Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary
May 22, 2024
Earnings Call Speaker Segments
Ankit Pandagre
analystNow let me begin with welcoming you all, so a very good morning, good afternoon, good evening, wherever you are in this world. And also, let me introduce myself. My name is [indiscernible], and I'm going to be on the instructor for this session. I'm a security engineer working for CloudNomics and we are delivering the session on behalf of Palo Alto Networks. Now talking about my professional background, so it includes experience in security operations center and MSS environment. And folks, this experience has provided me with the practical understanding of SOC operations, which I look forward to sharing with you throughout our time together, right? Now I'd like to mention here about the important piece of the webinar, like if you have any questions or queries throughout the session. I request you to post it only into the Q&A box. So those who are with your name, all right? And as you know, guys, this is a short session of 30 minutes. So in case I won't get time to answer your question, well, you don't have to worry about it. We'll collect all the questions and someone from Palo Alto Networks will get back to you with your answers. All right. So now without any further delay, let's start our presentation. So here are the agenda for today's session folks. So first of all, we'll have a presentation, wherein we have a couple of slides, which are basically meant to provide an overview about Cortex XDR Solution and the new features that are included in the latest release, all right? And then we'll jump into the demo and spend about 20 minutes or so over there. And at the end, I shall be providing you the links and materials where you can learn more about Cortex XDR, all right? So let's begin. So with Cortex XDR, we are trying to transform detection and response by bringing together all your data for industry's best visibility and attack detection coverage, right? And now the question appears like how does Cortex XDR -- so first, you need to configure your Palo Alto Networks product to send risk data, which is network, endpoint and cloud data to the Cortex data link and if you don't already have the Cortex XDR Endpoint Protection, you would need to deploy our lightweight single agent on your end. And here, Cortex XDR proper endpoint includes endpoint protection and makes it easy for you to block malware exploits and [indiscernible] attacks while also connecting all the data you need for detection and response. Now you can also send network data such as data from our [indiscernible] firewall, virtual cloud-based firewalls or Prisma Access to Cortex XDR for network-based detection [indiscernible]. And in addition, we also gather data from solutions like Prisma Cloud or even AWS, Google Cloud, Azure, as well as identity provider. So basically, Cortex XDR helps you swiftly response to threats with powerful surging capabilities like cross-data insights, root cause analysis as well as incident management. Now, while it can work with one source of data like your firewall or endpoint data, we highly recommend you to get the data from your multiple sources so that you can eliminate the blind spots and get the context needed to stop attacks quickly. And our cloud-based deployments provide the scale you need for forensic investigation, analytic and machine learning. Plus you don't need to manage log servers on premises. You can, in fact, use your existing prevention products as sensors and enforcement points for detection and response. So basically, with all these Cortex XDR simplifies the operations as compared to stand-alone silo, right? And once you have activated Cortex XDR, you can accurately detect and quickly investigate and contain threats and safeguarding your enterprise. So with this, let's see how Cortex XDR works. And folks, this is how Cortex XDR works. So Cortex XDR has this unique combination of capabilities that provides customer everything they need to secure their organization, right? Like with Cortex XDR, you can block attacks, exploits, malware and fileless attacks, right? So at first, Cortex XDR is able to prevent everything with is -- the leading network endpoint and cloud security product. And we can automatically detect attacks with behavioral analytics and machine learning using Cortex XDR. We also include customizable detection tools to detect certain combination of attributes and activities. So that implies with the help of Cortex XDR, now your IT team can even create their own rules to detect threats specific to their environment. And this is what accelerates threat hunting capabilities with powerful searching capability. And now because Cortex XDR is taking together network endpoint and cloud data, it can actually determine the root cause of an attack just to speed up the investigation. For an example, Cortex XDR not only determines which endpoint executable was responsible for our network attack but it can actually figure out which application has launched that executable, right? So basically, Cortex XDR helps your analysts to understand the root cause of an attack. And it also produces a time line of the event leading to the threats, provide integrated net intelligence. So your security team knows exactly what the threat is and what action they should take. And finally, analysts can respond to threats and safeguarding like they can respond to threats and adopt differences. And with the tight integration with enforcement points, this port allows an analyst to stop attacks quickly because now they can also adopt detection rules by applying knowledge gain to help future investigation. And now new features that were added over the last year allows analysts to respond or perform further investigation in real time. Like just to give you an example, it includes using the Cortex XDR user interface to open a live terminal session to any managed or unmanaged endpoint. And along with our ability to affirm a search across your organizations to either destroy or delete unwanted files. So folks, pardon me, like you can open a live terminal session to any managed [indiscernible]. So folks, this is how Cortex XDR works. And now let's see the entire landscape. So one of the most important part of this solution is Cortex XDR agent, which offers best-in-class prevention to stop day -- like zero-day malware, including ransomware, fileless attacks as well as exploits. And it is a software agent for Windows, Linux, MacOS, Android and [ ComOS ] endpoints. And this agent is designed to block like exploit and malware at all stages, right? Like the attack life cycle and provides you protection online and off-line, which is completely transparent to your end user. So now the first step of our multi- [indiscernible] protection is to block exploit itself, right? before they can deliver to the endpoint. And for this, we offer powerful exploit prevention based on the techniques. So like we block the various exploit techniques that attackers use to deliver the ransomware in the first place. But if a file is delivered perhaps in an e-mail attachment and the user attempts to launch it, we check for known threat based -- like threat based on the threat intelligence like from our WildFire malware prevention service, and then we do -- like what we do is like we apply AI-driven local analysis to examine a [ fight ], right? So our local analysis is based on machine learning module -- model, which has trained over 10 million malicious and [indiscernible] samples. And it also examines over 20,000 characteristics of a file virtually [indiscernible] to render a verdict before it's allowed to execute. So with all these capabilities, we are also able to keep our false positive low by training model on not only the bad files, but on the good files as well. And at the same time, if you have the cloud connectivity, we send the file to our cloud-based malware prevention service, which is WildFire. And here, we apply the power and scale of cloud-based machine learning model to further analyze the file and return a verdict to the agent because our powerful behavioral threat protection model which examines processes when they are running in order to determine the combination of activities associated with the attacks, this allows us to store zero day as well as fileless attacks and [indiscernible] that do not match any known attack pattern. And along with this, we also have an anti-ransomware [ module ] that deploys the decoy file in the key location and looks for ransomware behavior to block attacks, like -- however, like we have invested a lot of effort to stop ransomware attacks early in the sequence before they can execute. So our post-execution protection is additional layer of defense, and we provide online and off-line protection, malware scanning and a full suite of endpoint protection capabilities, including a host firewall disk encryption, device control as well as vulnerability management. And folks here in this slide, we can see how Cortex XDR delivers 100% protection and detection [ mitral ] attack evaluation. So I'm happy to see this. I have like I've been talking about mitral attack evaluation, right, on how you -- how protection and detection requires different methodologies. And I'm very much pleased that it's represented very well and anyone can come here and very easily see what techniques were executed and implemented. And with that, we come to this slide, which shows the rapid pace of innovation of Cortex XDR product since it was first released. So you can see that there are multiple releases each year and every quarter including new features and workload. And in the latest release, which is Cortex XDR 3.7, we have new extended threat hunting module and new security module for IAS protection. Well, we'll see that when we'll hop on to the demo part just in a couple of minutes. So folks, with this, we come to the end of our short presentation. And now it's time to quickly hop on to the demo environment. So just allow me a second for that. Let me bring the demo environment for you and here it is. So I hope my screen is visible folks, right? So in the first part of the demo, we'll be showing you the new feature of the Cortex XDR dashboard? And some of the new item in the widget library, all right? And now like this library is what makes it easy for our customer in order to create their own dashboard, okay? So as you can see from this main dashboard, like this main dashboard shows a high level of overview of all the incidents, right? Like you can see top incidents, top post incident by assignee, open incident by severity and top total incidents, right? And obviously, like this is what you'll get a high level of overview about the incident. And now let me show you an important dashboard, which is security admin dashboard, which is over here. So basically, this dashboard is especially designed for security admins to do like as I had shown to pull out this dashboard, you just need to click on this drop-down button over here and then you need to select the security admin dashboard from this list, right? And this security admin dashboard is like new and displays an overview of the detailed information regarding the incident across your organization? And also, how long an incident has been opened. Right now, the data is not populated yet, but once we'll start working on the coding part, it will get populated, right? So basically, this dashboard has these 5 sections, as you can see. And based on your need, you can edit and modify like you can modify it to show more data. And now one important question, security administrator and manager ask is how long incident have been open? And what is the average time it takes for my stock team to resolve an incident, right? So to answer that question, we have -- like we have this widget over here, which is resolved incident MTTR, which is resolved incident mean time to resolution, right, which is one of the KPI of [indiscernible]. So this data shows that the target MTTR like for all instant severity, right? And now let me show you how you will -- like firstly, we'll populate the data, then let me show you how you can work on it, right? So for -- to populate the data, what we need to do is like we need to work on reporting. So firstly, like before that we'll touch upon the reporting part because working into security operations centers like we need to work on reporting, right? Like it's -- we need to work on reporting so often, right? So it is important to know more about it. So for that, what you need to do is like you need to just click on this 3 dot button, which is over here, and you need to save this as report template. And then you can give any name like I would give today's date so that we can differentiate it by name. I'll give [ SOC ] reporting, just a minute, right? And you can give a description, a little description over here, like -- or you can just leave it blank, right? And then you'll just click on save and you will get this message like template has been created successfully, right? And now to open the template and like make a report from that template, you need to go to the report tab over here. And you need to find the template which you have created just now? For that, let me just first -- okay. You just -- you don't need to go to report, but you need to go to the report template and you need to find the template you have created right now? And then you see this -- there is no icon like this over here, right? That means this report template is not scheduled yet. So now you need to open it like just right click and click on edit, then again, you'll get option to give the name of it, description and the timeframe. As I have given it for SOC reporting, I will give description in monthly reporting, so I'll be selecting last, all right? Then I'll click on next. And see guys, this is how you'll get all the data populated over here, right? And we were like -- we were talking about a security admin dashboard, right? So here, this widget is for a result in MTTR and this data shows that our target MTTR for the high severity incident, critical, medium and low, right? And now, a common question arrives is like whether these values are hard-coded. So the answer is no. We expect our customer to configure the values as per their requirement or goals, right? So this is what I just wanted to show you for -- from the dashboard. And now for the reporting part, like as we have -- it is a template, then we have less like populated disc data. And now let me show you the power of widget library. So here, you have this widget over here, right, number of widgets you have over here, And to just find out the widget, which is like best suited for you, you can even type on over here, like you can just type top and you'll get widgets named related to top. You can see top 10 incidents, top 5 hosted risks. And to use that widget, it is very easy. You just need to drag and drop. And this is how it is -- how easy it is to work with widget library, right? And similarly, you'll get the 3 buttons, like 3 dot button, which is more button and you can just remove the widget from here. So if you want to add any of the more widget, you just click and drag and drop. And based on your need, you'll just -- you'll make the dashboard. And then you'll click on next, right? And then Cortex XDR gives you this option to send this report over e-mail, you need to type in the desired e-mail recipients, e-mail ID, right? Also, you can send this report over the communication channel like Slack, for that you need to enable Slack from here. And for this demo itself, like I would stick to the schedule part and I'll leave that value as default like well. So now I'll just click on save and now you'll see that icon would come in front of the template, like this. That means this report template has now been scheduled and now it will run daily at 12, right? So this is how you'll work on reporting, folks. And now let's have a quick look at incident, like how you'll work on incident, how you'll perform investigation on incident? For that just allow me a second. Let me quickly grab a glass of water. Thank you. Okay. Thank you, everyone. So you know like we need to keep ourselves hydrated especially in these hot summer days, right? So yes, that's why drinking water is a good idea? Okay. So now let's move with the incidents. So for that to have a look on the incidents, what you need to do is like you just need to first expand the wave of it. And now you need to go to go under incident response tab and click on incident. All right? And now for your better visibility, I will change the theme as light so that you can have a good view on it, right? And now this is what the incident page looks like, right? And here, you are seeing this left-hand side of pane, right, which is sort of e-mail preview type of view, right? So here, like what you can do is like you can select the incident and it will get automatically updated in this right-hand side of screen, which is completely redesigned. So let me first quickly get a good incident for you. Okay. Let me pick a good incident for you, folks. So I think I need to log out and log in, then I'll be showing you a perfect example, right? So just allow me a couple of seconds, folks, so that I could just log in once again, and I'll show you that incident, right? So I think I need to first -- let me check on another tenant -- let me first check on the another tenant. If it is not available, then I'll just jump on to the another tenant, okay? So first of all, let me check, I'll sort the incident by severity or else I could start. Okay. Suspicious file dropped, okay, so this could be a good example to show you guys, right? So this is what I just wanted to show you like this left-hand side pane is kind of e-mail preview window right, where you'll get that like a few details about the incident like it's ID, obviously, the incident ID, its status, whether it is that or not, score, right? And the user name who has like worked on this incident, to whom it is assigned to. Then you'll see the name of the incident, right? And a short description about it. Then you can straightaway check it from here, like what are the assets are involved in this incident? What are the users involved in this incident. Also, you can check what technology has contributed to raise this incident. Like this icon is for Palo Alto Networks next-generation firewall, and this icon is for XDR agent, right? So you can check it from here, like this incident includes events from XDR agent and next-generation firewall, right? And now by clicking on it, you'll open the incident here in this right hand side window, which is completely brand new. And let me show you like what are the new things over here. So first of all, what are the things you'll see over here. First of all, you'll see the severity of it, that's core trend. And then you can even edit a name, like you can even give a name to this incident, right? Then moving down like moving side, you'll see to whom it is assigned to and its status, right? Then you have this filter button over here and more button from where you can start saving your filters and you can check on their filters. And right. Also, if you want to straightway have a look on the alerts table in tabular form, then you can just click on this alerts table like this and it will open all the alerts, right? So right now, let us focus on the incident first, then we'll see. And then moving down here, you'll be seeing how many alerts are there and their sources, like next-generation firewall, XDR agent, how many PCs are involved, like hosts are involved, users are involved? And what is the WildFire [indiscernible]. What is the threat intelligence, then you'll be seeing this for -- like you'll be seeing these 5 tabs, which is very important. This is for overview tab, which will give you an overview about the incident, then you will be seeing e-assets and artifacts tab, right? And we'll talk about it in our later part. And now just to show you like new feature that was included in the latest release of Cortex XDR, is the MITRE ATT&CK framework mapping. And to have a look on it, we need to click on this top button and you'll see these are all the TTPs over here. And you'll see under the [indiscernible] assistance, the boot or log in autostart execution technique has been detected in this incident, right? This is how you'll get to know or the incident accordance to MITRE ATT&CK, right? Now from the overall page itself, you'll get a view like total number of alerts, then you'll see what are the automations work on it, then you'll see the list of artifacts and the asset. And now let me show you a good feature of Cortex XDR, which is the 360 complete view of the user, which is users risk data, right? For to have a look on that, you need to click on this more button and click on open user risk view. And this is how you'll open the 360 view of the user in which first part -- in its first part, you can see -- you can check on the details of the user, like you can check on the user's name, e-mail ID. It's title, last login time frame, department, location, last authentication timestamp, right? And the right hand side screen, from the right-hand side screen, you can check on the score trend, which will be very helpful in your investigation. Then you can check on the related incident in what are the incidents this user has been involved in. Also, you can check on the related alerts and insights. Actual activity like login and logout activity and all. And then you can check on the log in attempts, authentication attempts and [indiscernible]. So this is how it's easy to have a complete 360 view about any user, and you can get a clear picture like where this user has been throughout your network, all right? So this is how you will check on this feature. And now moving back to the incident, then after the overview tab, we have the key assets and artifacts tab from where you can check each and every artifact, which are included in this incident, right? And you can straight away check its adaptation from like -- or focus or virus total or you can open it in 2 quick launch up, right? You can check the reputation from here? And you can even add this to block list or in allow list. But be careful because it would be like enterprise-wide. If you're allowing this hash from this incident, it doesn't mean it will -- you are allowing this artifact for -- like this hash value for this particular incident only. You will be allowing this like hash value for enterprise-wide search, right? So this is how you'll check work on the artifacts. And similarly, you'll also have the post and the users feed. Then you have alerts and insights tab where you can check on each and every alerts and insights and to move like -- the switch over from alerts and insight, you'll get an option right here. So right now, we don't have, I think, alerts here. Let me just -- I think it's not loading up right now, but no problem. For now we'll be moving to next tab, which is a time line. And let me tell you guys this time line tab is just for the incident itself. That means from this time line, you can check when this incident has been raised, when this intent has been created. Then this incident has been assigned to any analyst and whether it has been start marked -- like it has been marked start or not, right? So this kind of information, you will get it from the time line tab then in terms of the next tab, which the execution tab. And here, this is a very important tab because from here, you'll do the actual root cause analysis. For now, like it is not opening right, so let me just select different incident, so yes. So by clicking on the execution tab, you'll be able to see causality chain like this, right? And because this is file-based detection so that's why we have got this kind of figure. And now this figure is interactive for like if you'll hover up on this node, you'll get to see more information like child process, parent process and other information. So you can expand its view like this, and this is how you'll get more information. Also, if you'll click on this node, that information would be populated under this -- like at this bottom side of screen, right? So this is how you'll check on the execution chain and the causality chain. And now folks, let me just quickly touch upon the forensics. So for that, you need to go to the incident response tab and you need to click on forensic, all right? So basically, all the information that's connected by the forensic model can be seen under this ad hoc, right, over here? Just a minute, so let me just open first of all. Just a minute, guys, let me open the incident because I think we are not seeing a proper view, right? Just a minute. Or else, let me just navigate to a different tenant, here it is. Just bear a second with me, and we'll be having a look on the forensics model. Here it is. Let me just first expand the view of incident response, then we'll select the forensics part. Okay. So I think we need to try after few minutes. So hey, Yes. So no issues, we'll check. So guys, next part, what we can see is like we can check on assets like you can check on asset inventory from this assets tab and you can check on on-premises asset or cloud compute instances, right, from this list and then you can like check on the cloud compute instance from this option, right? And if we click on it, you'll get to see this site inside pin from where you can get all the details about this asset. This how you'll check on the asset inventory. Similarly, you'll check on the network configuration. You can work on vulnerability assessment. And then like you need to select host inventory from the like -- just a minute, you can check on the users or you can check on the application, right? Also, for the admin role purposes, endpoint tab is all about the endpoints, right? How many endpoints you have on boarded? And what are the endpoint groups you have and for XDR agent installation, you can like go to agent installation and you can create and download the XDR agent, right? And then you need to share this agent file with your employees? And then like -- or else you can just straight away, you can do it you'll just download that XDR agent installation file, and then you can run that installation file on that endpoint. And then it would be connected, and it would be listed down over here in this list, right? Let me just clear the filter first. So this is how you'll check on the endpoint. Also, you can check on the managed services which is backed by our Unit 42 team, right? So now let me check whether it has been keyed in or not, no issues. All right. So guys, this was pretty much it, which I wanted to show you. As you know, this session was a quick introduction about Cortex XDR product and its capability and what are the new features we have included in the Cortex XDR product. So yes, this is it. And now it's time to share more materials with you if you want to learn more about Cortex XDR product, then you can just go to that link and you can just read about it, right? So just allow me a second for that. Meanwhile, I'm getting a link for you. You can even -- I'm just sharing that link in the webinar chatbox, right? You can even request for demo or you can even like join our ERs workshop on investigation and threat hunting, right? So this is the link for that and now just allow me a second so that I could share you more links from where you can learn more about Cortex XDR. So just a minute. Here it is. So folks, with that we come to the end of our short presentation and that demonstrations of the Cortex XDR product. And I hope, as you know, we have overshooted the time by 13 minutes. So now it's time to wrap up the session. And I hope that this session would have helped you in gaining some knowledge regarding Cortex XDR product and like gaining knowledge around the investigation, right? So this is it for today's session folks. And first of all, I really, really thank each and every one of you for being such a patient audience and lovely audience. And let me tell you, we have more webinar, boot camps and workshops lined up for Cortex XDR and Palo Alto Network's other products. So I really, really hope to e-meet you in our -- in one of our upcoming sessions. So yes, and as I see there are no open or unanswered question in the Q&A. So now I think we are good to wrap up the session. So thank you very much, everyone, and I hope to e-meet you again. So till then keep learning, keep hunting. And of course, have a great rest of the day. Thank you, everyone. Bye-bye. Take care.
This call discussed
For developers and AI pipelines
Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.