OFICIAL Palo Alto Networks Blog

Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security

What happened
Based on Palo Alto Networks Blog · Aug 06, 2026

Palo Alto Networks integrates Prisma Browser with Cortex XDR to address a critical visibility gap in browser security, enabling SOC teams to monitor and correlate browser-level threats with endpoint activity for faster incident response.

Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security
Palo Alto Networks Blog — Palo Alto Networks
Key points
·
The enterprise workforce now operates almost entirely within the web browser.
·
In fact, employees do roughly 85% of their daily work inside it, turning the browser into the sole operating system of the modern organization that connects every application, data interaction, and identity.
·
According to research from Unit 42, over 90% of breaches are preventable by solving for factors such as visibility gaps.
·
Because modern AI tools are predominantly accessed directly through the browser, it is now critical thatSOCs get visibility into what’s happening within the browser.
Key numbers
·
The modern enterprise relies on web browsers for 85% of daily tasks, yet security teams lack visibility into browser activity, treating it as an opaque process.
·
In fact, employees do roughly 85% of their daily work inside it, turning the

The modern enterprise relies on web browsers for 85% of daily tasks, yet security teams lack visibility into browser activity, treating it as an opaque process. Traditional XDR platforms monitor endpoints but fail to track malicious scripts, rogue extensions, or cross-origin attacks within the browser. This blind spot leaves SOC analysts unable to reconstruct attack narratives or identify the root causes of threats. Recent Palo Alto Networks research shows high volumes of Cortex threat detections stem from unmonitored browser activity, highlighting the urgency of this gap.

Palo Alto Networks has announced a native integration between Prisma Browser and Cortex XDR to unify browser-level telemetry with endpoint detection. The integration automatically feeds browser events—such as DLP violations, tampering, or unauthorized configurations—into Cortex XDR without requiring complex APIs or heavy deployment. When Cortex XDR detects an issue, browser-based events are correlated with endpoint activity to provide context on the attack's origin. This approach contrasts with legacy solutions that rely on brittle browser extensions, which often fail to monitor unmanaged devices effectively.

The integration introduces three key capabilities: comprehensive endpoint visibility paired with deep web context, precise forensic analysis to trace threats to their source, and surgical containment to neutralize threats without disrupting user productivity. For example, if a rogue extension attempts to compromise a session, traditional tools isolate the entire device, halting operations. The new integration isolates only the browser layer, allowing the employee to remain online while the threat is neutralized. Real-time analysis detects evasive threats like malicious scripts or rogue extensions as they occur.

The integration also addresses emerging risks from generative AI tools, such as unauthorized data exposure when employees paste proprietary code into public AI models. Prisma Browser monitors user behavior within the browser to detect and block DLP violations in real time, flagging shadow AI risks in the SOC dashboard before they escalate. By bridging the gap between browser and endpoint activity, the solution accelerates investigations, exposes hidden threats, and enables precise responses, reducing the impact of security incidents on business operations.

Original source → Deals on Clipraptor.com →