Threat Agent Workflows
Focus
Focus
Strata Cloud Manager

Threat Agent Workflows

Table of Contents

Threat Agent Workflows

Automate threat impact assessments using the Threat Expert Agent to cross-reference global threat intelligence with your active configuration in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Strata Cloud Manager Pro
  • This feature is currently in Beta and available on request. Contact your account team to enable the feature.
  • Superuser role (for agent administration, onboarding, and managing permissions)
  • Network Administrator or Security Administrator role (for agent interaction)
This feature leverages a large language model or generative AI, and may contain errors. Double-check for accuracy before applying changes.
The Threat Expert Agent automates threat impact assessments by cross-referencing global threat intelligence with your active security configuration. When a new vulnerability, malware campaign, or threat actor emerges, this agent evaluates whether your network has exposure, whether Palo Alto Networks provides protection, and whether your active policy rules enforce that protection.
The agent integrates with Unit 42® threat intelligence, WildFire® verdict databases, Advanced Threat Prevention signature repositories, and PAN-DB URL categorization to build a comprehensive view of your threat posture. It scans your 30-day telemetry for historical indicators of compromise and cross-examines firewall configurations, security profiles, and policy rules to confirm active enforcement.
The Threat Agent supports both reactive use (you query a specific CVE, hash, or threat actor) and proactive use (the agent automatically assesses new threat publications from Unit 42 and delivers completed reports to Action Center without manual invocation).
Supported Workflows
WorkflowTriggerDescription
Threat Impact AssessmentNLQ, Event (Unit 42 publication)Cross-reference threat indicators (CVEs, hashes, IPs, domains, threat actors) against your configuration and telemetry to determine exposure and coverage status.
Common Invocation Examples
QueryWhat It Does
@agent/threat Am I protected from CVE-2026-1234?Runs a full threat impact assessment: checks signature availability, verifies profile enforcement on active rules, and scans telemetry for exploit attempts.
@agent/threat Have I seen traffic to 192.0.2.50 in the last 30 days?Scans your traffic logs for historical interactions with the specified indicator and reports any matches with timestamps and source details.
@agent/threat Is my firewall configured to block Black Basta?Resolves the threat actor to known indicators of compromise and assesses your posture against the actor's specific toolset, C2 infrastructure, and exploitation techniques.