Navigate the Cortex XSIAM docs ↗
Cortex XSIAM unifies detection, investigation, response, endpoint security, and cloud security in one platform.
Use this page to jump into the right docs area fast.
Use the table of contents when you know the exact page.
Use this page when you need a quick overview of the main Cortex XSIAM areas.
Learn the product
:circle-info: Product overview Learn about the basics and architecture. | get-started-cortex-xsiam |
:wand-magic-sparkles: Agentic AI Explore AI-powered investigation, response, and workflows. | agentic-ai-in-cortex-xsiam |
:id-card: Licensing Review plans, add-ons, and retention. | cortex-xsiam-product-licenses |
:desktop: Interface Navigate pages, filters, views, and exports. | use-the-interface |
Onboard Cortex XSIAM
:list-check: Plan and prepare Consider storage, region, XDR agent, and data sources requirements. | plan-and-prepare |
:clipboard-list: Deployment checklist Follow the key steps to deploy and onboard. | cortex-xsiam-onboarding-checklist |
:check-double: Post-deployment Validate your deployment and complete initial tasks. | post-deployment |
:plug: Cortex XSIAM Data Sources Connect data sources, including CSP, and Cloud Posture and Runtime Security data sources. | cortex-xsiam-data-sources |
:chart-line: Analytics Set up analytics and enable the analytics engine. | cortex-xsiam-analytics |
Configure Cortex XSIAM
:database: Data management Manage ingestion, retention, and data access. | data-management |
:robot: Configure the Cortex Agentic Assistant Set up assistant access and capabilities. | configure-the-cortex-agentic-assistant-1 |
:server: Cortex MCP server Connect external AI clients through the MCP server. | cortex-mcp-server |
:bolt: Automations Automate recurring security tasks and responses. | automations |
:folder-tree: Customize cases and issues Tailor case and issue workflows to your needs. | customize-cases-and-issues |
:building: Multi-Tenant Manage tenants and their security operations. | multi-tenant |
:handshake: Managed Services configuration in Cortex Configure services for managed security operations. | managed-services-configuration-in-cortex |
Protect your environment
:shield-halved: Endpoint security Prevent, detect, and respond to endpoint threats. | endpoint-security |
:lock: Endpoint DLP Protect sensitive data on managed endpoints. | endpoint-dlp |
Detect, investigate, and respond
:chart-line: Monitor dashboards and reports Track security operations, trends, and outcomes. | monitor-dashboards-and-reports |
:magnifying-glass: Investigation and response Investigate cases/issues and respond to threats. | investigation-and-response |
:comments: Agentic Assistant chat Use natural language to investigate security data. | agentic-assistant-chat |
:boxes-stacked: Asset management Inventory and monitor assets across your environment. | asset-management |
:crosshairs: Threats Prioritize and manage threats affecting your organization. | threat-management |
:globe: Attack Surface Management Discover and assess internet-facing attack surface risks. | attack-surface-management |
:bug: Vulnerability management Identify, prioritize, and remediate vulnerabilities. | vulnerability-management |
:radar: Exposure management Understand and reduce your overall cyber exposure. | exposure-management |
Cloud Security
:database: Data Security Discover and protect sensitive cloud data. | cortex-data-security |
:scale-balanced: Monitor and track compliance adherence Measure cloud compliance against supported standards. | monitor-and-track-compliance-adherence |
:shield: Cloud Security Rules and Policies Configure policies and rules for cloud protection. | cloud-security-rules-and-policies |
:tags: Cloud Data Classification Classify cloud data using sensitive data profiles. | cortex-cloud-data-classification |
:user-shield: Cloud Identity Security Secure cloud identities and their permissions. | cortex-cloud-identity-security |
:network-wired: Network exposure detection Identify cloud network paths that create exposure. | network-exposure-detection |
:brain: Cloud AI Security Secure AI services and workloads in the cloud. | cortex-cloud-ai-security |
:bolt: Serverless function posture security Assess configuration risks in serverless functions. | serverless-function-posture-security |
:code: Cloud Application Security Protect cloud-native applications across their lifecycle. | cortex-cloud-application-security |
:cloud: Cloud workload policies and rules Define controls for cloud workloads and resources. | cloud-workload-policies-and-rules |
:globe: Web and API Security (WAAS) Protect web applications and APIs from attacks. | overview |
:play: Serverless function runtime security Detect runtime threats in serverless functions. | overview-1 |
:envelope-open-text: Cortex Advanced Email Security Protect users from email-based threats. | cortex-advanced-email-security |
Reference and developer docs
:terminal: XQL Query and analyze security data with XQL. | cortex-agentix-xql |
:share-nodes: Graph Search Explore relationships between entities and events. | graph-search |
:terminal: Cortex CLI Manage Cortex XSIAM from the command line. | about-cortex-cli |
:user-lock: Role-Based Access Control Control access with roles and permissions. | role-based-access-control |
:code: API documentation Integrate Cortex XSIAM with its public APIs. | api-documentation |