Alert side panel
The alert side panel provides detailed information about alerts at a glance and in the context of the incident.
The alert side panel provides detailed information about alerts at a glance and in the context of the incident. To open the alerts panel, on the Alerts page click on any alert.
In this view, you can change the severity of an alert, star it, investigate it in the causality view, and exclude it from the Analytics. The panel displays the name and description of the alert, the source that triggered the alert, and the following details where applicable:
General: Displays general information about the alert.
Number of suppressed alerts: (for IOC, BIOC, and Analytics alerts) Number of alerts that were suppressed because they were detected as duplicates of the alert
Last suppressed alert timestamp: (for IOC, BIOC, and Analytics alerts) The last time Cortex XDR suppressed an alert because it was detected as a duplicate of the alert
Action: Taken as a result of the alert
Category: Type of threat detected
File Macro SHA256
Tags: As applied by Cortex XDR
Behavioral analytics: Displays graphs that visualize the anomalies that were observed by the detector.
Note
The Behavioral Analytics section is available only when the Identity Threat Module add-on is enabled. Cortex XDR displays Behavioral Analytics widgets for selected alerts and is continuously adding widgets to more alerts.
You can use this section to evaluate the deviation in the context of the baseline behavior. As you navigate between the different factors that triggered the alert, the event and the baseline information are displayed in tabular format or in timeline format, depending on the type of event.
The tabular view displays the baseline behavior in a table, with the anomaly highlighted and in a separate line.
The timeline view displays the highlighted atypical value, and if applicable, the minimum, maximum, and average values, for the selected period.
MITRE ATT&CK: Displays the MITRE ATT&CK tactics and techniques.
Host: Displays the Host platform, Host name, Host IP, Host MAC address, Host FQDN.
Rule: Displays details about the alert that triggered the rule.
Connection details: Displays information about network connections, login, process execution, RPC calls, system calls, or registry events.
Cloud audit log: Displays the audit log details for alerts generated on cloud hosts.
Last updated
Was this helpful?
