> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-inventory.md).

# Host Inventory

With Host Inventory, you gain full visibility and inventory into the business and IT operational data on all your endpoints. By reviewing the inventory for all your hosts in a single place, you can quickly identify IT and security issues that exist in your network, such as identifying a suspicious service or autorun that was added to an endpoint.

The Cortex XDR agent scans the endpoint every 24 hours for any updates and displays the data found over the last 30 days. Alternatively, you can rescan the endpoint to retrieve the most updated data. It can take Cortex XDR up to 6 hours to collect initial data from all endpoints in your network.

The following are prerequisites to enable Host Inventory for your Cortex XDR instance:

| Requirement           | Description                                                                                                                                                                                                                                                                          |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Licenses and Add-ons  | <ul><li>Cortex XDR Pro per Endpoint license.</li><li>Host Insights Add-on.</li></ul>                                                                                                                                                                                                 |
| Supported Platforms   | Windows, Mac, and Linux.                                                                                                                                                                                                                                                             |
| Setup and Permissions | Ensure [Host Inventory Data Collection](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md) is enabled for your Cortex XDR agent. |

The Cortex XDR Host Inventory includes the following entities and information, according to the operating system running on the endpoint:

| Entity             | Windows | Mac | Linux |
| ------------------ | ------- | --- | ----- |
| Accessibility      | –       | ✓   | –     |
| Applications       | ✓       | ✓   | ✓     |
| Autoruns           | ✓       | ✓   | ✓     |
| Daemons            | –       | ✓   | ✓     |
| Disks              | ✓       | ✓   | ✓     |
| Drivers            | ✓       | –   | ✓     |
| Extensions         | –       | ✓   | –     |
| Groups             | ✓       | ✓   | ✓     |
| Mounts             | –       | ✓   | ✓     |
| Services           | ✓       | –   | –     |
| Shares             | ✓       | ✓   | ✓     |
| System Information | ✓       | ✓   | ✓     |
| Users              | ✓       | ✓   | –     |
| Users to Groups    | ✓       | ✓   | ✓     |

For each entity, Cortex XDR lists all the details about the entity, and the details about the endpoint it applies to. For example, the default Services view lists a separate row for every service on every endpoint:

Alternatively, to better understand the overall presence of each entity on the total number of endpoints, you can switch to an aggregated view (click ![aggregate-icon.png](/files/CdsGGKyPs0LGxcuoBDWQ)) and group the data by the main entity. You can also sort and filter according to the number of affected endpoints. For example, in the Services aggregated view, you can sort by the number of affected endpoints to identify the least commonly deployed service in your network. To get a closer view of all endpoints, right-click and select **View affected endpoints**.

### View Host Inventory

To view the Host inventory, go to **Incident Response** → **Investigation** → **Host Inventory**. You can export the tables and respective asset views to a tab-separated values (TSV) file.

| Data               | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Accessibility      | Details about installed applications that require and were allowed special permissions to enable a camera, microphone, accessibility features, full disk access, or screen captures.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Applications       | <p>Details about all applications installed on your endpoints.</p><p>For each application, Cortex XDR lists the existing CVEs and the vulnerability severity score that reflects the highest NIST vulnerability score detected for the application.</p><p>To further examine these vulnerabilities, see <a href="/pages/Mry5lIK58O0KqWQ7nc58">Application Analysis</a>.</p>                                                                                                                                                                                                                                                                                                                                                     |
| Autoruns           | <p>Details about executables that start automatically when the user logs in or boots the endpoint.</p><p>Cortex XDR displays information about autoruns that are configured in the endpoint Registry, startup folders, scheduled tasks, services, drivers, daemons, extensions, Crond tasks, login items, login, and logout hooks.</p><p>For each autorun, Cortex XDR lists the autorun type and configuration, such as startup method, CMD, user details, and image path.</p>                                                                                                                                                                                                                                                  |
| Daemons            | <p>Details about all daemons that exist on the endpoint.</p><p>For each daemon, Cortex XDR lists the following details.</p><ul><li>Information about the daemon, such as the name, type, and path</li><li>Daemon state, indicating whether it is loaded, running, or not running</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Disks              | <p>Details about the disk volumes that exist on an endpoint.</p><p>For each disk that exists on an endpoint, Cortex XDR lists details such as the drive type, name, file system, free space, and total size.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Drivers            | <p>Details about all the drivers installed on an endpoint.</p><p>For each driver, Cortex XDR lists all the following details:</p><ul><li>Information about the driver, such as the driver name, type, and path.</li><li><p>Listing details about the driver runtime configuration:</p><ul><li>Driver type</li><li>Whether the driver is currently running, in which mode, and the runtime state</li></ul></li></ul>                                                                                                                                                                                                                                                                                                             |
| Extensions         | <p>Details about the system and kernel extensions currently running on your Mac endpoints.</p><p>For each extension, Cortex XDR lists the following details:</p><ul><li>Extension type, name, path, and version</li><li>Extension state, indicating whether it is running, requires enabling, or unloaded</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                             |
| Groups             | <p>Details about all user groups defined on an endpoint.</p><p>For each group, Cortex XDR lists identifying details, such as name, SID/GID name, and type.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Mounts             | <p>Details about all the drives, volumes, and disks that were mounted on endpoints.</p><p>For each mount, Cortex XDR lists the mount point directory, file system type, mount spec, and GUID.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Services           | <p>Details about all the services running on an endpoint.</p><p>For each service, Cortex XDR lists all the following details:</p><ul><li>Information about the service, such as the service name, type, and path</li><li><p>Listing details about the service runtime configuration and status:</p><ul><li>Whether the service is currently running and what is the runtime state</li><li>Whether you can stop, pause, or delay the service start time</li><li>Whether the service requires interaction with the endpoint desktop</li><li>The name of the user who started the service and the start mode</li></ul></li></ul>                                                                                                   |
| Shares             | <p>Details about network shared folders defined on an endpoint.</p><p>For each folder, Cortex XDR lists all the following details:</p><ul><li>Shared network folder type: Disk Drive, Print Queue, Device, IPC, Disk Drive Admin, Print Queue Admin, Device Admin, IPC Admin</li><li>Identifying details such as folder name, description, and path</li><li>Whether the folder is limited to a maximum number of shares, and the maximum number of allowed shares</li></ul>                                                                                                                                                                                                                                                     |
| System Information | <p>General system information about an endpoint.</p><p>For each endpoint, Cortex XDR lists all the following details:</p><ul><li>Information about the endpoint hardware, such as manufacturer, model, physical memory, processor architecture, and CPU</li><li>The operating system name and release running on the endpoint</li></ul>                                                                                                                                                                                                                                                                                                                                                                                         |
| Users              | <p>List of users whose credentials are stored on the endpoint.</p><p>For each user, Cortex XDR lists all the following details.</p><ul><li>Identifying details about the user, such as name and SID/UID</li><li>Details about the account, such as whether the account is active and the account type</li><li>Information about the password set for this user account, such as whether it is required to login, has an expiration date or can be changed</li></ul>                                                                                                                                                                                                                                                             |
| Users to Groups    | <p>A list mapping all the users, local and in your domain, to the existing user groups on an endpoint.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><ul><li>Cortex XDR includes only the first 10,000 results per endpoint.</li><li>Cortex XDR lists only users that belong to each group directly, and does not include users who belong to a group within the main group.</li><li>If a local users group includes a domain user (whose credentials are stored on the Domain Controller server and not on the endpoint), Cortex XDR includes this user in the user-to-group mapping, but does not include it in the user's insights view.</li></ul></div> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-inventory.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
