< Back to all clusters
[TECHNOLOGY] · 4 sources

Palo Alto Networks promotes LLM use for endpoint security and threat detection

Palo Alto Networks is advocating the use of large language models (LLMs) to analyse massive amounts of endpoint data collected by its XDR platform. CEO Nikesh Arora said the company gathers the industry’s largest endpoint telemetry set and aims to fine‑tune LLMs to uncover new attack patterns and correlations.

Separately, a security researcher reported building a deterministic prompt‑injection detector that relies on regex and traditional machine‑learning (TF‑IDF n‑grams with logistic regression) instead of an LLM. The model achieves high recall and precision on real‑world jailbreaks and obfuscated attacks but struggles with subtle role‑play‑framed prompts, highlighting a gap in current defenses. The researcher emphasises that a cheap, fast, deterministic first‑line filter can reduce latency, cost and non‑determinism compared with inline LLM‑based detection.

Entities: Endpoint Detection and Response (XDR) · Nikesh Arora · Palo Alto Networks · Prompt Injection Detector · large language models