Category Archives: Cybersecurity
Cortex XSIAM automation connects security issues and events to playbooks, Quick Actions, jobs, connectors, and—currently in Preview for selected tenants—Agentic Response actions. Automation rules define trigger conditions and the action to run when an issue matches. The execution model matters: current Cortex XSIAM documentation notes that automated executions triggered by rules, jobs, or feed-triggered actions […]
Cortex XSIAM data modeling normalizes logs from different vendors and products into a shared XSIAM Data Model (XDM) so analysts, correlation rules, dashboards, and detections can query consistent fields instead of memorizing every source schema. Current XSIAM provides a published XDM schema with typed fields, constants, and aliases such as IP, user, file hash, domain, […]
Cortex XSIAM detection engineering combines several detection mechanisms: IOC rules for known indicators, BIOCs for behavioral conditions, scheduled XQL correlation rules for relationships across events and time, and analytics rules produced by the platform’s behavioral analytics engines. Current XSIAM 3.x documentation exposes these under Threat Management and Analytics, with MITRE ATT&CK coverage views, correlation-rule monitoring, […]
A Software Bill of Materials (SBOM) is a machine-readable inventory of software components and their supply-chain relationships. It helps software producers, purchasers, and operators answer which libraries, packages, versions, licenses, and dependencies are present in a product so newly disclosed vulnerabilities or licensing issues can be mapped to affected software faster. In 2025 CISA published […]
Prisma Access Explicit Proxy is a cloud Secure Web Gateway connection method that redirects proxy-aware HTTP and HTTPS traffic to Prisma Access using PAC files, forwarding profiles, GlobalProtect proxy mode, Prisma Agent transparent proxy, or supported proxy-chaining patterns. It is designed for organizations migrating from legacy explicit proxies or needing browser/SaaS web traffic inspection without […]
A Cloud Access Security Broker (CASB) provides visibility and policy control between enterprise identities/devices and cloud applications. Modern CASB capabilities usually span shadow-IT discovery, API-based SaaS inspection, data-loss prevention, threat detection, OAuth/app governance, posture assessment, and inline access or session controls. A production deployment normally combines several patterns because no single integration sees unmanaged apps, […]
Prisma Access protects mobile users through two main connection models: GlobalProtect and Explicit Proxy. Current Palo Alto Networks documentation describes GlobalProtect tunnel mode as the default full-tunnel agent mode for securing all applications, ports, and protocols, while Explicit Proxy focuses on Secure Web Gateway-style proxy traffic. The mobile-user architecture also ties together portal/gateway configuration, authentication, […]
Certificate pinning restricts a client so it accepts only a predefined certificate, public key, or key hash for a server rather than trusting the normal public certificate-authority ecosystem alone. Pinning can reduce exposure to a compromised or malicious CA, but modern platform guidance increasingly warns that the operational outage risk often outweighs the incremental security […]
Strata Logging Service is Palo Alto Networks’ cloud-delivered log storage and aggregation platform for network and security products. It is the current name for Cortex Data Lake. The service ingests logs from Prisma Access, on-premises and virtual NGFWs, Cloud NGFW, and supported Cortex/other Palo Alto Networks services, stores them in a scalable cloud infrastructure, makes […]
DMARC—Domain-Based Message Authentication, Reporting, and Conformance—lets a domain owner publish how receivers should evaluate mail that uses the domain in the visible From: header, with validation based on aligned SPF or DKIM authentication. In May 2026 the IETF replaced the original RFC 7489 with a new standards-track DMARC set: RFC 9989 defines the protocol, RFC […]
The approved title uses “detection rules,” but current FortiAnalyzer terminology centers on event handlers. Basic event handlers generate events when one of their rules matches, while correlation event handlers generate events when a sequence or combination of rules matches using operators such as AND, AND_NOT, OR, FOLLOWED_BY, and NOT_FOLLOWED_BY. FortiAnalyzer includes predefined handlers, lets teams […]
Log retention for investigations is the engineering decision that determines how far incident responders can look back when they discover a compromise. There is no universal retention period that fits every organization or log type. Retention should reflect threat dwell time, investigation/recovery needs, legal and regulatory requirements, storage cost, data sensitivity, and how quickly logs […]
Amazon EKS Pod Identity maps an IAM role to a Kubernetes service account without requiring an IAM OIDC provider or service-account annotation. An EKS Pod Identity association is created through the EKS control plane for a specific cluster, namespace, and service account. The EKS Pod Identity Agent on Linux EC2 worker nodes supplies temporary credentials […]
Amazon GuardDuty Malware Protection adds malware scanning to GuardDuty’s threat-detection workflow for EC2/EBS workloads and S3 objects. For EC2, GuardDuty can initiate an agentless scan of attached EBS volumes after certain findings or on demand by creating snapshots and scanning replica volumes in the GuardDuty service account. For S3, GuardDuty scans newly uploaded objects in […]
AWS Network Firewall policy design determines how packets move from stateless inspection into the stateful Suricata engine, which rule groups evaluate them, what default actions apply, and whether TLS inspection or other stateful settings affect connection handling. A firewall policy is reusable across firewalls, so one design choice can influence several VPC inspection points at […]