{"id":45290,"date":"2022-02-14T00:00:00","date_gmt":"2022-02-14T00:00:00","guid":{"rendered":"urn:uuid:e1ffe18b-33aa-cca1-9627-622f52043784"},"modified":"2022-02-14T00:00:00","modified_gmt":"2022-02-14T00:00:00","slug":"security-automation-with-vision-one-palo-alto","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/","title":{"rendered":"Security Automation with Vision One &amp; Palo Alto"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/RNP-Trend-Palo.jpg\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <!-- Begin mPulse library --> <!-- END mPulse library --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"Vision One integrates with Palo Alto's Cortex\u2122 XSOAR to drive automated response to incidents - read how this security automation simplifies work for SOC analysts.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"latest news,exploits &amp; vulnerabilities,cyber threats,apt &amp; targeted attacks,endpoints,network,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2022-02-14\"> <meta property=\"article:tag\" content=\"apt &amp; targeted attacks\"> <meta property=\"article:section\" content=\"latest news\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/b\/security-automation.html\"> <title>Security Automation with Vision One &amp; Palo Alto<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/b\/security-automation.html\"><br \/>\n<meta property=\"og:title\" content=\"Security Automation with Vision One &amp; Palo Alto\"><br \/>\n<meta property=\"og:description\" content=\"Vision One integrates with Palo Alto's Cortex\u2122 XSOAR to drive automated response to incidents - read how this security automation simplifies work for SOC analysts.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/RNP-Trend-Palo.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Security Automation with Vision One &amp; Palo Alto\"><br \/>\n<meta name=\"twitter:description\" content=\"Vision One integrates with Palo Alto's Cortex\u2122 XSOAR to drive automated response to incidents - read how this security automation simplifies work for SOC analysts.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/RNP-Trend-Palo.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"50.62616464582\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"2034544536\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"7.7542662116041\">\n<div class=\"article-details\" role=\"heading\" readability=\"34.894197952218\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">APT &amp; Targeted Attacks<\/p>\n<p class=\"article-details__description\">Trend Micro Vision One\u2122 integrates with Palo Alto Networks Cortex\u2122 XSOAR to drive automated response to incidents uncovered by Vision One.<\/p>\n<p class=\"article-details__author-by\">By: Trend Micro <time class=\"article-details__date\">February 14, 2022<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"32.469453376206\">\n<div readability=\"15.332797427653\">\n<p>Trend Micro Vision One\u2122 is at the core of our unified cybersecurity platform, delivering powerful, industry-leading extended detection and response (XDR), centralized visibility and risk insights. <a href=\"https:\/\/www.youtube.com\/watch?v=mH7NCnT1AP0\" target=\"_blank\" rel=\"noopener\">Vision One integrates with Palo Alto Networks Cortex\u2122 XSOAR<\/a> to drive automated response to incidents uncovered by Vision One. This simplifies investigations and response for SOC analysts, enabling them to easily execute necessary steps all from within Cortex\u2122 XSOAR via commands and playbooks.<\/p>\n<p>At the core of this integration is the creation of Cortex\u2122 XSOAR incidents from Trend Micro Vision One\u2122 workbench alerts.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure1.png\" alt=\"figure1\"> <\/figure>\n<\/p><\/div>\n<div>\n<div class=\"richText\" readability=\"43\">\n<div class=\"responsive-table-wrap\" readability=\"31\">\n<p>Having the incident details available in the Cortex\u2122 XSOAR platform enables analysts to execute a series of manual or automated actions through the Trend Micro Vision One\u2122 platform in response to a potential threat. In the initial release of this content pack, we have made the following response actions available:<\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"31.5\">\n<tr readability=\"7\">\n<td>Add item to exception list<\/td>\n<td>Adds domains, IP addresses, URLs, or file hashes to the known good list<\/td>\n<\/tr>\n<tr readability=\"7\">\n<td>Remove item from the exception list<\/td>\n<td>Removes domains, IP address, URLs, or file hashes from the known good list<\/td>\n<\/tr>\n<tr readability=\"7\">\n<td>Add item to suspicious objects list<\/td>\n<td>Adds domains IP addresses, URLs, or file hashes to the suspicious object list and specifies the appropriate action to take if discovered (log or block)<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>Remove item from suspicious objects list<\/td>\n<td>Removes domains IP addresses, URLs, or file hashes from the suspicious object list<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Collect files<\/td>\n<td>Collects the specified file from an endpoint during an investigation<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Submit a file for sandbox analysis<\/td>\n<td>Submits a file to the Trend Micro Vision One sandbox for automated analysis<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>Retrieve sandbox analysis report<\/td>\n<td>Retrieves the analysis report, IOCs, or artifacts available after automated analysis<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Quarantine email message<\/td>\n<td>Removes the specified email message from the user\u2019s mailbox and places it in the mail quarantine<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Delete email message<\/td>\n<td>Permanently deletes the specified email message from the user\u2019s mailbox<\/td>\n<\/tr>\n<tr readability=\"9\">\n<td>Gather information on an endpoint<\/td>\n<td>Gathers information from the endpoint such as the current logged on user, operating system details, IP address, hostname, mac address<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Terminate process<\/td>\n<td>Terminates the specified process if currently running on an endpoint<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Isolate endpoint<\/td>\n<td>Blocks all network activity on an endpoint while the system is being investigated<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>Restore endpoint connection<\/td>\n<td>Restores the network connectivity on an endpoint after investigation and\/or remediation has occurred<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Check action status<\/td>\n<td>Checks the status of a triggered Trend Micro Vision One response action<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These actions lend the power of Trend Micro Vision One\u2122 to analysts as they investigate and respond to incidents. All of these actions can be run manually or can be included in the organization\u2019s pre-defined playbooks for automated response.<\/p>\n<p>To demonstrate the value of these integrated platforms, let us walk through a use case where the combination of Trend Micro Vision One\u2122 and Palo Alto Networks Cortex\u2122 XSOAR improved a customer\u2019s ability to investigate and respond to incidents.<\/p>\n<p><b>Scenario: If credential dumping was detected on a host, the security operations team wanted to automate the collection of artifacts to be used during a subsequent investigation. Threat actors are very efficient at cleaning up their tracks to evade tracing, so this activity would need to be executed quickly.<\/b><\/p>\n<p>Trend Micro Vision One\u2122 is very effective at identifying the various techniques threat actors use to discover credentials. One commonly used technique that gets detected is the dumping of credentials via the Local Security Authority Server Service (LSASS) process in Microsoft Windows.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure2.png\" alt=\"figure2\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>As you can see in this example, it was observed that Windows Task Manager was used to dump the LSASS process to a file. This file can then be analyzed by a threat actor to look for password hashes they can use as part of their attack. Security analysts may also want to examine the content of a credential dump to identify the account information the threat actor may have had access to. Trend Micro Vision One\u2019s <i>contextual response actions<\/i> could be used to retrieve this information from the endpoint when reviewing an incident.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure3.png\" alt=\"figure3\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>However, since threat actors tend to cover their tracks quickly, by the time the security analyst is reviewing the incident, there is a chance that critical information may have been permanently deleted and is no longer readily accessible.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure4.png\" alt=\"figure4\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>Instead of depending on a security analyst to review a credential dumping event and manually collecting artifacts for their investigation, Trend Micro wanted to automate the collection of this evidence as quickly as possible when a detection occurs. This allows for information to be gathered prior to it being exfiltrated and destroyed.<\/p>\n<p>To automate the retrieval of the dumped credentials, we leveraged the powerful integration between Trend Micro Vision One\u2122 and Cortex\u2122 XSOAR to create a playbook for this task.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure5.png\" alt=\"figure5\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>1. The first step in our playbook is to check if the event is related to credential dumping. If not, there is no point in collecting any files from the endpoint, so we jump to the end.<\/p>\n<p>2. We then use the \u201c<b>trendmicro-visionone-get-endpoint-info<\/b>\u201d integration command to gather information about the endpoint(s) where the detection occurred that will be used as inputs for commands that will run later. This would include things like the operating system and which Trend Micro product is deployed on the endpoint.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure6.png\" alt=\"figure6\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>3. After we have gathered the information, the next step is to collect the file from the endpoint using the command \u201c<b>trendmicro-visionone-collect-forensic-file<\/b>\u201d. Outputs from the \u201c<b>trendmicro-visionone-get-endpoint-info<\/b>\u201d command will be passed to this command along with details from the incident about the files where the credentials were dumped.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure7.png\" alt=\"figure7\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>4. We now need to wait for the complete collection of the file(s) so we will run the \u201c<b>trendmicro-visionone-check-status<\/b>\u201d command to continuously poll for the status of the file collection and wait until it is complete before moving on to the next step.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure8.png\" alt=\"figure8\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p>5. After the file has been collected, it is stored in the Trend Micro Vision One\u2122 platform. We need to request that a download link be generated for the collected files with the \u201c<b>trendmicro-visionone-download-information-for-collected-forensic-file<\/b>\u201d. These download links are intended to be used quickly, or in automation tasks, and therefore have very short lifetimes.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure9.png\" alt=\"figure9\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>6. Once we have the download link, we can then use the Cortex\u2122 XSOAR built-in command \u201chttp\u201d to retrieve the file and save it to the War Room for this incident so that it can be downloaded and analyzed.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/figure10.png\" alt=\"figure10\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.64347826087\">\n<div readability=\"16.359420289855\">\n<p>This is just one example use case that we have seen implemented to automate security operations by leveraging the integration between Trend Micro Vision One\u2122 and Palo Alto Networks Cortex\u2122 XSOAR. We look forward to seeing how many additional ways these integrated platforms can help organizations improve their security operations.<\/p>\n<p>Why not take Trend Micro <a href=\"https:\/\/resources.trendmicro.com\/vision-one-test-drive.html?_ga=2.258269898.1102686256.1644357627-2.266528910.1607693918.1639750068-undefined\" target=\"_blank\" rel=\"noopener\">Vision One<\/a>\u2122 <a href=\"https:\/\/resources.trendmicro.com\/vision-one-test-drive.html?_ga=2.258269898.1102686256.1644357627-2.266528910.1607693918.1639750068-undefined\" target=\"_blank\" rel=\"noopener\">for a test drive<\/a> to see how it can help you see more and respond faster to the threats your organization faces?<\/p>\n<p><i>Copyright \u00a9 2022. Trend Micro Incorporated. All rights reserved. Trend Micro and the t-ball logo are registered trademarks of Trend Micro Incorporated. Cortex XSOAR is a trademark of Palo Alto Networks.<\/i><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/b\/security-automation.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trend Micro Vision One\u2122 integrates with Palo Alto Networks Cortex\u2122 XSOAR to drive automated response to incidents uncovered by Vision One. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":45291,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9546,9510,9511,9508,9555,9534,9523],"class_list":["post-45290","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-apttargeted-attacks","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-endpoints","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-latest-news","tag-trend-micro-research-network"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Automation with Vision One &amp; Palo Alto 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Automation with Vision One &amp; Palo Alto 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-14T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/RNP-Trend-Palo.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Security Automation with Vision One &amp; Palo Alto\",\"datePublished\":\"2022-02-14T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/\"},\"wordCount\":1205,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/security-automation-with-vision-one-palo-alto.png\",\"keywords\":[\"Trend Micro Research : APT&amp;Targeted Attacks\",\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Latest News\",\"Trend Micro Research : Network\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/\",\"name\":\"Security Automation with Vision One &amp; Palo Alto 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/security-automation-with-vision-one-palo-alto.png\",\"datePublished\":\"2022-02-14T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/security-automation-with-vision-one-palo-alto.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/security-automation-with-vision-one-palo-alto.png\",\"width\":1766,\"height\":1010},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/security-automation-with-vision-one-palo-alto\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : APT&amp;Targeted Attacks\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-apttargeted-attacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Security Automation with Vision One &amp; Palo Alto\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Automation with Vision One &amp; Palo Alto 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/","og_locale":"en_US","og_type":"article","og_title":"Security Automation with Vision One &amp; Palo Alto 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-02-14T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/b\/security-automation-with-vision-one-palo-alto\/RNP-Trend-Palo.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Security Automation with Vision One &amp; Palo Alto","datePublished":"2022-02-14T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/"},"wordCount":1205,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/security-automation-with-vision-one-palo-alto.png","keywords":["Trend Micro Research : APT&amp;Targeted Attacks","Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Threats","Trend Micro Research : Endpoints","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Latest News","Trend Micro Research : Network"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/","url":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/","name":"Security Automation with Vision One &amp; Palo Alto 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/security-automation-with-vision-one-palo-alto.png","datePublished":"2022-02-14T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/security-automation-with-vision-one-palo-alto.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/security-automation-with-vision-one-palo-alto.png","width":1766,"height":1010},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/security-automation-with-vision-one-palo-alto\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : APT&amp;Targeted Attacks","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-apttargeted-attacks\/"},{"@type":"ListItem","position":3,"name":"Security Automation with Vision One &amp; Palo Alto"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45290","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=45290"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45290\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/45291"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=45290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=45290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=45290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}