Cortex Cloud
Connect Cortex Cloud ASM to import its external service data into Guard as assets.
Overview
The Palo Alto Cortex Cloud integration imports the external services that Cortex Cloud's attack surface management has discovered for your organization. Guard turns each service into assets, open ports, and risks for the CVEs Cortex Cloud has inferred on it, so they join the rest of your attack surface for monitoring and testing.
The integration is read-only. Guard queries Cortex Cloud and never changes its configuration, assets, or services.
What Guard imports
Guard imports every external service that Cortex Cloud marks as active and that it has observed in the last 14 days. Services in the Prisma Access business unit are left out.
For each service, Guard creates:
- Assets. One asset for each pair of domain and IP address the service reports. A service with no domain is imported under its IP address.
- Ports. When the service reports a port and protocol, Guard records that port and its service type on the asset.
- Risks. One risk for each CVE that Cortex Cloud has inferred on the service. Severity comes from the CVE's CVSS v3 score, or its CVSS v2 score when no v3 score exists. The risk's evidence shows the service name, type, and port; the CVSS scores and severity; how confident Cortex Cloud is in the match; and the software versions it matched.
- Tags. Each asset is tagged with the service's Cortex Cloud business units.
Guard's standard asset filters still apply, so an asset you have excluded from Guard stays excluded.
Prerequisites
- A Palo Alto Cortex Cloud tenant with attack surface management data.
- Permission in Cortex Cloud to create API keys.
- Access to the Integrations page in Guard.
Create an API key in Cortex Cloud
- In Cortex Cloud, go to Settings > Configurations > Integrations > API Keys.
- Select New Key and choose the Standard security level.
- Assign a role that can read external services. If your Praetorian team will exclude cloud accounts for you (see below), the role must also be able to run XQL queries.
- Save the key, then copy it and store it securely.
- In the API Keys table, note the key's ID.
- Note your tenant's fully qualified domain name, for example
your-tenant.xdr.us.paloaltonetworks.com.
Connect Cortex Cloud to Guard
- In Guard, go to Integrations.
- Under Cloud Security Posture Management, select Palo Alto Cortex Cloud.
- Enter:
- Cortex Cloud FQDN: your tenant's domain name, without
https://. - API Key ID: the key ID from the API Keys table.
- API Key: the key you copied.
- Cortex Cloud FQDN: your tenant's domain name, without
- Save the integration.
Guard checks the credentials when you save by requesting your external services from Cortex Cloud. If the check fails, confirm the domain name, the key ID, and that the key's role can read external services.
API endpoints
Guard calls these Cortex Cloud endpoints under https://api-<your FQDN>/public_api/v1:
See Palo Alto's Get All Services reference for the external services data.
Excluding cloud accounts
Some of your cloud accounts may publish public IPs that you don't want Guard to test. Your Praetorian team can exclude them by organization, project or account, or folder. Guard then looks up those accounts' public IPs in the Cortex Cloud cloud_inventory dataset and imports any asset on one of those IPs as Frozen, so Guard doesn't scan it.
Still need help? Ask the team