Back to vendors
P

Palo Alto Networks

Also known as: PANW, Palo Alto, Cortex AgentiX, AgentiX, Cortex XSIAM, Cortex XSOAR, Cortex Cloud, Cortex XDR, Prisma AIRS, Unit 42, Cortex Extended Data Lake

Visit site
Entry priceContact sales; embedded in Cortex platform agreements or sold as the standalone AgentiX platformFull pricing detail

Cortex AgentiX, the successor to XSOAR: prebuilt and custom security agents over 1,100 integrations and 1,300 playbooks, manual approval for sensitive actions, every agent action logged, a model selector (Gemini, Claude) and tenants in eight regions.

Palo Alto Networks is a cybersecurity company whose agent platform is Cortex AgentiX, the successor to Cortex XSOAR. AgentiX builds, deploys and governs AI agents for security operations, cloud security and IT. It ships system agents, including Case Investigation, Automation Engineer, Phishing Response, Threat Intel and Cloud Posture agents, and lets teams build custom agents from natural-language prompts, grounded in their own context and policies. Agents draw on more than 1,100 integrations and more than 1,300 playbooks, AI prompts can be dropped into playbooks as steps, and integrations can call external MCP servers; a Cortex MCP server lets LLM clients query the platform.

Administrators decide when agents act on their own and when they need approval, and actions marked as sensitive require manual approval. Every action an agent executes is logged, along with its reasoning and plan. A model selector gives EU and US tenants a choice of Gemini 3.5 Flash, Claude Sonnet 4.6 and Claude Opus 4.8, with tenants in the US, EU, Singapore, Japan, India, the UK, Canada and Germany. AgentiX runs embedded in Cortex XSIAM, XDR and Cortex Cloud and as a standalone platform, and the company reports it was trained on 1.2 billion playbook executions.

Vendor details

Canonical URL

https://www.paloaltonetworks.com

Category

Security / SOC agent

Subcategory

Agentic security operations platform

Funding status

Public company (NASDAQ: PANW). Its identity business is CyberArk, acquired in February 2026 and now marketed as Idira.

Company status

independent

Use cases & customers

Primary use cases

autonomous security operations center responsecloud security posture, detection and responseIT operations automation including patching and onboardingcustom no code security agent buildinggoverned agent workflows with traceability and permission management

Target customers

large enterprisesecurity operations centerscloud security teamsIT operationspublic sector

Deployment options

SaaS tenants in EU, US, SG, JP, IN, UK, CA and DE regionsembedded in Cortex XSIAM, Cortex XDR and Cortex Cloudstandalone Cortex AgentiX platform

Integrations

More than 1,100 prebuilt integrations and 1,300 playbooks, integrations that call external MCP servers, a Slack integration to trigger agents, and a Cortex MCP server for LLM clients. AgentiX runs natively in Cortex XSIAM, Cortex XDR and Cortex Cloud, and the Cortex API documentation includes AgentiX APIs.

In practice

A SOC replaces manual triage with prebuilt agents that plan, reason and execute a full response workflow end to end, against playbooks the organization already trusted under XSOAR.

A cloud security team lets agents investigate and resolve posture and detection issues autonomously, with guardrails ensuring every automated action stays inside the organization's existing policy.

A platform team builds a custom agent in the GenAI builder against 1,100 existing integrations rather than writing new connectors, with MCP support for reaching tools outside the Cortex estate.

Agentic Index coverage score

10.5 / 14 capabilities · 75%

Integrations & Tool Calling Full

More than 1,100 prebuilt integrations connect through APIs, and some integrations call external MCP servers. A Slack integration triggers agents and runs remote executions, and agents deploy natively across Cortex XSIAM, XDR and Cortex Cloud. Admins can also add MCP integrations in the agents hub as extra tools for agents, and AgentiX powers the Cortex Agentic Assistant inside each of those products.

SourcePalo Alto Networks, paloaltonetworks.com/cortex/agentix and cortex-docs.paloaltonetworks.com agents hub MCP integrationsread 2026-10-05

Workflow Orchestration Full

Several system agents do the work (Case Investigation, Automation Engineer, Phishing Response, Threat Intel and Cloud Posture), and customers can build their own from natural language prompts. They run over more than 1,300 playbooks, where AI prompts can be dropped in as steps. Agents act through four kinds of actions, playbooks, scripts, commands and AI prompts, and custom agents can run custom scripts. Admins register actions, build agents and assign actions to them in the Agentic Assistant Hub.

SourcePalo Alto Networks, paloaltonetworks.com/cortex/agentix and cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiX and Configure the Cortex Agentic Assistantread 2026-10-05

Knowledge Grounding & RAG Partial

Custom agents are "grounded in organizational context and policies," and agents work over the customer's case and playbook data, but no retrieval layer for agents is documented. Palo Alto says its agents were trained on 1.2 billion playbook executions. In the Agentic Assistant Hub, admins can add knowledge sources that give agents business context, and a Help Center agent answers questions from the product documentation.

SourcePalo Alto Networks, paloaltonetworks.com/cortex/agentix and cortex-docs.paloaltonetworks.com Configure the Cortex Agentic Assistantread 2026-10-05

Human Oversight & Guardrails Full

"Actions marked as sensitive require manual approval." Administrators decide when agents act on their own and when they need approval, and any sensitive action can be flagged to require a person's validation before a critical system change runs. Agents are also bound by the organization's existing roles and permissions. An agent never exceeds the permissions of the user running it, so approvals sit inside the access the organization already grants.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiX and Configure the Cortex Agentic Assistantread 2026-10-05

Security, Identity & Governance Full

Attestations on the trust center include SOC 2+ reports, ISO certifications and FedRAMP for cloud products, though the page does not map them to Cortex products one by one. Role based access controls bind agents to the organization's existing roles and permissions. The same access controls decide who can build agents and register actions in the Agentic Assistant Hub, and an agent cannot do more than the user running it is allowed to.

SourcePalo Alto Networks, paloaltonetworks.com trust center certifications and cortex-docs.paloaltonetworks.com Configure the Cortex Agentic Assistantread 2026-10-05

Observability & Auditability Full

"All actions an agent executes are logged," and the agent's reasoning, its reading of the request and the plan it creates are visible alongside the actions it takes, with "every step logged and fully auditable." The logs cover every kind of action an agent takes, whether a playbook, a script, a command or an AI prompt.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiXread 2026-10-05

Memory & State Persistence Not documented

The platform has data stores, and no agent memory with a scope and lifetime is documented. The Agentic Assistant is described as agents, actions, knowledge and access control, with no memory component among them.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiX and Configure the Cortex Agentic Assistantread 2026-10-05

Deployment & Data Residency Full

Tenants sit in named regions: the US and CA in North America, the EU, UK and DE in Europe, and SG, JP and IN in Asia. Which models are available is documented per region. The current docs also list Australia and South Korea, with the EU tenant in the Netherlands, and the wider model choice is offered in the EU and US regions.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiXread 2026-10-05

Prebuilt Agents, Templates & Packs Full

Five named agents come prebuilt (Case Investigation, Automation Engineer, Phishing Response, Threat Intel and Cloud Posture), and each does its own job. More than 1,300 playbooks ship alongside them. The docs add a Help Center agent for questions about the product, and the Threat Intel agent is described for threat hunting.

SourcePalo Alto Networks, paloaltonetworks.com/cortex/agentix and cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiXread 2026-10-05

Triggers & Channel Coverage Full

Agents run around the clock on cases and alerts inside XSIAM, XDR and Cortex Cloud, and playbooks run agent steps as incidents arrive. Slack can trigger agents too, so alerts wake them and chat reaches them. In the Cortex Agentic Assistant, people start an agent with a plain language prompt. AI prompts placed in a playbook run as their own workflow steps, and from Slack a user can also investigate and run remote executions.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiX and paloaltonetworks.com/cortex/agentixread 2026-10-05

Model Flexibility & Routing Full

A model selector gives EU and US tenants a choice of Gemini 3.5 Flash, Claude Sonnet 4.6 and Claude Opus 4.8, with Claude Sonnet 5 on request, while other regions have Gemini 3.5 Flash. The customer chooses, and what is available is documented per region. The selector labels the three tiers Flash, Thinking and Pro, and the choice is made per chat.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiXread 2026-10-05

APIs, SDKs & MCP Extensibility Full

The Cortex API documentation lists Cortex AgentiX APIs next to the references for the other Cortex products, XSIAM, XDR, XSOAR and Cortex Cloud, and documents API key generation. A Cortex MCP server lets LLM clients query the platform. The MCP server is a download that runs on a local machine or in a container, and its docs use Claude Desktop as the client while supporting any MCP client, for investigating and managing cases and issues and for building custom tools.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Cortex API overview and Cortex MCP serverread 2026-10-05

Testing, Debugging & Optimization Not documented

Customers get no harness or scored tests for evaluating agents. Palo Alto reports training on 1.2 billion playbook executions and MTTR figures from its own development and results, and says more than 1,000 Cortex customers have turned AgentiX on.

SourcePalo Alto Networks, paloaltonetworks.com agentic workforce blog and /cortex/agentixread 2026-10-05

Browser & Computer Use Not documented

Agents act through integrations, playbooks and scripts; no browser or computer use is documented. Each agent action is a playbook, a script, a command or an AI prompt, and agents can also visualize data or an investigation. None of those actions opens a browser or works a desktop screen.

SourcePalo Alto Networks, cortex-docs.paloaltonetworks.com Agentic AI in Cortex AgentiXread 2026-10-05

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-22·Agent capabilityVerified

Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense, an agentic security service available worldwide by annual subscription. It continuously tests changing environments, validates attack paths across applications, APIs, cloud infrastructure and other assets, and supplies prioritized remediation guidance. A routing system assigns security tasks to frontier and open weight models.

Bears on: Security / enterprise

View source
2026-09-01·Funding / partnershipVerified

Palo Alto Networks has acquired Console, an AI-native platform designed to deliver autonomous agentic capabilities across enterprise operations. The acquisition will integrate Console's technology into the Cortex security operations portfolio to automate security investigation, prioritization, and response workflows.

Bears on: Agent capability

View source
View all 2 changes for Palo Alto Networks →Tracked since Sep 2026 · Verified from public vendor sources

Pricing

Contact sales; embedded in Cortex platform agreements or sold as the standalone AgentiX platform

enterprise platform agreement, not disclosed

What is public

Product packaging and availability (embedded and standalone) are public; no prices.

Billing mechanics

Not publicly disclosed. Direct enterprise sales and channel, structured around multi product platform agreements rather than per product licenses.

Cost watchouts

Inference, not stated by the vendor: when AgentiX is bought inside a Cortex platform agreement, its marginal cost is hard to isolate from the platform commitment.

Variable cost rationale

Inference, not stated by the vendor: with no billing unit published, cost depends on the platform agreement and scope.

Additional watchouts

Price the Cortex platform commitment and the AgentiX delta separately.

Sales call required

Yes, required for paid access

Free / trial

None retrieved

Commercial notes

Public company (NASDAQ: PANW).

Key ambiguities

How the standalone AgentiX platform is metered and how it is priced against the embedded version are not published.

Missing data

All pricing and the AgentiX metering unit.

Agentic Index verified 2026-09-28

Alternatives to Palo Alto Networks

The closest documented capability profiles to Palo Alto Networks among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Swimlane10.5 / 14Matches Palo Alto Networks across all 14 documented capabilities
  • Ghost Security10.0 / 14A lighter documented profile than Palo Alto Networks
  • D3 Security (Morpheus)10.5 / 14Adds documented Memory & State Persistence
  • SentinelOne10.5 / 14Fuller documented coverage on Knowledge Grounding & RAG
  • Tines11.5 / 14Adds documented Memory & State Persistence and Testing, Debugging & Optimization
  • Andesite9.0 / 14A lighter documented profile than Palo Alto Networks

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.