# Palo Alto Cortex

**Categories:** Security

Automate threat detection and security operations with Palo Alto Cortex.

Palo Alto Cortex is an AI-powered security operations platform that provides extended detection and response (XDR) capabilities across endpoints, networks, and cloud environments. Integrating Cortex with Harmony enables automated incident creation and enriched security context for faster threat resolution.

### Capabilities

- **Threat Detection & Response**: Receive Cortex XDR alerts in Harmony and automatically route them to the right teams
- **Incident Automation**: Trigger containment and remediation workflows in response to Cortex security events
- **Security Posture Monitoring**: Continuously assess endpoint and network security posture using Cortex data

## What Harmony does with Palo Alto Cortex

Connecting Palo Alto Cortex puts live endpoint threat posture inside Harmony's single agent inventory, so teams see at-risk devices without opening the Cortex console. Detections, alerts, and protection status sit alongside every other signal Harmony tracks. When a threat needs action, teams can isolate a device or trigger a scan from the same conversation.

## Data synced

- Threat detections with severity and device context
- Device protection status and agent health
- Active security alerts from endpoint activity
- Device isolation and containment state

## Actions available

- Isolate a device to contain a detected threat
- Trigger a scan on a suspicious endpoint
- Surface at-risk devices so teams can respond quickly

## Real-world use cases

**Respond without the switch**: Cortex flags a suspicious process on a laptop. Harmony surfaces it in Slack and the responder isolates the device before investigating further.

**One posture view**: IT checks Harmony to see which endpoints are missing a healthy Cortex agent, closing coverage gaps without a separate report.

**Scan on demand**: An employee reports odd behavior on their machine. Harmony triggers a Cortex scan and returns the result inside the same conversation.

## Related integrations

- [CrowdStrike](/integrations/crowdstrike)

- [SentinelOne](/integrations/sentinelone)

- [Qualys](/integrations/qualys)

## FAQ

### What is Palo Alto Cortex?

Bring Palo Alto Cortex device threat detections and agent health into Harmony so teams can see and respond to endpoint risk from one place. Connecting Palo Alto Cortex puts live endpoint threat posture inside Harmony's single agent inventory, so teams see at-risk devices without opening the Cortex console.

### What data does Harmony sync from Palo Alto Cortex?

Harmony's Palo Alto Cortex integration syncs the following into a single agent inventory: threat detections with severity and device context; device protection status and agent health; active security alerts from endpoint activity; and device isolation and containment state.

### What can I do with Palo Alto Cortex through Harmony?

Through the Palo Alto Cortex integration, Harmony can isolate a device to contain a detected threat; trigger a scan on a suspicious endpoint; and surface at-risk devices so teams can respond quickly.

### How does the Palo Alto Cortex integration help security teams?

Cortex flags a suspicious process on a laptop. Harmony surfaces it in Slack and the responder isolates the device before investigating further.

### What other integrations pair with Palo Alto Cortex in Harmony?

Palo Alto Cortex is commonly paired with CrowdStrike (Security), SentinelOne (Security), and Qualys (Security) inside Harmony, giving IT one unified view across related systems.