* [Blog](https://www.paloaltonetworks.com/blog) * [Palo Alto Networks](https://www.paloaltonetworks.com/blog/corporate/) * [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant) * Cortex XDR 介绍 # Cortex XDR 介绍 [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F04%2Fintroducing-cortex-xdr-cn%2F%3Flang%3Dzh-hans) [](https://twitter.com/share?text=Cortex+XDR+%E4%BB%8B%E7%BB%8D&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F04%2Fintroducing-cortex-xdr-cn%2F%3Flang%3Dzh-hans) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F04%2Fintroducing-cortex-xdr-cn%2F%3Flang%3Dzh-hans&title=Cortex+XDR+%E4%BB%8B%E7%BB%8D&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-xdr-cn/?lang=zh-hans&ts=markdown) \[\](mailto:?subject=Cortex XDR 介绍) Link copied By [Mitchell Bezzina](https://www.paloaltonetworks.com/blog/author/mitchell-bezzina/?lang=zh-hans&ts=markdown "Posts by Mitchell Bezzina") Apr 09, 2019 1 minutes [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant&ts=markdown) This post is also available in: [English (英语)](https://www.paloaltonetworks.com/blog/2019/02/introducing-cortex-xdr-new-wave-detection-response/ "切换到 英语(English)") [繁體中文 (繁体中文)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-tw/?lang=zh-hant "切换到 繁体中文(繁體中文)") [Nederlands (荷兰语)](https://www.paloaltonetworks.com/blog/2019/04/introductie-van-cortex-xdr-nl/?lang=nl "切换到 荷兰语(Nederlands)") [Français (法语)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-xdr-fr/?lang=fr "切换到 法语(Français)") [Deutsch (德语)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-xdr-de/?lang=de "切换到 德语(Deutsch)") [Italiano (意大利语)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-xdr-it/?lang=it "切换到 意大利语(Italiano)") [日本語 (日语)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-jp/?lang=ja "切换到 日语(日本語)") [한국어 (韩语)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-kr/?lang=ko "切换到 韩语(한국어)") [Español (西班牙语)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-xdr-es/?lang=es "切换到 西班牙语(Español)") [Türkçe (土耳其语)](https://www.paloaltonetworks.com/blog/2019/04/introducing-cortex-xdr-tr/?lang=tr "切换到 土耳其语(Türkçe)") ++[我们宣布了三项前沿创新](https://www.paloaltonetworks.com/company/press/2019/palo-alto-networks-introduces-cortex-the-industrys-only-open-and-integrated-ai-based-continuous-security-platform?ts=markdown)++ ,这些创新内容将挑战整个安全行业的现状。其中一项便是 ++[Cortex XDR](https://www.paloaltonetworks.com/products/xdr?ts=markdown)++,这是一款云交付的应用,安全团队利用此应用不仅可以检测并阻止复杂的攻击,还可以调整防御手段,从而不断改进并阻止未来的网络攻击得逞。 Cortex XDR 是 ++[Cortex](https://www.paloaltonetworks.com/products/cortex?ts=markdown)++ 上的第一款应用,是行业唯一一款基于 AI 的开放式集成连续安全平台。Cortex XDR 打破了隔离网络安全团队并减缓事件响应速度的数据孤岛。通过与丰富的网络、端点和云数据原生关联,Cortex XDR 使用机器学习和分析改进安全运营的每个阶段。 为何不运行简单路由并推出另一款端点产品? 组织面临着严重的网络安全技能短缺。据 2018 (ISC)² 网络安全劳动力研究++[估计,如今的职位空缺数量已接近 300 万个](https://www.isc2.org/Research/Workforce-Study)++。网络分析、计算机取证和云管理方面的专家稀缺。安全团队需要找出一种方法来提高生产力并减少识别、调查和减轻威胁的复杂性。 Cortex XDR 通过强制增强安全团队并优化安全运营的每个阶段重新定义了检测和响应。将不同来源的数据整合到一起,然后进行关联和分析。应用机器学习分析行为并检测潜在的攻击。自动化提供了潜在威胁的根本原因及完整概况。强大的查询引擎为威胁搜寻奠定了基础,自定义规则确保可以使用学到的知识简化未来的调查或检测未来的类似威胁。 Cortex XDR 独家提供以下功能: * **自动检测:** 通过使用机器学习分析大量数据,从而发现恶意软件、有针对性的攻击和内部威胁。行为分析可以极其精准地自动检测威胁,而可定制的检测规则可使安全团队保护需要人为干预的攻击者战略和技术的安全。 * \*\*加速调查:\*\*安全分析师只需点击一下鼠标即可了解发出任何安全警报的事件的根本原因和时间线。将情境应用于网络、端点和云活动,从而简化复杂分析,减少警报疲劳并加快调查速度。 * \*\*自适应响应:\*\*由于 Cortex XDR 与执行点紧密集成,因此可以立即协调响应。使用调查获取的知识更新可定制的检测规则,以此防范未来的威胁或增加调查情境,做到未雨绸缪。 * \*\*简单、基于云的部署:\*\*作为基于云的应用,Cortex XDR 克服了本地检测和响应所面临的管理和扩展挑战。Cortex XDR 分析存储于 Cortex Data Lake 中的网络、端点和云数据,提供高效运营方法以存储行为分析所需的大量数据,同时利用现有安全投资作为传感器和执行点。 * \*\*增长的基础:\*\*虽然 Cortex XDR 在单个产品中扩展了跨网络、端点和云数据的检测和响应,但它也可以在单个数据源上运行。客户可以从包含的 Traps 代理开始使用端点数据,与使用其他 EDR 工具展开有效竞争,或者从网络数据开始使用端点数据,与使用其他 NTA 工具展开竞争。但是,随着需求的增加,还可以扩展和集成其他数据源。 * **Traps 6.0** \*\*:\*\*这是最先进的恶意软件和漏洞利用防御手段,现在可通过添加行为威胁防御来保护整个威胁范围内的端点安全。与一次仅分析一个进程并依赖之前的威胁知识的传统防病毒产品不同,Traps 现在通过监控跨进程的恶意事件序列,并在检测到攻击时终止攻击来检测和阻止攻击活动。其他增强包括针对 Linux 容器的扩展防护、Linux ELF 恶意软件防护以及用于 Cortex XDR 的丰富数据收集。Cortex XDR 将 Traps 包括在内,提供单一、轻量级的代理以阻截端点威胁并收集用于检测和响应的数据。也可以单独购买 Traps,实现严密的端点防护。 *** ** * ** *** ## Related Blogs ### [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant&ts=markdown) [#### AI代理已經來臨,威脅也隨之而來](https://www.paloaltonetworks.com/blog/2025/05/ai-agents-threats/?lang=zh-hant) ### [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant&ts=markdown) [#### Strata Copilot - 加速迈向自主网络安全的未来](https://www.paloaltonetworks.com/blog/network-security/strata-copilot/?lang=zh-hans) ### [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant&ts=markdown) [#### 防火墙已死?至少本世纪不会!](https://www.paloaltonetworks.com/blog/2023/08/ngfw-is-not-dead-yet/?lang=zh-hans) ### [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant&ts=markdown) [#### 面对性命攸关的时刻,如何实现可靠的医疗物联网安全](https://www.paloaltonetworks.com/blog/2022/12/medical-iot-security-to-depend-on/?lang=zh-hans) ### [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant&ts=markdown) [#### 利用业界首创的 AIOps for NGFW 革新防火墙运行](https://www.paloaltonetworks.com/blog/2022/03/industry-first-aiops-for-ngfw/?lang=zh-hans) ### [未分类](https://www.paloaltonetworks.com/blog/category/%e6%9c%aa%e5%88%86%e7%b1%bb/?lang=zh-hant&ts=markdown) [#### Prisma Access 是保护远程用户安全的领先云服务](https://www.paloaltonetworks.com/blog/2021/08/prisma-access-leading-cloud-service-secure-remote-users/?lang=zh-hans) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language