757-216-3656 | Monday–Friday 8:30 AM – 4:30 PM | info@itdojo.com

Course Duration

2 Days

Audience

Employees of federal, state and local governments; and businesses working with the government.

Prerequisites

Participants should have a foundational understanding of cybersecurity principles and experience with analyzing incidents and using security tools for investigation.

Course Description

The Cortex XDR: Investigation and Analysis (PCXDR-IA) course is a two-day, instructor-led training that teaches security analysts how to investigate cases, analyze key assets and artifacts, and interpret causality chains within the Cortex XDR platform. You will learn how to query and analyze logs using XQL (XDR Query Language) to extract meaningful threat intelligence, and how to use advanced investigation tools to perform comprehensive case analysis. This course is designed for SOC analysts and incident responders working in Cortex XDR environments.

Learning Objectives

  • Investigate cases in Cortex XDR and analyze key assets and artifacts
  • Interpret causality chains to understand attack progression and root cause
  • Write and execute XQL queries to query and analyze log data
  • Extract actionable insights from XDR log data to support incident response
  • Use advanced Cortex XDR investigation tools and resources for comprehensive case analysis
  • Correlate alerts and events across endpoints, networks, and cloud to build a complete picture of an incident

Course Outline

Course Topics
  • Cortex XDR Platform Overview
  • Case Management and Investigation Workflow
  • Analyzing Alerts, Assets, and Artifacts
  • Causality Chain Analysis
  • XQL: Querying and Analyzing Log Data
  • Advanced Investigation Tools and Techniques
  • Incident Response with Cortex XDR

Frequently Asked Questions

What does the Cortex XDR Investigation and Analysis course cover?

This course covers how to use Cortex XDR to investigate security incidents — case management, artifact analysis, causality chain interpretation, and XQL-based log querying. It is designed for SOC analysts and incident responders.

What is XQL and why is it important for this course?

XQL (XDR Query Language) is Palo Alto Networks' query language for searching and analyzing log data within the Cortex platform. Proficiency in XQL is essential for effective threat hunting and incident investigation in Cortex XDR environments.

How long is the Cortex XDR Investigation and Analysis course?

The course is 2 days. It is available as live remote online instruction or on-site at your facility.

Is this course available as live remote online training?

Yes. IT Dojo offers this course as live remote online training. On-site delivery is also available for teams of four or more.

How do I register for this course?

IT Dojo training is employer-sponsored — your organization registers and pays for seats. Contact IT Dojo via the Request Training form or call 757-216-3656 to schedule for your team.

Get More Information

We work with Government Agencies, Military, government contractors, and corporate clients. As much as we would love to, our business model does not include working with the general public.