Threat Agent Workflows
Automate threat impact assessments using the Threat Expert Agent to cross-reference
global threat intelligence with your active configuration in Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
|
|
- Strata Cloud Manager Pro
- This feature is currently in Beta and available on request.
Contact your account team to enable the feature.
- Superuser role (for agent administration, onboarding, and
managing permissions)
- Network Administrator or Security Administrator role (for agent
interaction)
|
This feature leverages a large language model or generative
AI, and may contain errors. Double-check for accuracy before applying changes.
The Threat Expert Agent automates threat impact assessments by cross-referencing global
threat intelligence with your active security configuration. When a new vulnerability,
malware campaign, or threat actor emerges, this agent evaluates whether your network has
exposure, whether Palo Alto Networks provides protection, and whether your active policy
rules enforce that protection.
The agent integrates with Unit 42® threat intelligence, WildFire® verdict
databases, Advanced Threat Prevention signature repositories, and PAN-DB URL
categorization to build a comprehensive view of your threat posture. It scans your
30-day telemetry for historical indicators of compromise and cross-examines firewall
configurations, security profiles, and policy rules to confirm active enforcement.
The Threat Agent supports both reactive use (you query a specific CVE, hash, or threat
actor) and proactive use (the agent automatically assesses new threat publications from
Unit 42 and delivers completed reports to Action Center without manual invocation).
Supported Workflows
| Workflow | Trigger | Description |
| Threat Impact Assessment | NLQ, Event (Unit 42 publication) | Cross-reference threat indicators (CVEs, hashes, IPs, domains,
threat actors) against your configuration and telemetry to determine
exposure and coverage status. |
Common Invocation Examples
| Query | What It Does |
| @agent/threat Am I protected from CVE-2026-1234? | Runs a full threat impact assessment: checks signature availability,
verifies profile enforcement on active rules, and scans telemetry for
exploit attempts. |
| @agent/threat Have I seen traffic to 192.0.2.50 in the last 30 days? | Scans your traffic logs for historical interactions with the
specified indicator and reports any matches with timestamps and source
details. |
| @agent/threat Is my firewall configured to block Black Basta? | Resolves the threat actor to known indicators of compromise and
assesses your posture against the actor's specific toolset, C2
infrastructure, and exploitation techniques. |