For the complete documentation index, see llms.txt. This page is also available as Markdown.

Palo Alto Networks Cortex

This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.

Unit 42 Threat Intelligence by Palo Alto Networks delivers high-fidelity threat intelligence curated by the Unit 42 research team and derived from telemetry across the Palo Alto Networks product ecosystem. Use the Unit 42 Feed integration to continuously fetch indicators and threat objects, and the Unit 42 Intelligence integration to enrich indicators (IP, domain, URL, file hash) with verdicts, threat object associations, and relationships.

This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):

  • Unit 42 Feed: Unit 42 Feed integration provides threat intelligence from Palo Alto Networks Unit 42 research team.

  • Unit 42 Intelligence: Enrich indicators with Unit 42 threat intelligence context including verdicts, threat object associations, and relationships.

To configure this connector, follow the steps outlined in the configuration wizard.

Last updated

Was this helpful?