This course teaches security analysts how to investigate and analyze threats using Palo Alto Networks Cortex XDR. You will learn to conduct thorough threat investigations, analyze attack chains, perform root cause analysis, and correlate data from endpoints, networks, and cloud environments using Cortex XDR’s analytics and investigation capabilities.
Who Should Attend
SOC analysts, threat hunters, and incident responders who use Palo Alto Networks Cortex XDR for security investigations.
Prerequisites
- Understanding of cybersecurity incident response fundamentals
- Experience with security operations or endpoint detection and response (EDR) tools
Course Objectives
- Navigate the Cortex XDR incident and investigation workflow
- Analyze causality chains and attack sequences using XDR analytics
- Perform threat hunting using behavioral analytics and indicators
- Conduct root cause analysis and document investigation findings




