Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
Torrance, United States / California, Fri, Dec 19, 2025
Torrance, United States / California, Fri, Dec 19, 2025
Criminal IP , developed by AI SPERA, has been integrated into Palo Alto Networks’ Cortex XSOAR. This integration enhances incident response through real-time threat context and automated scanning capabilities.
The integration allows for the incorporation of external threat context, exposure intelligence, and automated scanning within Cortex XSOAR’s orchestration engine. This provides security teams with improved incident accuracy and response times compared to traditional methods.
Palo Alto Networks’ Cortex XSOAR serves as a hub for SOC automation. With the Criminal IP integration, users can evaluate IPs and domains using behavioral signals, exposure history, and AI-driven threat scoring, without needing additional systems.
Torrance, United States / California, Fri, Dec 19, 2025 Criminal IP , developed by AI SPERA, has been integrated into Palo Alto Networks’ Cortex XSOAR.
The integration addresses traditional limitations by providing enriched intelligence through Criminal IP’s analysis of internet-facing assets. It includes IP behavior, domain activity, SSL/TLS data, and more, enabling better incident assessment within Cortex XSOAR.
Cortex XSOAR can initiate Criminal IP’s three-stage scanning workflow, which includes Quick Lookup, Lite Scan, and Full Scan for comprehensive analysis. This workflow continues seamlessly, delivering structured reports and linking internal telemetry with external intelligence.
The integration of Palo Alto Networks and Criminal IP supports the shift towards autonomous security operations. By combining Cortex XSOAR’s capabilities with Criminal IP’s analysis, SOC teams can automate decisions, reducing response times and improving incident classification accuracy.
Criminal IP offers comprehensive threat visibility and is integrated with over 40 security vendors. It is available on marketplaces like Azure, AWS, and Snowflake, enhancing global access to high-quality threat intelligence.
Based on reporting by Cyber Security News.
