> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/causality-icons-key.md).

# Causality icons key

The following tables describe the causality chain icons, broken down by type:

### **Action icons**

Causality action icons mark the actions that were taken on a process or event. Pending actions are shown with a dotted line.

<table><thead><tr><th width="314">Icon</th><th>Description</th></tr></thead><tbody><tr><td><img src="/files/Oku8xgWPxhoF1q91h4Tt" alt="Blacklist__action_icon_.png" data-size="line"><img src="/files/qpjl7KOhsD5JrajtclxP" alt="Blacklist_-_pending__action_icon_.png" data-size="line"></td><td>Blocklist</td></tr><tr><td><img src="/files/HHdRolHkS9lj56ledAKG" alt="Quarantine__action_icon_.png" data-size="line"><img src="/files/kIDjNX9fjbJlnZ9vfbFp" alt="Quarantine_-_pending__action_icon_.png" data-size="line"></td><td>Quarantine</td></tr><tr><td><img src="/files/VY3CgCCPTXINQgPauE5p" alt="Whitelist__action_icon_.png" data-size="line"><img src="/files/qAu1ClojfZoQKJauw5xR" alt="Whitelist_-_pending__action_icon_.png" data-size="line"></td><td>Allowlist</td></tr></tbody></table>

### **Causality alert icons**

Causality alert icons indicate the type of alert that was triggered.

| Icon                                                                                                         | Description        |
| ------------------------------------------------------------------------------------------------------------ | ------------------ |
| <img src="/files/g3xpu98MwsGXlPzfplSI" alt="3rd_party__causality_alert_icon_.png" data-size="line">          | 3rd party          |
| <img src="/files/jaletcLKt3L4ZPLNtVcB" alt="Agent__causality_alert_icon_.png" data-size="line">              | XDR Agent          |
| <img src="/files/HQvcvlXB1kBcZhslJ7Jl" alt="Analytics__causality_alert_icon_.png" data-size="line">          | Analytics          |
| <img src="/files/doqbVXTkXPVSbodgGuws" alt="BIOC__causality_alert_icon_.png" data-size="line">               | BIOC               |
| <img src="/files/Zbps3UnB1UgnMOJVxUc4" alt="Firewall__causality_alert_icon_.png" data-size="line">           | Firewall           |
| <img src="/files/rTiUsH0xJ05dsBIAgmpn" alt="General_alert__causality_alert_icon_.png" data-size="line">      | General alert      |
| <img src="/files/UBS98WTufWfHUEHXdW7E" alt="Identity_analytics__causality_alert_icon_.png" data-size="line"> | Identity analytics |
| <img src="/files/H987T0p2fafNRxPzcL8A" alt="IOC__causality_alert_icon_.png" data-size="line">                | IOC                |

**Examples**

A number next to the alert icon indicates that there are multiple alerts. This icon show that there are three alerts and the selected alert is a BIOC alert. You can scroll through the alerts in the **Information Overview**.

![](/files/ktkAQ6O6Lt7HQov4ooeg)

This example shows AI activity from the Microsoft Copilot was detected.

<figure><img src="/files/Wg5teS9dK6vPjwAugkDB" alt=""><figcaption></figcaption></figure>

### **Cloud event icons**

Cloud event icons indicate the type of cloud event or process.

| Icon                                                                                                            | Description               |
| --------------------------------------------------------------------------------------------------------------- | ------------------------- |
| <img src="/files/qGWhNKlqSJTXve6wYrP5" alt="Cloud_admin__cloud_event_icon_.png" data-size="line">               | Cloud admin               |
| <img src="/files/hXZWpEV0q1wDedZL780S" alt="Compute_disks__cloud_event_icon_.png" data-size="line">             | Compute disks             |
| <img src="/files/iJN0LyTNfRXdtsH4GfeN" alt="Compute_instances__cloud_event_icon_.png" data-size="line">         | Compute instances         |
| <img src="/files/5pBcw7LAHuHcVivHP2wJ" alt="Container_escaped__cloud_event_icon_.png" data-size="line">         | Container escaped         |
| <img src="/files/ke2GfqNobWDXaJQJ7thR" alt="Drive__cloud_event_icon_.png" data-size="line">                     | Drive                     |
| <img src="/files/CamOebHG0MpyMpPpnHZ3" alt="Exchange__cloud_event_icon_.png" data-size="line">                  | Exchange                  |
| <img src="/files/xgOXAEZcP4DyLQbeHZzA" alt="General_resource__cloud_event_icon_.png" data-size="line">          | General resource          |
| <img src="/files/rVS2sGWnhkJUFh9x8ETE" alt="Groups__cloud_event_icon_.png" data-size="line">                    | Groups                    |
| <img src="/files/5nuKdLPCmMtEaSEUVtZV" alt="Images__cloud_event_icon_.png" data-size="line">                    | Images                    |
| <img src="/files/kfP9Mc4f9479teHh0C9e" alt="Network_interfaces__cloud_event_icon_.png" data-size="line">        | Network                   |
| <img src="/files/5AmbplQHp8uowDDfJurs" alt="Onedrive__cloud_event_icon_.png" data-size="line">                  | Onedrive                  |
| <img src="/files/NJbp9WT6zlW4dGHXXYGl" alt="Security_groups-_FW_rules__cloud_event_icon_.png" data-size="line"> | Security groups- FW rules |
| <img src="/files/iyAgunTNukyLD6W7FNlK" alt="Sharepoint__cloud_event_icon_.png" data-size="line">                | Sharepoint                |
| <img src="/files/l5RGNCX55cgigmoc7aZ9" alt="Skype__cloud_event_icon_.png" data-size="line">                     | Skype                     |
| <img src="/files/EnH0RIIZBCpfLuW1ejpM" alt="Storage_buckets__cloud_event_icon_.png" data-size="line">           | Storage buckets           |
| <img src="/files/TDZZhaTrC0wj3aDGoQZM" alt="Subnets__cloud_event_icon_.png" data-size="line">                   | Subnets                   |
| <img src="/files/aJtE0yXs4knq3jWrkl1w" alt="Teams__cloud_event_icon_.png" data-size="line">                     | Teams                     |
| <img src="/files/GKn7DeL4mpy5fbBCuvAC" alt="VPCs__cloud_event_icon_.png" data-size="line">                      | VPCs                      |

### **Event icons**

Event icons indicate the type of activity that occurred.

| Icon                                                                                                 | Description          |
| ---------------------------------------------------------------------------------------------------- | -------------------- |
| <img src="/files/7to5dvWD2RNCtMudQ4oY" alt="DotNet__event_icon_.png" data-size="line">               | AI tool              |
| <img src="/files/QcgokTwXn7EIcMAoX1GT" alt="DotNet__event_icon_.png" data-size="line">               | DotNet               |
| <img src="/files/I7HS2keZrxJ140ccFdnD" alt="Event_log__event_icon_.png" data-size="line">            | Event log            |
| <img src="/files/TwH8aVgQJL8VUCI3xbX6" alt="File__event_icon_.png" data-size="line">                 | File                 |
| <img src="/files/M5KPArGxcdqZkJXDm7a8" alt="Firewall__event_icon_.png" data-size="line">             | Firewall             |
| <img src="/files/KTWIyKfbwbsU2Smt1nN8" alt="Host__event_icon_.png" data-size="line">                 | Host                 |
| <img src="/files/1EAyVdEJCsNw5QoY5Vu5" alt="Host_group__event_icon_.png" data-size="line">           | Host group           |
| <img src="/files/Wis4E4wlCujzkR4YJwMx" alt="Identity_analytics__event_icon_.png" data-size="line">   | Identity analytics   |
| <img src="/files/g8BZ94LrnzGN8KaPpZED" alt="Internet__event_icon_.png" data-size="line">             | Internet             |
| <img src="/files/8AZzlHTO9sgrNnC1F5sr" alt="Malware_alert__event_icon_.png" data-size="line">        | Malware              |
| <img src="/files/aUqhBN4Xs0HQyIuxMEmb" alt="Mobile__event_icon_.png" data-size="line">               | Mobile               |
| <img src="/files/WREAopKLdaovzh5JpUvm" alt="Module_load__event_icon_.png" data-size="line">          | Module load          |
| <img src="/files/6lcWg5STm1YoFnv3sUXr" alt="Multi-user__event_icon_.png" data-size="line">           | Multi-user           |
| <img src="/files/Y0cWFnqWpBFSufLUfOoc" alt="Network__event_icon_.png" data-size="line">              | Network              |
| <img src="/files/Qj3W4UtEPvkK2k1i4UDH" alt="Potential_prevention__event_icon_.png" data-size="line"> | Potential prevention |
| <img src="/files/QZTGSdpkJIenpRiqXG7K" alt="Range__event_icon_.png" data-size="line">                | Range                |
| <img src="/files/vG0OWIghGDbv8GfPlbn9" alt="Registry__event_icon_.png" data-size="line">             | Registry             |
| <img src="/files/ysj463i4nSw9dI7katIF" alt="Router__event_icon_.png" data-size="line">               | TCP Protocol         |
| <img src="/files/IKVaVbyVjq1uOjByGAAq" alt="Server__event_icon_.png" data-size="line">               | Server               |
| <img src="/files/n3ohGy3szF69fb3ZxyOt" alt="Unknown__event_icon_.png" data-size="line">              | Unknown event        |
| <img src="/files/JV10cve35Ee2yFDyREQM" alt="User_session__event_icon_.png" data-size="line">         | User session         |
| <img src="/files/wv6ICHHNj1B0NX2iftzI" alt="VOIP__event_icon_.png" data-size="line">                 | VOIP                 |
| <img src="/files/QrFer2KL3zDMn2yn6bam" alt="VPN__event_icon_.png" data-size="line">                  | VPN                  |

### **Left node icons**

Left node icons provide additional information about a process.

| Icon                                                                                                | Description             |
| --------------------------------------------------------------------------------------------------- | ----------------------- |
| <img src="/files/rkQF5YtN8N1CvJEelj3N" alt="Injection__left_node_icon_.png" data-size="line">       | Injected node           |
| <img src="/files/jcJIO0BV5XLvn5Ecft9c" alt="Last_actor__left_node_icon_.png" data-size="line">      | Last actor              |
| <img src="/files/XrdwdyppK787cKUkSkxJ" alt="Remote_IP__left_node_icon_.png" data-size="line">       | Remote terminal session |
| <img src="/files/11UnSHmeNF3dpzTgX0Kq" alt="RPC__left_node_icon_.png" data-size="line">             | RPC                     |
| <img src="/files/wfTELGQjulg8D8nyDOs3" alt="Unknown_process__left_node_icon_.png" data-size="line"> | Unknown process         |

### **Node icons**

Node icons indicate the type of process or event that occurred in the chain.

| Icon                                                                                             | Description       |
| ------------------------------------------------------------------------------------------------ | ----------------- |
|                                                                                                  | Adobe             |
| <img src="/files/YAyimsslTY9E3uPeUOhh" alt="Attachment__node_icon_.png" data-size="line">        | Attachment        |
| <img src="/files/hM5IwbX4edalX2S26at1" alt="Chrome__node_icon_.png" data-size="line">            | Chrome            |
| <img src="/files/zPVMYyyIBJYOe798AuHi" alt="Cloud__node_icon_.png" data-size="line">             | Remote IP Address |
| <img src="/files/X3c6CngT025A4us39AuH" alt="Email__node_icon_.png" data-size="line">             | Email             |
| <img src="/files/VJriLFm6h8g8bqhrPriP" alt="Endpoint__node_icon_.png" data-size="line">          | Endpoint          |
| <img src="/files/1ho9ngpdnPLjL5RZkuBS" alt="Excel__node_icon_.png" data-size="line">             | Excel             |
| <img src="/files/jMrWrtfYthG1GccLfCkX" alt="Firefox__node_icon_.png" data-size="line">           | Firefox           |
| <img src="/files/2SvkPVrW39ukjaaOuMsV" alt="Generic_process__node_icon_.png" data-size="line">   | Generic process   |
| <img src="/files/aIrZ5rowuhZi82p6RFah" alt="Internet_Explorer__node_icon_.png" data-size="line"> | Internet Explorer |
| <img src="/files/EoRdm9uVhdCbTdjl0zHN" alt="IP__node_icon_.png" data-size="line">                | IP address        |
| <img src="/files/MOl3D8qLSaAAA7dIfaL5" alt="Link__node_icon_.png" data-size="line">              | Link              |
| <img src="/files/rwlt5BDMqcsfSx8xEAlG" alt="mySQL__node_icon_.png" data-size="line">             | mySQL             |
| <img src="/files/ICZsNTDuYeeWvPhymMVX" alt="Outlook__node_icon_.png" data-size="line">           | Outlook           |
| <img src="/files/ux2tdlGQv2wY4TamQenp" alt="Powerpoint__node_icon_.png" data-size="line">        | Powerpoint        |
| <img src="/files/dxKqKFhDsxx2GmOuqyeP" alt="Putty__node_icon_.png" data-size="line">             | Putty             |
| <img src="/files/KZNr87WcJ0BL3nVLGgZ4" alt="Sender__node_icon_.png" data-size="line">            | Sender            |
| <img src="/files/4nIm307yrt5AaBIXeH4h" alt="Unknown__node_icon_.png" data-size="line">           | Unknown           |
| <img src="/files/z5QBKf4E828kguPO7Gys" alt="User__node_icon_.png" data-size="line">              | User              |
| <img src="/files/P3fl4z7ux7CTqY7S2Pjk" alt="Word__node_icon_.png" data-size="line">              | Word              |

### **Other icons**

| Icons                                                                                                    | Description                  |
| -------------------------------------------------------------------------------------------------------- | ---------------------------- |
| <img src="/files/2qk0sZczIiT9k2FDNFMZ" alt="Benign.png" data-size="line">                                | Benign                       |
| <img src="/files/2YfG9y9dYuYgRn6zZZ5J" alt="Container.png" data-size="line">                             | Container                    |
| <img src="/files/RkV0G0Q4k5Yf2Y862lCz" alt="CGO__text_icon_.png" data-size="line">                       | Causality Group Owner (CGO). |
| <img src="/files/UlsJ8LHOgW5lupKuBfRh" alt="Default__other_icon_.png" data-size="line">                  | Default                      |
| <img src="/files/Mrp3R2fqL6ME5e0zMnxw" alt="Grayware.png" data-size="line">                              | Grayware                     |
| <img src="/files/yKmoYcU9gHHRShUDL69y" alt="In-evaluation.png" data-size="line">                         | In-evaluation                |
| <img src="/files/W2EhkIhTrlutawU7UpYF" alt="Malware.png" data-size="line">                               | Malware                      |
| <img src="/files/j0rKQOoll6orZn4rTkmI" alt="Quarantine__other_icon_.png" data-size="line">               | Quarantine                   |
| <img src="/files/yRbIqDEvLaynLP9GHyyL" alt="Still_running__text_icon_.png" data-size="line">             | Still running                |
| <img src="/files/2a2yqFp0vMXky1909ag8" alt="Unknown_sample.png" data-size="line">                        | Unknown sample               |
| <img src="/files/kTJsByIoATm6qiZshuRv" alt="User__text_icon_.png" data-size="line">                      | User                         |
| <img src="/files/vecrG5i2rtDrj2CxHk7G" alt="WF_Download__other_icon_.png" data-size="line">              | WF download                  |
| <img src="/files/Ca3R6UdI0wSwEUvWFxos" alt="WF_Download_unsuccessful__other_icon_.png" data-size="line"> | WF download unsuccessful     |

### **Examples**

The following example shows a XDR Agent alert was triggered on a File.

![](/files/ouW2R24t2otUxX1dafWg)

In this example, a NGFW alert was triggered on a TCP Protocol that called a remote IP address, that created an unknown process.

![](/files/0j1AurxEoV4InXNsDjSd)

In this example, the highlighted process node represents the real parent that executed the process. Click on the node for more details about the parent process. The pen icon on the first process nodes indicates that this process is "last actor". The syringe icon on the last process node indicates that this process is an "injected node".

![](/files/3DlWFaVPGYMcg1uZHROu)

In this example, two alerts were triggered on an email that was sent to two recipients and included attachments and links.

![](/files/hCsz1JAOYtdtIiZ2M4Xr)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/causality-icons-key.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
