logo

Unifying detection and response: Sysdig + Cortex XSOAR for security at cloud speed

ID: e8fddef1-84b7-5f51-b728-9f5d0157539f

STIX ID: report--e8fddef1-84b7-5f51-b728-9f5d0157539f

Feed Name: Sysdig Blog

Date Published: 2025-07-25

Date Updated: 2026-05-01

...
...

This document explains how integrating Sysdig with Palo Alto Networks Cortex XSOAR accelerates incident response across cloud, container, and host environments by unifying runtime detections, enriching context, and automating actions such as killing or pausing containers, quarantining files, and triggering system captures. It presents direct and SIEM-mediated integration patterns, details supported response commands and a sample system-capture playbook with human-in-the-loop approvals, provides high-level configuration steps, and illustrates an example workflow for responding to crypto-miner detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.