docsignal

Palo Alto Networks products and featurespaloaltonetworks.com

37 more productsShow fewer

Inline detection of evasive exploits, malware and C2 traffic.

Signature-Based Prevention

Custom Signatures

Threat Monitoring & Reporting

Inline Cloud Analysis

Cloud Service Connectivity

Threat Intelligence

Security Profiles & Policy

DNS Threat Detection

Licensing & Activation

Service Regions & Compliance

Inline classification and blocking of malicious and risky web destinations.

Web Access Policy

Monitoring & Reporting

URL Categorization

Cloud Service Connectivity

PAN-DB Private Cloud

Credential Phishing Prevention

Diagnostics

Inline Threat Analysis

Licensing & Content Updates

Response Pages

Cloud malware analysis and sandboxing feeding the inline services.

Analysis Engines

Appliance Clustering

Data Residency & Protection

Logging & Reporting

Sample Submission

Appliance Administration

Verdicts & Signatures

Access & Credentials

WildFire API

Service Connectivity

Inline Enforcement

Subscriptions & Licensing

Visibility and control over employee use of third-party AI applications.

Access policy control

GenAI app discovery

Licensing and activation

Usage insights and reporting

Data protection and compliance

App classification

Deployment and connectivity

Platform administration

Security recommendations

Digital experience monitoring across the SASE path.

Agents & Deployment

Experience Dashboards

Synthetic Monitoring

AI Troubleshooting

Real User Monitoring

Scoring & Root Cause

Administration & Access

End User Self-Serve

Collaboration App Telemetry

Telemetry Governance

Programmatic Access

The next-generation firewall delivered as a managed AWS service.

Firewall deployment & networking

Threat prevention services

Panorama management

Logging & monitoring

Licensing & credits

Native rulestack policy

Onboarding & compliance

Strata Cloud Manager management

Automation & APIs

Tenant access control

The next-generation firewall delivered as a managed Azure service.

Firewall deployment & networking

Threat prevention services

Panorama management

Logging & monitoring

Native rulestack policy

Licensing & credits

Onboarding & compliance

Strata Cloud Manager management

Automation & APIs

Tenant access control

The containerised firewall for Kubernetes environments.

Panorama management and policy

Threat prevention

Cluster network integration

Deployment tooling

Licensing and credits

Deployment modes

Scaling and throughput

Certificates and cluster authentication

High availability

Kubernetes context discovery

Lifecycle and diagnostics

Logging

The agentic automation layer — AI agents that plan and execute security workflows across the Cortex platform, with their own API and gateway.

Platform Administration

Investigation and Response

Automation and Playbooks

Cases and Issues

Threat Intelligence

Dashboards and Reporting

Data Sources and Connectors

Agentic AI

Query and XQL

Data Management

Engines

Marketplace and Content

The detection content shipped to the analytics engine — new and updated alerts, models and correlation rules, published per release date.

Detection coverage

Content lifecycle

Detection logic

Content releases

Detector catalog

Severity model

Application security posture — code, pipeline and supply-chain risk taken from version-control, CI and registry data sources and traced through to the running cloud resource.

Data Source Onboarding

Applications & Asset Inventory

Risk Prioritization & Remediation

Code Security Scanners

Policy & Rule Governance

Software Supply Chain Security

Third-Party Findings Ingestion

Developer Workflow Integration

Scan Execution & Health

Code-to-Cloud Traceability

Compliance Mapping & Reporting

Programmatic Administration

Cloud and Kubernetes security posture — configuration, identity and compliance risk across cloud accounts and clusters, including the Kubernetes connector.

Cloud Environment Onboarding

Asset Inventory & Lineage

Cases & Issues

Data Sources & Ingestion

Automation & Extensibility

Query & AI Assistance

SaaS, Identity & Data Posture

Posture Rules & Policies

Attack Surface & Exposure

Dashboards & Reporting

Vulnerability & Risk Prioritization

Compliance Management

Runtime detection and response for cloud workloads — hosts, containers and serverless — including the agent, runtime policy and cloud incident handling.

Asset inventory, exposure and vulnerabilities

Cases, investigation and response

Automation, playbooks and content

Workload and endpoint protection

Data sources, connectors and collectors

SaaS, data, identity and API security

Access control and tenant administration

Detection, analytics and threat intelligence

Onboarding and cloud connections

Query, dashboards and reporting

Security rules, policies and compliance

AI assistants and agents

Discovery and protection of sensitive data across SaaS applications and cloud stores, with its own connector set for the vendor systems it ingests from.

Platform administration

Dashboards and reporting

Data collection infrastructure

Data discovery and classification

Cloud onboarding

Data sources and connectors

Data security posture

Agentic AI assistant

Data detection and response

Data management and storage

Data access governance

Search and query

Extended detection and response across endpoint, network and cloud telemetry — incidents, causality analysis and response actions — as documented for the 3.x console.

Incident Investigation & Response

Threat Detection

Collection Infrastructure

Data Ingestion & Management

Endpoint Agent Management

Endpoint Protection

Tenant Onboarding & Administration

Search & Query

Asset Management

Access Management

APIs & External Services

Dashboards & Reporting

The 5.x generation of extended detection and response, documented in its own space with its own API and release notes, and reached from 3.x through a separate upgrade guide.

Data Ingestion & Collectors

Case Investigation & Response

Asset, Exposure & Compliance

Cloud & Application Security

Tenant Setup & Administration

Endpoint & Email Protection

Detection & Threat Intelligence

Automation & Content

Developer & API Platform

Query & Reporting

Endpoint Agent Management

Agentic AI Assistant

The endpoint agent that collects telemetry for and enforces protection from Cortex XDR and XSIAM, across Windows, Linux, macOS, iOS and Android.

Mobile Threat Protection

Agent Installation & Deployment

Endpoint Threat Prevention

Mobile App Deployment

Virtual & Container Endpoints

Agent Operations & CLI

Endpoint Agent Console

Platform Support & Lifecycle

Agent Upgrade & Content

Diagnostics & Support

The detection-content stream shipped to XDR outside the product release train — new and changed analytics, modules and detectors, published per content version.

Malware Protection Content

Exploit Protection Content

Content Release Stream

Agent Runtime Compatibility

Attack surface management — Expander discovers, attributes and monitors an organisation's internet-facing assets and raises incidents on the risky ones.

Access & Tenant Administration

Asset Inventory

Active Response Automation

Attack Surface Rules, Alerts & Incidents

Attack Surface Testing

Data Collection & Integrations

Discovery & Attribution

Remote Engines

Asset Organization & Scoping

Dashboards & Reporting

Risk Prioritization

The SOC platform that unifies detection, investigation, response, endpoint security and cloud security on one data layer, with XQL as its query language and its own analytics and automation engines.

Cloud Security

Investigation & Response

Platform Administration

Data Ingestion & Connectors

Exposure & Asset Management

Endpoint Security

Detection & Analytics

Query, Dashboards & Reporting

APIs & Developer Tooling

Automation & Orchestration

Agentic AI

Data Management

The previous XSOAR architecture, documented as separate administrator, installation, multi-tenant and threat-intel-management guides per 6.x version.

Threat intelligence management

Deployment and installation

System administration

Playbooks and automation

Incident configuration

Incident response

Multi-tenant management

Users, roles and authentication

Marketplace and content management

Engines and container runtime

Dashboards and reporting

Integrations and credentials

The customer-hosted edition of XSOAR 8, adding cluster installation, node and engine operation, and upgrade paths the SaaS edition does not document.

Threat intelligence management

Playbooks and automation

System administration

Incident configuration

Incident response

Deployment and installation

Integrations and credentials

Multi-tenant management

Marketplace and content management

Engines and remote execution

Users, roles and authentication

Dashboards and reporting

Security orchestration, automation and response — playbooks, incident management, integrations and the automation engine — as run by Palo Alto in its own cloud.

Threat intelligence management

System administration

Incident response

Playbooks and automation

Incident configuration

Engines and remote execution

Onboarding and tenant deployment

Multi-tenant management

Marketplace and content management

Integrations and credentials

Dashboards and reporting

Users, roles and authentication

Application Security

Identity & Access

Licensing & Entitlement

Product & App Administration

Vulnerability Management

Data Collection & Forwarding

Detection & Response

Posture & Compliance

Cloud Onboarding

Data Query & Analytics

Federated Identity

Tenant Lifecycle

Automation & Orchestration

Case & Issue Management

Platform Access

Asset Management

Operational Visibility

A cloud-delivered service detecting and blocking DNS-layer threats.

DNS Policy Enforcement

Domain Lists & Overrides

Service Connectivity & Tuning

Inspection Delivery

Logging & Visibility

Signature & Domain Intelligence

Threat Detection Engines

Licensing & Activation

Encrypted DNS

Resolver Administration

Configuration API

Data loss prevention applied inline across network and SaaS traffic.

Detection Methods

Data Profiles

Ecosystem Integrations

Incident Management & Logging

Policy & Enforcement

Data Risk & Discovery

Endpoint DLP

Evidence & Configuration Portability

Licensing & Activation

Service Connectivity & Limits

Email DLP

End User Coaching

The endpoint agent providing VPN and always-on secure connectivity.

User Authentication

Secure Connectivity

App Deployment & Management

Portal & Gateway Infrastructure

Traffic Policy Enforcement

Endpoint Posture

End-User App Experience

Monitoring & Troubleshooting

Clientless Access

Traffic Steering

Licensing & Activation

Discovery, identification and policy for unmanaged and IoT devices.

Third-Party Integrations

Asset Discovery & Inventory

Risk, Vulnerability & Compliance

Deployment & Data Collection

Network & Site Organization

Dashboards & Reports

Threat Detection & Alerts

Licensing, Activation & Onboarding

Policy Recommendations & Enforcement

Users & Access Control

Queries & Filters

Automation & Action Center

Palo Alto's core network security platform — the PA-Series hardware, software firewalls and the PAN-OS operating system they run, documented together as the current NGFW surface.

Networking, Routing and VPN

Platform Operations and Maintenance

Monitoring, Logging and Reporting

Threat Prevention and Security Profiles

Authentication and Certificate Management

Security Policy and Objects

High Availability and Clustering

User and Device Identification

Application Identification (App-ID)

Administrative Access and Multi-tenancy

Automation, API and CLI

Decryption and TLS Inspection

The firewall operating system, documented as per-version administration guides separate from the current NGFW tree.

Networking & Traffic Delivery

Device Setup & Configuration Operations

Security Policy & Enforcement

Authentication & User Identity

Monitoring, Logging & Reporting

Threat Prevention & Content Inspection

Decryption

Certificates & Keys

Administrative Access & Roles

App-ID Application Identification

High Availability

Licensing & Subscriptions

Central management for firewalls, policies and logs across a fleet.

Centralized Configuration

Appliance Operations & Diagnostics

Log Collection Infrastructure

Administrative Access

Commit & Push Control

Plugins & Integrations

Visibility & Reporting

Configuration Backup & Audit

Managed Device Lifecycle

Device Trust & Keys

Licensing & Update Deployment

Panorama High Availability

Cloud-delivered secure access (SASE) for remote users and branches.

Mobile User Access

Identity, Authentication & Compliance Posture

Network & Traffic Services

Security Policy & Threat Prevention

Branch & Site Connectivity

Private Application Connectivity

Monitoring, Logging & Digital Experience

Licensing, Activation & Onboarding

Service Lifecycle & Operations

Tenancy & Administrative Control

APIs & Automation

Web Application & API Security

The secure enterprise browser acquired with Talon.

Client platform & customization

Visibility & analytics

Data protection controls

Integrations

Policy engine & policy objects

Threat protection

Identity, credentials & session

Device posture & remediation

Application access & connectivity

Browser hardening

Browser extension governance

Onboarding & licensing

The next-generation mobile access agent for Prisma Access and NGFW deployments — agent lifecycle, tunnel behaviour and gateway selection on the endpoint.

User Authentication

Traffic Forwarding

Agent Deployment

Monitoring & Diagnostics

End-User App Experience

Endpoint Posture

Service Infrastructure

Tunnel Connectivity

Agent Fleet Management

Agent Integrity & Enforcement

Agent Configuration

Licensing & Activation

AI runtime security — inspection and policy for AI applications, models and agent traffic.

AI Red Teaming

Firewall Deployment & Lifecycle

AI Threat Detection

AI Model Security

Security Policy & Access Control

Logging & Monitoring

Discovery & Inventory

API Intercept & Developer Surface

Traffic Interception

Licensing & Tenant Administration

Scale & Availability

Platform Integrations

Software-defined WAN built on the ION appliance family.

Sites & Connectivity

Monitoring & Analytics

Traffic Policy

Device Lifecycle

Routing & Segmentation

Administrator Access & Audit

Device CLI & APIs

Integrations & CloudBlades

Platform Security & Compliance

Branch Security Policy

Licensing & Tenancy

Resiliency & Recovery

Threat Prevention & Device Identification

AI Assistance

CASB — discovery, posture and inline control for SaaS applications.

Incidents & Remediation

Posture Management

Visibility & Reporting

App & Directory Connectors

User Behavior Analytics

Inline Policy Enforcement

Data Discovery & Classification

Logging & SIEM/SOAR Integration

Administration & Access Control

Data Security Policy

Licensing & Activation

Service Connectivity

Content Threat Analysis

The unified management plane for the network security platform, covering both NGFW and SASE deployments.

Configuration Management

Visibility & Insights

Security Posture

Incident Management

Configuration Operations

Access & Tenancy Administration

AI Assistance

Configuration Migration

Device Health & Lifecycle

Onboarding & Provisioning

Licensing & Entitlement

Platform APIs

Cloud log storage and forwarding for the network security platform.

Log Forwarding

Device Onboarding & Inventory

Log Ingestion

Log Search & Export

Activation & Licensing

Monitoring & Dashboards

Regions & Data Residency

Storage & Retention

Access & Administration

Log Schema Reference

The console managed service providers and distributed enterprises use to run many customer tenants at once — device allocation, cross-tenant configuration, aggregated monitoring and the service-provider interconnect surface, none of which exist in single-tenant Strata Cloud Manager.

Monitoring & Insights

Service Provider Interconnect

Cross-Tenant Configuration

Tenant Services & Devices

Platform Access

The firewall as a virtual appliance for private and public cloud.

Licensing & Credits

Packet Path & Interfaces

Public Cloud Deployment

Automation & APIs

SDN Service Insertion

Capacity & Sizing

High Availability

Private Cloud Deployment

Workload Context & Tagging

Monitoring & Logging

Central Management & Policy

Certificates & Data Protection

Select a capability