* [Blog](https://origin-researchcenter.paloaltonetworks.com/blog) * [Security Operations](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/) * [AI and Cybersecurity](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/) * Beyond the SEG: Why Singl... # Beyond the SEG: Why Single-Domain Email Defenses Break Down in the Modern SOC [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fbeyond-the-seg-why-single-domain-email-defenses-break-down-in-the-modern-soc%2F) [](https://twitter.com/share?text=Beyond+the+SEG%3A+Why+Single-Domain+Email+Defenses+Break+Down+in+the+Modern+SOC&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fbeyond-the-seg-why-single-domain-email-defenses-break-down-in-the-modern-soc%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fbeyond-the-seg-why-single-domain-email-defenses-break-down-in-the-modern-soc%2F&title=Beyond+the+SEG%3A+Why+Single-Domain+Email+Defenses+Break+Down+in+the+Modern+SOC&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/beyond-the-seg-why-single-domain-email-defenses-break-down-in-the-modern-soc/&ts=markdown) \[\](mailto:?subject=Beyond the SEG: Why Single-Domain Email Defenses Break Down in the Modern SOC) Link copied By [Sehrish Khan](https://www.paloaltonetworks.com/blog/author/sehrish-khan/?ts=markdown "Posts by Sehrish Khan") and [Guy Mazaltrim](https://www.paloaltonetworks.com/blog/author/guy-mazaltrim/?ts=markdown "Posts by Guy Mazaltrim") Sep 10, 2026 10 minutes [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown) [AI Security](https://www.paloaltonetworks.com/blog/cloud-security/category/ai-security/?ts=markdown) [Cloud Workload Protection Platform](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-workload-protection-platform/?ts=markdown) [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown) [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown) [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [Business Email Compromise (BEC)](https://www.paloaltonetworks.com/blog/tag/business-email-compromise-bec/?ts=markdown) [Cyber AI \& Phishing](https://www.paloaltonetworks.com/blog/tag/cyber-ai-phishing/?ts=markdown) [Email Security](https://www.paloaltonetworks.com/blog/tag/email-security/?ts=markdown) [Extended Detection and Response (XDR)](https://www.paloaltonetworks.com/blog/tag/extended-detection-and-response-xdr/?ts=markdown) [Integrated Cloud Email Security (ICES)](https://www.paloaltonetworks.com/blog/tag/integrated-cloud-email-security-ices/?ts=markdown) [SOC Operations](https://www.paloaltonetworks.com/blog/tag/soc-operations/?ts=markdown) [Threat Detection \& Response](https://www.paloaltonetworks.com/blog/tag/threat-detection-response/?ts=markdown) # **Beyond the SEG: Why Single-Domain Email Defenses Break Down in the Modern SOC** Generative AI has fundamentally rewritten the rules of social engineering. Using Large Language Models (LLMs), adversaries now automate open-source intelligence collection ingesting corporate org charts, executive speaking schedules, and vendor communications to construct hyper-personalized, context-aware attacks at scale. Because these messages carry no malicious binaries, contain zero bad URLs, and feature pristine header profiles, they exploit a fundamental weakness in enterprise architecture: treating email security as a single, isolated domain. ### **Why Modern SEGs and ICES Vendors Both Fall Short** To defend against these threats, the industry's initial response was to upgrade perimeter controls. Modern **Secure Email Gateways (SEGs)** have evolved far beyond basic signatures and regex rules, incorporating machine learning, dynamic sandboxing, and behavioral heuristics. However, SEGs remain constrained by their inline architectural position at the mail boundary. Operating outside the cloud tenant, SEGs lack deep visibility into internal employee-to-employee communications, historical cloud collaboration patterns, and post-delivery account dynamics. To bridge this gap, organizations turned to **Integrated Cloud Email Security (ICES)** platforms. Connecting directly to cloud environments like Microsoft 365 via APIs, ICES tools brought significant advancements. By leveraging Natural Language Processing (NLP) and behavioral profiling, ICES solutions analyze email context to spot Business Email Compromise (BEC) and enable post-delivery remediation. Yet, even as ICES vendors apply sophisticated AI models to incoming mail, they increasingly struggle to keep pace with modern attacker tactics, techniques, and procedures (TTPs). Attackers now train their own AI models to systematically evade ICES detection baselines obfuscating semantic cues, leveraging compromised legitimate partner accounts, and executing multi-channel attacks that split the lure across email, SMS, and collaboration apps. According to **Gartner's Market Guide for Email Security**, while API-integrated ICES tools provide critical behavioral context, evaluating sender intent strictly within the email platform leaves critical gaps. Gartner highlights that as adversaries refine AI tools to bypass mailbox baselines, email telemetry can no longer exist as a standalone silo, it must be integrated into broader detection and response frameworks like Extended Detection and Response (XDR). Because standalone ICES detection models operate strictly within the email application, they must judge an email's legitimacy using mailbox telemetry alone. When an attacker successfully mimics legitimate business conversation from a trusted partner, an isolated ICES model has no additional data points to disprove it. ### **The Silo Penalty: Telemetry Blind Spots and Operational Friction** For modern Security Operations Center (SOC) teams, inspecting email telemetry in an isolated domain creates dangerous operational blind spots during an active intrusion. While an ICES solution can analyze the tone or sentiment of an incoming message, it remains completely blind to post-delivery behavior unable to track whether the recipient executed an anomalous PowerShell command on their host two minutes later, detect a concurrent high-risk login via Microsoft Entra ID from an unfamiliar location, or cross-reference out-of-band network connections triggered by a credential-harvesting site. Consequently, when an account compromise occurs, analysts are forced to waste critical minutes pivoting between disconnected consoles to manually correlate logs across email platforms, Identity Threat Detection and Response (ITDR), Endpoint Detection and Response (EDR), and Network Detection and Response (NDR). This reliance on standalone email security tools floods the SOC queue with isolated, low-fidelity alerts, driving up alert fatigue and inflating Mean Time to Respond (MTTR) while adversaries pivot laterally across the enterprise environment. ![Highlighting telemetry gaps between standalone email tools and endpoint/identity consoles](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/09/word-image-367646-1.png) *Highlighting telemetry gaps between standalone email tools and endpoint/identity consoles* **The Paradigm Shift: From Mailbox Filtering to Continuous Correlation** To defend against fast-moving, AI-driven campaigns, organizations must shift from isolated mail filtering to continuous, cross-domain threat correlation. Evaluating sender intent in isolation is no longer sufficient; message metadata and contextual signals must be correlated in real time alongside endpoint telemetry, network flows, and identity risk state. ![SOC workflow showing unified alert ingestion across email, identity, and endpoint agents](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/09/word-image-367646-2.png) *SOC workflow showing unified alert ingestion across email, identity, and endpoint agents* In their analysis of modern email threat dynamics, **Gartner** explicitly notes that *"humans are increasingly incapable of identifying social engineering attacks as LLMs are refined for purpose by attackers."* To compensate, analysts recommend that enterprise security leaders shift focus toward architectures that unify email telemetry with broader SOC telemetry---allowing AI engines to analyze cross-domain behavioral signals rather than relying solely on mailbox-level detection. ### **Unified Threat Correlation: Expanding Beyond Point Solutions** Integrating email telemetry directly into the broader SOC architecture transforms detection and response. Rather than relying on isolated mail filters, intent-based AI detection leverages behavioral analytics and language models directly within the unified SOC data foundation. This multi-signal correlation provides analysts with immediate, end-to-end attack path visualization. For example, if an employee receives an unusual financial authorization request, the SOC platform automatically correlates the email context against host process executions and identity authentication spikes to confirm whether an account takeover has occurred. Crucially, unifying this data enables automated, cross-domain containment workflows. Once a threat is validated, automated playbooks can execute coordinated response actions simultaneously across the entire enterprise stack quarantining the email message, revoking active user sessions, terminating malicious host processes, and isolating the affected endpoint via EDR. Treating email security as a standalone layer whether through a gateway or an isolated ICES vendor leaves critical gaps in enterprise defense. Resilience against modern, AI-assisted cyberthreats requires embedding email signals directly into the core detection and response pipeline. By unifying email telemetry with identity, endpoint, and network data through Cortex Advanced Email Security, security teams gain the full-stack visibility and automated control needed to stop multi-stage attacks before they escalate into major incidents. To explore how Advanced Email Security unifies email telemetry with Cortex XDR to stop phishing and streamline triage, visit our solution page [here](https://www.paloaltonetworks.com/cortex/advanced-email-security). Generative AI has fundamentally rewritten the rules of social engineering. Using Large Language Models (LLMs), adversaries now automate open-source intelligence collection ingesting corporate org charts, executive speaking schedules, and vendor communications to construct hyper-personalized, context-aware attacks at scale. Because these messages carry no malicious binaries, contain zero bad URLs, and feature pristine header profiles, they exploit a fundamental weakness in enterprise architecture: treating email security as a single, isolated domain. ### **Why Modern SEGs and ICES Vendors Both Fall Short** To defend against these threats, the industry's initial response was to upgrade perimeter controls. Modern **Secure Email Gateways (SEGs)** have evolved far beyond basic signatures and regex rules, incorporating machine learning, dynamic sandboxing, and behavioral heuristics. However, SEGs remain constrained by their inline architectural position at the mail boundary. Operating outside the cloud tenant, SEGs lack deep visibility into internal employee-to-employee communications, historical cloud collaboration patterns, and post-delivery account dynamics. To bridge this gap, organizations turned to **Integrated Cloud Email Security (ICES)** platforms. Connecting directly to cloud environments like Microsoft 365 via APIs, ICES tools brought significant advancements. By leveraging Natural Language Processing (NLP) and behavioral profiling, ICES solutions analyze email context to spot Business Email Compromise (BEC) and enable post-delivery remediation. Yet, even as ICES vendors apply sophisticated AI models to incoming mail, they increasingly struggle to keep pace with modern attacker tactics, techniques, and procedures (TTPs). Attackers now train their own AI models to systematically evade ICES detection baselines obfuscating semantic cues, leveraging compromised legitimate partner accounts, and executing multi-channel attacks that split the lure across email, SMS, and collaboration apps. According to **Gartner's Market Guide for Email Security** , while API-integrated ICES tools provide critical behavioral context, evaluating sender intent strictly within the email platform leaves critical gaps. Gartner highlights that as adversaries refine AI tools to bypass mailbox baselines, email telemetry can no longer exist as a standalone silo, it must be integrated into broader detection and response frameworks like Extended Detection and Response (XDR). Because standalone ICES detection models operate strictly within the email application, they must judge an email's legitimacy using mailbox telemetry alone. When an attacker successfully mimics legitimate business conversation from a trusted partner, an isolated ICES model has no additional data points to disprove it. ### **The Silo Penalty: Telemetry Blind Spots and Operational Friction** For modern Security Operations Center (SOC) teams, inspecting email telemetry in an isolated domain creates dangerous operational blind spots during an active intrusion. While an ICES solution can analyze the tone or sentiment of an incoming message, it remains completely blind to post-delivery behavior unable to track whether the recipient executed an anomalous PowerShell command on their host two minutes later, detect a concurrent high-risk login via Microsoft Entra ID from an unfamiliar location, or cross-reference out-of-band network connections triggered by a credential-harvesting site. Consequently, when an account compromise occurs, analysts are forced to waste critical minutes pivoting between disconnected consoles to manually correlate logs across email platforms, Identity Threat Detection and Response (ITDR), Endpoint Detection and Response (EDR), and Network Detection and Response (NDR). This reliance on standalone email security tools floods the SOC queue with isolated, low-fidelity alerts, driving up alert fatigue and inflating Mean Time to Respond (MTTR) while adversaries pivot laterally across the enterprise environment. *Image 1. Highlighting telemetry gaps between standalone email tools and endpoint/identity consoles* **The Paradigm Shift: From Mailbox Filtering to Continuous Correlation** To defend against fast-moving, AI-driven campaigns, organizations must shift from isolated mail filtering to continuous, cross-domain threat correlation. Evaluating sender intent in isolation is no longer sufficient; message metadata and contextual signals must be correlated in real time alongside endpoint telemetry, network flows, and identity risk state. *Image 2. SOC workflow showing unified alert ingestion across email, identity, and endpoint agents* In their analysis of modern email threat dynamics, **Gartner** explicitly notes that *"humans are increasingly incapable of identifying social engineering attacks as LLMs are refined for purpose by attackers."* To compensate, analysts recommend that enterprise security leaders shift focus toward architectures that unify email telemetry with broader SOC telemetry---allowing AI engines to analyze cross-domain behavioral signals rather than relying solely on mailbox-level detection. ### **Unified Threat Correlation: Expanding Beyond Point Solutions** Integrating email telemetry directly into the broader SOC architecture transforms detection and response. Rather than relying on isolated mail filters, intent-based AI detection leverages behavioral analytics and language models directly within the unified SOC data foundation. This multi-signal correlation provides analysts with immediate, end-to-end attack path visualization. For example, if an employee receives an unusual financial authorization request, the SOC platform automatically correlates the email context against host process executions and identity authentication spikes to confirm whether an account takeover has occurred. Crucially, unifying this data enables automated, cross-domain containment workflows. Once a threat is validated, automated playbooks can execute coordinated response actions simultaneously across the entire enterprise stack quarantining the email message, revoking active user sessions, terminating malicious host processes, and isolating the affected endpoint via EDR. Treating email security as a standalone layer whether through a gateway or an isolated ICES vendor leaves critical gaps in enterprise defense. Resilience against modern, AI-assisted cyberthreats requires embedding email signals directly into the core detection and response pipeline. By unifying email telemetry with identity, endpoint, and network data through Cortex Advanced Email Security, security teams gain the full-stack visibility and automated control needed to stop multi-stage attacks before they escalate into major incidents. To explore how Advanced Email Security unifies email telemetry with Cortex XDR to stop phishing and streamline triage, visit our solution page [here](https://www.paloaltonetworks.com/cortex/advanced-email-security). *** ** * ** *** ## Related Blogs ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown), [Unit 42](https://unit42-dev2.paloaltonetworks.com) [#### The Case for Multidomain Visibility](https://origin-researchcenter.paloaltonetworks.com/blog/2025/10/case-for-multidomain-visibility/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Cortex XDR Scores Perfect 100% in SE Labs 2026 Ransomware Test](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/cortex-xdr-scores-perfect-100-in-se-labs-2026-ransomware-test/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Identity Meets the SOC: Redefining the Last Perimeter](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/identity-meets-the-soc-redefining-the-last-perimeter/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Public Sector](https://www.paloaltonetworks.com/blog/category/public-sector/?ts=markdown), [Quantum Security](https://www.paloaltonetworks.com/blog/network-security/category/quantum-security/?ts=markdown) [#### NIST and PQC Readiness: Managing the Quantum-Safe Shift](https://origin-researchcenter.paloaltonetworks.com/blog/network-security/nist-and-pqc-readiness-managing-the-quantum-safe-shift/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Cloud NGFW](https://www.paloaltonetworks.com/blog/network-security/category/cloud-ngfw/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Data Security](https://www.paloaltonetworks.com/blog/cloud-security/category/data-security/?ts=markdown), [Machine Identity Security](https://www.paloaltonetworks.com/blog/identity-security/category/machine-identity-security/?ts=markdown) [#### Inside Black Hat Asia 2026: What We Learned from Deploying Quantum-safe Security](https://origin-researchcenter.paloaltonetworks.com/blog/network-security/inside-black-hat-asia-2026/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown) [#### How Mythos-Class Models Change Exposure Management](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/how-mythos-class-models-change-exposure-management/) ### Subscribe to Security Operations Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://origin-researchcenter.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language