Cortex XDR · endpoint
Cortex XDR agent telemetry, the causality chain of every alert and custom XQL detection rules mapped to MITRE ATT&CK.
For organisations that already run Cortex XDR and have no team to operate it at night, or an MSSP that opens tickets instead of containing. The Fortgale MDR service works inside your Cortex tenant: analysts with a mandate to decide read the causality chain and execute the response, with a median TTC of <30 minutes.
The Cortex modules and data sources the SOC takes on. Where Cortex is not deployed yet, Fortgale handles licensing and agent rollout as part of the service.
Cortex XDR agent telemetry, the causality chain of every alert and custom XQL detection rules mapped to MITRE ATT&CK.
Native ingestion from PAN-OS next-generation firewalls and Prisma Access, stitched with endpoint activity into the same case.
Workload telemetry from Prisma Cloud (now part of Cortex Cloud), in the same console as endpoint and network.
Identity Threat Detection analytics in Cortex XDR, part of the detections the SOC works on every day.
For organisations on XSIAM, detection and response run on the XSIAM platform; Xpanse exposure data is among the Cortex modules the SOC operates.
Optional: cross-tool response and enrichment playbooks in Cortex XSOAR, written and maintained by Fortgale.
What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.
On Cortex the analyst acts from the console with native actions: endpoint isolation, process termination, file quarantine, hash blocklisting and a Live Terminal session for live forensics on the host.
Locking an Active Directory account is not an endpoint action in Cortex XDR: it runs through a Cortex XSOAR playbook. Blocking indicators at the network edge goes through the PAN-OS integration, so endpoint and network containment are coordinated from the same case.
Fortgale indicators are loaded as Cortex IOC rules, so a known indicator opens a case before the causality chain is complete, and XQL rules follow the actors that target European sectors.
Takeover happens on your existing Cortex tenant: agents already deployed stay where they are and no data is migrated.
Defence is active as soon as access and monitoring go live, and technical onboarding closes in one week: Cortex roles, integrations and response authorisations are complete and the service runs at full capacity.
On your side: a technical contact, the Cortex roles for our analysts and the escalation list. Response authorisations and exclusions are agreed with your team before the first action.
In February 2026 the Fortgale incident response team contained Operation Storming Tide at a European logistics company. The attacker had come in months earlier through a vulnerable Fortinet firewall, left a persistent VPN tunnel and a compromised service account, then moved through unmanaged assets into the internal network, bringing the Matanbuchus 3.0 loader, the Astarion RAT, SystemBC and RClone staged to exfiltrate to S3 storage. The investigation started from anomalous internal network scanning; neither exfiltration nor ransomware happened.
The article is not about Cortex, but it is the kind of chain the SOC reads on Cortex from two sides. If internal traffic crosses PAN-OS firewalls, the scan leaves a trace even when it starts from a host with no agent; on hosts with an agent, the causality chain ties scheduled tasks, loader and RClone launch into one case, and endpoint isolation can run before data leaves.
No. Unit 42 MDR is the managed service of Palo Alto Networks. Fortgale operates independently on the Cortex XDR tenant you already use, from a SOC in Milan that works in the same time zone and under the same European rules as its customers.
The tenant, its policies and its data stay under your control. Our analysts work with the accounts and roles agreed at onboarding, and every response action they take is recorded in the Cortex audit log, where your team can review it.
There is no go-live event: monitoring starts in the first days of onboarding and protection grows from there. Plan the end of the previous contract once technical onboarding is complete, one week in.
Both models work. Fortgale can operate the Cortex XDR licence you already own, or provide Cortex XDR licensing as part of the MDR service.
NIS2 does not mandate an MDR, and the service alone does not make you compliant. It does cover capabilities the directive expects you to answer for: continuous monitoring, incident handling and, when an incident is significant, the technical evidence for the early warning within 24 hours and the notification within 72 hours. On Cortex that evidence starts from the causality chain and the audit log of response actions.
We show how a Cortex alert becomes a decision: the causality chain the analyst reads, the XQL rule that raised it, the response executed and the evidence kept for NIS2 reporting. With it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.