Skip to content

We would like to inform you that both our Computer Pride Nairobi and Mombasa offices will be closed completely from Wednesday, 19th July 2023 to Thursday, 27th July 2023. We will resume our regular operations on Friday, 28th July 2023.

This closure is in observance of the special Ashara Mubaraka prayers. In case of any urgent inquiries or assistance, please feel free to contact us at info@computer-pride.co.ke.

Search...

Palo Alto Networks: Cortex XSIAM for Investigation and Analysis

Courses Overview

The Palo Alto Networks: Cortex XSIAM for Investigation and Analysis course is designed to equip cybersecurity professionals with the skills to investigate, analyze, and respond to incidents using the industry’s most comprehensive Security Incident and Asset Management (XSIAM) platform.
XSIAM delivers unmatched coverage for securing and managing infrastructure, workloads, and applications across hybrid and multi-cloud environments. This course covers both the fundamental components and advanced features of XSIAM, providing participants with the ability to navigate incident handling, apply automation, and orchestrate efficient security operations.

By completing this course, you will be able to:
  • Investigate incidents, analyze critical assets and artifacts, and interpret causality chains
  • Use XQL to query and analyze logs for deeper insights into incidents and security events
  • Leverage advanced XSIAM tools and resources for comprehensive incident analysis and response
  • Apply best practices for automating and orchestrating security workflows
This course is ideal for:
  • SOC, CERT, CSIRT, and XSIAM Analysts and Managers
  • MSSPs and Service Delivery Partners/System Integrators
  • Professional Services Consultants (internal or external)
  • Security Sales Engineers
  • Incident Responders and Threat Hunters

Through guided instruction and hands-on labs, participants will gain practical expertise in using Cortex XSIAM to investigate incidents, analyze system artifacts, and orchestrate security operations. The training builds a strong foundation for professionals aiming to maximize efficiency in threat detection, response, and analysis.

Course Modules
  1. Introduction to Cortex XSIAM
  2. Endpoints
  3. XQL
  4. Alerting and Detection
  5. Threat Intel Management
  6. Automation
  7. Attack Surface Management
  8. Incident Handling
  9. Dashboards and Reports
Participants should have:
  • A foundational understanding of cybersecurity principles
  • Prior experience analyzing security incidents and using investigation tools