All integrations

Palo Alto Cortex Integration with DefectDojo

Palo Alto Cortex Integration with DefectDojo

Cortex is Palo Alto Networks' family of security operations and cloud security products. Cortex Cloud, the successor to Prisma Cloud, evaluates cloud accounts against posture policies and raises alerts for misconfigurations. Cortex XDR detects suspicious activity from endpoint agent telemetry and other sources, Cortex XSIAM is a security operations platform whose alerts span endpoints, cloud, network, and identity, and Cortex XSOAR (originally developed by Demisto) orchestrates incident response with playbooks. DefectDojo Pro has a separate API connector for each of the four, and none of them has a file parser.

Palo Alto Cortex Integration with DefectDojo

We run more than one Cortex product, and each console is good at its own job: posture in Cortex Cloud, detection in XDR or XSIAM, response in XSOAR. What none of them gives us is one place where the follow-up work from all of them gets an owner, an SLA, and a line in the quarterly report next to our scanner findings. The four Palo Alto Cortex connectors in DefectDojo Pro fill that gap. Each one pulls its product's alerts or incidents on a schedule, files them under Records that we map to DefectDojo Assets, and marks findings inactive when the source stops reporting them. Investigation and response stay in Cortex. DefectDojo tracks what has to be fixed afterward.

Why Palo Alto Cortex Matters

The Cortex products cover the part of security that scanners do not: what is actually deployed and what is actually happening.

  • Cortex Cloud checks the live configuration of cloud resources against policy, which catches changes made outside infrastructure as code.
  • Cortex XDR ties each alert to a specific endpoint, so follow-up work has a clear target machine.
  • Cortex XSIAM correlates data across endpoints, cloud, network, and identity, which surfaces activity no single sensor would flag.
  • Cortex XSOAR collects incidents from many detection tools, and many of those incidents close with a recommendation that becomes engineering work.

Without a link into vulnerability management, that follow-up lives in consoles and case notes that application and infrastructure owners rarely open.

Advantages of This Integration

What running the Cortex family through DefectDojo Pro gives us:

  • Scheduled, hands-off imports. Each connector runs Discover and Sync every 6, 12, or 24 hours at a time you choose, with no exports or scripts.
  • Records that match each product. Cortex Cloud creates a Record per cloud account and Cortex XDR a Record per endpoint, so findings can land on the owning team's Asset. XSIAM and XSOAR use one Record per tenant.
  • Lifecycle on every sync. New alerts or incidents become findings, and findings no longer reported are marked inactive, which keeps the open list current.
  • Severity floor per connector. Every Cortex connector has an optional Minimum Severity, so each product can feed DefectDojo at a different threshold.
  • One remediation workflow. Cortex findings use the same SLA rules, assignment, notes, risk acceptance with expiry, metrics, and Downstream Connector ticketing as everything else in DefectDojo Pro.
  • Detections next to exposure. When an XDR endpoint Record or a Cortex Cloud account Record maps to the same Asset as its scanner results, alerts and open vulnerabilities for that system sit together.

How This Integration Works

Connectors are a DefectDojo Pro feature. All four Cortex connectors are added the same way: in the Pro UI, open Connect > Upstream, find the connector under Available Connectors, click Add Configuration, fill in the fields below plus a Label, then set the Discovery and Synchronization schedules and decide on Auto-Mapping. Sync writes findings into the Global Connectors Engagement on each mapped Asset, in a Test dedicated to that connector, and updates the same Test on every run. Each product needs its own configuration and its own API credentials.

Cortex Cloud

Imports open cloud posture alerts as findings labeled Cortex Cloud:Posture. Create an access key under Settings > Access Control > Access Keys and leave it enabled; the connector exchanges it at /login for a short-lived token. The key inherits the role of the user who created it, and that role needs View on Cloud Accounts (required for discovery) and Alerts. The built-in Account Group Read Only role is the minimum.

  • Location: the Prisma Cloud API URL for your region, for example https://api.prismacloud.io, https://api2.prismacloud.io, or https://api.eu.prismacloud.io.
  • Access Key ID and Secret Key: from the access key.
  • Minimum Severity (optional): limits which findings are imported.

Cortex XDR

Imports alerts as findings labeled Cortex XDR:Alerts. Create a Standard security-level API key under Settings > Configurations > Integrations > API Keys. The connector signs requests with the Authorization and x-xdr-auth-id headers. The key's role needs View on Endpoints (required for discovery) and Alerts and Incidents; the built-in Viewer role is the minimum.

  • Location: the tenant API FQDN shown on the API Keys page, such as https://api-your-tenant.xdr.us.paloaltonetworks.com (the region segment varies).
  • API Key ID: the integer shown beside the key.
  • API Key: the key secret.
  • Minimum Severity (optional): limits which findings are imported.

Cortex XSIAM

Imports alerts as findings labeled Cortex XSIAM:Alerts. The key setup matches XDR: a Standard key created under Settings > Configurations > Integrations > API Keys in the XSIAM console, signed with the same two headers. The role needs View on Alerts and Incidents, and the credential check also reads Endpoints, so grant both. The built-in Viewer role is the minimum.

  • Location: the tenant API FQDN from the API Keys page, following the pattern https://api-your-tenant.xdr.us.paloaltonetworks.com.
  • API Key ID and API Key: from the key.
  • Minimum Severity (optional): limits which findings are imported.

Cortex XSOAR

Imports incidents as findings labeled Cortex XSOAR, and supports both XSOAR 6 and XSOAR 8. Create an API key under Settings > Integrations > API Keys. For XSOAR 8 or Cortex multi-tenant, also copy the API Key ID, which the connector sends as the x-xdr-auth-id header; XSOAR 6 has none. The role needs read access to incidents, and a read-only role is the minimum.

  • Location: for a Cortex-hosted tenant, the FQDN from the API Keys page, such as https://api-your-tenant.xsoar.paloaltonetworks.com; for self-hosted XSOAR, your server's base URL.
  • API Key: the key secret.
  • API Key ID (optional): XSOAR 8 and Cortex multi-tenant only.
  • Minimum Severity (optional): limits which findings are imported.

After the first Discover, map Records to Assets yourself from the Unmapped Records list, or let Auto-Mapping match each Record to an Asset by name or create one.

Data Granularity: What Gets Imported

The connector documentation describes scope and structure rather than field-by-field mappings, so this table lists only what is documented for each connector.

Item Cortex Cloud Cortex XDR Cortex XSIAM Cortex XSOAR
Finding label Cortex Cloud:Posture Cortex XDR:Alerts Cortex XSIAM:Alerts Cortex XSOAR
What becomes a finding Open posture alert Alert Alert Incident
Record created per Onboarded cloud account Endpoint, named by hostname and OS Tenant (one Record) Tenant (one Record)
Credentials Access Key ID, Secret Key API Key ID, API Key API Key ID, API Key API Key, optional API Key ID
Required read access Cloud Accounts, Alerts Endpoints, Alerts and Incidents Alerts and Incidents, Endpoints Incidents
Minimum Severity Optional Optional Optional Optional
Notable scope rule Only open alerts import Alerts follow the endpoint Record Alerts span endpoints, cloud, network, identity XSOAR 6 and XSOAR 8

All four share the same DefectDojo structure: findings go to the Global Connectors Engagement on the mapped Asset, in one Test per connector, and each Sync adds new findings and marks findings that are no longer reported as inactive. Connector Field Mappings under Connect > Field Mappings can rearrange or combine the values a connector sends, per scan type.

Use Cases

Putting cloud posture in team queues: A central cloud security team maps each Cortex Cloud account Record to the Asset owned by the application team that runs the account. Each team sees its open posture alerts with SLA dates, without a Cortex login.

Connecting endpoint detections to exposure: An infrastructure team maps each server's Cortex XDR endpoint Record to the Asset that already receives its vulnerability scan results. A server with both recent alerts and open Critical CVEs is an easy case for patching first.

Tracking SOC follow-up work: XSIAM alerts and XSOAR incidents that end with a hardening task, such as tightening an identity policy or changing how a service account is provisioned, are assigned in DefectDojo with an SLA. The task stays visible after the case closes in Cortex.

Reporting across the stack: Security leadership reports posture, detection, and incident volume by severity next to code and container findings from the same DefectDojo instance, instead of pulling numbers from four consoles.

Operational Tips

  • Create a separate, dedicated credential for each connector, with a role limited to the read permissions listed above.
  • Plan Auto-Mapping before the first Discover. Cortex Cloud and XDR create one Record per account or endpoint, which can mean many new Assets on a large estate.
  • Map the single XSIAM and XSOAR tenant Records by hand to an Asset built for security operations, then route individual findings with tags, assignment, or Downstream Connector tickets.
  • If a sync succeeds but imports nothing, check the key's role first. Missing View on Cloud Accounts or Endpoints blocks discovery.
  • Set Minimum Severity per connector. A floor that suits Cortex Cloud posture alerts may be too low for XSIAM alert volume.
  • For XSOAR, match the version: XSOAR 8 and Cortex multi-tenant need the API Key ID, and XSOAR 6 leaves it blank.
  • Turn on the Connector Health Warning notification so an expired key or reduced role is reported instead of silently stopping imports.