Palo Alto Networks Incident Response
Unified incident response capability for SOC analysts — investigate incidents, triage alerts, manage endpoints, execute response playbooks, and assess attack surface exposure across Cortex XDR, XSIAM, XSOAR, and Xpanse.
What You Can Do
MCP Tools
xdr-list-incidents
List XDR incidents with optional filters, pagination, and sorting.
xdr-get-incident-details
Get extra data for a specific XDR incident.
xdr-update-incident
Update an XDR incident.
xsiam-list-incidents
List XSIAM incidents with optional filters and pagination.
xsoar-create-incident
Create a new incident in Cortex XSOAR.
xsoar-search-incidents
Search incidents with filters in Cortex XSOAR.
xsoar-get-incident
Retrieve a specific incident by ID from Cortex XSOAR.
xsoar-update-incident
Update an existing incident in Cortex XSOAR.
xdr-list-alerts
List XDR alerts with optional filters, pagination, and sorting.
xsiam-list-alerts
List XSIAM alerts with optional filters and pagination.
xdr-list-endpoints
List XDR endpoints with optional filters, pagination, and sorting.
xdr-isolate-endpoints
Isolate endpoints from the network via XDR.
xdr-unisolate-endpoints
Unisolate endpoints and restore network connectivity via XDR.
xdr-scan-endpoints
Initiate a scan on endpoints via XDR.
xsiam-list-endpoints
List XSIAM endpoints with optional filters.
xdr-run-script
Run a script on endpoints via XDR.
xdr-get-script-results
Get script execution results from XDR.
xdr-start-xql-query
Start an XQL query on XDR.
xdr-get-xql-results
Get XQL query results from XDR.
xsiam-start-xql-query
Start an XQL query on XSIAM.
xsiam-get-xql-results
Get XQL query results from XSIAM.
xpanse-list-exposed-assets
Get internet-exposed assets from Xpanse.
xpanse-get-asset-details
Get internet exposure details for specific assets from Xpanse.
xpanse-list-incidents
Get Xpanse incidents.
xpanse-update-incident
Update an Xpanse incident.
xpanse-list-attack-surface-rules
Get attack surface rules from Xpanse.
xpanse-update-attack-surface-rule
Update an attack surface rule in Xpanse.
xpanse-list-services
Get exposed services from Xpanse.
xpanse-list-ip-ranges
Get owned IP ranges from Xpanse.
xsoar-create-investigation
Create a new investigation in Cortex XSOAR.
xsoar-get-investigation
Retrieve a specific investigation by ID from Cortex XSOAR.
xsoar-add-entry
Add an entry to an investigation in Cortex XSOAR.
xsoar-list-playbooks
List available playbooks in Cortex XSOAR.
xsoar-run-playbook
Run a playbook on an investigation in Cortex XSOAR.
xsoar-search-integrations
Search for available integrations in Cortex XSOAR.
xsoar-search-integration-instances
Search for integration instances in Cortex XSOAR.
xsiam-list-assets
List XSIAM assets with optional filters.
xsiam-configure-datasource
Configure a datasource for XSIAM ingestion.
xdr-get-audit-logs
Get audit management logs from XDR.
xpanse-get-audit-logs
Get audit management logs from Xpanse.
xsiam-get-management-logs
Get management logs from XSIAM.