> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management.md).

# Threat Management

- [Extended Threat Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence.md): Research threats, investigate indicators, and apply intelligence across Cortex Cloud Runtime Security workflows.
- [XTI Threat Intel Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/xti-threat-intel-library.md): Research curated threat actors, malware families, vulnerabilities, and reports from Unit 42.
- [XTI Indicators](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/xti-indicators.md): Investigate, manage, and enrich threat indicators, including domains, IP addresses, URLs, and file hashes.
- [Threat intel context in cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md): Analyze indicator intelligence and Behavioral Threat Analysis (BTA) findings in cases and issues.
- [XTI indicator rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/xti-indicator-rules.md): Create rules that detect known threat indicators and generate issues from matching data.
- [Threat intel investigation through XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/threat-intel-investigation-through-xql.md): Query XTI indicators, threat objects, and their relationships using Cortex Query Language.
- [Threat Intel Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/threat-intel-dashboard.md): Visualize threat intelligence data to monitor distribution, ingestion health, and emerging trends.
- [Using XTI with Threat Intel Agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/using-xti-with-threat-intel-agent.md): Use the Threat Intel Agent to list, enrich, and update XTI indicators.
- [Using XTI in playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/using-xti-in-playbooks.md): Automate XTI indicator triage, enrichment, and response with supported playbook commands.
- [Detection rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules.md): Learn about IOC, BIOC, and correlation rules for detecting threats and generating issues.
- [What are detection rules?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules.md): Understand detection rule types that identify threats and generate issues in Cortex Cloud.
- [What's an IOC?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc.md): Learn how IOC rules detect known malicious or suspicious artifacts in your environment.
- [IOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/ioc-rule-details.md): Review IOC rule fields, match status, and issue-generation details.
- [Create an IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/create-an-ioc-rule.md): Create an IOC rule to detect known malicious or suspicious artifacts.
- [What's a BIOC?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc.md): Learn how BIOC rules detect suspicious behavior across endpoint and network activity.
- [BIOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/bioc-rule-details.md): Review BIOC rule fields, exceptions, and status for user-defined and global rules.
- [Create a BIOC rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/create-a-bioc-rule.md): Create a BIOC rule to detect suspicious behavior in your environment.
- [Manage Global BIOC Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/manage-global-bioc-rules.md): View and manage Palo Alto Networks global BIOC rules in your tenant.
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule.md): Learn how correlation rules use XQL to identify relationships across security events.
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/correlation-rule-details.md): Review correlation rule fields, schedules, errors, and XQL query settings.
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/create-a-correlation-rule.md): Create a correlation rule using XQL to identify related security events.
- [Field replacement syntax in correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rules.md): Use field replacement syntax to insert event values into correlation rule results.
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/manage-correlation-rules.md): View, edit, enable, disable, import, export, and delete correlation rules.
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/monitor-correlation-rules.md): Monitor correlation rule executions, issues, and processing status.
- [Troubleshoot server errors in scheduled correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rules.md): Resolve server errors that affect scheduled correlation rule execution.
- [Manage IOC and BIOC rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/manage-ioc-and-bioc-rules.md): View, edit, enable, disable, and delete IOC and BIOC rules.
- [Analytics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics.md): Learn how Analytics detects anomalous activity and generates security issues.
- [Analytics overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-overview.md): Cortex Cloud uses an Analytics engine to examine logs and data from your sensors.
- [Analytics engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-engine.md): Learn how the Analytics engine builds behavior baselines and detects anomalies.
- [Analytics sensors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-sensors.md): Review the sensors and data sources that provide Analytics detection data.
- [Coverage of MITRE Attack tactics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/coverage-of-mitre-attack-tactics.md): Explore the MITRE ATT\&CK tactics that Analytics can detect.
- [Review MITRE ATT\&CK framework coverage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/review-mitre-att-and-ck-framework-coverage.md): Review Cortex Cloud detection coverage across the MITRE ATT\&CK framework.
- [Analytics detection time intervals](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-detection-time-intervals.md): Understand detector time intervals used to baseline and identify suspicious activity.
- [Analytics issues and Analytics BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-issues-and-analytics-biocs.md): Learn how Analytics issues and BIOCs identify anomalous and suspicious activity.
- [View and manage Analytics rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/view-and-manage-analytics-rules.md): View, filter, and manage XDR Analytics and Analytics BIOC rules.
- [Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/identity-analytics.md): Investigate suspicious user activity with Identity Analytics profiles, issues, and BIOCs.
- [AI Detection & Response in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud.md): Detect, investigate, and respond to AI-specific security threats in Cortex Cloud.
- [Data sources and supported services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/data-sources-and-supported-services.md): Review data sources and AI services supported by AI Detection & Response.
- [Collect prompt logs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs.md): Collect prompt logs to detect and investigate AI-related security threats.
- [Prompt log collection in AWS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/prompt-log-collection-in-aws.md): Configure prompt log collection for supported AWS AI services.
- [Enable prompt log collection in Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure.md): Enable prompt log collection from supported Azure AI services.
- [Configure the Azure Event Hub collection in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-cloud.md): Configure Azure Event Hub collection for AI Detection & Response prompt logs.
- [Set up prompt logging](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-logging.md): Set up Azure AI service prompt logging for AI Detection & Response.
- [Log HTTP data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-data.md): Configure HTTP data logging for Azure prompt log collection.
- [Configure diagnostic settings:](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settings.md): Configure Azure diagnostic settings to send prompt logs to Event Hub.
- [Identity Threat Detection and Response (ITDR)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr.md): Detect identity threats, manage posture, and enforce directory protections.
- [Get started with ITDR](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/get-started-with-itdr.md): Activate ITDR and configure Identity Profiles for Domain Controller protection.
- [Manage role based access control (RBAC) in ITDR](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/manage-role-based-access-control-rbac-in-itdr.md): Assign ITDR permissions for Conditional Access and Identity Security Runtime features.
- [Monitor user risk exposure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/monitor-user-risk-exposure.md): Use the Risk Management dashboard to assess identity threat exposure.
- [Investigate user risk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/investigate-user-risk.md): Investigate user identity activity, risk scores, and related security issues.
- [Manage user asset roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/asset-roles.md): Classify users into asset roles and fine-tune role memberships.
- [Improve Active Directory posture with AD-SPM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/active-directory-security-posture-management.md): Detect Active Directory misconfigurations and remediate identity security risks.
- [Enforce dynamic access control with CAP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/conditional-access-policy.md): Create risk-based access rules that allow, block, or require MFA.
- [Prevent malicious LDAP queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/prevent-malicious-ldap-queries.md): Detect and block LDAP reconnaissance against Active Directory domain controllers.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
