MDR partner · Cortex XDR · Palo Alto Networks

MDR for Cortex XDR, run from a European SOC.

For organisations that already run Cortex XDR and have no team to operate it at night, or an MSSP that opens tickets instead of containing. The Fortgale MDR service works inside your Cortex tenant: analysts with a mandate to decide read the causality chain and execute the response, with a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × Cortex
MDR · live
Cortex sensor activeEndpoint · cloud · identity telemetry
Cortex
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native Cortex responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, Cortex + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Cortex XDR · Palo Alto Networks
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on Cortex.

The Cortex modules and data sources the SOC takes on. Where Cortex is not deployed yet, Fortgale handles licensing and agent rollout as part of the service.

01

Cortex XDR · endpoint

Cortex XDR agent telemetry, the causality chain of every alert and custom XQL detection rules mapped to MITRE ATT&CK.

02

Palo Alto network telemetry

Native ingestion from PAN-OS next-generation firewalls and Prisma Access, stitched with endpoint activity into the same case.

03

Cloud workloads

Workload telemetry from Prisma Cloud (now part of Cortex Cloud), in the same console as endpoint and network.

04

Identity

Identity Threat Detection analytics in Cortex XDR, part of the detections the SOC works on every day.

05

Cortex XSIAM and Xpanse

For organisations on XSIAM, detection and response run on the XSIAM platform; Xpanse exposure data is among the Cortex modules the SOC operates.

06

Cortex XSOAR playbooks

Optional: cross-tool response and enrichment playbooks in Cortex XSOAR, written and maintained by Fortgale.

What we add

What Fortgale adds on top of Cortex.

What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.

On Cortex the analyst acts from the console with native actions: endpoint isolation, process termination, file quarantine, hash blocklisting and a Live Terminal session for live forensics on the host.

Locking an Active Directory account is not an endpoint action in Cortex XDR: it runs through a Cortex XSOAR playbook. Blocking indicators at the network edge goes through the PAN-OS integration, so endpoint and network containment are coordinated from the same case.

Fortgale indicators are loaded as Cortex IOC rules, so a known indicator opens a case before the causality chain is complete, and XQL rules follow the actors that target European sectors.

Takeover

How we take over your Cortex environment.

Takeover happens on your existing Cortex tenant: agents already deployed stay where they are and no data is migrated.

Defence is active as soon as access and monitoring go live, and technical onboarding closes in one week: Cortex roles, integrations and response authorisations are complete and the service runs at full capacity.

On your side: a technical contact, the Cortex roles for our analysts and the escalation list. Response authorisations and exclusions are agreed with your team before the first action.

From the field

Storming Tide: when the attack moves where there is no agent.

In February 2026 the Fortgale incident response team contained Operation Storming Tide at a European logistics company. The attacker had come in months earlier through a vulnerable Fortinet firewall, left a persistent VPN tunnel and a compromised service account, then moved through unmanaged assets into the internal network, bringing the Matanbuchus 3.0 loader, the Astarion RAT, SystemBC and RClone staged to exfiltrate to S3 storage. The investigation started from anomalous internal network scanning; neither exfiltration nor ransomware happened.

The article is not about Cortex, but it is the kind of chain the SOC reads on Cortex from two sides. If internal traffic crosses PAN-OS firewalls, the scan leaves a trace even when it starts from a host with no agent; on hosts with an agent, the causality chain ties scheduled tasks, loader and RClone launch into one case, and endpoint isolation can run before data leaves.

FAQ

What buyers running Cortex actually ask.

Do we need Unit 42 MDR to work with Fortgale?

No. Unit 42 MDR is the managed service of Palo Alto Networks. Fortgale operates independently on the Cortex XDR tenant you already use, from a SOC in Milan that works in the same time zone and under the same European rules as its customers.

What happens to our Cortex console and our access?

The tenant, its policies and its data stay under your control. Our analysts work with the accounts and roles agreed at onboarding, and every response action they take is recorded in the Cortex audit log, where your team can review it.

How do we move from another provider without a gap in coverage?

There is no go-live event: monitoring starts in the first days of onboarding and protection grows from there. Plan the end of the previous contract once technical onboarding is complete, one week in.

Do we buy the Cortex licences, or do you?

Both models work. Fortgale can operate the Cortex XDR licence you already own, or provide Cortex XDR licensing as part of the MDR service.

Does the service help with NIS2 obligations?

NIS2 does not mandate an MDR, and the service alone does not make you compliant. It does cover capabilities the directive expects you to answer for: continuous monitoring, incident handling and, when an incident is significant, the technical evidence for the early warning within 24 hours and the notification within 72 hours. On Cortex that evidence starts from the causality chain and the audit log of response actions.

See a real runbook

A real runbook on your Cortex tenant.

We show how a Cortex alert becomes a decision: the causality chain the analyst reads, the XQL rule that raised it, the response executed and the evidence kept for NIS2 reporting. With it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.