---
title: "Introduction"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDICortexXSOAR/1812858545/Introduction"
format: markdown
---
# Overview

The *Infoblox Threat Defense with DDI* integration for **PAN Cortex XSOAR** enables security teams to enhance visibility, automate incident response, and strengthen DNS-based security enforcement.  
It connects Infoblox Threat Defense with Cortex XSOAR, transforming network data into actionable threat intelligence.

# The Challenge: Too Many Threats, Too Little Context

Security teams often find themselves drowning in alerts with limited visibility into *what’s really happening* at the network level.  
While firewalls and endpoint tools catch what they see, most attacks start much earlier — **at the DNS layer**.  
Without DNS visibility and automation, threats like phishing, C2 communications, and data exfiltration can slip through undetected.

That’s where this integration comes in — to **turn DNS into a proactive defense layer**.

# The Solution: Infoblox + Cortex XSOAR

The **Infoblox Threat Defense with DDI integration for PAN Cortex XSOAR** bridges DNS intelligence with automated response.  
It transforms DNS — one of the most fundamental network services — into a **security control point**.

Once deployed, this integration:

- **Detects and blocks** malicious domains and IPs directly through Infoblox Threat Defense.
- **Shares threat intelligence** bi-directionally with Cortex XSOAR for correlation and automation.
- **Automates incident response** — letting playbooks block, unblock, or enrich indicators without manual effort.
- **Provides context-rich visibility** into every DNS event, enabling faster, more confident investigations.

# The Outcome: Smarter, Faster, DNS-Driven Security

By combining Infoblox’s authoritative DNS data with Cortex XSOAR’s orchestration power, organizations can:

- Detect threats at the earliest stage — **before** they impact endpoints.
- Enrich and prioritize incidents using **real network intelligence**.
- Automate repetitive response actions and reduce mean time to respond (MTTR).

In short, this integration helps SOC teams **see more, act faster, and secure better — starting right at the DNS layer.**

# Supported Platforms

- Cortex XSOAR
- Infoblox Threat Defense