> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats.md).

# Detect, Investigate, and respond to threats

- [Monitor dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports.md): Learn how to use Cortex XSIAM dashboards and reports to monitor security operations, visualize data, and share actionable insights.
- [Overview of dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports.md): Learn how Cortex XSIAM dashboards, widgets, and reports turn security data into operational insights.
- [Dashboard interface basics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basics.md): Learn the Cortex XSIAM dashboard interface, including navigation, widgets, filters, and available actions.
- [Dashboard types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-types.md): Explore Cortex XSIAM dashboard types and choose the right view for your security operations.
- [Report basics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/report-basics.md): Learn Cortex XSIAM report concepts, including report templates, scheduling, and data presentation.
- [Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/widget-library.md): Explore the Cortex XSIAM Widget Library to find visualizations for dashboards and security monitoring.
- [Access and visibility for dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports.md): Control Cortex XSIAM dashboard and report access, visibility, ownership, and sharing.
- [Visibility settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settings.md): Configure Cortex XSIAM dashboard and report visibility settings for the appropriate audience.
- [Access to widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgets.md): Manage Cortex XSIAM access to dashboard widgets and the data they display.
- [Sharing icons](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-icons.md): Understand Cortex XSIAM sharing icons and their dashboard and report visibility meanings.
- [Access and sharing cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-and-sharing-cheat-sheet.md): Use this Cortex XSIAM reference to manage dashboard and report access and sharing.
- [Manage dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports.md): Manage Cortex XSIAM dashboards and reports, including ownership, sharing, imports, and deleted content.
- [Dashboard Manager](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/dashboard-manager.md): Use Cortex XSIAM Dashboard Manager to organize, find, and manage dashboards.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/reports.md): Manage Cortex XSIAM reports and report templates for security operations and stakeholder communication.
- [Duplicate dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reports.md): Duplicate Cortex XSIAM dashboards and reports to reuse existing visualizations and templates.
- [Share custom dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templates.md): Share Cortex XSIAM custom dashboards and report templates with users and teams.
- [Change ownership to dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templates.md): Change Cortex XSIAM dashboard and report template ownership to maintain access and accountability.
- [Import and export dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templates.md): Import and export Cortex XSIAM dashboards and report templates for reuse across environments.
- [Configure the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-report.md): Configure Cortex XSIAM notifications for failed report generation and delivery.
- [Deleted content](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/deleted-content.md): Restore or permanently manage deleted Cortex XSIAM dashboards, reports, and related content.
- [Create dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards.md): Create Cortex XSIAM dashboards to monitor security data, trends, and operational outcomes.
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards/create-a-dashboard.md): Create a Cortex XSIAM dashboard with widgets, filters, and layouts for focused monitoring.
- [Create reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports.md): Create Cortex XSIAM reports to present and share security data with stakeholders.
- [Create a report template from scratch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports/create-a-report-template-from-scratch.md): Create a Cortex XSIAM report template from scratch for repeatable security reporting.
- [Advanced configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration.md): Configure Cortex XSIAM dashboards with custom widgets, global filters, and drilldowns.
- [Create custom widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets.md): Create custom Cortex XSIAM dashboard widgets using AI, XQL, scripts, and parameters.
- [Create widgets using AI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-ai.md): Use AI to create Cortex XSIAM dashboard widgets from natural language prompts.
- [Create XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets.md): Create Cortex XSIAM XQL widgets to visualize query results on dashboards.
- [Add parameters to a custom XQL widget](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widget.md): Add parameters to Cortex XSIAM custom XQL widgets for interactive dashboard filtering.
- [Create script-based widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgets.md): Create Cortex XSIAM script-based widgets to display custom dashboard data and insights.
- [Configure global filters](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-global-filters.md): Configure Cortex XSIAM global dashboard filters to refine data across multiple widgets.
- [Configure drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-drilldowns.md): Configure Cortex XSIAM dashboard drilldowns to investigate data from widget visualizations.
- [Dashboard reference](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference.md): Reference Cortex XSIAM dashboards, including Command Center and system dashboard views.
- [Command Center reference](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference.md): Reference Cortex XSIAM Command Center dashboards for security operations visibility and monitoring.
- [Cortex Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-command-center.md): Use Cortex Command Center in Cortex XSIAM to monitor operational security insights and priorities.
- [Cortex Agentic Assistant dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-agentic-assistant-dashboard.md): Use the Cortex XSIAM Agentic Assistant dashboard to monitor AI-assisted security operations.
- [XSIAM Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center.md): Use the XSIAM Command Center to monitor Cortex XSIAM security operations and key metrics.
- [Data Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/data-inventory.md): Use Cortex XSIAM Data Inventory to monitor data sources, coverage, and security telemetry.
- [Dynamic View](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/dynamic-view.md): Use Cortex XSIAM Dynamic View to monitor changing security data and operational insights.
- [Cases Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/cases-overview.md): Use Cortex XSIAM Cases Overview to monitor case status, priorities, and investigation workload.
- [Cloud Detection and Response (CDR) Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cloud-detection-and-response-cdr-command-center.md): Use the Cortex XSIAM CDR Command Center to monitor cloud detection and response operations.
- [Cortex Cloud Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-cloud-command-center.md): Use Cortex Cloud Command Center in Cortex XSIAM to monitor cloud security operations and insights.
- [System dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md): Reference Cortex XSIAM system dashboards for operational, cloud security, and data ingestion monitoring.
- [Cortex Cloud Consumption](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cortex-cloud-consumption.md): Use Cortex Cloud Consumption in Cortex XSIAM to monitor cloud security usage and consumption.
- [Cloud Security Operations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cloud-security-operations.md): Use Cortex XSIAM Cloud Security Operations to monitor cloud risks, findings, and remediation progress.
- [Data Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/data-ingestion.md): Use Cortex XSIAM Data Ingestion to monitor data collection health, volume, and coverage.
- [Investigation and response](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response.md)
- [Overview of cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases.md): Learn how cases group security issues, support investigations, and track responses through resolution in Cortex XSIAM.
- [What are cases?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/what-are-cases.md): Learn how Cortex XSIAM cases unify issues, assets, and artifacts for streamlined investigations.
- [Resolving cases with AI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/resolving-cases-with-ai.md): Use AI in Cortex XSIAM to prioritize, investigate, and resolve security cases faster.
- [Case lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-lifecycle.md): Understand how Cortex XSIAM moves security cases from detection through resolution.
- [Case thresholds](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-thresholds.md): Learn how Cortex XSIAM case thresholds control issue grouping and auto-resolved case reopening.
- [Case scope and impact](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-scope-and-impact.md): Learn how Cortex XSIAM uses severity, score, and domain to prioritize and scope cases.
- [Case and issue domains](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-and-issue-domains.md): Learn how Cortex XSIAM assigns case and issue domains to organize response work.
- [Overview of case teams and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/overview-of-case-teams-and-roles.md): Learn how Cortex XSIAM case teams assign roles and control sensitive case access.
- [Case concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts.md): Learn Cortex XSIAM case concepts, including issues, grouping, scoring, SLAs, and causality.
- [Issues, findings, and events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/issues-findings-and-events.md): Understand how Cortex XSIAM connects issues, findings, and events to support case investigations.
- [Case grouping](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-grouping.md): Learn how Cortex XSIAM automatically groups related issues and artifacts into unified cases.
- [Case scoring](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-scoring.md): Learn how Cortex XSIAM scores cases using rules, SmartScore, and manual input.
- [Case starring](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-starring.md): Learn how Cortex XSIAM stars important cases manually or through automated configurations.
- [SLAs and tracking](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/slas-and-tracking.md): Learn how Cortex XSIAM tracks case SLAs, timers, and severity-based response targets.
- [What is Causality?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/what-is-causality.md): Learn how Cortex XSIAM connects activity into causality chains for faster investigations.
- [Analyze and resolve cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases.md): Learn how Cortex XSIAM helps you analyze, investigate, and resolve security cases.
- [Review all cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/review-all-cases.md): Review and prioritize Cortex XSIAM cases using status, severity, scores, and saved views.
- [Start case analysis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/start-case-analysis.md): Start Cortex XSIAM case analysis from the Cases page, a unified workspace for investigation and response.
- [Agentic Assistant- Case Investigation agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/start-case-analysis/agentic-assistant-case-investigation-agent.md): Use the Case Investigation agent in Cortex XSIAM for contextual summaries and investigation guidance.
- [Establish case context](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context.md): Establish Cortex XSIAM case context by reviewing titles, descriptions, scores, and ownership.
- [AI-generated case summaries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context/ai-generated-case-summaries.md): Use Cortex XSIAM AI-generated summaries to understand current case scope and context.
- [Assess case severity and score](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context/assess-case-severity-and-score.md): Assess and update Cortex XSIAM case severity and scores to prioritize response.
- [Update case attributes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context/update-case-attributes.md): In Cortex XSIAM you can update case titles, descriptions, assignments, and starred status.
- [Analyze case details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details.md): To analyze a case in Cortex XSIAM you can review details about case relationships, evidence, issues, assets, tactics, and timelines.
- [Grouping graph](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/grouping-graph.md): Use the Cortex XSIAM grouping graph to understand linked issues and artifacts.
- [Evidence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/evidence.md): Review Cortex XSIAM evidence to understand threats, validate findings, and guide remediation.
- [Issue feed](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/issue-feed.md): Review the case issue feed in Cortex XSIAM to trace case activity chronologically.
- [Associated assets and artifacts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/associated-assets-and-artifacts.md): Investigate Cortex XSIAM assets and artifacts associated with a case.
- [MITRE ATT\&CK tactics and techniques](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/mitre-att-and-ck-tactics-and-techniques.md): Review the MITRE ATT\&CK tactics and techniques associated with issues in Cortex XSIAM.
- [Compliance standards and controls](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/compliance-standards-and-controls.md): Review compliance standards and violated controls for Posture cases in Cortex XSIAM.
- [Case timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/case-timeline.md): Use the case timeline to track events, actions, and investigation evidence in Cortex XSIAM.
- [Detailed View](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/detailed-view.md): Use the Detailed View for table-based case investigation and analysis in Cortex XSIAM.
- [Resolve the case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case.md): Resolve Cortex XSIAM cases through remediation tasks and verified closure workflows.
- [Resolution Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolution-center.md): Use Cortex XSIAM Resolution Center to manage remediation tasks and resolve cases.
- [Collaborative notes and comments](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/collaborative-notes-and-comments.md): Use notes and comments to coordinate case investigations and responses in Cortex XSIAM.
- [How to resolve a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolve-a-case.md): Resolve Cortex XSIAM cases manually, through playbooks, or with the API.
- [Resolution reasons for cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolution-reasons-for-cases-and-issues.md): Select resolution reasons when closing cases and issues in Cortex XSIAM.
- [Monitor and track resolution times](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/monitor-and-track-resolution-times.md): Monitor case and issue resolution times in Cortex XSIAM against configured SLAs.
- [Cortex Response and Remediation content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/cortex-response-and-remediation-content-pack.md): Use Response and Remediation playbooks to automate incident workflows in Cortex XSIAM.
- [Investigate an issue using Cortex Response and Remediation playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/cortex-response-and-remediation-content-pack/investigate-an-issue-using-cortex-response-and-remediation-playbooks.md): Investigate Cortex XSIAM issues using Response and Remediation playbooks.
- [Example use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/cortex-response-and-remediation-content-pack/example-use-cases.md): Explore Response and Remediation playbook use cases in Cortex XSIAM.
- [Additional case actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions.md): Manage Cortex XSIAM cases with creation, merging, access, and unified-view actions.
- [Create a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/create-a-case.md): Create Cortex XSIAM cases manually and link or create associated issues.
- [Merge a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/merge-a-case.md): Merge related Cortex XSIAM cases to consolidate investigations, teams, and response efforts.
- [Assign a case team and restrict access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access.md): Assign case teams and restrict access to sensitive investigations in Cortex XSIAM.
- [Playbook examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access/playbook-examples.md): See playbook example for assigning case teams and restricting access to cases in Cortex XSIAM.
- [Unified case view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/unified-case-view.md): Use Cortex XSIAM Unified Case View to manage cases across child tenants.
- [Investigate issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues.md): Cortex XSIAM generates issues to bring your attention to security risks in your framework.
- [Overview of the Issues page](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/overview-of-the-issues-page.md): Review and prioritize Cortex XSIAM issues from the Issues page.
- [Issue card](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-card.md): Use the issue card to investigate and respond to issues in Cortex XSIAM.
- [Resolution actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/resolution-actions.md): Use the Resolution tab to see all resolution actions to remediate and close issues in Cortex XSIAM.
- [Link or unlink issues from a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/link-or-unlink-issues-from-a-case.md): You can link or unlink issues from cases in Cortex XSIAM.
- [Run an automation on an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/run-an-automation-on-an-issue.md): Run automations on issues to accelerate investigation and remediation in Cortex XSIAM.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-war-room-in-an-investigation.md): Use the Cortex XSIAM War Room to investigate issues and run response actions.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md): Use the Cortex XSIAM Work Plan to manage issue playbook tasks.
- [Issue syncing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-syncing.md): Sync Cortex XSIAM issues with external tickets to coordinate remediation.
- [Issue deduplication](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-deduplication.md): Cortex XSIAM uses issue deduplication to reduce duplicate security events.
- [Causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view.md): Investigate event chains behind issues in Cortex XSIAM with the causality view.
- [Network causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/network-causality-view.md): Investigate connected endpoint and firewall events in Cortex XSIAM with the network causality view.
- [Cloud causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/cloud-causality-view.md): Investigate cloud identities and resources in Cortex XSIAM with the cloud causality view.
- [Cloud causality view for audit log issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/cloud-causality-view-for-audit-log-issues.md): Investigate cloud audit log issues in Cortex XSIAM with the cloud causality view.
- [SaaS causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/saas-causality-view.md): Investigate SaaS-related issues in Cortex XSIAM with the SaaS causality view..
- [Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/timeline.md): Use the Cortex XSIAM timeline to trace events and issues during an attack.
- [Causality icons key](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/causality-icons-key.md): Use the causality icons key to interpret investigation data in causality chains in Cortex XSIAM.
- [Issue investigation actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions.md): Use issue actions to investigate, enrich, and remediate issues in Cortex XSIAM.
- [Copy issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/copy-issues.md): Copy issue details, rows, or URLs for sharing and analysis in Cortex XSIAM.
- [Analyze an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/analyze-an-issue.md): Analyze Cortex XSIAM issues using issue cards and causality views.
- [Update issue fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/update-issue-fields.md): Use CLI commands to update issue fields and statuses through commands, scripts, or playbooks in Cortex XSIAM.
- [Query case and issue data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md): Query case and issue data with Cortex Query Language in Cortex XSIAM.
- [Exclude an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/exclude-an-issue.md): Exclude Cortex XSIAM issues that do not indicate a security threat.
- [Create a featured field](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/create-a-featured-field.md): Create featured fields to highlight important issue attributes in Cortex XSIAM.
- [Export issue details to a file](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/export-issue-details-to-a-file.md): Export Cortex XSIAM issue details to a TSV file for offline analysis.
- [Investigate contributing events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/investigate-contributing-events.md): Investigate correlation rule events in Cortex XSIAM that contributed to an issue.
- [Retrieve additional issue details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/retrieve-additional-issue-details.md): Retrieve Cortex XSIAM issue data, related files, and packet captures for analysis.
- [View generating BIOC or IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/view-generating-bioc-or-ioc-rule.md): View the BIOC or IOC rule that generated a Cortex XSIAM issue.
- [Create profile exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/create-profile-exceptions.md): Create profile exceptions in Cortex XSIAM for relevant XDR agent issues.
- [Add a file path to a malware profile allow list](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/add-a-file-path-to-a-malware-profile-allow-list.md): Add safe file paths to Cortex XSIAM malware profile allow lists.
- [Close an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/close-an-issue.md): Close Cortex XSIAM issues after completing investigation and remediation.
- [Review findings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/review-findings.md): Review findings for an asset to gain insights into an asset’s posture status in Cortex XSIAM.
- [Findings card](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/review-findings/findings-card.md): View selected finding details and investigation context in Cortex XSIAM.
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets.md): Investigate IP addresses, assets, hosts, users, and file hashes in Cortex XSIAM.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-an-ip-address.md): Investigate IP address activity, threat intelligence, and related cases in Cortex XSIAM.
- [Investigate an asset](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-an-asset.md): Investigate the assets associated with an issue in Cortex XSIAM.
- [Investigate a host](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-a-host.md): Investigate host activity, risk scores, and related issues in Cortex XSIAM.
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md): Investigate SHA256 file and process hashes in Cortex XSIAM.
- [Investigate a user](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-a-user.md): Investigate user activity, risk scores, and identity insights in Cortex XSIAM.
- [Investigate endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints.md): Investigate and take actions on your endpoints in the Cortex XSIAM Action Center.
- [Overview of the Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/overview-of-the-action-center.md): Track investigation, response, and maintenance actions on protected endpoints in the Cortex XSIAM Action Center.
- [Initiate and monitor endpoint actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/overview-of-the-action-center/initiate-and-monitor-endpoint-actions.md): Initiate endpoint actions and monitor their progress in Cortex XSIAM.
- [Action Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/overview-of-the-action-center/action-center-reference-information.md): Review Cortex XSIAM Action Center fields, statuses, and action details.
- [Manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/manage-endpoints.md): View, manage, and take actions on endpoints in Cortex XSIAM.
- [Retrieve files from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-files-from-an-endpoint.md): Retrieve investigation files from endpoints and download them in Cortex XSIAM.
- [Retrieve support logs from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-support-logs-from-an-endpoint.md): Retrieve endpoint support logs and forensic data through Cortex XSIAM.
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-support-file-password.md): Retrieve the password needed to decrypt Cortex XSIAM endpoint support files.
- [Scan an endpoint for malware](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/scan-an-endpoint-for-malware.md): Run and monitor on-demand malware scans on endpoints with Cortex XSIAM.
- [Investigate files](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files.md): Investigate files, manage execution, and review analysis results in Cortex XSIAM.
- [Manage file execution](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/manage-file-execution.md): Manage allow and block lists for endpoint file execution in Cortex XSIAM.
- [Manage quarantined files](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/manage-quarantined-files.md): View, restore, and delete quarantined endpoint files in Cortex XSIAM.
- [Review WildFire analysis details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/review-wildfire-analysis-details.md): Review WildFire verdicts and file analysis reports in Cortex XSIAM.
- [Import file hash exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/import-file-hash-exceptions.md): Import file hash exceptions into allow and block lists in Cortex XSIAM.
- [Cortex Assistant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/cortex-assistant.md): Use Cortex Assistant in Cortex XSIAM to triage, investigate, and remediate security cases.
- [Cortex Assistant layout](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/cortex-assistant/cortex-assistant-layout.md): Navigate the Cortex Assistant layout to investigate security data in Cortex XSIAM.
- [Cortex Assistant capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/cortex-assistant/cortex-assistant-capabilities.md): Use Cortex Assistant capabilities to investigate and respond to threats in Cortex XSIAM.
- [Response actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions.md): Use Cortex XSIAM response actions to contain threats and remediate affected endpoints.
- [Initiate a Live Terminal session](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/initiate-a-live-terminal-session.md): Start a Live Terminal session to investigate and manage remote endpoints in Cortex XSIAM.
- [Isolate an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/isolate-an-endpoint.md): Isolate compromised endpoints to contain threats and protect your network with Cortex XSIAM.
- [Pause endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/pause-endpoint-protection.md): Temporarily pause Cortex XSIAM endpoint protection for approved troubleshooting or maintenance tasks.
- [Run agent scripts on an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/run-agent-scripts-on-an-endpoint.md): Run agent scripts to investigate, manage, and remediate endpoints from Cortex XSIAM.
- [Remediate changes from malicious activity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/remediate-changes-from-malicious-activity.md): Use Cortex XSIAM to remediate endpoint changes caused by malicious activity.
- [Search and destroy malicious files](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/search-and-destroy-malicious-files.md): Use Cortex XSIAM to find and remove malicious files across managed endpoints.
- [Manage external dynamic lists](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/manage-external-dynamic-lists.md): Manage external dynamic lists to share indicators with network security products with Cortex XSIAM.
- [Collect a memory image](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/collect-a-memory-image.md): Collect endpoint memory images in Cortex XSIAM for forensic investigation and analysis.
- [Forensics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics.md): Use the Cortex XSIAM Forensics add-on to collect, analyze, and document endpoint evidence.
- [Forensic investigations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/forensic-investigations.md): Use Cortex XSIAM forensic investigations to organize endpoint hunt and triage collections.
- [Manage an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation.md): Manage Cortex XSIAM forensic investigations, collections, alerts, evidence, exports, and access controls.
- [Create a new investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/create-a-new-investigation.md): Create forensic investigations to organize collections, evidence, alerts, and user access with Cortex XSIAM.
- [Edit an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/edit-an-investigation.md): Update a Cortex XSIAM forensic investigation's name, description, and user permissions.
- [Close an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/close-an-investigation.md): Close, reopen, or permanently delete Cortex XSIAM forensic investigations and their collections.
- [User permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/user-permissions.md): Control access to Cortex XSIAM forensic investigations with RBAC and scope-based permissions.
- [Data collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection.md): Collect endpoint forensic evidence in Cortex XSIAM through hunt and triage collections.
- [Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting.md): Use Cortex XSIAM hunt collections to search for targeted activity across many endpoints.
- [Create a hunt](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting/create-a-hunt.md): Create Cortex XSIAM hunt collections for scheduled or one-time endpoint artifact searches.
- [Hunt results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting/hunt-results.md): Analyze Cortex XSIAM hunt results across collected endpoint forensic artifacts.
- [Hunt status](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting/hunt-status.md): Monitor Cortex XSIAM hunt searches and results across targeted endpoints.
- [Triage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage.md): Use Cortex XSIAM triage collections for in-depth forensic analysis of specific endpoints.
- [Create a triage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/create-a-triage.md): Create Cortex XSIAM triage collections for detailed online and offline endpoint evidence gathering.
- [Upload an offline triage package](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/upload-an-offline-triage-package.md): Upload offline triage packages to Cortex XSIAM for forensic data ingestion and analysis.
- [Offline triage collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/offline-triage-collection.md): Collect Cortex XSIAM forensic evidence from offline endpoints without an installed agent.
- [Triage results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/triage-results.md): Review Cortex XSIAM triage alerts, artifacts, and endpoint forensic timelines.
- [Triage status](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/triage-status.md): Track Cortex XSIAM triage collection and ingestion status for endpoint artifacts.
- [Configure collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/configure-collection.md): Configure Cortex XSIAM hunt and triage artifact collection criteria and filters.
- [Analysis and documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/analysis-and-documentation.md): Analyze Cortex XSIAM forensic evidence through issues, timelines, and key assets.
- [Export](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/export.md): Export Cortex XSIAM forensic collection data for retention or offline analysis.
- [Notebooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/notebooks.md): Leverage the data collected by Cortex XSIAM using Jupyter Notebooks' data analysis and visualization capabilities within your existing security infrastructure.
- [Manage datasets in Notebooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/notebooks/manage-datasets-in-notebooks.md): Create and manage Cortex XSIAM Notebook datasets for queries, rules, and access control.
- [Notebooks scheduler](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/notebooks/notebooks-scheduler.md): Schedule Cortex XSIAM Notebook jobs to automate recurring data enrichment.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries.md): Build XQL queries with Query Builder for investigation and analysis in Cortex XSIAM.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/about-the-query-builder.md): Understand how Query Builder supports XQL queries and data analysis in Cortex XSIAM.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries.md): Build XQL queries using Query Builder tools and workflows in Cortex XSIAM.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md): Get started building XQL queries in Query Builder with Cortex XSIAM.
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md): Query Builder features help you to create and refine XQL queries in Cortex XSIAM.
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md): Review XQL query best practices for efficient, accurate results when creating queries in Cortex XSIAM.
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md): Understand expected field values and results in Cortex XSIAM XQL queries.
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/create-xql-query.md): Create and run XQL queries with Query Builder in Cortex XSIAM.
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md): Review and analyze XQL query results in the Cortex XSIAM Query Builder.
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md): Translate searches and query logic into XQL with Cortex XSIAM .
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/graph-query-results.md): Visualize XQL query results as graphs for faster analysis with Cortex XSIAM.
- [Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates.md): Use Cortex XSIAM Query Builder templates to query datasets without writing XQL.
- [Get started with Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/get-started-with-query-builder-templates.md): Get started with Cortex XSIAM Query Builder templates for guided data queries.
- [Considerations for using Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/considerations-for-using-query-builder-templates.md): Review Cortex XSIAM Query Builder template requirements and limitations.
- [Create a query from a template](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/create-a-query-from-a-template.md): Create data queries from Query Builder templates in Cortex XSIAM.
- [Run a free text query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/run-a-free-text-query.md): Run free-text queries with Query Builder templates in Cortex XSIAM.
- [Query Builder template examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/query-builder-template-examples.md): Explore Cortex XSIAM Query Builder template examples for common data queries.
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/overview-of-the-query-center.md): Monitor in-progress and completed Cortex XSIAM queries in Query Center.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md): Edit and run Cortex XSIAM queries from Query Center.
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/overview-of-the-query-center/query-center-reference-information.md): Reference Cortex XSIAM Query Center fields, statuses, and query details.
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-scheduled-queries.md): Create and manage scheduled queries for recurring analysis in Cortex XSIAM.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md): Review scheduled query settings, statuses, and run details in Cortex XSIAM .
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-your-personal-query-library.md): The Query Library is a personal library for saving and managing your queries in Cortex XSIAM.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/xql-macros.md): Use XQL macros to reuse query logic and simplify searches in Cortex XSIAM.
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-your-macros.md): Create and manage XQL macros for reusable query logic in Cortex XSIAM.
- [Federated Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search.md): Use Federated Search to query supported external data sources in Cortex XSIAM.
- [Federated Search configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search/federated-search-configuration.md): Configure Cortex XSIAM Federated Search connections for external data sources.
- [Query using Federated Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search/query-using-federated-search.md): Query external data sources with Federated Search in Cortex XSIAM.
- [Manage external datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search/manage-external-datasets.md): Manage external datasets used by Federated Search in Cortex XSIAM.
- [Legacy Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder.md): Use the Cortex XSIAM Legacy Query Builder to query security data entities.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-authentication-query.md): Create legacy authentication queries to investigate login activity in Cortex XSIAM.
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-event-log-query.md): Create legacy event log queries to investigate system activity in Cortex XSIAM.
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-file-query.md): Create legacy file queries to investigate file activity in Cortex XSIAM.
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-image-load-query.md): Create legacy image load queries to investigate loaded modules in Cortex XSIAM.
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-network-connections-query.md): Create legacy network connection queries to investigate endpoint traffic in Cortex XSIAM.
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-network-query.md): Create legacy network queries to investigate network activity in Cortex XSIAM.
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-process-query.md): Create legacy process queries to investigate process activity in Cortex XSIAM.
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-registry-query.md): Create legacy registry queries to investigate registry activity in Cortex XSIAM.
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/query-across-all-entities.md): Create legacy queries across all supported security data entities in Cortex XSIAM.
- [Research a known threat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/research-a-known-threat.md): Cortex XSIAM enables you to investigate any threat, also referred to as a lead, which has been detected.
- [Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat.md): Chat with the Cortex Agentic Assistant in Cortex XSIAM using natural language prompts.
- [Get started with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/get-started-with-agentic-assistant-chat.md): Enable Agentic Assistant and access the chat interface in Cortex XSIAM.
- [Choose an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/choose-an-agentic-assistant-agent.md): Choose a system or custom agent for your chat in Cortex XSIAM.
- [Chat with an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-an-agentic-assistant-agent.md): Tips for chatting with the Cortex Agentic Assistant in Cortex XSIAM.
- [Chat with the Agentic Assistant from Slack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-the-agentic-assistant-from-slack.md): Enable chatting in Cortex XSIAM with an Agentic Assistant agent from Slack.
- [Create and run XQL queries with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/create-and-run-xql-queries-with-agentic-assistant-chat.md): Interact with Cortex Agentic Assistant agents to build and run XQL queries in Cortex XSIAM.
- [Use natural language to query and visualize your data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/use-natural-language-to-query-and-visualize-your-data.md): Prompt Cortex Agentic Assistant agents to create graphs and charts from its findings in Cortex XSIAM.
- [Manage chat history](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/manage-chat-history.md): Manage and navigate your past chats with the Cortex Agentic Assistant in Cortex XSIAM.
- [Asset management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management.md): Manage assets, inventory, groups, configurations, and risk scores in Cortex XSIAM.
- [Asset inventory overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-inventory-overview.md): Learn asset inventory concepts, features, and lifecycles in Cortex XSIAM.
- [All assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-assets.md): View and manage all discovered assets in Cortex XSIAM Asset Inventory.
- [All cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets.md): View and assess cloud assets and your cloud footprint in Cortex XSIAM.
- [Discovery Engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets/discovery-engine.md): Learn how Cortex XSIAM Discovery Engine identifies and discovers cloud assets.
- [Asset hierarchy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets/asset-hierarchy.md): Explore asset relationships and hierarchy views in Cortex XSIAM.
- [Asset classes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes.md): Explore Cortex XSIAM asset classes and the resources each class represents.
- [AI assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/ai-assets.md): View and investigate AI assets in Cortex XSIAM.
- [API assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/api-assets.md): View and investigate API assets in Cortex XSIAM.
- [Application assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/application-assets.md): View and investigate application assets in Cortex XSIAM.
- [Code and Supply Chain Security assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets.md): View code and supply chain security assets in Cortex XSIAM.
- [IaC resources assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/iac-resources-assets.md): View infrastructure-as-code resource assets in Cortex XSIAM.
- [Repository assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/repository-assets.md): View repository assets in Cortex XSIAM.
- [VCS organization assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/vcs-organization-assets.md): View VCS organization assets in Cortex XSIAM.
- [CI/CD pipeline assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/ci-cd-pipeline-assets.md): View CI/CD pipeline assets in Cortex XSIAM.
- [CI/CD instances assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/ci-cd-instances-assets.md): View CI/CD instance assets in Cortex XSIAM.
- [Software package assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/software-package-assets.md): View software package assets in Cortex XSIAM.
- [Compute assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets.md): View compute assets across your environment in Cortex XSIAM.
- [Container image assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/container-image-assets.md): View and investigate container image assets in Cortex XSIAM.
- [Serverless functions assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/serverless-functions-assets.md): View and investigate serverless function assets in Cortex XSIAM.
- [VM images assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/vm-images-assets.md): View and investigate virtual machine image assets in Cortex XSIAM.
- [Data assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/data-assets.md): View and investigate data assets in Cortex XSIAM.
- [Device assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/device-assets.md): View and investigate device assets in Cortex XSIAM.
- [External Surface assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets.md): View external surface assets discovered by Cortex XSIAM.
- [Website assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/website-assets.md): View and investigate website assets in Cortex XSIAM.
- [Service assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/service-assets.md): View and investigate service assets in Cortex XSIAM.
- [Domain assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/domain-assets.md): View and investigate domain assets in Cortex XSIAM.
- [Certificate assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/certificate-assets.md): View and investigate certificate assets in Cortex XSIAM.
- [External Surface attribution evidence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/external-surface-attribution-evidence.md): Review external surface attribution evidence in Cortex XSIAM.
- [Identity assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/identity-assets.md): View and investigate identity assets in Cortex XSIAM.
- [Network assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/network-assets.md): View and investigate network assets in Cortex XSIAM.
- [Security services assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/security-services-assets.md): View managed security service assets in Cortex XSIAM.
- [Asset groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-groups.md): Create and manage asset groups in Cortex XSIAM for filtering and access control.
- [Manage Risk Scores](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/manage-asset-scores.md): View and investigate user and host risk scores in Cortex XSIAM.
- [Asset configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations.md): Configure networks, application criteria, and asset roles in Cortex XSIAM.
- [Network configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/network-configuration.md): Configure your internal network parameters, trusted networks, and external IP ranges to help Cortex XSIAM identify and map your network assets.
- [Application criteria](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/application-criteria.md): Configure application criteria for asset management in Cortex XSIAM.
- [Asset Roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles.md): View and manage user and endpoint asset roles in Cortex XSIAM.
- [Manage Asset Roles for Endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-endpoints.md): Manage endpoint asset roles in Cortex XSIAM.
- [Manage Asset Roles for Users](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-users.md): Manage user asset roles in Cortex XSIAM.
- [Honey user](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-users/honey-user.md): Configure and manage honey users in Cortex XSIAM.
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/vulnerability-assessment.md): Assess asset vulnerabilities and associated risk in Cortex XSIAM.
- [Query the asset inventory via XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/query-the-asset-inventory-via-xql.md): Query asset inventory data with XQL in Cortex XSIAM.
- [Threat management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management.md)
- [Detection rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules.md): Learn how Cortex XSIAM detection rules identify threats using IOC, BIOC, and correlation logic.
- [What are detection rules?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules.md): Explore Cortex XSIAM IOC, BIOC, and correlation rules for detecting threats and generating issues.
- [What's an IOC?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc.md): Learn how Cortex XSIAM IOC rules detect known malicious or suspicious artifacts.
- [IOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/ioc-rule-details.md): Review Cortex XSIAM IOC rule fields, conditions, and detection behavior.
- [Create an IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/create-an-ioc-rule.md): Create Cortex XSIAM IOC rules to generate issues from known threat indicators.
- [What's a BIOC?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc.md): Learn how Cortex XSIAM BIOC rules detect suspicious endpoint and network behavior.
- [BIOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/bioc-rule-details.md): Review Cortex XSIAM BIOC rule fields, conditions, and detection behavior.
- [Create a BIOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/create-a-bioc-rule.md): Create Cortex XSIAM BIOC rules to detect suspicious behavior and generate issues.
- [Manage Global BIOC Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/manage-global-bioc-rules.md): Manage Cortex XSIAM Global BIOC rules for consistent detections across endpoints.
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule.md): Learn how Cortex XSIAM correlation rules detect relationships across events and data sources.
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/correlation-rule-details.md): Review Cortex XSIAM correlation rule settings, query logic, and issue generation.
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/create-a-correlation-rule.md): Create Cortex XSIAM correlation rules using XQL to detect patterns across data sources.
- [Field replacement syntax in correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rules.md): Use Cortex XSIAM field replacement syntax in correlation rule queries.
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/manage-correlation-rules.md): Manage Cortex XSIAM correlation rules, including rule settings, status, and configuration.
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/monitor-correlation-rules.md): Monitor Cortex XSIAM correlation rule runs, errors, and detection health.
- [Troubleshoot server errors in scheduled correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rules.md): Troubleshoot scheduled Cortex XSIAM correlation rule server errors and failed executions.
- [Manage IOC and BIOC rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/manage-ioc-and-bioc-rules.md): Manage Cortex XSIAM IOC and BIOC rules to maintain threat detections.
- [Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics.md): Learn how Cortex XSIAM Analytics detects anomalous behavior using analytics engines, sensors, and rules.
- [Analytics overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview.md): Learn how Cortex XSIAM Analytics establishes behavioral baselines, identifies anomalies, and creates issues for investigation.
- [Analytics engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-engine.md): Learn how the Cortex XSIAM Analytics engine analyzes data to detect anomalous behavior and generate issues.
- [Analytics sensors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-sensors.md): Explore Cortex XSIAM Analytics sensors that collect telemetry for behavioral baselines and anomaly detection.
- [Coverage of MITRE Attack tactics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/coverage-of-mitre-attack-tactics.md): Review Cortex XSIAM Analytics coverage of MITRE ATT\&CK tactics to understand detection visibility.
- [Review MITRE ATT\&CK framework coverage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/review-mitre-att-and-ck-framework-coverage.md): Review Cortex XSIAM Analytics coverage across the MITRE ATT\&CK framework, tactics, and techniques.
- [Analytics detection time intervals](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-detection-time-intervals.md): Understand Cortex XSIAM Analytics detection time intervals and their effect on anomaly identification.
- [Analytics issues and Analytics BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-issues-and-analytics-biocs.md): Learn how Cortex XSIAM Analytics issues and BIOCs identify anomalous activity for investigation.
- [Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/identity-analytics.md): Use Cortex XSIAM Identity Analytics to identify anomalous user and identity-related behavior.
- [View and manage Analytics rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/view-and-manage-analytics-rules.md): View and manage Cortex XSIAM Analytics rules that detect anomalous behavior and generate issues.
- [AI Detection & Response in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta.md): Use AI Detection & Response in Cortex XSIAM to identify and investigate AI-related security risks.
- [Data sources and supported services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/data-sources-and-supported-services.md): Review data sources and supported services for AI Detection & Response in Cortex XSIAM.
- [Collect prompt logs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs.md): Collect prompt logs in Cortex XSIAM to support AI Detection & Response monitoring and investigations.
- [Prompt log collection in AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-aws.md): Configure Cortex XSIAM to collect prompt logs from AWS for AI Detection & Response.
- [Enable prompt log collection in Azure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure.md): Enable Azure prompt log collection in Cortex XSIAM for AI Detection & Response monitoring.
- [Configure the Azure Event Hub collection in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-xsiam.md): Configure Azure Event Hub collection in Cortex XSIAM to ingest prompt logs for AI Detection & Response.
- [Set up prompt logging](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-logging.md): Set up prompt logging in Cortex XSIAM to collect AI interaction data for security monitoring.
- [Log HTTP data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-data.md): Configure Cortex XSIAM to collect HTTP data for AI Detection & Response monitoring and investigation.
- [Configure diagnostic settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settings.md): Configure Azure diagnostic settings for Cortex XSIAM prompt log collection and AI Detection & Response.
- [Extended Threat Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence.md): Explore Extended Threat Intelligence in Cortex XSIAM to research threats, investigate indicators, and strengthen security workflows.
- [XTI Threat Intel Library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-threat-intel-library.md): Explore the Cortex XSIAM XTI Threat Intel Library for Unit 42 threat actors, malware families, vulnerabilities, and reports.
- [XTI Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicators.md): Investigate, manage, and enrich threat indicators in Cortex XSIAM, including domains, IP addresses, URLs, and file hashes.
- [Threat intel context in cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md): Use Cortex XSIAM threat intelligence context to analyze indicators and Behavioral Threat Analysis findings in cases and issues.
- [XTI indicator rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicator-rules.md): Create Cortex XSIAM XTI indicator rules to detect known threat indicators and generate issues from matching data.
- [Threat intel investigation through XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-investigation-through-xql.md): Use Cortex XSIAM XQL to query XTI indicators, threat objects, and relationships for threat intelligence investigations.
- [Threat Intel Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-dashboard.md): Use the Cortex XSIAM Threat Intel Dashboard to monitor intelligence distribution, ingestion health, and emerging threats.
- [Using XTI with Threat Intel Agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-with-threat-intel-agent.md): Use the Cortex XSIAM Threat Intel Agent to list, enrich, and update Extended Threat Intelligence indicators.
- [Using XTI in playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-in-playbooks.md): Use Cortex XSIAM playbooks to automate XTI indicator triage, enrichment, and response with supported commands.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management.md): Manage threat indicators, feeds, enrichment, and detection workflows with Threat Intel Management.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management.md): Learn Threat Intel Management concepts, use cases, roles, and the indicator lifecycle.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Learn how Threat Intel Management centralizes indicators, enrichment, and investigation workflows.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Explore workflows for ingesting, enriching, investigating, and acting on threat indicators.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Understand the roles and responsibilities for configuring and operating Threat Intel Management.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md): Learn the indicator concepts, fields, types, and sources used in Threat Intel Management.
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Understand how indicators are created, enriched, managed, expired, and removed.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration.md): Configure feeds, indicator types, fields, extraction, enrichment, and indicator rules.
- [Configure Threat Intelligence feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/configure-threat-intelligence-feed-integrations.md): Connect threat intelligence feeds to ingest indicators into Cortex XSIAM.
- [Customize indicator fields and types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types.md): Customize indicator types and fields to organize threat intelligence data.
- [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type.md): Create custom indicator types and configure their profiles, scripts, and field mappings.
- [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/indicator-type-profile.md): Configure profile settings that define an indicator type's behavior and appearance.
- [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/formatting-scripts.md): Use formatting scripts to normalize indicator values before storage.
- [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/enhancement-scripts.md): Use enhancement scripts to add threat intelligence context to indicators.
- [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/reputation-scripts.md): Use reputation scripts to calculate or update an indicator's reputation.
- [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/reputation-commands.md): Configure integration commands that retrieve reputation data for indicators.
- [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/map-custom-indicator-fields.md): Map custom fields to indicator types for consistent indicator data.
- [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field.md): Create custom fields to store additional threat indicator information.
- [Indicator field structure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field/indicator-field-structure.md): Understand the structure and settings available for custom indicator fields.
- [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field/indicator-field-trigger-scripts.md): Use trigger scripts to run actions when indicator field values change.
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Classify and map extracted values to the appropriate indicator types and fields.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-extraction.md): Configure how Cortex XSIAM extracts indicators from tasks, scripts, and integrations.
- [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md): Choose how a playbook task extracts and creates indicators from its output.
- [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md): Prevent selected scripts or integrations from automatically extracting indicators.
- [Configure Threat Intelligence feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/configure-threat-intelligence-feed-integrations-1.md): Configure threat intelligence feed integrations and manage their indicator ingestion.
- [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Exclude selected indicators from enrichment to control processing and data usage.
- [Generate issues from indicators using indicator rules for prevention and detection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/generate-issues-from-indicators-using-indicator-rules-for-prevention-and-detection.md): Create rules that generate prevention or detection issues from matching indicators.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/export-indicators.md): Export threat indicators for use in external systems and workflows.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-management.md): Create, view, edit, and organize threat indicators throughout their lifecycle.
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation.md): Investigate indicators using verdicts, enrichment, relationships, expiration, and exclusions.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/indicator-verdict.md): Understand indicator verdicts and how they assess threat relevance.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): Extract indicators from data and enrich them with context from supported integrations.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire indicators when they no longer require active monitoring or matching.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): Create and manage relationships between indicators to capture threat context.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Delete unwanted indicators or exclude them from future ingestion and enrichment.
- [Attack surface management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management.md): Learn how to discover, monitor, and remediate external asset exposures with Cortex XSIAM attack surface management.
- [Learn about Attack Surface Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management.md): Learn about Cortex XSIAM Attack Surface Management (ASM) capabilities for finding, prioritizing, and remediating external asset exposures.
- [Network mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/network-mapping.md): Learn how Cortex XSIAM discovers, attributes, and validates internet-facing assets to map your public attack surface.
- [Scanning](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/scanning.md): Learn how Cortex XSIAM ASM scans internet-facing assets, monitors known assets, and identifies exposed services.
- [GeoIP data collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/geoip-data-collection.md): ASM in Cortex XSIAM uses GeoIP data to validate network distribution, identify location-based compliance risks, and route remediation efforts.
- [Attack Surface Management detections](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections.md): Learn about Cortex XSIAM Attack Surface Management detections, findings, and issues.
- [Attack surface rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/attack-surface-rules.md): Cortex XSIAM ASM uses attack surface rules to identify risks, generate findings, and manage severity.
- [Attack Surface Testing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/attack-surface-testing.md): Use Cortex XSIAM Attack Surface Testing to validate external asset exposure and detection coverage.
- [Externally inferred CVEs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/externally-inferred-cves.md): Use Cortex XSIAM to identify externally inferred CVEs affecting internet-facing assets and prioritize remediation.
- [Digital Risk Protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/digital-risk-protection.md): Use Cortex XSIAM Digital Risk Protection to identify external threats, exposure, and brand-related risks.
- [Attack surface assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-assets.md): Manage Cortex XSIAM attack surface assets and submit CSV requests to add or remove them.
- [Deploy ASM and Exposure Management enrichment and remediation automation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/deploy-asm-and-exposure-management-enrichment-and-remediation-automation.md): Enable the Exposure Management playbooks in Cortex XSIAM to automate ASM and vulnerability issue enrichment and remediation.
- [ASM enrichment of cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/asm-enrichment-of-cloud-assets.md): ASM enrichment of cloud assets in Cortex XSIAM provides visibility into all the assets in your cloud infrastructure that are exposed to the internet.
- [Emerging Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/emerging-vulnerabilities.md): Identify external exposures linked to emerging vulnerabilities, zero-day exploits, and global threat events on the Emerging Vulnerabilities page in Cortex XSIAM.
- [Global Lookup](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/global-lookup.md): Query and enrich global internet scan data for IP addresses, domains, and certificate hashes in Cortex XSIAM.
- [Vulnerability management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management.md): Manage, prioritize, and remediate vulnerabilities across endpoints, code, and cloud with Cortex XSIAM.
- [Vulnerability management in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-management-in-cortex-xsiam.md): Use Cortex XSIAM Vulnerability Management to identify, assess, prioritize, and remediate vulnerabilities across your environment.
- [Cortex Vulnerability Risk Score](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/cortex-vulnerability-risk-score.md): Learn how Cortex XSIAM calculates and displays Cortex Vulnerability Risk Scores for prioritized remediation.
- [Vulnerability policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-policies.md): Configure Cortex XSIAM vulnerability policies to define actions for selected vulnerability findings.
- [Investigate and remediate vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/investigate-and-remediate-vulnerabilities.md): Investigate, prioritize, and remediate vulnerabilities through Cortex XSIAM issues, findings, and vulnerable assets.
- [Vulnerability Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-intelligence.md): Use Cortex XSIAM Vulnerability Intelligence for real-time data and threat intelligence from certified sources.
- [Emerging Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/emerging-vulnerabilities.md): Use Cortex XSIAM Emerging Vulnerabilities to research, assess, and respond to zero-day exploits and global threats.
- [Recast CVSS scores and CVSS severities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/recast-cvss-scores-and-cvss-severities.md): Recast CVSS scores and severities in Cortex XSIAM to align vulnerability risk with organizational priorities.
- [Exposure management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management.md): Assess, prioritize, and remediate organizational exposures with Cortex XSIAM Exposure Management.
- [Learn about Exposure Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/exposure-management.md): Learn how Cortex XSIAM Exposure Management unifies exposure data, prioritization, and remediation workflows.
- [Get started with Exposure Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/get-started-with-exposure-management.md): Set up Cortex XSIAM Exposure Management with scanners, integrations, policies, security controls, and automation.
- [Ingest assets and vulnerabilities from third-party applications](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/ingest-assets-and-vulnerabilities-from-third-party-applications.md): Ingest assets and vulnerabilities from third-party applications into Cortex XSIAM Exposure Management.
- [Security controls](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/security-controls.md): Use Cortex XSIAM security controls to assess compensating-control effectiveness and residual exposure risk.
- [Cortex Network Scanner](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/cortex-network-scanner.md): Deploy Cortex XSIAM Network Scanner to discover assets, assess vulnerabilities, and investigate issues.
- [Exposure Management Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/exposure-management-command-center.md): Use Cortex XSIAM Exposure Management Command Center to prioritize findings and track remediation.
- [Cortex Advanced Email Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security.md): Configure, monitor, and respond to email security threats with Cortex XSIAM Advanced Email Security.
- [Cortex Advanced Email Security module overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-overview.md): Learn how Cortex XSIAM Advanced Email Security detects, investigates, and remediates email threats.
- [Cortex Advanced Email Security module architecture and data flow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-architecture-and-data-flow.md): Understand Cortex XSIAM Advanced Email Security architecture, integrations, and email threat data flow.
- [Getting started with the Cortex Advanced Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/getting-started-with-the-cortex-advanced-email-security-module.md): Get started with Cortex XSIAM Advanced Email Security using the deployment workflow and setup requirements.
- [Deploy and configure the Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/deploy-and-configure-the-email-security-module.md): Deploy and configure Cortex XSIAM Advanced Email Security to protect your email environment.
- [Cortex Advanced Email Security threat detection and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-threat-detection-and-issues.md): Use Cortex XSIAM Advanced Email Security to detect email threats and investigate related issues.
- [Email Security Analytics Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-threat-detection-and-issues/email-security-analytics-rules.md): Configure Cortex XSIAM Email Security Analytics Rules to detect suspicious email activity and create issues.
- [Investigate and respond to email security issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/investigate-and-respond-to-email-security-issues.md): Investigate and respond to email security issues with Cortex XSIAM Advanced Email Security.
- [Automate remediation for the Cortex Advanced Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module.md): Automate Cortex XSIAM Advanced Email Security remediation workflows for detected email threats.
- [Email Remediation Response Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module/email-remediation-response-rules.md): Configure Cortex XSIAM Email Remediation Response Rules to automate responses to email threats.
- [Email Security Remediation Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module/email-security-remediation-action-center.md): Use the Cortex XSIAM Email Security Remediation Action Center to track and manage response actions.
- [Email Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/email-command-center.md): Use the Cortex XSIAM Email Command Center to monitor email security status and threat activity.
- [Malicious Email Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/malicious-email-inventory.md): Use Cortex XSIAM Malicious Email Inventory to investigate and manage detected malicious messages.
- [Mailbox Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/mailbox-inventory.md): Use Cortex XSIAM Mailbox Inventory to view and investigate protected email mailboxes.
- [Advanced Email Security module security and compliance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/advanced-email-security-module-security-and-compliance.md): Review Cortex XSIAM Advanced Email Security security controls and compliance considerations.
- [Identity Threat Detection and Response (ITDR)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr.md): Use Cortex XSIAM Identity Threat Detection and Response to detect, investigate, and respond to identity threats.
- [Get started with ITDR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/get-started-with-itdr.md): Get started with Cortex XSIAM Identity Threat Detection and Response to protect identities and investigate threats.
- [Manage role based access control (RBAC) in ITDR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/manage-role-based-access-control-rbac-in-itdr.md): Manage role-based access control in Cortex XSIAM ITDR to control access to identity security capabilities.
- [Monitor user risk exposure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/monitor-user-risk-exposure.md): Monitor user risk exposure in Cortex XSIAM ITDR to identify risky identity activity and prioritize response.
- [Investigate user risk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/investigate-user-risk.md): Investigate user risk in Cortex XSIAM ITDR to assess identity threats and guide response actions.
- [Manage user asset roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/asset-roles.md): Manage user asset roles in Cortex XSIAM ITDR to classify identities and strengthen identity risk analysis.
- [Improve Active Directory posture with AD-SPM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/active-directory-security-posture-management.md): Use Cortex XSIAM ITDR AD-SPM to improve Active Directory posture and reduce identity attack risks.
- [Enforce dynamic access control with CAP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/conditional-access-policy.md): Use Cortex XSIAM ITDR Conditional Access Policies to enforce dynamic access control and reduce identity risk.
- [Prevent malicious LDAP queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/prevent-malicious-ldap-queries.md): Use Cortex XSIAM ITDR to detect and prevent malicious LDAP queries that target Active Directory.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
