CCNA-Image

Extended detection and response (XDR) is central to modern security operations, helping teams investigate threats across endpoints, networks, and cloud environments with greater speed and context. Palo Alto Cortex XDR: Investigation & Analysis equips cybersecurity professionals with hands-on expertise in endpoint management, case management, forensic analysis, log analysis, and platform automation.

This 2-day instructor-led course explores the core capabilities of Cortex XDR, from investigating alerts and analysing causality chains to using XQL queries to uncover meaningful security insights. Participants gain the knowledge and practical skills needed to investigate incidents efficiently, improve analysis workflows, and support stronger security operations.

This course provides a practical introduction to Cortex XDR investigation and analysis capabilities. Participants explore how to investigate cases, analyse assets and artefacts, interpret causality chains, query logs using XQL, and use advanced tools to support comprehensive case analysis.

Course Objectives

By the end of this course, participants will be able to:

  • Investigate Cortex XDR cases and analyse key assets, artefacts, and causality chains.

  • Query and analyse logs using XQL to extract meaningful insights.

  • Use advanced Cortex XDR tools and resources for comprehensive case analysis.

  • Manage endpoints and work with alerts, detections, vulnerabilities, and forensic data.

  • Navigate case management, dashboards, reporting, and platform automation workflows.

Scope

  • Course level: Intermediate
  • Course duration: 2 days
  • Course format: Instructor-led Training with Hands-on Simulations
  • Platform support: Cortex

 

Course Modules

  • Module 1: Introduction to Cortex XDR
  • Module 2: Endpoints
  • Module 3: XQL
  • Module 4: Alerting and Detection
  • Module 5: Vulnerability and Forensics
  • Module 6: Platform Automation
  • Module 7: Case Management
  • Module 8: Dashboards & Reports

This course is designed for cybersecurity professionals who work in security operations, incident investigation, and threat detection environments.

It is suitable for:

  • SOC analysts and managers
  • CERT and CSIRT professionals
  • XDR analysts
  • Security analysts
  • Incident responders
  • Threat hunters
  • Professional services consultants
  • Sales engineers
  • Service delivery partners

Recommended Prerequisites

Participants should have a foundational understanding of cybersecurity principles and experience analysing security incidents or using security tools for investigation. Familiarity with SOC processes, alerts, endpoint security, and incident-response workflows will be beneficial.

Delivery Mode: Facilitated Classroom / Virtual Training 

2025

Please email to enquiry@bridgingminds.net for course dates

Duration: 2 Days

Course Fee

 

Course Fee w/o GST USD 1,500.00
Course Fee w. GST (9% effective 1st Jan 2024) USD 1,635.00
SME (Company Sponsored) – All Singaporean and Permanent Resident Employee USD 1,635.00
Singapore Citizens aged 40 years old and above USD 1,635.00
Singapore Citizens below 40 years old and Permanent Residents USD 1,635.00

Exam Fee

  • Exam Voucher is non-inclusive and optional. Please contact us for more info.

Certification Body

Leave a Comment

Your email address will not be published.