* [Blog](https://origin-researchcenter.paloaltonetworks.com/blog) * [Palo Alto Networks](https://origin-researchcenter.paloaltonetworks.com/blog/corporate/) * [AI and Cybersecurity](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/) * Bridging the Gap: An Unpr... # Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2F2026%2F08%2Fbridging-the-gap-an-unprecedented-approach-to-browser-and-endpoint-security%2F) [](https://twitter.com/share?text=Bridging+the+Gap%3A+An+Unprecedented+Approach+to+Browser+and+Endpoint+Security&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2F2026%2F08%2Fbridging-the-gap-an-unprecedented-approach-to-browser-and-endpoint-security%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2F2026%2F08%2Fbridging-the-gap-an-unprecedented-approach-to-browser-and-endpoint-security%2F&title=Bridging+the+Gap%3A+An+Unprecedented+Approach+to+Browser+and+Endpoint+Security&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://origin-researchcenter.paloaltonetworks.com/blog/2026/08/bridging-the-gap-an-unprecedented-approach-to-browser-and-endpoint-security/&ts=markdown) \[\](mailto:?subject=Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security) Link copied By [Sehrish Khan](https://www.paloaltonetworks.com/blog/author/sekhan/?ts=markdown "Posts by Sehrish Khan") and [Maxim Shifrin](https://www.paloaltonetworks.com/blog/author/maxim-shifrin/?ts=markdown "Posts by Maxim Shifrin") Aug 06, 2026 6 minutes [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown) [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown) [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown) [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) # **Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security** The enterprise workforce now operates almost entirely within the web browser. In fact, employees do roughly [85% of their daily work inside it](https://start.paloaltonetworks.com/Omdia-state-of-workforce-security), turning the browser into the sole operating system of the modern organization that connects every application, data interaction, and identity. Yet, for modern Security Operations Center (SOC) teams, the browser remains a frustrating and dangerous "black box." While traditional Extended Detection and Response (XDR) platforms excel at monitoring endpoint hosts and processes, they treat the browser as a single, opaque process. This creates a critical visibility gap. According to research from Unit 42, [over 90% of breaches are preventable](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report) by solving for factors such as visibility gaps. Because modern AI tools are predominantly accessed directly through the browser, it is now critical thatSOCs get visibility into what's happening within the browser. Leaving browser activity unmonitored forces your SOC to fight today's AI-driven workflows in the dark. **The Operational Fallout of Browser Blind Spots** SOC analysts frequently see alerts for malicious endpoint processes but lack the granular telemetry to pinpoint the exact web tab, malicious script, or user interaction that initiated the threat. This leaves incident responders blind to sophisticated tactics like rogue extensions and cross-origin attack chains, making it nearly impossible to reconstruct the full attack narrative. [When a security team operates with a fragmented view](https://www.paloaltonetworks.com/blog/sase/your-browser-is-your-socs-biggest-blind-spot/), a dangerous domino effect triggers the moment an attack strikes. * The root cause is hidden as analysts frequently see alerts for malicious endpoint processes but do not have enough context. Lacking the necessary telemetry, the SOC is forced to take extreme containment measures and completely isolate the entire endpoint machine. * In some cases, SOCs use third party investigation tools which create problems with disconnected context and long investigation times. * What starts as a simple browser blind spot ultimately leads to an aggressive response that unnecessarily halts daily operations, disrupts user productivity, and floods the help desk with tickets. Recent research on Palo Alto Networks customer incidents highlights the sheer scale of this problem, revealing massive monthly volume of Cortex threat detections stemming from siloed browser activity. To eliminate this vulnerability, Palo Alto Networks is thrilled to announce **the native** **integration of** [**Prisma Browser**](https://www.paloaltonetworks.com/sase/prisma-browser)**and** [**Cortex XDR.**](https://www.paloaltonetworks.com/cortex/cortex-xdr) **Cortex XDR and Prisma Browser Better Together** By unifying deep browser-level telemetry with industry-leading endpoint detection, we are providing SOC teams with visibility into the user's primary workspace, transforming the browser from an unmonitored process into an active security sensor. ![Prisma Browser and Cortex XDR Better Together](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-363782-1.png) Figure1: Prisma Browser and Cortex XDR Better Together Organizations can achieve the full benefits of this integration without complex APIs or heavy deployment overhead. Prisma Browser events including DLP violations, browser tampering, and unauthorized configuration updates are automatically fed directly into your Cortex tenant, making it incredibly easy to adopt this joint offering. Moreover, when Cortex XDR raises an issue, browser-based events are correlated with the user's malicious activity on the same endpoint, to add browser-based context and adding visibility to the possible starting point of the attack when it is initiated from the browser context. ## **What Makes Our Approach Different?** Many legacy vendors attempt to solve this problem using brittle, easily bypassed browser extensions that provide basic, surface-level visibility especially providing poor visibility into unmanaged devices. Palo Alto Networks takes a fundamentally different approach. Cortex XDR now integrates natively with Prisma Browser under the hood. This ensures both layers "speak the same language," turning a massive blind spot into a rich engine of security telemetry and visibility into everything from each user action to specific activities into their device posture while executing a particular activity.. True workspace security requires a unified defense system that understands exactly how web activity can impact the host device. This first-of-its-kind integration achieves this through **three fundamental pillars**: ### **1. Find the Root Source of Attacks in Seconds** Integrating Prisma Browser with Cortex XDR connects comprehensive endpoint visibility with deep web context. By seamlessly linking endpoint process execution directly to browser events and host execution, Cortex XDR provides an unprecedented unified data foundation that allows SOC teams to analyze complete attack narratives rather than isolated, disjointed issues. ![SOC Teams Get Insights Into Attack Scenarios with Prisma Browser Investigation Panel](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-363782-2.png) Figure 2: SOC Teams Get Insights Into Attack Scenarios with Prisma Browser Investigation Panel *SOC Teams Get Insights Into Attack Scenarios with Prisma Browser Investigation Panel* **Scenario: Unmasking Phishing and Malware Narratives** When a malicious payload executes on an endpoint, traditional tools show the threat on the host but leave analysts guessing the source of the attack. By correlating Prisma Browser events directly with Cortex XDR eliminates this guesswork. Analysts can effortlessly trace a malware alert back to the exact phishing URL, original download source, or hidden iFrame metadata, uncovering the precise forensic root cause in seconds while easily dismissing false positives. ![Connecting the Dots: Instantly correlate browser activity with endpoint execution for faster response and zero false positives.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-363782-3.png) Figure 3: Connecting the Dots: Instantly correlate browser activity with endpoint execution for faster response and zero false positives. ### **2. Respond Without Disrupting Business** Traditional XDR tools often need to disconnect a device to mitigate a threat. While effective at stopping lateral movement, it severely disrupts user productivity and halts business operations. The integration of Prisma Browser and Cortex XDR introduces granular, precision control. ![Prisma Browser detects a malicious file download, blocks the action and sends a detailed report to the SOC](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-363782-4.png) Figure 4: Prisma Browser detects a malicious file download, blocks the action and sends a detailed report to the SOC For example, when a rogue browser extension attempts to compromise a web session, traditional tools are forced to isolate the device, forcing the employee offline, and disrupting daily operations. The integration of Prisma Browser and Cortex XDR introduces surgical containment instead. The threat is instantly neutralized and terminated only at the browser layer while simultaneously alerting Cortex, allowing the employee's laptop to stay completely online and productive. ### **3. Detect Evasive Threats in Real Time** Prisma Browser uses a pioneering approach to analyze activity in real time, detecting threats as they happen. This ensures that even the most sophisticated, evasive threats, such as rogue extension behavior or malicious script execution, are identified and flagged in real-time within your Cortex dashboard. ![Prisma Browser detects an evasive threat in real time and shows in the Cortex dashboard](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-363782-5.png) Figure 5: Prisma Browser detects an evasive threat in real time and shows in the Cortex dashboard **4. Securing GenAI Use Cases:** As employees rush to adopt GenAI tools, critical risks emerge, such as an engineer copying proprietary source code and pasting it into an unapproved, public AI model to fix a bug. To traditional XDR, this looks like safe, standard web traffic. Prisma Browser solves this by monitoring user behavior inside the workspace to automatically detect and block data loss prevention (DLP) violations in real time. Because it connects natively to the Cortex tenant without complex APIs, shadow AI risks are instantly flagged in the SOC dashboard before they turn into major compliance issues. ## **Future-Proof Your Workspace Security** Security operations can no longer afford to leave the browser unmonitored. By bridging the gap between what happens in the browser and activities on the endpoint, the integration of Prisma Browser and Cortex XDR accelerates investigation times, exposes hidden threats, and allows your SOC to respond with unprecedented precision. **New to Prisma Browser?** [**Talk to your account team**](https://www.paloaltonetworks.com/sase/prisma-browser#product_report_modal) *** ** * ** *** ## Related Blogs ### [Cloud Delivered Security Services](https://www.paloaltonetworks.com/blog/network-security/category/cloud-delivered-security-services/?ts=markdown), [Cloud NGFW](https://www.paloaltonetworks.com/blog/network-security/category/cloud-ngfw/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Palo Alto Networks Collaborates with Google Cloud to Redefine Protection Against AI-Generated Malware](https://origin-researchcenter.paloaltonetworks.com/blog/network-security/palo-alto-networks-google-cloud-ai-malware-protection/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### What's New in Cortex](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/whats-new-in-cortex-july-2026/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Partner Integrations](https://www.paloaltonetworks.com/blog/security-operations/category/partner-integrations/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Securing the AI Factory: Empowering Security Teams with In-Silicon Visibility](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/securing-the-ai-factory-empowering-security-teams-with-in-silicon-visibility/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Cortex ITDR: Detecting Cyber threats in Google Workspace](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/cyberthreats-in-google-workspace-and-their-detection/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Breaking Down Security Silos: How XDL Powers Advanced Threat Operations](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/breaking-down-security-silos-how-xdl-powers-advanced-threat-operations/) ### [Partner Integrations](https://www.paloaltonetworks.com/blog/sase/category/partner-integrations/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Palo Alto Networks \& Dell Join Forces for a Modern SD-WAN Solution](https://origin-researchcenter.paloaltonetworks.com/blog/sase/palo-alto-networks-dell-join-forces-for-a-modern-sd-wan-solution/) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://origin-researchcenter.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language