> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses.md).

# Cortex XSIAM product licenses

Cortex XSIAM is available in the following subscription tiers, designed to support specific security use cases:

{% hint style="info" %}

### Note

You can upgrade your license by purchasing add-ons or moving to a different XSIAM license.
{% endhint %}

### Cortex XSIAM NG-SIEM

Cortex XSIAM NG-SIEM is an analytics subscription tier that includes data collection and full automation, suitable for users who want to enhance their security without immediately replacing their existing SIEM and endpoint solutions.

Key features include:

<table><thead><tr><th width="342.5">Feature</th><th>Description</th></tr></thead><tbody><tr><td>AI and Big Data</td><td>Integrates data analytics, AI/ML, and automation into a unified platform.</td></tr><tr><td>Comprehensive Data Collection</td><td>Offers extensive cloud data collection with out-of-the-box analytics, detection, and cloud asset discovery.</td></tr><tr><td>Advanced Analytics</td><td>Provides capabilities for threat hunting, analysis, response, and automation.</td></tr><tr><td>User and Entity Behavior Analytics (UEBA)</td><td>Uses machine learning to profile users and entities, alerting on anomalous behavior that could indicate a compromised account or insider threat</td></tr></tbody></table>

### Cortex XSIAM Enterprise

Cortex XSIAM Enterprise includes all the features of Cortex XSIAM NG-SIEM and builds upon them by adding advanced endpoint visibility and data collection:

Key additions include:

| Feature                               | Description                                                                                                                                                                             |
| ------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cortex XDR agent                      | Entitles you to one Cortex XDR agent per endpoint, which provides tailored endpoint data and third-party logs collection to optimize detection and investigation visibility.            |
| Extended Detection and Response (XDR) | Incorporates extended data collection and ingestion of endpoint logs and alerts, firewalls, and third-party audit and flow logs through Host Insights and Extended Threat Hunting Data. |

### Cortex XSIAM Premium

Cortex XSIAM Premium is the most comprehensive tier, providing the highest level of security by combining all Enterprise features together with the following capabilities:

<table><thead><tr><th width="227">Feature</th><th>Details</th></tr></thead><tbody><tr><td>Cloud Posture Security</td><td><p>Delivers comprehensive visibility and continuous monitoring of cloud environments to ensure configurations meet security best practices, compliance standards, and vulnerability management. This bundle includes the following advanced modules:</p><ul><li>Cloud Security Posture Management (CSPM): Continuously scans your cloud environment (AWS, Azure, GCP) to detect misconfigurations, compliance violations, and drift from secure baselines.</li><li>Cloud Infrastructure Entitlement Management (CIEM): Enforces least-privilege access to cloud infrastructure. It protects and manages access to resources by analyzing identity misconfigurations, reducing excessive permissions, and providing real-time monitoring of identity anomalies.</li><li>AI Security Posture Management (AI-SPM): Secures AI-powered applications and models against misuse and vulnerabilities.</li><li>Data Security Posture Management (DSPM): Discovers, classifies, and secures sensitive data across your cloud environment.</li><li>Agentless Workload Scanning: Scans cloud workloads for vulnerabilities, malware, and exposed secrets without requiring an agent installation.</li><li><p>Application Security Posture Management (ASPM): Provides a consolidated view of application risks and vulnerabilities across your environment, enabling you to understand and manage your overall security posture.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Full code security scanning requires a separate add-on.</p></div></li><li>CI/CD: Focuses on securing your continuous integration and continuous delivery pipelines, ensuring the integrity and security of your automated build and deployment processes</li></ul></td></tr><tr><td>Cloud Runtime Security</td><td><p>Prevents attackers from exploiting risks present in your cloud environment. Provides real-time protection, detection, and response for cloud workloads, crucial for applications, containers, serverless functions, and APIs. Includes</p><ul><li>Cloud Workload Rules: Cloud Workload Rules define the criteria for identifying security violations. This criteria can be applied to assets in your cloud environment and to findings generated by Cortex XSIAM.</li><li>Cloud Workload Policies: Cloud Workload Policies help you prevent and manage security violations in your cloud runtime instances.</li><li>Web and API Security: Cortex Web and API Security (WAAS) capabilities offer comprehensive protection of APIs across integrated API gateways and web-based applications and APIs running on Linux-based workloads.</li></ul><p>Cortex XSIAM Premium users can install an XDR agent on endpoints and on any host or cloud workload, including Kubernetes hosts, based on the user's per-unit subscription parameters and workload demands. The XDR agent offers cloud-based endpoint protection and detection support, along with tailored endpoint and third-party log data collection.</p><p>For more information about the license relationship between the XDR agent on endpoints and the XDR agent on host or cloud workloads, and how the licenses are allocated, see <a href="/pages/ThOeQdWmw5iPy6NeLElO">License allocation</a>.</p></td></tr><tr><td>Extended Threat Intelligence (XTI)</td><td>Provides operationalized Threat Intelligence (TI) seamlessly integrated across the Cortex platform.</td></tr><tr><td>Threat Intel Management</td><td>Investigates indicators and files, applies indicator rules, generates reports, and integrates feed integrations.</td></tr><tr><td>Attack Surface Management</td><td>Provides internet-facing assets and ASM enrichment, external services, external IP ranges, attack surface rules and alerts, ASM widgets, and report capabilities.</td></tr></tbody></table>

{% hint style="info" %}

### Note

Existing users who have a Cortex XSIAM Enterprise Plus license retain all Cortex XSIAM Enterprise features, with cloud agent features. You can deploy agents for runtime detection on cloud sources, such as Kubernetes nodes, OpenShift clusters, or cloud VMs, whether in the cloud or on-premises. If you want the full cloud posture security bundle (Cloud Posture Security or Cloud Runtime Security), you need to upgrade to Cortex XSIAM Premium.

Some add-ons, such as Advanced Email Security and Exposure Management, are only available for Cortex XSIAM Premium, Enterprise, and NG-SIEM licenses.
{% endhint %}

{% tabs %}
{% tab title="Capabilities and add-ons" %}
Cortex offers a modular set of license packages that work interchangeably with each other, allowing them to become add-ons to subsequent products seamlessly. The table below shows the breakdown of each type of license package:

<table><thead><tr><th width="114.5">Feature</th><th width="220.5">Description</th><th width="117.5" align="center">Cortex XSIAM NG SIEM</th><th width="120.5" align="center">Cortex XSIAM Enterprise</th><th align="center">Cortex XSIAM Premium</th></tr></thead><tbody><tr><td>Core Analytics</td><td>Detects anomalies and threats using machine learning and behavioral models.</td><td align="center">Included in license</td><td align="center">Included in license</td><td align="center">Included in license</td></tr><tr><td>Automation</td><td>Orchestrates and automates security workflows with prebuilt and customizable playbooks.</td><td align="center">Included in license</td><td align="center">Included in license</td><td align="center">Included in license</td></tr><tr><td>Data Ingestion</td><td><p><strong>Analytics tier</strong>: Collects and normalizes data, creating a unified foundation for analytics, investigation, and detection. GB/day-based, with a minimum of 100 GB/day.<br></p><p><strong>Cortex Data Lake tier</strong>: Provides cost-efficient ingestion and storage of security data at scale for use cases such as threat hunting, forensic investigations, and compliance audits. This tier is available as an optional add-on with a minimum of 50 GB/day, provided the mandatory 100 GB/day Analytics tier license is already met. For more information, see <a href="/pages/lFvvv9MaqZV5o1bcojsK">Configure Cortex Data Lake tier</a>.</p></td><td align="center">Included in license</td><td align="center">Included in license</td><td align="center">Included in license</td></tr><tr><td>Enterprise Runtime Security (XDR)</td><td>Comprehensive endpoint and server protection by combining AI-driven analytics, endpoint controls, next-generation antivirus, and automated investigation to detect and respond to threats across various environments.</td><td align="center">Add-on</td><td align="center">Included in license</td><td align="center">Included in license</td></tr><tr><td>Cloud Posture Security</td><td><p>Agentless comprehensive visibility across your cloud environment. Includes:</p><ul><li>Up to 400 workloads, dependent on the license plan</li><li>Cloud Security Posture Management (CSPM)</li><li>Cloud Infrastructure Entitlement Management (CIEM)</li><li>Data Security Posture Management (DSPM)</li><li>AI Security Posture Management (AI-SPM)</li><li>Continuous Integration/Continuous Deployment (CI/CD)</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>For Cortex XSIAM Enterprise and NG SIEM, if purchasing Cloud Posture Security only, a minimum number of workloads is required. If you purchase Cloud Runtime Security or Cortex XSIAM Premium, this add-on is included with the subscription.</p></div></td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Included with Cloud Runtime Security</td></tr><tr><td>Cloud Runtime Security</td><td><p>Full cloud protection, detection, and response. In addition to Cloud Posture Security:</p><ul><li>For Cortex XSIAM Premium: Minimum 200 workloads (priced per workload).</li><li>Cloud Detection and Response (CDR)</li><li>Cloud Workload Protection (CWP)</li><li>Web Application and API Security (WAAS)</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>For all Cortex XSIAM license plans, a minimum number of workloads is required.</p></div></td><td align="center">Add-on (priced per cloud workload)</td><td align="center">Add-on (priced per cloud workload)</td><td align="center">Included capability (priced per cloud workload)</td></tr><tr><td>Application Security</td><td><p>Comprehensive protection for your software development lifecycle (SDLC) from code-to-cloud, offering visibility, detection, contextual analysis, prioritization, prevention, and remediation.</p><p><strong>License requirements</strong></p><p>To access the Application Security module, you must have a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license. The following features are automatically included with these licenses:</p><ul><li>Application Security Posture Management (ASPM)</li><li>CI/CD Security</li></ul><p><strong>Add-on component: Code Security</strong></p><p>Code Security requires the purchase of a separate Application Security add-on in addition to your Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license.</p></td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>Extended Threat Intelligence (XTI)</td><td>Provides operationalized Threat Intelligence (TI) seamlessly integrated across the Cortex platform</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Included in license</td></tr><tr><td>Threat Intelligence Management</td><td>Investigates indicators and files, uses indicator rules, reports, and feed integrations.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Included in license</td></tr><tr><td>Attack Surface Management</td><td>Provides internet-facing assets and ASM enrichment, external services, external IP ranges, attack surface rules and alerts, ASM widgets, and report capabilities.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Included in license</td></tr><tr><td>Identity Threat Detection &#x26; Response</td><td>Enables asset role configuration, advanced analytics alert layout, Risk Management dashboard, User/Host Risk view, designated analytics for compromised accounts, and insider threat coverage. This solution helps organizations proactively secure identities, accelerate threat response, and reduce the complexity of security operations.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>Forensics</td><td>Detect attacker activity by reviewing key artifacts such as event logs, registry keys, browser history, etc. Forensics simplifies investigations so you can trace every move an adversary made and swiftly contain threats from one place without needing to pivot between security tools.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>Host Insights</td><td>Host Insights combines Vulnerability Management, Host Inventory, and a powerful Search and Destroy feature to help you identify and contain threats. It offers a holistic approach to endpoint visibility and attack containment, helping reduce your exposure to threats so you can avoid future breaches.</td><td align="center">Add-on</td><td align="center">Included in license</td><td align="center">Included in license</td></tr><tr><td>Extended Threat Hunting</td><td>Investigates everyday activities in real time and analyzes patterns to discover new threats, aiming to proactively minimize risk for an organization.</td><td align="center">Add-on</td><td align="center">Included in license</td><td align="center">Included in license</td></tr><tr><td>Data Retention</td><td>Retention per dataset ensures extended access to data, strengthening threat investigation, compliance, and long-term visibility.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>Extended Compute Units</td><td>Additional computing resources beyond the annual allocation. You can purchase more units or enable dynamic allocation for flexible access. This ensures uninterrupted service, supports scaling during peak workloads, and optimizes resource management to maintain performance during high-demand periods.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>Endpoint Event Forwarding</td><td>Enables exporting the raw telemetry collected by XDR Agents and event data from cloud endpoints to external systems (if relevant).</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>GB Event Forwarding</td><td>Enables exporting parsed logs to an external SIEM for storage, so you can keep data in your own storage in addition to the Cortex XSIAMdata layer, for compliance requirements and machine learning purposes.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>Advanced Email Security</td><td>Investigate and respond to threats within modern, distributed email infrastructures. The module is a scalable, API-based solution that passively analyzes cloud-hosted email environments to detect threats. It ingests data from messages, attachments, and user identities to identify early-stage threats and high-risk behaviors without requiring any changes to mail flow.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>Exposure Management</td><td>Gain comprehensive visibility, actionable prioritization, and automation-first remediation to help security teams proactively assess and respond to organizational exposures.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr><tr><td>DLP (Data Loss Prevention)</td><td>The Cortex Data Loss Prevention (DLP) module provides a unified and flexible solution to prevent sensitive data exfiltration. It continuously enforces policies on endpoints (even offline) across web, local, and USB channels, protecting both on-premise and cloud environments.</td><td align="center">Add-on</td><td align="center">Add-on</td><td align="center">Add-on</td></tr></tbody></table>
{% endtab %}

{% tab title="Tiers and key capabilities" %}
![Cortex\_XSIAM\_Licenses\_Jan22.png](/files/EbVgiUN0RgXWrBYzzvRN)
{% endtab %}
{% endtabs %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
