For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cortex Analytics Alert Reference

The Cortex Analytics Alert Reference describes every Analytics alert that Cortex can raise. Use this reference to understand what an alert means and what you should do about it.

How this reference is organized

  • Alerts by name — every Analytics alert, listed alphabetically. Each alert page covers its synopsis (activation, training, test, and deduplication periods, required data, detection modules, MITRE ATT&CK mapping, and severity), a description, the attacker's goals, and recommended investigative actions. Some alerts also document variations.

  • Alerts by data source — the same alerts, grouped by the data source that produces them.

The Analytics alerts that Cortex can raise depend on the data sources you integrate with Cortex. Some alerts require a combination of data sources, and you can improve the accuracy of some alerts by adding additional data sources.

Was this helpful?