{"id":109833,"date":"2020-04-22T06:00:01","date_gmt":"2020-04-22T13:00:01","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=109833"},"modified":"2020-07-30T19:54:54","modified_gmt":"2020-07-31T02:54:54","slug":"cortex-network-visibility","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2020\/04\/cortex-network-visibility\/","title":{"rendered":"Cortex XDR Further Extends Network Visibility and Endpoint Control"},"content":{"rendered":"<p><div style=\"max-width:100%\" data-width=\"775\"><span class=\"ar-custom\" style=\"padding-bottom:58.32%;\"><img loading=\"lazy\" decoding=\"async\"  class=\" wp-image-109834 aligncenter lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/04\/Cortex-fire.png\" alt=\"This conceptual image illustrates the concepts of the extended network visibility and endpoint control in Cortex XDR 2.2.\" width=\"775\" height=\"452\" \/><\/span><\/div><\/p>\n<p><span style=\"font-weight: 400;\">Threat hunting and response across data sources just got a little easier. Cortex XDR application and agent releases in March and April introduce an amazing array of new features to help your security team identify threats in network traffic, orchestrate response at scale and reduce the attack surface of their endpoints.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With so many new features, where do we begin? Let\u2019s start with the network viewpoint.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>Enhanced Network Visibility\u00a0<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Since its inception, Cortex XDR could <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/03\/cortex-busted-by-cortex-xdr\/\"><span style=\"font-weight: 400;\">collect network data<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/03\/cortex-ai\/\"><span style=\"font-weight: 400;\">apply behavioral analytics and AI to uncover attacks<\/span><\/a><span style=\"font-weight: 400;\">. Now, Cortex XDR extends direct access to network data for threat hunting and custom detection rules. With Cortex XDR, you can:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Hunt for threats or further investigations by <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/02\/cortex-network-traffic-analysis\/\"><span style=\"font-weight: 400;\">exploring network traffic logs<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Create granular custom detection rules (BIOCs) based on network data.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Quickly determine the sequence and scope of an attack by reviewing network and endpoint data together in a new investigation view.<\/span><\/li>\n<\/ul>\n<figure id=\"attachment_109847\" aria-describedby=\"caption-attachment-109847\" style=\"width: 1025px\" class=\"wp-caption aligncenter\"><div style=\"max-width:100%\" data-width=\"1025\"><span class=\"ar-custom\" style=\"padding-bottom:64.2%;\"><img loading=\"lazy\" decoding=\"async\"  class=\" wp-image-109847 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/04\/workgroup.png\" alt=\"The new investigation view in Cortex XDR 2.2 displays both network and endpoint context in one place, when both types of data are available. \" width=\"1025\" height=\"658\" \/><\/span><\/div><figcaption id=\"caption-attachment-109847\" class=\"wp-caption-text\">The Network Causality investigation view displays both network and endpoint context in one place, when both types of data are available. It reveals the endpoint activity for multiple hosts involved in an attack, simplifying analysis of adversary techniques.<\/figcaption><\/figure>\n<h4><b>Cortex XDR Agent Script Execution and More<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">There are times when your analysts may need to perform sweeping actions across multiple endpoints at once. Whether collecting endpoint information, updating settings or immediately stopping fast-spreading attacks, remote script execution provides your team a powerful tool to manage endpoints.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With Cortex XDR agent 7.1 for Windows, MacOS, and Linux, you can run Python 3.7 scripts from the Cortex XDR management console and instantly see the results. A new API allows you to execute Python scripts from management and orchestration tools such as Cortex XSOAR. Out-of-the-box scripts make it easy for your team to take advantage of this powerful new feature.<\/span><\/p>\n<figure id=\"attachment_109860\" aria-describedby=\"caption-attachment-109860\" style=\"width: 1025px\" class=\"wp-caption aligncenter\"><div style=\"max-width:100%\" data-width=\"1025\"><span class=\"ar-custom\" style=\"padding-bottom:58.44%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"wp-image-109860 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/04\/define-action.png\" alt=\"A screenshot of the management console in Cortex XDR 2.2\" width=\"1025\" height=\"599\" \/><\/span><\/div><figcaption id=\"caption-attachment-109860\" class=\"wp-caption-text\">Your analysts can easily upload and run scripts from the Cortex XDR management console.<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">Cortex XDR agent 7.1 also introduces important new features that secure your endpoints, address compliance requirements and make it easier than ever for you to replace your legacy antivirus with <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2019\/12\/cortex-what-is-xdr\/\"><span style=\"font-weight: 400;\">extended detection and response<\/span><\/a><span style=\"font-weight: 400;\">. New endpoint security features include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">A host firewall for Windows endpoints.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Disk encryption for Windows endpoints.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">File scanning for macOS endpoints.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">MAC address reporting.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Full visibility into agent operational status.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h4><b>MITRE ATT&amp;CK Tagging for Alerts and BIOC Rules<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">To help your analysts understand attackers\u2019 methods and objectives at each stage of an attack, Cortex XDR now displays the associated MITRE ATT&amp;CK technique and tactic for every alert that relates to the MITRE ATT&amp;CK framework. <\/span><\/p>\n<figure id=\"attachment_109873\" aria-describedby=\"caption-attachment-109873\" style=\"width: 1025px\" class=\"wp-caption aligncenter\"><div style=\"max-width:100%\" data-width=\"1025\"><span class=\"ar-custom\" style=\"padding-bottom:41.95%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"wp-image-109873 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/04\/mitre.png\" alt=\"A screenshot of the dashboard that displays the top MITRE ATT&amp;CK techniques and tactics associated with Cortex XDR alerts. \" width=\"1025\" height=\"430\" \/><\/span><\/div><figcaption id=\"caption-attachment-109873\" class=\"wp-caption-text\">A new dashboard displays the top MITRE ATT&amp;CK techniques and tactics associated with Cortex XDR alerts.<\/figcaption><\/figure>\n<h4><b>Granular Role-Based Access Control (RBAC)<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">For fine-grained control of individual permissions assigned to users and roles, Cortex XDR now separates what type of views and actions are permitted for each role. Roles are defined in the hub and allow customers to create and save new roles based on a broad set of permissions, edit role permissions, and more.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>Alert and Log Forwarding from Cortex XDR\u00a0<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">You can configure forwarding policies for alerts, management audit logs, agent audit logs and dashboard reports from the Cortex XDR application.\u00a0You can also now forward alerts to Slack channels and Syslog servers, in addition to email accounts, and forward audit logs to Syslog servers.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>Broker VM Enhancements<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">To ease the<\/span> <a href=\"https:\/\/docs.paloaltonetworks.com\/cortex\/cortex-xdr\/cortex-xdr-pro-admin\/get-started-with-cortex-xdr-pro\/set-up-broker-vm.html\"><span style=\"font-weight: 400;\">deployment of the Broker VM<\/span><\/a><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">you can download the Broker VM images directly from the Cortex XDR management console. The registration and configuration are managed through the following web consoles:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><b>Broker web console<\/b><span style=\"font-weight: 400;\">: You can configure and register the Broker VM to Cortex XDR from the web console without needing to access the Broker VM directly.<\/span><\/li>\n<li style=\"font-weight: 400;\"><b>Cortex XDR management console:<\/b><span style=\"font-weight: 400;\"> You can manage Broker VM settings through the Cortex XDR management console, including tracking connectivity, editing configurations and enabling realtime monitoring.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h4><b>Improved Manageability for MSSPs<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Cortex XDR now allows Managed Security Services Providers (MSSPs) to easily manage security on behalf of their clients. MSSPs can now:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Configure profiles, behavioral alert (BIOC) rules, exclusions and starred alerts for each child tenant.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">View alerts, incidents, causality cards and timelines of child tenants from the parent tenant.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Run investigation queries on child tenants from the parent tenant.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">The above features are available with the Cortex XDR agent release 7.1 and later and with Cortex XDR version 2.2 and later.\u00a0 In addition to the features listed above, Cortex XDR includes updates that improve usability, simplify tuning and deployment, enhance APIs, and accelerate analysts\u2019 tasks. For a complete list of new features introduced in March and April, see the<\/span> <a href=\"https:\/\/docs.paloaltonetworks.com\/cortex\/cortex-xdr\/cortex-xdr-release-notes\/release-information\/features-introduced\/features-introduced-in-2020.html#iddb59f5e7-aac3-4e46-a08d-ab6f7a304416\"><span style=\"font-weight: 400;\">Cortex XDR release notes<\/span><\/a><span style=\"font-weight: 400;\">\u00a0and the <a href=\"https:\/\/docs.paloaltonetworks.com\/cortex\/cortex-xdr\/7-1\/cortex-xdr-agent-release-notes\/cortex-xdr-agent-release-information\/features-introduced-in-cortex-agent.html\">Cortex XDR agent release notes<\/a>.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cortex XDR enhances network visibility and endpoint control, making threat hunting and response across data sources easier.<\/p>\n","protected":false},"author":370,"featured_media":109834,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6770],"tags":[6737,532,6971],"coauthors":[3907],"class_list":["post-109833","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-future","tag-cortex-xdr","tag-endpoint","tag-network-visibility","sec_ops_category-product-features"],"jetpack_featured_media_url":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/04\/Cortex-fire.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/109833","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/370"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=109833"}],"version-history":[{"count":4,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/109833\/revisions"}],"predecessor-version":[{"id":110134,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/109833\/revisions\/110134"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/109834"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=109833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=109833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=109833"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=109833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}