PAN-OS 12.2 Ceres: what it covers and what it does not
Published August 19, 2026 · North Star Labs · 11 pages
What is inside
The brief explains how the prevention loop behind Ceres actually works, what it genuinely improves, where its coverage ends, and what that costs the teams who have to operate it. Sections five and six cover how CyPhER closes the gap without replacing anything you already run.
- 01How the new PAN Ceres architecture works
- 02What PAN Ceres buys you
- 03Where it stops
- 04What those limits cost you
- 05How North Star Labs closes the gap
- 06Why this is possible now
- 07What to ask before you sign
Get the analysis
Three fields and the download appears immediately.

Learn more about CyPhER and make your data AI-ready
Book a meetingAbout North Star Labs
North Star Labs provides deterministic network telemetry for defense and critical infrastructure. CyPhER gives teams a complete, tamper-resistant record of network activity, so they can prove what their prevention stack covers and investigate what it does not.
Frequently asked questions
Does PAN-OS 12.2 Ceres cover east-west traffic?
Not directly. Ceres protections attach to zone boundaries, so they evaluate traffic crossing between segments and do not observe communication between two machines inside the same segment. Lateral movement within a segment produces no record at the enforcement layer.
What are the limitations of Advanced Virtual Patching?
Advanced Virtual Patching protects a vulnerable system only when traffic to that system crosses a device carrying the protection. It also cannot be independently examined, because the protections are deliberately built so attackers cannot reverse engineer them, which means an assessor cannot document the control logic either.
Why does Advanced IP Defense generate false positives in OT environments?
Industrial equipment routinely connects to numeric addresses without a preceding name lookup. Controllers, historians, and engineering workstations were not designed to use DNS, so a control treating missing resolution provenance as suspicious will fire continuously against normal plant behavior.
How do you audit autonomous network security agents?
You need an independent record of network state before and after the agent acted. Agents operating without human review produce consequences that have to be reconstructable, and a platform cannot serve as the impartial record of its own automated actions.
Does CyPhER replace Palo Alto Networks firewalls?
No. CyPhER is passive and does not enforce policy. It observes and records network activity beneath the enforcement layer, including segments where no firewall is deployed, so security teams can verify what their enforcement controls actually cover.
What is deterministic network telemetry?
Deterministic telemetry means the same network activity always produces the same record, with no sampling and no inference in between. It matters because a sampled or summarized record cannot answer questions that were not anticipated when the sampling rules were written.
How does CyPhER reduce alert volume?
By resolving alerts against a record of what actually happened rather than correlating alerts with other alerts. Working with the US Air Force, North Star Labs reduced 2.5 million alerts from existing security tools to five findings in under twenty minutes.
Who publishes this analysis?
North Star Labs, a defense cybersecurity company headquartered in Alexandria, Virginia. The analysis is independent and North Star Labs is not affiliated with Palo Alto Networks.
How the PAN-OS 12.2 Ceres architecture actually works
Ceres runs on a closed loop. Firewalls sit at the boundaries between network zones and inspect the traffic that crosses them. For every connection, the firewall writes a record of what the traffic was and what it decided to do about it. Those records travel to Palo Alto’s cloud, where they are pooled across a customer base the company describes as more than seventy thousand organizations, and researchers and models work across that pool to identify attacker infrastructure and emerging vulnerabilities. New protections then return to the fleet as routine content updates.
Three flagship capabilities draw on that loop. Advanced Virtual Patching pushes a protection to the firewall before a software vendor has published a fix, using an engine built so the protection cannot be reverse engineered by attackers. Advanced IP Defense targets malware that connects directly to numeric addresses to avoid the name lookups most security tools monitor. A set of Network Security Agents in Strata Cloud Manager automates routine administration and proposes remediation, with a per-workflow choice of how much human review is required.
What PAN-OS Ceres genuinely improves
The speed advantage is real. Enterprise teams average well over fifty days to remediate a vulnerability after a vendor publishes a fix, and vendors themselves often take one to three months to publish. A protection arriving in hours changes the shape of that exposure, and adopting it does not require a hardware project.
The pooled intelligence is real as well. An organization running Ceres benefits from attacks aimed at companies it will never meet. The browser integration is the strongest visibility gain in the release, because inspecting web activity inside the browser gives application-level detail on encrypted traffic without a decryption proxy, which nothing watching the network from outside can offer.
Where enforcement coverage ends
Everything in the loop depends on traffic crossing a firewall, and most network traffic does not. Protections attach to the boundaries between zones, so they evaluate what moves across those boundaries and never observe two machines on the same segment communicating with each other. An attacker already inside and moving laterally operates in the space between enforcement points, producing no record, triggering no protection, and teaching the intelligence loop nothing.
The records that do reach the cloud are conclusions rather than observations. A connection record states what the firewall classified the traffic as and what it decided to do. If the classifier found nothing interesting, that is what gets stored, and nothing in the loop can later revisit the underlying activity to ask a different question.
Coverage also grows only by deploying more equipment. The ruggedized firewall for industrial sites, the browser component for user activity, and the service for AI workloads are each a real capability, and each is another product to buy, install, and operate in another location.
What those coverage limits cost security teams
Four consequences follow, and each is a question a security team will be asked and will not be able to answer from the platform alone.
You cannot verify that a protection covers what you think it covers
When a virtual patch lands for a serious vulnerability, the questions that matter are which systems actually run the affected service and whether every route to those systems passes a firewall carrying the protection. The loop only knows about traffic it already sees, so neither question can be answered from it.
Controls in industrial environments get quietly tuned off
Plant equipment connects to numeric addresses constantly. Controllers, historians, and engineering workstations were never designed to use name lookups, so a rule treating a missing lookup as suspicious fires against normal operations all day. The exception list widens quarter after quarter until the capability on the invoice and the capability in production have little to do with each other.
Investigations stop at the enforcement boundary
After an incident the question is always what else the intruder touched. A system that stored verdicts rather than activity cannot describe the connections it judged uninteresting at the time.
Accreditation and audit obligations are not satisfied by the platform alone
Protections deliberately built so attackers cannot examine them also cannot be examined by the people accountable for the system. An assessor cannot document a control whose logic is withheld, and continuous monitoring cannot rest on automated actions that leave no independent record of network state before and after they ran.
Where the savings actually come from
A coverage layer is additive spend and it does not lower a firewall bill. The savings appear in five places. Analyst time, because a team receiving a handful of findings rather than millions of alerts spends its hours on the findings. Retention, because compression removes the tradeoff between what a team can keep and what it can afford to keep. Avoided instrumentation, because organizations frequently deploy enforcement appliances at internal boundaries mainly to gain visibility there, and observing a segment costs considerably less than enforcing at it. Incident duration, which drives nearly every downstream cost of a breach. And agent consumption, since automated agents are metered and an agent handed a resolved set of findings reasons across a fraction of what a raw alert queue would require.
What CyPhER adds beneath the enforcement layer
CyPhER observes passively and records what actually occurred at Layers 2 through 4, across the segments where enforcement points are not deployed and where lateral traffic never reaches a perimeter. The record is deterministic rather than sampled, so it answers coverage questions directly. It does not sit in the path of traffic, it does not enforce anything, and it does not replace or compete with existing firewalls. It establishes what the enforcement layer was and was not in a position to see.
The full analysis, including diagrams and a buyer’s checklist, is available above.
PAN-OS, Prisma, and Strata are trademarks of Palo Alto Networks, Inc. North Star Labs is not affiliated with or endorsed by Palo Alto Networks. This analysis is based on publicly available vendor materials published August 2026.
Last updated August 19, 2026.
