Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary
January 17, 2024
Earnings Call Speaker Segments
Nana-Ampofo Ampofo-Anti
executiveAll right. So we seem to have a pretty stable number of attendees at the moment. So good morning, good afternoon, good evening. If there is anybody joining in later time zones then I myself sitting in South Africa for this one. So thank you all for joining this webinar today. Today, we're going to be talking about how you can automate away stock. And in fact, to talk and not busy work because we're going to be talking about use cases from the network security world and some of the things that you can do to make it easier to take advantage of the very rich APIs that you have baked into your Palo Alto Networks portfolio of capabilities, especially our next-generation firewall, Prisma Access, Prisma Cloud. We are going to talk about that. We're also going to, of course, talk about Cortex XDR today, very recently named the leader in the Gartner, Magic Quadrant, which we're very excited about. So we're going to jump into that, just a little bit of a quick introduction. So my name is Nana-Ampofo. I am a senior consulting engineer part of our Cortex organization within Palo Alto Networks. I just call it our stock transformation organization. So it's easier for everybody outside to understand what that means because Cortex is everything stock at Palo Alto Networks. So let's get started. What we're going to talk about today is first, how our technologies are better when used together. No surprises there, as a company, we've always believed in trying to have that 1 plus 1 equals 3 effect. With every product that we build, we try to find ways that we can make it easier for our customers to get value by having more of our technologies rather than just being that, just take all of the new stuff from us and your life will be better. It should be take all the stuff from us because we've really thought deeply about how it will work together to make -- to provide genuine value and impact from your team. And let's talk about Network Security operations. We're going to talk about how you can automate that you can connect them to PAN-OS, connect them to that infrastructure and make it easier for you to go and deploy things for you to go and make changes. We do best practice assessment. So when I started my career at Palo Alto Networks several years ago, I was very much focused on the Network Security side of our business. And day to day, I was speaking to customers, building things with them as well, and of course, managing my own demo systems and environment. And I know how challenging it can be, especially at Gale, the managed network security infrastructure of any kind. So it's not that was something specific about our Network Security infrastructure. This is where XSOAR could really make a tangible difference to the way that this is done. We're going to talk about Cloud Security operations as well. Of course, the Cloud is here to stay, it's never going away. And we always need to think about ways we can be more efficient in the way that we do that. We'll talk about how we can prioritize the alerts that come from the cloud technology, and that will also allow you to focus in terms of, let's say, you've got lots and lots of VMs and computing those out there, which most organizations, I speak to day-to-day do. How do you actually manage alerts that come in at scale? How do you prioritize those alerts? So we'll talk about that, too. So just to recap on those 3 areas of our business of Palo Alto Networks and the different technologies that fit into them. So when we talk about securing the enterprise is, of course, our strata portfolio of SaaS security, panelist based infrastructure, WildFire as well, then we'll talk about securing the future, which is all about Cortex XDR expand and, of course, Cortex XSIAM. How we can connect all of these various technologies into XSOAR and use XSOAR to automate things make life easier. We'll also talk about Prisma Cloud and how that helps you to provide end-to-end visibility for your teams or something in the [indiscernible] chart, I'm sure everyone that tend any vendor talk here is end-to-end in visibility all the time. So apologies for combining those terms back to back. But what Prisma Cloud will help to do, of course, Prisma SASE as well isn't to really help to secure your cloud infrastructure. So let's get into it. And this still, you know, it won't just be slide today. There will be some demos just for safety tech, there will be reported demos. So do bear with me. I'll now use through those recorded demos, and we should hopefully get some time at the end to go through some questions too. Now why do we want to bring all these tools together because of automation. I'm a very, very big believer in how you can use automation, how you can use various technology tools like machine learning, like orchestration and automation tools like XSOAR to make a meaningful impact in the work that humans do. If not to replace humans, it's to augment humans. It's to ensure that there's an easier way for you to do things like collaborate with your colleagues in a unified war room as you'll see in XSOAR in the demos, to run command in real time, which makes it very easy for you to plug into different technologies. So whether you are the person that owns and runs Prisma Cloud of panorama or you're a team that's going to have to support that technology, they've been able to go and run that command without having to click through the UI, do that from the CLI that's built into XSOAR that connects right back into the tool. We'll actually see how you connect XSOAR into Prisma Cloud as part of our second demo. This makes our life significantly easier and just makes it more efficient because what we want to do is we want to take that busy work and we want to automate, just higher purpose of this webinar and ensure that you have valuable time back to do more strategic things, strategic activities day-to-day. So let's start with Strata. So we're going to talk about how we can take our next-generation firewall, our cloud-delivered security services, WildFire and bring those together with XSOAR's ability to automate. But before we do that, this would not, of course, be a security webinar without some statistics. So we're going to start with a statistic here. So in 2023, 99% of the firewall filters will be caused by misconfigurations. That was Gartner making that prediction. And this stems from the fact that unfortunately, misconfigurations remain a common thing. Now again, and harking back to the early part of my career at Palo Alto Networks, this was a very common thing, unfortunately. I would often be speaking to customers that would discover through the course of our conversation that looks like this firewall is not considered according to the best practice. It looks like this firewall is allowing things that it shouldn't be allowing. It might have unexpected behavior because of a rule that was set up years ago that was a necessity. Now don't get me wrong. This is not a criticism of anyone that has come across the passive misconfigurations. In my experience in even having had some misconfigurations myself in my own infrastructure, this of course is labs, it is -- it can be very -- it can be unfortunately too easy sometimes, especially when you're doing things manually to make a mistake and for that mistake to then ripple and especially if we're talking about large infrastructure deployment, then we'll talk -- we'll see some examples of that as well where some customers had some unfortunate mishaps in their environment because of this. This is why certain activities it's really good to use a machine because machine is always going to do the same thing over and over again. Yes, some people say that includes doing the wrong thing over and over again, that is absolutely true. But if you set it up to do the right things, it will do the right things reliably every time, and we can have pretty good behavior as opposed to humans who are quite fallible. You're having a bad day, you're having a tire day, you make one misconfiguration, one misstep and that causes serious issues. So let's talk about that in real terms, things that have happened to our customers. So we had a customer that -- a banking customer that had a manual policy change management, they were doing 10 to 20 rule change requests per day, it's taken them 15 minutes to an hour to do this. So that was actually taking 60 to 400 hours a month from that. And a firewall upgrade in CVE management insurance customer, they had 450 firewalls. I've worked with customers that have more firewalls. So the numbers can get pretty intimidating, taking them 2 hours to do an upgrade every single firewall. So this is incredibly painful and time consuming, again, not because infrastructure is designed to make your life difficult, but just because you need to actually do those click-throughs. Now again, if you're familiar with PAN-OS, you'll know that it has a KPI, you'll not be wasting, you can actually connect in and do this through automation, that's precisely what we're going to be talking about today with XSOAR. And then we have a health care customer who's taking them weeks to do design just to find those best practice gaps. We actually have a playbook in XSOAR that will run a BPA for you, that will run a BPA against your infrastructure. Within our own environment, we run BPAs regularly using XSOAR. So within Palo Alto Networks, one of the key principles of how we manage our own infrastructure is using automation to do things like run those best practice check. So every time a firewall is set up when we have policy changes, that kind of thing, we have technology that's coming in and doing that sanity check that suite that you need to do because, again, it saves -- not only saves time, time is really critical, from my perspective, it's not just the time that it saves, it's also ensuring that consistency in terms of how things are done. So these are a few really important use cases that we've seen out in the wild and that we're helping our customers with as parts logs into populate EDLs if you're not familiar with those, those are external dynamic lifts. This is a way to productively put Palo WildFire policy rule, point to this container that I will come and populate later. And that's very powerful because we're allowed to do all sorts of flexible gains from both a blacklisting and white listing perspective. So a good example of that would be often in a past with customers to white list, they, let's say, for example, you want to white list all traffic towards AWS, all traffic towards Microsoft Office 365, so you want to have a very tight policy rule that this FID and with this set of IPs, you can pull that data in from the third-party feed. For those of you that have played with that technology for quite some time, you might have heard of tools like MineMeld. MineMeld is actually now part of Threat Intel Management or TIM in XSOAR and that's helping us to bring in those feeds to manage feed and then to do things like that automated white listing using things like jobs for example, to manage that. IoC validation with CDSS, so that's reaching its threat vaults. This is something that I've done manually, many, many, many times, too many times for me to remember in my career where I'd be helping a customer do something and we'd have to go into threat vaults and look some information up. The good news is that you can actually do this all through the Threat Vault API. We're going to see that as an example, how we can actually reach back to Threat Vault to pull that data in. The next-generation firewall analyst upgrade I have a 220 that sits at home, my home office. And it's joyful, I would say we can further do upgrade until you start doing some level of automation. So those are very, very important, too. Let's talk about how this can go wrong. So we have an example of a customer base in North America in finance, they said they created a particular rule that block all the traffic just because of a single character, and I'm sure this has happened or you've heard of this happening to colleagues, peers or perhaps something to tap into you. I certainly had some misadventures of wild cards along the way. So I know how one character can become a total disaster. And of course, we're talking about a production environment, that is very serious. Then -- and this is the second case, we have a customer base in JAPAC, and we missed the one, and that completely changed the [ fighter age. ] And that made all of the devices only began to talk with 127,001, which we all know is not particularly useful. So this is how things can unfortunately go quite wrong. Now the good news is that we have this generic export indicator service, which works for not just our firewalls, third-party firewalls, third-party infrastructure with SIMs as well. So you could use this to go and export indicators into these third-party tools at some form of friendliness that these tools would accept that would allow you to do things like export institutional dynamic lists, you can tag the indicators that they will be pushed in certain black listers or white listers. And we even have an odd process in content back. So this is one of the things that makes external view different in this whole world is the amount of prebuilt content that is there for easy consumption for customers out of the box. You can bring in that content and plug into your Palo Alto Networks infrastructure by taking advantage of it. Now we are talking a lot about Palo Alto Networks infrastructure in this particular call, but very important to mention that we have this content. We'll talk about that towards the end of the webinar for many, many, many different tools, hundreds of tools, which means that it's not just focused on our infrastructure, you would be getting the benefit of our infrastructure and connectivity from an automation perspective, but you'd also be able to take advantage across multiple different use cases. Right. So let's talk about how you can automate EDL updates within PAN-OS using XSOAR. So you can create different instances of the JAK indicator export service. I've actually gone through a similar project like this myself, where we had -- we wanted to populate specific EDL. And the nice thing is that because of the way this works, you can run a playbook every time there's a difference in the feed, so you can run. We have these feed triggered playbooks in the Threat Intel management module. You can use that to extract indicators you care about to push aside the ones that you don't care about, doing things like check against prebuilt white list in your system that will ensure that if, for example, one of your public IPs or partner's public IP ends up on the wrong side of the black list, you can make sure that, that is not added to your block list EDL as we populate that. You can then have different EDLs that are populated by different jobs that run in the background and those will then be pushed into your infrastructure. And then, of course, again, if you're familiar with PAN-OS, you'll know that you could then say, for example, for this EDL that's pretty much used that as a watch list, that EDL block all the traffic that originates from it or goes towards it. And for this EDL, we're using that EDL's white list and that's going to be the EDL, for example, Office 365 or else they do by workspace infrastructure, packing all the Google IPs. There's many, many different things that you could do here that could be very, very powerful, it's a big win from a configuration perspective. And because a lot of this has been put up in a way for plug and play, it's also not a massive, massive amount of overhead for you to take advantage of this. Now the other thing that we can do is, of course, we know that you have policy matching in PAN-OS, you can actually exploit this through the API, using XSOAR, you can validate all those EDL changes against your security policies before you go and deploy them and then you can use XSOAR to actually you can do that validation for you to make sure that you're not breaking anything from a conflict perspective when you go to deploy that. So this is really be useful. I've gone through with many customers, and I found that it's just a very, very, very simple way to get value from I would say not just threat intelligence, but just general IoC feeds or in the IoC feeds as called IP feed, domain feeds that are useful out there, both the friendly Intel and all the bads are. All right. So the other thing is that we have safeguards to prevent the insertion of incorrect domains. Again, you know that PAN-OS can be -- as every OS does, could be very specific for the format of content. And that means that you can actually use XSOAR to strip out any noise, anything that could have gone in to PAN-OS so that we have as a valid entry, but we can also use this for different tools that have their requirements around things that need to be stripped out or left in for the purposes of inserting those into lists in various different network security tools, EDR tools, SIMs, et cetera. All right. Let's talk about XSOAR Threat Vault, CDSS. So that's going to be our next major topic. I mentioned that earlier. Again, this is something that I've done personally in terms of manually going through the Threat Vault website, pulling up a signature, getting all of this detail as you see here on the screen, this is actually coming from XSOAR. So here, you could actually go into XSOAR to pull back contextual information. This can be very helpful for the security operations center, and some network security people that would do this kind of investigations, but pretty much anybody in the organization that wants to run through this kind of data and pull it through. You no longer have to go and do that on the fly manually, you could have that enrichment happening where you're pulling in the additional detail. For example, you have a CDSS alert or spyware signature that goes off, you can go and enrich that further and then make some decisions based on the detail that comes back within the Threat Vault data. So this is really useful, really great way to make use of Threat Vault and pull that additional data in. So here, we have extra going and stretching that. This could also just be a way to get a bulletin where you're getting the latest details and the release notes of various threats that are being populated, maybe only one to track certain types of threats as well. XSOAR could actually bundle that up that out to the PDF as a monthly PDF, for example, you can do all sorts of really interesting things with this. So for example, you could be looking at, you could be tracking how many threats that you have, how many feeds you have CDSS, you could extract that data and you could actually start to build out some sort of reporting next to on a month -- on a weekly basis, on a monthly basis, et cetera. So with the Threat Intel module, because we're able to tie in and pull in all of these threat intelligence feeds. And again, sometimes the term Threat Intel isn't voice. The perfect one here because it's not just threat. We're also pulling in data on benign, [indiscernible] benign, IPs benign domains, again, for use cases like being able to white list certain things, being able to white list taking to Office 365 and other SaaS services, Dropbox, et cetera pretty much anybody that's in the cloud providers. So anyone that's going to share that content ahead of time, you could use this tool to pull that data in, you could have your own dedicated library. And in fact, in the case of the threat into our reports, you could also write out reports to get the tool to write reports for you on anything that has been blacklisted. So let's talk about XSOAR and WildFire. So WildFire, of course, is our amazing cloud-based sandbox. We can upload and embed new SaaS samples or web pages using WildFire and I can automate this using XSOAR. So you can get XSOAR to go and push data into Wild, push things into WildFire, pull that data back in, get that real-time information from tens of thousands of customers we have out there in the world and then make certain decisions on threat hunting clusters from the case security operations center, maybe trying to see how you need to public specific rules or update your rules in the case of the network security people. So there's many ways that you could actually use this integration to benefit the way that you work. Because we get this detail, and we also have our Unit 42 Threat Intel baked into the Threat Intel Management module or let's call it TIM module. Let me just see if there are any TIMs on this call. Okay, there are no TIMs on the call, so I'm safe. So I'll save him without setting anyone. And apologies if there's a TIM that I haven't seen, but I don't see one right now. So what we do is with the TIM module, we'll have our Unit 42 Threat Intel coming in. We'll have the autofocus data, we'll have a WildFire data and then you could bring in all of your own feeds too whether those are open source, posting feeds or you're bringing in premium feeds. You could then weight the reliability of these different feeds. So here, you can see how reliable the feeds are being listed out. And then you can also pull in additional data like the MITRE tactics and techniques, [ FRED Active ] data, you also get reports from different threat actors from Unit 42. And you can bring all of that together to get a comprehensive view of every single indicator in your environment. This is really powerful for things like threat hunting, for validating threats, for adding if something is a false positive, et cetera, and just to help your team do your work more effectively, add customers, of course, have CPI teams that would use this type of technology. But again, remember that the same tool can be used to do things like the external dynamic list. So you're getting a lot of different capabilities for handling indicators at scale in a single module, which is really helpful. So here is just an example of showing in this case called [ cabin ]. Of course, we always have these weird names for these various threat actors. So giving a little bit of detail for the threat actor and how you can see we have that relationships had. So we could actually use that to fact relationships with different indicators in the environment. We can do this for reporting -- out of the box reporting in the TIM module too. So it's a very powerful way for you to get into the weed of what is actually happening in your environment. And as you can see here, we also have in [indiscernible] itself. So that's directly from the product. You can see all the detail that you get for a WildFire report with all the additional details of the verdict the different hates that you will get. So can -- if you're used to a WildFire report, you get that detail all in the environments as well in the TIM module. So let's have a look at what that looks like, let's go through our personal demo video. [Presentation] We're able to then move on to that [indiscernible] indicator. We see the various different feeds. It's been categorized. It's malicious, all the different feeds are listed there. You could see that we have the relationships as well. So in this case, this is related to the clock malware group and malware campaign. Then you can see additional detail on the related incidents. And this is something I haven't mentioned here. Within XSOAR, every single time that there's an incident or an incident could come from alerts, data coming in from a third-party technology and e-mail, et cetera, also to different ways to feed data into XSOAR. Once the data is fed into XSOAR, XSOAR runs script that will automatically attract indicators and then with those indicators we'll have this indicator, really interesting right now, within the indicator view, we'll automatically populate all the incidents. So this is really great because it means that with one click into an indicator, you can see where else this has been spotted in your environment and what types of tools are spotted in. In this case, this is the XDR tool, but it could be that you're seeing the same indicator through Prisma Cloud through the firewalls, et cetera. Of course, in the case of files, it should be decrypted traffic or it's decrypted traffic. And here, we can see that we're also looking through the WildFire report of this particular file has. We're getting the detail that supports the assessment from WildFire that is malicious or additional detail there is about the behaviors, the parameters that were being used. So this is really powerful because again, one place within that module, we're able to get that detail. So remember that XSOAR with PAN-OS, we could do many different things for reaching back into the PAN-OS API. This is one of our built-in playbooks that is part of our 3 content packs. Again, most of the content in XSOAR, be a product out of the box. And here, we're providing you a way to do things like block an IP using static address groups. You can, of course, use dynamic address groups, user groups, et cetera. You can create a managed objective, you made a push conflict to your firewalls in all the various form factors, I have customers that will be using for batch upgrades as well, which is really powerful. And then you can query all of your various logs, whether that's to do real-time enrichment when you're doing some sort of an investigation, and that could be cross products as well. So it could be that you have an alert from your SIM, and then you trigger additional enrichment within the playbook to go and look at their firewall, things to go and look through EDR tools to match that all up to also reference the actual Threat Intel light that you have within the product, all of that together. And that makes it much easier for teams to get the data they need right to hand when they start doing the investigation because the product will go and do a lot of that heavy lifting for you. So let's look at a couple of outcomes here. So we had a Fortune 100 consulting services company. They were doing 10 to 20 rule change requests per day, was taking the fixed 15 minutes to an hour, 60 to 400 hours a month, which is a significant amount of time. So this allowed them with XSOAR, they were able to do fewer manual tasks to automate a lot of this heavy lifting to improve their efficiency in net ops and to ensure that there's networks are more scalable, adaptable and stable. So again, it's just making life easier by letting the tool do a lot of heavy lifting to augment your team. And then, of course, we've been at Black Hat for most of the last 6 years. We've been providing various security infrastructure services. We've also brought extra into the Black Hat to automate the classification of indicators to do MAC address lookups. Some of our team have even gone and built some really interesting things. So there's a Black Hat box that's used as Blackbot that works through XSOAR that allows other people in the team to easily communicate with it, to open cases, to ask questions, let XSOAR go and run off and do work that's being triggered by that bot. Again, I know the term bot is a bit loaded now. So to be fair, this isn't some sort of generative AI kind of bot, this is a bot that's actually running through external or speaking through the fact API, and this could be really powerful if there's a quick way for someone to interact and ask questions. We are also able to do complete network segmentation and can call this through our firewall to monitor through XSOAR and to ensure that we can then treat different traffic in Black Hat the way it's supposed to be treated. So if you've ever been to Black Hat, I've been fortunate enough to be a couple -- to go there a couple of times. And you'll know that there's kind of the user traffic area. This egresses well after the public Internet and this infrastructure to Black Hat itself. We were able to segment all of this and then reach for that, we're able to prioritize any alerts and any suspicious activity. I can tell you having fact in a Black Hat knock, there is a lot more. There's a lot more than you'd expect. So -- and again, it's for most people would expect quite a bit, it is significant. This is allowing us to quickly [indiscernible] simulated and real malicious activity. So that's kind of wrapping things up. This is what we're able to do when we bring our firewall technology, our CDFF technology together with XSOAR to streamline a lot of this activity to integrate Threat Intel or Intelligence in general, use it in a better way in a more intelligent way and to streamline the day-to-day operations, doing things like requesting rule changes in our environment. But let's change tack a bit. Let's talk about the cloud. So let's talk about Prisma Cloud and the way that you can bring that together with Cortex actual. Now again, we're going to lead this software with a stat, by 2023 70% of all enterprise workloads will be deployed in cloud infrastructure and platform services, up from 40% in 2020. So that is just speaking to the trend that we're all very aware of. The trend is that we're seeing more and more things being deployed at the cloud. This is very true because day-to-day, I speak to PXOs, I speak to head of security operations, I speak to CIOs sometimes as well. And the common trend is very much that everything is going up into the right. The attacks are going up to the right, the deployment in cloud infrastructure is going up to the right. And we all need to find better ways to make use of these tools. Now Prisma Cloud is amazing because it gives you that detailed information about potential misconfigurations, vulnerabilities. It allows you to scan your container environment to both agents and agent less. The thing is, though, it does generate a lot of different alerts for this. And the challenge with managing a tool like this, which is true for any sophisticated tool of security, is repetitive and high quantity costs, potential misconfigurations of the technology. There's no defined cloud security response processes of playbook. So what we want to do is we want to get to a point where we're able to take the technology and link it back into the remediation flow and to have a playbook built around it. Now remember that there are multiple teams that are often involved in alert remediations, maybe some of you in this call are sitting in those types of teams. And you'll know that it can be quite painful to kind of send that data around paying back between different teams, especially if you're the one sitting at the center of the investigation because you're effectively then having to ping a lot of different people back and forth. I've worked with many customers that have had to do this in all these different teams. And that can be very, very challenging. So what we want to do is we want to be able to tie it back into our cloud infrastructure. We want to be able to tie to tool like Jira, ServiceNow. We want to tie to tools like Splunk and we want to bring all of those things together so that we can get a handle of the alerts, we can automate as much as possible, but we can also prioritize our load. So we want to prioritize risk, you identify them and incident in virtual machines or containers or the mobility-related incidents. We want to have granular routing for those alerts that we can send them out to the team that need to look at them. So a particular piece of infrastructure belongs to Ms. or Mr. X, Y, Z. We want to read that alert to them and say, "Hey, please look at this, please pack this, for example, the data in this container don't deploy that image, et cetera. Then when it comes to actually, to support this, we want to reduce that alert. So what we're doing within, [indiscernible] one of our [indiscernible] playbooks for Prisma Cloud is to be able to take action, so we're going to pull in alerts from Prisma Cloud, where we're going to deliver between the 2 technologies so that if we close an alert in XSOAR, it will be closed in Prisma Cloud and vice versa. So what this means is that we can then hook into the infrastructure, and we'll see that in a bit. I'm going to take you through a demo video. We can search for events, we can adjust our cloud configurations and permissions on the slides. We can deal with any IM issues that might come up along the way. We can trigger vulnerability scans. And then we can also use the outputs of those scans to be able to do some additional work. And then, of course, we can manage all of our cloud accounts. And we can also patch into our various ticketing systems to open ticket and track tickets in our infrastructure. And then we want to enrich -- we want to do enrichment prioritization and routing. So here, we see an example of a playbook that is analyzing that if we have data in AWS, we have data in GCP, in Azure, we can identify the severity and then we can pull in the complete incident context. So again, if you've ever investigated anything in Prisma Cloud, you'll know that sometimes you're lacking that detail, very often, you're lacking the detail that's relevant to your own organization because, of course, the tool's going to tell you. Hey, we spotted this with this particular virtual machine, with this particular container. Then do you want to kind of go into your own organization just to find out who owns the technology, who is working on it, et cetera, which teams are responsible, which account it fits into, all of that is a bunch of clicking around, sending e-mail, waiting for response, pinging people waiting for their response. You can get experts to do much, if not all, of that work. So a good example of that is we have data collection path in XSOAR, whereby you can send an e-mail out to somebody to say, "Hey, we found a piece of infrastructure, does it belong to your team?" Yes, no, get that response back in and take a series of actions or send an e-mail of the case, we found a piece of infrastructure with this CPE, click here to read about the additional detail in the CPE, can you confirm if there's a patch mitigation in place and/or patch plan in place? Yes, no. And then that incident can maybe be closed automatically without having to get an actual human to get involved and to do the manual work required. All right. So taking a look at how we can enrich data, now Prisma Cloud itself has a lot of rich data in it. So when we get an alert, we can pull back the network logs to get detail on subscriptions IP because, of course, Prisma Cloud has many, many different threat feeds, there's about these dozens of threat feeds that go into Prisma Cloud that allows us to do things like user special [indiscernible] to see vulnerability data to pull all of that into the product. So when we have a Prisma Cloud alert, we can query the Prisma Cloud API, we can pull in the detail on the vulnerabilities that have been discovered by the agent let scan it or to defend itself. We can also query to get the [indiscernible] permissions that I find and exposed to virtual machines, and then we can start to bring that entire story together by using XSOAR. So this is really important that XSOAR sits on top of Prisma Cloud and allows us to do that a difficult enrichment on the flow. So this then allows us to prioritize virtual machines. So we have a -- we have many playbooks that will help you to do this out of the box. That will then ensure that you're able to take incidents that arise in the cloud environment, identify virtual machines that have been exposed to the Internet, for example, that are misconfigured in the various cloud environments that maybe have default encryption infect them, and then we can go through these different severity checks. You can check. There is a public address associated with the instance, or despite that you can get the finance-related instance, get the IM permissions and enrich the particular IP that the instance is talking to, for example, to be what 100% sure that this is either a trustworthy IP or particularly bad one. We could notify the teams as I talked about earlier, and then we can create ticket. And now the other thing is, if you kind of take a step back to this, that you will see on this, in this fleet on the right-hand side, you see several disclosure, next one. One of them here is, there is still icon, I hope you can see is a little book icon. A little book icon is actually a symbol for its up cable. So this is a very important concept in XSOAR because, again, if you've ever done a little bit of programming, modularity is always best, though in the XSOAR world, we do this through the modularity of playbook. So we'll have is we'll have some playbooks that you can use that can do repetitive -- certain repetitive things for you. And the really good news is that we have many of these playbooks within -- extra already within the Prisma Cloud content pack. Within that comprehensive content pack, you can get all the details that you need that will allow you to start to do things like pull in alerts, prioritize the alerts, decide whether or not you want to route them out, connect to your various ticketing tools, and you can just have enough to get you started fairly quickly, to take advantage of the fact that you can automate a lot of things in Prisma Cloud. So let's actually go through our second demo. We have a third demo coming just now too, so just stick around for a demo. But let's go through our second demo and talk through a bit of Prisma Cloud, how that actually comes together in terms of tracking exposed virtual machine and virtual machines vulnerability and then helping getting XSOAR to help us to do some prioritization and to link that back into Prisma Cloud. So let's go through this demo. [Presentation] Do a quick prayer to, in this case, I guess, the video guards and not the demo guards. This video will play a long life. So here we go. So we're going to start with this view in Prisma Cloud that some of you may be quite familiar with. And what this is showing is that it's actually showing all of the various pieces of infrastructure and it's showing in red, the ones that are speaking to suspicious IPs. It's also tracking the different pools, affect -- different applications like SSH and RDP to how this communication is actually taking place. You can use the privy language within Prisma Cloud to extend this and get more detail, if you want, the nice privy language within the product that comes from the -- inherited from the RedLock acquisition we made many years ago, in fact, I was way back in the day when I was in the company when I was early days in the company, and we brought in this capability. So here, you can see that we can see a lot of detail on our various pieces of infrastructure. And then the next thing that we can see the Internet exposed virtual machines and then we can track these Internet exposed virtual machines. We have the detail for each one of the machines. We can see the accounts they're associated with and where they're deployed, but then we also can see the various vulnerabilities or virtual machines. Now the challenge is that you have to try and tie all of this data together. X, you have to do that manually in this case, but XSOAR is going to help us actually bring this all together in one view and also enrich all of that further with detail. So here, we're able to do this. These queries -- is really powerful queries and Prisma Cloud to get this additional detail on these Internet exposed virtual machines of vulnerability. But what we want to do is we want to send specific alerts into XSOAR and this is another very important concept. Many customers will, I speak to, will say, well, we'll spend a bunch of things. Should we send all of alerts from Prisma Cloud out into various tools. I would say that send an alert into XSOAR if you have a planned work. So make sure that you have a playbook that you're going to use, again, there's lots of prebuilt content in XSOAR, beside the alerts that you want to send into the tool, creating alert rules as we're going to walk through now and then take advantage of that to push that into X, into XSOAR do -- let XSOAR do some work for you. So as you see, we're going to give this alert a little name. We're going to create that notification so that it will be pushed out and then we're going to go ahead and save this in a little bit. So we're going to go over to the next screen. We're going to decide which accounts we're interested in. So we're going to track all these specific accounts rather than track all accounts. So in this case, we're going to track the default account group. We're going to assign a policy. So that policy is going to decide which alerts are actually picked out. And in this case, we're tracking Internet exposed virtual machines. So we want that particular policy that they're alerting in Prisma Cloud to be part of our alert rule. So we're saving that alert rule. We need to go ahead and create a service account so that XSOAR is able to interact with Prisma Cloud, and pull data on behalf of Prisma Cloud and also to be able to take action as part of that. So we're going to go ahead and create that service account or we're going to call it the VM alert prioritization. We're going to associate it with a role that's a read-only role to be able to grab the data that we need and to give it the access key as well. And in a moment, we're going to take that into XSOAR, so that we can add this into our XSOAR tenants and save and onboard Prisma Cloud. Now as you can see, there are many, many commands in XSOAR that we have out of the box that covers the Prisma Cloud API pretty comprehensively. And then we're going to show you how we can go in and insert the details that we've taken in from Prisma Cloud. We'll enter those details in. We'll test and ensure that our integration is working, and then we're all set and ready to go and run our playbook. So here, we have a playbook that's running according to Prisma Cloud alerts. It will first do things like establish which CSP we're going to use. So in this case, we're working between AWS, GCP and Azure, so all the big 3. From there, we're going to decide to ensure that this is a public IP and they were going to do a series of different enrichment steps. So I want to emphasize some of these enrichment steps. So for example, here, we'll pull in the IM details. We'll pull in additional findings. Now all of this is going to show up in the alert layout and the case info that we'll see shortly in XSOAR. This is another very important thing that we haven't spoken about yet. In XSOAR and indeed in XIM, you're able to customize and alert layout so that you're able to show the specific detail that you care about. Now this is really important because when you're investigating a case for phishing or investigating something to do with an alert from CDS -- from the CDSS and PAN-OS, you're investigating an alert from your SIM, from EDR, et cetera, you don't always want the same information presented to you in the same rigid fraction. You want to have a lot of flexibility in how that information is laid out to you, and XSOAR allows you to have a lot of control around how information is laid out so that your team can work with the information they need when they need it as part of that lab. So here, we're going to grab additional detail. We're going to change the severity on the fly of our alert in XSOAR if we need to. We're also spending out Slack messages, as you can see. So you'll see that we're actually sending creating a ticket in Jira, creating an issue in Jira, to use Jira terminology. We're standing out a Slack message and then we're deciding to close the XSOAR Internet. So we've done a bunch of different work. We've communicated across different pooling, so Slack and Jira, 2 examples. We could do this by sending a web hook into MS Teams. We extend out e-mails. There's many, many different ways we could communicate with teams to bring them into the inference to inform them if something has happened. We open a ticket to time to work to teach, for example. This can all be done within the XSOAR playbook. And here, we're actually going to see an example of the layout as I spoke about earlier, you can see quite a bit of detail here being pulled through from Prisma Cloud and also the enrichment work that's been done. So this is really key because again, this allows us that flexibility to lay out the information as you please, to get that IM detail to do the findings as well based on the enrichment work that XSOAR has been doing on our behalf. And we will then capture all of that information, so that it's possible for us and both of the Jira ticket too, and then possible for us to track everything from within XSOAR and have all of our various tools populated appropriately. In the investigation tab, we'll have additional information. We're pulling in Threat Intel as well from export TIM module, so we're doing enrichment there, and we're pulling in detail from Unit 42 and from various other different Threat Intel sources like VirusTotal and AbuseIPDB. And it's helpful because then we're able to be sure that there's net IP initiatives and then help to have the remediation action, which again can fit the policy and be very specific or it can be something that's done manually by the analysts. So this is how we're able to pull in data, as you see from Prisma Cloud, can insert an alert into XSOAR track those alerts based on, in this case, BM being exposed to the Internet. [indiscernible] is communicating with a malicious IP, taking remediation steps, communicating to the outside world and doing a lot of work on behalf of our analysts. So let's move on to cryptojacking. So conscious that we have about 10 minutes left. So what I might do is ensure that we have enough time to go through some questions. I do see one question in the chat. I'm going to have a look at that question, so bear with me. I might answer that one live. If you have questions at this point, feel free to start sharing those questions. And we might just skip through our cryptojacking demo just for the sake of time and then have a look at that. So I see just a question around the invitation. So yes, that invitation is correct. So that's no issue, [ Christian ] has handled that. If anyone else has questions, feel free to go ahead, quite inserting this question. If I start to take questions what I'll do for the next 10 minutes or so that I'll stop and answer the question. But for now, I will continue with final part of the presentation on cryptojacking. But again, feel free to just bring in your questions as and when you have them. So cryptojacking operations are on the highest profile Cortex Cloud. And again, we know all about this. Last year, I did a series of presentations, part of the research that. So again, I didn't do the research, our research team did the research, they have some really interesting data on real-world threats projecting. So the scenario that we're going to talk to is based on the real threat that our referring [indiscernible], as presenting those last year throughout our Ignite on Tour conferences. So again, if you want to hear people speaking about these kind of things, we call network issues, feel free to come to Ignite on Tour, throughout this year. And the first one is actually going to be in London. Obviously, we see the adverse assessing the cloud by core. So what this adverse was actually doing is that they're hiding their IP viator, they're hiding the location viator. They're going tampering with the IM to create persistent, but they actually end up creating the user for themselves. They're opening up the security group rules that they can create any type of ideas that these types of threat actors are very financially motivated. So they just want to open up your cloud environment as much as possible and then find a dormant region ideally in the case of this particular threat actor that they can then go and deploy a bunch of very, very large in this case, EP2 instant pit, they go and do their cryptomining and to do as much cryptomining as they possibly can before we shut them down. They don't really carefully set up tons and tons of alarms. They're not trying to be long slow. They don't mind being noisy because the idea for them is just make as much as you can and then if you get shut down, what's the next target, that's it. So let's go through the demo today. Just before I get right into that demo, what I'd like us to see them about one [indiscernible] demo guards. So right up top, I want to show you a state of affairs after the attack had occurred. So this is when the factors already gained access now and know that some people will go, well, how do they get in, don't worry about that. It's not so much how [indiscernible] on research on, we actually published a blog on this and it's a threat actor that matched the initial access to somebody who knows some phishing or something they got in to the details. They got into this environment. They are running their own script. As you can see on the left-hand side, they're going deploying [indiscernible] large, which if you're familiar with AWS, you know it is very expensive to have that many of them have been deployed at the same time, 25 instances being rolled out. They're updating the security rules to open everything up so that they can have free range to go in and out to connect their services, et cetera, to do all the cryptomining. And this is how thing stuck which is looking pretty bad, right? So then we look at how we can remediate this from an XDR perspective. XDR will ingest cloud locks and it will start to flag things like suspicious activity, cryptomining activity, suspicious kind of action from an IM perspective, connections [indiscernible] or that kind of thing. And then we can get through those alerts direct for us from XDR. So again because cloud alerts into cloud logs into XDR, XDR using machine learning to look for strange behavior, XDR analytics alert, firing, those alerts going into XSOAR and then an XSOAR playbook picking that up and starting to do additional enrichments to get details of the cloud environment, which we go into our enrichment playbook that we'll get additional detail on things like the regions that this is being done and get the geo location data. Again, it's much information as an analyst that have to do manually, by the way, an analyst have to run through all of these thoughts, maybe some of you that are on this call might be analysts yourselves. And you'll know that you have to go and jump through a lot of information to try and validate some of the alerts because again, as we all know, alerts that are coming from machine learning technology is not perfect. It's giving you a hint that something bad may be happening and then you need to go and validate that. And this is why it's still amazing if you combine machine learning alerting with automation, because we get the best from these technologies and that the machine learning tells you, I think that's happening, the automation goes and does some automated work to go in and enrich that and do investigation. And then together, they're saving the analysts a significant amount of time press hunting on the one side from a machine learning perspective, and then validating the alert on the other side from the automation perspective, which is exactly what we're doing here with XDR, feeding into XSOAR. So XSOAR is doing a lot of the enrichment work. It's pulling through the data to set the verdict as well, [indiscernible] findings is how to playbook works, and then identify this as being perhaps a high severity alert. We have an additional sub playbook that will go check the IP. You can see that it says unusual allocation and heavy allocation of alerts to existence. So in other words, what we're doing is we're seeing an unusual allocation of resources later on in the playbook on the past will actually track the ASN. We will see if it's happening in the dormant region. So we're determining if the dormant region, which is not always an easy thing to do, but we're using both the machine learning alert that help with this and then letting XSOAR self go and double-check and validate that. And once we are able to do that, we're then able to set the verdict to continue. So we might -- we'll then hand over to the user and say, can you go and manually check all the findings so far that have been done through automation, understand this and see if you agree with this verdict, we're going to set that verdict manually to continue and if it's a false positive, you can go ahead and close that alert in XDR and XSOAR. If it's a true positive, we can go and trigger a response on the XSOAR side and that trigger a response from the XSOAR side can feed into the cloud technology. We have a bunch of different sub-labels that are there specifically for AWS or Azure or GCP that will help us to shut down that activity as it's happening and to terminate the instance or just stop the instance by choosing that automation that remediate automatically. Now I want to linger on that for a moment because here, we see that that's actually often the user. So the user that is investigating with incident, we've done a series of different steps when we said, do you want to have this do automated remediation. If yes, then the technology will go ahead and fire you through the steps. It's not a runaway train of automation, you are still very much in control. Now we go back here, see what happened in this particular pack when XSOAR kicked in, you can see that we've now gone ahead and stopped and/or terminated depending on the decision of the playbook, all of those instances to ensure that we no longer have business that will be running. But usually on the right terraform, they are created a lot of [indiscernible] part of the playbook. So all that work that the creditors rating is also actively being reversed by the technology on behalf of the organization. So let's move through to the last [indiscernible] here. We invested about the cryptomining alerts from XDR. So all of this being done for machine learning. We will reach that with a lot of detail. We've stepped a verdict including manual [indiscernible]. We just are opting the [indiscernible] findings. You decide on what the verdict should be. We have done response through automation, allowing the user to be part of that flow, usually identified if you want to do automated response to take a manual response, and we've closed the incident. We notified all the relevant parties. So recap [indiscernible] Prisma Cloud and bring in the full capabilities of Prisma Cloud, Cortex XDR [indiscernible] capabilities, we can bring those tools into XSOAR to help us do things like prioritize alerts to integrate all the intelligence that you saw much earlier with the Threat Intel Management and to have a centralized management portal and notice that we've just talked and again we talked about 3 Palo Alto Networks tools, but we can actually integrate with hundreds and hundreds of tools out of the box, which allows this automation to be quite straightforward and it allows us take advantage of all this content that we have and to start taking advantage of automation immediately. Just a very, very quick case study just on prioritizing incoming alerts. We had a health care services company that was now able to automate alerts at scale from Prisma Cloud to manage them using automation, to use a playbook to do that, to handle incidents related dozens of Prisma Cloud public working machines. That's all being done by XSOAR today. And then the last thing, if you'd like to repeat more, we'd like to hear a bit more about what we do in XSOAR, the playbooks and content that our teams are working really hard on, go ahead and scan that QR code, I'll linger on this slide and go to our really, really exciting playbook of the week blog that is being written by our product team, our product marketing and management teams, our engineers also to people that are contributing to our XSOAR community, a great way for you to see the different ways you can take advantage of automation with our technology and beyond. Okay. So I'm going to stop here. I hope that this webinar was informative for you. I know there's quite a bit of information along the way in a few different demos going in many different directions. So I do appreciate you bearing with me as we kind of walked through that. And I hope that you will move on to read a bit more about this through our playbook of the week. And again, feel free to reach out to your Palo Alto Networks teams. If you'd like to hear more about anything we discussed today. That's it from me and the team today. So thank you for attending. And if you have any questions, I'm happy to kind of give it another minute or so for anyone that has a question that they'd like to ask and we can walk through that. All right. So since we're at the half -- almost half of our market, I'm going to give it another 30 seconds or so. We've got a summary slide up on stream. Again, if you have any questions, feel free to fire away in the Q&A, and I will address those questions. Once, twice. All right. So thank you again for attending this webinar. That will be it for today and have a pleasant day, evening, afternoon, et cetera, wherever in the world you are. Good bye for today.
This call discussed
For developers and AI pipelines
Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.