
- • Jul 13-14, 2026 · Live Remote Online
- • Sep 14-15, 2026 · Live Remote Online
XSIAM-IA Cortex XSIAM for Investigation and Analysis
Course Duration
2 Days
Audience
Employees of federal, state and local governments; and businesses working with the government.
Prerequisites
Participants should have a foundational understanding of cybersecurity principles and experience with analyzing incidents and using security tools for investigation.
Course Description
The Cortex XSIAM for Investigation and Analysis (XSIAM-IA) course is a two-day, instructor-led training focused on using Palo Alto Networks Cortex XSIAM for security incident investigation. XSIAM (Extended Security Intelligence and Automation Management) is Palo Alto Networks' AI-driven security operations platform that combines SIEM, SOAR, threat intelligence, and attack surface management into a single unified system. This course teaches SOC analysts and incident responders how to leverage XSIAM's investigation capabilities to rapidly detect, analyze, and respond to threats.
Learning Objectives
- Describe the Cortex XSIAM architecture and how it unifies SIEM, SOAR, and threat intelligence capabilities
- Navigate the XSIAM console and use key investigation features
- Investigate security incidents and alerts using the XSIAM incident management workflow
- Analyze causality chains and key artifacts to determine root cause and attack scope
- Use XSIAM's built-in query and analytics capabilities to surface threat data
- Apply threat intelligence within XSIAM to enrich investigation findings
- Document findings and close incidents following SOC investigation procedures
Course Outline
Course Topics
- Cortex XSIAM Platform Overview
- Incident Management and Investigation Workflow
- Alert Analysis and Triage
- Causality Chain Analysis
- Query and Analytics Capabilities
- Threat Intelligence Integration
- Case Documentation and Closure
Frequently Asked Questions
What does the Cortex XSIAM Investigation and Analysis course cover?
This course covers using Cortex XSIAM to investigate and analyze security incidents — incident management, alert triage, causality chain analysis, querying, threat intelligence enrichment, and case documentation. It is designed for SOC analysts and incident responders.
What is Cortex XSIAM?
Cortex XSIAM (Extended Security Intelligence and Automation Management) is Palo Alto Networks' AI-driven security operations platform. It consolidates SIEM, SOAR, threat intelligence, and attack surface management into a single platform designed to significantly reduce mean time to detect and respond.
How is XSIAM different from Cortex XDR?
Cortex XDR focuses on extended detection and response across endpoints, networks, and cloud. XSIAM is a broader security operations platform that incorporates XDR capabilities along with SIEM, SOAR, and threat intelligence management, providing a unified SOC platform.
How long is the Cortex XSIAM Investigation and Analysis course?
The course is 2 days. It is available as live remote online instruction or on-site at your facility.
How do I register for this course?
IT Dojo training is employer-sponsored — your organization registers and pays for seats. Contact IT Dojo via the Request Training form or call 757-216-3656 to schedule for your team.