EDR / XDR integration

Automate Palo Alto Cortex XDR EDR / XDR with plain language

Read Cortex XDR endpoints, incidents and alerts, and isolate an endpoint that VernacSecure SuperBot™ flags as compromised.

What you can do

Palo Alto Networks Cortex XDR — Public API v1

  • List endpoints with agent status
  • Read incidents and alerts
  • Isolate an endpoint

Connection: header authentication against https://api-example.xdr.us.paloaltonetworks.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Isolate the laptop with the latest critical detection in Palo Alto Cortex XDR”

Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.

Get started free

Read actions
  • Fetch endpoints — Lists installed agents.
  • Fetch incidents — Lists incidents.
  • Fetch alerts — Lists alerts.
Write actions
  • Isolate endpoint — Isolates the named endpoint ID.