Skip to main content

CyberArk Endpoint Privilege Manager

Download With Dependencies

Endpoint Privilege Manager helps remove local admin rights while improving user experience and optimizing IT operations.

Overview

The CyberArk Endpoint Privilege Manager (EPM) integration with Cortex (XSOAR and XSIAM) enhances security operations by providing SOC teams with enriched context around security incidents related to identities. EPM helps organizations reduce the risk of endpoint attacks by removing local administrator rights and enforcing least privilege policies. It provides application control and privilege management to prevent malware and ransomware attacks, while enabling end-users to perform their tasks without interruption.

What does this pack do?

This new pack enables you with correlation rules for all detections fetched from EPM to XSIAM, mapping them to MITRE ATT&CK techniques and generate alerts. Additionally, it provides EPM commands for XSOAR and XSIAM, allowing you to build integrations using these connectors. You can execute these commands from the Cortex XSIAM Alerts War Room as part of an automation, or in a playbook.

Overview

The CyberArk Endpoint Privilege Manager (EPM) integration with Cortex (XSOAR and XSIAM) enhances security operations by providing SOC teams with enriched context around security incidents related to identities. EPM helps organizations reduce the risk of endpoint attacks by removing local administrator rights and enforcing least privilege policies. It provides application control and privilege management to prevent malware and ransomware attacks, while enabling end-users to perform their tasks without interruption.

What does this pack do?

This new pack enables you with correlation rules for all detections fetched from EPM to XSIAM, mapping them to MITRE ATT&CK techniques and generate alerts. Additionally, it provides EPM commands for XSOAR and XSIAM, allowing you to build integrations using these connectors. You can execute these commands from the Cortex XSIAM Alerts War Room as part of an automation, or in a playbook.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedFebruary 16, 2026
Last ReleaseMay 11, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
By downloading or using Marketplace content, you agree to the applicable Terms of Use and End User License Agreement. Third-party content is provided by its publisher, and Palo Alto Networks does not warrant, endorse, support, or assume responsibility for content not expressly identified as owned by Palo Alto Networks.