For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Manage Asset Scores

Learn how to view and investigate User Scores and Host Scores using the Asset Scores page.

The Asset Scores page provides a central location from which you can view and investigate information relating to User Scores and Host Scores in your network.

Note

The Asset Scores page is available if the Identity Threat Module add-on is enabled.

Cortex XDR aggregates Workday and Active Directory data to create a list of user and host assets within your network. When alerts and incidents occur, they are associated with a host or user asset and Cortex XDR calculates a score that represents the risk level of each asset. This score helps to identify high-risk assets in your organization and detect compromised accounts and malicious activities.

To Include System Users in the table, select the Include System Users checkbox: system users are SYSTEM, administrators, NT authority, and others.

Note

As new alerts are associated with incidents, the User and Host Scores are recalculated. You can view the latest User and Host Scores on the Asset Scores page, or track the Score trend on the User Risk View and Host Risk View.

To investigate your users and hosts:

  1. Select Assets → Asset Scores. Use the toggle in the page header to switch between the Users and Hosts tabs.

  2. Filter and review your assets.

The fields in the Users tab
Field
Description

Starred

Whether the user is included in the watchlist.

Score

Represents the Cortex XDR high-risk user score. The score is updated continuously as new alerts are associated with incidents.

User name

Name of the user as provided by Cortex XDR.

Full name

Name of the user as provided by Workday or Active Directory.

Department

Department of the user as provided by Workday or Active Directory.

Email

Email of the user as provided by Workday or Active Directory.

Member of

(Derived from AD) The security groups that the user is associated with.

Featured

Whether the user is flagged as a featured user in the platform.

Location

Location of the user as provided by Workday or Active Directory.

Last login

Last date and time the user accessed Cortex XDR.

Asset role

Asset roles that the user is associated with.

The fields in the Hosts tab
Field
Description

Starred

Whether the host is included in the watchlist.

Hostname

Unique ID of the host.

Score

Host score.

IP

IP on which the endpoint is running.

Has XDR agent

Whether the endpoint has an XDR agent installed.

Users

Users assigned to the endpoint.

Agent installation date

Date and time that the XDR agent was installed.

Last communication

Date and time of last communication.

Operating system

Operating system with which the endpoint is running.

Endpoint isolated

Whether the endpoint is isolated.

Featured

Whether the host is flagged as a featured host in the platform.

Tags

Endpoint tags applied to the host.

Group names

User groups that the host is associated with.

Asset role

Asset roles that the host is associated with.

  1. To investigate further, right-click on a selected host or user and click Open User Risk View or Host Risk View. For more information, see Investigate a user and Investigate a host.

    Note

    Some User Associated Insights may not appear as part of the User Associated Incidents due to the insight generation mechanism. For example, when an insight related to one of the assets in an incident is generated a few days after the associated incident, the insight may not be associated with the incident.

Last updated

Was this helpful?