Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary
July 12, 2023
Earnings Call Speaker Segments
Nana-Ampofo Ampofo-Anti
executiveGood morning, good afternoon and good evening, depending on which time zone you're joining from. And thank you for joining this webinar Cortex by Palo Alto Networks, titled Less Busy Work, More Security. So like this title implies today, we're going to talk about how we can use automation in intelligent ways and security operations. I'm your host for today, and my name is Nana-Ampofo. I'm a technical specialist for our Cortex products. Day-to-day, I work with customers from all around the world, talking to them about how we can transform security operations and more focused around how we can use technologies, like automation and machine learning, to make changes to the way the teams work and to drive better, more sophisticated outcomes and most importantly of all, give analysts the precious time back that they need to focus on the things that matter. So this is something that I'm incredibly passionate about. We're going to talk about how we can do that today from the perspective of our XSOAR technology and where that fits in. So we're going to go ahead and get started. And I'm going to take you through some of the content today. We're going to get to see some demos in video contents, too. So you'll get to also see the technology in action. It's not just going to be death by PowerPoint. So let's go ahead and get started. All right. So I would say that if you joined this webinar, you probably encountered some of these things before, so I'm not going to spend too much time on it. Some of the things that I see talking to security teams day to day really are these. I will go into a conversation, and I won't even pull up a slide deck. I'll talk about what's going on in your team? What are you struggling with? And invariably, this is the feedback I get. It's almost like a magician playing a game where I go. Did you mean to say this? Because unfortunately, it is true that we have a lack of integration technologies. We have teams that are struggling to communicate with end users, and it's an absolute pain. So for example, within our own security operation center, we have a Slack bot that's tied to our XSOAR technology. And that Slack bot can ping a user and ask a question. It can pass the response from that user. It can take that back into playbook, and it can take additional actions. This is the way to actually change how security teams work, is to apply technology that's more than capable at this point. You don't need fancy AI or anything along those lines. It's just a well-structured playbook that reflects your internal process and you can change the way you work. So you can start to tackle those repetitive tasks, you can capture all the actions that are taken on the incident automatically. So the beautiful thing about XSOAR is that it has this automated documentation capability. Now I don't know about the rest of you, but I personally despise admin tasks and filling in forms and those kinds of things. Now XSOAR will actually capture all that work for you. So as your team is working, there's a ChatOps capability. There's a tool within the product called DBot that does many things, but one of the things it does is that it will go ahead and it'll capture all the actions that have been taken. The automated actions, the manual actions, chatting with your teammates around something and making decisions, you'll capture all of that within the incident. You don't need to go and make separate notes about it later on. It has a full incident management capability as well. So it's really, really, really useful. But let's dig a bit deeper, let's get into actual use cases. So we're going to start with incident IOC enrichment. I know, terribly boring thing for most people. And that's precisely why we want to automate it because dealing with IOCs, it's repetitive, it's manual, it is time-consuming grunt work. It requires you to jump between disparate tools and to effectively try and find a needle in a massive haystack or in fact, more accurately in multiple haystacks spread across different barns in different locations. So you're just driving around like a maniac trying to find those needles, and it doesn't really work. So we can do something better than that, like we have technology that we can use, the playbooks to help us do that better. So with playbook technology and with the orchestration of XSOAR, we have support for hundreds of different tools. And as you'll see, we have hundreds of different pieces of content out of the box because, I'll say the quiet part out loud, there's lots of different other sort of technologies out there, and you could go, why are you different from vendor X? We're different because our focus has gone past just providing integrations, integrations depending on the tool that you're trying to integrate with depending on how flexible or sophisticated their API is, if they provide you with an SDK, and depending on whether you're familiar with certain generative AI tools out there that will help you to build code or you're an excellent coder yourself or somewhere in between, you could probably write an integration to just about any technology, right, you can do that. The difficult part is actually building the content around that, learning from a community of users that have used that content, improving that content over time. So we are a content capability for SOAR as opposed to just an integrated -- integration product. And that's incredibly important because as you can see here, we have this process around extracting the indicators, doing the enrichment, doing the update and notifying portion for the users and then going -- closing that playbook, integrating with ticketing tools as well, but I'd like to show you how that works. Let's spend those time on slides and actually get into the technology.
Unknown Executive
executiveEnrichment of the indicators detected an incident response is one of the first tasks security analysts perform when responding to incidents, but this process is repetitive and manual and slows down investigations. Secondly, isolated security tools make it hard to reconcile intel across platforms for an overall view of indicator malice. One of the essential ways to speed up decision-making is to automate the data retrievement processes that require manual effort on behalf of your security analysts. Cortex XSOAR offers entity enrichment playbooks that automatically pull information about indicators of compromise from your threat intel sources for richer context. From the moment your analysts are alerted to an IOC, Cortex XSOAR has already highlighted and organized the essential information needed for deeper investigations. Let's take a look at the entity enrichment, phishing version 2 playbook to see this principle in action. The entity enrichment, phishing version 2 playbook comes with the Cortex XSOAR phishing pack available for free on the XSOAR marketplace and relies on sub-playbooks, integrations and scripts to provide actionable intelligence on suspected phishing e-mails. Specifically, this playbook enriches intelligence about all files, e-mail addresses, URLs, IPs and domains associated with the e-mail that triggered the playbook. Clicking on the file enrichment sub-playbook, we see that once XSOAR has detected a file hash, 3 operations are automatically run simultaneously. If XSOAR detects both a SHA-256 hash and that [ Silence Protect ] version 2 is enabled. It will pull the relevant threat information from [ Silence Protect ]. Second, it will run the VirusTotal Private API sub-playbook that queries file reports on the specific hash affiliated with the e-mail. Third, it runs the file enrichment of VirusTotal API version 3 sub-playbook to obtain any necessary information from its repository. Another sub-playbook, highlights how once XSOAR has detected a URL within the suspected e-mail. It simultaneously captures screen shots from the URL, verifies the secure sockets layer for the URLs and obtains a URL report from VirusTotal's Private API. To conclude, the entity enrichment, phishing version 2 playbook showcases just a few ways you can automate indicator enrichment.
Nana-Ampofo Ampofo-Anti
executiveRight. Great. So that gave you an idea of the types of outcomes you can get when you use playbook technology, the previous contents in XSOAR and our expertise in the content to actually take a different approach to solve this problem. But let's look at a mini-case study just to wrap this for a section up. So this is an organization that had more than 10,000 [ alerts ] per week, only [indiscernible]. They were able to reduce those 10,000 [ alerts ] to 500 per week. That is an incredible reduction. That's because the technology was able to just remove the noise, remove the repetitive manual tasks, like you saw in the demo, and just fundamentally change the way that this team works. And that, again, is really going to be our theme today, so let's tackle our next topic. The next topic is everybody's favorite, phishing incident response. I'm sure you've all been victims of [ attempted ] phishing e-mails in your personal lives and in your business lives, whether that's been someone actually coming after you or your company trying to catch you out, so they can do some coaching around phishing. So we've all seen these before. We're little more unfortunate of us, and they have actually been in situations where something actually went wrong when it's phishing, and we have had to go and do some work around it too. So it is a topic that we should care about. Of course, it is still very much the way that attacks would trigger today. Social engineering is absolutely the best way to get it. If you can't get around technology, you focus on the people, you will find a weak link. So just like this poor baby here, this is what's happening to users. They're being suffered and often through no faults of their own because we're all just trying to do the best we can. I work with a security company, and we still have plenty of people that click on phishing links. It happens. That's the reality of the business that we're in because attackers are always getting more sophisticated, too. So how do we address that? So surprise, surprise, the answer is to use playbook capability, to use orchestration, to be able to open tickets to engage the end user through sending out e-mails and saying, "Hey, did you click on this link?" for example, and maybe even using the same technology to educate them off to the fact. Being able to really eliminate all of the manual processes around it and get the technologies to do as much of the heavy lifting as possible, so that once you're ready to actually tackle the more dangerous phishing incidents, you can have your time back to do that, whilst the technology is kind of dealing with the innocuous things and the noise and setting off e-mails to educate users as well that can all be automated. Well, let's look at demo. I'm actually going to narrow you through this particular demo. So as you can see here, we have one of our playbooks that is running. We're going to go ahead and run through that playbook. It is going to do a couple of different things. It's going to get some information, just going to pass and store information about phishing e-mail or the potential phishing e-mail, [indiscernible] so that we can watch that online. We can look at what the user would have seen. We're going to go through a sub-playbook that goes through the process of enriching entity. So it's great that you can actually have a modular or do this by even sub-playbooks. We'll gather a bunch of other details, and then we'll actually allow the analysts to take over. Now this is incredibly important because here, we're showing you how we can mix and match automated and manual tasks and allow an analyst to actually intervene where required to give feedback and be part of that process. So this shows that adopting SOAR, at least in the case of XSOAR, is not just about building some tool is going to run away and do a bunch of things that you may not want us to do. It's about building a tool that's actually going to represent the process that you have designed that handles things with a level of risk associated for your organization. And that's really key. So I speak to customers all the time, and I always see that coming up as a concern. There's this tension between having automated and manual tasks. We can have the best of both worlds and XSOAR. And we're not trying to dictate to you how you plan those. It's up to you. And having that visual playbook [ editor ] also means that and all the content we have, it actually also means that you're unlikely to have to go and code things. I'm not going to tell you [ zero code ]. That's one of those catchy marketing terms that I don't personally believe in. What I do see is that most of my customers don't tend to have a reason to go and build custom contents because, as I said, that is where we focused our work. We try to take ownership of the content to make it less painful for our customers to start getting value out of the product. Right. So just a little bit about automated phishing response. Now as you saw in that brief demo, we can dramatically reduce the amount of effort required by doing things like de-duplicating, removing and auto closing, just spam and noise and being able to take an organization that was taking 730 phishing alerts a week, and to give them 4 analyst days back per month, which is massive. So this is saving a significant amount of time. The tool also has a built-in machinery phishing classifier. So we have a model that you could trend using your own phishing data, so that you could use that to start doing some classification around phishing that can either work to complement your existing technologies for detecting phishing or it can be your solution for detecting phishing as well within your organization. So that's a really powerful capability that we have that's just out of the box is there for you to use alongside all the other contents. So that's phishing. Let's talk about everybody's favorite topic, malware investigation and response, which, I guess, you could say, ransomware investigation and response because these days, that is the malware that we are most -- we all tend to be most concerned about. Now I'm not going to spend too much time here. I think we're more than aware of the fact that there's a lot going on out there, and things are getting worse with respect to malware. Attacks are increasing. Visibility can be limited. And by that, I mean that even if you have the best capabilities, invariably because of the way market technology architectures are designed, those capabilities are looking at very specific data silos. You have the EDR, you have the MDR, SDR, [indiscernible]. They're focused on their data silo. They're pumping things up into your [ SIEM ]. You're lacking a lot of the context often, and [ SIEM ] technologies will do the best they can to give you that context. But because they're not the ones designing and building the underlying technology, there are upper limits to what they can do. So this is one of the reasons. There are other factors to it, but again, speaking to customers day to day, we find that if this leads to very inefficient operations and there are better ways to do this. So much like everything we've done today, unsurprisingly, the solution is to break this down into different steps and to look at what we could possibly automate so that we can get significantly better at the way that we do this. So there are different steps to malware investigation and response process. What we've actually done is that we've gone ahead and built a malware investigation response content pack that works out of the box with some of the more common EDR tools. So CrowdStrike, Palo Alto Networks, Cortex XDR, Microsoft Defender for endpoint. And we've made it possible for there to be very swift onboarding with these technologies, lots of built in rich content. So as you can see there, we're highlighting content. We have action for response. We've given you the ability to just go and retrieve this forensics data. You can click a button, you can isolate and unisolate an endpoint. So you have all of these things there, and there's a whole [indiscernible] that helps you to actually onboard the technology and then start using the technology. Well, let's actually have a look at that. So we're going to go through a demo now. You could have a look at what that looks like.
Unknown Executive
executiveMy name is Nicholas Ericksen, and I'm a Solutions Architect for Automation here at Palo Alto Networks. Today, we're going to be taking a look at the newly released malware investigation and response content pack available in the Cortex XSOAR marketplace today. We find that organizations largely still struggle with responding to malware incidents within their environment. Although they may have some automation already in their environment today, they still struggle with operating at scale and answering fundamentally the question of, is this a compromised device? When we look across the [ MITRE ] framework, we see a couple of different questions that might naturally be asked, such as, is there evidence of persistence or maybe lateral movement or defense evasion? And when we can finally answer those questions as an analyst, we can begin to understand what's the actual impact here? And what are the procedures that we need in order to respond? The malware investigation and response pack automates the process of asking these questions and presents the answers to the analyst so they can quickly understand the impact, respond appropriately and protect your organization. When we take a look at what's in this content pack, of course, there's the malware investigation and response incident type as well as the corresponding incident handler playbook. We support a variety of EDRs, such as CrowdStrike Falcon, Microsoft Defender and, of course, Palo Alto Networks Cortex XDR. There are a couple of supporting packs to note as well. The WildFire, AutoFocus, VirusTotal and MITRE ATT&CK V2 content packs, all provide additional enrichment information during the course of the investigation. You can contact and message or send these results to other teams using the Microsoft Graph mail integration. And also you can report on them to ServiceNow or other tools as well. Now let's take a look at the demo. When you go to install the malware investigation and response content pack in the marketplace, they'll be prompted to install the supporting packs as well. In this case, I'll choose Cortex XDR. You can also add in messaging and case management capabilities as well. Once the pack is installed, you'll see you'll be prompted to use the new Deployment Wizard to onboard this use case. The Deployment Wizard helps to streamline the process of onboarding new use cases by walking you through all the necessary steps, such as configuring the integration and entering in all the required parameters as well as providing any of the playbook inputs, configuring supporting integrations and finally, enabling fetching on the integration so that you can use your use case in production. Once you've completed all the steps in the Deployment Wizard, you will have successfully onboarded this use case and can then go and view the incidents being handled on the XSOAR platform. When we take a look at one of these incidents from an analyst's perspective, we can immediately see a ton of valuable information on the layout here. Not only do we see the endpoint details, such as the IP and operating system, but we immediately get feedback on some of those high-level questions that every analyst should ask, was there a defense evasion or execution or persistence mechanisms at play here? And all of these things are being flagged automatically by the XSOAR platform. As we continue to look into the investigation, we see that this particular incident is comprised of 2 different alerts. And although the binaries themselves that are encompassed within these alerts are not being flagged as suspicious by our threat intel, we can see that a lot of behaviors on this endpoint are being flagged by the XSOAR platform. We can see that registry keys are being modified, files are being deleted after execution, some of the data is being encrypted, and all of these suspicious behaviors are incredibly valuable from an analyst's perspective. We can also see, thanks to the [ MITRE ] integration, some more details on these particular attack patterns as well. So from an analyst's perspective, you get a lot of contextual information around not just the file and threat intel, but the behaviors of that file as well. As we continue to look down, we can see the process list for this particular machine being captured as well as some different evidence, such as WildFire reports that were being generated from the sandbox detonations. Here, we can read these reports directly from the XSOAR console as well. We can also search for individual techniques and tactics that have been flagged, such as execution. Here we can see this as being safe to evidence with more details around the individual alerts that were pulled back via the XDR, get alerts command. In this command, you're able to pass a variety of parameters, including a custom alert filter, where you can search for specific minor techniques and tactics, for example, in order to provide additional information to the analysts in regards to why these alerts were actually triggered and flagged within the XSOAR platform. As an analyst, after I've reviewed all this information, I'll determine probably that this is more than likely a suspicious event and an action needs to be taken here. We have some quick response actions for isolating the endpoint or deleting the file or killing the process as well as taking that file hash and adding it to a denial list within the environment. As an analyst, I'm then prompted to make a decision. In this case, I could say it's a true positive and leave a particular comment. Well, I hope that was a useful overview of the new malware investigation and response content pack. Check out the pack documentation and supporting blog posts for more information. And go ahead, install, onboard, deploy and automate.
Nana-Ampofo Ampofo-Anti
executiveAll right. So that gave you a good idea of how the pack works. So I'm going to just wrap this section by telling you a little bit more about -- actually going through a customer case study. So let's go through this mini case study, just showing some of the outcomes that you get by adopting this. So this organization, 22,000 endpoints, they're getting 70 EDR alerts per month. They're actually able to save 2 to 3 human days per month, which again is significant, and they were able to add case documentation, which talked about how much a lot of that capability in XSOAR. It's one of the simplest things in the product, but it's also one of the most powerful things in terms of just alleviating the pain of doing that [ happening ]. So let's move on to our next section. So up next, we're going to talk about zero-day threat response. Now [indiscernible] in these situations, I've been in these conversations with customers as well, having late-night conversations, where we're trying to actually deal with a potential threat on threat x some new 0 days out. Everyone's scrambling, trying to hunt for it and figure out how best to detect and/or mitigate against it. So this is, of course, a very, very important day to day topic. Now I won't spend too much time here. Probably fair to say that everyone on this call are more than aware of revenue loss that would come with this, how important it is to respond swiftly and the threats that could be associated with not handling zero-day threat effectively. Once again, the solution is to use automation. If you could break this up into steps, collecting the indicators, hunting for the indicators, we've already talked about indicator and IOC enrichment quite a bit and then taking action. So we're going to walk you through how we can actually do that using XSOAR. We have an emerging threat response playbook. We have a lot of content because again, as I said, it's all about content. That is the secret source in XSOAR. It's all the amazing content that we produce. And this allows you to have something out of the box to go and respond to various different zero-day threats. These are just examples. Every time there's a new major one of these, we'll go ahead and [indiscernible] content, make that available for all of our customers to start running that playbook against their infrastructure and to take action.
Unknown Executive
executiveIt's not fun to think about, but every cybersecurity professional dreads the day when their indicators point to a major network breach within their organization. The Palo Alto Networks Cortex XSOAR marketplace has a solution that will help you worry less about these worst-case scenarios. The rapid breach response content pack collects, investigates and remediates incidents related to major breaches. It leverages automation to proactively address serious incidents by getting ahead of the threat and giving your organization's time to catch your breath. This pack runs a collection of playbooks that rapidly respond to high-profile breaches with existing deployed tools in your enterprise. The playbooks in this pack can also be used as a template to hunt and block these indicators by using additional tools in your environment. Let's take a look at what one playbook does in particular, the SUNBURST and SolarStorm hunting and response playbook. As you may recall, in December of 2020, multiple agencies within the United States were attacked by a malware called SUNBURST that exploited software from SolarWinds. Running this playbook collects indicators to aid in your threat hunting process for this specific exploit. As you can see, this playbook retrieves IOCs of SUNBURST, which is a trojanized version of the SolarWinds Orion plug-in. It also retrieves C2 domains and URLs associated with SUNBURST, while discovering IOCs of associated activity related to the [ infection ]. Then it generates an indicator list to block indicators with SUNBURST tags and hunts for the SUNBURST backdoor. Next, a queries firewall logs to detect network activity and searches endpoint logs for SUNBURST hashes due to [ tags ] presence on hosts. If compromised hosts are found, then the playbook notifies the necessary security team to review and trigger remediation response actions, while also firing off sub-playbooks to isolate or quarantine infected hosts and endpoints. It then awaits further action from the security team. The SUNBURST and SolarStorm hunting and response playbook showcases just one way that the rapid breach response content pack can provide your organization's network with exhaustive automated protection. Thank you.
Nana-Ampofo Ampofo-Anti
executiveAll right. So we've had an opportunity to see the zero-day threat response in action. Let's move on and talk about what we can do beyond the [ SOC ]. So most of the day, we've been talking about XSOAR in the SOC. We've been talking about security operations use cases. We've got an opportunity to see those capabilities. I'd actually like to talk to you about what we do outside of that because so many of our customers noted that this technology actually can do so many things because we integrate with hundreds of different technology tools out there, so this is an opportunity to start to use it more. So let's run through some of the things that our Palo Alto Networks IT team uses XSOAR for. We automate onboarding, updating and off-boarding of the users across multiple applications, so Slack, Zoom, ServiceNow. Internally, we actually have a lot that we've been using for quite some time. So internally, if I need to open a ServiceNow ticket, for example, I don't have to go to the ServiceNow URL, fill in a form. I tap to our bot, and I use that to open a ticket. And of course, as things have -- so this was pre-generative AI, now with [ LLMs ] the capabilities have a bit more intelligence and chatbots. I'm sure that we're looking at ways to actually make that look [ smarter ]. So the great thing is we can tie back then to XSOAR, can tie that front-end intelligence to the back-end playbook and orchestration capability. We are using the pre-built app integrations. We've gone up to more than 50 of those within our IT environment. Again, this is just our IT team. This is not a security operations team that, of course, uses technology, and that's actually allowed us to save hundreds of thousands of dollars in user license fees from various tools that we have to purchase separately. So that's just allowed us to operate much smarter internally. One of the things that we looked at is identity life cycle management. So identity life cycle management, of course, use our onboarding. So this talks about fast and consistent user onboarding. Now of course, you absolutely care about that, and that's incredibly important. What I would add to this is off-boarding is arguably even more important from a security perspective. So from an IT user experience, onboarding is incredibly important. From a security perspective, we want to make sure that when someone leaves the organization, you shut the door behind that. Whether they leave on good terms or bad terms, doesn't matter. It's security principle, zero trust, least privilege. They should have zero privilege actually if they don't work at the company, and that's how you use technology to make that consistent. So you can go ahead and remove the access of that person, but you can also use it to remove and control access internally if we need to do some sort of internal temporary access to technology into tools. We can review access and also new certifications with periodic review and security compliance requirements, that can all be automated using playbooks because again, if you think about this, computers are incredibly good at the computer programs are incredibly good at just taking a bunch of data, passing that data and just applying whatever rules that set for them. So compliance is exactly that, you don't need a human to go necessarily depending on the requirements because, of course, there's going to be a [ nuance ] to these things to go and read this specific thing to go, yes, we took that box. You can get a machine to go and do that on your behalf and go and do some level of validation. And it's another thing that we use -- internally, we use XSOAR for GRC [indiscernible]. So how we automate that life cycle? When a new hire comes in, we will create the new user and the identity. We'll go ahead and provision the applications to access everything that they need. When we need to update those things, we also [indiscernible] manager profile and tools like Workday, for example, in our case, and we'll synchronize that across all the relevant applications, all the access you need. So it's a seamless thing when a new use comes in. When they exit the organization, we can use XSOAR to go and do reverse of all of that, to go and disable, remove the account, remove all the access and make sure that they fully exited. And that can be a same system run by a playbook and not a human. This is incredibly important because this is such a key part of the organization security. Leaving it to a human is incredibly dangerous because we all have bad days. You may wake up one morning and be the person that is in charge of doing the termination flow, but you've got a personal emergency. You might say, I'm going to get to this later and you don't actually get to it at all. And that's not because you're not doing your job properly or you have that intention, it's just because life happens. So having a machine do that is a lot more reliable way to make sure that this process is being followed. And that's something, again, that we found consistently in our adoption to it, and I was looking at some stats in terms of how our IT ops uses it. We've integrated 69 applications to do automated onboarding and off-boarding. We're at 17 playbooks with 38 sub-playbooks. Now again, remember, as I said, and for any of those of you that have got programming before, sub-playbooks aren't really important to all of this because there are many things that we might do frequently that are small tasks. So for example, it might be that you frequently need to -- you frequently need to e-mail a user and have it back and forth with them on some particular topic. You frequently need a flow around updating a ServiceNow ticket or Jira ticket or remedy ticket doing some sort of enrichment that can be friendly intel, so just going and checking who's this users manager, what is their -- the risk priority of the organization and other things that you may need before taking action. You can just have a sub-playbook that does that work for you. And again, because of the way that we've built the product because we have this focus on content, the contents that we deliver also has the sub-playbook so that you might be able to then build out your whole processes in detail by just pulling in bits of our sub-playbooks actually get you to do work. It's actually led to 4,500 plus HR events new process per month in our case. From security and compliance perspective, we used to disable accounts based on the continuing activity. We also do automated IP whitelisting for our applications. So this is a great way to go and whitelist across the board on all of our network security tooling. And of course, Palo Alto Networks tools are built to be very API-friendly and automation friendly. And by that, I mean that you can set up policies that will allow us to grow and automate the changing -- adding a user to a group or adding an IP to a group dynamically and having -- and not having to change the entire policy or even to do a [indiscernible], which is really cool. Now the self-service automation, whereby you will have [ password self-service ] response to allow you just to go and change their password when they need to and also be able to enforce a password reset through credential theft. So this is really powerful because again, it's just automating a lot of those painful tasks that a software would have to work through day to day if they didn't have automation to do the job for them. Audit automation and identity governance, kind of coming back to the more GRC, being able to do periodic critical access review for compliance. So being able to go and run through all of those different checks by scheduling the checks to happen is also ensuring that the checks do happen because much like things like people being off-boarding, if you have a tool go and do some level of this work automatically, you know that some or all of the work, depending on the checks that need to be done, are being done at the frequency, which would require them to be done, versus it's being assigned to some person who might not be available on that day, might skip it, et cetera. So you're actually ensuring that the machine does it. And you're also ensuring that the humans are doing more meaningful work rather than getting to look at things for the sake of it. We're going to work through automation. So let's talk about the user life cycle process flow in XSOAR. And there was a [indiscernible] I think that was a glitch in the slides, apologies for that. Now usual life cycle process review is something that we've already gone through, so I'll skip that. That's a duplicate slide, and we can wrap up for today. So what's next? Today, you've heard about how we can use XSOAR to do incredible automation across multiple use cases in the [ SOC ]. We've touched on different use cases like IOC, enrichment, malware response and zero-day threat response. What's next is to change everything in their [ SOC ] and look at how you can build an automation for [ SOC ]. Let's do that, and we welcome you to join us for a virtual tour of Palo Alto Networks SOC. We'll talk to you about how we've built an autonomous SOC, and how we solved 2 of the critical or rather, we've looked to find a different solution. I don't want to say solved, make it seem like we have all the answers. We just look to find a different solution that we feel is really moving the needle for us, and we'd love to tell everyone more about it. So feel free to join one of our virtual SOC tours. We'll talk to you about how we've used automation both at the data level using technologies and machine learning and in terms of the process flow and orchestration level, using technologies like SOAR and in fact bringing all of those technologies together in a net new technology and providing an alternative to the [ SIEM-based ] approach. We'll talk to you about all of those in the SOC tour. So I hope that you will join us for one of those. I'm going to hang on and see if we do have any questions in the Q&A. But I do thank you for your time and attention today. And I hope that this webinar was useful and informative for you. Please feel free to pop questions in the Q&A. I'm monitoring that. Thanks for the feedback, so [indiscernible] your name. I'll give it another minute in case there are any questions. If not, you're all welcome to drop. All right. I'll take that to meaning there are no further questions. Again, I want to thank you all for your time this morning, evening or afternoon, depending on which time zone that you've been watching this in. And I look forward to perhaps having an opportunity to interact with some of you in person or virtually in the coming weeks. Feel free to reach out to us and Palo Alto Networks account team for further conversations. And I wish you a fantastic day, evening or afternoon ahead. Goodbye. Thank you.
This call discussed
For developers and AI pipelines
Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.