Use Cases and Deployment Scope
Palo Alto Networks Cortex XDR is used in our organization to gain the better visibility in terms of networks, cloud, endpoint. it provide the single pane of glass visibility where user don't have to go tab by tab for multiple tool, rather than that they get the visibility from a single console. It reduce the mean time to detect and respond. Before we are facing the challenge that in a single day analyst are getting more than 500 alerts. The analyst not able to identicy which one is false positive and which one true positive this bring that a single analyst is busy on a single incident for 1-2 hour. Meanwhile the most important and priority aleert get breached. So Palo Alto Networks Cortex XDR bring the feature of case which bring same type of incidents into a single case which reduce the alert noise as well as analyst do not have to focus on a single alert rather than that they investigate a case and that investigation can solve 15 or more alerts from a single case. It also provides the RBAC which help admin to provide the necessary permission to analyst, admin, investigator etc. Previously if we have to get the visibility of application, autoruns, registry etc then we have to check individual endpoint on by one but from Palo Alto Networks Cortex XDR host insights model we get all this type of visibility from a single console. its also providing the Vulnerability management platform which help admin to get visibility of vulnerability of assets, OS even of application. It is the one solution which provides GUI based live terminal where admin can get the visibility of drive, folders, file and can also download it over from console of specific endpoint. Even we can also run python code, script and also get visibility of task manager and we can end process from task manager from Live terminal only. So we do not need to go one by one on every endpoint rather we can manage and get visibility of all this thing from a single console.
Alternatives Considered
SentinelOne Singularity, CrowdStrike Falcon and Trend Micro Deep Security
Other Software Used
VirusTotal, Forcepoint DSPM, Microsoft 365