Security teams do not need another threat feed.
Instead, they need to know which threats matter to their organization, what’s coming, and what they should do next.
That distinction has never been more important. Adversaries are discovering vulnerabilities, evolving techniques and adapting campaigns faster than security teams can update their defenses. What’s more, AI accelerates every stage of this process. Unit 42 has already observed attacks moving four times faster over the past year, shrinking the window defenders have to disrupt attacks before they become incidents.
The traditional threat intelligence model was not built for this reality.
For years, the industry has focused on collecting more – more feeds, more reports, more indicators and larger repositories to store them. But intelligence that remains disconnected from the organization it is meant to protect just creates more work, not better defense. Analysts are left to determine what is relevant, connect it to their environment and manually translate it into detections, hunts and response actions.
In a threat landscape measured in minutes, that model no longer works.
Consider ransomware. Knowing that a group is active is useful, but knowing that it is targeting organizations in your industry, exploiting technology deployed in your environment and following a pattern Unit 42 has already observed during incident response is actionable. When you embed that context directly into the tools your analysts use to detect and respond, it can change the outcome.
Today, we are introducing Unit 42 Threat Intelligence to expand access to our proprietary research and close the gap between understanding a threat and neutralizing it.
Unit 42 Threat Intelligence is available through two complementary offerings: Cortex eXtended Threat Intelligence (Cortex XTI) and Unit 42 Threat Intel Services.
Cortex XTI embeds Unit 42 intelligence directly into the Cortex platform, combining global threat visibility with the context of each customer’s environment to identify the actors, campaigns, malware and exposures that matter most. It then brings that intelligence into the security operations workflows analysts already use, helping teams move faster from awareness to prevention, detection, hunting and investigation.
Unit 42 Threat Intel Services connect customers directly with the Unit 42 analysts tracking these adversaries on the front lines. Customers gain tailored intelligence, proprietary research and expert guidance grounded in active threat campaigns and real-world incidents, not simply another stream of automated signals.
These capabilities are designed to help security teams:
- See what matters: Prioritize the threats and exposures most relevant to their environment.
- Understand the adversary: Connect activity to the actors, campaigns, techniques and intent behind it.
- Take action: Operationalize intelligence directly with expert guidance and native integrations within the tools and workflows defenders already use.
Unit 42 Threat Intelligence draws on Palo Alto Networks deep visibility across more than 70,000 customers, from which we analyze billions of events and identify nearly 9 million novel threat daily, combined with lessons from thousands of Unit 42 incident response engagements.
Yet our scale alone is not intelligence. The advantage comes from connecting what we see globally and in real attacks to each customer’s environment, showing them which threats matter, why they matter and what they should do next.
The future of threat intelligence cannot be another feed. It is frontline intelligence embedded directly into security operations, helping defenders understand the adversary, strengthen their defenses and act before an attacker achieves its objective. Learn more here : https://www.paloaltonetworks.com/unit42/threat-intelligence.