# Palo Alto HyperVisor Integration

The CyberCyte portal provide Palo Alto - Cortex integration for more comprehensive visibility. We recommend it for observe all the Palo Alto - Cortex security events from users infrastructure from one portal.

## 1. Create Remote Credential in Portal

Please navigate to "Settings & Reporting" -> "Credential Settings". Click on the "+ Credential" button to create a new credential. Select the "Palo Alto Cortex API Credential" as a "Credential Type". The password should be provided by user. These uniqe variable can be get it from Palo Alto platform.

## 3. Editing The Policy in the Portal

Please navigate to "Rules & Policies" -> "Policy Management" -> Edit the "Palo Alto XDR Health Analysis" policy that we created in the previous page. Please select the "Supervisor Credential" and optionally enable the futures like "Uninstall If Not Running", "Perform Repair", "EDR/DLP Enabled", "Host Firewall Enabled". Demonstration is provided below:

If XDR agent is not running on users devices, CyberCyte can detect that and install it or attempt to repair the agent. The users can define custom installation command for these actions. Also, users can enable EDR, DLP and host firewall on the Palo Alto HypverVisor.

## 4. Reviewing the Results

The results can be observed from under the "Analysis & Investigation" -> "Artifact Analysis" -> "Threat Management" -> "Palo Alto Cortex XDR Alerts / Incidents".

Also, please navigate to "Analysis & Investigation" -> "Artifact Analysis" -> "Threat Management" -> "Palo Alto Cortex XDR Analysis" to observe the Palo Alto Cortex XDR health state on the CyberCyte portal.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.cloudcyte.com/getting-started/integrations/palo-alto-hypervisor-integration.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
