All evals
Palo Alto Networks

Eval directory · Security Operations

Evals for Palo Alto Networks

Eval coverage for Palo Alto Networks, mapped from its public product surface.

About Palo Alto Networks

Palo Alto Networks markets an integrated portfolio of cybersecurity platforms spanning network security, cloud security, SOC, SASE, and identity security, unified under a "platformization" approach powered by Precision AI. Recent product pushes center on securing AI usage — Prisma AIRS for AI applications, agents, models and data, and Idira, a next-generation identity security platform for human, machine and AI agent identities. Prisma SASE covers hybrid work with security for users, apps, data and devices across managed and unmanaged endpoints.

Industry

enterprise cybersecurity platform (network, cloud, SOC, SASE, AI and identity security)

Use the eval library for Palo Alto Networks

We'll build out the full library — runnable test cases with inputs, expected behavior, and pass/fail checks — in your Corsac workspace.

Generate your own →

Coverage map

What would you measure for Palo Alto Networks?

6 scoring areas · 24 capabilities mapped · grounded in 8 cited pages

Every eval set is graded on

  • Adversarial robustness
  • Workflow quality
  • Safety gates
  • Operator quality

Pass/Fail + LLM judge 1–5 · critical severity flags · negative controls

01

AI Application & Agent Security (Prisma AIRS)

Coverage of the publicly described Prisma AIRS platform for securing AI apps, agents, models and data from development to deployment, including the generally available AI Gateway, AI runtime threat classes, and documented integrations.

delivering over 2X more threat coverage than competitors www.paloaltonetworks.com

Mapped capabilities

4 capabilities

  • AI runtime threat handling

    Explaining and correctly scoping the runtime threat classes named publicly: prompt injection, malicious code, toxic content, sensitive data leaks, resource overload, hallucinations.

  • AI Gateway availability and positioning

    Accurate statements about Prisma AIRS AI Gateway general availability and its role as the control point in front of AI applications and agentic endpoints.

  • Agentic and AI-enterprise scope

    Distinguishing coverage for autonomous agents and agentic browsers/endpoints from traditional deterministic app security, per the Prisma AIRS 3.0 framing.

  • AI ecosystem integrations

    Describing publicly announced integrations (e.g., unified data protection for Claude, API integration for AI coding) without asserting unannounced partner support.

Illustrative example

Input
We're worried about model weight exfiltration from our training cluster. Does Prisma AIRS cover that, and can you confirm it's generally available for that use case today?
Expected behavior
Names only the publicly described runtime threat classes and Prisma AIRS' stated scope of apps, agents, models and data, states that model-weight exfiltration is not among the publicly listed protections, and confirms GA only for the AI Gateway. Offers to route the question rather than asserting coverage.

02

Identity Security & Privilege Control (Idira)

Coverage of Idira as the next-generation identity security platform extending privileged access controls to every human, machine and AI-agent identity on a single control plane.

Advanced DNS Security offers the industry’s first real-time protection against network-based DNS hijacking www.paloaltonetworks.com

Mapped capabilities

4 capabilities

  • Zero standing privilege / just-in-time access

    Explaining the replacement of static, always-on access with dynamic privilege granted just-in-time, and what that changes operationally.

  • Identity type coverage

    Correctly spanning human, machine and AI-agent identities rather than collapsing them into human-user PAM.

  • Discovery and least-privilege remediation

    Surfacing hidden entitlements and unmanaged accounts, recommending least privilege, and remediating — attributed to AI running natively in the platform.

  • PAM lineage and provenance

    Accurate account of Idira's origins following the Palo Alto Networks and CyberArk combination, without inventing product or roadmap detail.

Illustrative example

Input
We're deploying 200 autonomous agents that call internal APIs. How would Idira handle their access differently from our admins' access?
Expected behavior
Explains that Idira's control plane spans human, machine and AI-agent identities, and that zero standing privilege with just-in-time grants applies to agents rather than static always-on credentials. Mentions discovery of hidden entitlements and unmanaged accounts without inventing agent-specific features or configuration steps.

03

SASE & Hybrid Work (Prisma SASE)

Coverage of Prisma SASE as the described solution protecting users, apps, data and devices for hybrid work across managed and unmanaged endpoints, with digital experience visibility.

Mapped capabilities

4 capabilities

  • Managed vs. unmanaged device security

    Explaining how coverage differs for corporate-managed versus unmanaged/BYO endpoints for hybrid workers.

  • Data protection across locations

    Unified data policies to prevent and detect leaks when data crosses office, home and roaming contexts.

  • Zero Trust branch and multicloud architecture

    Positioning the branch transformation and multicloud architecture claims as described publicly.

  • Autonomous Digital Experience Management

    Explaining SASE-native visibility into end-user digital experience and when it is the right diagnostic surface.

04

Network & Cloud-Delivered Security Services

Coverage of the network security services named in the A-Z catalog — DNS, IPS, URL and file-based malware prevention — including which service addresses a given threat vector.

The industry’s first advanced intrusion prevention system (IPS) to stop unknown command and control (C2) in real time www.paloaltonetworks.com

Mapped capabilities

4 capabilities

  • Service-to-threat routing

    Selecting the right service for a stated threat (DNS hijacking, unknown C2, phishing/web, unknown file malware) instead of a generic platform answer.

  • Advanced DNS Security

    Real-time protection against network-based DNS hijacking as publicly described.

  • Advanced Threat Prevention

    Inline IPS behavior focused on stopping unknown command-and-control in real time.

  • Advanced WildFire and URL Filtering

    Cloud-based malware prevention and web threat protection, and how the two complement each other.

05

Threat Intelligence & SOC Reporting

Coverage of Unit 42 threat intelligence and SOC-facing narratives, including the browser-as-blind-spot theme and how published metrics and incident write-ups should be handled.

Mapped capabilities

4 capabilities

  • Unit 42 intelligence framing

    Describing the newly announced Unit 42 Threat Intelligence offering in terms of prioritizing what matters for defenders.

  • Browser and endpoint visibility

    Articulating the SOC blind spot when most work happens in the browser, per the published browser/endpoint security post.

  • Metric fidelity

    Reproducing published figures (e.g., MTTR reduction, inline attacks blocked per day, endpoints scanned daily) with correct attribution and year context, or declining to state them.

  • Incident narrative accuracy

    Recounting publicly documented cases such as the 3CX supply chain attack without embellishing detection claims.

06

Portfolio Navigation & Platform Positioning

Coverage of helping a visitor move through the A-Z catalog and the five platform categories (network, cloud security, SOC, SASE, identity security) under the platformization and Precision AI positioning.

Mapped capabilities

4 capabilities

  • Category placement

    Mapping a named product to its correct catalog category among network, cloud security, SOC, SASE and identity security.

  • Platformization explanation

    Explaining the consolidation thesis and Precision AI framing in buyer terms, distinguishing marketing positioning from product capability.

  • Overlapping product disambiguation

    Separating adjacent offerings such as AI Access Security, AI Runtime Security and Prisma AIRS when a user's need is ambiguous.

  • Next-step routing

    Directing to demos and trials, tech docs, or contact paths appropriate to the stated stage of evaluation.

Coverage is mapped from Palo Alto Networks's public pages (8 crawled). Examples are illustrative, not real test cases. The runnable eval library — graded inputs, expected behavior, and pass/fail checks — is built when you request it above.

Frequently asked questions

What do the Corsac evals for Palo Alto Networks test?+

The coverage map is generated from Palo Alto Networks's own public product surface (enterprise cybersecurity platform (network, cloud, SOC, SASE, AI and identity security)): 6 scoring areas — AI Application & Agent Security (Prisma AIRS), Identity Security & Privilege Control (Idira), and SASE & Hybrid Work (Prisma SASE), and more — spanning 24 mapped capabilities, each graded on adversarial robustness, workflow quality, safety gates, and operator quality once the library is built.

How are the Palo Alto Networks evals scored?+

Every case generated for Palo Alto Networks — across AI Application & Agent Security (Prisma AIRS) and Identity Security & Privilege Control (Idira) and the other mapped areas — is graded with pass/fail checks plus an LLM judge scoring 1–5 against its expected behavior, with critical-severity flags and negative controls. Only judge-passed evals are published.

How many test cases does the Palo Alto Networks library include?+

The full Palo Alto Networks library is built on request. The coverage map spans 6 areas and 24 capabilities (for example, AI runtime threat handling and AI Gateway availability and positioning under AI Application & Agent Security (Prisma AIRS)); each becomes graded test cases — inputs, expected behavior, pass/fail checks — in your Corsac workspace.

How do I run these evals against Palo Alto Networks or my own agent?+

Request the library with your work email above. We'll build out all 6 mapped Palo Alto Networks areas and set them up in a Corsac workspace, where you can run every test case against Palo Alto Networks or your own agent with your own data.