Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster
Palo Alto Networks’ Unit 42 launches new threat intelligence services to help security teams prioritize and act on relevant threats faster amid rapidly evolving attacks.
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
Security teams face an overwhelming volume of threat data, much of which lacks relevance to their specific environments. Traditional models, which rely on collecting vast quantities of indicators, often fail to provide actionable insights in time to prevent incidents. Adversaries are exploiting vulnerabilities and adapting techniques at an accelerated pace, with Unit 42 observing attacks moving four times faster over the past year. The new approach aims to bridge the gap between threat awareness and effective response by focusing on what matters most to each organization.
Unit 42 Threat Intelligence introduces two offerings: Cortex eXtended Threat Intelligence (Cortex XTI) and Unit 42 Threat Intel Services. Cortex XTI integrates Unit 42’s proprietary research directly into the Cortex platform, combining global threat visibility with contextual data from each customer’s environment. This integration helps analysts identify the most relevant threats—such as active adversaries targeting their industry or exploiting their deployed technologies—and streamlines workflows from detection to response. The goal is to reduce the time between awareness and action, enabling faster prevention and mitigation.
Unit 42 Threat Intel Services provides customers with direct access to Unit 42 analysts, who track adversaries through active campaigns and real-world incidents. Unlike automated feeds, this service offers tailored intelligence, proprietary research, and expert guidance grounded in firsthand observations. Customers receive insights tailored to their specific needs, helping them understand not just what threats exist, but why they matter and how to address them. The service emphasizes practical, actionable intelligence derived from thousands of incident response engagements.
The new intelligence model leverages Palo Alto Networks’ visibility across over 70,000 customers, analyzing billions of daily events to identify nearly 9 million novel threats. However, the company emphasizes that scale alone does not equate to intelligence; the value lies in connecting global threat data to each customer’s unique environment. By embedding frontline intelligence into security operations, Unit 42 aims to help defenders anticipate adversary actions, strengthen defenses, and respond before attackers achieve their objectives.