Account Scoped Rules Restricts a recommendation to specific user accounts within an app using firewall session tracking, so corporate accounts can be allowed while personal accounts on the same app are blocked.
Data Discovery & Classification Asset Discovery and Scanning Discovers and inspects assets in connected apps through backward scans of historical content, forward scans of new and modified content, and on-demand rescans, gathering file and folder metadata, collaborators and file contents. Asset Search and Export Finds assets and users through faceted search, advanced search and advanced search expressions, and exports the result set to CSV. Asset Snippets Displays the matched content excerpt behind an incident with confidence-level filtering, retained for 90 days and gated on write access to snippet requests. Data Pattern and Profile Matching Matches scanned content against predefined and custom data patterns and Enterprise DLP data profiles, including machine-learning document classification into financial, legal and healthcare categories and exact data matching against structured sources. Exposure Level Classification Assigns each asset an exposure level — Public, External, Company, Internal or shared via custom URL — by analyzing its sharing links and the set of users with access. Internal Domains and Collaborator Trust Defines the internal domain list that separates internal from external collaborators, with wildcard subdomain matching, and marks individual users or whole domains trusted or untrusted to override that classification. Policy-Driven Data Labeling Applies Microsoft Purview Information Protection sensitivity labels to Office 365 files and badged-field labels to Google Drive files from data asset policy actions, honoring label priority so a lower-priority value never overwrites a higher one, with manual override, downgrade prevention and daily labeling quotas. Snippet Data Masking Controls how sensitive values appear in snippets with no masking, partial masking showing the last four digits, or full masking. Supported File Types and Languages Extracts and scans more than 100 file formats across 17 file type categories up to 25 MB, in English, German, Japanese, Spanish, Italian, French, Dutch and Portuguese.
Logging & SIEM/SOAR Integration API Client Registration Registers one third-party API client with a generated client ID and secret and scopes limited to log file access, incident management, quarantine management, violation management and posture management, authenticating via OAuth2 client credentials against a region-specific host. Cortex XSIAM Incident Streaming Pushes Behavior Threats incidents as JSON to a Cortex XSIAM HTTP log collector, carrying tenant identifiers, description, severity, policy and user email under the ba_incident_event log type. Cortex XSOAR Integration Ships a Cortex XSOAR content pack and sample playbooks that pull incidents into XSOAR, mirror state in both directions, and run the same remediation actions — remove public sharing, quarantine, restore, notify owners and administrators — from the XSOAR incident view. Incident and Remediation API Provides REST endpoints to read and close an incident's state and to asynchronously quarantine or restore the asset behind it, under separate incident and remediation scopes. Log Events API Exposes a long-polling REST endpoint that returns activity monitoring, incident, remediation, policy violation and admin audit events one at a time with documented response fields, timing out after 20 seconds. Syslog Forwarding Pushes incident, policy violation, remediation, activity monitoring, admin audit and Behavior Threats logs to one external syslog receiver over TCP with TLS, in BSD or IETF message format with a selectable facility, with a separate SSPM syslog receiver profile for posture logs.
Administration & Access Control Administrator Activity Audit Logs Records state-changing administrator actions across Data Security, SaaS Security Inline, SSPM and Behavior Threats — policy edits, risk score resets, watchlist changes, tag and risk-score changes, report and data downloads, application and ticketing changes — and exposes them as filterable, downloadable logs including in the central Strata Cloud Manager audit log. Administrator Management Adds and manages Data Security, SaaS Security Inline and SSPM administrators through Common Services identity and access, including SAML single sign-on via third-party identity provider integrations. Application Groups Groups connected cloud apps and restricts an administrator to the assets, incidents and reports of only the apps in their assigned group. Custom Administrator Roles Creates up to 50 custom roles that assign no-access, read or write privileges per page and per action across Data Security, Inline Security and Posture Security permission hierarchies, with child permissions inheriting from parents unless overridden. Predefined Administrator Roles Ships fixed role definitions — Super Admin, Admin, Limited Admin, Incident Management Admin and Read Only for Data Security, and SaaS Inline Administrator, Superuser and View Only Administrator for SaaS Security Inline — each mapping to a documented set of view, download, create and full-control privileges per interface area.
Data Security Policy Data Asset Policies Authors rules that flag stored content by match criteria such as data pattern, exposure level, owner group, collaborators and applied label, on top of six predefined data policies that run automatically. Policy Tuning Lifecycle Edits, disables or deletes a policy rule to reduce false positives, and chooses whether the incidents associated with a deleted rule are closed or deleted. Rule-Free Data Violations Surfaces sensitive-content matches for enabled data profiles as data violations without requiring an asset policy rule to be authored. Security Control Policies Authors rules that monitor administrator-controlled settings and email behavior in SaaS and IaaS apps — email forwarding, retention rules, storage encryption, key and credential handling, multi-factor authentication — and raise violations when they are misconfigured. User Activity Policies Authors rules that flag abnormal user actions such as downloading or exporting data, with activity thresholds and originating IP address as match criteria, alongside predefined suspicious-activity policies.
Licensing & Activation CASB-X Bundle Activation Activates the cross-platform Next-Generation CASB (CASB-X) license against a Customer Support Portal account to unlock SaaS Security, Enterprise DLP, AI Access Security and SaaS Agent Security for associated NGFW and Prisma Access tenants, covering first-time single-tenant, multi-CSP multitenant and return-visit activation. License Tiers and Bundles Offers user-based and volume-based license options — Data Security All Apps, Public Cloud Storage add-on, per-firewall and per-tenant SaaS Security Inline, standalone SSPM, Behavior Threats, and the CASB-X, CASB-PA and Prisma Access Enterprise bundles — that determine which capabilities a tenant can use. Module Subscription Activation Activates the individual Data Security, SaaS Security Inline and SaaS Security Posture Management subscriptions on a tenant from an activation email, the hub, or the Customer Support Portal, including enterprise-level activation of up to 200 firewalls per session and conversion of an evaluation license to production. Tenant Allocation and Region Selection Allocates a purchased subscription to a tenant or subtenant in a tenant service group hierarchy and pins the deployment region, supporting managed service provider and distributed enterprise structures. VM-Series Credit-Funded Activation Enables SaaS Security Inline on VM-Series firewalls by including it in a Software NGFW credit deployment profile and registering firewalls against that profile, deducting credits at registration.
Service Connectivity Advanced Forwarding Transport Establishes pooled TLS connections directly from firewall data plane cores to regionally discovered advanced service addresses for inline cloud analysis submissions, replacing the legacy single-process transport, with configurable discovery interval, retry count, address overrides and proxy support. Service IP Allow List Publishes the region-specific outbound IP addresses used by Data Security, SSPM, SaaS Agent Security and identity security so customers can allow them on SaaS app allow-lists and on NGFW or Prisma Access tenants. Strata Logging Service Connection Streams NGFW and Prisma Access traffic logs from a Strata Logging Service instance into SaaS Security Inline so it can discover apps and users, and reports the connection as monitoring, not connected, or in error.
Content Threat Analysis Phishing URL Analysis Scans chat and channel messages and the URLs embedded in them for malicious and phishing links against an allow list of exempt URLs and domains, and modifies or deletes the offending URL automatically or on demand. WildFire Malware Analysis Submits selected file type categories, optionally with cloud app, path, timestamp and user context, to WildFire for static and dynamic analysis, tracks a per-asset malware verdict, and renders a downloadable report with the verdict, VirusTotal link, analysis detail and a verdict-dispute request.
The unified management plane for the network security platform, covering both NGFW and SASE deployments.
Configuration Management Advanced/Legacy Routing Engine Coexistence Manages both Advanced Routing Engine (Logical Router) and Legacy Routing Engine (Virtual Router) configurations within a single tenant via device-level routing mode selection, so a mixed-generation firewall fleet migrating from Panorama does not need separate tenants; the Panorama-to-Strata-Cloud-Manager migration tool converts and pushes both configuration types simultaneously. Application Catalog Lists vendor-identified applications with normalized names and metadata such as risk score, category, technology, and compliance attributes, lets administrators classify them as sanctioned, tolerated or unclassified, and now extends Unified Application Dictionary normalized names across policy surfaces including Security Policy Rules, SD-WAN, and WildFire/Antivirus profiles. Auto-Tagging and Dynamic Groups Assigns tags from log-triggered activity and re-evaluates dynamic user and address group membership so policy enforcement changes without an administrator edit. Certificate Lifecycle Integration Syncs certificates from the running configuration into an external certificate-inventory service, tracks managed and unmanaged state, surfaces expiration and cryptographic-health widgets, and renews certificates against enterprise certificate authorities using issuing templates. Certificate Management Generates, imports, renews, revokes and exports certificates and private keys in multiple encodings and manages certificate profiles, OCSP responders, SSL/TLS service profiles and trusted certificate authorities for use across decryption, authentication and client connectivity. Cloud and Virtual Firewall Onboarding Registers cloud-native firewall resources on AWS and Azure for shared policy management and deploys and monitors VM-Series firewalls from the same console alongside hardware appliances. Cloud IP-Tag Collection Onboards cloud provider and microsegmentation accounts by credential or generated infrastructure-as-code template, polls them on an interval for IP-to-tag mappings scoped by region or VPC, and distributes the mappings to firewall folders as dynamic address groups. Configuration Health and Drift Surfaces per-folder counts of firewalls and objects whose cloud configuration conflicts with local device configuration, alongside device connectivity, sync state, high-availability pairing, content and software versions and license status. Configuration Snippets Bundles configuration objects into named, labelled, versioned units associated with folders, deployments or devices, with a vendor-maintained predefined library, clone and delete controls, and conversion of an existing device local configuration into a snippet. Configuration Variables Defines typed placeholder values for network, routing, QoS, high-availability, interface and threshold settings that shared configuration references, resolves them per folder, deployment or device with override, and bulk-edits them through CSV export and import. Cross-Tenant Snippet Publishing Establishes mutual trust between tenants by tenant ID and pre-shared key, then publishes snippets from a publisher tenant to subscriber tenants with pre-update validation, per-subscriber delete controls and publish status tracking. Cryptographic Key Management Connects managed firewalls to external hardware security module providers for key generation and storage, and deploys, re-encrypts and rotates the device master key on a defined lifetime with expiry reminders across standalone and high-availability pairs. Custom EDL Hosting Hosts tenant-owned external dynamic lists aggregated from git repositories, API endpoints and file uploads, validates them, and distributes them from a chosen region to the firewalls that reference them. Device Networking Configuration Configures per-device network constructs from the console including interfaces and sub-interfaces, zones, virtual wire, routing profiles and static routes, IPSec tunnels, DHCP, DNS proxy, web proxy and remote-access gateway and portal roles. Device Quarantine Maintains the quarantine list for firewalls acting as GlobalProtect portals and gateways and for Prisma Access, blocking a device by host ID or host ID and serial number and showing which devices administrators have quarantined. Device Setup Settings Exposes the platform-level device settings surface — management interface and service routes, services and DNS, dynamic-update scheduling, administrator authentication, accounting and password policy, SNMP, banners and logos, session and tunnel timers, and Content-ID inspection and signature-lookup behaviour. Dynamic Privilege Access Defines projects as a user-group and IP-pool pairing mapped to location groups so a mobile user receives only the network and security policy of the project selected in the agent, administered under a dedicated project administrator role. End User Coaching Notifications Delivers branded, locale-aware notifications to end users on policy or experience events through a tenant-wide brand profile and editable notification templates bound to policy rules, with preview and exemption-request handling. Enterprise Browser Management Manages a secure enterprise browser from the same console with dashboards, event analytics, user, device, application and extension directories, access and sign-in rules built from reusable profiles, and end-user bypass requests. Enterprise DLP Configuration Configures inline data loss prevention using predefined and custom data patterns, exact data matching, custom document types, optical character recognition on images and email inspection, and surfaces the resulting incidents for investigation. Folder Hierarchy Management Groups managed firewalls and deployments into labelled folders nested up to four levels that can be created, edited, moved and deleted, alongside predefined non-editable hierarchies for managed services. Global Configuration Search Searches every configuration object and setting for a string filtered by location, object type, editor and edit time, returns every reference with a link to its location, and keeps a per-administrator search history. Global Network Services Setup Configures tenant-wide services including automated VPN tunnel and cluster creation between managed devices and centrally managed SaaS application endpoint definitions. GlobalProtect Portal and Gateway Management Turns cloud-managed firewalls into remote-access portals and gateways with agent application and tunnel settings, match criteria, gateway priority and region selection, and authentication profiles. Guided Folder Structure Builder Proposes a device-grouping architecture from a chosen pattern such as by function, by region or mixed, lets the administrator edit the resulting folder tree, and bulk-assigns firewalls into it. Hierarchical Configuration Scope Applies configuration and policy at a selectable scope — global, folder, nested folder, deployment type or individual device — inheriting down the tree with override at lower levels, and indicates on each object whether its value is inherited, predefined or locally defined. High Availability and Clustering Configures active/passive and active/active high-availability pairs with session-synchronization interfaces, floating addresses, load-sharing methods and election priorities, and groups supported chassis into a cluster managed as a single logical device. Identity Services Configuration Connects the platform to directory and authentication sources, redistributes user-to-IP identity mappings across firewalls and Prisma Access, and maintains local user and group databases. Internet Access Rules Defines a rule type in the security rulebase that replaces Web Access policy rules, matching SaaS applications and URL categories against Cloud Identity Engine users and groups to apply per-application functional controls, data-security inspection and app-tenant handling, with SaaS Security inline enforced natively rather than through policy recommendations. Internet Security Central Settings Captures internet security settings and objects centrally for a scope — vulnerability protection, WildFire and malware protection, country block, command-and-control detection, DNS security, decryption, file control, device posture and App Group with Control — which apply globally to all allowed internet traffic without being attached to individual rules. IPS Signature Converter Translates third-party Snort signatures and Suricata rules into custom threat signatures that can be referenced from vulnerability protection and anti-spyware profiles. Network Policies Creates traffic-handling rules for QoS prioritization, application override, policy-based forwarding, network address translation, packet brokering to third-party appliances and SD-WAN path selection. Policy and Object Context Menu Applies rule, field and object actions directly from policy and object list views, including clone, move, enable/disable, paste, filter by value, resolved-value lookup and a pre-filtered Config Search. Response Page Customization Edits the pages end users are served by the firewall — GlobalProtect portal login, welcome and help pages, multi-factor and SAML authentication error pages, and decryption notification pages. SaaS Application Controls Provides per-SaaS-application policy match criteria including subscription to vendor-hosted endpoint IP and URL feeds that refresh automatically, restriction of application use to approved corporate tenants and domains, and safe search enforcement. SaaS Security Configuration Discovers sanctioned and unsanctioned SaaS applications from traffic logs, scores their risk, scans stored assets for exposure, detects SaaS posture misconfigurations and anomalous user behaviour, and generates a shareable usage report. Sandbox Service Administration Administers the malware-analysis cloud service by generating API tokens, reporting submission counts, and selecting the regional cloud used for macOS dynamic analysis to satisfy data residency requirements. SD-WAN Management Manages SD-WAN sites, data centers and ION devices with stacked forwarding and security policies, CloudBlade integrations, shared resources, configuration profiles and templates, and tenant system settings. Security Policy and Profiles Defines top-down traffic allow and deny rules plus attachable protection profiles and profile groups covering anti-spyware, vulnerability protection, antivirus and sandboxing, DNS, URL filtering, file blocking, HTTP header inspection, AI traffic, decryption and denial-of-service. Shared Policy Objects Defines reusable policy building blocks — addresses, application groups, services, tags, host information profiles, dynamic address and user groups, external dynamic lists, schedules, log forwarding profiles and quarantine lists — that rules reference and that propagate when the object changes. Virtual System Management Enables multi-virtual-system mode on a firewall and creates, updates, deletes and moves virtual systems between containers, imports interfaces into a chosen virtual system, and pushes configuration to one or several virtual systems at once with per-system sync status.
Visibility & Insights Activity Insights Aggregates firewall, SASE and SD-WAN log data into a filterable dashboard of applications, users, domains and URLs, security policy rules, source and destination regions and privileged-access projects, with drill-down to per-entity detail and pivots into the log viewer. Advanced Threat Prevention Insights Presents exploit and command-and-control activity with blocking efficacy metrics, a known-versus-unknown detection split, severity-to-action mapping and geographic attribution of attacker infrastructure to internal victim hosts. Advanced URL Filtering Insights Presents web threat activity including total versus malicious URL requests, real-time zero-day URL detections, malicious category breakdowns, top risky domains and the users, firewalls and rules driving malicious traffic. AI Security Insights Reports generative-AI application usage by user and app, and the cloud attack surface and runtime threats against AI models, applications and datasets, from the console's AI Access and AI runtime security dashboards. Application Experience Monitoring Scores end-user digital experience for monitored applications from synthetic tests on mobile-user endpoints and remote sites, breaking the score down by device, Wi-Fi, local network, internet, cloud location and application segment, and charting trends and geographic distribution. Command Center Presents swappable summary, threat, operational health, data security and application security perspectives with headline metric widgets showing period-over-period change and drill-through into the detailed dashboard behind each one. Custom Dashboard Builder Assembles personal dashboards by dragging widgets from a subscription-gated widget library onto a canvas, previewing with sample or live data and editing widget filters and layout. Custom Report Builder Builds multi-page PDF reports in a what-you-see-is-what-you-get editor by dragging chart, table and text widgets onto page layouts, generating widgets from a natural-language prompt against selected data sources, and paginating oversized tables automatically. CVE Exploit Visibility Lists unique CVEs observed exploited in network traffic with CVSS severity, EPSS score and percentile, known-exploit status, affected device counts and a patch-prioritization metric, mapped to the threat signatures that detected them. Device Log Forwarding Forwards system, config, User-ID, IP-tag, HIP match and GlobalProtect logs from managed firewalls to syslog, HTTP, SNMP and email destinations with severity and attribute filters, and configures NetFlow export and the PA-7000 log forwarding card. Device Security Insights Surfaces discovered IT, IoT, OT and BYOD assets with identity and posture attributes, prioritized vulnerability and threat risk, and recommended security policy rules built from observed traffic behaviour. DNS Security Insights Presents DNS threat activity including malicious versus benign query volumes, top malicious and command-and-control domains by category, the users and devices querying them, destination countries, resolver usage, domain-hijacking activity and DNS misconfigurations. Insights Dashboard Suite Ships a library of prebuilt interactive dashboards spanning activity, threats, application experience, SD-WAN, compliance, zero-trust posture, feature adoption, CVEs and capacity, each gated by license and role. Interactive Widget Controls Allows per-widget filtering, column reordering, zooming, raw-data viewing, CSV export and legend toggling, with dashboard time ranges from fifteen minutes to forty-five days or a custom window. Log Viewer Opens raw log records against a query and allows further refinement, export and investigation from any analytics drill-down. Logging Service Management Manages the cloud log store from the console — instance status, onboarded log sources, allocated storage quota, available space and retention days, and forwarding of stored log data to external servers. NetSec and SASE Health Maps Plots user devices, branch and third-party sites, NGFW devices and ADEM-monitored applications on interactive geographic maps colour-coded by experience score, with flight paths between endpoints, degraded-experience breakdowns by network segment, experience trend charts and drill-down to a single device, site or application. NGFW Device Inventory Lists every onboarded firewall and Panorama appliance with model, software and content versions, telemetry state, licence and certificate expiry, hardware component health and quantum readiness, filterable and exportable, and lets an administrator set each device's geographic location and network role. Personal Favorites Lets a user star any sub-menu page into a private list, rename entries without affecting the original, see each entry source path and remove entries. Report Templates and Scheduled Delivery Provides prebuilt report templates such as executive summary, user activity, network usage, application usage, GDPR and SaaS risk plus custom reports, which can be downloaded as PDF, CSV or text, shared with validated recipients and scheduled to recur. Sandbox Analysis Insights Reports malware-analysis activity as submission and verdict trends, prevention split by signature, inline machine learning and inline cloud analysis, attack origin and target regions, targeted users, submitting firewalls and delivering applications, with per-sample download and incorrect-verdict reporting. SASE Deployment Monitoring Reports the status, bandwidth consumption, tunnel health and routing tables of remote networks, service connections, ZTNA connectors, Prisma Access locations and compute locations, ION devices and network services such as GlobalProtect authentication and DNS proxy. SD-WAN Application Health Scores WAN application health over time and reports new TCP and UDP flows, bandwidth utilization per site and application, and TCP transaction success and failure statistics. SD-WAN Link Quality Monitoring Rates links and applications per VPN cluster on tunnel downtime, latency, jitter and packet loss, ranks the worst links and most impacted applications, and raises alerts from data-driven thresholds with drill-down to the affected site. SD-WAN Predictive Analytics Scores sites, links and applications as good, fair or poor from machine-learning health models and forecasts branch capacity utilization from the previous three to six months of traffic, alongside device-to-controller connectivity and traffic-growth rankings. Threat Activity Insights Classifies detected threats into a category and sub-category taxonomy attributed to the security subscription that caught them, separating signature-based blocks from novel detections and quantifying threats prevented through shared global intelligence. Threat Artifact Search Searches a file hash, URL, domain, IP address, threat identifier or CVE and returns its local and global prevalence, detection reasons, passive DNS history, WHOIS registration, sandbox static and dynamic analysis, and downloadable PDF, MAEC and packet-capture reports. Threat Research Context Linking Surfaces vendor threat-research articles and category descriptions alongside a selected threat category and links threat names, identifiers and CVE references into a threat search. Traffic Topology View Renders an interactive source-to-application traffic map across Prisma Access, NGFW and SD-WAN with hover detail, click-to-filter bubbles, global filters by platform, source and connection type, selectable time ranges and automatic refresh.
Security Posture Best Practice Assessment Scores device, Panorama and cloud-service configuration daily against vendor best practices across security rulebases, rules, profiles, identity, network and service-setup categories, flags which failed checks map to CIS Critical Security Controls, and reports adoption trends over time. CLI Remediation Guidance Generates the device-level CLI commands that fix the configuration issue behind a failed check or posture alert. Compliance Center Continuously assesses NGFW and SASE configuration against selected industry frameworks, producing an overall compliance rate, an industry peer benchmark, a compliance trend over time, per-control pass and fail results with severity, and downloadable or scheduled framework reports. Compliance Remediation Workflow Turns failed configuration checks into incidents carrying a remediation playbook, evidence of the exact failing configuration and its console path, deep links to the managing console, an activity log, and scoped or global exceptions that remove a check from compliance calculations. Configuration Cleanup Identifies unused configuration objects, objects inside rules that never matched traffic, and zero-hit policy rules, and deletes, enables or disables them with filtering by age and object type. Custom Compliance Framework Authoring Creates a compliance framework by cloning an existing one, uploading a CSV template or building it manually, defining control hierarchy levels, controls and sub-controls, optional control groups and associated predefined or custom checks, with revision numbers, release notes and controlled deployment. Custom Posture Checks Builds tenant-defined configuration compliance rules in a logic builder of expressions, conditionals and groups that can evaluate referenced objects, invert the pass verdict, and be cloned from predefined best-practice checks. Feature Adoption Tracking Shows which security capabilities are in use across device groups, zones, tags and rules and identifies the rules where an unused capability could be turned on. Inline Cloud Analysis Bulk Enablement Lists every security profile where cloud-based inline threat analysis is disabled and turns it on across multiple profiles from a single dialog. Panorama Deployment Posture Coverage Extends posture, cleanup and optimization analysis to Panorama-managed firewalls in the same tenant, writing remediations into the Panorama candidate configuration with per-item status tracking. Policy Analyzer Reports whether existing rules already satisfy a proposed rule intent before a change, and analyzes committed rulebases on every change and on a recurring schedule for shadows, redundancies, generalizations, correlations and consolidation opportunities with per-rule remediation steps. Policy Optimizer Flags overly permissive rules from traffic-log analysis over a configurable lookback window and generates narrower replacement rules covering source user, address group and application, which administrators edit, merge, accept and track. Posture Check Enforcement Applies an alert or block response to a failed posture check, enforced in real time for security policy and at push or commit time for other configuration objects. Posture Check Exceptions Bypasses a posture check verdict either globally across the tenant or narrowed by scope down to a single configuration object. Posture Coverage Recommendations Flags coverage gaps in the overview — unsecured direct-to-SaaS traffic, last-mile protection opportunities, unlicensed subscriptions and recommended policies against detected anomalies — and routes the administrator to where each gap can be closed. Quantum-Safe Security Builds a live cryptographic bill of materials from session, certificate and tunnel telemetry, classifies each application, user device, infrastructure and IoT asset by cryptographic risk, quantum readiness and business impact, and issues hardware, software, certificate and cipher-translation remediation recommendations with executive reports. Security Subscription Adoption Tracking Tracks each cloud-delivered security subscription through activation, configuration and best-practice stages per device, recommends missing services from administrator-assigned zone roles, and lets an administrator override a recommendation with a stated reason. Zero Trust Posture Center Scores configuration against five zero-trust pillars with an industry peer comparison, stack-ranks impact cards showing the risk, detected active threats and the score gain from fixing each, and routes each recommendation to the filtered incidents that remediate it.
Incident Management Associated Event Notification Control Separates incident state-change notifications from correlated-alert notifications and suppresses the latter over email per profile by default. Incident Dashboard and Filtering Shows open incident counts broken down by product, category, severity and priority with raised, cleared and suppressed counts for the last 24 hours, and filters the incident table by those dimensions plus state and impacted-object type with configurable column selection and order. Incident Detail Investigation Opens a single incident to show its description, impacted and related objects, evidence list of affected devices, raise and clear conditions, root-cause and remediation guidance, timestamps and a chronological activity log. Incident Settings Audit and Reset Records who changed each incident setting or notification profile and when, publishing every create, update and delete to the Strata Logging Service log viewer, tracks per-setting hit counts, searches all detections by any dimension, and resets settings to factory defaults at code, subcategory, category or product level. Incident Settings Framework Ships an editable default setting per incident code and lets tenants add custom settings matching on product, severity, category, subcategory, code and object that raise or suppress incidents, with scheduled maintenance-window suppression, cloning, bulk modification, per-check toggles, and longest-match custom-over-default resolution when several settings match. Incident Threshold Customization Defines how long a condition must persist, how often it must recur and over what window before an incident is raised or cleared, for a defined set of tunnel, BGP, site-capacity, CPU, license, certificate, sync and high-availability incident codes, with revert to default. Incident Trend Analytics Charts incidents raised, cleared and newly raised over a selectable time range and surfaces recommended actions for improving incident configuration and operational health. Incident Triage Actions Allows an operator to acknowledge or unacknowledge an incident, add comments, set or change its priority, and manually clear it. Informational Alerts Feed Lists alerts about upcoming, in-progress and completed software upgrades with alert name, code, generation time, identifier and notifications sent, filterable by time range and alert code. Notification Profiles Routes incident raise, update and clear notifications to teams or individuals by category or specific incident over email and webhook endpoints with none, basic or bearer authentication, validates both channels with a test send, and deep-links back into the console. Sandbox Verdict Incidents Surfaces malware, phishing, grayware and benign sandbox verdicts as incidents under a suppress-by-default model requiring explicit per-object opt-in, with automatic clearing, no manual clear and dedicated email templates. ServiceNow Ticketing Integration Creates and updates ServiceNow tickets from incidents over the table API using OAuth or basic authentication with configurable field mapping including static custom fields, connection testing, optional status sync back from ServiceNow, and an audit log of each operation. Signed Webhook Deliveries Signs each webhook payload with a per-profile HMAC-SHA256 secret carried in a versioned signature header and supports secret rotation with a 72-hour dual-signature grace period. Unified Incident Framework Consolidates alerts and incidents from every covered security product into one list under a shared taxonomy of categories, subcategories and flat-namespace incident codes, correlating multiple alerts into a single incident with parent and child relationships. User Risk Behavior Analytics Scores user risk from weighted policy violations and a machine-learning baseline with recency decay, aggregates data-loss violations across endpoint, firewall, email, proxy, SaaS API and browser channels into behaviour incidents, shows a per-user activity timeline of risk contributions, and amplifies scores for users on predefined or custom watchlists.
Configuration Operations Configuration Version Snapshots Retains pushed configuration versions plus user-saved named snapshots, compares any two versions or a snapshot against the candidate configuration, and restores a version to running devices or loads it back as the candidate. Device Lifecycle Operations Runs per-device operations from the console — fetch licence information, reboot, change routing mode, force bootstrap, view and restore local device configuration versions as XML — and replaces a failed appliance through a return-authorization workflow that transfers configuration and high-availability pairing to the replacement. Panorama Configuration Sync Links on-premises Panorama appliances to the tenant and publishes snippets to them as device groups and templates, pruning unsupported elements, recording per-job status with timeout and crash recovery, and keeping snippet version snapshots and an audit history. Panorama Connector Plugin Connects an on-premises Panorama management appliance to the cloud service through an installed plugin, including via an HTTP proxy, so Panorama-managed firewall configurations can be analyzed and checked before commit. Policy Rule Targeting Restricts which NGFWs in a configuration scope receive a given policy rule at push time, and converts Panorama target nodes to the same form during migration. Push Status and Job History Records each push and validation as a job with result, initiating administrator, target devices, timing, warnings and errors, and lets pending commits be inspected or cancelled. Scoped Configuration Push Pushes candidate configuration to selected devices, folders, deployment types or external services filtered by administrator scope, supports partial push and selective revert with a colour-coded before-and-after preview and dependency errors, allows blocking security-check failures to be overridden, and queues concurrent pushes. Software Upgrade Scheduler Schedules PAN-OS upgrades and downgrades to a target version at a chosen date and time across selected firewalls, and can defer the reboot so installation and restart happen in separate maintenance windows. Tenant Metadata Export Exports the tenant deployment data as compressed JSON for handoff to technical support. Troubleshooting Jobs Runs on-demand diagnostic jobs against selected firewalls for live sessions, DNS proxy cache, NAT rule IP pools, user groups, dynamic address groups, dynamic user groups and user-to-IP mappings, and keeps a sortable history of the jobs run.
Access & Tenancy Administration Administrator Scope Management Defines scope objects listing specific folders, firewalls, deployments and snippets, then assigns administrators and a role to each scope so their read and write access is confined to that subset of the configuration. Audit Logs Records every administrator- and API-initiated action with the actor, timestamp, category and description, filterable by date range, user, category and change type, and consolidates audit events published by covered services into the same log. Multi-Tenant and Subtenant Scoping Filters incidents, settings and operational data to a selected tenant or Panorama subtenant, persisting that context across pages while keeping per-subtenant settings isolated. Regional Tenant Placement Runs a tenant instance in a customer-selected geographic region and pins telemetry processing to that region, falling back to a United States instance where the service is not deployed. Role-Based Access Control Gates each console action behind a fixed set of administrator roles split into read-only and full-access tiers, covering view, create, delete, snapshot, schedule, widget build and data explorer permissions. Role-Scoped UI Modes Filters the entire navigation to a task-focused subset for a given administrative mission, sets a per-mode default landing page and colour-coded header, persists the selection across logins, and biases global search results toward the active mode. Tenant and Product Lifecycle Sets the per-tenant details the console holds on each tenant in the hierarchy — business vertical, support contact and idle-session timeout. Trusted IP Access Control Restricts web interface and API access to a per-tenant allow list of IP addresses added singly or by CSV import, inherits the list from parent to child tenants, records who added each entry, and provides an out-of-band path to unlock an administrator who blocked themselves.
AI Assistance Access Analyzer Answers natural-language questions about access and connectivity in a secure-access deployment, running what-if analysis against the configuration and keeping a table of prior queries to reopen. AI Canvas Lets users query network security data in plain language and assemble the resulting visualizations onto named drag-and-drop canvases created either from scratch or generated wholesale from a single query. AI Widget Library Stores generated and prebuilt visualization widgets in a reusable catalog where users view, zoom, regenerate, switch chart type, export as image or table, and delete widgets not in use on a canvas. AI-Assisted Support Case Creation Opens a vendor support case from the assistant with product, component, severity, description, affected assets and steps already taken prepopulated from the session and tenant context, allows file attachments, and preserves the draft for an hour. Canvas Export and Sharing Exports a canvas as a formatted PDF and generates an authenticated shareable link that preserves the data view as of the time it was shared. Canvas Summarizer Generates natural-language summaries of a whole canvas, a single widget or one clicked data point, each with highlighted insights, suggested follow-up prompts, the underlying query code, related canvases and a pivot into pre-filtered raw logs. Query Intent Clarification Intercepts an ambiguous widget query with a clarifying question and suggested refinements, then shows the executing prompt, data sources, generated query code and chart type for approval or modification before any data is fetched. Strata Copilot Answers natural-language questions about the deployment and about vendor documentation in a multi-turn chat, returning cited summaries, live deployment data and interactive visualizations, and executing actions such as searching indicators, searching configuration, navigating the console, marking applications sanctioned and quarantining devices, across supported regions and languages.
Configuration Migration Migration Catalog Presents the available migration paths from other management platforms as a hub of tiles carrying per-path prerequisites, workflow steps and last-accessed timestamps. Migration Compatibility Assessment Analyzes an uploaded configuration before migration, reports unsupported and partially supported features, trims them from the staged configuration and exports a compatibility summary. Migration Configuration Diff Compares the staged post-migration configuration against a device last-pushed configuration, grouping changes into modified, unsupported and informational categories with per-object drill-down, filtering and export. Migration Policy Optimization and Reporting Deduplicates, merges and splits translated rules against best-practice logic, flags fully, partially and unmigrated rules and unmapped objects for manual mapping, and emits PDF and JSON migration reports. Migration Snapshot and Rollback Takes a pre-migration configuration snapshot and lets an administrator revert, cancel or roll a migration back to the prior staged state. Migration Template Mapping Associates Panorama templates and template stacks with target folders automatically during migration, with manual mapping and snippet precedence ordering as an alternative. Panorama Configuration Migration Imports an exported Panorama running-configuration XML and converts device groups into folders and templates and template stacks into snippets, migrating device groups in phases. Zscaler Configuration Migration Ingests Zscaler Internet Access and Private Access configuration by API credential or uploaded JSON bundle, translates the policies and objects into Prisma Access equivalents, and imports the result as a reusable snippet.
Device Health & Lifecycle Anomaly Baseline Bands Computes a rolling 28-day hour-binned tenth-to-ninetieth-percentile baseline band behind trend widgets and highlights the trend line when values fall outside it. Application Acceleration Monitoring Reports which applications are being accelerated for remote users and how the service is adapting to device, network and application context. Capacity Analyzer Charts per-metric resource utilization as a heatmap across device models and devices against model-specific maximums, and uses a trained model over accumulated telemetry to forecast the date each metric will hit capacity and raise alerts ahead of it. Device Health Metrics Charts per-device system, session, interface and environmental metrics over time across the managed fleet, with per-metric definitions and drill-down to the contributing devices. Device Telemetry Ingestion Collects PAN-OS telemetry from firewalls and Panorama into the logging service on a fixed sampling schedule, enabling it automatically on newly onboarded devices and controlling telemetry settings centrally from the cloud console. Experience Agent Management Lists registered digital-experience endpoint agents and remote-site agents with their online state, last-seen time, monitoring state and agent version, releases a licence when an entry is deleted, drives agent upgrades, and shows the domain health-score metrics and thresholds behind the experience scores. Feature-Aware CVE Assessment Raises vulnerability incidents only for firewalls running both an affected software version and the affected feature, and shows per-CVE device impact with the affected feature named. Software Upgrade Recommendations Analyzes enabled features to recommend a target software version per device, generated automatically twice weekly, on demand from selected CVEs, or from an uploaded tech-support file, with a report of new features, behaviour changes, vulnerabilities and known issues.
Onboarding & Provisioning Device Labels and Onboarding Rules Tags devices with labels and applies top-down match rules on model, serial pattern or label expression that assign a target folder, snippet, VPN cluster and user-context mapping when a device first connects. Guided Onboarding Workflows Walks an administrator through first-time deployment of firewalls and secure-access components — mobile users, explicit proxy, enterprise browser, private-app connectors, service connections and branch or remote-network sites — as step-by-step wizards. NGFW Onboarding to Cloud Management Moves a registered firewall from the available-devices pool into cloud management, pushes a default configuration, converts it to advanced-routing mode, and offboards it back to an unmanaged state on request. Onboarding Validation Confirms a newly onboarded device reached connected state, that both default configuration pushes succeeded, and that its data is appearing in device management and the command center. Site Management and Variable Resolution Models deployment sites with typed properties and resolves per-device configuration variables from those properties using string substitution or bitwise IPv4 expressions, previewable before a device claims a site. Zero Touch Provisioning Registers a shipped firewall by serial number and claim key so it self-onboards to its tenant on first internet connection over Ethernet or 5G cellular, with automatic management-interface failover and per-stage bootstrap tracking. ZTP Mobile Activation App Lets a field installer activate a firewall from a phone browser using QR-code scan to prefill the serial and claim key, GPS-based nearby-site suggestion, camera-based cable detection, and a seven-day activation history.
Licensing & Entitlement Subscription Lifecycle Management Drives the subscription actions the console adds on top of the shared entitlement surface — requesting a trial add-on, amending an existing subscription, and tracking terms that start on a future date. Subscription Usage Tracking Charts consumption against entitlement — twelve-month tenant data transfer, unique mobile users over the previous thirty days by connection method, remote-network bandwidth against allocation per compute region or site, service connections deployed, and remaining add-on quantities such as application tests. Tenant Activation and Licensing Confers a Strata Cloud Manager instance at either the free Essentials tier or the paid Pro tier, entitled by a Prisma Access, enterprise agreement or software NGFW credits purchase, and upgrades an Essentials instance to Pro in place.
Platform APIs Configuration APIs Exposes the managed configuration over REST endpoints organized by functional area and covering the secure-access, NGFW and cloud NGFW platforms. Service Account API Access Authenticates automation to the Strata Cloud Manager configuration APIs with a service-account OAuth token, gated by the same role permissions and trusted IP allow list that apply to an interactive administrator of the tenant.
The firewall as a virtual appliance for private and public cloud.
Licensing & Credits Bundle Renewal, Downgrade and Forfeit Offers three choices at bundle renewal — renew at an adjusted quantity, downgrade to a basic bundle that keeps the model with perpetual capacity and support, or forfeit licenses per serial number and keep the installed software running without updates. BYOL and Pay-As-You-Go Marketplace Licensing Sells bring-your-own-license auth codes singly or in bootstrappable bundles and prelicensed pay-as-you-go images across the AWS, Azure, Google, Oracle, Alibaba, IBM and Tencent marketplaces, billed hourly, annually or per minute, with sovereign marketplaces and IBM Cloud license-only. A pay-as-you-go instance takes the largest model its vCPU and memory allow and suspends licensing when stopped. Capacity Model Upgrade Raises a deployed firewall to a larger model — and its session, rule, zone, address-object and tunnel limits — by allocating more host resources and then retrieving keys from the license server, entering an auth code or uploading a key file, upgrading the passive peer of a high-availability pair first while configuration sync is automatically suspended for the capacity mismatch. Credit Activation and Administration Activates purchased credits into a support account's credit pool from an emailed activation link, creating the customer support portal account when none exists and granting the purchaser a credit administrator role that can allocate and transfer credits. Credit and Profile Renewal Moves expired deployment profiles to a renewal tab where they can be renewed without disruption within 30 days, restores profiles automatically once renewed credits meet the prior allocation, and consumes surplus credits to upgrade legacy Threat Prevention, URL Filtering and WildFire subscriptions to their Advanced versions. Credit Transfer Between Pools Moves credits between pools in the same support account or into a different account under the same parent-child contract when credit type and expiration date match, recording each transaction in the pool audit trail. Deployment Profiles Defines a named licensing profile specifying PAN-OS version, fixed model or flexible vCPU count up to 64, firewall and virtual system counts, memory profile, Panorama role and security subscriptions, issues one shared auth code consumed by every firewall it deploys, and supports editing, cloning, transferring between credit pools, deleting and an audit trail of changes. Enterprise Agreement Token Delegation Grants an enterprise-agreement administrator role that activates the agreement auth code, invites other support accounts to share the token pool, allocates specific models and quantities per grantee subject to their acceptance of the licence terms, and reclaims tokens for redistribution. Firewall Registration to a Support Account Registers each firewall instance on the customer support portal by auth code, or by serial number, CPU ID and UUID with no auth code for usage-based public cloud instances, and tracks deployed against available licenses per auth code. Instance Identity Binding Derives a unique serial number from the virtual machine's UUID and CPU ID at activation, encoding hypervisor and license type in the CPU ID format, and leaves unlicensed firewalls without a serial number, with non-unique dataplane MAC addresses and minimal session capacity. License Deactivation and Credit Return Releases capacity, subscription and support licenses from the firewall web interface, CLI, XML API or Panorama and returns the credits to the pool automatically when connected or through an exported token file when air-gapped, and reclaims credits server-side from firewalls that were terminated without deactivating by selecting those absent from check-in for a chosen number of days. License Expiry Warning and Degradation Writes a daily system warning starting 30 days before expiry and enforces expiry at midnight GMT regardless of firewall time zone, after which some subscriptions fall back to limited operation and others stop, and an expired Panorama support license retains management and log collection but blocks software and content updates. License Type Switching Switches a deployed bring-your-own-license firewall between subscription bundles, capacity and enterprise-agreement licenses individually or in bulk from Panorama without interrupting traffic, while conversion between bring-your-own-license and pay-as-you-go requires export, redeploy and import. Migration to Flexible Credit Licensing Converts deployed firewalls from perpetual or enterprise-agreement model licenses to credit-funded deployment profiles without interrupting traffic, requiring no reboot for a fixed-vCPU profile and a reboot when setting licensed vCPUs on a flexible profile. Multi-Model Enterprise License Agreement Provides a one- or three-year fixed-price token pool priced per model with no end-of-term true-up, bundling GlobalProtect, PAN-DB URL filtering, Threat Prevention, WildFire, DNS Security, support and unlimited Panorama with 1000-device management licenses. Online and Air-Gapped License Activation Activates a capacity license either by the firewall retrieving keys from the Palo Alto Networks update server or, for firewalls with no internet path, by exporting an authorization file, registering it against the auth code on the support portal and uploading the returned license key through the web interface. Service Provider End-Customer Attribution Links a provisioned firewall serial number to end-customer records covering reference ID, company, D-U-N-S number, contact, ISO country and subdivision codes and industry through the support portal or a reporting API, and searches all firewalls provisioned for a given customer. Service Provider Usage-Based Licensing Offers authorized cloud security service providers hourly, monthly, one-year and three-year usage packages combining a firewall model, a subscription bundle tier, premium or backline support and a high-availability option, supporting up to 10,000 firewall instances per package. Software NGFW Credit Pool Funds VM-Series and CN-Series firewalls, cloud-delivered security subscriptions and virtual Panorama from a single term-based credit pool bought for one to five years, refunding credits to the pool when a resource is deallocated and expiring both allocated and unallocated credits at term end. Support Account and Asset Registry Provides the customer support portal account that gates software downloads, credit management and support cases and holds the registry of owned appliances, licenses and subscriptions, with a role set spanning superuser, standard, limited, threat researcher and authorized support center variants that gates each licensing operation. Virtual Panorama Provisioning and Migration Provisions a credit-funded virtual Panorama from a deployment profile and migrates an existing enterprise-agreement or perpetual Panorama, standalone or high-availability pair, onto credit licensing while retaining serial numbers, logs and policies.
Packet Path & Interfaces Deterministic Interface Ordering and Disk Bus Selection Maps guest NICs to firewall interfaces by ascending PCI ID with the lowest becoming the management port, exposes the mapping through a debug command, and supports virtio, IDE or an attached virtio-SCSI controller as the virtual disk bus. DPDK Packet I/O Runs the dataplane on the Data Plane Development Kit for userspace packet processing, enabled by default on supported NIC drivers and instance types and switchable to the PacketMMAP path through a CLI setting or bootstrap parameter where a deployment mode requires it. Encapsulated Overlay Routing Performs a Layer 3 lookup on the inner header of encapsulated traffic so an inspected packet can leave by a different interface than it entered — egressing to an internet or NAT gateway on AWS and from the untrust interface under Google Cloud Network Security Integration — turning transparent insertion into a two-zone policy with its own routes and source NAT, set by CLI or bootstrap parameter. Expanded Data Interface Count Supports up to 20 data interfaces per instance on Hyper-V, raised from seven, on higher memory tiers so multiple zone-limited firewalls consolidate onto one instance. Hypervisor-Assigned MAC Addresses Uses the MAC address the host assigns to each interface in ARP responses so non-learning virtual switches forward traffic to the dataplane without promiscuous mode, enabled by default and not disableable on AWS and Azure, and replacing the floating virtual MAC of a high-availability pair with a gratuitous ARP on failover. IPv6 and Dual-Stack Support Handles IPv6 traffic on public cloud dataplane interfaces with dual-stack Layer 3 addressing, DHCPv6 client addressing, IPv6 static routes, session-based DSCP, NPTv6 prefix translation against a checksum-neutral address, GENEVE-encapsulated IPv6 behind a gateway load balancer, and IPv6 transport for the high-availability control and data links, the supported set differing per provider. Jumbo Frames Raises the default MTU for all Layer 3 interfaces to 9192 bytes with a global setting adjustable between 512 and 9216 and overridable per interface, enabled from the web interface or a bootstrap parameter, requiring a reboot and falling back to the PacketMMAP path on instances spanning multiple NUMA nodes. Link Aggregation with LACP Bundles multiple Ethernet interfaces into an IEEE 802.1AX aggregate group of up to 16 members in high-availability, virtual wire, Layer 2 or Layer 3 mode with LACP for load balancing, link-layer failure detection and failover to hot-spare interfaces. Management Interface Swap Reassigns the management role from the first network interface to the second through a CLI setting, bootstrap parameter, instance user data or Google Compute Engine metadata so a load balancer or public IP pre-bound to the first interface reaches the dataplane instead of the management plane, requiring at least two attached interfaces and a reboot to take effect. Multi-Queue NIC Support Parallelizes packet processing across vCPUs using multiple transmit and receive queues per interface with receive-side scaling, configured through host-side NIC feature flags on ESXi or virtio-net queue counts on KVM. NUMA Isolation and CPU Pinning Pins guest vCPUs to physical cores within a single NUMA node through libvirt CPU tuning on KVM or NUMA processor settings on Hyper-V and ESXi, and confines the dataplane to the vCPUs of node 0 through a VM-Series plugin setting enabled by CLI or bootstrap parameter that takes precedence over a custom dataplane core count, to remove cross-node memory latency from the packet path. Open vSwitch with DPDK Datapath Supports Open vSwitch with DPDK as an accelerated alternative to the Linux bridge for host-side switching on KVM. Software Cut-Through Session Offload Offloads eligible flows, including GTP-U inner sessions, to a shortened software datapath after Layer 7 inspection on hosts without a data processing unit, enabled by CLI or bootstrap and requiring at least six cores. SR-IOV and PCI Pass-Through Attaches dataplane interfaces directly to a physical NIC or an SR-IOV virtual function — including Azure accelerated networking and Google gVNIC on qualified instance families — bypassing the software bridge, across a tested matrix of Intel, Broadcom and Nvidia Mellanox adapters with paired host physical-function and guest virtual-function driver versions. Tap, Virtual Wire, Layer 2 and Layer 3 Interface Modes Deploys dataplane interfaces in tap, virtual wire, Layer 2 or Layer 3 mode subject to the host's MAC-assignment and promiscuous-mode settings, with SR-IOV-attached interfaces restricted to Layer 3 and high-availability use. VLAN Access Mode Switches all dataplane interfaces from the default VLAN trunk mode to untagged access mode on SR-IOV virtual functions so the firewall runs as a per-tenant network function and can apply QoS policy on the access interface. VPC Endpoint to Interface Association Binds each gateway load balancer VPC endpoint to a chosen interface or subinterface of the firewall through a CLI command, bootstrap parameter or instance user data, so endpoints in one VPC share consistent policy while endpoints in VPCs with overlapping addresses are separated onto different subinterfaces and zones.
Public Cloud Deployment Alibaba Cloud Deployment Runs as an Alibaba ECS instance from a marketplace image with a management network interface plus separately created untrust and trust interfaces across VPC virtual switches, on qualified general-purpose instance families under bring-your-own-license or enterprise-agreement terms. AWS Cloud WAN Integration Attaches the security VPC to an AWS Cloud WAN core network so segment and segment-sharing policy redirects traffic between VPCs, regions and on-premises sites to the firewall for inspection, either federating existing transit gateways through peering or replacing them entirely, with appliance mode on the security attachment preserving flow symmetry. AWS EC2 Deployment Launches the firewall as an EBS-optimized EC2 instance with up to eight Layer 3 interfaces — one management plus seven elastic network interfaces — and an elastic IP for persistent management access, with interfaces attached at launch rather than hot-added. AWS GovCloud, China and Outposts Deployment Deploys the same firewall feature set into AWS GovCloud, the Beijing and Ningxia regions under a separate China account, and onto on-premises AWS Outposts racks using region-specific images. AWS Machine Image Distribution Publishes marketplace AMIs under bring-your-own-license and two pay-as-you-go bundle product codes, provides a CLI filter query resolving the AMI ID for a given PAN-OS version and region, and supports building a private custom AMI pinned to a chosen version through a private-data reset. Azure Security Center Integration Registers with Azure Security Center as a partner security solution, deploying an instance from a Security Center recommendation with a default user-defined route and example inbound and outbound rules, discovering existing firewalls for connection, and surfacing Threat and WildFire Submission logs as Security Center alerts through a log forwarding profile or Common Event Format syslog. Azure Stack, Stack HCI and Stack Edge Deployment Deploys the firewall onto Microsoft's on-premises Azure platforms — Azure Stack through an ARM template with a NAT appliance fronting inbound traffic, Azure Stack HCI as a generation 1 guest inside an SDN fabric managed from Windows Admin Center, and Azure Stack Edge as a network function alongside Azure Private 5G Core with LAN and WAN interfaces mapped for RAN, GTP-U and perimeter inspection. Cloud Load Balancer Sandwich Registers firewall dataplane interfaces rather than the management interface as backend targets of provider load balancers with health-check listeners — external, internal, application-layer and route-mode across AWS, Azure, Google and IBM Cloud — so firewalls sit between the internet-facing and internal load balancers, with a loopback interface and management profile answering the health probes. Cloud NAT-Based Traffic Inspection Inspects inbound and outbound traffic between cloud subnets using destination NAT rules on the untrust interface and source NAT rules that force application-originated internet traffic back through the firewall. Custom Cloud Image Creation Builds a private machine image pinned to a chosen PAN-OS, plugin, content and antivirus version by upgrading a marketplace instance, deactivating its license, running a private-data reset and generalizing the stopped disk into an Azure managed image or a Google Compute Engine image, which can then be copied between regions and referenced from templates or CI pipelines. Google Cloud Platform Deployment Runs as a Google Compute Engine instance deployed from the Marketplace, the gcloud CLI or a custom Deployment Manager template, with each of up to eight interfaces attached to its own VPC network and subnet in a fixed management, untrust, trust order, an SSH public key supplying first login, and optional automatic creation of a Google firewall rule scoping management access. IBM Cloud Deployment Runs as an IBM Cloud Gen 2 VPC virtual server instance deployed from the IBM Cloud catalog through a Schematics Terraform workspace on qualified bx2 profiles in a defined set of regions, with up to five network interfaces and a floating IP address providing management access. Microsoft Azure Deployment Runs as an Azure Resource Manager virtual machine deployed from a marketplace solution template with one management and up to seven dataplane Layer 3 interfaces, on the public Azure cloud and on the Azure China, Government and Government DoD marketplaces that meet DoD Impact Level 5 and FedRAMP High, with managed disks for additional log storage and multiple public IPs per interface. Multi-Application NAT Onboarding Publishes several backend applications through one shared cloud load balancer by mapping each to a forwarding rule address or a named port and translating it to the application with a per-application destination NAT rule on the firewall, with a Terraform path for the load-balancer and firewall objects and an X-Forwarded-For setting that carries the original client address into policy and logs. Oracle Cloud Infrastructure Deployment Runs as an OCI compute instance launched from the Oracle Cloud Marketplace on qualified standard, optimized and AMD flexible shapes, with the management VNIC created at launch and further data VNICs attached afterward in an order the firewall preserves, an expandable boot volume, and initial configuration supplied as cloud-init user data. Supported Deployment Topologies Documents the topologies the firewall is deployed in across clouds — internet or VNet gateway for north-south traffic, segmentation gateway and inter-subnet inspection for east-west traffic, hybrid and network-to-network connectivity terminating IPSec or ExpressRoute, and GlobalProtect gateway and large-scale VPN roles that extend gateway policy to remote users in regions with no hardware. Tencent Cloud Deployment Runs on Tencent Cloud China by uploading the qcow2 image to object storage, force-importing it as a custom image and launching an instance with management, untrust and trust elastic network interfaces, supporting inbound and outbound north-south inspection only.
Automation & APIs Autoscale Application Onboarding Brings an application behind an autoscaled firewall deployment under policy without redeployment — by Pub/Sub message or sample template on Google Cloud, by polling labelled Kubernetes services in GKE, or by a frontend protection entry on Azure — after which the plugin programs the load balancer, NAT rules, address and service objects and routes, reporting each as protected or not with a reason. AWS Warm Pool Integration Keeps pre-initialized firewall instances in an AWS auto scaling group warm pool so a scale-out event brings one into service in under 90 seconds instead of 15 to 20 minutes, using launch and terminate lifecycle hooks with heartbeat timeouts, an instance role scoped to the auto scaling and logging APIs, consuming credits only on transition to service and streaming transition logs to CloudWatch. Cloud Auto Scaling Scales a firewall fleet against a chosen PAN-OS metric — active sessions, session utilization, dataplane CPU or packet buffer use — using an AWS auto scaling group, an Azure virtual machine scale set driven by the Panorama plugin, or a Google managed instance group, attaching interfaces, registering on Panorama and licensing each instance as it joins, and reversing that as it leaves. Cloud Deployment Templates Publishes infrastructure-as-code templates that stand up the firewall together with its networks, subnets, interfaces, security groups, routes and load balancers — Azure Resource Manager, AWS CloudFormation, Google Deployment Manager and IBM Cloud Schematics stacks plus community Terraform plans — under either the official or a community support policy. First-Boot Bootstrap Provisioning Reads an init-cfg.txt and optional bootstrap.xml at first boot from attached or cloud storage, instance user data or metadata, a secrets-manager secret or vApp properties, in a package of config, license, software, content and plugin folders — setting hostname, management networking, DNS, Panorama or Strata Cloud Manager registration, licensing and operating mode without console interaction. Licensing API Key Management Issues a per-support-account licensing API key that PAN-OS installs by CLI and requires for online deactivation, propagates from Panorama to managed devices, and can be regenerated to invalidate the previous key or disabled entirely. Model-Based Licensing API Exposes activate, deactivate and usage-lookup endpoints taking UUID, CPU ID, auth code, memory, vCPU count and serial number and returning license keys as JSON, so firewalls with no path to the licensing server can be licensed by script or orchestration. NSX Automated License Distribution Licenses NSX-deployed firewalls automatically by having Panorama retrieve licenses from the update server against the service definition's bundled auth code as each firewall boots and connects, with a manual CPU ID and UUID path when Panorama is offline and an evaluation code covering a small fleet for a fixed period. OpenStack Heat Orchestration Templates Publishes Heat orchestration templates that instantiate the firewall together with its networks, subnets, ports, security groups and floating IPs in basic gateway, service chaining and service scaling topologies. Panorama Cloud Plugin Management Installs and upgrades the per-platform Panorama plugins for AWS, Azure, Google Cloud, IBM Cloud, OCI, Nutanix, Kubernetes and software firewall licensing, requiring a matching version on each peer of a Panorama high-availability pair, a reboot when a second plugin is added, and an unblock command that stops an unconfigured plugin from withholding IP-tag pushes to managed firewalls. Panorama Software Firewall License Plugin Uses bootstrap definitions and license managers in a Panorama plugin to license and delicense firewalls automatically as they connect to Panorama, covering autoscaling environments and firewalls with no path to the licensing server, and excluding pay-as-you-go and NSX-T firewalls. Panorama-Orchestrated Cloud Deployment Builds and manages a security VPC or VNet from Panorama — subnets, route tables, NAT and gateway load balancers, firewall instances or scale sets, plus device groups, template stacks and NAT policy — as hub and inbound stacks with scale bounds and autoscale thresholds, then watches transit gateway attachments and rewrites routes for inbound, outbound, east-west and cross-account flows. Simplified Onboarding Deploys a production-ready reference architecture in one pass on AWS and Azure, allocating public addresses and preconfiguring interfaces, zones, virtual routers, static routes, outbound NAT and default security rules through a single bootstrap flag, with a choice of common, dedicated-inbound, dedicated-outbound or split firewall sets. Software NGFW Credits API Provides OAuth 2.0-secured create, read, update and delete operations over credit pools and deployment profiles, listing firewall serial numbers by auth code and deactivating firewalls by serial number. VM-Series Plugin Ships a built-in plugin that carries the firewall's cloud and hypervisor integrations — metric publishing, bootstrapping, credential provisioning and cloud library updates — and can be upgraded or downgraded independently of PAN-OS from the firewall, from a bootstrap package, or centrally from Panorama, with each PAN-OS release pinning a corresponding minimum version.
SDN Service Insertion Cisco ACI Multi-Context Mapping Presents each virtual system on a multi-vsys firewall to Cisco ACI as an individually managed firewall by configuring a chassis manager in the tenant and assigning it to the firewall service. Cisco ACI Service Insertion Inserts the firewall or a high-availability pair into a Cisco ACI fabric as an unmanaged Layer 4 to Layer 7 device cluster redirected by an APIC policy-based redirect keyed to the firewall interface IP and MAC and applied through service graph templates on endpoint group contracts, covering east-west traffic in one-arm Layer 3 mode and north-south traffic through an L3Out with OSPF peering. Gateway Load Balancer Transparent Insertion Terminates GENEVE-encapsulated traffic from AWS and Alibaba gateway load balancers and VXLAN traffic from an Azure one in a centralized security VPC or VNet, registering dataplane interfaces as backend targets behind a gateway load balancer endpoint so inspected traffic returns with original addressing and flow intact; tunnel ports and VNIs map to trust and untrust subinterfaces. Google Cloud Network Security Integration Registers the firewall as the producer of a Google Cloud Network Security Integration service so consumer VPC firewall policies steer traffic through intercept endpoint and deployment groups to an internal load balancer, delivering it GENEVE-encapsulated for inline inspection or mirrored copies for out-of-band analysis, with the security profile group and VPC identity carried in the encapsulation. NSX-T East-West Micro-Segmentation Deploys firewall instances either clustered on a single service cluster with a chosen instance count or one per ESXi host, attached to an overlay service segment with an NSX-T service health check driving instance failover, so traffic between guest virtual machines inside the data centre is inspected. NSX-T North-South Router Insertion Attaches firewall instances in virtual wire mode to a tier-0 or tier-1 logical router as standalone or high-availability edge-node pairs, with a configurable allow or block failure policy governing traffic when the firewall is unavailable. NSX-T Partner Service Insertion Registers the firewall with VMware NSX-T Manager as a partner security service so NSX-T deploys firewall instances from a referenced base image and attaches them to receive traffic redirected by the hypervisor virtual switch. NSX-T Service Chaining Places the firewall's service profile into an ordered NSX-T service chain with forward and inverse reverse paths, optionally sequenced alongside other partner service profiles, under an allow or block failure policy. NSX-T Traffic Redirection Rules Creates NSX-T network introspection policies that redirect selected source and destination groups and services to the firewall's service chain or service instance, applied to the distributed firewall or to specific groups, with stateless reflexive return rules on the north-south path. NSX-V to NSX-T Migration Carries an existing NSX-V deployment onto NSX-T either by sharing device groups and adding NSX-T tags to existing dynamic address groups so both platforms run in parallel, or by an in-place migration that imports the NSX-V configuration and maps its service profiles to NSX-T equivalents. OpenStack Service Chaining and Scaling Deploys the firewall as a Contrail service instance inside a virtual wire or Layer 3 service chain and adds or removes instances automatically against Ceilometer CPU-utilization or throughput thresholds. Operations-Centric and Security-Centric NSX-T Workflows Offers two NSX-T deployment models — one splitting configuration between Panorama and NSX-T Manager, and one driving service chains and steering entirely from Panorama — with a documented path to convert an existing deployment from the first to the second. Panorama-Generated NSX-T Steering Policy Generates NSX-T steering policy and steering rules on Panorama from intrazone security rules in the pre- or post-rulebase and pushes them to NSX-T Manager with TCP-strict and failure-policy settings, so redirection is configured without touching NSX-T Manager.
Capacity & Sizing ARM Architecture Support Runs on ARM-based hosts — Linux KVM servers and AWS Graviton 2 and 3 instance families — at feature parity with x86 including accelerated packet I/O, licensed through flexible credits. CPU Oversubscription Runs multiple firewall instances per physical core at ratios from 2:1 to 5:1 on all models with no configuration, so a single host can carry tens of instances. Dataplane Core Customization Reallocates cores between the management plane and the dataplane on credit-licensed firewalls through a bootstrap parameter or CLI command without changing the deployment profile or credit consumption, unsupported on NSX-T and with intelligent traffic offload. Fixed Model Capacity Tiers Ships seven fixed models from VM-50 to VM-1000-HV built from a single common software image, where applying the capacity license activates that model's fixed session, rule, zone and tunnel limits. Flexible vCPU Sizing Licenses a chosen subset of the host instance's vCPUs through a bootstrap parameter or CLI command so a larger compute instance consumes only the intended credits, taking effect after a reboot. Log Storage Expansion Accepts an additional virtual disk of 60 GB to 2 TB that PAN-OS initializes on boot and migrates existing logs onto, supplementing the 60 GB system disk whose log partition is otherwise fixed. Memory-Tier Capacity Limits Groups allocated memory into four tiers from 4.5 GB through 128 GB that set per-firewall maximums for sessions, policy rules, zones, objects, VPN tunnels and virtual systems, published separately for each PAN-OS release. Multiple Virtual Systems Divides one firewall into independently managed logical firewalls with separated traffic and administration, licensed one by default and extended by a virtual system license bought through the deployment profile, enabled from the web interface, from Panorama or by bootstrap parameter, and capped at 25 systems on tier 3 and 100 on tier 4 instances. Qualified Cloud Instance Types Publishes, per PAN-OS release, which cloud instance families, sizes and shapes each licensing bundle and model runs on together with their vCPU, memory, bandwidth and maximum interface counts, where a bundle image unlocks itself to the largest model the instance supports and a model launched on an undersized instance boots into maintenance mode. Virtual Metadata Collector Mode Runs the firewall in a reduced sub-mode dedicated to IoT metadata collection, selected by a bootstrap operating mode on ESXi and KVM, which fixes a non-editable allow-all policy with default profiles, rejects IoT policy recommendations, and requires Panorama for management. VM-50 Lite Mode Runs the smallest model in a reduced-footprint mode at 4.5 GB rather than 5.5 GB of memory, dropping jumbo frame and WildFire inline machine learning support, and requires both high-availability peers to match. ZRAM Compressed Swap Creates a compressed in-RAM block device used as swap on firewalls hitting low-memory conditions, enabled by CLI against a host memory threshold and a reboot, with runtime commands reporting module state, memory limit and compression ratio.
High Availability Alibaba Active/Passive High Availability Pairs two firewalls with configuration and session sync, binding untrust and trust interfaces to external and internal Alibaba high-availability virtual IPs that follow gratuitous ARP to the active peer, failing over in roughly eleven seconds within a single availability zone. AWS Active/Passive High Availability Runs a firewall pair that fails over either by moving secondary IPv4 addresses and rewriting route tables or by detaching and reattaching dataplane network interfaces, using the management port for the control link and a dataplane port for session sync, authorized by an attached IAM role, with a documented migration path between the two modes. Azure Active/Passive High Availability Pairs two firewalls in one Azure resource group with a dedicated HA2 data link, failing over either by moving a secondary IP configuration carrying the floating public and private addresses to the new active peer for north-south traffic, or by rewriting user-defined routes to the peer's primary addresses for east-west traffic only, and supports peers in separate availability zones. Azure Health Monitoring and Remediation Runs a daemon that watches Azure scheduled freeze and interface hotplug events and firewall states such as downed dataplane links, missing DHCP addresses, licensing, certificate and Panorama connection failures and disabled accelerated networking, then logs them to syslog or, when auto-remediation is set at deployment, fails an active peer over or drops the load balancer health probe. Google Cloud Active/Passive High Availability Pairs two firewalls in unmanaged instance groups in separate zones of one region with configuration and session synchronization over a dedicated HA2 interface, where external and internal pass-through load balancer health checks decide the active peer and connection tracking carries live sessions across a failover completing in roughly three seconds. IBM Cloud Active/Active Resiliency Runs firewalls active/active behind an IBM Cloud route-mode network load balancer sharing a data subnet, with IP spoofing enabled on the data interface, ingress and egress custom routes steering application traffic through the load balancer, and custom routes updated automatically when the load balancer fails over between its own nodes. OCI Active/Passive High Availability Pairs two firewalls with secondary floating private addresses on the untrust and trust VNICs and a dedicated HA2 VNIC, authorizing the move through an OCI dynamic group matched on the peer instance OCIDs and a policy over the virtual-network and instance families, with security-list ingress rules opened for the HA control and data ports and support in FIPS mode. SD-WAN Interface Floating IP Failover Assigns up to four IPv4 addresses per SD-WAN interface with a second floating address matched between external and internal zones to achieve active/passive failover in a public cloud. Session Resiliency Across a Firewall Cluster Synchronizes session state to an external Redis cache — Amazon ElastiCache or Google Memorystore, with in-transit encryption — so when a load balancer deregisters an unhealthy firewall it rehashes existing flows onto a healthy peer that resumes forwarding them, enabled only at bootstrap with an endpoint, auth code and optional CA certificate, and capping the firewall's maximum sessions. vMotion Heartbeat Pause Suspends the firewall's internal heartbeat monitoring for up to 60 minutes through a CLI command so traffic keeps flowing while vMotion moves the firewall between ESXi hosts with matching CPUs, unnecessary from vSphere 7.0 onward.
Private Cloud Deployment Cisco Cloud Services Platform Deployment Runs as a network virtual service on the Cisco CSP KVM platform from the qcow2 base image with a bootstrap package supplied as a day-zero configuration ISO, standalone or as a high-availability pair, on all models except VM-50 and with up to ten virtual NICs. Cisco ENCS Branch VNF Deployment Packages the qcow2 image into a Cisco ENCS bundle through the NFVIS interface or the image-packaging utility with an embedded bootstrap configuration, auth codes and per-model resource profiles, then deploys it from the NFVIS life-cycle manager as a virtual wire, Layer 2 or Layer 3 firewall with up to eight virtio data interfaces. KVM and Linux Deployment Runs as a libvirt and QEMU guest on a Linux KVM host from a qcow2 image, installable through virt-manager, virt-install or virsh with a hand-authored domain XML on Red Hat Enterprise Linux, CentOS and Ubuntu hosts. Microsoft Hyper-V Deployment Runs as a generation 1 guest on standalone Hyper-V or the Windows Server Hyper-V role from a VHDX image, provisioned through either Hyper-V Manager or PowerShell cmdlets, and supports Linux Integration Services so the host can display the management IP, monitor heartbeat and shut the firewall down gracefully. Nutanix AHV Deployment Runs on the Nutanix Acropolis hypervisor under either pay-as-you-go or bring-your-own-license terms. OpenStack Deployment Runs as a Nova instance on OpenStack with a management interface and two data interfaces attached to tenant networks, receiving its initial configuration through user data and personality files. VMware Tools Integration Ships VMware Tools inside the firewall and Panorama images so vCenter and vCloud Director can display the management IP and software version, report disk, memory and CPU utilization, trigger alarms such as missed heartbeats, and power off or restart the appliance gracefully. VMware vCloud Air Deployment Deploys into an on-demand or dedicated virtual data centre by importing the OVF into the organization catalog and adding it to a vApp alongside the workloads it protects, reachable through NAT rules on the vCloud Air edge gateway and supporting active/passive high availability. VMware vSphere and ESXi Deployment Runs as a guest virtual machine on a standalone or vCenter-managed ESXi host from a signed OVA with one management and up to nine data virtual NICs on vmxnet3 drivers, deployable one firewall per host, per virtual network, or in a hybrid physical and virtual topology.
Workload Context & Tagging AWS Resource Monitoring Collects predefined and user-defined AWS instance attributes as tags for dynamic address groups, either directly on the firewall through a VM information source covering a small number of VPCs or through the Panorama AWS plugin polling up to 1000 VPCs and registering the mappings to device groups. AWS Shared VPC Cross-Account Monitoring Registers multiple monitoring definitions against the same shared VPC with different cross-account IAM role ARNs so IP-to-tag data from each participating AWS account is collected and routed to per-account or shared notify groups. Azure Resource Monitoring Polls up to 500 Azure subscriptions through the Panorama plugin and converts virtual machine, load balancer, subnet and VNet metadata plus Azure service tags into eleven predefined and up to twenty-one user-defined IP tags per resource, pushing up to 8000 mappings to the device groups in a notify group as dynamic address group match criteria, retained if the subscription is lost. Cisco ACI Endpoint Monitoring Connects to up to 16 APIC clusters and converts fabric endpoint data into hierarchical tags spanning cluster, tenant, application profile, endpoint group, micro-endpoint group, external endpoint and bridge-domain subnet for dynamic address group membership, scaling to 20,000 endpoints and retaining IP-tag enforcement on firewalls when Panorama loses APIC connectivity. Google Cloud Resource Monitoring Collects internal and external addresses and tags from Compute Engine instances on the firewall through a VM information source or through the Panorama plugin with per-project service account credentials, converting eight predefined attributes plus up to sixteen user-defined labels and eight network tags into IP-to-tag mappings, and onboarding service projects from a shared VPC host project. Kubernetes Service Monitoring Connects Panorama to an Azure Kubernetes Service or Google Kubernetes Engine cluster with a service-account token scoped by a cluster role, harvests services exposed through an internal load balancer, and generates per-service, per-label and label-selector IP tags for dynamic address groups so inbound traffic to cluster services is matched by policy while outbound cluster traffic is monitored. NSX-T Dynamic Address Group Sync Maps Panorama dynamic address groups to NSX-T security groups in both directions, importing NSX-T group tags as match criteria or creating NSX-T security groups from prefixed match criteria, so IP membership updates as guest virtual machines change. Nutanix Prism Monitoring Polls Nutanix Prism Central on an interval and converts its categories, values and clusters into IP tags that feed dynamic address groups used as security policy match criteria. vCenter VM Monitoring Polls up to 16 vCenter instances on a configurable interval for guest IP addresses through VMware Tools and converts the vCenter hierarchy into tags — virtual machine name, guest operating system, annotation, VLAN ID, host IP and user-defined tags — that Panorama pushes to notify groups as dynamic address group match criteria.
Monitoring & Logging Azure Application Insights Metrics Publishes native PAN-OS metrics to an Azure Application Insights instance at a one- to sixty-minute interval using an instrumentation key, logging each authentication attempt, and supports migrating a classic instance onto a log analytics workspace as the deployment requires. Cisco ACI Dashboard in Panorama Displays a two-level tiled dashboard counting monitored tenants, application profiles, endpoint groups, bridge domains and service graphs alongside their associated dynamic address groups, whether each is used in pre-rule security policy, and which firewalls are inline with each service graph. CloudWatch Metrics Publishing Publishes native PAN-OS metrics to a configurable CloudWatch namespace at a one- to sixty-minute interval and creates a dimensions namespace for per-firewall filtering by hostname and instance ID so alarms and autoscaling policies can act on them. ENA Network Performance Metrics Publishes Elastic Network Adapter bandwidth and packets-per-second allowance metrics to CloudWatch every five minutes, disabled by default and toggled by CLI, bootstrap parameter or the web interface. Google Cloud Monitoring Metrics Publishes custom PAN-OS metrics to Google Cloud Monitoring at a one- to sixty-minute interval using the instance default service account or an explicit service account with the metric writer role, so they can be explored and used to trigger alerts and autoscaling. OCI Kafka Log Streaming Streams traffic, threat and URL logs into a managed OCI Kafka cluster by forwarding each log type to a local high-numbered syslog port that an on-box engine parses into a structured JSON payload and delivers to a per-type topic over mutual TLS, with commands to map log types to ports and to verify delivery counts and certificate state. OCI Kafka Metric Forwarding Pushes data flow, system, customer and App-ID metrics with instance, compartment and version metadata directly from the firewall to a managed OCI Kafka topic over mutual TLS instead of being polled, with CLI commands to define the broker, topic and client certificate and to inspect pipeline statistics, log level and broker and handshake health. Startup and Health Logging Emits leveled boot and system-health messages with per-event message IDs to the serial console and to a per-instance CloudWatch log stream under a shared log group, with optional periodic health messages.
Central Management & Policy Centralized Security Policy Push Authors App-ID-based security rules using dynamic or static address groups with antivirus, anti-spyware and vulnerability profiles in Panorama device groups and pushes them to the managed firewalls, including force-template-values commits. NSX Group Membership Criteria Authoring Defines up to five criteria of five rules each per dynamic address group in the Panorama NSX plugin, matching virtual machines or IP sets on tag, name, operating system or computer name with equality, contains, starts-with and ends-with operators, and pushes them to NSX-T Manager as security groups. NSX Service Definitions Defines up to 32 service definitions on Panorama, each binding a device group, template stack, base-image URL, insertion type, notify group, auth code and device certificate, pushes them to NSX-T Manager, and deletes them along with their dependent steering rules, policy and membership criteria. PAN-OS Software Upgrade and Downgrade Upgrades PAN-OS on a standalone firewall, across an HA pair one peer at a time with preemption disabled, or across a managed fleet from Panorama, gating each on the minimum content release, plugin version and allocated memory, with a non-disruptive path for NSX deployments that migrates guests between hosts and a downgrade path that reloads the configuration autosaved at upgrade. Panorama NSX Plugin Connection Installs a Panorama plugin that maintains bidirectional API communication with up to 16 NSX-T Managers, reports registered and out-of-sync status, works across a Panorama high-availability pair, allows proxy bypass, and offers a configuration-sync action to reconcile drift. Strata Cloud Manager Management Associates a deployment profile with a Strata Cloud Manager tenant and region to manage firewalls directly or alongside Panorama, provisioning IoT, SaaS inline, Strata Cloud Manager Pro and Strata Logging Service entitlements and adding new firewall serial numbers to the tenant service group as their auth code checks in. Template Stacks and Device Groups Manages deployed firewalls through Panorama device group hierarchies plus template stacks that supply the virtual wire, interface, zone, DNS and NTP configuration each firewall boots with.
Certificates & Data Protection Cloud IAM Role Authorization Authorizes firewall and Panorama cloud API calls — address failover, route-table rewrites, workload monitoring, secret retrieval and orchestrated deployment — through an attached or assumed AWS role, an Azure service principal or managed identity, a Google service account, or an OCI dynamic group and policy, each with a minimum permission set, rather than stored long-term credentials. Device Certificate Fetches site license entitlements and authenticates the firewall to cloud services using a device certificate obtained through a support-portal one-time password, an autoregistration PIN embedded in a bootstrap package or NSX-T service definition, or a Panorama push to managed firewalls. Encrypted Boot Volume Encrypts the firewall's root storage volume at instance creation with a provider-default or customer-managed key management service key, on any supported instance type and from marketplace or custom images. Secrets Manager Certificate Retrieval Retrieves PEM certificates and private keys from AWS Secrets Manager or the Azure Key Vault certificate store at commit and boot using the instance IAM role or managed identity rather than storing private keys on firewall disk, making them available for decryption and IPSec including on autoscaled instances, and refetching them after a master key change. Secure Boot and vTPM Boots under UEFI with cryptographically verified boot components, a virtual trusted platform module and integrity monitoring on Google Compute Engine instances created with those options, available only on fresh installations and requiring secure boot to be turned off before a downgrade.