Features by License Type - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2023-03-30
Last date published
2023-03-30

Cortex XDR licenses are provided on the basis of detection and protection capabilities, log ingestion, retention, and the number of users.

  • Cortex XDR Prevent

    • Next-Generation Antivirus - Block malware, ransomware, and exploits attacks

    • Endpoint Protection - Safeguard endpoints with device control, firewall, and disk encryption

  • Cortex XDR Pro

    • Enhanced Data Collection on the endpoint

    • Detection, Response, and Remediation analysis

    • Host Insights - Forensics, Vulnerability Assessment, Host Inventory, and File Search and Destroy

    Cortex Pro license is split into 3 license tiers that you can use independently or together for complete coverage:

    • Cortex XDR Pro per Endpoint

    • Cortex XDR Cloud per Host

    • Cortex XDR Pro per TB

Retention

All of the Cortex XDR licenses provide you with a default retention period of 30 days for your integrated data and 180 days for your alert and incident data.

To extend your license retention, depending on your requirements, you can select the following add-on capabilities:

  • Hot Storage - Fully searchable storage, for investigation and threat hunting. Available for Ingested and Alert/Incident data.

  • Cold Storage - Cheaper storage for long-term compliance needs with limited search options. Available only for Ingested data.

Incident and alert data are retained according to the last Update Date and Creation Date, respectively. Data collected within these dates is kept and displayed for 180 days. To ensure the accuracy of incidents, Cortex XDR provides a grace period of up to 30 days for alerts displayed in the Incidents View, Alerts table, and Casualty View.

For XQL Search capabilities, Cortex XDR enforces retention on all log-type datasets excluding Host Inventory, Vulnerability Assessment, Metrics, and Users.

You can view your retention storage duration in the Data Management page.

The following table lists the features offered with each type of license.

Feature

Cortex XDR Prevent

Cortex XDR Pro per Endpoint

Cortex XDR Cloud per Host

Cortex XDR Pro per TB

license-cortex-xdr-prevent.png
license-cortex-xdr-pro-endpoint.png
cloud-per-host-license.png
license-cortex-xdr-pro-network.png

Log storage

Minimum of 200 endpoints

Minimum of 200 endpoints

Minimum of 50 endpoints

  • Minimum 5TB log storage

  • Ingestion quota of 1 TB per month and no more than 33GB per day

Retention

  • 30 day ingested data  retention

  • 180 day alert and incident data retention

  • 30 day ingested data  retention

  • 180 day alert and incident data retention

  • 365 day ingested Forensics data retention

  • 30 day ingested data  retention

  • 180 day alert and incident data retention

  • 365 day ingested Forensics data retention

  • 30 day ingested data  retention

  • 180 day alert and incident data retention

Kubernetes Host Support

check-mark.png

Cortex XDR Add-on Licenses

Add-on licenses are required on top of a Cortex XDR license

Host Insights, including:

  • Host Inventory

  • Vulnerability Assessment

  • File Search and Destroy

check-mark.png

Without the add-on license, Host Insights is available with Cortex XDR Pro per Endpoint for a 1-month trial period.

check-green2.png

Without the add-on license, Host Insights is available with Cloud Host Protection for Cortex XDRfor a 1-month trial period.

Forensics

check-green2.png

Without the add-on license, Forensics is available with Cortex XDR Pro per Endpoint for a 1-month trial period.

check-mark.png

Without the add-on license, Forensics is available with Cloud Host Protection for Cortex XDR for a 1-month trial period.

Compute Unit

checkmark-n.png

Without the add-on license, Compute unit is available with Cortex XDR Pro per Endpoint for a 1-month trial period.

checkmark-n.png

Without the add-on license, Compute unit is available with Cloud Host Protection for Cortex XDR for a 1-month trial period.

checkmark-n.png

Without the add-on license, Compute unit is available with Cortex XDR Pro per TBfor a 1-month trial period.

Period Based Retention (Hot Storage)

  • Hot storage EP-Minimum of 1 month storage for ingested data

  • Hot storage EP-Minimum of 1 month storage for alert and incident data.

  • Hot storage EP-Minimum of 1 month storage for ingested data

  • Hot storage EP-Minimum of 1 month storage for alert and incident data.

  • Hot storage GP-Minimum of 1 month storage for ingested data

  • Hot storage GP-Minimum of 1 month storage for alert and incident data.

Period Based Retention (Cold Storage)

Cold storage EP­ Minimum of 6 months storage for ingested data

  • Cold storage EP­ Minimum of 6 months storage for ingested data

Cold storage GP­ Minimum of 6 months storage for ingested data

GB Event Forwarding

checkmark-n.png

Endpoints Event Forwarding

checkmark-n.png
checkmark-n.png

Identity Threat Module

  • Asset Roles Configuration

  • Advanced Analytics Alert layout

  • Risk Management Dashboard

  • User/Host Risk View

  • Designated Analytics for Compromised Accounts

  • Insider Threat Coverage

Available for a free trial period ending on July 31, 2023. After this date, the module will be available as an Add-on.

Endpoint Prevention Features

Endpoint management

checkmark-n.png
checkmark-n.png
checkmark-n.png

Device control

checkmark-n.png
checkmark-n.png
checkmark-n.png

Host firewall

checkmark-n.png
checkmark-n.png
checkmark-n.png

Disk encryption

checkmark-n.png
checkmark-n.png
checkmark-n.png

Response Actions

Live Terminal

checkmark-n.png
checkmark-n.png
checkmark-n.png

Endpoint isolation

checkmark-n.png
checkmark-n.png
checkmark-n.png

External dynamic list (EDL)

checkmark-n.png
checkmark-n.png
checkmark-n.png

Script execution

checkmark-n.png
checkmark-n.png

Remediation analysis

checkmark-n.png
checkmark-n.png

Incident Scoring Rules

checkmark-n.png
checkmark-n.png
checkmark-n.png

Featured Alert Fields

checkmark-n.png
checkmark-n.png
checkmark-n.png

Widget Library

checkmark-n.png
checkmark-n.png
checkmark-n.png

Assets

Asset Management

checkmark-n.png
checkmark-n.png
checkmark-n.png

Palo Alto Networks IoT Security

checkmark-n.png

Analysis

Analytics, including Identity Analytics

checkmark-n.png
checkmark-n.png
checkmark-n.png

Alert and Log Collectors

Cortex XDR agent alerts

checkmark-n.png
checkmark-n.png
checkmark-n.png

Collection Integrations

checkmark-n.png

Prisma Cloud and Prisma Cloud Compute

checkmark-n.png

Palo Alto Networks IoT Security

checkmark-n.png

Third-Party Cloud Security Data (AWS, Azure, Google)

checkmark-n.png

Enhanced data collection for EDR and other Pro features

checkmark-n.png
checkmark-n.png

Other alerts (from Palo Alto Networks and third-party sources)

checkmark-n.png

(API)

checkmark-n.png
checkmark-n.png

Other logs (from Palo Alto Networks and third-party sources)

checkmark-n.png

Integrations

Threat intelligence (AutoFocus, VirusTotal)

checkmark-n.png
checkmark-n.png
checkmark-n.png
checkmark-n.png

Outbound integration and notification forwarding (Slack, Syslog)

checkmark-n.png

+ agent audit logs

checkmark-n.png

+ agent audit logs

checkmark-n.png
checkmark-n.png

Broker VM

Agent Proxy

checkmark-n.png
checkmark-n.png
checkmark-n.png
checkmark-n.png

Syslog Collector

checkmark-n.png

Apache Kafka Collector

checkmark-n.png

CSV Collector

checkmark-n.png

Database Collector

checkmark-n.png

Files and Folders Collector

checkmark-n.png

FTP Collector

checkmark-n.png

NetFlow Collector

checkmark-n.png

Network Mapper

checkmark-n.png
checkmark-n.png
checkmark-n.png

Pathfinder

checkmark-n.png
checkmark-n.png
checkmark-n.png

Windows Event Collector

checkmark-n.png

MSSP

MSSP (requires additional MSSP license)

checkmark-n.png
checkmark-n.png
checkmark-n.png
checkmark-n.png

Managed Threat Hunting (requires an additional Managed Threat Hunting License)

checkmark-n.png

+ a minimum of 500 endpoints

checkmark-n.png