> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans.md).

# Understand Cortex XDR license plans

The following provides a summary of what is included in the Cortex XDR license plans and add-ons:

* **Cortex XDR Prevent:** A comprehensive endpoint protection solution providing multi-layer protection and detection capabilities. Cortex XDR Prevent can effectively block malware, ransomware, behavioral-based and exploit attacks. Additionally, this license includes device control, firewall protection, and disk encryption.
* **Cortex XDR Pro per Endpoint:** This license offers tailored endpoint data and third-party logs collection to optimize detection and investigation visibility. For enhanced data collection, the Cortex XDR eXtended Threat Hunting Data (XTH) add-on expands the data collection to allow for more granular threat-hunting operations in your environment.
* **Cortex XDR Cloud per Host:** A cloud-based endpoint protection and detection license with tailored endpoint and third-party logs data collection. The license also provides Kubernetes support.

  Along with the Cortex XDR eXtended Threat Hunting Data (XTH) add-on, you can expand the data collection to allow for more granular threat-hunting operations in your environment.
* **Cortex XDR Pro per GB:** Collects endpoint data, and can ingest numerous data sources for complete visibility over your network traffic, and user behavior. When combined with the Cortex XDR Pro per Endpoint license, the Cortex XDR Pro per GB license provides streamlined investigation techniques and extensive remediation analysis capabilities.

| Capabilities                                                                                                                                                                                                                                         | **Cortex XDR Prevent** | <p><strong>Cortex XDR Pro per Endpoint</strong></p><p><strong>Cortex XDR Cloud per Host</strong></p> | **Cortex XDR Pro per Gigabyte** |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :--------------------: | :--------------------------------------------------------------------------------------------------: | :-----------------------------: |
| <p><strong>Next-Generation Antivirus</strong></p><p>Block malware, ransomware, exploits, and fileless attacks</p>                                                                                                                                    |            ✓           |                                                   ✓                                                  |                –­               |
| <p><strong>Endpoint Protection</strong></p><p>Safeguard endpoints with device control, ﬁrewall, and disk encryption</p>                                                                                                                              |            ✓           |                                                   ✓                                                  |                –­               |
| <p><strong>Detection and Response</strong></p><p>Pinpoint attacks with AI-driven analytics and coordinate response</p>                                                                                                                               |           –­           |                                                   ✓                                                  |                ✓                |
| <p><strong>Add-on: Host Insights</strong></p><p>Find vulnerabilities and sweep across endpoints to eradicate threats</p>                                                                                                                             |           –­           |                                                   ✓                                                  |                –­               |
| <p><strong>Third-Party Security Events</strong></p><p>Send security events from other data sources</p>                                                                                                                                               |           –­           |                                                   ✓                                                  |                ✓                |
| <p><strong>Third-Party Security Logs</strong></p><p>Send raw logs from other data sources</p>                                                                                                                                                        |           –­           |                                                  –­                                                  |                ✓                |
| <p><strong>Network Trafﬁc Analysis</strong></p><p>Syslog, Kafka, DB, CSV ﬁle, FTP, NetFlow, Windows events, Pathﬁnder</p>                                                                                                                            |           –­           |                                                  –­                                                  |                ✓                |
| <p><strong>Prisma and PANW IoT Security</strong></p><p>Unify cloud and/or control system environments with XDR</p>                                                                                                                                   |           –­           |                                                  –­                                                  |                ✓                |
| <p><strong>Integrations</strong></p><p>Threat intelligence solutions, Slack, send Syslog</p>                                                                                                                                                         |            ✓           |                                                   ✓                                                  |                ✓                |
| <p><strong>Security Analytics</strong></p><p>Apply machine learning and UEBA detections to security data</p>                                                                                                                                         |           –­           |                                                   ✓                                                  |                ✓                |
| <p><strong>Add-on: Compute Units (CU)</strong></p><p>Additional compute units to run API and cold storage queries. Compute units are allocated on an annual basis.</p><p>Requires a minimum of 50 units. Available for a one-month trial period.</p> |            -           |                                                   ✓                                                  |                ✓                |
| <p><strong>Add-on: Forensics Investigation</strong></p><p>Incidents swiftly with comprehensive forensics evidence</p>                                                                                                                                |           –­           |                                                   ✓                                                  |                –­               |
| <p><strong>Add-on: Identity Threat Detection and Response (ITDR Module)</strong></p><p>Uncover hard-to-detect threats like insiders, lateral movement, credential compromise</p>                                                                     |           –­           |                                                  –­                                                  |                ✓                |
| <p><strong>Add-on: eXtended Threat Hunting Data (XTH Module)</strong></p><p>Collect rich data at the endpoint to support deep threat-hunting operations in an environment</p>                                                                        |           –­           |                                                   ✓                                                  |                –­               |
| <p><strong>Add-on: Managed Threat Hunting</strong></p><p>Let Unit 42 experts work for you 24/7 to discover advanced threats</p>                                                                                                                      |           –­           |                                                   ✓                                                  |                ✓                |
| <p><strong>Add-on: Managed Detection and Response</strong></p><p>Let Unit 42 experts work for you 24/7 to detect and respond to threats</p>                                                                                                          |           –­           |                                                   ✓                                                  |                ✓                |

To view the license types and add-ons associated with your Cortex XDR instance, go to Settings → **Cortex XDR License**.

![liscenseimage\_\_1\_.png](/files/lqGGbSMW01pZKVwmqfJM)

To keep you informed of updates made to your license and avoid service disruptions, Cortex XDR displays license notifications when you log in. The notification identifies any changes made to your license and describes any required actions.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
