> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/identity-threat-module.md).

# Identity Threat Module

The Identity Threat module provides superior coverage for stealthy identity threat vectors, including compromised accounts and insider threats. The module is available as an add-on and includes the following UI features.

* Automated and customizable [Asset Role](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles.md) classification based on constant analysis of the users and host in your network. You can edit and manage the [User Asset Roles](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-users.md) and [Host Asset Roles](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-endpoints.md) to meet the needs of your organization.
* The [Behavioral Analytics](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/alert-side-panel.md) tab in the Alert Panel view that displays background information for quicker triaging and investigation. This enables you to analyze the deviation that triggered the alert against the backdrop of baseline behavior.
* [Risk Management dashboard](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/predefined-dashboards.md) for reviewing the risk posture of the organization and enabling faster decision making. The dashboard contains a number of Metrics widgets that present statistical risk information for your organization.
* [User Risk View](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-user.md) and [Host Risk View](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-host.md) which provide additional information about the asset, including score trend timeline, notable events, peer comparison, and additional asset-associated alerts and insights for easy uncovering of hidden threats.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/identity-threat-module.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
