Documentation — August 07, 2026
2712 files changed, 181439 insertions, 1 deletions — view the commit on the mirror.
Initial import: 2,711 pages across eight books seeded from the Cortex documentation portal
- This is the mirror’s first export, not a day of change: 2,711 of the 2,712 files are additions and the one modification is the generated
README.md. - Eight books were seeded — the largest by far is the Cortex XSIAM Documentation at 2,271 pages.
- Within XSIAM, Configure Cortex XSIAM accounts for 1,224 pages and Detect, Investigate, and Respond to Threats for another 408.
- Nothing here should be read as an upstream edit; the first meaningful docs diff is the following day.
Highlights
-
The mirror starts from a snapshot, so every page reads as new
There is no prior state to diff against, so no page on this date was actually added, removed or changed upstream.
-
Eight books were captured, each at its portal path under a book-named directory
Cortex XSIAM Documentation (2,271), Cortex XQL Command Reference (184), Linux Kernel Versions (100), Cortex XSIAM Developer Guide (84), Cortex XDR Agent Administrator Guide (35), Cortex XDR Compatibility Matrix (15), Cortex XQL Schema Reference (10) and Cortex XDR Agent Releases (4).
-
The Cortex XDR Agent Administrator Guide was pinned at version 9.3
Its 35 pages came from the cortex-xdr-agent/9.3 portal section, the only book seeded from a version-specific section.
-
Navigation trees were recorded alongside the pages
Eight `.meta/<book>.json` manifests capture each book's navigation and the portal section it was collapsed from, which is what later diffs use to detect added, removed or reordered pages.
Bulk change — 2,712 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
2712 files listed, 1 written up and shaded below.
-
▸ ▾ Access to widgets added +8 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgetsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Sharing icons added +9 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-iconsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Visibility settings added +13 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settingsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Advanced configuration added +3 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configurationRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure drilldowns added +133 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-drilldownsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure global filters added +73 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-global-filtersRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create custom widgets added +13 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgetsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Add parameters to a custom XQL widget added +34 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widgetRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create script-based widgets added +179 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgetsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create widgets using AI added +42 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-aiRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create XQL widgets added +61 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgetsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create dashboards added +22 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboardsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create a dashboard added +87 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards/create-a-dashboardRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create reports added +20 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reportsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create a report template from scratch added +80 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports/create-a-report-template-from-scratchRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Dashboard reference added +3 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-referenceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Command Center reference added +11 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-referenceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cloud Detection and Response (CDR) Command Center added +15 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cloud-detection-and-response-cdr-command-centerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cortex Agentic Assistant dashboard added +17 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-agentic-assistant-dashboardRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cortex Cloud Command Center added +38 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-cloud-command-centerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cortex Command Center added +42 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-command-centerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ XSIAM Command Center added +18 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-centerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cases Overview added +7 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/cases-overviewRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Data Inventory added +7 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/data-inventoryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Dynamic View added +7 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/dynamic-viewRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ System dashboards added +7 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboardsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cloud Security Operations added +44 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cloud-security-operationsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cortex Cloud Consumption added +68 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cortex-cloud-consumptionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Manage dashboards and reports added +4 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reportsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Change ownership to dashboards and report templates added +27 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templatesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure the notification rule for a failed report added +10 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-reportRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Dashboard Manager added +18 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/dashboard-managerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Deleted content added +11 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/deleted-contentRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Duplicate dashboards and reports added +8 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reportsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Import and export dashboards and report templates added +34 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templatesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Reports added +25 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/reportsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Share custom dashboards and report templates added +28 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templatesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Overview of dashboards and reports added +5 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reportsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Dashboard interface basics added +20 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basicsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Dashboard types added +17 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-typesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Report basics added +7 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/report-basicsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Widget Library added +9 −0
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/widget-libraryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Threat management added +13 −0
xsiam/detect-investigate-and-respond-to-threats/threat-managementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Analytics added +2 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analyticsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Analytics overview added +7 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overviewRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AI Detection & Response in Cortex XSIAM added +9 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-betaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Collect prompt logs added +10 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Enable prompt log collection in Azure added +8 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure diagnostic settings added +8 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settingsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure the Azure Event Hub collection in Cortex XSIAM added +3 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-xsiamRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Log HTTP data added +20 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-dataRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Set up prompt logging added +5 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-loggingRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Prompt log collection in AWS added +11 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-awsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Data sources and supported services added +11 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/data-sources-and-supported-servicesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Analytics detection time intervals added +18 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-detection-time-intervalsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Analytics engine added +13 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-engineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Analytics issues and Analytics BIOCs added +7 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-issues-and-analytics-biocsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Analytics sensors added +17 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-sensorsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Coverage of MITRE Attack tactics added +18 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/coverage-of-mitre-attack-tacticsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Identity Analytics added +12 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/identity-analyticsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Review MITRE ATT&CK framework coverage added +17 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/review-mitre-att-and-ck-framework-coverageRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ View and manage Analytics rules added +78 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/view-and-manage-analytics-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Detection rules added +3 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ What are detection rules? added +9 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Manage IOC and BIOC rules added +110 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/manage-ioc-and-bioc-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ What's a BIOC? added +9 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-biocRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ BIOC rule details added +61 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/bioc-rule-detailsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create a BIOC rule added +215 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/create-a-bioc-ruleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Manage Global BIOC Rules added +43 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/manage-global-bioc-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ What's a correlation rule? added +12 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-ruleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Correlation rule details added +62 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/correlation-rule-detailsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create a correlation rule added +213 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/create-a-correlation-ruleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Field replacement syntax in correlation rules added +82 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Manage correlation rules added +27 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/manage-correlation-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Monitor correlation rules added +53 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/monitor-correlation-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Troubleshoot server errors in scheduled correlation rules added +80 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ What's an IOC? added +22 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-iocRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create an IOC rule added +65 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/create-an-ioc-ruleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ IOC rule details added +26 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/ioc-rule-detailsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Extended Threat Intelligence added +72 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligenceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Threat intel context in cases and issues added +195 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issuesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Threat Intel Dashboard added +39 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-dashboardRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Threat intel investigation through XQL added +37 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-investigation-through-xqlRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Using XTI in playbooks added +26 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-in-playbooksRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Using XTI with Threat Intel Agent added +34 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-with-threat-intel-agentRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ XTI indicator rules added +89 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicator-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ XTI Indicators added +144 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicatorsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ XTI Threat Intel Library added +112 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-threat-intel-libraryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Threat Intel Management added +17 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-managementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Get started with Threat Intel Management added +20 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-managementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Indicator concepts added +68 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/indicator-conceptsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Indicator lifecycle added +23 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Roles and responsibilities in Threat Intel Management added +14 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-managementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Threat Intel Management use cases added +93 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-casesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ What is Threat Intel Management? added +58 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-managementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Indicator configuration added +9 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configurationRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure Threat Intelligence feed integrations added +41 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/configure-threat-intelligence-feed-integrations-1Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure Threat Intelligence feed integrations added +39 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/configure-threat-intelligence-feed-integrationsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Customize indicator fields and types added +18 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-typesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Create an indicator field added +63 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-fieldRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.