man in black jacket using computer

Cortex XSIAM and AgentiX: The Incumbent’s Answer to the AI SOC

<![CDATA[

Part five of a six-part series looking at the current wave of AI-driven SOC automation tools — Torq HyperSOC, Tines, Dropzone AI, Prophet Security, Cortex XSIAM/AgentiX, and StackStorm.

Everyone else in this series is a challenger of some size. Cortex XSIAM is the incumbent, and it’s worth understanding why Palo Alto Networks’ answer to the AI SOC trend looks different from the rest of the field: it isn’t a new product bolted onto an existing SOAR tool, it’s a decade of SOAR maturity with agentic AI built directly into a platform that already sits at the centre of a lot of large enterprise security stacks.

From XSIAM to AgentiX

XSIAM itself launched back in 2022 as a “novel category” designed to break away from the analyst-driven SIEM model — collecting telemetry, alerts, and events centrally and using automation to productise processes that used to require a human to stitch together manually. Cortex AgentiX, unveiled in late 2025, is the next evolution of that idea and effectively the successor to Cortex XSOAR: a platform specifically for building, deploying, and governing a workforce of AI agents, starting with the SOC.

AgentiX ships with prebuilt agents covering Threat Intelligence, Email Investigation, Endpoint Investigation, Network Security, Cloud Security, and IT, backed by over 1,000 prebuilt integrations and native MCP support so custom agents can be built without writing code. It’s currently available inside Cortex Cloud and Cortex XSIAM, with a standalone AgentiX platform and Cortex XDR integration following in early 2026.

Governance as the selling point

Palo Alto’s pitch leans hard into control rather than pure autonomy — role-based access, human-in-the-loop approval for anything with real impact, and full auditability, explicitly framed against “newer entrants” that the company suggests lack the same enterprise-grade policy enforcement. Whether or not you buy the competitive framing, the reasoning behind it is sound: an agent making changes across 70,000+ organisations’ security stacks needs a very different level of guardrails than a startup’s first production deployment. Palo Alto claims up to a 98% reduction in MTTR from the platform, alongside 75% less manual work for analysts.

The trade-off, as with most platform-native approaches, is that you’re buying into the wider Palo Alto ecosystem rather than picking a best-of-breed point solution — which is either a strength or a constraint depending on what you’re already running.

Next in this series: StackStorm, the open-source automation engine that predates all of this by over a decade.

]]>


Leave a Reply