Palo Alto Cortex XDR: Investigation and Analysis

What's In It For Me

Extended detection and response (XDR) is central to modern security operations, helping teams investigate threats across endpoints, networks, and cloud environments with greater speed and context. Palo Alto Cortex XDR: Investigation & Analysis equips cybersecurity professionals with hands-on expertise in endpoint management, case management, forensic analysis, log analysis, and platform automation.


This 2-day instructor-led course explores the core capabilities of Cortex XDR, from investigating alerts and analysing causality chains to using XQL queries to uncover meaningful security insights. Participants gain the knowledge and practical skills needed to investigate incidents efficiently, improve analysis workflows, and support stronger security operations.


Course Overview

Scope

  1. Course level: Intermediate
  2. Course duration: 2 days
  3. Course format: Instructor-led Training with Hands-on Simulations
  4. Platform support: Cortex



Training Type

Full-Time


Who Should Attend

This course is designed for cybersecurity professionals who work in security operations, incident investigation, and threat detection environments.


It is suitable for:

  1. SOC analysts and managers
  2. CERT and CSIRT professionals
  3. XDR analysts
  4. Security analysts
  5. Incident responders
  6. Threat hunters
  7. Professional services consultants
  8. Sales engineers
  9. Service delivery partners





Course Duration

2 days


Course Outline

Module 1: Introduction to Cortex XDR

Module 2: Endpoints

Module 3: XQL

Module 4: Alerting and Detection

Module 5: Vulnerability and Forensics

Module 6: Platform Automation

Module 7: Case Management

Module 8: Dashboards & Reports



Course Objectives

By the end of this course, participants will be able to:

  1. Investigate Cortex XDR cases and analyse key assets, artefacts, and causality chains.
  2. Query and analyse logs using XQL to extract meaningful insights.
  3. Use advanced Cortex XDR tools and resources for comprehensive case analysis.
  4. Manage endpoints and work with alerts, detections, vulnerabilities, and forensic data.
  5. Navigate case management, dashboards, reporting, and platform automation workflows.



Pre-requisitess

Participants should have a foundational understanding of cybersecurity principles and experience analysing security incidents or using security tools for investigation. Familiarity with SOC processes, alerts, endpoint security, and incident-response workflows will be beneficial.


Medium of Instruction & Trainer

English


Price
Course Fee Payable
Original Fee Before GST With GST (9%)
Course Fee $1,920.00 $2,092.80

Please note that prices are subjected to change.
Back to Catalogue →
Next Available Schedules
Available Seats:
Course Name:
Category:
Mode of Delivery:
Trainer:
Venue:
Language:
Session Dates:

Registration Date:
From To