For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Privileged Investigator

Learn more about the Cortex XDR predefined user role called Privileged Investigator.

Extends Investigator role with rules visibility, threat intel, and action center. Can view and triage issues, cases, and rules, and view profiles and policies, with Analytics management. No response actions, detection rule editing, endpoint, or configuration access.

While a standard Investigator focuses on viewing and triaging issues, the Privileged Investigator is granted deeper View/Edit access to the investigation logic itself.

Tip

Assign to senior SOC analysts or threat hunters who need to understand detection rules, edit threat intel indicators, manage playbooks/scripts, and have visibility into endpoint policies, but who do not need to perform response actions like isolating endpoints or running Live Terminal.

To quickly see exactly which pages and actions a role allows, click on the role name, which opens a read-only view of all checked permissions. For more information about the permissions, see Role permissions by components.

Last updated

Was this helpful?