Designed to enable cybersecurity professionals, particularly those in SOC/CERT/CSIRT and engineering roles, to use XSIAM.

Overview

XSIAM is the industry’s most comprehensive security incident and asset management platform, offering extensive coverage for securing and managing infrastructure, workloads, and applications across multiple environments.

The course is designed to enable cybersecurity professionals, particularly those in SOC/CERT/CSIRT and engineering roles, to use XSIAM. The course reviews XSIAM intricacies, from fundamental components to advanced strategies and techniques, including skills needed to configure security integrations, develop automation workflows, manage indicators, and optimize dashboards for enhanced security operations.

Skills Covered

This course is designed to enable you to:

  • Describe how endpoint agents, XDR collectors, NGFWs, and Broker VMs secure networks and devices.
  • Query and analyze logs using XQL for data ingestion and detection.
  • Configure Threat Intel Management features, automate workflows, and apply EDLs and indicator rules.

Prerequisites

Participants should have a foundational understanding of cybersecurity principles and experience with network and endpoint security fundamentals.

Target Audience

SOC/CERT/CSIRT/XSIAM engineers and managers, MSSPs and service delivery partners/system integrators, internal and external professionalservices consultants and sales engineers, SIEM and automation engineers.

Course Curriculum

Module 0: Course Overview
Module 1: Overview of Cortex XSIAM
Module 2: Software Components
Module 3: XQL
Module 4: Detection Engineering
Module 5: Integrations
Module 6: Automation
Module 7: Threat Intel Management
Module 8: Attack Surface Management
Module 9: UI Customizations

Dates & Locations

Let’s make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our learning experts today.

August 19, 2026 - August 21, 2026

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 1000

August 19, 2026 - August 21, 2026

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 1000

November 18, 2026 - November 20, 2026

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 1000

November 18, 2026 - November 20, 2026

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 1000
Trainocate exam and cert

Exam & Certification

Palo Alto Networks Certified XSIAM Engineer.

This certification validates experienced security operations engineers on their knowledge and skills in installation, deployment configuration, post-deployment management and configuration, data source onboarding and integration configuration, playbook creation, and detection engineering using Cortex XSIAM in security operations environments.

Training & Certification Guide

Frequently Asked Questions

Speak to a Training Consultant

All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631

Preferred mode of training
Checkboxes