[](https://www.paloaltonetworks.com/unit42?ts=markdown) ![x close icon to close mobile navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/x-black.svg) [![unit42 logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/unit42-logo-dark.svg)](https://www.paloaltonetworks.com/unit42?ts=markdown) ![magnifying glass search icon to open search field](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/search-black.svg) * [](https://www.paloaltonetworks.com/unit42?ts=markdown) * [About Unit 42](https://www.paloaltonetworks.com/unit42/about?ts=markdown) * Services ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Services [Assess and Test Your Security Controls](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [AI Security Assessment](https://www.paloaltonetworks.com/unit42/assess/ai-security-assessment?ts=markdown) * [Attack Surface Assessment](https://www.paloaltonetworks.com/unit42/assess/attack-surface-assessment?ts=markdown) * [Breach Readiness Review](https://www.paloaltonetworks.com/unit42/assess/breach-readiness-review?ts=markdown) * [BEC Readiness Assessment](https://www.paloaltonetworks.com/unit42/assess/business-email-compromise?ts=markdown) * [Cloud Security Assessment](https://www.paloaltonetworks.com/unit42/assess/cloud-security-assessment?ts=markdown) * [Compromise Assessment](https://www.paloaltonetworks.com/unit42/assess/compromise-assessment?ts=markdown) * [Cyber Risk Assessment](https://www.paloaltonetworks.com/unit42/assess/cyber-risk-assessment?ts=markdown) * [M\&A Cyber Due Diligence](https://www.paloaltonetworks.com/unit42/assess/mergers-acquisitions-cyber-due-diligence?ts=markdown) * [Penetration Testing](https://www.paloaltonetworks.com/unit42/assess/penetration-testing?ts=markdown) * [Purple Team Exercises](https://www.paloaltonetworks.com/unit42/assess/purple-teaming?ts=markdown) * [Ransomware Readiness Assessment](https://www.paloaltonetworks.com/unit42/assess/ransomware-readiness-assessment?ts=markdown) * [SOC Assessment](https://www.paloaltonetworks.com/unit42/assess/soc-assessment?ts=markdown) * [Supply Chain Risk Assessment](https://www.paloaltonetworks.com/unit42/assess/supply-chain-risk-assessment?ts=markdown) * [Tabletop Exercises](https://www.paloaltonetworks.com/unit42/assess/tabletop-exercise?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [IR Plan Development and Review](https://www.paloaltonetworks.com/unit42/transform/incident-response-plan-development-review?ts=markdown) * [Security Program Design](https://www.paloaltonetworks.com/unit42/transform/security-program-design?ts=markdown) * [Virtual CISO](https://www.paloaltonetworks.com/unit42/transform/vciso?ts=markdown) * [Zero Trust Advisory](https://www.paloaltonetworks.com/unit42/transform/zero-trust-advisory?ts=markdown) [Respond in Record Time](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Cloud Incident Response](https://www.paloaltonetworks.com/unit42/respond/cloud-incident-response?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/unit42/respond/digital-forensics?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond/incident-response?ts=markdown) * [Managed Detection and Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response?ts=markdown) * [Managed Threat Hunting](https://www.paloaltonetworks.com/unit42/respond/managed-threat-hunting?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-unit-42.svg) UNIT 42 RETAINER Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Learn more](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) * Unit 42 Threat Research ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Unit 42 Threat Research [Unit 42 Threat Research](https://unit42.paloaltonetworks.com/) * [Threat Briefs and Assessments Details on the latest cyber threats](https://unit42.paloaltonetworks.com/category/threat-research/) * [Tools Lists of public tools released by our team](https://unit42.paloaltonetworks.com/tools/) * [Threat Reports Downloadable, in-depth research reports](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Fresearch&ts=markdown) [THREAT REPORT 2025 Unit 42 Global Incident Response Report Read now](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report?ts=markdown) [THREAT BRIEF Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement Learn more](https://unit42.paloaltonetworks.com/preparing-for-cyber-impact-russia-ukraine-crisis/) [THREAT REPORT Highlights from the Unit 42 Cloud Threat Report, Volume 6 Learn more](https://www.paloaltonetworks.com/resources/research/unit-42-cloud-threat-report-volume-6?ts=markdown) * Partners ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Partners Partners * [Threat Intelligence Sharing](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) * [Law Firms and Insurance Providers](https://www.paloaltonetworks.com/unit42/incident-response-partners?ts=markdown) [THREAT REPORT 2025 Unit 42 Incident Response Report Read now](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report?ts=markdown) [THREAT BRIEF Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement Learn more](https://unit42.paloaltonetworks.com/preparing-for-cyber-impact-russia-ukraine-crisis/) [THREAT BRIEF Operation Falcon II: Unit 42 Helps Interpol Identify Nigerian Business Email Compromise Ring Members Learn more](https://unit42.paloaltonetworks.com/operation-falcon-ii-silverterrier-nigerian-bec/) * Resources ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Resources Resources * [Research Reports](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Fresearch&ts=markdown) * [Webinars](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Fwebinar&ts=markdown) * [Customer Stories](https://www.paloaltonetworks.com/unit42/customer-stories?ts=markdown) * [Datasheets](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Fdatasheet&ts=markdown) * [Videos](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Fvideo&ts=markdown) * [Infographics](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Finfographic&ts=markdown) * [Whitepapers](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Fwhitepaper&ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&fq=RC_TYPE_DFACET%3Apan%253Aresource-center%252Frc-type%252Farticle&ts=markdown) Industries * [Financial Services](https://www.paloaltonetworks.com/industry/unit42-financial-services?ts=markdown) * [Healthcare](https://www.paloaltonetworks.com/industry/unit42-healthcare?ts=markdown) * [Manufacturing](https://www.paloaltonetworks.com/industry/unit42-manufacturing?ts=markdown) [THREAT REPORT 2025 Unit 42 Global Incident Response Report Read now](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report?ts=markdown) [ANALYST REPORT Unit 42^®^ named a Leader in the 2025 IDC MarketScape for Worldwide IR Services. See our difference](http://start.paloaltonetworks.com/idc-incident-response-marketscape-2025) * * [Under Attack?](https://start.paloaltonetworks.com/contact-unit42.html) ![palo alto networks logo icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-default.svg) ![white arrow icon pointing left to return to main Palo Alto Networks site](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-white.svg) [](https://www.paloaltonetworks.com/unit42?ts=markdown) Search All * [Tech Docs](https://docs.paloaltonetworks.com/search#q=unit%2042&sort=relevancy&layout=card&numberOfResults=25) Close search modal *** ** * ** *** ![unit42](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response-partners/unit42.png) # Respond with Confidence. Partner with Experts. The clock starts immediately when you've identified a potential breach. It's at that point you want a partner that can start answering the hard questions: how did they get in? What did they access? What is the impact? When you team up with Unit 42 Incident Response, you partner with an elite team of incident responders who leverage trusted threat intelligence and best-in-class tools to help you stop the attack and prevent the next one. [IDC MarketScape Leader in Worldwide IR Services. See why.](https://www.paloaltonetworks.com/blog/2025/08/idc-unit-42-ir/?ts=markdown) **unit42** ![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/x-white.svg) BenefitsService FeaturesMethodologyWhy Unit 42 * [Benefits](#benefits) * [Service Features](#service-features) * [Methodology](#methodology) * [Why Unit 42](#why) {#benefits} BENEFITS ## Every second counts when responding to an attack. Respond with confidence. ### Staying ahead of advanced threats requires an elite incident response team with access to world-class threat intelligence. Unit 42^®^ incident response experts will help you understand the nature of the attack and then quickly contain, remediate and eradicate it. We utilize a proven methodology and battle-tested tools developed from our real-world experience investigating thousands of incidents. [Tour the Unit 42 Retainer](https://www.paloaltonetworks.com/resources/ebooks/unit42-retainer-tour?ts=markdown) ![Card Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/6Findhiddenthreats.svg) ![Card Mobile Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/6Findhiddenthreats.svg) ### Jumpstart your investigation in minutes No need to start from scratch every time. With Unit 42 on retainer, you can quickly jumpstart an intelligence-led investigation, deploying best-in-class tools within minutes to contain threats and gather the evidence needed to fully analyze the incident. ![Card Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/11eradicatethethreat.svg) ![Card Mobile Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/11eradicatethethreat.svg) ### Confidence the threat is fully remediated If you don't identify the root cause, the adversary will be back again in no time. We have responded to thousands of cases, so we've seen incidents like yours before. Our experts will give you confidence that each incident has been completely remediated. ![Card Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/forensically.svg) ![Card Mobile Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/forensically.svg) ### Forensically defensible reporting Unit 42's leaders have decades of experience working with cyber insurance carriers and legal counsel. We know what to report and how to report it to ensure the best privilege protections in the event of litigation. Transform your cybersecurity with Unit 42 --- [![white triangle](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/video-play-white.svg)](https://www.paloaltonetworks.com//players.brightcove.net/1050259881001/default_default/index.html?videoId=6371373113112&ts=markdown) ![UNIT 42 IR REPORT](https://www.paloaltonetworks.com/content/dam/pan/en_US/includes/igw/unit42-sec-ebook/sticky_nav/images/global-incident-response-report.png) READ THE REPORT ## Dive into the latest cyber threat trends and insights from Unit 42. Discover the latest threat actor tactics and get real-world insights and expert recommendations to stay ahead of evolving AI threats. [Download now](https://start.paloaltonetworks.com/unit-42-incident-response-report.html) ![unit42 star](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42/Unit42Star.png)![unit42 star](https://www.paloaltonetworks.com/content/dam/pan/en_US/unit42-contained-exp/overview/Unit42DemandGenMobile.svg) {#service-features} TYPES OF INCIDENTS ## Here are the types of incidents we typically manage ### Unit 42 is your trusted advisor before, during and after a breach. We perform more than 1,000 investigations each year. Below are the most common types we see: ![RANSOMWARE INVESTIGATION \& NEGOTIATION](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/ramsomware.png) ![RANSOMWARE INVESTIGATION \& NEGOTIATION](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/ransomware1.svg) ### RANSOMWARE INVESTIGATION \& NEGOTIATION ![CLOUD INCIDENT RESPONSE](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/cloud-incident-response/cloud-incident.svg) ![CLOUD INCIDENT RESPONSE](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/supply-chain-risk-assessment/cloud-data-classification1.svg) ### CLOUD INCIDENT RESPONSE ![ADVANCED PERSISTENT THREATS](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/Transform/incident-response-plan-development-review/lock-shield-icon.svg) ![ADVANCED PERSISTENT THREATS](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/encryption1.svg) ### ADVANCED PERSISTENT THREATS ![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/cloud-incident-response/business-email.svg) ![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/supply-chain-risk-assessment/malicious%20email1.svg) ### BUSINESS EMAIL COMPROMISE ![WEB APPLICATION ATTACKS](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/cloud-incident-response/web-application-attacks.svg) ![WEB APPLICATION ATTACKS](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/chrome1.svg) ### WEB APPLICATION ATTACKS {#methodology} METHODOLOGY ## An intelligence-driven approach to incident response SCOPE ![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/u42_icon1_assess_dk.svg) ### Define engagement scope Assess the breadth, severity and nature of the security incident. INVESTIGATE ![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/6-find-hidden-threats-in-your-environment-investigate-dk.svg) ### Fully understand the incident Our experts use advanced tools for evidence collection, detection and analysis to flag IoCs, TTPs and other clues. SECURE ![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/U42_Icon5_respond_secure-DK.svg) ### Contain and eradicate We remove the threat with custom eradication strategies and provide 24/7 monitoring against new malicious activity. SUPPORT \& REPORT ![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/support-and-report-.svg) ### Findings and response assistance Get a detailed investigation report as well as guidance in implementing additional security controls while you get back on your feet. TRANSFORM ![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/u42_Icon6_transform_dk.svg) ### Improve your security posture Use lessons learned and apply specific improvements to your security approach to protect against future and similar attacks. Threat Intelligence INCIDENT RESPONSE PARTNERS ### Law Firms \& Insurance Minimize costs and reduce liability by getting your clients the help they need before, during and after a breach. [Learn more](https://www.paloaltonetworks.com/unit42/incident-response-partners?ts=markdown) ![Image Alt](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/overview/law-firm.svg) {#why} WHY UNIT 42 ## World-renowned security experts, always in your corner ### As an industry-leading threat intelligence, cyber risk management and incident response organization, it's our job to help you prepare and respond to some of the most challenging threats so that your team can get back to business faster. As threats escalate, we act as your trusted partner to advise and strengthen your security strategies. ![Card Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/1-world-class-threat-intelligence-lt.svg) ![Card Mobile Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/1-world-class-threat-intelligence-lt.svg) ### WORLD-CLASS THREAT INTELLIGENCE Unit 42 provides access to one of the world's largest and most experienced threat intelligence teams. Our team of more than 200 cyberthreat researchers includes threat hunters, malware reverse engineers and threat modeling experts who enable you to apply a threat-informed approach to prepare for and respond to the latest cyberthreats. ![Card Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/assess/tabletop-exercises/3-experience-and-expertise-lt.svg) ![Card Mobile Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/assess/tabletop-exercises/3-experience-and-expertise-lt.svg) ### TRUSTED EXPERTISE \& EXPERIENCE Unit 42 has assembled an experienced team of security consultants with backgrounds in public and private sectors who have handled some of the largest cyberattacks in history. We manage complex cyber risks and respond to advanced threats, including nation-state attacks, APTs and complex ransomware investigations. ![Card Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/2%20-industry-leading-tools-lt.svg) ![Card Mobile Head Icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/incident-response/2%20-industry-leading-tools-lt.svg) ### INDUSTRY-LEADING TOOLS Unit 42 security consultants leverage industry-leading Palo Alto Networks tools to jumpstart your investigation by gaining necessary visibility across your endpoint, network, cloud and third-party data. This enables you to develop and execute a plan to get back to business as quickly as possible following an incident. ## Explore customer stories ### Discover how Unit 42 security consultants and incident responders are helping our customers before, during and after an incident. [View all customer stories](https://www.paloaltonetworks.com/unit42/customer-stories?ts=markdown) ![Infrastructure Manufacturer Reclaims Control After Dual Ransomware Attacks](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/ir-unit42-2024/industrial-water-filters-white-pipes-and-red-valves-purification-of-water-at-plant.jpg) ## Infrastructure Manufacturer Reclaims Control After Dual Ransomware Attacks [Learn how Unit 42 protected data and operations](https://www.paloaltonetworks.com/customers/infrastructure-manufacturer-reclaims-control-after-dual-ransomware-attacks?ts=markdown) ![Unit 42 Secures Medical Device Manufacturer After Network Breach](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/ir-unit42-2024/secures-medical-device-manufacturer-after-network-breach.jpg) ## Unit 42 Secures Medical Device Manufacturer After Network Breach [See how our IR team sprang into action](https://www.paloaltonetworks.com/customers/unit42-secures-medical-device-manufacturer-after-network-breach?ts=markdown) ![Government Eradicates Ransomware Threat and Reinstates Critical Services](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/ir-unit42-2024/the-government-of-a-communist-country.jpg) ## Government Eradicates Ransomware Threat and Reinstates Critical Services [See how our Unit 42 experts took action](https://www.paloaltonetworks.com/customers/government-eradicates-ransomware-threat-and-reinstates-critical-services?ts=markdown) ![Restoring a Software and Services Provider’s Cloud Environment After a Breach](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/overview/lapsus$-sp-case-study.png) ## Restoring a Software and Services Provider's Cloud Environment After a Breach [See the Lapsus$ cloud breach case study](https://www.paloaltonetworks.com/customers/restoring-a-software-and-services-providers-cloud-environment-after-a-breach?ts=markdown) ![Multinational Organization Enhances Defenses by Stress Testing Its Cybersecurity Program](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/case-study/multinational-organization-enhances-defenses-by-stress-testing-its-cybersecurity-program.jpg) ## Multinational Organization Enhances Defenses by Stress Testing Its Cybersecurity Program [Read the cyber risk management case study](https://www.paloaltonetworks.com/customers/multinational-organization-enhances-defenses-by-stress-testing-its-cybersecurity-program?ts=markdown) {#stop} #### Related resources [See all resources](https://www.paloaltonetworks.com/resources?q=*%3A*&_charset_=UTF-8&fq=PRODUCTS0_DFACET%3Apan%253Aresource-center%252Fproducts0%252Funit42-managed-detection-and-response&ts=markdown) Case Study #### Glacier Bancorp Hardens Security Without Breaking the Bank [Learn more](https://www.paloaltonetworks.com/customers/glacier-bancorp-hardens-security-without-breaking-the-bank?ts=markdown) BLOG #### Unit 42 --- A Leader in The Forrester Wave for Cybersecurity Incident Response [Read now](https://www.paloaltonetworks.com/blog/2024/06/forrester-wave-for-cybersecurity-incident-response/?ts=markdown) CASE STUDY #### Defense contractor contains APT with Unit 42 IR expertise [Watch now](https://www.paloaltonetworks.com/resources/videos/chinese-apt-attack-on-a-defense-and-technology-company?ts=markdown) GARTNER REPORT #### 4 Key Considerations to Perform Effective Incident Response [Embrace readiness](http://start.paloaltonetworks.com/gartner-four-key-considerations-to-perform-effective-incident-response) {#contact} ![jeffries-logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/unit42-contained-exp/overview/panw-sml-logo-white.svg) ## Get immediate IR support If you have been breached or have an urgent matter, please call the Unit 42 Incident Response team or fill out the form to get in touch immediately. * North America Toll-Free: +1 (866) 486-4842 (866.4.UNIT42) * UK: +44.20.3743.3660 * Europe and Middle East: +31.20.299.3130 * Asia: +65.6983.8730 * Japan: +81.50.1790.0200 * Australia: +61.2.4062.7950 If you have cyber insurance or legal counsel, you can request Unit 42 to serve as your Incident Response team. Unit 42 is on over 70 cyber insurance panels as a preferred vendor. First Name \* Last Name \* Email \* Company \* Job Level \*Job Level Job Function/Focus Area \*Job Function/Focus Area Phone \* Country \*Country StateState ProvinceProvince Zip Code \* Department Under Attack?Under Attack?Yes, I have an urgent matterNo, I'm looking to connect with the sales team IncidentType Incident TypeRansomwareBusiness Email CompromiseNetwork IntrusionOther Additional Attack Details Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners. By submitting this form, I understand my personal data will be processed in accordance with [Palo Alto Networks Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use.](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. Contact us #### THANK YOU! A Palo Alto Networks specialist will reach out to you shortly. We look forward to connecting with you! {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2025 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language