Extended detection and response (XDR) is central to modern security operations, helping teams investigate threats across endpoints, networks, and cloud environments with greater speed and context. Palo Alto Cortex XDR: Investigation & Analysis equips cybersecurity professionals with hands-on expertise in endpoint management, case management, forensic analysis, log analysis, and platform automation.
This 2-day instructor-led course explores the core capabilities of Cortex XDR, from investigating alerts and analysing causality chains to using XQL queries to uncover meaningful security insights. Participants gain the knowledge and practical skills needed to investigate incidents efficiently, improve analysis workflows, and support stronger security operations.
Scope
Full-Time
This course is designed for cybersecurity professionals who work in security operations, incident investigation, and threat detection environments.
It is suitable for:
2 days
Module 1: Introduction to Cortex XDR
Module 2: Endpoints
Module 3: XQL
Module 4: Alerting and Detection
Module 5: Vulnerability and Forensics
Module 6: Platform Automation
Module 7: Case Management
Module 8: Dashboards & Reports
By the end of this course, participants will be able to:
Participants should have a foundational understanding of cybersecurity principles and experience analysing security incidents or using security tools for investigation. Familiarity with SOC processes, alerts, endpoint security, and incident-response workflows will be beneficial.
English
| Course Fee Payable | ||
|---|---|---|
| Original Fee | Before GST | With GST (9%) |
| Course Fee | $1,920.00 | $2,092.80 |