SOAR / MDR / Palo Alto Networks

Cortex XSOAR and XSIAM

Cortex XSOAR is standalone security orchestration software with playbooks, a war room, marketplace content, and case management. Cortex XSIAM is a separate converged operations platform that embeds SIEM, XDR, and SOAR, including playbooks, Quick Actions, and automation rules.

SOAR / automation softwareResearch reviewed

What you are evaluating

These are two licensed software products, not one SKU. The buyer staffs playbooks and owns credentials. XSIAM automation is not a staffed MDR service, and Unit 42 MDR is sold separately.

A useful evaluation context

Evaluate whether you need a standalone orchestrator across a mixed stack or automation inside one Palo Alto Networks operations platform.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • XSOAR playbooks, war room, marketplace content, and case management across connected tools.
  • XSIAM unified SIEM, XDR, and SOAR with playbooks, Quick Actions, and automation rules.
  • XSIAM documents agentic assistants alongside automation; verify the approval controls and permissions governing each intended action.

Where it fits in the work

  1. Choose standalone XSOAR across a mixed stack or automation inside an XSIAM tenant.
  2. Encode enrichment and a mandatory human gate before containment actions.
  3. Export case history and playbook definitions for audit and exit.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In an authorized test tenant, run a synthetic phishing case through a playbook that enriches the alert, pauses for analyst approval, then opens a ticket without touching production identities.

Evidence to look for

The audit trail shows enrichment, the human gate, the ticket, and that no production mailbox or host changed.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which product owns cases when detections already live in other tools?
  2. Who on the buyer staff maintains playbooks after professional services leave?
  3. How do playbooks hand off to Unit 42 or a retainer when an incident exceeds automation?

Find your next idea.

Tip: press / to open search. Escape closes this window.