Data Detection and Response
Data Detection and Response (DDR) detects and responds to threats against your data. It uses behavioral baselining and anomaly detection on top of data classification, ensuring each alert includes context about what was accessed, its sensitivity, and the data owner.
DDR baselines normal behavior for human and non-human identities and detects deviations across cloud, SaaS, and AI infrastructure. You can then respond to confirmed threats—for example, by revoking access, or escalating to the SOC.
View DDR Detections
DDR detections are driven by specialized analytics rules focused on data risks, such as mass downloads, risky data sharing, and ransomware behavior.
These rules are managed automatically to maintain a focused data-security experience. You can view analytics rules in Threat Management → Detection Rules → Analytics Rules, and you can view and manage all resulting detections within the Cases and Issues views. Detections are automatically tagged with 'DDR' to help you prioritize data-specific risks.
For a detailed description of each analytics alert, the behavior it identifies, and its required data sources, see the Cortex Analytics Alert Reference.
Supported data sources for threat detection
DDR threat detection relies on continuous log ingestion from your cloud and SaaS environments. Once onboarded, these logs provide the raw data required by the Cortex Analytics engine to baseline normal user behavior and identify anomalies across your entire data estate, such as unauthorized data access or mass file downloads.
For detailed instructions on how to ingest logs from each data source, see the following articles:
Last updated
Was this helpful?
