Palo Alto Cortex XDR
Strengthen your endpoint security with JupiterOne's Palo Alto Cortex XDR integration. Our guide offers detailed instructions on setting up the integration and utilizing its comprehensive data model to gain visibility into your device and endpoint security data. Learn how the integration can help you detect potential security threats and streamline your security operations.
- Installation
- Data Model
- Types
Installation
Before you begin, create an API key in Palo Alto Cortex XDR. See the Cortex XDR documentation for step-by-step instructions.
To install the Palo Alto Cortex XDR integration in JupiterOne, navigate to the Integrations tab and select Palo Alto Cortex XDR. Click New Instance to begin.
Prerequisites
Creating a Palo Alto Cortex XDR integration instance requires the following:
- A Cortex XDR API key and API key ID. In Cortex XDR, navigate to Settings > Configurations > Integrations > API Keys and generate a new key.
- Select the Standard security level.
- Assign the appropriate role:
- To ingest Users, User Groups, and Roles, assign the Instance Administrator role.
- For all other data, the Viewer role is sufficient.
- After generation, copy the API key value and note the numeric API Key ID shown in the table. Your tenant Host is the FQDN displayed in the Cortex XDR top-right URL bar (for example,
tenant-id.xdr.us.paloaltonetworks.com).
- Your Host (the Cortex XDR tenant FQDN, for example
mytenant.xdr.us.paloaltonetworks.com) - Your API Key (the generated key value)
- Your API Key ID (the numeric ID displayed next to the key in the API Keys table)
Create an instance
- Sign in to Cortex Gateway.
- Select the tenant you want to integrate.
- In the Cortex XDR console, navigate to Settings > Configurations > Integrations > API Keys.
- Click New Key. Under Security Level choose Standard; under Role choose Instance Administrator (for full data access) or Viewer (for alerts, incidents, and endpoints only).
- Click Generate. Copy the API key — it is shown only once.
- Note the API Key ID (the numeric value in the table) and the FQDN from your browser's address bar.
- In JupiterOne, enter the Host, API Key, and API Key ID in the corresponding fields, then click Create.
Data Volume Configuration
Ingestion Windows
Limit how far back the integration looks when ingesting incidents and alerts. Narrower windows reduce ingestion volume.
| Field | Description | Default |
|---|---|---|
| Incident Ingestion Window | How far back (in days) to look for incidents based on their last modification time. | 90 days |
| Alert Ingestion Window | How far back (in days) to look for alerts based on their detection timestamp. | 90 days |
Available options for both fields: 1 day, 7 days, 30 days, 60 days, 90 days.
Data Filtering Options
Control which incidents are ingested by status.
| Field | Description | Default |
|---|---|---|
| Incident Status | Restrict ingestion to incidents in specific statuses. When left at the default, only open incidents are ingested. | New, Under Investigation |
Available status options: New, Under Investigation, Resolved (auto-resolve), Resolved (duplicate incident), Resolved (false positive), Resolved (true positive), Resolved (known issue), Resolved (threat handled), Resolved (security testing), Resolved (other).
Next steps
Your integration is now configured. It will run on the polling interval you selected and populate data in JupiterOne. See the Instance management guide for more details on working with integration instances.
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Account | palo_alto_account | Account |
| Alert | palo_alto_alert | Finding |
| Alert | palo_alto_alert | Finding, Vulnerability |
| Cortex Case | palo_alto_cortex_case | Finding |
| Cortex Compute Asset | palo_alto_cortex_compute_asset | Host |
| Cortex Issue | palo_alto_cortex_issue | Finding |
| Cortex Software Package | palo_alto_cortex_software_package | CodeModule |
| Cortex Vulnerability Finding | palo_alto_cortex_vulnerability_finding | Finding, Vulnerability |
| Endpoint Agent | palo_alto_endpoint_sensor | HostAgent |
| Endpoint Host | palo_alto_host | Host |
| Endpoint Policy | palo_alto_endpoint_policy | ControlPolicy |
| Incident | palo_alto_incident | Finding |
| Incident | palo_alto_incident | Finding, Vulnerability |
| Role | palo_alto_role | AccessRole |
| Service | palo_alto_endpoint_protection | Service |
| User | palo_alto_user | User |
| User Group | palo_alto_user_group | UserGroup |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
palo_alto_account | HAS | palo_alto_endpoint_protection |
palo_alto_account | HAS | palo_alto_cortex_compute_asset |
palo_alto_cortex_compute_asset | HAS | palo_alto_cortex_vulnerability_finding |
palo_alto_cortex_compute_asset | HAS | palo_alto_cortex_issue |
palo_alto_cortex_compute_asset | HAS | palo_alto_cortex_case |
palo_alto_cortex_compute_asset | CONTAINS | palo_alto_cortex_software_package |
palo_alto_cortex_software_package | HAS | palo_alto_cortex_vulnerability_finding |
palo_alto_endpoint_policy | HAS | palo_alto_endpoint_protection |
palo_alto_endpoint_sensor | ASSIGNED | palo_alto_endpoint_policy |
palo_alto_endpoint_sensor | PROTECTS | palo_alto_host |
palo_alto_endpoint_sensor | IDENTIFIED | palo_alto_incident |
palo_alto_endpoint_sensor | IDENTIFIED | palo_alto_alert |
palo_alto_host | HAS | palo_alto_incident |
palo_alto_incident | HAS | palo_alto_alert |
palo_alto_user | HAS | palo_alto_role |
palo_alto_user_group | HAS | palo_alto_role |
palo_alto_user_group | HAS | palo_alto_user |
Mapped Relationships
The following mapped relationships are created:
Source Entity _type | Relationship _class | Target Entity _type | Direction |
|---|---|---|---|
palo_alto_cortex_compute_asset | IS | aws_instance | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_lambda_function | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_ecs_cluster | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_ecs_service | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_ecs_task | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_ecs_task_definition | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_ecs_container_instance | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_eks_cluster | FORWARD |
palo_alto_cortex_compute_asset | IS | aws_eks_node_group | FORWARD |
Palo Alto Cortex Case
palo_alto_cortex_case inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
assetIds | array | null | Cortex asset IDs the case applies to. HAS relationships exist only for ingested Compute assets. | |
caseId | number | Cortex case ID. | |
issueCount | number | Number of issues in the case. | |
mitreTactics | array | null | MITRE ATT&CK tactics. | |
mitreTechniques | array | null | MITRE ATT&CK techniques. | |
resolveReason | string | Reason the case was resolved. | |
statusProgress | string | Case progress status, e.g. New, In Progress, Resolved. |
Palo Alto Cortex Compute Asset
palo_alto_cortex_compute_asset inherits from Host
| Property | Type | Description | Specifications |
|---|---|---|---|
assetCategory | string | null | Cortex asset type category (xdm.asset.type.category). | |
assetClass | string | null | Cortex asset type class (xdm.asset.type.class), e.g. Compute. | |
assetId * | string | Cortex asset ID (xdm.asset.id). | |
assetType | string | null | Cortex asset type ID (xdm.asset.type.id), e.g. EC2_INSTANCE. | |
firstObservedOn | number | When Cortex first observed the asset. | |
provider | string | null | Cloud provider of the asset, e.g. AWS. | |
region | string | null | Cloud region of the asset. | |
resourceGroup | string | null | Resource group the asset belongs to. | |
strongId | string | null | Provider-side identifier of the asset (xdm.asset.strong_id). |
Palo Alto Cortex Issue
palo_alto_cortex_issue inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
assetIds | array | null | Cortex asset IDs the issue applies to. HAS relationships exist only for ingested Compute assets. | |
cveId | string | CVE ID, for VULNERABILITY-category issues. | |
detectionMethod | string | Detection method of the issue. | |
domain | string | Issue domain, e.g. Security, Posture. | |
externalId | string | External ID of the issue. | |
issueId | number | Cortex issue ID. | |
mitreTactics | array | null | MITRE ATT&CK tactics. | |
mitreTechniques | array | null | MITRE ATT&CK techniques. | |
remediation | string | Remediation guidance. |
Palo Alto Cortex Software Package
palo_alto_cortex_software_package inherits from CodeModule
| Property | Type | Description | Specifications |
|---|---|---|---|
author | string | Package author. | |
licenses | array | null | Licenses declared for the package. | |
packageType | string | CycloneDX component type, e.g. library. | |
purl | string | Package URL (PURL). | |
version | string | Package version. |
Palo Alto Cortex Vulnerability Finding
palo_alto_cortex_vulnerability_finding inherits from Finding, Vulnerability
| Property | Type | Description | Specifications |
|---|---|---|---|
assetId | string | Cortex asset ID of the affected asset. The HAS relationship exists only when the asset is an ingested Compute asset. | |
epssScore | number | EPSS probability score (0-1). | |
exploitLevel | string | null | Exploit maturity level. | |
fixVersions | array | null | Package versions that fix the CVE. | |
imageName | string | null | Container image name, for image findings. | |
isExploitable | boolean | Whether Cortex considers the vulnerability exploitable. | |
isFixAvailable | boolean | Whether a fix is available for the finding. | |
isInternetExposed | boolean | Whether the affected asset is exposed to the internet. | |
isKnownExploited | boolean | Whether the CVE is in the CISA Known Exploited Vulnerabilities catalog. | |
layerId | string | null | Container image layer ID, for image findings. | |
packageName | string | null | Name of the affected package. | |
packagePurl | string | null | Package URL (PURL) of the affected package. | |
packageType | string | null | Type of the affected package, e.g. npm, pip, deb. | |
packageVersion | string | null | Version of the affected package. | |
platformId | string | Cortex platform identifier of the finding. |
Palo Alto Host
palo_alto_host inherits from Host
Palo Alto User
palo_alto_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
groups | array of strings | ||
lastLoggedIn | number | ||
role | string |