EDR / XDR integration
Automate Palo Alto Cortex XDR EDR / XDR with plain language
Read Cortex XDR endpoints, incidents and alerts, and isolate an endpoint that VernacSecure SuperBot™ flags as compromised.
What you can do
Palo Alto Networks Cortex XDR — Public API v1
- List endpoints with agent status
- Read incidents and alerts
- Isolate an endpoint
Connection: header authentication against https://api-example.xdr.us.paloaltonetworks.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Isolate the laptop with the latest critical detection in Palo Alto Cortex XDR”
Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.
Read actions
- Fetch endpoints — Lists installed agents.
- Fetch incidents — Lists incidents.
- Fetch alerts — Lists alerts.
Write actions
- Isolate endpoint — Isolates the named endpoint ID.