Palo Alto Networks Cortex XSOAR Primary Use Case

Donald Keeber - PeerSpot reviewer
President at Margate Net

Cortex XSOAR is our desktop endpoint security standard. We deploy it on the desktops, monitor the events, and ensure the endpoints stay clean and inoculated. The client is a retail company with salespeople on the floor and roving notebooks that employees bring with them to various locations. We needed a solution that allows us to protect those endpoints no matter where they are. We deployed them through Active Directory using a group policy system. 

Customers don't always have endpoints that are part of their Active Directory, but we chose to use ADGPO to ensure any user logging into our domain(s) had the product installed. There are about 600 users spread out across three locations and six dealerships.

View full review »
JP
Cybersecurity Cyber Crime Infrastructure Engineer & Investigator at a government with 5,001-10,000 employees

We were looking for a single pane of glass type of solution that would allow us to physically be in one appliance be able to work in concert with other servers that we have within our environment. We wanted orchestration and automation. The single pane of glass was the most important part. 

Every investigator has a different way of tackling an investigation. Essentially what we wanted to do is to take the mundane tasks that the investigators have to do as part of their investigation process and then automate those mundane tasks as a pre-processor. That way, when the investigation is provided to the investigator in order to review what was found, all they have to do is look at the data that was presented to them and they wouldn't have to go through the process of doing the data enrichment with regards to threats and functions of that nature because all of that was done ahead of time as part of the processing.

Right now we've started with one investigation, which is phishing. The user will report any phishing attempts against any of our users within JPL to an email address. Our XSOAR appliance will peek into that mailbox, pull the emails out, and then process those emails that have been reported. As part of the processing, it'll do the data enrichment and once that's done, that's presented to the investigator in order to review the findings. The investigator makes the final verdict. Once the final verdict is rendered, then the other automated task would be the enforcement tasks, which would include any blocking of the sender, blocking of the IP, blocking of the domain, blocking of the URL, and those types of actions.

View full review »
Iskandar Iskak - PeerSpot reviewer
Director Sales for Education Market at Telekom Malaysia

The client never had any XSOAR automation before, and they never had a CRM implemented with them, either. So we provided both CRM and complemented with XSOAR.

So it's a totally new experience, and we have already developed three playbooks. To move further, we have to wait for the next few months before we agree on any automation response.


View full review »
Buyer's Guide
Palo Alto Networks Cortex XSOAR
April 2024
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.
Jasmin Surani - PeerSpot reviewer
Senior Cybersecurity Engineer (Security Operations & Engineering) at a manufacturing company with 10,001+ employees

It is a security orchestration and automation tool.

It basically lets us automate and orchestrate tasks across all your security tools. Imagine integrating our vulnerability management tool with XSOAR. For example, we get a ServiceNow ticket requesting a scan for a specific server before it goes live. XSOAR can trigger that scan automatically, streamlining the entire process. That's the power of XSOAR—automating repetitive tasks and freeing up your security team for more strategic work.

View full review »
Oleksii Pavlyk - PeerSpot reviewer
Head of the direction of ensuring the security of digital systems, electronic databases and networks at Ukreximbank

In my company, it is not me but my team that is involved with Palo Alto Networks Cortex XSOAR. The tool is majorly useful for incident response and automation purposes.

View full review »
ML
Splunker, Networking and E-Mail Security Architect, Engineer and Guru at a healthcare company with 10,001+ employees

We use Palo Alto Networks Cortex XSOAR for several areas of security automation, such as phishing, investigating, mitigating, the detection of impossible travel, and consolidating threat information for our internal systems.

View full review »
Nethra Sk - PeerSpot reviewer
Head of Security Monitoring and Control at Alstom Ferroviaria S.p.A.

Our primary use case for the solution is customization and integration with Microsoft infrastructure.

View full review »
DL
Senior Information Technology Support Engineer at TSCNET Services GmbH

We primarily use the solution for network inspection.

View full review »
Chetankumar Savalagimath - PeerSpot reviewer
Delivery Manager at a tech services company with 1,001-5,000 employees

I primarily pitch and sell this solution to our customers. We do product assessments and consult with customers for the most part.

Clients can use it for automation. 

View full review »
MA
MSS Delivery Lead at Help AG

We have a lot of playbooks. It makes our SOC operations easy.

View full review »
SB
Vice President Global Technology Infrastructure Automation at a financial services firm with 10,001+ employees

We use Palo Alto as a firewall, a system for detecting and whitelisting certain IP addresses or to block certain IP addresses based on where they're coming from. We then send the logs to another log management tool for more forensics and analysis before we make a decision.

We're basically using Palo Alto for firewalling and sending those logs to another security monitoring tool to make decisions based on analytics that it provides us.

View full review »
ShubhamAgarwal - PeerSpot reviewer
Specialist - Information Security at LPI

I mainly use Cortex XSOAR to automate cybersecurity and the SOC environment.

To minimize manual tasks and increase level of automation. 

View full review »
Sara Qafa - PeerSpot reviewer
Systems Engineer at Exclusive Networks

The SOC team needs the tool to understand the network and determine why an incident happens. The tool helps understand user behavior and helps with threat hunting.

View full review »
Mostafa-Ahmed - PeerSpot reviewer
Cybersecurity incident response team lead at Information Technology Solutions- ITS

As an integrator, I have used Palo Alto Networks Cortex XSOAR in various customer environments for a wide range of purposes. This includes improving IT security, streamlining operations, automating incident response actions, creating playbooks with approvals, and enhancing integrations with different security tools. In essence, Cortex XSOAR serves as a versatile platform that helps address multiple cybersecurity and operational needs in organizations.

View full review »
EG
Manager at Commercial Bank of Ethiopia

Our company uses the solution for security management and threat response. 

View full review »
AYOUB ECH-CHKAF - PeerSpot reviewer
Security Operations Center Analyst (L2 at Thales

We use the solution for incident orchestration.

View full review »
SM
Security Project Manager at a retailer with 10,001+ employees

We are using Palo Alto Networks Cortex XSOAR for automation.

View full review »
AM
Intern Cybersecurity at a computer software company with 10,001+ employees

I'm currently evaluating XSOAR to see what the solution can do. I'm playing around with the various features. 

View full review »
HendrikDu Plooy - PeerSpot reviewer
Business Development Manager at a tech services company with 11-50 employees

Our clients use it in our managed service platform, in our cloud. We also provide solutions to our clients on Service Cloud and XDR.

View full review »
Rodrigo AlexiPizarro - PeerSpot reviewer
IT Operations Deputy Manager at Ultramar Agencia Marítima

My primary use for Palo Alto Networks Cortex XSOAR is to protect the workstation for the end-users.

View full review »
Cemil Altug - PeerSpot reviewer
Hybrid Cyber Security Team Lead at Dndx CyberSecurity

The solution is used for security. 

View full review »
GJ
Deputy Vice President at a financial services firm with 10,001+ employees

It is a help desk ticketing tool. It's a sought platform, however, it is just a help desk ticketing tool.

View full review »
YP
Business Development Manager at a tech services company with 51-200 employees

We use the solution to create playbooks for all the operational programs.

View full review »
DL
Sales engineer at MUK

XSOAR is the cherry on top of Cortex XDR. It provides you with the ability to make a lot of response actions to your incidents. Cortex XDR is collecting an incident, and Cortex XSOAR is providing you the ability to remediate it.

When the customers need the ability to remediate incidents, for example, antivirus or network security issues, some SIEM solution, et cetera, yet need to integrate everything, they can use the power of the platform without needing different solutions. Cortex XSOAR will give you the ability to integrate

For example, if some endpoint was infected in your infrastructure, you need to do something about that. XSOAR provides you the ability to understand how that endpoint was infected and to do something with that. 

Cortex XSOAR will go to the firewall and block the IP address of this endpoint. Cortex XSOAR will go to the domain and disable the user as well. Then it will go to some other solution and will do something there. It is a variety of actions based on the incidents. 

View full review »
RK
Network and Information Security at a tech services company with 10,001+ employees

I work for a company, and we provide support and complete end-to-end management of the product for our customers who hold the product.

View full review »
VW
Security Professional at a tech services company with 51-200 employees

Our primary case issues are phishing, TI, and sensors.

View full review »
RP
Regional Director, Customer Success (GTM Solutions & Services) at a tech services company with 51-200 employees

We primarily use the solution for automation and the orchestration of security.

View full review »
NN
None at Invecto

The product can be used for securing endpoints from various types of attacks, threat incidents, and malware attacks.

View full review »
Nicolo Corrado - PeerSpot reviewer
Consulente immobiliare at Libero

I'm using Cortex XSOAR to manage our network security.

View full review »
FA
Cyber Security Analyst at a tech services company with 11-50 employees

Our customers use the product for automation.

View full review »
DS
Consultant at a tech services company with 501-1,000 employees

We are using this solution to have a completely organized SOC from a list of devices in our environment. We are able to manage all of our devices, such as firewalls and endpoint protection solutions.

View full review »
SA
Network Security Engineer at a tech services company with 201-500 employees

The use cases basically came from the customers. Most of the time, the major concern is from a security perspective because various kinds of attacks are happening. To restrict or stop those attacks, we are building playbooks. We are also automating repetitive tasks.

We are using on-premise as well as cloud deployments.

View full review »
it_user1333062 - PeerSpot reviewer
Director at a tech services company with 11-50 employees

We are a solution provider and this is one of the products that we are selling to our clients.

View full review »
Buyer's Guide
Palo Alto Networks Cortex XSOAR
April 2024
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.