Detect, Investigate, and respond to threats
Sub-topics
- Monitor dashboards and reports
-
Investigation and response
- Overview of cases
- Case concepts
- Analyze and resolve cases
-
Investigate issues
- Overview of the Issues page
- Issue card
- Resolution actions
- Link or unlink issues from a case
- Run an automation on an issue
- Use the War Room in an investigation
- Use the Work Plan in an investigation
- Issue syncing
- Issue deduplication
- Causality view
-
Issue investigation actions
- Copy issues
- Analyze an issue
- Update issue fields
- Query case and issue data
- Exclude an issue
- Create a featured field
- Export issue details to a file
- Investigate contributing events
- Retrieve additional issue details
- View generating BIOC or IOC rule
- Create profile exceptions
- Add a file path to a malware profile allow list
- Close an issue
- Review findings
- Investigate artifacts and assets
- Investigate endpoints
- Investigate files
- Cortex Assistant
- Response actions
- Forensics
- Notebooks
- Build XQL queries
- Research a known threat
- Agentic Assistant chat
-
Asset management
- Asset inventory overview
- All assets
- All cloud assets
- Asset classes
- Asset groups
- Manage Risk Scores
- Asset configurations
- Vulnerability Assessment
- Query the asset inventory via XQL
-
Threat management
- Detection rules
- Analytics
- Extended Threat Intelligence
-
Threat Intel Management
- Get started with Threat Intel Management
-
Indicator configuration
- Configure Threat Intelligence feed integrations
- Customize indicator fields and types
- Indicator classification and mapping
- Indicator extraction
- Configure Threat Intelligence feed integrations
- Exclude indicators from enrichment
- Generate issues from indicators using indicator rules for prevention and detection
- Export indicators
- Indicator management
- Indicator investigation
- Attack surface management
- Vulnerability management
- Exposure management
-
Cortex Advanced Email Security
- Cortex Advanced Email Security module overview
- Cortex Advanced Email Security module architecture and data flow
- Getting started with the Cortex Advanced Email Security module
- Deploy and configure the Email Security module
- Cortex Advanced Email Security threat detection and issues
- Investigate and respond to email security issues
- Automate remediation for the Cortex Advanced Email Security module
- Email Command Center
- Malicious Email Inventory
- Mailbox Inventory
- Advanced Email Security module security and compliance
- Identity Threat Detection and Response (ITDR)