<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="36479" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/paloalto-pcxdr-ia" lastchanged="2026-03-27T09:30:51+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Cortex XDR: Investigation and Analysis</title><productcode>PCXDR-IA</productcode><vendorcode>PA</vendorcode><vendorname>PaloAlto</vendorname><fullproductcode>PA-PCXDR-IA</fullproductcode><version>1.0</version><objective>&lt;p&gt;This course is designed to enable you to:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Investigate cases, analyze key assets and artifacts, and interpret the causality chain.&lt;/li&gt;&lt;li&gt;Query and analyze logs using XQL to extract meaningful insights.&lt;/li&gt;&lt;li&gt;Utilize advanced tools and resources for comprehensive case analysis.&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;Participants should have a foundational understanding of cybersecurity principles and experience with analyzing incidents and using security tools for investigation.&lt;/p&gt;</essentials><audience>&lt;p&gt;This course is for a wide range of security professionals, including SOC, CERT, CSIRT, and XDR analysts, managers, incident responders, and threat hunters. It is also well-suited for professional-services consultants, sales engineers, and service delivery partners.&lt;/p&gt;</audience><contents>&lt;p&gt;Course Modules
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;1 - Introduction to Cortex XDR&lt;/li&gt;&lt;li&gt;2 - Endpoints&lt;/li&gt;&lt;li&gt;3 - XQL&lt;/li&gt;&lt;li&gt;4 - Alerting and Detection&lt;/li&gt;&lt;li&gt;5 - Vulnerability &amp;amp; Forensics&lt;/li&gt;&lt;li&gt;6 - Platform Automation&lt;/li&gt;&lt;li&gt;7 - Case Management&lt;/li&gt;&lt;li&gt;8 - Dashboards &amp;amp; Reports&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>This course is designed to enable you to:



- Investigate cases, analyze key assets and artifacts, and interpret the causality chain.
- Query and analyze logs using XQL to extract meaningful insights.
- Utilize advanced tools and resources for comprehensive case analysis.</objective_plain><essentials_plain>Participants should have a foundational understanding of cybersecurity principles and experience with analyzing incidents and using security tools for investigation.</essentials_plain><audience_plain>This course is for a wide range of security professionals, including SOC, CERT, CSIRT, and XDR analysts, managers, incident responders, and threat hunters. It is also well-suited for professional-services consultants, sales engineers, and service delivery partners.</audience_plain><contents_plain>Course Modules



- 1 - Introduction to Cortex XDR
- 2 - Endpoints
- 3 - XQL
- 4 - Alerting and Detection
- 5 - Vulnerability &amp; Forensics
- 6 - Platform Automation
- 7 - Case Management
- 8 - Dashboards &amp; Reports</contents_plain><duration unit="d" days="2">2 days</duration><pricelist><price country="GB" currency="GBP">1575.00</price><price country="DE" currency="EUR">1980.00</price><price country="US" currency="USD">1995.00</price><price country="CA" currency="CAD">2755.00</price><price country="AT" currency="EUR">1980.00</price><price country="SE" currency="EUR">1980.00</price><price country="SI" currency="EUR">1980.00</price><price country="IL" currency="EUR">1980.00</price><price country="CH" currency="CHF">1980.00</price></pricelist><miles><milesvalue country="US" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue><milesvalue country="CA" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue><milesvalue country="GB" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue><milesvalue country="DE" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue></miles></course>