Palo Alto Networks Takes On Identity Attacks, Extends its Cortex XSIAM Platform with AI-driven Identity Threat Detection and Response
Palo Alto Networks (NASDAQ: PANW) announced the launch of its new Identity Threat Detection and Response (ITDR) module for Cortex XSIAM on March 6, 2023. This module enhances security by allowing customers to analyze user identity and behavior data to detect identity-driven attacks swiftly. ITDR consolidates multiple security functions into a single AI-powered platform, reducing complexity in security operations centers (SOCs). By integrating various data sources, it offers comprehensive threat detection and addresses insider risks. The move aligns with growing cybersecurity needs as identity-driven attacks become more prevalent.
- Launch of ITDR module enhances Cortex XSIAM's capabilities.
- Consolidation of multiple security tools into a unified platform.
- AI-driven detection improves response time to potential threats.
- None.
XSIAM enables security teams to further consolidate disparate SOC products
Identity-driven attacks, which target user credentials to access confidential data and systems, are one of the most common methods cyber criminals use to breach organizations' networks. For example, in recent years Lapsus$ Group has used privileged user credentials to attack multiple government agencies, as well as multiple large technology companies.
"Today, customers who want to detect identity-related attacks must deploy multiple tools – UEBA, Insider Risk Management, endpoint-based ITDR, etc. – each providing a partial view into user activities," said
The ITDR module ingests and integrates user behavior data, such as what times an employee typically works, and which applications and data they usually access. It processes data from a variety of sources, including authentication services, endpoint logs, cloud identity data, email and HR data, as well as network, OS, and custom sources. The built-in AI models can then be trained to flag suspicious activity based on irregular user behavior, getting ahead of prominent insider risks such as configuration manipulation, file manipulation, modification of permissions.
In addition to yielding stronger security outcomes, the addition of ITDR to Cortex XSIAM further reduces complexity in the SOC by tightly integrating identity analytics into a unified SOC platform. Cortex XSIAM already natively integrates security information and event management (SIEM), endpoint detection and response (EDR), network detection and response (NDR), security, orchestration and response (SOAR), Threat Intelligence Management (TIM) and Attack Surface management (ASM) capabilities, replacing the need for multiple point solutions.
"The ability to process large amounts of data and handle potential threats in real-time has become a major problem as the cybersecurity landscape has evolved," said
Follow
About
At
View original content to download multimedia:https://www.prnewswire.com/news-releases/palo-alto-networks-takes-on-identity-attacks-extends-its-cortex-xsiam-platform-with-ai-driven-identity-threat-detection-and-response-301762982.html
SOURCE
FAQ
What is the new feature launched by Palo Alto Networks on March 6, 2023?
How does the ITDR module improve security for Palo Alto Networks customers?
What impact does the ITDR module have on security operations centers (SOCs)?