> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-user.md).

# Investigate a user

Drilldown on a user in the **User Risk View** or the **User View**. On this view Cortex XDR aggregates all of the data collected for a user, displays the information in graphs and tables, and provides further drilldown options for easy investigation. Cortex XDR uses Identity Analytics to aggregate information on a user and displays insights about the user.

{% hint style="info" %}

### Notice

If the Identity Threat module is enabled you can open the **User Risk View**. This view displays insights and profiling information to help you investigate alerts and incidents. Viewing anomalies in the context of baseline behavior facilitates risk assessment and shortens the time you require for making verdicts.

If the Identity Threat module is *not* enabled you can open the **User View**. This view displays an overview of the user and information about the user's score and activity.
{% endhint %}

You can take the following actions to investigate a user:

* Assess the user's behavior and score.
* Star the user to be included in the watchlist.
* (User Risk View only) Review the user's working hours and related alerts.
* (User Risk View only) Analyze the user's behavior over time and compare to their peers with the same asset role.

**How to investigate a user**

1. Right-click a user name and select **Open User Risk View** or **Open User Card**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Tip</h3><p>You can also see a list of all users under <strong>Assets</strong> → <strong>Asset Scores</strong>.</p></div>
2. Select the timeframe to view the user's details.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Cortex XDR normalizes and displays incident and alert times in your time zone. If you're in a half-hour time zone, the activity in the Normal Activity and the Actual Activity charts is displayed in the whole-hour time slot preceding it. For example, if you're in a UTC +4.5 time zone, the time displayed for the activity will be UTC +4.5, however, the visualization in the Normal Activity and the Actual Activity charts will be in the UTC +4 slot.</p></div>
3. Investigate the user.

<details>

<summary>User Risk View</summary>

Review the sections of the **User Risk View**. Depending on your permissions, some information might be limited by your scope.

1. In the left panel, review the overview of the user:
   * **User Score:** Displays the score assigned on the last day of the selected time frame and the change in the score for the selected time frame. The score is updated continuously as new alerts are associated with incidents.
   * **Common Locations:** Displays the countries from which the user connected most in the past few weeks.
   * **Common UAs:** Displays the user agents that the user used most in the past few weeks.
   * **Regular Activity Hours:** This data is based on the preceding several weeks and takes into account holidays and seasonality to present an accurate picture. Cortex XDR leverages endpoint telemetry to provide the activity data.
2. Review the **Score Trend** graph.

   The graph is based on new incidents created within the selected time frame, and updates on past incidents that are still active. The straight line represents the user score, which is based on the scores of the incidents associated with the user.

   The bubbles in the graph represent the number of alerts and insights generated on the selected day. Bigger bubbles indicate more alerts and insights, and a possible risk.
3. Drilldown on a score for a specific day by clicking a bubble. Alternatively, review the user information for the selected timeframe (Last 7D, 30D, or custom timeframe). The widgets in the right panel reflect the selected timeframe.
4. Review the **Related Incidents** for the selected timeframe or score selected in the **Score Trend** graph. If you are drilling down on a score, you can see the incidents that contributed to the total score on the selected day. Review the following data:
   * The **Status** column provides visibility into the reason for the score change. For example, if an incident is resolved, its score will decrease, bringing down the host score.
   * The **Points** column displays the risk score that the incident contributed to the host score. The points are calculated according to SmartScore or Incident Scoring Rules.
5. Review the **Related Alerts and Insights** for the selected timeframe or score selected in the **Score Trend** graph.

   The timeline displays all detection activities associated with the host. The alerts are grouped into buckets according to MITRE ATT\&CK tactics. Click on a tactic to filter the alerts in the table. To further investigate an alert, click the alert to open the Alert Panel and click **Investigate**.
6. Review the user activity per day in the **Actual Activity** widget.

   In this widget Cortex XDR compares the user's actual activity data with the **Regular Activity Hours**, and highlights any differences or anomalies in the user's expected activity.

   The cells are marked according to the activity that took place:, and a dashed frame indicates that Cortex XDR detected uncommon activity in the time slot.

   * A dashed ribbon highlights discrepancies between regular activity hours and actual activity.
   * A colored ribbon indicates the level of activity on a specific day/hour.
   * A numbered ribbon indicates the number of alerts and insights that occurred on a specific day/hour.
7. Review the user's **Login Attempts** during the selected timeframe or on the day selected in the **Score Trend** graph.

   You can see details of the related login attempts, and whether the attempts were successful. To further investigate login activity for the user, click **View In XQL** to link to a prefilled query in the **Query Builder**. Using Cortex Query Language you can create queries to refine your search.
8. Review the user's **Latest Authentication Attempts** during the selected timeframe or on the day selected in the **Score Trend** graph.

   You can see details of the related authentication attempts, and whether the attempts were successful. To further investigate authentication attempts by the user, click **View In XQL** to link to a prefilled query in the **Query Builder**. Using Cortex Query Language you can create queries to refine your search.
9. Review the user's **SAAS Log** activity during the selected timeframe or on the day selected in the **Score Trend** graph. You can see details of the SaaS logs that were ingested into the platform in context of the user.

   To further investigate SaaS log activity for the user, click **View In XQL** to link to a prefilled query in the **Query Builder**. Using Cortex Query Language you can refine your search.
10. For users with associated asset roles, compare the data with other peers with the same asset role. In the **Score Trend** graph click **Compare To** and select an asset role to which you want to compare the data.

    The dashed line presents the average score for peers with the same asset role as the user, over the same time period. Hover over a bubble on the dashed line to see the Average score for the selected peer, and a breakdown of the score per endpoint. Click **Show&#x20;*****x*****&#x20;Hosts** to see a full breakdown of the score on the Peer Score Breakdown, filtered by the selected asset role. From the Peer Score Breakdown you can select any user name and pivot to additional views for further investigation.

</details>

<details>

<summary>User View</summary>

Review the sections of the **User View**. Depending on your permissions, some information might be limited by your scope.

1. In the left panel, review the overview of the user. The displayed information is aggregated by Cortex XDRfrom incidents, Workday, and Active Directory data.

   The **User Score** displays the score that is currently assigned to the user and is updated continuously as new alerts are associated with incidents.
2. Review the **Score Trend** graph.

   The graph is based on new incidents created within the selected time frame, and updates on past incidents that are still active. The straight line represents the user score, which is based on the scores of the incidents associated with the user.

   Select a score to display in the **Incidents** table the incidents that contributed to the total user score on a specific day.
3. Click a score to drilldown on the score for a specific day. Alternatively, review the user information for the selected timeframe (Last 7D, 30D, or custom timeframe).

   The widgets in the right panel reflect the selected timeframe.
4. Review the **Related Incidents** for the selected timeframe or score selected in the **Score Trend** graph. If you are drilling down on a score, you can see the incidents that contributed to the total score on the selected day. Review the following data:
   * The **Status** column provides visibility into the reason for the score change. For example, if an incident is resolved, its score will decrease, bringing down the host score.
   * The **Points** column displays the risk score that the incident contributed to the host score. The points are calculated according to SmartScore or Incident Scoring Rules.
5. Review the following additional widgets:
   * **User Associated Insights**
   * **Top 5 Hosts Logged Into**
   * **Top 5 Authentication Target Hosts**
   * **Top 5 Authentication Source Hosts**
   * **Recent Login**
   * **Recent Authentications**

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-user.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
