> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md).

# Cortex XSOAR navigation cheat sheet

The main menu for Cortex XSOAR includes:

| Feature                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| My Incidents             | Includes your favorites, incidents you own, and incidents you have participated in.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Dashboards & Reports     | <p>Dashboards include visualized data, including Cortex XSOAR incident, indicator, and system data, displayed for a rolling, relative time frame. Dashboards enable you to track metrics, analyze trends that appear in your Cortex XSOAR data, and identify areas of concern. Dashboards can be customized with widgets that focus on the data points most relevant to your organization.</p><p>Reports also contain visualized data, but can be run for a specific time frame and automatically sent via email to internal or external stakeholders.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Incidents                | <p>On the <strong>Incidents</strong> page, you can search for and interact with incidents that have been ingested from third-party integrations or manually created in Cortex XSOAR.</p><p>Incidents enable you to organize your investigation and response work. Each incident is a self-documenting IR workbench where you can view incident details in a custom layout, run scripts and playbooks on the incident, create notes, tag evidence items, and more.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Threat Intel (Indicators | <p>The <strong>Threat Intel</strong> page displays a table or summary view of all indicators.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If you do not have a TIM license, the page is titled <strong>Indicators</strong>. Most Threat Intel features are available only with a Cortex XSOAR Threat Intelligence license.</p></div><p>Search, review, and interact with indicators including IPs, domains, URLs, hashes. Research threats and correlate indicators of compromise across multiple incidents. Track indicator properties such as their verdict and add tags to apply your own indicator classification and grouping logic.</p>                                                                                                                                                                                                                                                                                                                                                                                                         |
| Playbooks                | <p>On the <strong>Playbooks</strong> page, you can browse, create, and customize Cortex XSOAR playbooks, which are workflows that link together ordered response steps including scripts, manual tasks, and communication tasks.</p><p>Playbooks enable you to standardize and orchestrate your IR processes. A playbook helps ensure users follow a consistent response process, automates mundane response tasks, ties together your different IR tools, and gathers all relevant incident context and enrichment data in one centralized place.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You can copy/paste tasks from one playbook to another by using keyboard shortcuts.</p></div>                                                                                                                                                                                                                                                                                                                                                           |
| Scripts                  | On the **Scripts** page, you can browse, create, and customize Python, PowerShell, and JavaScript scripts for use in Cortex XSOAR. View the code for out-of-the-box scripts in order to troubleshoot, better understand, or build upon them. You can create custom scripts to extend Cortex XSOAR’s functionality to achieve your automation goals.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Jobs                     | Jobs allow you to schedule playbooks to run on a recurring basis, either at a specific time or triggered by new indicators ingested from a feed integration. With jobs, you can automate actions you would normally take on a recurring basis, such as compiling malicious indicators and sending them to the SOC for verification before they are blocked.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Marketplace              | <p>The Cortex Marketplace provides access to hundreds of integrations that extend the functionality of Cortex XSOAR and allow communication with third-party services. Includes the following:</p><ul><li>Browse: The central location for searching and installing Cortex XSOAR content, including playbooks, integrations, and scripts.</li><li>Installed content packs: View and manage your installed Cortex XSOAR content packs.</li><li>Contributions: Contribute content that you have created, including playbooks, integrations, and scripts.</li><li>Deployment Wizard: The Deployment Wizard significantly reduces the time required to set up your use case. It guides you through the process of setting up your content pack for your specific use case, Relevant for phishing and malware content packs.</li></ul>                                                                                                                                                                                                                                                                                              |
| Settings & Info          | <p>Includes the following:</p><ul><li>Cortex Gateway: Cortex Gateway allows you to activate new tenants and view and manage existing tenants and tenants available for activation that are allocated to your <a href="https://support.paloaltonetworks.com/">Customer Support Portal account</a>.</li><li>Cortex XSOAR License: View information about the licenses, expiry dates, and the number of licensed and active users.</li><li>Management Audit Logs: View and export a historical audit trail of user actions taken in Cortex XSOAR.</li><li>Settings: Access the detailed Settings menu.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Tenant Navigator         | <p>if you have more than one Customer Support Portal account, you can view and pivot to all the tenants that you have access to, by clicking <strong>Tenant Navigator</strong>. In the <strong>Tenant Navigator</strong>, you can do the following:</p><ul><li><p>View existing tenants</p><p>The currently chosen tenant is marked by a green Active Session label. The tenants are grouped according to Customer Support Portal accounts.</p></li><li><p>Pivot to an existing tenant</p><p>The current tenant is marked by a green <strong>Active Session</strong> label.</p></li><li><p>Search for a tenant</p><p>If there are more than 5 tenants, a search option is available. If there are more than 5 tenants within a specific account, a list of tenants is available for that Customer Support Portal account.</p></li><li>Pivot to Cortex Gateway</li><li>Pivot to the Customer Support Portal</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If you do not have more than one account, the Tenant Navigator is unavailable.</p></div> |
| User Menu (username)     | <ul><li>About: Detailed information on Cortex XSOAR version.</li><li>User preferences: Change default landing page and configure notifications via your preferred communication method. Customize your display to suit your preferences. Get notified of Cortex XSOAR events of interest to you, such as being assigned an incident. Disable unwanted notifications.</li><li>Set Yourself as Away: Change your away/active status.</li><li>Log out: Log out of the Customer Support Portal</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
