Focus
Strata Cloud Manager

Threats

Table of Contents


Threats

Review the data provided by the Threats view.
The Threats view shows the traffic inspected on your network and threats detected by your CDSS subscriptions and Prisma SD-WAN devices. You can use this view to monitor the blocked and alerted threats on your network across Prisma Access, NGFW, and Prisma SD-WAN, or investigate areas of your network that need updated policies to better block any alerted threats.
Threats Licenses
  • Threats licenses, including:
    • Threat Prevention license
    • URL Filtering license
    • WildFire license
    • DNS Security license
    • Branch Security license (optional) — enables threat visibility from Prisma SD-WAN ION devices at branch sites

Central Threats View

The central Threats view provides a look into all the threats on your network that have been identified by your active Cloud-Delivered Security Services subscriptions and Prisma SD-WAN ION devices at branch sites.
The Threats view will show how your Palo Alto Networks CDSS subscriptions are protecting your traffic by monitoring potential threats on your network. The Command Center gives you insight into the traffic inspected for your IoT devices, users, and applications, and the total number of threats allowed or alerted.
The lines in the central Threats view represent the traffic being monitored by your security subscriptions, with the thickness representing the volume of threats detected and the color representing if the threats are of critical, high, medium, or low severity.
Hovering over a traffic line shows the volume of threats detected for that traffic path. Use the global filters at the top of the page to narrow the view by source type, platform, or security service.

Platform Types and Filter Scopes

The Threats view supports the following platform types:
  • Prisma Access
  • NGFW
  • Secure Direct Access — With a Branch Security license, this represents traffic reaching destinations with security enforcement applied at the branch. Without a Branch Security license, this represents direct access traffic that does not pass through a security inspection point.
To view threats specific to Prisma SD-WAN, filter by IoT or Users in the Command Center and select the Prisma SD-WAN connection type.
Standalone Prisma SD-WAN: When a tenant has only a Prisma SD-WAN license (no Prisma Access), the Threats page displays only the threats detected by Prisma SD-WAN devices, if the Branch Security subscription is enabled.

Security Subscriptions

The Security Subscriptions widget gives you a view into your Cloud-Delivered Security Subscriptions, which ones are active, and a snapshot of how they are securing your network.
SubscriptionDescription
Threat PreventionThreat Prevention defends your network against both commodity threats—which are pervasive but not sophisticated—and targeted, advanced threats perpetuated by organized cyber adversaries.
URL FilteringAdvanced URL Filtering is our comprehensive URL filtering solution that protects your network and users from web-based threats.
WildFireThe cloud-delivered WildFire malware analysis service uses data and threat intelligence from the industry’s largest global community, and applies advanced analysis to automatically identify unknown threats and stop attackers in their tracks.
DNS SecurityAutomatically secure your DNS traffic by using Palo Alto Networks DNS Security service.
Clicking on the Security Subscriptions widget (Command CenterView Security Subscriptions) gives you a detailed report of the status of your subscriptions in relation to your NGFWs and Prisma Access deployments. Click Back to the Dashboard to return to the Threats view.

Total Threats Count

The Total Threats Count widget gives you a quick view into the total number of threats detected in your network, how many threats have been blocked, how many threats have been alerted, and the change in threats from a selected time range. This widget also surfaces New and Unknown Threats as a separate metric — threats that do not yet have a known signature — broken down by those that were blocked and those that were allowed through. New and unknown threats represent a higher-risk category and help security teams prioritize investigation into emerging threats before they are widely classified.
Click through to the Activities Insights (InsightsActivity InsightsThreats) for a more detailed breakdown of threats on your network.

Best Practices Security Posture Assessment

The Best Practices Security Posture Assessment widget gives you a view into your security posture score as a percentage, the change in that score from the selected time range, and the number of critical recommendations related to threat prevention gaps in your deployment. This score reflects how well your security policies and subscriptions are aligned with best practices for threat prevention across Prisma Access, NGFW, and Prisma SD-WAN.
Click through to the Zero Trust Posture dashboard (InsightsZero Trust Posture) for a full breakdown of your posture score, a prioritized list of security recommendations, and guidance on how to close the gaps that are impacting your posture score.