TrustRadius: an HG Insights company

Palo Alto Networks AutoFocus

Score8 out of 10

10 Reviews and Ratings

What is Palo Alto Networks AutoFocus?

AutoFocus™ contextual threat intelligence service, from Palo Alto Networks, accelerates analysis, correlation and prevention workflows. Targeted attacks are automatically prioritized with full context, allowing security teams to respond to critical attacks faster, without additional IT security resources.

Categories & Use Cases

Who Buys & Uses Palo Alto Networks AutoFocus

Autofocus Simple & Smooth

Use Cases and Deployment Scope

Palo Alto Autofocus help our team as their main threat intelligence product, we have most of our perimeter with Palo Alto devices so it was easy to integrate the product with our current infrastructure. Palo Alto Autofocus helps us to determine if a threat is a real threat in a matter of seconds and also notify us when they are emerging threats that might affect us.

Pros

  • Threat intelligence
  • Emerging Threats
  • Intelligence feeds

Cons

  • Better GuI
  • Not so many automation options
  • Too simple queries

Most Important Features

  • Threat intelligence
  • Emerging threats
  • Notifications in real time

Return on Investment

  • Cheap for us
  • Easy integration
  • Easy management

Alternatives Considered

Anomali ThreatStream

Other Software Used

Rapid7 InsightVM (Nexpose), Nessus, Metasploit

Best value for the money

Use Cases and Deployment Scope

Auto focus is being used for threat intelligence integrated with all of the palo alto networks firewalls. We use it throughout the enterprise even for the subsidiary companies. It really helps the SOC team to enhance their incident analysis. It broadens the scope of analysis with threat specific pinpoint data with a little False Positive. Autofocus is a saas service. Licensing is based on the number of users. It leverages the analytics and correlation with cloud services whereas the correlation is based on the customer data. Dahsboard is customizable. I see more value on the autofocus data compared to panorama or palo alto firewalls dashboards. It has tight integrations with several services. There are feeds which we use and indirectly to import these lists to the firewalls with SOAR entegration.

Pros

  • tagging and prioritization of events
  • sectoral and peer/industry views compared to your company
  • dnssec view is superb, I get more detail on the autofocus compared to my local implementation
  • customizable alerts for specific indicators and events
  • additional feed entegrations
  • searches for IP, URL, hash
  • minemeld integration throgh the indicators
  • unit42 direct integration on the dashboard

Cons

  • Views are cumbersome, you should know what to search and use the input
  • It's solely to PaloAlto environment I can't integrate other vendors natively
  • Application integrations is limited, you should have your own SOAR to automaion
  • Concerns related to privacy, I can't hash some values or variables on the cloud
  • Sharing option of the datas with cloud has limited configuration
  • It's aimed for strata, I don't see data coming/analyzed or integration for the prisma cloud side.

Most Important Features

  • Analytics and correlation
  • Threat Hunting
  • Unit42 data
  • company vs global vs industry view
  • Search functionality

Return on Investment

  • Licensing is solid and based on numbers of users
  • ROI time for the big enterprises is very fast
  • Pinpoint accuracy on the threats, SOC does not waste time for additional analysis
  • Superb easy integration
  • Little maintenance for the service
  • Service uptime is very high

Alternatives Considered

Check Point ThreatCloud

Other Software Used

Picus Security, Cymulate, FortiGuard Web Filtering Service

Excelent threat intelligence network

Use Cases and Deployment Scope

I implemented Palo Alto Networks AutoFocus in many companies as an intelligence threat network used to detect and block new threats and especially 0-day vulnerabilities . It's generally connected to firewalls and SOC software to enable automated updates and intelligence sources for files that need to be analyzed looking for malware.

Pros

  • real time alerts
  • detecting new malwares
  • Proactively Response

Cons

  • third party product integration
  • simplicity of the managment console
  • integration to cortex agents directly

Most Important Features

  • threat tags
  • statistics and graphs of reports
  • automatic attack prevention

Return on Investment

  • new attacks mitigation
  • less need to hire personal to analyse data
  • increase security level

Alternatives Considered

Talos, powered by 360 and FortiGuard Web Filtering Service

Other Software Used

Trend Micro Apex One (formerly OfficeScan), Vade Secure, Sophos Intercept X, Palo Alto Networks Cortex XDR (Traps), FortiManager

Advanced Threat Intelligence Service from Paloalto

Use Cases and Deployment Scope

AutoFocus is a SaaS-based security service [that] offers a threat intelligence service that assists security teams on how to protect their organizations from unique, targeted attacks. In my organization as well, as part of our cybersecurity setup, threat intelligence has been an important focus area with the objective of leveraging a threat intelligence platform/service to secure against cybersecurity attacks.

Pros

  • The ability to have quick access to the Palo Alto Networks threat intelligence repository is a big value add
  • Each threat is enriched with a lot of contextual information
  • Guidance on TI use cases

Cons

  • Search mechanism needs improvement to optimize performance and reliability
  • DNS Security dashboard could be improved
  • UI improvements which could be made more intuitive

Most Important Features

  • Access to a massive repository of Palo Alto Networks threat intelligence data
  • Helps understand better our attack surface and TI use cases
  • Solution to operationalize TI in our cybersecurity program

Return on Investment

  • Very positive in setting up our TI practice