For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSIAM

Action Center permissions

Manage access to Cortex XSIAM endpoint response actions and action history.

Action Center permissions

In the Action Center, you can initiate and monitor actions on your endpoints. You can limit access to the Action Center (Investigation & ResponseResponseAction Center) and response actions (outside the Action Center). When you select View/Edit, you can set additional permissions.

For more information, see Overview of the Action Center.

Permission
Description
Roles Example

None

No access to the Action Center, and response action buttons are hidden.

SOC Tier-1 Analysts: View action history, isolation status, and quarantine lists, but cannot execute any actions.

View

Read-only access. You can see the action history and results, but cannot initiate any actions. All action buttons are hidden.

IT Admin: Response actions (isolate, terminate process, quarantine, file retrieval, file search, destroy files) are security response functions. Granting IT Admins access to these actions creates significant risk — they could isolate endpoints or destroy files.

View/Edit

Full control to initiate, retry, or cancel actions. This is a high-privilege permission that enables the Response in Endpoint Detection and Response (EDR). Unchecked actions remain view only.

When Action Center is set to View/Edit, the following action checkboxes become available. Each checkbox controls whether the user can execute that specific action type.

SOC Tier 2 and 3 Analysts, Threat Hunters, and Security Engineers have full access with granular controls.

Warning

Action Center sub-permissions

Sub-permission
Description
Roles Example

Isolate

Isolates an endpoint from the network while maintaining communication with the Cortex XSIAM tenant.

  • Checked: Full access to Isolate in all menus, such as Isolate when defining an action in the Action Center and isolating endpoints on the Vulnerability Assessment page. Initiate, cancel, and edit isolation with comments.

  • Unchecked: Users can view isolation history and status in the Action Center, but cannot initiate or cancel isolation.

All Responders/Admins. The SOC Tier-1 Analyst should escalate isolation decisions to Tier 2, but can monitor isolation status.

Terminate Process

Terminates running processes on endpoints. Can terminate individual processes by process ID or entire causality chains (all processes from a malicious parent). This stops active malicious activity without requiring full endpoint isolation.

The Causality view is available from the Cases or Issues pages, or from the Query Results (Investigation & Response)Query Builder → **Build an XQL Query)**after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view.

  • Checked: Full access to the Terminate Process option in the Causality View. Users can initiate termination from remediation suggestions.

  • Unchecked: Users can view process termination history in Action Center, but can't initiate termination.

Tip

Consider adding the Remedation permission. Terminate Process appears in the Remediation Suggestions panel. Enabling both provides a complete response workflow.

All Responders/Admins. The SOC Tier-1 Analyst should escalate process termination to Tier 2, but can view termination history.

Quarantine

Moves malicious or suspicious files to a secure quarantine folder on the endpoint, preventing execution while preserving the file for analysis. Quarantined files can be restored if determined to be false positives.

  • Checked: Full access to quarantine files in the Action Center and in the Causality View. Users can restore quarantined files, can add a hash to the allow list during restore, and can view quarantine details per endpoint.

  • Unchecked: User can view the File Quarantine tab in the Action Center and view quarantine files in the Causality View, but can't quarantine or restore files.

All Responders/Admins. SOC Tier-1 Analysts and Threat Hunters need to hand off to SOC Tier 2 and 3 Analysts for containment.

File Retrieval

Retrieves files from endpoints for forensic analysis. Files are uploaded to Cortex XSIAM where they can be downloaded for examination, malware analysis, or evidence preservation.

  • Checked: Users can retrieve files from an endpoint in Action Center, from file search results, and view/download files from Action Center and from Cases.

  • Unchecked: Users can view retrieval history in Action Center, but can't download retrieved files.

Tip

Consider adding the following permissions:

File Search. File Retrieval is typically initiated from File Search results. Without File Search, retrieval options are limited.

All Responders/Admins. SOC Tier-1 and 2 Analysts and Threat Hunters need to hand off to SOC Tier 3 Analysts or the Forensics Team for containment.

File Search

Searches for files across all managed endpoints by hash (SHA256, MD5), file path, or file name patterns. Used to determine file prevalence, locate IOCs, and identify affected endpoints.

Notice

Requires the Host Insights add-on, which is included in Cortex XSIAM Enterprise and Premium licenses.

  • Checked: Full access to File Search when defining an action in the Action Center. Users can search files by hash, path, or pattern.

  • Unchecked: Users can view search history in Action Center, but can't rerun file searches.

Tip

Consider adding File Retrieval. After finding files, users often need to retrieve them for analysis.

All Responders/Admins. The SOC Tier-1 Analyst should escalate to the SOC Tier 2 Analyst.

Destroy Files

High risk. Permanently and irreversibly deletes files from endpoints. This is a destructive action that cannot be undone. Used to remove persistent malware or malicious files that cannot be quarantined.

  • Checked: Full access to take action to destroy files in the Action Center. Users can destroy files from file search results and permanently delete files from endpoints.

  • Unchecked: Users can view the destroyed file history in the Action Center, but can't permanently delete files.

SOC Tier-3 Analysts and Security Admins. This is a high-risk action that permanently deletes files and cannot be reversed.

Allow List/Block List

Exempt or block files matching specified hashes across the environment.

  • Checked: Full access to take action on the Allow List or Block List, such as adding hashes to the allow/block list when defining an action in the Action Center, editing list entries, and moving hashes between lists.

  • Unchecked: Users can view the Allow List and Block List tabs in Action Center, see hash entries and status, but can't add, edit, or delete allow/block lists.

SOC Tier-3 Analysts, Threat Hunters, Security Engineers, and Security Admins who manage hash-based prevention policies.

Disable Response Actions

High risk. Temporarily disables or pauses endpoint protection and response capabilities. This weakens endpoint security and should be used only for troubleshooting or specific operational requirements.

You can view disabled response actions by going to InventoryEndpointsAll Endpoints. If you have View/Edit permissions, pivot (right-click) an endpoint that isn't an iOS endpoint, and select Endpoint ControlDisable Capabilities.

  • Checked: Users can disable specific response actions on endpoints, pause endpoint protection temporarily, and can re-enable disabled actions.

  • Unchecked: Users can view current response action status, see which actions are disabled, but can't modify response action settings or pause endpoint protection.

Security Admins only. Disabling response actions reduces security posture and should require proper change management approval.

Remediation

Execute automated actions to reverse malicious system changes (registry, files, processes).

  • Checked: Full access to Remediation Suggestions from Case View. Users can initiate remediation from Causality View and can execute file restore, registry restore, and process termination.

  • Unchecked: Users can view remediation history in Action Center, see remediation results and status, but can't initiate remediation actions.

All Responders/Admins. The SOC Tier 1 Analyst should escalate to Tier 2 Analysts.

Delete Quarantine Files

High risk. Permanently deletes files from the quarantine folder on endpoints. Unlike restoring quarantined files, this action removes the files entirely and cannot be undone.

  • Checked: Full access to delete files from the File Quarantine page, enabling a user to permanently remove quarantined files from endpoints.

    The delete option only appears in the Aggregated by SHA256 tab in File Quarantine.

  • Unchecked: Users can view the quarantined files list in the Action Center, including file details and status, but can't permanently delete quarantined files.

Tip

Consider adding Quarantine. Delete Quarantine Files operates on the quarantine list. Without the Quarantine checkbox, users can still see the list, but the Delete option requires the quarantine view to be meaningful.

  • SOC Tier-3 Analyst: May need to permanently remove confirmed malware after thorough analysis. Has experience for informed deletion decisions.

  • Security Engineer: Manages quarantine storage, cleans up confirmed malware, and maintains endpoint health. Understands implications of permanent deletion.

Agent Scripts Library permissions

The Agents Script Library in the Action Center (Investigation & ResponseResponseAction CenterAgent Script Library) enables security teams to create, manage, and execute Python scripts on endpoints for response actions, forensic collection, and custom automation.

Permission
Description
Roles Example

None

No access to the Agent Script Library. Users cannot run scripts on endpoints, access script execution history, create, edit, or delete scripts.

View

Users can access the Agent Script Library and view the script list, details, and code. Download the script code and definitions file and view the script history and results.

SOC Analyst Tier-1: Should have visibility into scripts and execution history, but no execution capabilities.

View/Edit

When set to View/Edit, the following action checkboxes become available:

  • Run Standard Script

  • Run High Risk Script

  • Script Configurations

SOC Tier 2 and 3 Analysts, Threat Hunters, and Security Engineers should have full access with granular controls.

Agent Script Sub-permissions

Sub-permission
Description
Roles Example

Run Standard Scripts

Enables execution of standard scripts, which are lower-risk operations that don't make significant system changes, such as data collection, log retrieval, or read-only queries.

  • Checked: Full access to run standard scripts in the Action Center (where the Outcome column is set to Standard), when defining an action (select Run Endpoint Script), Agent Management, and can rerun standard script executions and use interactive script mode for standard scripts.

  • Unchecked: Can view standard scripts in the Agent Script Library, but cannot execute standard scripts.

SOC Tier 2 and 3 Analysts, Security Engineers, Threat Hunters.

Run High-Risk Scripts

Enables execution of scripts marked as High-Risk, which can make significant system changes, including file modifications, process termination, registry changes, or system configuration alterations. These scripts require elevated permissions due to their potential impact.

  • Checked: Full access to run high-risk scripts in the Action Center (where the Outcome column is set to High-Risk), when defining an action (select Run Endpoint Script), Agent Management, and can rerun High-Risk script executions and use interactive script mode for standard scripts.

  • Unchecked: Can view high-risk scripts in the Agent Script Library, but cannot execute standard scripts.

Tip

Consider adding Run Standard Scripts. High-risk scripts permission is typically granted alongside standard scripts.

SOC Tier-3 Analysts, Security Engineers, and Threat Hunters.

Script Configurations

Controls the ability to create, edit, clone, and delete scripts in the Agents Script Library. This is separate from the ability to run scripts.

  • Checked: Full script management capabilities, including creating, editing, deleting, and saving a script

    Note

    Only local scripts (created in the tenant) can be edited or deleted. Scripts from content packs can only be viewed or copied.

  • Unchecked: Can only view and download scripts.

Security Engineer

Required and recommended permissions

Consider adding the following permissions:

Permission
Permission Level
Reason

Action Center

View

Without Action Center access, users cannot reach the Script Library page. Required.

Cases & Issues

View

Strongly recommended as the script execution results link to cases.

Agent Administrations

View

Required for endpoint selection for script execution.

Live Terminal

View

Often used together. Run scripts for data collection and then use Live Terminal for hands-on investigation. Recommended.

Last updated

Was this helpful?