Navigate the Cortex XSIAM docs

Cortex XSIAM unifies detection, investigation, response, endpoint security, and cloud security in one platform.

Use this page to jump into the right docs area fast.

Use the table of contents when you know the exact page.

Use this page when you need a quick overview of the main Cortex XSIAM areas.

Learn the product

:circle-info: Product overview

Learn about the basics and architecture.

get-started-cortex-xsiam

:wand-magic-sparkles: Agentic AI

Explore AI-powered investigation, response, and workflows.

agentic-ai-in-cortex-xsiam

:id-card: Licensing

Review plans, add-ons, and retention.

cortex-xsiam-product-licenses

:desktop: Interface

Navigate pages, filters, views, and exports.

use-the-interface

Onboard Cortex XSIAM

:list-check: Plan and prepare

Consider storage, region, XDR agent, and data sources requirements.

plan-and-prepare

:clipboard-list: Deployment checklist

Follow the key steps to deploy and onboard.

cortex-xsiam-onboarding-checklist

:check-double: Post-deployment

Validate your deployment and complete initial tasks.

post-deployment

:plug: Cortex XSIAM Data Sources

Connect data sources, including CSP, and Cloud Posture and Runtime Security data sources.

cortex-xsiam-data-sources

:chart-line: Analytics

Set up analytics and enable the analytics engine.

cortex-xsiam-analytics

Configure Cortex XSIAM

:database: Data management

Manage ingestion, retention, and data access.

data-management

:robot: Configure the Cortex Agentic Assistant

Set up assistant access and capabilities.

configure-the-cortex-agentic-assistant-1

:server: Cortex MCP server

Connect external AI clients through the MCP server.

cortex-mcp-server

:bolt: Automations

Automate recurring security tasks and responses.

automations

:folder-tree: Customize cases and issues

Tailor case and issue workflows to your needs.

customize-cases-and-issues

:building: Multi-Tenant

Manage tenants and their security operations.

multi-tenant

:handshake: Managed Services configuration in Cortex

Configure services for managed security operations.

managed-services-configuration-in-cortex

Protect your environment

:shield-halved: Endpoint security

Prevent, detect, and respond to endpoint threats.

endpoint-security

:lock: Endpoint DLP

Protect sensitive data on managed endpoints.

endpoint-dlp

Detect, investigate, and respond

:chart-line: Monitor dashboards and reports

Track security operations, trends, and outcomes.

monitor-dashboards-and-reports

:magnifying-glass: Investigation and response

Investigate cases/issues and respond to threats.

investigation-and-response

:comments: Agentic Assistant chat

Use natural language to investigate security data.

agentic-assistant-chat

:boxes-stacked: Asset management

Inventory and monitor assets across your environment.

asset-management

:crosshairs: Threats

Prioritize and manage threats affecting your organization.

threat-management

:globe: Attack Surface Management

Discover and assess internet-facing attack surface risks.

attack-surface-management

:bug: Vulnerability management

Identify, prioritize, and remediate vulnerabilities.

vulnerability-management

:radar: Exposure management

Understand and reduce your overall cyber exposure.

exposure-management

Cloud Security

:database: Data Security

Discover and protect sensitive cloud data.

cortex-data-security

:scale-balanced: Monitor and track compliance adherence

Measure cloud compliance against supported standards.

monitor-and-track-compliance-adherence

:shield: Cloud Security Rules and Policies

Configure policies and rules for cloud protection.

cloud-security-rules-and-policies

:tags: Cloud Data Classification

Classify cloud data using sensitive data profiles.

cortex-cloud-data-classification

:user-shield: Cloud Identity Security

Secure cloud identities and their permissions.

cortex-cloud-identity-security

:network-wired: Network exposure detection

Identify cloud network paths that create exposure.

network-exposure-detection

:brain: Cloud AI Security

Secure AI services and workloads in the cloud.

cortex-cloud-ai-security

:bolt: Serverless function posture security

Assess configuration risks in serverless functions.

serverless-function-posture-security

:code: Cloud Application Security

Protect cloud-native applications across their lifecycle.

cortex-cloud-application-security

:cloud: Cloud workload policies and rules

Define controls for cloud workloads and resources.

cloud-workload-policies-and-rules

:globe: Web and API Security (WAAS)

Protect web applications and APIs from attacks.

overview

:play: Serverless function runtime security

Detect runtime threats in serverless functions.

overview-1

:envelope-open-text: Cortex Advanced Email Security

Protect users from email-based threats.

cortex-advanced-email-security

Reference and developer docs

:terminal: XQL

Query and analyze security data with XQL.

cortex-agentix-xql

:share-nodes: Graph Search

Explore relationships between entities and events.

graph-search

:terminal: Cortex CLI

Manage Cortex XSIAM from the command line.

about-cortex-cli

:user-lock: Role-Based Access Control

Control access with roles and permissions.

role-based-access-control

:code: API documentation

Integrate Cortex XSIAM with its public APIs.

api-documentation