{"id":105927,"date":"2020-02-06T06:00:45","date_gmt":"2020-02-06T14:00:45","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=105927"},"modified":"2020-05-20T17:59:41","modified_gmt":"2020-05-21T00:59:41","slug":"cortex-managed-threat-hunting","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2020\/02\/cortex-managed-threat-hunting\/","title":{"rendered":"Announcing Cortex XDR Managed Threat Hunting \u2013 Community Edition and New XDR Features"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\"  class=\"wp-image-105928 alignright lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1.png\" alt=\"This conceptual illustration of the Community Access edition of Cortex XDR Managed Threat Hunting shows how the service identifies hidden attacks that would otherwise go undetected\" width=\"414\" height=\"217\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1.png 1999w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-230x121.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-500x263.png 500w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-768x403.png 768w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-1536x807.png 1536w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-510x268.png 510w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-76x40.png 76w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-571x300.png 571w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1-874x459.png 874w\" sizes=\"auto, (max-width: 414px) 100vw, 414px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">We are proud to announce the Community Access edition of Cortex XDR Managed Threat Hunting, a powerful threat hunting service exclusively for our Cortex XDR customers. For a limited time, <\/span><b>Community Access is available for free to eligible customers<\/b><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With Cortex XDR, Palo Alto Networks has delivered <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/products\/xdr\/mitre.html\"><span style=\"font-weight: 400;\">unmatched detection capabilities<\/span><\/a><span style=\"font-weight: 400;\"> that run on high-fidelity integrated data from endpoint, network and cloud data sources. Now, we\u2019re augmenting the power of Cortex XDR with a managed threat hunting service led by the globally renowned <\/span><a href=\"https:\/\/unit42.paloaltonetworks.com\/\"><span style=\"font-weight: 400;\">Unit 42 threat intelligence team<\/span><\/a><span style=\"font-weight: 400;\"> to identify hiddens attacks that would otherwise go undetected. Our threat hunters apply human expertise augmented with big data analytics and comprehensive threat intelligence to surface malicious tactics, techniques and procedures hiding amongst billions of benign actions.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/start.paloaltonetworks.com\/managed-threat-hunting-community-access-sign-up.html\"><span style=\"font-weight: 400;\">Registration for the Community Access edition of Cortex XDR Managed Threat Hunting is available today<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>What Makes Cortex XDR Managed Threat Hunting Unique?<\/b><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><b>Backed by Unit 42: <\/b><span style=\"font-weight: 400;\">The world-renowned experts, who<\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2019\/12\/network-threat-intelligence-research\/\"><span style=\"font-weight: 400;\"> lead the way in tracking adversaries <\/span><\/a><span style=\"font-weight: 400;\">and have uncovered major attacks like <\/span><a href=\"https:\/\/unit42.paloaltonetworks.com\/tag\/oilrig\/\"><span style=\"font-weight: 400;\">OilRig<\/span><\/a><span style=\"font-weight: 400;\">, will work around the clock to identify hidden threats in your network, endpoint and cloud assets.<\/span><\/li>\n<li style=\"font-weight: 400;\"><b>Unprecedented analytics<\/b><span style=\"font-weight: 400;\">: 7 trillion threat artifacts and 14 billion malware samples crowdsourced from 35,000+ organizations inform our industry-leading researchers and machine learning models.<\/span><\/li>\n<li style=\"font-weight: 400;\"><b>Clear and proactive<\/b><span style=\"font-weight: 400;\">: Gain clear direction with deep context on active threats and proactive impact reports to shut down emerging threats with confidence.<\/span><\/li>\n<\/ul>\n<p><i><span style=\"font-weight: 400;\">Threat hunting is not just a people problem. You need good data and analytics.<\/span><\/i><\/p>\n<p><b>Don't miss your chance to <\/b><a href=\"https:\/\/start.paloaltonetworks.com\/managed-threat-hunting-community-access-sign-up.html\"><b>take advantage of the Community Access edition of Cortex XDR Managed Threat Hunting<\/b><\/a><b>.<\/b><span style=\"font-weight: 400;\"> You can also access it directly within the settings menu of Cortex XDR.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Even More New Cortex XDR Capabilities<\/span><\/h2>\n<p><div style=\"max-width:100%\" data-width=\"900\"><span class=\"ar-custom\" style=\"padding-bottom:57%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-105972 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image.png\" alt=\"This screenshot of Cortex XDR shows its incidents management and agent control.\" width=\"900\" height=\"513\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image.png 1530w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image-230x131.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image-500x285.png 500w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image-768x438.png 768w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image-510x291.png 510w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image-70x40.png 70w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image-526x300.png 526w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image-874x498.png 874w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/span><\/div><\/p>\n<p><span style=\"font-weight: 400;\">On the heels of the <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2019\/12\/cortex-xdr-2-0-features\/\"><span style=\"font-weight: 400;\">latest release of Cortex XDR<\/span><\/a><span style=\"font-weight: 400;\">, our R&amp;D teams have already delivered several exciting new Cortex XDR features that further improve dashboarding, alerting and third-party integrations:<\/span><\/p>\n<p><b>Enhanced visibility and reporting<\/b><\/p>\n<p><span style=\"font-weight: 400;\">To identify high-severity threats and connectivity problems, your analysts need dashboards tailored to their unique requirements. When reviewing security alerts, they must have rich investigative context at their fingertips.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the February release, Cortex XDR has added six new dashboard widgets that allow analysts to monitor incidents by status, alerts by category or source, and much more. Analysts can build custom dashboards with flexible chart options to assess security status.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Improved integration with WildFire lets your analysts view WildFire Analysis Reports without needing to download a PDF file or leave the Cortex XDR management console. Analysts can click on a link in the Cortex XDR \u201cCausality\u201d window to examine process, timeline and network information gathered by WildFire. WildFire analysis, included standard with Cortex XDR, takes the guesswork out of malware analysis.<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><div style=\"max-width:100%\" data-width=\"900\"><span class=\"ar-custom\" style=\"padding-bottom:59%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-105954 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2.png\" alt=\"This screenshot shows the Wildfire Analysis Report, which is now better integrated with the Cortex XDR management console.\" width=\"900\" height=\"531\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2.png 1077w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2-230x136.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2-500x295.png 500w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2-768x454.png 768w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2-508x300.png 508w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2-68x40.png 68w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image2-874x516.png 874w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/span><\/div><\/p>\n<p><i><span style=\"font-weight: 400;\">An integrated WildFire Analysis Report simplifies Cortex XDR investigations.<\/span><\/i><\/p>\n<p><b>New APIs extend integration with third-party tools<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cortex XDR now supports flexible APIs to retrieve or quarantine files, scan endpoints and much more. Organizations can use <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/demisto\"><span style=\"font-weight: 400;\">Demisto<\/span><\/a><span style=\"font-weight: 400;\"> or other third-party tools to coordinate responses or collect telemetry from many Cortex XDR agents at the same time. These public APIs also allow partners or managed service providers to use the administration tools of their choice for monitoring and management. The <\/span><a href=\"https:\/\/docs.paloaltonetworks.com\/cortex\/cortex-xdr\/cortex-xdr-api\"><span style=\"font-weight: 400;\">new APIs<\/span><\/a><span style=\"font-weight: 400;\"> complement existing Cortex XDR APIs introduced in the December 2019 release.<\/span><\/p>\n<p><b>Email-based alert notifications<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Email-based alerts allow analysts to be notified instantly when security events occur. Analysts can now streamline alert management by configuring alert notification and\u00a0 aggregation settings from the Cortex XDR management console. They can also define the alert specifications, distribution lists and how often to send notifications in the \u201cSettings &gt; Alert Notifications\u201d page.<\/span><\/p>\n<p><b>Coordinated response across multiple endpoints<\/b><\/p>\n<p><span style=\"font-weight: 400;\">To shut down malware outbreaks, security teams must act quickly. By locking down multiple endpoints at once, Cortex XDR administrators can prevent the spread of dangerous attacks across the organization. Cortex XDR now allows administrators to isolate multiple endpoints simultaneously, cutting response time and eliminating repetitive administrative tasks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Other enhancements introduced in February include encrypted and password-protected PDF reports and agent management features. To learn more about these new features, see the <\/span><a href=\"https:\/\/docs.paloaltonetworks.com\/cortex\/cortex-xdr\/cortex-xdr-release-notes\"><span style=\"font-weight: 400;\">Cortex XDR release notes<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Community Access edition of Cortex XDR Managed Threat Hunting is a powerful threat hunting service exclusively for our Cortex XDR customers.<\/p>\n","protected":false},"author":632,"featured_media":105928,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6770],"tags":[6737,2623],"coauthors":[6734],"class_list":["post-105927","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-future","tag-cortex-xdr","tag-threat-research"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/02\/image1-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/105927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/632"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=105927"}],"version-history":[{"count":7,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/105927\/revisions"}],"predecessor-version":[{"id":111771,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/105927\/revisions\/111771"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/105928"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=105927"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=105927"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=105927"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=105927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}