• Course overview
  • Course details
  • Prerequisites

Course overview

About this course

This 2-day, hands-on training course is designed to equip cybersecurity professionals with the knowledge and skills to effectively investigate incidents and manage security operations using Cortex XSIAM — Palo Alto Networks’ next-generation SOC platform.

Participants will learn how to query and analyze logs with XQL, leverage built-in threat intelligence tools, automate investigation workflows, and visualize security data using dashboards and reports. With a strong focus on real-world application, this course combines lectures and lab-based exercises to ensure participants gain practical expertise in incident analysis and response.

Audience profile

This course is intended for SOC/CERT/CSIRT/XSIAM analysts and managers, MSSPs and service delivery partners/system integrators, internal and external professional-services consultants and sales engineers, incident responders and threat hunters.

At course completion, you will learn:

  • Investigate incidents, analyze key assets and artifacts, and interpret the causality chain.
  • Query and analyze logs using XQL to extract meaningful insights.
  • Utilize advanced tools and resources for comprehensive incident analysis.

Show More Show Less

Course details

  1. Introduction to Cortex XSIAM
  2. Endpoints
  3. XQL
  4. Alerting and Detection
  5. Threat Intel Management
  6. Automation
  7. Attack Surface Management
  8. Incident Handling
  9. Dashboards and Reports

Prerequisites

Participants should have foundational understanding of cybersecurity principles and experience with analyzing incidents and using security tools for investigation.

Our Technology Partners

Spectrum Networks is the Authorised Learning Partner for some of the leaders in IT technology for Digital Transformation