> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents.md).

# Manage incidents

On the **Incident** view you can track incidents, investigate incident details, and take remedial action. Navigate to Incident Response → **Incidents** and locate the incident you want to investigate.

{% hint style="info" %}

### Note

If you do not have permissions to access an asset of an incident (which is shown as grayed out and locked), check your scoping permissions in Manage Users or Manage User Groups.
{% endhint %}

<details>

<summary>Review incident list details</summary>

The incident list provide a short summary of each incident to help you to quickly assess and prioritize your incidents:

1. Review the incident severity, score, and assignee. Select whether to Star the incident.
2. Review the status of the incident and when it was last updated.
3. Review the incident ID and incident summary.
4. Review the incident assets and alert sources:
   * Review the host name associated with the incident. If there is more than one host, select the `[+x]` to display the additional host names.
   * Review the user name associated with the incident. If there is more than one user, select the `[+x]` to display the additional user names.
   * Hover over the alert source icons to display the alert source type. Select the alert source icon to display the three most common alerts that were triggered and how many alerts of each are associated with the incident.

</details>

<details>

<summary>Update incident details</summary>

Click on an incident to open the incident in the right panel. In the incident header you can update various data, such as the severity, incident name, score, and merge incidents.

1. Change the incident severity.

   The default severity is based on the highest alert in the incident. To manually change the severity select the severity tag and choose the new severity.
2. Add or edit the incident name.
3. Edit the incident description.

   Hover over the incident description and select the pencil icon to edit the incident description.
4. Update the incident score.

   Click on the assigned score to investigate how the score was calculated.

   In the **Manage Incident Score** dialog displays all rules that contributed to the incident total score, including rules that have been deleted. Deleted scores appear with a **N/A**.

   You can override the **Rule based score** by selecting **Set score manually** or change the scoring method. For more information, see [Incident scoring](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring/incident-scoring.md).
5. Assign an incident.

   Select the assignee (or **Unassigned**) and begin typing the assignee’s email address for automated suggestions. Users must have logged in to the app to appear in the auto-generated list.
6. Assign an incident status.

   Select the incident **Status** to update the status to either **New**, **Under Investigation**, or **Resolved**. By updating the status you can indicate which incidents have been reviewed and to filter by status in the incidents table.

   When setting an incident to **Resolved**, select the reason the resolution was resolved, add an optional comment, and select whether to **Mark all alerts as resolved**. For more information, see [Resolution reasons for incidents and alerts](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents/resolution-reasons-for-incidents-and-alerts.md).
7. Merge incidents you think belong together. Click the more options icon and select **Merge Incidents**.

   Incident assignees are managed as follows:

* If both incidents have been assigned, the merged incident takes the target incident assignee.
* If both incidents are unassigned, the merged incident remains unassigned.
* If the target incident is assigned and the source incident is unassigned, the merged incident takes the target assignee.
* If the target incident is unassigned and the source incident is assigned, the merged incident takes the existing assignee.
* In the merged incident, all source context data is lost even if the target incident does or doesn't contain context data. If the target incident contains context data, that context data is preserved in the merged incident.

8. Create an exclusion.
   1. Click the more options icon and select **Create Exclusion**.
   2. Enter a rule name and description.
   3. Filter the **Alerts** table to defined the alerts that you want to include in the policy.
   4. Select whether to apply the rule to existing alerts.
   5. Click **Create**.
9. Review the remediation suggestions. Click the more options icon to open the **Remediation Suggestions** dialog.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Notice</h3><p>Remediation suggestions require a Cortex XDR Pro license.</p></div>
10. Review the incident assets.

    Review the number of alerts, alert sources, hosts, users, and wildfire hits associated with the incident. Select **Hosts**, **Users**, and **Wildfire Hits** to display the asset details.
11. Track and share your investigation progress.

    Add notes or comments to track your investigative steps and any remedial actions taken.

    * Select the Incident Notepad (![incident-note-icon.png](/files/8JtFNOHnc1718wEBZOu2)) to add and edit the incident notes. You can use notes to add code snippets to the incident or add a general description of the threat.
    * Use the Incident Messenger (![incident-comment-icon.png](/files/YjyTISq4jyWglIuZz1nB)) to coordinate the investigation between analysts and track the progress of the investigation. Select the comments to view or manage comments.

      If needed, **Search** to find specific words or phrases in Notepad and Messenger.

</details>

<details>

<summary>Review the incident overview</summary>

The incident **Overview** tab displays the MITRE tactics and techniques, summarized timeline, and interactive widgets that visualize the number of alerts, types of sources, hosts, and users associated with the incident.

1. Review the incident MITRE tactics and techniques widget.

   Cortex XDR displays the number of alerts associated with each tactic and technique. Select the centered arrow at the bottom of the widget to expand the widget and display the sub-techniques. Hover over a number of alerts to display a link to the MITRE ATT\&CK official site.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>In some cases, the number of alerts associated with the techniques will not be aligned with the number of the parent tactic because of missing tags or in case an alert belongs to several techniques.</p></div>
2. Investigate information about the **Alerts**, **Alert Sources**, and **Assets** associated with the incident.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Notice</h3><p>Requires a Cortex XDR Pro license.</p></div>

* In the **Alerts** widget:
  * Select **See All** to pivot to the **Alerts & Insights** table.
  * Review the **Total** number of alerts and the colored line indicating the alert severity. Select the severity tag to pivot to the **Alerts & Insights** table filtered according to the selected severity.
* In the **Alert Sources** widget:
  * Select **See All** to pivot to the **Alerts & Insights** table.
  * Select each of the alert source types to pivot to the **Alerts & Insights** table filtered according to the selected alert source.
* In the **Assets** widget:
  * Select **See All** to pivot to the **Key Assets and Artifacts** tab.
  * Select the host names to display the Details panel. The panel is only available for hosts with Cortex XDR agent installed and displays the host name, whether it’s connected, along with the **Endpoint Details**, **Agent Details**, **Network**, and **Policy information**. Use the available actions listed in the top right-hand corner to take remedial actions.
  * Review Users that are marked as Featured.
  * If available, review the User Score allocated to each user.

3. Review the artifacts and asset that are associated with the incident.

   You can click the more options icon next to an asset or artifact to open an associated view, or you can see more details in the **Key Assets & Artifacts** tab.

</details>

<details>

<summary>Investigate incident key assets and artifacts</summary>

The **Key Assets & Artifacts** tab displays all the incident asset and artifact information of hosts, users, and key artifacts associated with the incident.

1. Investigate artifacts.

   In the **Artifacts** section, search for and review the artifacts associated with the incident. Each artifact displays, if available, the artifact information and available actions according to the type of artifact; File, IP Address, and Domain.
2. Investigate hosts.

   In the **Hosts** section, search for and review the hosts associated with the incident. Each host displays, if available, host information and available actions.

   To further investigate the host, select the host name to display the Details panel. The panel is only available for hosts with the agent installed and displays the host name, whether it’s connected, along with the **Endpoint Details**, **Agent Details**, **Network**, and **Policy information** details. If the Details panel is not available, click the more options icon next to a host name to see the available options.
3. Investigate users.

   In the **Users** section, search for and review the users associated with the incident. Each user displays, if available, the user information and available actions

</details>

<details>

<summary>Investigate incident alerts and insights</summary>

The **Alerts & Insights** tab displays a table of the alerts and insights associated with the incident.

1. Use the table tabs to switch between alerts and insights, and add filters to the table to refine the displayed entries.
2. Click an alert or insight to open the Details panel.

   Use the available actions listed in the top right-hand corner to take remedial actions.

{% hint style="info" %}

### Note

When an alert is resolved it remains linked to an incident. Once all of the alerts in an incident are resolved, the incident is automatically closed.
{% endhint %}

</details>

<details>

<summary>Investigate the incident timeline</summary>

The incident **Timeline** tab is a chronological representation of alerts and actions relating to the incident.

1. Navigate to the **Timeline** tab and filter the actions according to the action type.
2. Investigate a timeline entry.

   Each timeline entry is a representation of a type of action that was triggered in the alert. Alerts that include the same artifacts are grouped into one timeline entry and display the common artifact in an interactive link. Depending on the type of action, you can select the entry, host names, and artifacts to further investigate the action:

   * Locate the action you want to investigate:
     * For **Response Actions** and **Incident Management Actions**, you can add and view comments relating to the action.
     * For **Alerts**, click the action to open the Details panel. In the panel, navigate to the **Alerts** tab to view the **Alerts** table filtered according to the alert ID, the **Key Assets** to view a list of **Hosts** and **Users** associated to the alert, and an option to add **Comments**.
   * Select the Host name to display the endpoint data, if available.
   * Select the Artifact to display the following type of information:
     * **Hash artifact:** Displays the **Verdict**, **File name**, and **Signature status** of the hash value. Select the hash value to view the **Wildfire Analysis Report**, **Add to Block list**, **Add to Allow list** and **Search file**.
     * **Domain artifact:** Displays the **IP address** and **VT score** of the domain. Select the domain name to **Add to EDL**.
     * **IP address:** Display whether the IP address is **Internal** or **External**, the **Whois** findings, and the **VT score**. Expand **Whois** to view the findings and **Add to EDL**.
   * In action entries that involved more artifacts, expand **Additional artifacts found** to further investigate.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
