# Cortex Documentation Portal

## Home

- [Home](https://cortex-docs.paloaltonetworks.com/readme.md): Welcome to your team’s developer platform

## Cortex XSIAM

- [Cortex XSIAM Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/cortex-xsiam-documentation.md): Find Cortex XSIAM product guides, references, and release information.

## Cortex XDR

- [Cortex XDR Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs/readme.md): Find Cortex XDR product guides, references, and release information.

## Cortex Cloud

- [Cortex Cloud Documentation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs/readme.md): Find Cortex Cloud product documentation, references, and release information.

## Cortex XDR Agent

- [Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-docs/readme.md): Cortex XDR Agent guides, releases, compatibility, and reference information.

## Cortex AgentiX

- [Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-agentix.md): Cortex AgentiX documentation, release notes, and API references.
- [What's New](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/whats-new.md): Latest Cortex AgentiX release notes.
- [Cortex Gateway Admin Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-gateway-admin-guide.md): Manage permissions, RBAC, and user groups across Cortex products.
- [Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/release-notes.md): Latest Cortex AgentiX features and known issues.
- [Cortex AgentiX Documentation](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-agentix-documentation.md): Product guides for Cortex AgentiX.
- [API Reference Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/api-reference-guide.md): Cortex AgentiX API reference.

## Cortex Data Security

- [Cortex Data Security](https://cortex-docs.paloaltonetworks.com/cortex-data-security-docs/cortex-data-security.md)

## Cortex XSOAR

- [Cortex XSOAR Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs/readme.md): Explore Cortex XSOAR guides, releases, and product resources.

## Cortex Xpanse

- [Cortex Xpanse Expander](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/readme.md): Find Cortex Xpanse Expander guides, APIs, and release information.

## Cortex XSIAM Documentation

- [Navigate the Cortex XSIAM docs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/readme.md): Start here for a visual overview of the main Cortex XSIAM documentation areas.
- [Get started with Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/get-started-cortex-xsiam.md): Learn about Cortex XSIAM and the key integrated capabilities.
- [Cortex XSIAM architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/get-started-cortex-xsiam/cortex-xsiam-architecture.md): Explore the Cortex XSIAM architecture, including SIEM, XDR, SOAR, cloud security, XDL data ingestion, and Broker VM.
- [Agentic AI in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam.md): Use the Cortex Agentic Assistant in Cortex XSIAM to investigate cases, perform threat hunting, and create scripts. Embed and run LLM prompts in playbooks. View AI case summaries.
- [Agentic Assistant use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam/agentic-assistant-use-cases.md): Recommended prompts to automate your SOC using the Cortex Agentic Assistant in Cortex XSIAM.
- [Compare Agentic Assistant with Cortex Assistant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam/compare-agentic-assistant-with-cortex-assistant.md): Feature comparison between Cortex Agentic Assistant and Cortex Assistant in Cortex XSIAM.
- [Agentic Assistant security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam/agentic-assistant-security.md): Learn about how the Agentic Assistant is built using responsible AI principles in Cortex XSIAM.
- [Cortex XSIAM license tiers and product licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses.md): Compare Cortex XSIAM license tiers and product licenses: NG-SIEM, Enterprise, Premium, included capabilities, and add-ons.
- [Data retention](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses/data-retention.md): Learn more about the default retention periods for all Cortex XSIAM licenses and the available retention add-ons.
- [Data storage lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses/data-storage-lifecycle.md): Understand the Cortex XSIAM data storage lifecycle, including hot and cold storage, retention extensions, and Event Forwarding exports.
- [License allocation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses/license-allocation.md): Learn more about how Cortex XSIAM regulates licenses.
- [License expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses/license-expiration.md): Learn more about the Cortex XSIAM license expiration and validation period.
- [Upgrade your tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses/upgrade-your-tenant.md): If you have purchased new entitlements, Cortex XSIAM automatically upgrades your tenant to provide product upgrades and new license entitlements.
- [In-product support ticket creation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/in-product-support-case-creation.md): Open a support ticket directly in Cortex XSIAM and record your console to capture your issues and have the ticket handled efficiently.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/supported-web-browsers.md): View the web browsers and minimum browser versions supported for Cortex XSIAM.
- [Use the Cortex XSIAM interface](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/use-the-interface.md): Learn Cortex XSIAM interface navigation, filtering, saved views, result exports, system tools, and product areas.
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/manage-api-keys.md): Learn to create and manage Cortex XSIAM API keys, roles, expiration, scopes, and credential permissions.
- [How to onboard Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/onboard-cortex-xsiam.md): Learn about the deployment preparation and procedures for onboarding and configuring Cortex XSIAM.
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/plan-and-prepare.md): Plan your Cortex XSIAM deployment, including storage, region, licensing, XDR agents, data sources, and user roles.
- [Plan your agent deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/plan-and-prepare/plan-your-agent-deployment.md): Plan phased Cortex XDR agent deployment, from pilot testing to organization-wide Cortex XSIAM rollout.
- [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps.md): Review the plan and prepare considerations, and then follow the steps in the onboarding checklist to successfully deploy and onboard Cortex XSIAM.
- [Cortex XSIAM onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-onboarding-checklist.md): Cortex XSIAM onboarding checklist for activation, data source configuration, XDR agent deployment, and analytics setup.
- [Activate Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam.md): Activate Cortex XSIAM tenants in Cortex Gateway, including prerequisites, encryption, and access configuration.
- [Bring your own keys](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/bring-your-own-keys.md): Set up, import, rotate, and disable Cortex BYOK encryption keys for Cortex XSIAM tenant data.
- [Cortex XSIAM supported regions and data residency](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/cortex-xsiam-supported-regions.md): View Cortex XSIAM supported hosting regions and data residency locations in Americas, EMEA, and JPAC.
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources.md): Configure firewall access to Cortex XSIAM resources using required FQDNs, IP addresses, ports, and App-IDs.
- [Cortex XSIAM regional egress resources](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources/regional-egress-resources.md): Configure Cortex XSIAM firewall egress access with regional FQDNs, IP addresses, ports, and App-IDs.
- [Cortex XSIAM engine outbound IP addresses](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources/engine-ip-addresses-outbound.md): Configure firewall allowlists for Cortex XSIAM engine outbound IP addresses by deployment region.
- [Cortex XSIAM inbound source IP addresses](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources/inbound-source-resources.md): Configure firewall allowlists for Cortex XSIAM inbound source IP addresses by deployment region.
- [FedRAMP and US federal Cortex XSIAM required resources](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md): Configure required Cortex XSIAM network resources for FedRAMP and US federal government deployments.
- [Set up users, groups, and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-users-and-roles.md): Learn how to set up users and roles in Cortex XSIAM.
- [Manage Cortex XSIAM user groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-users-and-roles/user-group-management.md): Manage Cortex XSIAM user groups for RBAC, SBAC scoping, SAML mapping, and Active Directory synchronization.
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-users-and-roles/assign-user-roles-and-groups.md): Assign Cortex XSIAM roles and groups, configure RBAC permissions, and apply SBAC granular access.
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-authentication.md): Authenticate Cortex XSIAM users using SAML 2.0 or Customer Support Portal (CSP).
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate Cortex XSIAM users through Customer Support Portal and assign Gateway or tenant access roles.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-authentication/authenticate-users-using-sso.md): Configure Cortex XSIAM SAML 2.0 single sign-on with identity providers, group mapping, and user provisioning.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta SAML 2.0 single sign-on and group mapping for Cortex XSIAM users.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID SAML 2.0 single sign-on, security group claims, and user group mapping for Cortex XSIAM.
- [Configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/configure-content.md): Configure Cortex XSIAM data sources with standard collectors, Broker VM applets, XDR Collectors, CSP onboarding, and content packs.
- [Set up Cloud Identity Engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/set-up-cloud-identity-engine.md): Learn how to set up Cloud Identity Engine to use with Cortex XSIAM.
- [Install Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents.md): Install Cortex XDR agents with agent installation packages to monitor endpoints and collect Cortex XSIAM endpoint data.
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/create-an-agent-installation-package.md): Create Cortex XDR agent installation packages for endpoints, Kubernetes, container, and serverless workloads in Cortex XSIAM.
- [Deploy installation packages](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/deploy-installation-packages.md): Deploy Cortex XDR agent installation packages to Windows, macOS, Linux, Kubernetes, and Android endpoints using manual or software distribution methods in Cortex XSIAM.
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/endpoint-data-collection.md): Review endpoint metadata, EDR events, Windows event logs, and performance metrics collected by Cortex XDR agents for Cortex XSIAM.
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/configure-global-agent-settings.md): Configure global Cortex XDR agent settings for uninstall passwords, content bandwidth, upgrades, advanced analysis, and endpoint cleanup for Cortex XSIAM.
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/define-endpoint-groups.md): Create and manage static or dynamic Cortex XDR Agent endpoint groups to target security policies and actions by endpoint attributes for Cortex XSIAM.
- [Manage endpoint profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/manage-endpoint-profiles.md): Manage Cortex XSIAM endpoint security profiles and policy mappings to apply reusable threat protection settings across endpoint groups.
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Plan phased Cortex XDR agent upgrades and content updates with rollout schedules, staging content, and bandwidth controls in Cortex XSIAM.
- [Cortex XSIAM - Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-analytics.md): Learn how to enable Cortex XSIAM - Analytics, which allows Cortex XSIAM to analyze data from a variety of sensors and develop a baseline to raise analytics alerts.
- [Configure Cortex XSIAM network parameters](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-analytics/configure-cortex-xsiam-network-parameters.md): Configure Cortex XSIAM internal IP address ranges and domain suffixes for network asset identification, tracking, and analysis.
- [Enable the Analytics Engine and Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-analytics/enable-the-analytics-engine-and-identity-analytics.md): Enable Cortex XSIAM Analytics Engine and Identity Analytics to baseline activity and detect anomalous endpoint and user behavior.
- [FedRAMP overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/fedramp-overview.md): Learn how FedRAMP standardizes cloud security assessment, authorization, and continuous monitoring for U.S. government agencies.
- [Cortex XSIAM FedRAMP compliance for federal agencies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/fedramp-overview/cortex-xsiam-federal-compliance.md): Learn how FedRAMP-authorized Cortex XSIAM supports U.S. federal agencies with isolated tenants, U.S. data residency, and government cloud infrastructure.
- [Onboard and configure government cloud environments](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/fedramp-overview/onboarding-and-configuration.md): Onboard government cloud environments to Cortex XSIAM with the CSP wizard, Government tenant settings, and compliant scan modes.
- [FedRAMP limitations and supported government cloud regions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/fedramp-overview/limitations-and-supported-regions.md): Review Cortex XSIAM FedRAMP feature limitations and supported AWS GovCloud and Azure Government regions for federal deployments.
- [Post-deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment.md): Complete Cortex XSIAM post-deployment tasks, including health checks, automations, and reviews of security cases and issues.
- [Cortex XSIAM post-deployment checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/post-deployment-checklist.md): Use this Cortex XSIAM post-deployment checklist for health checks, automations, case triage, XDR agent rollout, and integrations.
- [Perform health checks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/perform-health-checks.md): Perform Cortex XSIAM health checks for prevention policies, Cortex XDR agents, WildFire testing, alerts, cases, and log ingestion.
- [Monitor agent operational status in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/perform-health-checks/monitor-agent-operational-status-in-cortex-xsiam.md): Monitor Cortex XDR agent operational status in Cortex XSIAM, including protected, partially protected, unprotected, and resource-impact states.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/cortex-marketplace.md): Discover Cortex Marketplace content packs for integrations, playbooks, automations, correlation rules, dashboards, and security use cases.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/cortex-marketplace/content-packs.md): Explore pre-installed and recommended Cortex Marketplace content packs for integrations, playbooks, scripts, widgets, and security workflows.
- [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/cortex-marketplace/install-content-packs.md): Install Cortex Marketplace content packs, review dependencies, and configure integrations and data sources in Cortex XSIAM.
- [Manage user roles and access management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management.md): Learn how to manage access for users, user roles, user groups, and Single Sign-On (SSO) for users on a specific Cortex XSIAM tenant.
- [Manage user roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-user-roles.md): Create and manage Cortex XSIAM user roles with RBAC permissions, XQL dataset access controls, and scoped access settings.
- [Manage user access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-user-access.md): Manage Cortex XSIAM user access with roles, user groups, RBAC permissions, SBAC scopes, and XQL dataset row controls.
- [User access reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-user-access/user-access-reference-information.md): Reference Cortex XSIAM Users page fields for user types, direct roles, groups, group roles, and granular access scopes.
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-user-scope.md): Configure Cortex XSIAM Scope-Based Access Control (SBAC) for users, groups, and API keys across assets, cases, endpoints, and dataset rows.
- [Manage access to objects](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-access-to-objects.md): Manage Cortex XSIAM per-object access for dashboards, reports, playbooks, scripts, and saved XQL queries using owner, editor, and viewer roles.
- [Manage access to custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-custom-dashboards.md): Manage Cortex XSIAM custom dashboard access with role permissions, object sharing, owners, editors, viewers, and SBAC data scopes.
- [Manage access to report templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-report-templates.md): Manage Cortex XSIAM report template access with role permissions, ownership, sharing, public visibility, and SBAC data scopes.
- [Manage access to playbooks and scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-playbooks-and-scripts.md): Manage Cortex XSIAM playbook and script access with role permissions, ownership, sharing, public visibility, and automation controls.
- [Manage access to saved queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-saved-queries.md): Manage Cortex XSIAM saved XQL query access with role permissions, ownership, sharing, public visibility, and Query Library controls.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/dashboards-and-reports.md): Use Cortex XSIAM dashboards, widgets, reports, and report templates to visualize security data and monitor system activity.
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/configure-server-settings.md): Configure Cortex XSIAM server settings for localization, branding, AI, access control, data ingestion, security, and support access.
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/configure-security-settings.md): Configure Cortex XSIAM security settings for session expiration, login domains, approved IP ranges, inactive users, cookies, and report emails.
- [Data and log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding.md): Configure Cortex XSIAM notifications and forward logs, alerts, cases, and issues to email, Slack, syslog, and third-party services.
- [Forward logs and data from Cortex XSIAM to external services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services.md): Forward Cortex XSIAM logs, cases, and issues to email, Slack, syslog, Splunk, Amazon SQS, Amazon S3, or webhooks.
- [Configure external applications for forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding.md): Configure external applications in Cortex XSIAM to forward cases, issues, and logs to email, Slack, syslog, Amazon S3, Amazon SQS, Splunk, and webhooks.
- [Forward notifications to Amazon SQS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqs.md): Configure Cortex XSIAM notification forwarding to Amazon SQS with Cortex Gateway egress, an AWS SQS queue, IAM role or access keys, and queue permissions.
- [Forward notifications to Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-s3.md): Configure Cortex XSIAM notification forwarding to Amazon S3 with Cortex Gateway egress, AWS IAM roles, bucket permissions, and file rollup.
- [Forward notifications to Splunk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-splunk.md): Configure Cortex XSIAM notification forwarding to Splunk with firewall access, Cortex Gateway egress, HTTPS Event Collector, and authentication tokens.
- [Forward notifications to webhook](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-webhook.md): Configure Cortex XSIAM case and issue notifications to HTTPS webhooks with firewall access, Gateway egress, authentication, and JSON payload support.
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver.md): Integrate a syslog receiver for Cortex XSIAM notifications with regional firewall access, TCP or UDP transport, TLS certificates, and troubleshooting.
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-slack-for-outbound-notifications.md): Integrate Cortex XSIAM with Slack to forward issue and report notifications to dedicated workspace channels.
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-notification-forwarding.md): Configure Cortex XSIAM forwarding notifications for issues, cases, and audit logs with scoped filters, formats, grouping, and external destinations.
- [Set up email notifications for tenant updates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/set-up-email-notifications-for-tenant-updates.md): Set up Cortex XSIAM email notifications for tenant upgrades, hotfixes, downtime warnings, and Management Audit Log events.
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/monitor-administrative-activity.md): Monitor Cortex XSIAM administrative and investigative activity with Management Audit Logs, filters, 365-day retention, and notification forwarding.
- [Data and log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/data-and-log-notification-formats.md): Understand Cortex XSIAM notification formats for forwarded cases, issues, and logs, including optional alert formatting for email, syslog, and Slack.
- [Management audit log messages](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-messages.md): Reference Cortex XSIAM Management Audit Log message types for administrative, authentication, automation, endpoint, policy, and integration activity.
- [Cortex XSIAM issue notification format](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/data-and-log-notification-formats/issue-notification-format.md): Reference Cortex XSIAM issue notification formats and payloads for email, Slack, syslog, Splunk, Amazon S3, Amazon SQS, and webhooks.
- [Agent Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/data-and-log-notification-formats/agent-audit-log-notification-format.md): Reference Cortex XDR Agent Audit Log notification formats for email and syslog, including CEF field mappings and payload examples.
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-notification-format.md): Reference Cortex XSIAM Management Audit Log notification formats for email and syslog, including CEF field mappings and payload examples.
- [Log format for IOC and BIOC issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/data-and-log-notification-formats/log-format-for-ioc-and-bioc-issues.md): Reference legacy Cortex XSIAM IOC and BIOC issue log formats for email and syslog, including fields, prefixes, and categories.
- [Analytics log format](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/data-and-log-notification-formats/analytics-log-format.md): Reference legacy Cortex XSIAM Analytics issue log formats for email and syslog, including detection, network activity, user, device, and file fields.
- [Learn how to configure Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-cortex-xsiam.md): Learn how to configure Cortex XSIAM, such as Agentic configuration, setting up an MCP Server, remote repositories, and automations.
- [Data management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management.md): Manage Cortex XSIAM data with Analytics and Data Lake tiers, Federated Search, retention settings, datasets, and data lifecycle controls.
- [Optimize data management in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/optimize-data-management-in-cortex-xsiam.md): Learn more about the differences between the Cortex XSIAM data management solutions.
- [Configure Cortex Data Lake tier](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/configure-cortex-data-lake-tier.md): Configure the Cortex Data Lake tier in Cortex XSIAM.
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm.md): Manage Broker VMs that collect and forward data to Cortex XSIAM.
- [What is the Broker VM?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/what-is-the-broker-vm.md): Learn how Broker VM securely connects data sources to Cortex XSIAM.
- [Set up and configure Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm.md): Install and configure a Broker VM to collect data for Cortex XSIAM.
- [Broker VM image installations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations.md): Install a Cortex XSIAM Broker VM image on supported cloud and virtual platforms.
- [Set up Broker VM on Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-alibaba-cloud.md): Deploy a Cortex XSIAM Broker VM on Alibaba Cloud.
- [Set up Broker VM on Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-amazon-web-services.md): Deploy a Cortex XSIAM Broker VM on Amazon Web Services.
- [Set up Broker VM on Google Cloud Platform (GCP)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-google-cloud-platform-gcp.md): Deploy a Cortex XSIAM Broker VM on Google Cloud Platform.
- [Set up Broker VM on KVM using Ubuntu](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-kvm-using-ubuntu.md): Deploy a Cortex XSIAM Broker VM on Ubuntu with KVM.
- [Set up Broker VM on Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-azure.md): Deploy a Cortex XSIAM Broker VM on Microsoft Azure.
- [Set up Broker VM on Microsoft Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-hyper-v.md): Deploy a Cortex XSIAM Broker VM on Microsoft Hyper-V.
- [Set up Broker VM on Nutanix Hypervisor](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-nutanix-hypervisor.md): Deploy a Cortex XSIAM Broker VM on Nutanix Hypervisor.
- [Set up Broker VM on VMware ESXi using vSphere Client](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-vmware-esxi-using-vsphere-client.md): Deploy a Cortex XSIAM Broker VM on VMware ESXi.
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets.md): Configure Broker VM data collector applets for Cortex XSIAM.
- [Manage Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm.md): Manage Broker VM configuration, capacity, updates, and clusters in Cortex XSIAM.
- [Edit Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/edit-broker-vm-configuration.md): Update Broker VM settings for Cortex XSIAM data collection.
- [Increase Broker VM storage allocated for data caching](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/increase-broker-vm-storage-allocated-for-data-caching.md): Increase Broker VM cache storage for Cortex XSIAM data collection.
- [Monitor Broker VM using Prometheus](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/monitor-broker-vm-using-prometheus.md): Monitor Cortex XSIAM Broker VM metrics with Prometheus.
- [Collect Broker VM Logs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/collect-broker-vm-logs.md): Collect Broker VM logs for Cortex XSIAM troubleshooting.
- [Upgrade Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/upgrade-broker-vm.md): Upgrade a Broker VM that supports Cortex XSIAM data collection.
- [Update Broker VM applets independently](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/update-broker-vm-applets-independently.md): Update Cortex XSIAM Broker VM applets independently.
- [Import Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/import-broker-vm-configuration.md): Import Broker VM configuration for Cortex XSIAM data collection.
- [Open Live Terminal](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/open-live-terminal.md): Access a live terminal for a Cortex XSIAM Broker VM.
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/add-broker-vm-to-cluster.md): Add a Cortex XSIAM Broker VM to a cluster.
- [Switchover Primary Node in Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/switchover-primary-node-in-cluster.md): Switch the primary node in a Cortex XSIAM Broker VM cluster.
- [Remove from Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm/remove-from-cluster.md): Remove a Broker VM from a Cortex XSIAM cluster.
- [Manage Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/manage-broker-vm-data-collector-applets.md): Manage data collector applets on Cortex XSIAM Broker VMs.
- [Broker VM High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster.md): Configure highly available Broker VM clusters for Cortex XSIAM.
- [Configure High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster/configure-high-availability-cluster.md): Configure a high availability Broker VM cluster for Cortex XSIAM.
- [Manage Broker VM clusters](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters.md): Manage high availability Broker VM clusters in Cortex XSIAM.
- [View cluster details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/view-cluster-details.md): View details for a Cortex XSIAM Broker VM cluster.
- [Edit cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/edit-cluster.md): Edit configuration for a Cortex XSIAM Broker VM cluster.
- [Add applet to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-applet-to-cluster.md): Add a data collector applet to a Cortex XSIAM Broker VM cluster.
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-broker-vm-to-cluster.md): Add a Broker VM to a Cortex XSIAM high availability cluster.
- [Remove cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/remove-cluster.md): Remove a Cortex XSIAM Broker VM cluster.
- [Broker VM notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/broker-vm-notifications.md): Configure notifications for Cortex XSIAM Broker VM events.
- [Monitor Broker VM activity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/monitor-broker-vm-activity.md): Monitor Broker VM activity in Cortex XSIAM.
- [Troubleshoot Broker VM applet errors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/broker-vm/troubleshoot-broker-vm-applet-errors.md): Troubleshoot data collector applet errors on Cortex XSIAM Broker VMs.
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/dataset-management.md): Manage Cortex XSIAM datasets, storage, and period-based retention.
- [What are datasets?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/dataset-management/what-are-datasets.md): Learn how Cortex XSIAM datasets store and organize your data.
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/dataset-management/lookup-datasets.md): Create and manage lookup datasets in Cortex XSIAM.
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/dataset-management/import-a-lookup-dataset.md): Import a lookup dataset into Cortex XSIAM.
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/dataset-management/download-json-file-of-lookup-dataset.md): Download a lookup dataset as JSON from Cortex XSIAM.
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/dataset-management/set-time-to-live-for-lookup-datasets.md): Set retention periods for Cortex XSIAM lookup datasets.
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md): Monitor dataset and dataset view activity in Cortex XSIAM.
- [Archived data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/archived-data.md): Learn more about archived data in Cortex XSIAM.
- [Import historical data into cold storage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/archived-data/import-historical-data-into-cold-storage.md): Import historical data into Cortex XSIAM cold storage.
- [Building XQL archived data queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/archived-data/building-xql-archived-data-queries.md): Build XQL queries for archived data in Cortex XSIAM.
- [Success and failure code responses to your HTTP POST requests](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/archived-data/success-and-failure-code-responses-to-your-http-post-requests.md): Interpret HTTP POST responses when importing Cortex XSIAM archived data.
- [Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules.md): Learn more about Cortex XSIAM Parsing Rules.
- [Parsing Rules editor views](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-editor-views.md): Navigate the Cortex XSIAM Parsing Rules editor.
- [Parsing Rules file structure and syntax](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax.md): Learn Cortex XSIAM Parsing Rules file structure and XQLp syntax.
- [INGEST](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest.md): Define INGEST sections in Cortex XSIAM Parsing Rules.
- [parse\_cef](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cef.md): Use \`parse\_cef\` in Cortex XSIAM Parsing Rules.
- [parse\_cisco](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cisco.md): Use \`parse\_cisco\` in Cortex XSIAM Parsing Rules.
- [parse\_json](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_json.md): Use \`parse\_json\` in Cortex XSIAM Parsing Rules.
- [COLLECT](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/collect.md): Define COLLECT sections in Cortex XSIAM Parsing Rules.
- [CONST](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/const.md): Define reusable constants in Cortex XSIAM Parsing Rules.
- [RULE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/rule.md): Define reusable rules in Cortex XSIAM Parsing Rules.
- [EXTEND](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/extend.md): Extend default rule logic in Cortex XSIAM Parsing Rules.
- [Create Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/create-parsing-rules.md): Create custom Parsing Rules for Cortex XSIAM data.
- [Troubleshooting Parsing rules errors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/troubleshooting-parsing-rules-errors.md): Troubleshoot parsing rule errors in Cortex XSIAM.
- [Parsing Rules Raw Dataset](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-raw-dataset.md): Work with the raw dataset used by Cortex XSIAM Parsing Rules.
- [Data Model Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules.md): Learn more about Cortex XSIAM Data Model (XDM) Rules.
- [Data Model Rules editor views](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-editor-views.md): Navigate the Cortex XSIAM Data Model Rules editor.
- [Data Model Rules file structure and syntax](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-file-structure-and-syntax.md): Learn Cortex XSIAM Data Model Rules file structure and syntax.
- [MODEL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-file-structure-and-syntax/model.md): Define models in Cortex XSIAM Data Model Rules.
- [RULE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-file-structure-and-syntax/rule.md): Define rules in Cortex XSIAM Data Model Rules.
- [Field structure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-file-structure-and-syntax/field-structure.md): Define field structures in Cortex XSIAM Data Model Rules.
- [How to map authentication events for analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/how-to-map-authentication-story-events.md): Map authentication events for Cortex XSIAM analytics.
- [Generate data model rules with AI (preview)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/generate-data-model-rules-with-ai-preview.md): Generate Cortex XSIAM Data Model Rules with AI.
- [Create Data Model Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/create-data-model-rules.md): Create custom Data Model Rules in Cortex XSIAM.
- [Troubleshooting Data Model Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/troubleshooting-data-model-rules.md): Troubleshoot Data Model Rules in Cortex XSIAM.
- [Using data enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/using-data-enrichment.md): Use data enrichment with Cortex XSIAM Data Model Rules.
- [Data Model Rules notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-notifications.md): Configure notifications for Cortex XSIAM Data Model Rules.
- [Monitor Data Model Rules activity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/monitor-data-model-rules-activity.md): Monitor Data Model Rules activity in Cortex XSIAM.
- [Manage Event Forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/manage-event-forwarding.md): Export Cortex XSIAM event logs to a temporary GCP storage bucket.
- [Endpoints Event Forwarding - included/excluded fields by event type](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/manage-event-forwarding/endpoints-event-forwarding-included-excluded-fields-by-event-type.md): Review event forwarding fields by Cortex XSIAM event type.
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/manage-compute-units.md): Manage Cortex XSIAM compute units for API, Apps, and Cold Storage XQL queries.
- [Compute units usage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/manage-compute-units/compute-units-usage.md): Monitor compute unit usage in Cortex XSIAM.
- [Cortex XSIAM Data Sources and Connectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources.md)
- [What are Cortex XSIAM data sources and connectors?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/what-are-cortex-xsiam-data-sources.md): Learn more about Cortex XSIAM Data Sources and connectors with a unified approach to integrations.
- [Complete data source and connector catalog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/complete-data-source-catalog.md): Learn more about the complete data source and connector catalog available in Cortex XSIAM.
- [Vendor-specific data sources and connectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors.md): Browse vendor-specific data sources and connectors for Cortex XSIAM.
- [1Password](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/1password.md): Configure the 1Password integration for Cortex XSIAM.
- [1Password](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/1password/1password.md): Use 1Password data with Cortex XSIAM.
- [Abnormal Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/abnormal-security.md): Configure the Abnormal Security integration for Cortex XSIAM.
- [Abnormal Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/abnormal-security/abnormal-security.md): Use Abnormal Security data with Cortex XSIAM.
- [Absolute](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/absolute.md): Configure the Absolute integration for Cortex XSIAM.
- [Absolute](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/absolute/absolute.md): Use Absolute data with Cortex XSIAM.
- [abuse.ch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/abuse.ch.md): Configure the abuse.ch integration for Cortex XSIAM.
- [abuse.ch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/abuse.ch/abuse.ch.md): Use abuse.ch threat intelligence with Cortex XSIAM.
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/abuseipdb.md): Configure the AbuseIPDB integration for Cortex XSIAM.
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/abuseipdb/abuseipdb.md): Use AbuseIPDB data with Cortex XSIAM.
- [Accenture](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/accenture.md): Configure the Accenture integration for Cortex XSIAM.
- [Accenture](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/accenture/accenture.md): Use Accenture data with Cortex XSIAM.
- [AdminByRequest](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/adminbyrequest.md): Configure the AdminByRequest integration for Cortex XSIAM.
- [AdminByRequest](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/adminbyrequest/adminbyrequest.md): Use AdminByRequest data with Cortex XSIAM.
- [Aha](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/aha.md): Configure the Aha integration for Cortex XSIAM.
- [Aha!](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/aha/aha.md): Use Aha! data with Cortex XSIAM.
- [Aha](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/aha/aha-1.md): Use Aha data with Cortex XSIAM.
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/aiops.md): Configure the AIOps integration for Cortex XSIAM.
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/aiops/aiops.md): Use AIOps data with Cortex XSIAM.
- [Akamai](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/akamai.md): Configure the Akamai integration for Cortex XSIAM.
- [Akamai](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/akamai/akamai.md): Use Akamai data with Cortex XSIAM.
- [AlgoSec](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/algosec.md): Configure the AlgoSec integration for Cortex XSIAM.
- [AlgoSec](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/algosec/algosec.md): Use AlgoSec data with Cortex XSIAM.
- [Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/alibaba-cloud.md): Configure the Alibaba Cloud integration for Cortex XSIAM.
- [Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/alibaba-cloud/alibaba-cloud.md): Use Alibaba Cloud data with Cortex XSIAM.
- [AlienVault](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/alienvault.md): Configure the AlienVault integration for Cortex XSIAM.
- [AlienVault](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/alienvault/alienvault.md): Use AlienVault data with Cortex XSIAM.
- [Amazon](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon.md)
- [Amazon Cloud Watch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-cloud-watch.md)
- [Ingest logs from Amazon CloudWatch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-cloud-watch/ingest-logs-from-amazon-cloudwatch.md)
- [Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3.md)
- [Ingest audit logs from AWS CloudTrail](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-audit-logs-from-aws-cloudtrail.md)
- [Ingest network flow logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-network-flow-logs-from-amazon-s3.md)
- [Ingest generic logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-generic-logs-from-amazon-s3.md)
- [Ingest network Route 53 logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-network-route-53-logs-from-amazon-s3.md)
- [Create an assumed role](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/create-an-assumed-role.md)
- [Configure data collection from Amazon S3 manually](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/configure-data-collection-from-amazon-s3-manually.md)
- [Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-web-services.md)
- [AWS Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/aws-automation-and-collection.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/anomali.md): Configure the Anomali integration for Cortex XSIAM.
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/anomali/anomali.md): Use Anomali data with Cortex XSIAM.
- [Anthropic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/anthropic.md): Configure the Anthropic integration for Cortex XSIAM.
- [Claude Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/anthropic/claude-automation-and-collection.md): Use Claude automation and collection with Cortex XSIAM.
- [Claude](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/anthropic/claude.md): Use Claude with Cortex XSIAM.
- [Apache](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/apache.md)
- [Apache](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/apache/apache.md)
- [API Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security.md)
- [Ingest data for API security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-security.md)
- [Ingest AWS API Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-security/ingest-aws-api-gateway.md)
- [Ingest Azure APIM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-security/ingest-azure-apim.md)
- [Ingest Apigee Proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-security/ingest-apigee-proxy.md)
- [Ingest Kong](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-security/ingest-kong.md)
- [Ingest F5](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-security/ingest-f5.md)
- [APIVoid](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/apivoid.md)
- [APIVoid](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/apivoid/apivoid.md)
- [Apollo.io](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/apollo.io.md)
- [Apollo.io](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/apollo.io/apollo.io.md)
- [AppSentinels](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/appsentinels.md)
- [AppSentinels](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/appsentinels/appsentinels.md)
- [ArcSight](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/arcsight.md)
- [ArcSight](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/arcsight/arcsight.md)
- [Arista Networks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/arista-networks.md)
- [Arista Networks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/arista-networks/arista-networks.md)
- [Arkime](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/arkime.md)
- [Arkime](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/arkime/arkime.md)
- [Armis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/armis.md)
- [Armis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/armis/armis.md)
- [Articulate Global](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/articulate-global.md)
- [Articulate Global](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/articulate-global/articulate-global.md)
- [Asana](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/asana.md)
- [Asana](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/asana/asana.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/atlassian.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/atlassian/atlassian.md)
- [Atlassian Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/atlassian/atlassian-automation-and-collection.md)
- [AttackIQ](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/attackiq.md)
- [AttackIQ](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/attackiq/attackiq.md)
- [Aurora Endpoint Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/aurora-endpoint-security.md)
- [Aurora Endpoint Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/aurora-endpoint-security/aurora-endpoint-security.md)
- [Automox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/automox.md)
- [Automox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/automox/automox.md)
- [BeyondTrust](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/beyondtrust.md)
- [BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/beyondtrust/beyondtrust-privilege-management-cloud.md)
- [Ingest logs from BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/beyondtrust/beyondtrust-privilege-management-cloud/ingest-logs-from-beyondtrust-privilege-management-cloud.md)
- [BeyondTrust](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/beyondtrust/beyondtrust.md)
- [BitSight](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bitsight.md)
- [BitSight](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bitsight/bitsight.md)
- [bitwarden](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bitwarden.md)
- [bitwarden](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bitwarden/bitwarden.md)
- [Blocklist.de](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/blocklist.de.md)
- [Blocklist.de](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/blocklist.de/blocklist.de.md)
- [BloodHound Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bloodhound-enterprise.md)
- [BloodHound Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bloodhound-enterprise/bloodhound-enterprise.md)
- [BlueCat Address Manager](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bluecat-address-manager.md)
- [BlueCat Address Manager](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bluecat-address-manager/bluecat-address-manager.md)
- [BMC](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bmc.md)
- [BMC](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bmc/bmc.md)
- [Box](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/box.md)
- [Ingest logs and data from Box](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/box/ingest-logs-and-data-from-box.md)
- [Box Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/box/box-automation-and-collection.md)
- [Box](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/box/box.md)
- [Broadcom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/broadcom.md)
- [Broadcom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/broadcom/broadcom.md)
- [BruteForceBlocker](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bruteforceblocker.md)
- [BruteForceBlocker](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/bruteforceblocker/bruteforceblocker.md)
- [Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/businessmap.md)
- [Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/businessmap/businessmap.md)
- [C2SEC](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/c2sec.md)
- [C2SEC](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/c2sec/c2sec.md)
- [CAPESandbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/capesandbox.md)
- [CAPESandbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/capesandbox/capesandbox.md)
- [Carbon Black](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/carbon-black.md)
- [Carbon Black](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/carbon-black/carbon-black.md)
- [Celonis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/celonis.md)
- [Celonis Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/celonis/celonis-collection.md)
- [Celonis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/celonis/celonis.md)
- [Centreon](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/centreon.md)
- [Centreon](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/centreon/centreon.md)
- [ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/chatgpt-enterprise.md)
- [ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/chatgpt-enterprise/chatgpt-enterprise.md)
- [Check Point](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/check-point.md)
- [Check Point FW1/VPN1](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/check-point/check-point-fw1-vpn1.md)
- [Checkpoint Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/check-point/checkpoint-firewall.md)
- [CheckPhish](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/checkphish.md)
- [CheckPhish](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/checkphish/checkphish.md)
- [CipherTrust](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ciphertrust.md)
- [CipherTrust](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ciphertrust/ciphertrust.md)
- [CIRCL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/circl.md)
- [CIRCL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/circl/circl.md)
- [CircleCI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/circleci.md)
- [CircleCI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/circleci/circleci.md)
- [Cisco](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco.md)
- [Cisco ASA firewalls and AnyConnect\`](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-asa-firewalls-and-anyconnect.md)
- [Cisco ASA](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-asa.md)
- [Cisco Duo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-duo.md)
- [Cisco DUO Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-duo-automation-and-collection.md)
- [Cisco Firepower](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-firepower.md)
- [Cisco ISE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-ise.md)
- [Cisco Meraki](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-meraki.md)
- [Cisco Meraki Automation and Remediation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-meraki-automation-and-remediation.md)
- [Cisco Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-security.md)
- [Cisco Umbrella](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-umbrella.md)
- [Citrix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/citrix.md)
- [Citrix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/citrix/citrix.md)
- [ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/clickup.md)
- [ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/clickup/clickup.md)
- [Cloaken](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cloaken.md)
- [Cloaken](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cloaken/cloaken.md)
- [CloudConvert](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cloudconvert.md)
- [CloudConvert](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cloudconvert/cloudconvert.md)
- [Cloudflare](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cloudflare.md)
- [Cloudflare](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cloudflare/cloudflare.md)
- [Code42](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/code42.md)
- [Code42](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/code42/code42.md)
- [Cohesity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cohesity.md)
- [Cohesity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cohesity/cohesity.md)
- [Contentful](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/contentful.md)
- [Contentful](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/contentful/contentful.md)
- [Corelight](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/corelight.md)
- [Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/corelight/corelight-zeek.md)
- [Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/couchbase.md)
- [Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/couchbase/couchbase.md)
- [CounterTack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/countertack.md)
- [CounterTack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/countertack/countertack.md)
- [Coveo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/coveo.md)
- [Coveo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/coveo/coveo.md)
- [Cribl](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl.md)
- [Ingest data from Cribl](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl.md)
- [Disable or delete Cribl integration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/disable-or-delete-cribl-integration.md)
- [Data souce UUIDs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/data-souce-uuids.md)
- [Collect Windows Event Logs for Cortex XSIAM via Cribl](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/collect-windows-event-logs-for-cortex-xsiam-via-cribl.md)
- [Cribl connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/cribl-connector.md)
- [CrowdStrike](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike.md)
- [Crowdstrike APIs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike-apis.md)
- [Ingest alerts and metadata from Crowdstrike APIs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike-apis/ingest-alerts-and-metadata-from-crowdstrike-apis.md)
- [CrowdStrike Falcon Data Replicator](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike-falcon-data-replicator.md)
- [Ingest raw EDR events from CrowdStrike Falcon Data Replicator](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike-falcon-data-replicator/ingest-raw-edr-events-from-crowdstrike-falcon-data-replicator.md)
- [CrowdStrike](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike.md)
- [CryptoCurrency](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cryptocurrency.md)
- [CryptoCurrency](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cryptocurrency/cryptocurrency.md)
- [Cuckoo Sandbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cuckoo-sandbox.md)
- [Cuckoo Sandbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cuckoo-sandbox/cuckoo-sandbox.md)
- [Cursor](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cursor.md)
- [Cursor](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cursor/cursor.md)
- [CybelAngel](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cybelangel.md)
- [CybelAngel](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cybelangel/cybelangel.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cyberark.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cyberark/cyberark.md)
- [Cyber Triage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cyber-triage.md)
- [Cyber Triage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cyber-triage/cyber-triage.md)
- [CYFIRMA](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cyfirma.md)
- [CYFIRMA](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cyfirma/cyfirma.md)
- [Darktrace](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/darktrace.md)
- [Darktrace](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/darktrace/darktrace.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/databricks.md)
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/databricks/how-to-onboard-databricks.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/databricks/databricks.md)
- [DataDog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/datadog.md)
- [DataDog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/datadog/datadog.md)
- [DeHashed](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dehashed.md)
- [DeHashed](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dehashed/dehashed.md)
- [DHS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dhs.md)
- [DHS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dhs/dhs.md)
- [digicert](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/digicert.md)
- [digicert](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/digicert/digicert.md)
- [dnstwist](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dnstwist.md)
- [dnstwist](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dnstwist/dnstwist.md)
- [DocuSign](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/docusign.md)
- [DocuSign](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/docusign/docusign.md)
- [Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dropbox.md)
- [Ingest logs and data from Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dropbox/ingest-logs-and-data-from-dropbox.md)
- [Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dropbox/dropbox.md)
- [Druva](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/druva.md)
- [Druva](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/druva/druva.md)
- [EasyVista](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/easyvista.md)
- [EasyVista](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/easyvista/easyvista.md)
- [Email Hippo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/email-hippo.md)
- [Email Hippo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/email-hippo/email-hippo.md)
- [Elastic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic.md)
- [Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/elasticsearch-filebeat.md)
- [Ingest logs from Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/elasticsearch-filebeat/ingest-logs-from-elasticsearch-filebeat.md)
- [Windows DHCP via Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/windows-dhcp-via-elasticsearch-filebeat.md)
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/windows-dhcp-via-elasticsearch-filebeat/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md)
- [ElasticSearch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/elasticsearch.md)
- [Endgame](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/endgame.md)
- [Endgame](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/endgame/endgame.md)
- [Envoy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/envoy.md)
- [Envoy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/envoy/envoy.md)
- [Exabeam](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/exabeam.md)
- [Exabeam](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/exabeam/exabeam.md)
- [ExtraHop](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/extrahop.md)
- [ExtraHop](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/extrahop/extrahop.md)
- [F5](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/f5.md)
- [F5 Automation and Remediation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/f5/f5-automation-and-remediation.md)
- [Fastly](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fastly.md)
- [Fastly](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fastly/fastly.md)
- [Fidelis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fidelis.md)
- [Fidelis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fidelis/fidelis.md)
- [Filigran](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/filigran.md)
- [Filigran OpenCTI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/filigran/filigran-opencti.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forcepoint.md)
- [Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forcepoint/forcepoint-dlp.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forcepoint/forcepoint.md)
- [ForeScout](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forescout.md)
- [ForeScout](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forescout/forescout.md)
- [Fortinet](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet.md)
- [Fortinet Fortigate](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortigate.md)
- [Fortinet FortiGate connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortigate/fortinet-fortigate-connector.md)
- [Fortinet](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet.md)
- [Fortinet FortiWeb VM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortiweb-vm.md)
- [Fortra](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortra.md)
- [Fortra](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortra/fortra.md)
- [FraudWatch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fraudwatch.md)
- [FraudWatch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fraudwatch/fraudwatch.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/freshworks.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/freshworks/freshworks.md)
- [Gainsight](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gainsight.md)
- [Gainsight](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gainsight/gainsight.md)
- [Gamma.AI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gamma.ai.md)
- [Gamma.AI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gamma.ai/gamma.ai.md)
- [Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gemini-enterprise.md)
- [Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gemini-enterprise/gemini-enterprise.md)
- [Genetec](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/genetec.md)
- [Genetec Security Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/genetec/genetec-security-center.md)
- [Generic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic.md)
- [Generic Intel Feed](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-intel-feed.md)
- [Generic API Event Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-api-event-collector.md)
- [Generic MCP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-mcp.md)
- [Generic SQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-sql.md)
- [Genesys](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/genesys.md)
- [Genesys](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/genesys/genesys.md)
- [Gigamon](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gigamon.md)
- [Gigamon](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gigamon/gigamon.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/github.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/github/github.md)
- [GitGuardian](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gitguardian.md)
- [GitGuardian](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gitguardian/gitguardian.md)
- [GitLab](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gitlab.md)
- [GitLab Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gitlab/gitlab-automation-and-collection.md)
- [GitLab](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/gitlab/gitlab.md)
- [Giphy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/giphy.md)
- [Giphy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/giphy/giphy.md)
- [Google](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google.md)
- [Google AI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-ai.md)
- [Google Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-cloud.md)
- [Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-cloud-platform.md)
- [Ingest logs and data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-cloud-platform/ingest-logs-and-data-from-a-gcp-pub-sub.md)
- [Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-kubernetes-engine.md)
- [Ingest logs from Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-kubernetes-engine/ingest-logs-from-google-kubernetes-engine.md)
- [Google SecOps](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-secops.md)
- [Google Services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-services.md)
- [Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace.md)
- [Ingest logs and data from Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace/ingest-logs-and-data-from-google-workspace.md)
- [Google Workspace connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace/google-workspace-connector.md)
- [Google Workspace Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace/google-workspace-automation-and-collection.md)
- [GraphQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/graphql.md)
- [GraphQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/graphql/graphql.md)
- [Grouped Example Connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grouped-example-connector.md)
- [Grouped Example Connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grouped-example-connector/grouped-example-connector.md)
- [GRR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grr.md)
- [GRR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grr/grr.md)
- [Grafana](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grafana.md)
- [Grafana](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grafana/grafana.md)
- [Halcyon](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/halcyon.md)
- [Halcyon](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/halcyon/halcyon.md)
- [Harness](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/harness.md)
- [Harness](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/harness/harness.md)
- [HashiCorp](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hashicorp.md)
- [HashiCorp](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hashicorp/hashicorp.md)
- [Have I Been Pwnd](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/have-i-been-pwnd.md)
- [Have I Been Pwnd](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/have-i-been-pwnd/have-i-been-pwnd.md)
- [HCL BigFix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hcl-bigfix.md)
- [HCL BigFix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hcl-bigfix/hcl-bigfix.md)
- [HPE Aruba](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hpe-aruba.md)
- [HPE Aruba](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hpe-aruba/hpe-aruba.md)
- [Hostio Solutions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hostio-solutions.md)
- [Hostio Solutions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/hostio-solutions/hostio-solutions.md)
- [HTTP log collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/http-log-collector.md)
- [Set up an HTTP log collector to receive logs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/http-log-collector/set-up-an-http-log-collector-to-receive-logs.md)
- [IBM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ibm.md)
- [IBM Storage Scale](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-storage-scale.md)
- [IBM QRadar](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-qradar.md)
- [IBM Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-security.md)
- [iManage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/imanage.md)
- [iManage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/imanage/imanage.md)
- [Imperva](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/imperva.md)
- [Imperva](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/imperva/imperva.md)
- [InfoArmor](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/infoarmor.md)
- [InfoArmor](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/infoarmor/infoarmor.md)
- [Infoblox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/infoblox.md)
- [Infoblox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/infoblox/infoblox.md)
- [Intellum](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/intellum.md)
- [Intellum](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/intellum/intellum.md)
- [Intercom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/intercom.md)
- [Intercom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/intercom/intercom.md)
- [IPInfo.io](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ipinfo.io.md)
- [IPInfo.io](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ipinfo.io/ipinfo.io.md)
- [IPstack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ipstack.md)
- [IPstack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ipstack/ipstack.md)
- [Ironscales](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ironscales.md)
- [Ironscales](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ironscales/ironscales.md)
- [Ivanti](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ivanti.md)
- [Ivanti](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ivanti/ivanti.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/izoologic.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/izoologic/izoologic.md)
- [Jamf](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jamf.md)
- [Jamf](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jamf/jamf.md)
- [Jamf Pro](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jamf/jamf-pro.md)
- [Joe Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/joe-security.md)
- [Joe Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/joe-security/joe-security.md)
- [JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jumpcloud.md)
- [JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jumpcloud/jumpcloud.md)
- [JSONWhoIs.com](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jsonwhois.com.md)
- [JSONWhoIs.com](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jsonwhois.com/jsonwhois.com.md)
- [Kafka](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kafka.md)
- [Kafka](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kafka/kafka.md)
- [Kaspersky](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kaspersky.md)
- [Kaspersky](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kaspersky/kaspersky.md)
- [Keeper Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/keeper-security.md)
- [Keeper Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/keeper-security/keeper-security.md)
- [KnowBe4](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/knowbe4.md)
- [KnowB4](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/knowbe4/knowb4.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/koi.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/koi/koi.md)
- [Koodous](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/koodous.md)
- [Koodous](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/koodous/koodous.md)
- [Kubernetes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kubernetes.md)
- [Onboard the Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kubernetes/onboard-the-kubernetes-connector.md)
- [What's new in Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kubernetes/whats-new-in-kubernetes-connector.md)
- [Supported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kubernetes/supported-kubernetes-distributions.md)
- [Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kustomer.md)
- [Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kustomer/kustomer.md)
- [LastPass](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lastpass.md)
- [LastPass](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lastpass/lastpass.md)
- [Lastline](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lastline.md)
- [Lastline](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lastline/lastline.md)
- [LevelBlue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/levelblue.md)
- [LevelBlue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/levelblue/levelblue.md)
- [LogRhythm](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/logrhythm.md)
- [LogRhythm](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/logrhythm/logrhythm.md)
- [LOLBAS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lolbas.md)
- [LOLBAS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lolbas/lolbas.md)
- [Lookout](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lookout.md)
- [Lookout](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lookout/lookout.md)
- [Lumu](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lumu.md)
- [Lumu](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/lumu/lumu.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mail-utilities.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mail-utilities/mail-utilities.md)
- [Majestic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/majestic.md)
- [Majestic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/majestic/majestic.md)
- [ManageEngine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/manageengine.md)
- [ManageEngine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/manageengine/manageengine.md)
- [Mattermost](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mattermost.md)
- [Mattermost](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mattermost/mattermost.md)
- [MaxMind](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/maxmind.md)
- [MaxMind](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/maxmind/maxmind.md)
- [Menlo Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/menlo-security.md)
- [Menlo Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/menlo-security/menlo-security.md)
- [Meta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/meta.md)
- [Meta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/meta/meta.md)
- [Mimecast](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mimecast.md)
- [Mimecast](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mimecast/mimecast.md)
- [Microsoft](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft.md)
- [Azure DevOps](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-devops.md)
- [Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-event-hub.md)
- [Ingest logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-event-hub/ingest-logs-from-microsoft-azure-event-hub.md)
- [Azure Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-firewall.md)
- [Azure Network Watcher](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-network-watcher.md)
- [Ingest network flow logs from Microsoft Azure Network Watcher](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-network-watcher/ingest-network-flow-logs-from-microsoft-azure-network-watcher.md)
- [Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-azure.md)
- [Microsoft Copilot Studio](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-copilot-studio.md)
- [Microsoft Defender for Endpoint Events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-defender-for-endpoint-events.md)
- [Ingest raw EDR events from Microsoft Defender for Endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-defender-for-endpoint-events/ingest-raw-edr-events-from-microsoft-defender-for-endpoint.md)
- [Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-entra-id.md)
- [Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365.md)
- [Ingest logs from Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/ingest-logs-from-microsoft-office-365.md)
- [Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-365.md)
- [Microsoft365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft365.md)
- [Microsoft 365 Copilot](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-365-copilot.md)
- [Microsoft Graph](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-graph.md)
- [Microsoft Office 365 (email)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365-email.md)
- [Ingest logs and data from Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365-email/ingest-logs-and-data-from-microsoft-365.md)
- [Microsoft 365 (Posture)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-365-posture.md)
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-365-posture/how-to-onboard-microsoft-365.md)
- [Microsoft Teams](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-teams.md)
- [Azure Log Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-log-analytics.md)
- [Azure Services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-services.md)
- [Azure WAF](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-waf.md)
- [Microsoft Active Directory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-active-directory.md)
- [Microsoft Identity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-identity.md)
- [Microsoft Intune](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-intune.md)
- [Microsoft Security Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-security-automation-and-collection.md)
- [Microsoft Windows Tools](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-windows-tools.md)
- [M365 Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/m365-automation-and-collection.md)
- [MISP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/misp.md)
- [MISP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/misp/misp.md)
- [MITRE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mitre.md)
- [MITRE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mitre/mitre.md)
- [Monday](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/monday.md)
- [Monday](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/monday/monday.md)
- [Monday.com](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/monday/monday.com.md)
- [MongoDB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mongodb.md)
- [MongoDB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mongodb/mongodb.md)
- [MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mongodb/mongodb-atlas.md)
- [MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mulesoft.md)
- [MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mulesoft/mulesoft.md)
- [Mural](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mural.md)
- [Mural](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mural/mural.md)
- [MxToolBox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mxtoolbox.md)
- [MxToolBox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mxtoolbox/mxtoolbox.md)
- [NetBox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netbox.md)
- [NetBox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netbox/netbox.md)
- [Netcraft](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netcraft.md)
- [Netcraft](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netcraft/netcraft.md)
- [Netmiko](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netmiko.md)
- [Netmiko](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netmiko/netmiko.md)
- [NetQuest](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netquest.md)
- [NetQuest](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netquest/netquest.md)
- [Netskope](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netskope.md)
- [Netskope](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/netskope/netskope.md)
- [Nintex Workflow Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nintex-workflow-cloud.md)
- [Nintex Workflow Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nintex-workflow-cloud/nintex-workflow-cloud.md)
- [NIST](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nist.md)
- [NIST](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nist/nist.md)
- [nmap](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nmap.md)
- [nmap](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nmap/nmap.md)
- [NAVEX](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/navex.md)
- [NAVEX](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/navex/navex.md)
- [Nutanix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nutanix.md)
- [Nutanix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/nutanix/nutanix.md)
- [Okta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/okta.md)
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/okta/ingest-logs-and-data-from-okta.md)
- [Okta Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/okta/okta-automation-and-collection.md)
- [Okta connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/okta/okta-connector.md)
- [OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/onelogin.md)
- [Ingest logs and data from OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/onelogin/ingest-logs-and-data-from-onelogin.md)
- [OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/onelogin/onelogin.md)
- [OpenAI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openai.md)
- [OpenAI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openai/openai.md)
- [OpenCVE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opencve.md)
- [OpenCVE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opencve/opencve.md)
- [OpenLDAP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openldap.md)
- [OpenLDAP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openldap/openldap.md)
- [OpenPhish](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openphish.md)
- [OpenPhish](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/openphish/openphish.md)
- [OpenText](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentext.md)
- [OpenText EnCase Endpoint Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-encase-endpoint-security.md)
- [OpenText Service Manager](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-service-manager.md)
- [OpenText Vertica](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-vertica.md)
- [OPSWAT](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opswat.md)
- [OPSWAT MetaDefender](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opswat/opswat-metadefender.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oracle.md)
- [Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oracle/oracle-cloud-infrastructure.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oracle/oracle.md)
- [Orca Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/orca-security.md)
- [Orca Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/orca-security/orca-security.md)
- [PacketMail.net](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/packetmail.net.md)
- [PacketMail.net](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/packetmail.net/packetmail.net.md)
- [PacketSled](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/packetsled.md)
- [PacketSled](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/packetsled/packetsled.md)
- [PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pagerduty.md)
- [PagerDuty Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pagerduty/pagerduty-automation-and-collection.md)
- [PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pagerduty/pagerduty.md)
- [PAT Helpdesk Advanced](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pat-helpdesk-advanced.md)
- [PAT Helpdesk Advanced](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pat-helpdesk-advanced/pat-helpdesk-advanced.md)
- [PhishLabs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/phishlabs.md)
- [PhishLabs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/phishlabs/phishlabs.md)
- [Ping Identity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ping-identity.md)
- [PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ping-identity/pingfederate.md)
- [PingOne](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ping-identity/pingone.md)
- [Ingest authentication logs and data from PingOne](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ping-identity/pingone/ingest-authentication-logs-and-data-from-pingone.md)
- [Ping Identity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ping-identity/pingone/ping-identity.md)
- [Pipedrive](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pipedrive.md)
- [Pipedrive](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pipedrive/pipedrive.md)
- [Pipl](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pipl.md)
- [Pipl](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pipl/pipl.md)
- [Plainview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/plainview.md)
- [Plainview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/plainview/plainview.md)
- [Proofpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/proofpoint.md)
- [Proofpoint Targeted Attack Protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/proofpoint/proofpoint-targeted-attack-protection.md)
- [Ingest logs from Proofpoint Targeted Attack Protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/proofpoint/proofpoint-targeted-attack-protection/ingest-logs-from-proofpoint-targeted-attack-protection.md)
- [Proofpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/proofpoint/proofpoint.md)
- [ProtectWise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/protectwise.md)
- [ProtectWise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/protectwise/protectwise.md)
- [Qualtrics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/qualtrics.md)
- [Qualtrics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/qualtrics/qualtrics.md)
- [Qualys](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/qualys.md)
- [Qualys](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/qualys/qualys.md)
- [Quest KACE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/quest-kace.md)
- [Quest KACE](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/quest-kace/quest-kace.md)
- [Radware](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/radware.md)
- [Radware](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/radware/radware.md)
- [Rapid7](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rapid7.md)
- [Rapid7](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rapid7/rapid7.md)
- [Razor Group](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/razor-group.md)
- [Razor Group](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/razor-group/razor-group.md)
- [Recorded Future](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/recorded-future.md)
- [Recorded Future](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/recorded-future/recorded-future.md)
- [Red Hat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/red-hat.md)
- [Red Hat Ansible](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/red-hat/red-hat-ansible.md)
- [Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/redis-labs.md)
- [Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/redis-labs/redis-labs.md)
- [Redmine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/redmine.md)
- [Redmine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/redmine/redmine.md)
- [ReliaQuest](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/reliaquest.md)
- [ReliaQuest](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/reliaquest/reliaquest.md)
- [RemoteAccess](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/remoteaccess.md)
- [RemoteAccess](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/remoteaccess/remoteaccess.md)
- [Retarus](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/retarus.md)
- [Retarus](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/retarus/retarus.md)
- [RSA](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rsa.md)
- [RSA](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rsa/rsa.md)
- [RTIR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rtir.md)
- [RTIR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/rtir/rtir.md)
- [runZero](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/runzero.md)
- [runZero](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/runzero/runzero.md)
- [Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/salesforce.md)
- [Ingest logs and data from Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/salesforce/ingest-logs-and-data-from-salesforce.md)
- [Salesforce connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/salesforce/ingest-and-run-salesforce-automation-and-remediation.md)
- [SailPoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sailpoint.md)
- [SailPoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sailpoint/sailpoint.md)
- [Samhaus](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/samhaus.md)
- [Samhaus](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/samhaus/samhaus.md)
- [SANS DShield](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sans-dshield.md)
- [SANS DShield](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sans-dshield/sans-dshield.md)
- [SAP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sap.md)
- [SAP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sap/sap.md)
- [SAP Ariba](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sap/sap-ariba.md)
- [Saviynt](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/saviynt.md)
- [Saviynt](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/saviynt/saviynt.md)
- [SecurityScorecard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/securityscorecard.md)
- [SecurityScorecard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/securityscorecard/securityscorecard.md)
- [Securonix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/securonix.md)
- [Securonix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/securonix/securonix.md)
- [Sentry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentry.md)
- [Sentry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentry/sentry.md)
- [SentinelOne](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentinelone.md)
- [SentinelOne DeepVisibility](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentinelone/sentinelone-deepvisibility.md)
- [Ingest raw EDR events from SentinelOne DeepVisibility](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentinelone/sentinelone-deepvisibility/ingest-raw-edr-events-from-sentinelone-deepvisibility.md)
- [SentinelOne](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentinelone/sentinelone.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenow.md)
- [ServiceNow CDMB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenow/servicenow-cdmb.md)
- [Ingest data from ServiceNow CMDB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenow/servicenow-cdmb/ingest-data-from-servicenow-cmdb.md)
- [ServiceNow Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenow/servicenow-automation-and-collection.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenow/servicenow.md)
- [Shopify](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/shopify.md)
- [Shopify](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/shopify/shopify.md)
- [Shodan](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/shodan.md)
- [Shodan](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/shodan/shodan.md)
- [Skyhigh Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/skyhigh-security.md)
- [Skyhigh Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/skyhigh-security/skyhigh-security.md)
- [Slack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/slack.md)
- [Slack Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/slack/slack-automation-and-collection.md)
- [Slack Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/slack/slack-enterprise.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/smb.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/smb/smb.md)
- [SMIME Messaging](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/smime-messaging.md)
- [SMIME Messaging](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/smime-messaging/smime-messaging.md)
- [Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/snowflake.md)
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/snowflake/how-to-onboard-snowflake.md)
- [Snowflake Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/snowflake/snowflake-automation-and-collection.md)
- [SolarWinds](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/solarwinds.md)
- [SolarWinds](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/solarwinds/solarwinds.md)
- [Sophos](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sophos.md)
- [Sophos](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sophos/sophos.md)
- [Splunk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/splunk.md)
- [Splunk Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/splunk/splunk-automation-and-collection.md)
- [Splunk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/splunk/splunk.md)
- [Sublime Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sublime-security.md)
- [Sublime Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sublime-security/sublime-security.md)
- [Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sumo-logic.md)
- [Sumo Logic Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sumo-logic/sumo-logic-automation-and-collection.md)
- [Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sumo-logic/sumo-logic.md)
- [SysAid](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sysaid.md)
- [SysAid](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sysaid/sysaid.md)
- [Syslog Sender](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/syslog-sender.md)
- [Syslog Sender](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/syslog-sender/syslog-sender.md)
- [Tanium](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tanium.md)
- [Tanium](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tanium/tanium.md)
- [TAXII](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/taxii.md)
- [TAXII](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/taxii/taxii.md)
- [TeamViewer](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/teamviewer.md)
- [TeamViewer](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/teamviewer/teamviewer.md)
- [Telegram](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/telegram.md)
- [Telegram](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/telegram/telegram.md)
- [Tenable](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tenable.md)
- [Tenable](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tenable/tenable.md)
- [Terraform](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/terraform.md)
- [Terraform](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/terraform/terraform.md)
- [Thales](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thales.md)
- [Thales](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thales/thales.md)
- [TheHive](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thehive.md)
- [TheHive](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thehive/thehive.md)
- [Thinkst Canary](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thinkst-canary.md)
- [Thinkst Canary](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/thinkst-canary/thinkst-canary.md)
- [ThreatConnect](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatconnect.md)
- [ThreatConnect](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatconnect/threatconnect.md)
- [ThreatMiner.org](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatminer.org.md)
- [ThreatMiner.org](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatminer.org/threatminer.org.md)
- [ThreatX](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatx.md)
- [ThreatX](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/threatx/threatx.md)
- [Tidy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tidy.md)
- [Tidy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tidy/tidy.md)
- [TOPdesk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/topdesk.md)
- [TOPdesk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/topdesk/topdesk.md)
- [Tor Exit Adress](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tor-exit-adress.md)
- [Tor Exit Adress](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/tor-exit-adress/tor-exit-adress.md)
- [Trellix](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix.md)
- [Trellix Database Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-database-security.md)
- [Trellix Email Security (ETP)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-email-security-etp.md)
- [Trellix Email Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-email-security.md)
- [Trellix Endpoint (HX)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-endpoint-hx.md)
- [Trellix ePO](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-epo.md)
- [Trellix Network](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-network.md)
- [Trellix Sandbox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-sandbox.md)
- [Trellix SIEM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-siem.md)
- [Trellix Threat Intel](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-threat-intel.md)
- [TrendAI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trendai.md)
- [TrendAI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trendai/trendai.md)
- [Twilio](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/twilio.md)
- [Twilio](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/twilio/twilio.md)
- [Uptycs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/uptycs.md)
- [Uptycs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/uptycs/uptycs.md)
- [Vectra](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vectra.md)
- [Vectra](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vectra/vectra.md)
- [Versa Networks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/versa-networks.md)
- [Versa Networks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/versa-networks/versa-networks.md)
- [VMware](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vmware.md)
- [VMware Automation and Colection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vmware/vmware-automation-and-colection.md)
- [VMWare](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vmware/vmware.md)
- [VulnDB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vulndb.md)
- [VulnDB](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vulndb/vulndb.md)
- [WhatsMyBrowser.org](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/whatsmybrowser.org.md)
- [WhatsMyBrowser.org](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/whatsmybrowser.org/whatsmybrowser.org.md)
- [Whois](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/whois.md)
- [Whois](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/whois/whois.md)
- [WithSecure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/withsecure.md)
- [WithSecure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/withsecure/withsecure.md)
- [Workday](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workday.md)
- [Ingest report data from Workday](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workday/ingest-report-data-from-workday.md)
- [Workday Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workday/workday-automation-and-collection.md)
- [Workday](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workday/workday.md)
- [X](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/x.md)
- [X Automation and Remediation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/x/x-automation-and-remediation.md)
- [YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/youtrack.md)
- [YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/youtrack/youtrack.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zendesk.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zendesk/zendesk.md)
- [Zero Networks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zero-networks.md)
- [Zero Networks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zero-networks/zero-networks.md)
- [Zimperium](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zimperium.md)
- [Zimperium](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zimperium/zimperium.md)
- [Zoom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zoom.md)
- [Zoom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zoom/zoom.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler.md)
- [Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscaler-internet-access.md)
- [Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscaler-private-access.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscaler.md)
- [Connectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/connectors.md): Configure connectors that collect and enrich data in Cortex XSIAM.
- [Standard data sources](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/standard-data-sources.md): Configure standard data sources to ingest telemetry into Cortex XSIAM.
- [Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding.md): Learn about onboarding your cloud service provider to Cortex XSIAM.
- [Understand CSP onboarding tiers and licensing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/understand-csp-onboarding-tiers-and-licensing.md): Understand the license tiers and capabilities available for CSP onboarding in Cortex XSIAM.
- [Amazon Web Services cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding.md): Follow the AWS onboarding wizard, and Cortex XSIAM creates a custom authentication template to be deployed in AWS.
- [AWS security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-capabilities-and-deployment-planning.md): Plan AWS security capabilities for Cortex XSIAM cloud onboarding.
- [AWS resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-resource-inventory.md): Inventory AWS resources for Cortex XSIAM cloud onboarding.
- [AWS security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-model-and-authentication.md): Understand AWS authentication for Cortex XSIAM cloud onboarding.
- [Cortex XSIAM and AWS audit log collection architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/cortex-cloud-and-aws-audit-log-collection-architecture.md): Understand AWS audit log collection architecture for Cortex XSIAM.
- [Onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/onboard-amazon-web-services.md): Follow the AWS onboarding wizard, and Cortex XSIAM creates a custom authentication template to be executed in AWS.
- [Prerequisites for onboarding AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/prerequisites-for-onboarding-aws.md): Before you begin onboarding AWS, you must review the following prerequisites.
- [How to onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/how-to-onboard-amazon-web-services.md): Follow the AWS onboarding wizard and Cortex XSIAM creates a custom authentication template to be deployed in AWS CloudFormation.
- [Deploy the authentication template in AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/deploy-the-authentication-template-in-aws.md): Learn how to deploy the Terraform or CloudFormation authentication template in Amazon Web Services.
- [Post-deployment: Custom (BYOB) and Control Tower audit log collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/post-deployment-custom-byob-audit-log-collection.md): Configure AWS audit log collection after Cortex XSIAM deployment.
- [Grant cross-account KMS key access for Control Tower BYOB log collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/grant-cross-account-kms-key-access-for-control-tower-byob-log-collection.md): Learn how to configure cross-account AWS KMS key permissions for Cortex Control Tower BYOB log collection. Step-by-step guide to updating KMS key policies.
- [AWS post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-post-deployment-verification.md): After you have completed the AWS onboarding wizard and you have deployed the authentication template in AWS (using CloudFormation or Terraform), verify that the deployment succeeded.
- [Microsoft Azure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding.md): Onboard Microsoft Azure cloud resources to Cortex XSIAM.
- [Onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Prerequisites for onboarding Azure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/prerequisites-for-onboarding-azure.md): Before you begin onboarding Microsoft Azure, you must review the following prerequisites.
- [How to onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Finalize Microsoft Azure onboarding by executing the authentication template](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/finalize-microsoft-azure-onboarding-by-executing-the-authentication-template.md): Learn how to execute the authentication template file in Microsoft Azure for subscriptions, tenants, and management groups. We provide instructions both for applying the Terraform template's configura
- [Microsoft Azure offboarding overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview.md): This section contains the technical procedures required to safely decommission and offboard your Cortex XSIAM resources in Microsoft Azure.
- [Offboard Terraform-based Azure deployments (all scopes)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-terraform-based-azure-deployments-all-scopes.md): How to offboard all Terraform-based Microsoft Azure scopes from Cortex XSIAM: A step-by-step technical guide to safely running Terraform destroy and cleaning up policy-deployed resources.
- [Offboard Azure subscription (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-subscription-arm.md): How to offboard a Microsoft Azure subscription scope that was onboarded using ARM: A step-by-step technical guide to safely running the interactive offboarding script and cleaning up all resources.
- [Offboard Azure management group or tenant scope (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-management-group-or-tenant-scope-arm.md): How to offboard Microsoft Azure management group or tenant scopes from Cortex XSIAM: A step-by-step technical guide to safely removing all Azure resources deployed by Cortex onboarding templates.
- [Offboard Azure tenant with Entra ID only](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-tenant-with-entra-id-only.md): How to offboard a Microsoft Azure tenant onboarded with the Entra ID only option from Cortex XSIAM: A step-by-step technical guide to safely removing deployed resources.
- [Google Cloud Platform onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding.md): Onboard Google Cloud Platform resources to Cortex XSIAM.
- [Onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex creates a custom authentication template to be executed in GCP.
- [Prerequisites for onboarding GCP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/prerequisites-for-onboarding-gcp.md): Before you begin onboarding GCP, you must review the following prerequisites.
- [How to onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex XSIAM creates a custom authentication template to be applied in GCP.
- [How to onboard GCP with foundational configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-microsoft-azure-with-foundational-configuration.md): Onboard GCP with foundational configuration for Cortex XSIAM.
- [Deploy the Terraform authentication template in GCP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/deploy-the-terraform-authentication-template-in-gcp.md): Learn how to deploy the Terraform authentication template in Google Cloud Console.
- [Connect Google Workspace with your GCP cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/connect-google-workspace-with-your-gcp-cloud-instance.md): Connect Google Workspace to Cortex XSIAM through your GCP instance.
- [Monitor GCP resources inside service perimeters](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/monitor-gcp-resources-inside-service-perimeters.md): Learn how to grant authorization to Cortex XSIAM to scan within your GCP service perimeter.
- [Oracle Cloud Infrastructure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding.md): Follow the Oracle Cloud Infrastructure onboarding wizard and Cortex XSIAM creates a custom Terraform authentication template to be deployed in Oracle Cloud Infrastructure.
- [Onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard, and Cortex creates a custom authentication template to be executed in OCI.
- [Prerequisites for onboarding OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/prerequisites-for-onboarding-oci.md): Before you begin onboarding Oracle Cloud Infrastructure, you must review the following prerequisites.
- [How to onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/how-to-onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard and Cortex XSIAM creates a custom authentication template to be applied in OCI.
- [How to onboard Oracle Cloud Infrastructure with foundational configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/how-to-onboard-oracle-cloud-infrastructure-with-foundational-configuration.md): Onboard Oracle Cloud Infrastructure to Cortex XSIAM.
- [Deploy the Terraform authentication template in OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/deploy-the-terraform-authentication-template-in-oci.md): Learn how to deploy the Terraform authentication template in Oracle Cloud Infrastructure.
- [Alibaba Cloud cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding.md): Follow the Alibaba Cloud onboarding wizard and Cortex XSIAM creates a custom Terraform authentication template to be deployed in Alibaba Cloud.
- [Alibaba security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-security-capabilities-and-deployment-planning.md): Plan Alibaba Cloud security capabilities for Cortex XSIAM onboarding.
- [Alibaba Cloud resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-resource-inventory.md): Inventory Alibaba Cloud resources for Cortex XSIAM onboarding.
- [Alibaba Cloud security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-security-model-and-authentication.md): Understand Alibaba Cloud authentication for Cortex XSIAM onboarding.
- [Onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/onboard-alibaba-cloud.md): Follow the Alibaba Cloud onboarding wizard and Cortex XSIAM creates a custom CloudFormation authentication template to be deployed in Alibaba Cloud.
- [Prerequisites for onboarding Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/prerequisites-for-onboarding-alibaba-cloud.md): Before you begin onboarding Alibaba Cloud, you must review the following prerequisites.
- [How to onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/how-to-onboard-alibaba-cloud.md): Onboard Alibaba Cloud resources to Cortex XSIAM.
- [Alibaba Cloud post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-post-deployment-verification.md): After you have completed the Alibaba Cloud onboarding wizard and you have deployed the authentication template in Alibaba Cloud, verify that the deployment succeeded.
- [Outpost onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding.md): Learn about outposts, which are a dedicated set of infrastructure resources that extends the reach of Cortex XSIAM into your environment.
- [Outpost fundamentals and planning](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-fundamentals-and-planning.md): An outpost enables you to have security scans performed on infrastructure in a cloud account owned by you. Learn about outpost fundamentals and what to consider when planning your outpost.
- [Outpost creation workflow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-creation-workflow.md): Learn about the creation process for an outposts, which facilitate security scanning performed on infrastructure in a cloud account owned by you.
- [Working with standard outposts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts.md): Standard outposts are the recommended way to create dedicated set of infrastructure resources that extends the reach of Cortex XSIAM into your environment.
- [Create a standard outpost](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts/create-a-standard-outpost.md): Instructions for creating a standard outpost while onboarding your CSP.
- [Working with Bringing your own Azure app (BYOA) outposts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts.md): Using advanced settings while creating your outpost, you can deploy a Cortex Cloud Azure outpost using your own pre-created Entra ID app registration.
- [Task 1: Meet the prerequisites for Azure BYOA outposts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-1-meet-the-prerequisites-for-azure-byoa-outposts.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page lists the prerequisites that must be met before customizing your outpost in this way.
- [Task 2: Create the app registration for the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-2-create-the-app-registration-for-the-azure-byoa-outpost.md): You can customize your own outpost for Azure by bringing your own app (BYOA). This page describes the steps for creating the app registration.
- [Task 3: Deploy the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-3-deploy-the-azure-byoa-outpost.md): You can customize your own outpost by bringing your own app (BYOA). This page describes the steps for deploying the Azure BYOA outpost.
- [Task 4: Verify the BYOA outpost deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-4-verify-the-byoa-outpost-deployment.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page describes the steps for verifying your BYOA outpost deployment.
- [The shell script for Azure app registration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/the-shell-script-for-azure-app-registration.md): You can run this helper shell script to set up your resources and retrieve their IDs for use while creating your Azure BYOA outpost. This page provides technical, "read-me style" details about the scr
- [Outpost troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-troubleshooting.md): Check here for solutions to issues that might occur while configuring, deploying, and operating outposts.
- [Outpost Cloud Service Provider (CSP) permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions.md): This page lists and explains the various roles and permissions needed for working with resources for outposts by CSP.
- [Amazon Web Services (AWS) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/amazon-web-services-aws-outpost-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex XSIAM outpost onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/microsoft-azure-outpost-permissions.md): List of Microsoft Azure provider outpost permissions for Cortex XSIAM.
- [Google Cloud Platform (GCP) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/google-cloud-platform-gcp-outpost-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex XSIAM onboarding outposts to enable continuous monitoring in your cloud environment.
- [Introduction to Terraform for Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/introduction-to-terraform-for-cloud-service-provider-csp-onboarding.md): Learn how to onboard Cloud Service Providers (CSPs) using Terraform. Discover step-by-step workflows for initial provisioning, updates, and Cloud Shell deployment.
- [Manually connect a cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/manually-connect-a-cloud-instance.md): Manually connect a cloud instance to Cortex XSIAM.
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/manage-cloud-instances.md): Manage cloud instances connected to Cortex XSIAM.
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/pending-cloud-instances.md): Review pending cloud instances in Cortex XSIAM.
- [Edit your onboarded CSP configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/edit-your-onboarded-csp-configuration.md): Update onboarded cloud configurations in Cortex XSIAM.
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/update-cloud-permissions-after-cortex-release-updates.md): Manage permission updates for your cloud instances following new feature releases or bug fixes.
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/troubleshoot-errors-on-cloud-instances.md): You can troubleshoot errors on cloud instances by drilling down on an instance from the Data Sources & Integrations page.
- [Cloud service provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions.md): Grant the correct cloud service provider permissions for Cortex XSIAM.
- [Amazon Web Services (AWS) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/amazon-web-services-aws-provider-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex XSIAM onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/microsoft-azure-provider-permissions.md): List of Microsoft Azure provider permissions for Cortex XSIAM.
- [Google Cloud Platform (GCP) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/google-cloud-platform-gcp-provider-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex XSIAM onboarding to enable continuous monitoring in your cloud environment.
- [Oracle Cloud Infrastructure (OCI) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/oracle-cloud-infrastructure-oci-provider-permissions.md): List of Oracle Cloud Infrastructure provider permissions for Cortex XSIAM.
- [Generic on-premise data collectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors.md): Configure generic on-premise data collectors for Cortex XSIAM.
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets.md): Configure Broker VM data collector applets for Cortex XSIAM.
- [Activate Apache Kafka Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-apache-kafka-collector.md): Configure this collector for Cortex XSIAM.
- [Activate Cortex Network Scanner](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-cortex-network-scanner.md): Configure this scanner for Cortex XSIAM.
- [Activate CSV Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-csv-collector.md): Configure this collector for Cortex XSIAM.
- [Activate Database Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-database-collector.md): Configure this collector for Cortex XSIAM.
- [Activate DSPM Fileshare](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-fileshare.md): Configure this data source for Cortex XSIAM.
- [Activate Files and Folders Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-files-and-folders-collector.md): Configure this collector for Cortex XSIAM.
- [Activate FTP Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-ftp-collector.md): Configure this collector for Cortex XSIAM.
- [Activate Local Agent Settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-local-agent-settings.md): Configure local agent settings for Cortex XSIAM.
- [Activate NetFlow Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-netflow-collector.md): Configure this collector for Cortex XSIAM.
- [Activate Network Mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-network-mapper.md): Configure Network Mapper for Cortex XSIAM.
- [Activate Registry Scanner](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-registry-scanner.md): Configure Registry Scanner for Cortex XSIAM.
- [Syslog Collector applet](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet.md): Configure the Syslog Collector applet for Cortex XSIAM.
- [Activate Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/activate-syslog-collector.md): Configure the Syslog Collector for Cortex XSIAM.
- [Ingest logs from a Syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/ingest-logs-from-a-syslog-receiver.md): To extend visibility, Cortex XSIAM can receive Syslog from additional vendors that use CEF or LEEF formatted over Syslog (TLS not supported).
- [Check Point FW1 VPN1](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1.md): Ingest Check Point firewall data into Cortex XSIAM.
- [Ingest logs from Check Point firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1/ingest-logs-from-check-point-firewalls.md): Ingest Check Point firewall logs into Cortex XSIAM.
- [Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect.md): Ingest Cisco ASA and AnyConnect data into Cortex XSIAM.
- [Ingest logs from Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect/ingest-logs-from-cisco-asa-firewalls-and-anyconnect.md): Ingest Cisco ASA and AnyConnect logs into Cortex XSIAM.
- [Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/corelight-zeek.md): Ingest Corelight Zeek data into Cortex XSIAM.
- [Ingest logs from Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/corelight-zeek/ingest-logs-from-corelight-zeek.md): Ingest Corelight Zeek logs into Cortex XSIAM.
- [Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/forcepoint-dlp.md): Ingest Forcepoint DLP data into Cortex XSIAM.
- [Ingest logs from Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/forcepoint-dlp/ingest-logs-from-forcepoint-dlp.md): Ingest Forcepoint DLP logs into Cortex XSIAM.
- [Fortinet Fortigate](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/fortinet-fortigate.md): Ingest Fortinet FortiGate data into Cortex XSIAM.
- [Ingest logs from Fortinet Fortigate firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/fortinet-fortigate/ingest-logs-from-fortinet-fortigate-firewalls.md): Ingest Fortinet FortiGate logs into Cortex XSIAM.
- [Next Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/next-generation-firewall.md): Ingest next-generation firewall data into Cortex XSIAM.
- [Ingest Next-Generation Firewall logs using the Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md): Ingest firewall logs through Syslog Collector into Cortex XSIAM.
- [PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/pingfederate.md): Ingest PingFederate data into Cortex XSIAM.
- [Ingest authentication logs from PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/pingfederate/ingest-authentication-logs-from-pingfederate.md): Ingest PingFederate authentication logs into Cortex XSIAM.
- [Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access.md): Ingest Zscaler Internet Access data into Cortex XSIAM.
- [Ingest logs from Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access/ingest-logs-from-zscaler-internet-access.md): Ingest Zscaler Internet Access logs into Cortex XSIAM.
- [Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-private-access.md): Ingest Zscaler Private Access data into Cortex XSIAM.
- [Ingest logs from Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-private-access/ingest-logs-from-zscaler-private-access.md): Ingest Zscaler Private Access logs into Cortex XSIAM.
- [Activate Transporter](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter.md): Configure Transporter for Cortex XSIAM.
- [Activate Windows Event Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector.md): Configure Windows Event Collector for Cortex XSIAM.
- [Activate Windows Event Collector on Windows Core](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector/activate-windows-event-collector-on-windows-core.md): Configure Windows Core event collection for Cortex XSIAM.
- [Renew WEC certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector/renew-wec-certificates.md): Renew Windows Event Collector certificates for Cortex XSIAM.
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors.md): Use XDR Collectors to collect data for Cortex XSIAM.
- [XDR Collector audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-audit-logs.md): Review XDR Collector audit logs in Cortex XSIAM.
- [XDR Collector machine requirements and supported operating systems](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-machine-requirements-and-supported-operating-systems.md): Review XDR Collector requirements for Cortex XSIAM.
- [Resources required to enable access to XDR collectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/resources-required-to-enable-access-to-xdr-collectors.md): Review required collector access resources for Cortex XSIAM.
- [Manage XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors.md): Manage XDR Collectors in Cortex XSIAM.
- [XDR Collectors installation resource for Windows and Linux](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/xdr-collectors-installation-resource-for-windows-and-linux.md): Install XDR Collectors for Cortex XSIAM.
- [Create an XDR Collector installation package](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/create-an-xdr-collector-installation-package.md): Create an XDR Collector package for Cortex XSIAM.
- [Install the XDR Collector installation package for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows.md): Install an XDR Collector on Windows for Cortex XSIAM.
- [Install the XDR collector on Windows using the MSI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-the-msi.md): Install an XDR Collector MSI for Cortex XSIAM.
- [Install the XDR Collector on Windows using Msiexec](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-msiexec.md): Install an XDR Collector with Msiexec for Cortex XSIAM.
- [Install the XDR Collector installation package for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-linux.md): Install an XDR Collector on Linux for Cortex XSIAM.
- [Configure XDR Collector upgrade scheduler](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/configure-xdr-collector-upgrade-scheduler.md): Schedule XDR Collector upgrades for Cortex XSIAM.
- [Set an application proxy for XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/set-an-application-proxy-for-xdr-collectors.md): Configure an XDR Collector proxy for Cortex XSIAM.
- [Set an alias for an XDR Collector machine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/set-an-alias-for-an-xdr-collector-machine.md): Set an XDR Collector machine alias in Cortex XSIAM.
- [Upgrade XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/upgrade-xdr-collectors.md): Upgrade XDR Collectors for Cortex XSIAM.
- [Uninstall the XDR Collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/uninstall-the-xdr-collector.md): Uninstall an XDR Collector from Cortex XSIAM.
- [Define XDR Collector machine groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/define-xdr-collector-machine-groups.md): Define XDR Collector machine groups in Cortex XSIAM.
- [About Cortex XDR Collector content updates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/about-cortex-xdr-collector-content-updates.md): Understand XDR Collector content updates for Cortex XSIAM.
- [XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles.md): Configure XDR Collector profiles for Cortex XSIAM.
- [Add an XDR Collector profile for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows.md): Add a Windows XDR Collector profile for Cortex XSIAM.
- [How to configure XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/how-to-configure-xdr-collector-profiles.md): Configure XDR Collector profiles for Cortex XSIAM.
- [Additional XDR Collector profile management options](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/additional-xdr-collector-profile-management-options.md): Manage XDR Collector profiles in Cortex XSIAM.
- [Query Windows Event Log records](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/query-windows-event-log-records.md): Query Windows Event Log records for Cortex XSIAM.
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md): Ingest Windows DHCP logs into Cortex XSIAM.
- [Ingest Windows DNS debug logs using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/ingest-windows-dns-debug-logs-using-elasticsearch-filebeat.md): Ingest Windows DNS logs into Cortex XSIAM.
- [Add an XDR Collector profile for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-linux.md): Add a Linux XDR Collector profile for Cortex XSIAM.
- [Apply profiles to collection machine policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/apply-profiles-to-collection-machine-policies.md): Apply collection profiles to Cortex XSIAM policies.
- [XDR Collector datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-datasets.md): Review XDR Collector datasets in Cortex XSIAM.
- [Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations.md): Configure Palo Alto Networks integrations for Cortex XSIAM.
- [Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cloud-next-generation-firewall.md): Configure Cloud NGFW data ingestion for Cortex XSIAM.
- [Ingest data from Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cloud-next-generation-firewall/ingest-data-from-cloud-next-generation-firewall.md): Ingest Cloud NGFW data into Cortex XSIAM.
- [Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall.md): Configure Next-Generation Firewall ingestion for Cortex XSIAM.
- [Ingest data from Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-data-from-next-generation-firewall.md): Ingest Next-Generation Firewall data into Cortex XSIAM.
- [Ingest Next-Generation Firewall logs using the Syslog collector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md): Ingest firewall Syslog data into Cortex XSIAM.
- [Panorama](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall/panorama.md): Configure Panorama data ingestion for Cortex XSIAM.
- [Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-access.md): Configure Prisma Access data ingestion for Cortex XSIAM.
- [Ingest data from Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-access/ingest-data-from-prisma-access.md): Ingest Prisma Access data into Cortex XSIAM.
- [Palo Alto Networks Prisma](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-access/palo-alto-networks-prisma.md): Configure Palo Alto Networks Prisma for Cortex XSIAM.
- [Prisma Access Browser](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-access-browser.md): Configure Prisma Access Browser for Cortex XSIAM.
- [Ingest logs from Prisma Access Browser](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-access-browser/ingest-logs-from-prisma-access-browser.md): Ingest Prisma Access Browser logs into Cortex XSIAM.
- [Ingest detection data from Strata Logging Service](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/ingest-detection-data-from-strata-logging-service.md): Ingest Palo Alto Networks detection data from Strata Logging Service into Cortex XSIAM, migrate legacy collectors to Cortex Native Data Lake, and query logs with XQL.
- [IoT Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/iot-security.md): Configure IoT Security data ingestion for Cortex XSIAM.
- [Ingest alerts and assets from IoT Security (Deprecated)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/iot-security/ingest-alerts-and-assets-from-iot-security.md): Ingest legacy IoT Security data into Cortex XSIAM.
- [Ingest alerts and assets from Device Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/iot-security/ingest-alerts-and-assets-from-device-security.md): Ingest Device Security alerts and assets into Cortex XSIAM.
- [IoT Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/iot-security/iot-security.md): Use IoT Security data with Cortex XSIAM.
- [Cortex Attack Surface Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cortex-attack-surface-management.md): Configure Attack Surface Management data for Cortex XSIAM.
- [Cortex Automation Developer Tools](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cortex-automation-developer-tools.md): Use Cortex Automation Developer Tools with Cortex XSIAM.
- [Cortex Data Lake](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cortex-data-lake.md): Configure Cortex Data Lake data for Cortex XSIAM.
- [Cortex Internals](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cortex-internals.md): Use Cortex Internals data with Cortex XSIAM.
- [Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cortex-xdr.md): Use Cortex XDR data with Cortex XSIAM.
- [Enterprise DLP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/enterprise-dlp.md): Configure Enterprise DLP data for Cortex XSIAM.
- [Palo Alto Networks Cortex](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/palo-alto-networks-cortex.md): Configure Palo Alto Networks Cortex data for Cortex XSIAM.
- [PAN PSIRT Advisories](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/pan-psirt-advisories.md): Ingest PAN PSIRT advisories into Cortex XSIAM.
- [Prisma Cloud Compute](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-cloud-compute.md): Configure Prisma Cloud Compute data for Cortex XSIAM.
- [Prisma Cloud CSPM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-cloud-cspm.md): Configure Prisma Cloud CSPM data for Cortex XSIAM.
- [SaaS Security (Aperture)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/saas-security-aperture.md): Configure SaaS Security data for Cortex XSIAM.
- [Threat Vault](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/threat-vault.md): Use Threat Vault data with Cortex XSIAM.
- [WildFire Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/wildfire-cloud.md): Configure WildFire Cloud data for Cortex XSIAM.
- [Log type filtering](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/log-type-filtering.md)
- [Collecting URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/collecting-url-and-file-log-types.md): Configure URL and File log collection for Palo Alto Networks integrations in pre-3.x Cortex XSIAM to balance analytics visibility, correlation rules, and ingestion costs.
- [Detectors connected to URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/collecting-url-and-file-log-types/detectors-connected-to-url-and-file-log-types.md): Review Cortex XSIAM detectors affected when URL or File log collection is disabled, including impacts on cyberattack detection, investigation context, and correlation rules.
- [Cloud Posture and Runtime Security data sources](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources.md): Learn more about the Cloud Posture and Runtime Security data sources in Cortex XSIAM.
- [How to onboard on-premise assets to Cloud Data Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-on-premise-assets-to-cloud-data-security.md): Onboard on-premise assets to Cloud Data Security with Cortex XSIAM.
- [Activate DSPM Fileshare](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-on-premise-assets-to-cloud-data-security/activate-dspm-fileshare.md): Activate the DSPM Fileshare applet on a Broker VM in Cortex XSIAM.
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-databricks.md): Add Databricks as a Cortex XSIAM data source.
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-microsoft-365.md): Add Microsoft 365 as a Cortex XSIAM data source.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/ingest-logs-and-data-from-okta.md): Configure Okta log and configuration data ingestion for Cortex XSIAM.
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-snowflake.md): Add Snowflake as a Cortex XSIAM data source.
- [Activate AppSec Transporter](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/activate-appsec-transporter.md): Activate and manage the AppSec Transporter on a Cortex XSIAM Broker VM for secure self-hosted VCS connectivity and code scanning.
- [Container Registries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning.md): Connect and scan cloud and third-party container registries in Cortex XSIAM to identify image vulnerabilities, malware, exposed secrets, and policy violations.
- [Registry Components](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/registry-components.md): Learn about the container registry components that Cortex XSIAM uses for registry scanning.
- [How Container Registry Scanning Works](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/how-container-registry-scanning-works.md): Learn how Cortex XSIAM scans container registries and evaluates container image risks.
- [Configure registry scanning for cloud accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/configure-registry-scanning-for-cloud-accounts.md): Configure Cortex XSIAM to scan container registries in connected cloud accounts.
- [Modify the container registry scanning scope](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/modify-the-container-registry-scanning-scope.md): Modify the Cortex XSIAM container registry scanning scope for cloud accounts and registries.
- [Scan re-evaluation process](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/scan-re-evaluation-process.md): Understand how Cortex XSIAM re-evaluates container registry scan results.
- [Connect Docker Hub registry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry.md): Connect a Docker Hub registry to Cortex XSIAM for container image scanning.
- [Manage a Docker Hub connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry/manage-a-docker-hub-connector.md): Manage the Docker Hub registry connector in Cortex XSIAM.
- [Connect Docker V2 compliant container registry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry.md): Connect a Docker V2-compliant registry to Cortex XSIAM for container image scanning.
- [Manage a Docker V2 connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry/manage-a-docker-v2-connector.md): Manage the Docker V2-compliant registry connector in Cortex XSIAM.
- [Connect GitLab container registry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry.md): Connect a GitLab container registry to Cortex XSIAM for image scanning.
- [Manage a GitLab Container Registry connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry/manage-a-gitlab-container-registry-connector.md): Manage the GitLab Container Registry connector in Cortex XSIAM.
- [Connect Harbor registry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry.md): Connect a Harbor registry to Cortex XSIAM for container image scanning.
- [Manage a Harbor connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry/manage-a-harbor-connector.md): Manage the Harbor registry connector in Cortex XSIAM.
- [Connect JFrog container registry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry.md): Connect a JFrog container registry to Cortex XSIAM for image scanning.
- [Manage a JFrog connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry/manage-a-jfrog-connector.md): Manage the JFrog container registry connector in Cortex XSIAM.
- [Connect Sonatype Nexus registry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry.md): Connect a Sonatype Nexus registry to Cortex XSIAM for container image scanning.
- [Manage a Sonatype connector](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry/manage-a-sonatype-connector.md): Manage the Sonatype registry connector in Cortex XSIAM.
- [External alerts using External Issue Mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/external-alerts-using-external-issue-mapping.md): Learn more about collecting alerts from any external source using External Issue Mapping in Cortex XSIAM.
- [Ingest external alerts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/external-alerts-using-external-issue-mapping/ingest-external-alerts.md): Send external alerts to Cortex XSIAM and map source fields using External Issue Mapping.
- [Administration and troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting.md): Learn more about the administration and troubleshooting of the different data collector integrations in Cortex XSIAM.
- [Manage instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances.md): Manage data source and integration instances in Cortex XSIAM.
- [Add a new data source or instance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/add-a-new-data-source-or-instance.md): Add a data source or integration instance in Cortex XSIAM.
- [How to configure the scanning settings for supported services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/how-to-configure-the-scanning-settings-for-supported-services.md): Configure scanning settings for supported services in Cortex XSIAM.
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/manage-cloud-instances.md): Manage cloud instances connected to Cortex XSIAM.
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/update-cloud-permissions-after-cortex-release-updates.md): Update cloud permissions after Cortex XSIAM releases.
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/pending-cloud-instances.md): Review pending cloud instances in Cortex XSIAM.
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/troubleshoot-errors-on-cloud-instances.md): Troubleshoot errors on cloud instances in Cortex XSIAM.
- [Manage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/manage-kubernetes-connector-instances.md): Manage Kubernetes Connector instances in Cortex XSIAM.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations.md): Manage and configure integrations in Cortex XSIAM.
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/integration-use-cases.md): Explore common integration use cases in Cortex XSIAM.
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/add-an-integration-instance.md): Add and configure an integration instance in Cortex XSIAM.
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/configure-integration-permissions.md): Configure permissions for integrations in Cortex XSIAM.
- [Fetch issues from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/fetch-issues-from-an-integration-instance.md): Fetch issues from an integration instance in Cortex XSIAM.
- [Map fields to issue types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/fetch-issues-from-an-integration-instance/map-fields-to-issue-types.md): Map integration fields to issue types in Cortex XSIAM.
- [Classify events using a classifier for issue types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/fetch-issues-from-an-integration-instance/classify-events-using-a-classifier-for-issue-types.md): Classify integration events for issue types in Cortex XSIAM.
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/manage-credentials.md): Manage integration credentials securely in Cortex XSIAM.
- [Troubleshoot Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/troubleshoot-integrations.md): Troubleshoot integration issues in Cortex XSIAM.
- [Forward Requests to Long-Running Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/integrations/forward-requests-to-long-running-integrations.md): Forward requests to long-running integrations in Cortex XSIAM.
- [Verify collector connectivity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/verify-collector-connectivity.md): Check collector connection status, investigate errors, and track connectivity changes in Cortex XSIAM.
- [Overview of data ingestion metrics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics.md): Learn how Cortex XSIAM calculates and uses metrics to monitor data ingestion health.
- [Creating correlation rules to monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics/creating-correlation-rules-to-monitor-data-ingestion-health.md): Create correlation rules in Cortex XSIAM that detect data ingestion disruptions and trigger health issues.
- [Measuring data freshness](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics/measuring-data-freshness.md): Understand how Cortex XSIAM measures and reports delays between log creation and ingestion.
- [Health issues in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/about-health-issues.md): Understand Cortex XSIAM health issues, their types, and how to view and investigate them.
- [Investigate and resolve health issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/about-health-issues/investigate-and-resolve-health-issues.md): Investigate and resolve ingestion, collection, correlation, and automation health issues in Cortex XSIAM.
- [Monitor data ingestion health (BETA)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/about-health-issues/monitor-data-ingestion-health.md): Monitor data ingestion health using metrics, custom rules, and built-in issue detection in Cortex XSIAM
- [Monitor Correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/about-health-issues/monitor-correlation-rules.md): Monitor correlation rule executions, audit status, errors, and related health issues in Cortex XSIAM
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace.md): Use Marketplace, a centralized content portal, to download and manage content packs in Cortex XSIAM.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace/content-pack-support-types.md): Types of content packs support - Cortex supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace/marketplace-faqs.md): Frequently Asked Questions about Cortex XSIAM Marketplace Content
- [Content changes when upgrading Cortex XSIAM versions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace/content-changes-when-upgrading-cortex-xsiam-versions.md): Content updates when upgrading Cortex XSIAM versions.
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex Marketplace.
- [Configure the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1.md)
- [Agentic Assistant components and concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agentic-assistant-components-and-concepts.md): Learn about the key components and concepts, such as agents and actions in the Cortex Agentic Assistant
- [Agentic Assistant Hub](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub.md): Learn about personal and system agents in in the Agentic Assistant Hub
- [Manage actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub/manage-actions.md)
- [Register actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub/register-actions.md)
- [Manage agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub/manage-agents.md)
- [Build agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub/build-agents.md)
- [Manage knowledge sources (preview)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub/manage-knowledge-sources-preview.md): Enhance AI agent capabilities by leveraging the Knowledge Center (preview) to provide agents with your business-specific source of truth and built-in Cortex (system) knowledge.
- [Expand agent capabilities with MCP integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub/expand-agent-capabilities-with-mcp-integrations.md)
- [Agentic Assistant role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agentic-assistant-role-based-access-control.md): Configure permissions to access Cortex Agentic Assistant features.
- [Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-mcp-server.md): The Cortex MCP server enables you to leverage Cortex's powerful capabilities directly through natural language.
- [Install the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-mcp-server/install-the-cortex-mcp-server.md)
- [Configure the MCP client](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-mcp-server/configure-the-mcp-client.md)
- [Use the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-mcp-server/use-the-cortex-mcp-server.md)
- [Create custom Cortex MCP server tools](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-mcp-server/create-custom-cortex-mcp-server-tools.md)
- [Automations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations.md)
- [Automation in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/automation-in-cortex-xsiam.md): Automate response to issues, using playbooks and Quick Actions, triggered automatically by automation rules or manually from an issue.
- [Quick Actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/quick-actions.md)
- [Automation Exclusion Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/automation-exclusion-center.md): Automation exclusion policies prevent commands and scripts from performing remediation on critical assets.
- [Manage automation exclusion policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/automation-exclusion-center/manage-automation-exclusion-policies.md): Edit policies that exclude critical assets from automated remediation.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks.md)
- [Playbooks overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/playbooks-overview.md)
- [Access to playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/access-to-playbooks.md)
- [Playbook development checkli](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/playbook-development-checklist.md)
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/plan-your-playbook.md)
- [Manage playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/manage-playbooks.md)
- [Build your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook.md)
- [Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/choose-from-existing-playbooks-or-create-your-own.md)
- [Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/configure-playbook-settings.md)
- [Add objects from the Task Library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library.md)
- [Add commands and scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-commands-and-scripts.md)
- [Add sub-playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-sub-playbooks.md)
- [Add AI Prompt tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-ai-prompt-tasks.md)
- [Add manual tasks and blank tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks.md): Add manual and blank tasks to a playbook.
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-standard-task.md)
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-conditional-task.md)
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-communication-task.md)
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/create-a-section-header.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/configure-script-error-handling-in-a-playbook.md)
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook.md)
- [Configure a sub-playbook loop](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/configure-a-sub-playbook-loop.md)
- [Filter and Transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/filter-and-transform-data.md)
- [Create custom filter and transformers](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/create-custom-filter-and-transformers.md)
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/filter-considerations-categories-and-built-in-filters.md)
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/transformer-considerations-categories-and-built-in-transformers.md)
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/extend-context.md)
- [Extract Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/extract-indicators.md)
- [Update issue fields with playbook tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/customize-your-playbook/update-issue-fields-with-playbook-tasks.md)
- [Test your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/test-your-playbook.md): Set breakpoints, conditional breakpoints, skips, and input or output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/test-your-playbook/troubleshoot-playbook-performance.md)
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/manage-playbook-content.md)
- [Accelerate playbook development using the Automation Engineer agent (preview)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview.md)
- [Automation Engineer prompt examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview/automation-engineer-prompt-examples.md)
- [Best practices for playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/best-practices-for-playbooks.md)
- [Autonomous playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/autonomous-playbooks.md): Accelerate your incident response and reduce your team's workload with Autonomous Playbooks, fully managed security automation that automatically installs, updates, and maintains expert-level playbook
- [Enable autonomous playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/autonomous-playbooks/enable-autonomous-playbooks.md)
- [Manage autonomous playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/autonomous-playbooks/manage-autonomous-playbooks.md)
- [Manage autonomous automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/autonomous-playbooks/manage-autonomous-automation-rules.md)
- [Work Plan for autonomous playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/autonomous-playbooks/work-plan-for-autonomous-playbooks.md)
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/ai-prompts.md)
- [AI prompts role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/ai-prompts/ai-prompts-role-based-access-control.md): Manage AI prompt permissions with role-based access control.
- [Use existing prompts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/ai-prompts/use-existing-prompts.md): Find, duplicate, and edit prompts from the Prompts Library.
- [Create a prompt](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/ai-prompts/create-a-prompt.md): Create prompts, configure settings, and use them in agents or playbooks.
- [Write effective prompts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/ai-prompts/write-effective-prompts.md): Tips for creating effective AI prompts.
- [Agentic Response (Preview)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/agentic-response-preview.md): Learn how Agentic Response transitions automated SOC workflows from linear playbooks to dynamic, agentic automation by triggering AI agents directly from an automation rule.
- [Create an automation rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/create-an-automation-rule.md): Learn how to create an automation rule for an issue.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/scripts.md)
- [Access to scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/scripts/access-to-scripts.md)
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/scripts/use-existing-scripts.md)
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/scripts/create-a-script.md)
- [Accelerate script development using the Automation Engineer agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/scripts/accelerate-script-development-using-the-automation-engineer-agent.md)
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/scripts/change-the-docker-image-in-an-integration-or-script.md)
- [Context data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data.md): Use context data to assist with the investigation and remediation process.
- [Issue context data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data/issue-context-data.md): View and use context data stored for an issue.
- [Case context data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data/case-context-data.md): View and use context data stored for a case.
- [Search context data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data/search-context-data.md): Search and expand values in context data.
- [Add context data to an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data/add-context-data-to-an-issue.md): Add keys and values to issue context data.
- [Add context data to a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data/add-context-data-to-a-case.md): Add keys and values to case context data.
- [Delete context data from a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data/delete-context-data-from-a-case.md): Delete all or selected context data from a case.
- [Use context data in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/context-data/use-context-data-in-a-playbook.md): Access and update issue and case context data in playbooks.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists.md): Use lists to store data for use in playbooks and scripts.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists/create-a-list.md)
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists/list-commands.md)
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists/use-cases-json-lists.md)
- [Extract data from a JSON object](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists/use-cases-json-lists/extract-data-from-a-json-object.md)
- [Extract a subset of the data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists/use-cases-json-lists/extract-a-subset-of-the-data.md)
- [Filter extracted data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists/use-cases-json-lists/filter-extracted-data.md)
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/lists/transform-a-list-into-an-array-1.md)
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
- [Access to Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/jobs/access-to-jobs.md)
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/jobs/manage-jobs.md): Create, manage, and schedule playbook jobs
- [Create a time-triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/jobs/create-a-time-triggered-job.md): Schedule a playbook to run at a specific time
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Trigger a playbook when a feed changes
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine.md): Install, deploy and configure Cortex XSIAM engines.
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker.md): Install, configure, secure, and troubleshoot Docker for Cortex XSIAM engines.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/install-docker.md): Install Docker and verify engine user permissions.
- [Install Docker distribution for Red Hat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/install-docker-distribution-for-red-hat.md): Configure Docker and SELinux on Red Hat engine servers.
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-image-security.md): Secure, harden, and troubleshoot Docker images and containers.
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-faqs.md)
- [Troubleshoot Docker Issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
- [Change the Docker Installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide.md)
- [Docker network hardening](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide/docker-network-hardening.md)
- [Configure Docker images](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide/configure-docker-images.md)
- [Run Docker with non-root internal users](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
- [Configure the memory limit support without swap capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limit-support-without-swap-capabilities.md)
- [Configure the memory limitation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limitation.md)
- [Configure the CPU, PIDs, and open the file descriptors limit](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide/configure-the-cpu-pids-and-open-the-file-descriptors-limit.md)
- [Check Docker hardening configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/docker/docker-hardening-guide/check-docker-hardening-configurations.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/podman.md): Install, configure, and troubleshoot Podman for Cortex XSIAM engines.
- [Change the Container storage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/podman/change-the-container-storage.md): Configure Podman container storage for an engine.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/podman/install-podman.md): Install and configure Podman for Cortex XSIAM engines.
- [Migrate from Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/podman/migrate-from-docker-to-podman.md): Migrate an existing engine from Docker to Podman.
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/install-an-engine/podman/troubleshoot-podman.md): Resolve common Podman issues on Cortex XSIAM engines.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/manage-engines.md): Manage engines and load balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSIAM or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/configure-engines.md): Configure Cortex XSIAM engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md)
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/configure-engines/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/use-an-engine-in-an-integration.md): Use an engine or a load-balancing group of engines to fetch issues and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/engines/troubleshoot-integrations-running-on-engines.md)
- [Remote repository management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/remote-repository-management.md)
- [Cortex XSIAM development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/remote-repository-management/cortex-xsiam-development-tenant.md)
- [Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/remote-repository-management/set-up-a-remote-repository.md): Use a remote repository in Cortex XSIAM to enable centralized version control and streamlined collaboration across multiple environments.
- [Set up a built-in remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/remote-repository-management/set-up-a-remote-repository/set-up-a-built-in-remote-repository.md): Set up the built-in remote repository feature for production and development tenants.
- [Set up a Private Remote Repository](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/remote-repository-management/set-up-a-remote-repository/set-up-a-private-remote-repository.md): Set up the private remote repository feature.
- [Push and pull content](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/remote-repository-management/push-and-pull-content.md): Learn more about synchronizing content across different environments.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSIAM.
- [Customize cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues.md)
- [External integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/external-integrations.md): Integrate external threat intelligence and case management services with Cortex XSIAM.
- [Set up case scoring](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/set-up-case-scoring.md): Enable SmartScore and configure scoring rules for cases and issues.
- [Create a starring configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-a-starring-configuration.md): Create rules that automatically star matching issues and their linked cases.
- [Create custom case statuses and resolution reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-custom-case-statuses-and-resolution-reasons.md): Create custom case and issue statuses and resolution reasons for your workflow.
- [Create a sync profile](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-a-sync-profile.md)
- [Create a case domain](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-a-case-domain.md): Create custom case domains to organize workflows, statuses, resolution reasons, and access.
- [Customize case fields and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts.md)
- [Case fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-fields.md): View, manage, import, and export system, content pack, and custom case fields.
- [Case field types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-fields/case-field-types.md)
- [Create custom case fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-fields/create-custom-case-fields.md)
- [Create a grid field for a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-fields/create-a-grid-field-for-a-case.md)
- [Update case fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-fields/update-case-fields.md)
- [Case layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-layouts.md)
- [Create custom layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-layouts/create-custom-layouts.md)
- [Create rules for case layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-case-fields-and-layouts/case-layouts/create-rules-for-case-layouts.md)
- [Customize issue fields and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts.md)
- [Issue fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields.md)
- [Issue field types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/issue-field-types.md)
- [Create custom issue fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields.md): Create and manage custom issue fields for incoming data, layouts, and correlation rules.
- [Create a grid field for an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/create-a-grid-field-for-an-issue.md): Create configurable grid fields for displaying and editing tabular issue data.
- [Issue timer fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/issue-timer-fields.md): Track issue response times and SLAs with configurable timer fields.
- [Issue field-triggered scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/issue-field-triggered-scripts.md)
- [Configure issue timer fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/configure-issue-timer-fields.md)
- [Configure a playbook to run timers](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/configure-a-playbook-to-run-timers.md)
- [Automate changes to issue fields using timer scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/automate-changes-to-issue-fields-using-timer-scripts.md)
- [User issue timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-fields/user-issue-timer-field-commands-manually-in-the-cli.md)
- [Issue layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-layouts.md)
- [Create custom issue layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-layouts/create-custom-issue-layouts.md)
- [Add a custom widget to an issue layout](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-layouts/add-a-custom-widget-to-an-issue-layout.md)
- [Create rules for issue layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/customize-issue-fields-and-layouts/issue-layouts/create-rules-for-issue-layouts.md)
- [Create SLAs for case and issue resolution](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-slas-for-issue-resolution.md): Create SLA rules to set and track issue-resolution timers and time goals.
- [Create additional case timers and SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas.md)
- [Update case timer and SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas/update-case-timer-and-sla-fields.md)
- [Create issue exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-issue-exceptions.md): Create time-bound exceptions that pause issue SLA timers during approved remediation delays.
- [Configure the issue exception approval workflow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-issue-exceptions/configure-the-issue-exception-approval-workflow.md): Manage approvers and approval requirements for issue exception rules.
- [Create issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-issue-exceptions/create-issue-exception-rules.md): Create approval-based rules that temporarily pause SLA timers for selected issues.
- [Create an exception rule from an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-issue-exceptions/create-an-exception-rule-from-an-issue.md)
- [View issue Exception Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-issue-exceptions/view-issue-exception-rules.md)
- [Disable issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-issue-exceptions/disable-issue-exception-rules.md)
- [View excepted issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/create-issue-exceptions/view-excepted-issues.md)
- [Optimize case grouping in correlations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/optimize-case-grouping-in-correlations.md)
- [Run indicator extraction in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues/run-indicator-extraction-in-the-cli.md)
- [XQL query management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/xql-query-management.md): Administrators can set controls on running XQL queries.
- [Multi-Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant.md)
- [What is Cortex XSIAM multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/what-is-cortex-xsiam-multi-tenant.md): Learn about Cortex multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a single console.
- [MSSP multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/what-is-cortex-xsiam-multi-tenant/mssp-multi-tenant.md)
- [Enterprise multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/what-is-cortex-xsiam-multi-tenant/enterprise-multi-tenant.md)
- [Multi-tenant central licensing management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/multi-tenant-central-licensing-management.md)
- [Onboard Cortex multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant.md): Learn how to activate and manage tenants.
- [Onboarding checklist for multi-tenant central licensing deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments.md)
- [Step 1. Activate Cortex XSIAM (main account)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments/step-1.-activate-cortex-xsiam-main-account.md)
- [Step 2. Create a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments/step-2.-create-a-child-tenant.md)
- [Onboarding checklist for multi-tenant customer-owned license deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments.md)
- [Step 1. Active Cortex XSIAM (parent and child tenants)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-1.-active-cortex-xsiam-parent-and-child-tenants.md)
- [Step 2. Define access configuations and role permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-2.-define-access-configuations-and-role-permissions.md)
- [Step 3. Pair a parent tenant with a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-3.-pair-a-parent-tenant-with-a-child-tenant.md)
- [Dynamic license allocation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/dynamic-license-allocation.md): In a multi-tenant central licensing management environment, you can dynamically edit child tenant allocations, add child tenants, and delete child tenants with the license pool automatically updated.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/child-tenant-management.md): Track, manage, and investigate child tenant data from the parent tenant.
- [Track your tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/child-tenant-management/track-your-tenant-management.md)
- [Investigate child tenant data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/child-tenant-management/investigate-child-tenant-data.md)
- [Create and allocate configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/child-tenant-management/create-and-allocate-configurations.md)
- [Create a security managed action](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/child-tenant-management/create-a-security-managed-action.md)
- [About managed threat hunting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/about-managed-threat-hunting.md): Understand how Managed Threat Hunting can help your organization.
- [Set up Managed Threat Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/about-managed-threat-hunting/set-up-managed-threat-hunting.md)
- [Investigate Managed Threat Hunting reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/multi-tenant/about-managed-threat-hunting/investigate-managed-threat-hunting-reports.md)
- [Managed Services configuration in Cortex](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/managed-services-configuration-in-cortex.md)
- [Managed Services configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/managed-services-configuration-in-cortex/managed-services-configuration.md)
- [Configure report forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/managed-services-configuration-in-cortex/configure-report-forwarding.md)
- [Configure actions permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/managed-services-configuration-in-cortex/configure-actions-permissions.md)
- [Manage escalation contacts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/managed-services-configuration-in-cortex/manage-escalation-contacts.md)
- [Endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security.md)
- [Endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection.md): This topic provides an overview of traditional endpoint protection versus the protection of endpoints using Cortex XSIAM.
- [Malware protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/malware-protection.md)
- [Exploit protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/exploit-protection.md)
- [File analysis and protection flow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/file-analysis-and-protection-flow.md)
- [Endpoint protection capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/endpoint-protection-capabilities.md)
- [Processes protected by exploit security policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/processes-protected-by-exploit-security-policy.md)
- [File Integrity Monitoring (FIM)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/file-integrity-monitoring-fim.md)
- [CaaS Workloads](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/caas-workloads.md)
- [WildFire analysis concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/wildfire-analysis-concepts.md)
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md)
- [About content updates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/about-content-updates.md)
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/endpoint-data-collection.md)
- [Install and manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints.md): Learn how to set up profiles, policies and other settings for endpoint protection, how to install Cortex XDR agent on endpoints, and how to manage them after installation.
- [Set up endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection.md)
- [Set up endpoint profiles and exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules.md)
- [Set up malware prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md)
- [Set up exploit prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md)
- [Set up agent settings profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md)
- [Set up restrictions prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-restrictions-prevention-profiles.md)
- [Set up exception profiles and rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules.md)
- [Exception configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/exception-configuration.md)
- [Issue exclusions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions.md)
- [Add an issue exclusion rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions/add-an-issue-exclusion-rule.md)
- [Add an IOC or BIOC rule exception](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-an-ioc-or-bioc-rule-exception.md)
- [Add a disable prevention rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-prevention-rule-for-endpoints.md)
- [Add a disable injection and prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-injection-and-prevention-rule.md)
- [Add a support exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-support-exception-rule-for-endpoints.md)
- [Add a legacy exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints.md)
- [Add a new exceptions security profile](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-new-exceptions-security-profile.md)
- [Add a global endpoint policy exception](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-global-endpoint-policy-exception.md)
- [Set up Identity profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-identity-profiles.md)
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/define-endpoint-groups.md)
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/configure-global-agent-settings.md)
- [Apply profiles to endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/apply-profiles-to-endpoints.md)
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/create-an-agent-installation-package.md)
- [Manage an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/create-an-agent-installation-package/manage-an-agent-installation-package.md)
- [Harden endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security.md)
- [Device control](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/device-control.md)
- [Host firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall.md)
- [Host firewall for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-windows.md)
- [Host firewall for macOS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-macos.md)
- [Disk encryption](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/disk-encryption.md)
- [Host Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-inventory.md)
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/vulnerability-assessment.md)
- [Set a Cortex XDR agent Critical Environment version](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/set-a-cortex-xdr-agent-critical-environment-version.md)
- [Manage endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection.md)
- [Move agents between managing servers](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/move-agents-between-managing-servers.md)
- [Manage endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags.md)
- [Create an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/create-an-endpoint-tag.md)
- [Remove an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/remove-an-endpoint-tag.md)
- [Track your endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/track-your-endpoint-tags.md)
- [Permanently remove Endpoint tags from the system](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/permanently-remove-endpoint-tags-from-the-system.md)
- [Set an alias for an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/set-an-alias-for-an-endpoint.md)
- [Manage endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-prevention-profiles.md)
- [Create a new prevention policy rule for serverless function](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/create-a-new-prevention-policy-rule-for-serverless-function.md)
- [View information about your endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/view-information-about-your-endpoint-prevention-profiles.md)
- [Upgrade Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/upgrade-cortex-xdr-agents.md)
- [Restart agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/restart-agent.md)
- [Uninstall the Cortex XDR agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/uninstall-the-cortex-xdr-agent.md)
- [Clear agent database](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/clear-agent-database.md)
- [Delete Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/delete-cortex-xdr-agents.md)
- [Manage agent tokens](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-agent-tokens.md)
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/retrieve-support-file-password.md)
- [Send push notifications to iOS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/send-push-notifications-to-ios.md)
- [Monitor agent operational status](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-operational-status.md)
- [Monitor agent activity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md)
- [Monitor agent upgrade status](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-upgrade-status.md)
- [Endpoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp.md)
- [Cortex Data Loss Prevention (DLP) module overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview.md): Learn about Cortex Data Loss Prevention (DLP) module, which provides a solution to prevent sensitive data exfiltration.
- [Archive file classification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/archive-file-classification.md)
- [True-file type detection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/true-file-type-detection.md)
- [Personas workflow for DLP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/personas-workflow-for-dlp.md): The data security administrator and data security viewer are responsible for identifying DLP requirements for creating data-in-motion rules and investigating issues and cases.
- [Best Practices](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/best-practices.md)
- [Configure DLP end-to-end](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/configure-dlp-end-to-end.md)
- [DLP status in all endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/dlp-status-in-all-endpoints.md)
- [Cortex DLP threat detection and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-dlp/cortex-dlp-threat-detection-and-issues.md)
- [Monitor dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports.md)
- [Overview of dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports.md)
- [Dashboard interface basics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basics.md)
- [Dashboard types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-types.md)
- [Report basics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/report-basics.md)
- [Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/widget-library.md)
- [Access and visibility for dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports.md)
- [Visibility settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settings.md)
- [Access to widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgets.md)
- [Sharing icons](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-icons.md)
- [Access and sharing cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-and-sharing-cheat-sheet.md)
- [Manage dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports.md)
- [Dashboard Manager](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/dashboard-manager.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/reports.md)
- [Duplicate dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reports.md)
- [Share custom dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templates.md)
- [Change ownership to dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templates.md)
- [Import and export dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templates.md)
- [Configure the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-report.md)
- [Deleted content](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/deleted-content.md)
- [Create dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards.md)
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards/create-a-dashboard.md)
- [Create reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports.md)
- [Create a report template from scratch](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports/create-a-report-template-from-scratch.md)
- [Advanced configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration.md)
- [Create custom widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets.md)
- [Create widgets using AI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-ai.md)
- [Create XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets.md)
- [Add parameters to a custom XQL widget](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widget.md)
- [Create script-based widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgets.md)
- [Configure global filters](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-global-filters.md)
- [Configure drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-drilldowns.md)
- [Dashboard reference](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference.md)
- [Command Center reference](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference.md)
- [Cortex Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-command-center.md)
- [Cortex Agentic Assistant dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-agentic-assistant-dashboard.md)
- [XSIAM Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center.md)
- [Data Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/data-inventory.md)
- [Dynamic View](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/dynamic-view.md)
- [Cases Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/xsiam-command-center/cases-overview.md)
- [Cloud Detection and Response (CDR) Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cloud-detection-and-response-cdr-command-center.md)
- [Cortex Cloud Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-cloud-command-center.md)
- [System dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md)
- [Cortex Cloud Consumption](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cortex-cloud-consumption.md)
- [Cloud Security Operations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cloud-security-operations.md)
- [Data Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/data-ingestion.md)
- [Investigation and response](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response.md)
- [Overview of cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases.md): Understand how cases work in Cortex XSIAM.
- [What are cases?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/what-are-cases.md)
- [Resolving cases with AI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/resolving-cases-with-ai.md)
- [Case lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-lifecycle.md)
- [Case thresholds](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-thresholds.md)
- [Case scope and impact](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-scope-and-impact.md)
- [Case and issue domains](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-and-issue-domains.md)
- [Overview of case teams and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/overview-of-case-teams-and-roles.md)
- [Case concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts.md)
- [Issues, findings, and events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/issues-findings-and-events.md)
- [Case grouping](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-grouping.md)
- [Case scoring](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-scoring.md)
- [Case starring](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-starring.md)
- [SLAs and tracking](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/slas-and-tracking.md)
- [What is Causality?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/what-is-causality.md)
- [Analyze and resolve cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases.md): Learn how to analyze and resolve cases.
- [Review all cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/review-all-cases.md)
- [Start case analysis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/start-case-analysis.md)
- [Agentic Assistant- Case Investigation agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/start-case-analysis/agentic-assistant-case-investigation-agent.md)
- [Establish case context](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context.md)
- [AI-generated case summaries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context/ai-generated-case-summaries.md)
- [Assess case severity and score](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context/assess-case-severity-and-score.md)
- [Update case attributes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context/update-case-attributes.md)
- [Analyze case details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details.md)
- [Grouping graph](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/grouping-graph.md)
- [Evidence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/evidence.md)
- [Issue feed](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/issue-feed.md)
- [Associated assets and artifacts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/associated-assets-and-artifacts.md)
- [MITRE ATT\&CK tactics and techniques](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/mitre-att-and-ck-tactics-and-techniques.md)
- [Compliance standards and controls](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/compliance-standards-and-controls.md)
- [Case timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/case-timeline.md)
- [Detailed View](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/detailed-view.md)
- [Resolve the case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case.md)
- [Resolution Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolution-center.md)
- [Collaborative notes and comments](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/collaborative-notes-and-comments.md)
- [How to resolve a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolve-a-case.md)
- [Resolution reasons for cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolution-reasons-for-cases-and-issues.md)
- [Monitor and track resolution times](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/monitor-and-track-resolution-times.md)
- [Cortex Response and Remediation content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/cortex-response-and-remediation-content-pack.md)
- [Investigate an issue using Cortex Response and Remediation playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/cortex-response-and-remediation-content-pack/investigate-an-issue-using-cortex-response-and-remediation-playbooks.md)
- [Example use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/cortex-response-and-remediation-content-pack/example-use-cases.md)
- [Additional case actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions.md)
- [Create a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/create-a-case.md)
- [Merge a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/merge-a-case.md)
- [Assign a case team and restrict access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access.md)
- [Playbook examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access/playbook-examples.md)
- [Unified case view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/unified-case-view.md)
- [Investigate issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues.md): Cortex XSIAM generates issues to bring your attention to security risks in your framework.
- [Overview of the Issues page](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/overview-of-the-issues-page.md)
- [Issue card](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-card.md)
- [Resolution actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/resolution-actions.md)
- [Link or unlink issues from a case](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/link-or-unlink-issues-from-a-case.md)
- [Run an automation on an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/run-an-automation-on-an-issue.md)
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-war-room-in-an-investigation.md)
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md)
- [Issue syncing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-syncing.md)
- [Issue deduplication](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-deduplication.md)
- [Causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view.md)
- [Network causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/network-causality-view.md)
- [Cloud causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/cloud-causality-view.md)
- [Cloud causality view for audit log issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/cloud-causality-view-for-audit-log-issues.md): Investigate cloud attacks faster with entity context directly in the Cloud causality view.
- [SaaS causality view](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/saas-causality-view.md)
- [Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/timeline.md)
- [Causality icons key](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view/causality-icons-key.md)
- [Issue investigation actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions.md)
- [Copy issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/copy-issues.md)
- [Analyze an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/analyze-an-issue.md)
- [Update issue fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/update-issue-fields.md)
- [Query case and issue data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md)
- [Exclude an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/exclude-an-issue.md)
- [Create a featured field](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/create-a-featured-field.md)
- [Export issue details to a file](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/export-issue-details-to-a-file.md)
- [Investigate contributing events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/investigate-contributing-events.md)
- [Retrieve additional issue details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/retrieve-additional-issue-details.md)
- [View generating BIOC or IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/view-generating-bioc-or-ioc-rule.md)
- [Create profile exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/create-profile-exceptions.md)
- [Add a file path to a malware profile allow list](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/add-a-file-path-to-a-malware-profile-allow-list.md)
- [Close an issue](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/close-an-issue.md)
- [Review findings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/review-findings.md): Review findings for an asset to gain insights into an asset’s posture status.
- [Findings card](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/review-findings/findings-card.md)
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets.md): You can investigate specific artifacts and assets on dedicated views related to IP address, Network Assets, and File and Process Hash information.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-an-ip-address.md)
- [Investigate an asset](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-an-asset.md)
- [Investigate a host](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-a-host.md)
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md)
- [Investigate a user](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-a-user.md)
- [Investigate endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints.md): You can investigate and take actions on your endpoints in the Action Center.
- [Overview of the Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/overview-of-the-action-center.md)
- [Initiate and monitor endpoint actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/overview-of-the-action-center/initiate-and-monitor-endpoint-actions.md)
- [Action Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/overview-of-the-action-center/action-center-reference-information.md)
- [Manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/manage-endpoints.md)
- [Retrieve files from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-files-from-an-endpoint.md)
- [Retrieve support logs from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-support-logs-from-an-endpoint.md)
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-support-file-password.md)
- [Scan an endpoint for malware](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/scan-an-endpoint-for-malware.md)
- [Investigate files](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files.md)
- [Manage file execution](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/manage-file-execution.md)
- [Manage quarantined files](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/manage-quarantined-files.md)
- [Review WildFire analysis details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/review-wildfire-analysis-details.md)
- [Import file hash exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-files/import-file-hash-exceptions.md)
- [Cortex Assistant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/cortex-assistant.md): Cortex Assistant is designed to streamline processes by simplifying case triaging, investigation, and remediation. It enables you to seamlessly uncover new insights on hashes, hosts, and more. You can
- [Cortex Assistant layout](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/cortex-assistant/cortex-assistant-layout.md)
- [Cortex Assistant capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/cortex-assistant/cortex-assistant-capabilities.md)
- [Response actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions.md): During the case investigation, various response actions are available.
- [Initiate a Live Terminal session](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/initiate-a-live-terminal-session.md)
- [Isolate an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/isolate-an-endpoint.md)
- [Pause endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/pause-endpoint-protection.md)
- [Run agent scripts on an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/run-agent-scripts-on-an-endpoint.md)
- [Remediate changes from malicious activity](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/remediate-changes-from-malicious-activity.md)
- [Search and destroy malicious files](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/search-and-destroy-malicious-files.md)
- [Manage external dynamic lists](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/manage-external-dynamic-lists.md)
- [Collect a memory image](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/response-actions/collect-a-memory-image.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics.md)
- [Forensic investigations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/forensic-investigations.md)
- [Manage an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation.md)
- [Create a new investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/create-a-new-investigation.md)
- [Edit an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/edit-an-investigation.md)
- [Close an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/close-an-investigation.md)
- [User permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/manage-an-investigation/user-permissions.md)
- [Data collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection.md)
- [Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting.md)
- [Create a hunt](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting/create-a-hunt.md)
- [Hunt results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting/hunt-results.md)
- [Hunt status](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/hunting/hunt-status.md)
- [Triage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage.md)
- [Create a triage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/create-a-triage.md)
- [Upload an offline triage package](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/upload-an-offline-triage-package.md)
- [Offline triage collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/offline-triage-collection.md)
- [Triage results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/triage-results.md)
- [Triage status](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/triage/triage-status.md)
- [Configure collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/data-collection/configure-collection.md)
- [Analysis and documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/analysis-and-documentation.md)
- [Export](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/forensics/export.md)
- [Notebooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/notebooks.md): Leverage the data collected by Cortex XSIAM using Jupyter Notebooks' data analysis and visualization capabilities within your existing security infrastructure.
- [Manage datasets in Notebooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/notebooks/manage-datasets-in-notebooks.md)
- [Notebooks scheduler](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/notebooks/notebooks-scheduler.md)
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/about-the-query-builder.md)
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries.md)
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md)
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md)
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md)
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md)
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/create-xql-query.md)
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md)
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md)
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/graph-query-results.md)
- [Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates.md): Use Query Builder templates to query your data sets without using the Cortex Query Language.
- [Get started with Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/get-started-with-query-builder-templates.md)
- [Considerations for using Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/considerations-for-using-query-builder-templates.md)
- [Create a query from a template](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/create-a-query-from-a-template.md)
- [Run a free text query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/run-a-free-text-query.md)
- [Query Builder template examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/query-builder-templates/query-builder-template-examples.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md)
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/overview-of-the-query-center/query-center-reference-information.md)
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md)
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-your-personal-query-library.md): Cortex XSIAM provides as part of the Query Library a personal library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/manage-your-macros.md)
- [Federated Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search.md)
- [Federated Search configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search/federated-search-configuration.md)
- [Query using Federated Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search/query-using-federated-search.md)
- [Manage external datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/federated-search/manage-external-datasets.md)
- [Legacy Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder.md): Learn more about the entities in the Legacy Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-authentication-query.md)
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-event-log-query.md)
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-file-query.md)
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-image-load-query.md)
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-network-connections-query.md)
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-network-query.md)
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-process-query.md)
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/create-registry-query.md)
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/legacy-query-builder/query-across-all-entities.md)
- [Research a known threat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/research-a-known-threat.md): Cortex XSIAM enables you to investigate any threat, also referred to as a lead, which has been detected.
- [Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat.md): Chat with the Cortex Agentic Assistant using natural language prompts.
- [Get started with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/get-started-with-agentic-assistant-chat.md): Enable Agentic Assistant and access the chat interface.
- [Choose an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/choose-an-agentic-assistant-agent.md): Choose a system or custom agent for your chat.
- [Chat with an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-an-agentic-assistant-agent.md): Tips for chatting with the Cortex Agentic Assistant
- [Chat with the Agentic Assistant from Slack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-the-agentic-assistant-from-slack.md): Enable chatting with an Agentic Assistant agent from Slack.
- [Create and run XQL queries with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/create-and-run-xql-queries-with-agentic-assistant-chat.md): Interact with Cortex Agentic Assistant agents to build and run XQL queries.
- [Use natural language to query and visualize your data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/use-natural-language-to-query-and-visualize-your-data.md): Prompt Cortex Agentic Assistant agents to create graphs and charts from its findings.
- [Manage chat history](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/manage-chat-history.md): Manage and navigate your past chats with the Cortex Agentic Assistant.
- [Asset management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management.md)
- [Asset inventory overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-inventory-overview.md): Learn about the core concepts, features, and lifecycle of assets within the Asset Inventory.
- [All assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-assets.md): Learn about the All Assets page, under Asset Inventory.
- [All cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets.md): Learn about the All Cloud Assets page to view and assess your cloud footprint.
- [Discovery Engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets/discovery-engine.md)
- [Asset hierarchy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets/asset-hierarchy.md)
- [Asset classes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes.md): Accelerating remediation: Automated fix suggestions and manual remediation guidance enable developers to resolve code weaknesses directly in the source repository without context-switching to external
- [AI assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/ai-assets.md)
- [API assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/api-assets.md)
- [Application assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/application-assets.md)
- [Code and Supply Chain Security assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets.md)
- [IaC resources assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/iac-resources-assets.md)
- [Repository assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/repository-assets.md)
- [VCS organization assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/vcs-organization-assets.md)
- [CI/CD pipeline assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/ci-cd-pipeline-assets.md)
- [CI/CD instances assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/ci-cd-instances-assets.md)
- [Software package assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets/software-package-assets.md)
- [Compute assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets.md)
- [Container image assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/container-image-assets.md)
- [Serverless functions assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/serverless-functions-assets.md)
- [VM images assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/vm-images-assets.md)
- [Data assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/data-assets.md)
- [Device assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/device-assets.md)
- [External Surface assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets.md)
- [Website assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/website-assets.md)
- [Service assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/service-assets.md)
- [Domain assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/domain-assets.md)
- [Certificate assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/certificate-assets.md)
- [External Surface attribution evidence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets/external-surface-attribution-evidence.md)
- [Identity assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/identity-assets.md)
- [Network assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/network-assets.md)
- [Security services assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/security-services-assets.md)
- [Asset groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-groups.md): Group assets based on shared attributes to address them collectively, simplify filtering, and enable strict access control boundaries.
- [Manage Risk Scores](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/manage-asset-scores.md): View and investigate User Scores and Host Scores using the Risk Scores page to identify high-risk assets and detect compromised accounts or malicious activities.
- [Asset configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations.md)
- [Network configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/network-configuration.md): Configure your internal network parameters, trusted networks, and external IP ranges to help Cortex XSIAM identify and map your network assets.
- [Application criteria](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/application-criteria.md)
- [Asset Roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles.md): View asset roles and the number of assets that are associated with each role. Learn how to manage asset roles for users and endpoints.
- [Manage Asset Roles for Endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-endpoints.md)
- [Manage Asset Roles for Users](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-users.md)
- [Honey user](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-users/honey-user.md)
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/vulnerability-assessment.md)
- [Query the asset inventory via XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/query-the-asset-inventory-via-xql.md)
- [Threat management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management.md)
- [Detection rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules.md)
- [What are detection rules?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules.md)
- [What's an IOC?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc.md)
- [IOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/ioc-rule-details.md)
- [Create an IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/create-an-ioc-rule.md)
- [What's a BIOC?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc.md)
- [BIOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/bioc-rule-details.md)
- [Create a BIOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/create-a-bioc-rule.md)
- [Manage Global BIOC Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/manage-global-bioc-rules.md)
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule.md)
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/correlation-rule-details.md)
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/create-a-correlation-rule.md)
- [Field replacement syntax in correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rules.md)
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/manage-correlation-rules.md)
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/monitor-correlation-rules.md)
- [Troubleshoot server errors in scheduled correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rules.md)
- [Manage IOC and BIOC rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/manage-ioc-and-bioc-rules.md)
- [Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics.md)
- [Analytics overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview.md)
- [Analytics engine](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-engine.md)
- [Analytics sensors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-sensors.md)
- [Coverage of MITRE Attack tactics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/coverage-of-mitre-attack-tactics.md)
- [Review MITRE ATT\&CK framework coverage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/review-mitre-att-and-ck-framework-coverage.md)
- [Analytics detection time intervals](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-detection-time-intervals.md)
- [Analytics issues and Analytics BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-issues-and-analytics-biocs.md)
- [View and manage Analytics rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/view-and-manage-analytics-rules.md)
- [Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/identity-analytics.md)
- [AI Detection & Response in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta.md)
- [Data sources and supported services](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/data-sources-and-supported-services.md)
- [Collect prompt logs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs.md)
- [Prompt log collection in AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-aws.md)
- [Enable prompt log collection in Azure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure.md)
- [Configure the Azure Event Hub collection in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-xsiam.md)
- [Set up prompt logging](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-logging.md)
- [Log HTTP data](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-data.md)
- [Configure diagnostic settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settings.md)
- [Extended Threat Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence.md): Research threats, investigate indicators, and apply intelligence across Cortex XSIAM workflows.
- [XTI Threat Intel Library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-threat-intel-library.md): Research curated threat actors, malware families, vulnerabilities, and reports from Unit 42.
- [XTI Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicators.md): Investigate, manage, and enrich threat indicators, including domains, IP addresses, URLs, and file hashes.
- [Threat intel context in cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md): Analyze indicator intelligence and Behavioral Threat Analysis (BTA) findings in cases and issues.
- [XTI indicator rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicator-rules.md): Create rules that detect known threat indicators and generate issues from matching data.
- [Threat intel investigation through XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-investigation-through-xql.md): Query XTI indicators, threat objects, and their relationships using Cortex Query Language.
- [Threat Intel Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-dashboard.md): Visualize threat intelligence data to monitor distribution, ingestion health, and emerging trends.
- [Using XTI with Threat Intel Agent](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-with-threat-intel-agent.md): Use the Threat Intel Agent to list, enrich, and update XTI indicators.
- [Using XTI in playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-in-playbooks.md): Automate XTI indicator triage, enrichment, and response with supported playbook commands.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management.md): Manage threat indicators, feeds, enrichment, and detection workflows with Threat Intel Management.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management.md): Learn Threat Intel Management concepts, use cases, roles, and the indicator lifecycle.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Learn how Threat Intel Management centralizes indicators, enrichment, and investigation workflows.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Explore workflows for ingesting, enriching, investigating, and acting on threat indicators.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Understand the roles and responsibilities for configuring and operating Threat Intel Management.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md): Learn the indicator concepts, fields, types, and sources used in Threat Intel Management.
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Understand how indicators are created, enriched, managed, expired, and removed.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration.md): Configure feeds, indicator types, fields, extraction, enrichment, and indicator rules.
- [Configure Threat Intelligence feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/configure-threat-intelligence-feed-integrations.md): Connect threat intelligence feeds to ingest indicators into Cortex XSIAM.
- [Customize indicator fields and types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types.md): Customize indicator types and fields to organize threat intelligence data.
- [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type.md): Create custom indicator types and configure their profiles, scripts, and field mappings.
- [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/indicator-type-profile.md): Configure profile settings that define an indicator type's behavior and appearance.
- [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/formatting-scripts.md): Use formatting scripts to normalize indicator values before storage.
- [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/enhancement-scripts.md): Use enhancement scripts to add threat intelligence context to indicators.
- [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/reputation-scripts.md): Use reputation scripts to calculate or update an indicator's reputation.
- [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/reputation-commands.md): Configure integration commands that retrieve reputation data for indicators.
- [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/map-custom-indicator-fields.md): Map custom fields to indicator types for consistent indicator data.
- [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field.md): Create custom fields to store additional threat indicator information.
- [Indicator field structure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field/indicator-field-structure.md): Understand the structure and settings available for custom indicator fields.
- [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field/indicator-field-trigger-scripts.md): Use trigger scripts to run actions when indicator field values change.
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Classify and map extracted values to the appropriate indicator types and fields.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-extraction.md): Configure how Cortex XSIAM extracts indicators from tasks, scripts, and integrations.
- [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md): Choose how a playbook task extracts and creates indicators from its output.
- [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md): Prevent selected scripts or integrations from automatically extracting indicators.
- [Configure Threat Intelligence feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/configure-threat-intelligence-feed-integrations-1.md): Configure threat intelligence feed integrations and manage their indicator ingestion.
- [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Exclude selected indicators from enrichment to control processing and data usage.
- [Generate issues from indicators using indicator rules for prevention and detection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/generate-issues-from-indicators-using-indicator-rules-for-prevention-and-detection.md): Create rules that generate prevention or detection issues from matching indicators.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-configuration/export-indicators.md): Export threat indicators for use in external systems and workflows.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-management.md): Create, view, edit, and organize threat indicators throughout their lifecycle.
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation.md): Investigate indicators using verdicts, enrichment, relationships, expiration, and exclusions.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/indicator-verdict.md): Understand indicator verdicts and how they assess threat relevance.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): Extract indicators from data and enrich them with context from supported integrations.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire indicators when they no longer require active monitoring or matching.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): Create and manage relationships between indicators to capture threat context.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Delete unwanted indicators or exclude them from future ingestion and enrichment.
- [Attack surface management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management.md): Learn how to discover, monitor, and remediate external asset exposures with attack surface management.
- [Learn about Attack Surface Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management.md): Learn about Cortex XSIAM Attack Surface Management capabilities for finding, prioritizing, and remediating external asset exposures.
- [Network mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/network-mapping.md): Learn how Cortex XSIAM discovers, attributes, and validates internet-facing assets to map your public attack surface.
- [Scanning](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/scanning.md): Learn how Cortex XSIAM ASM scans internet-facing assets, monitors known assets, and identifies exposed services.
- [GeoIP data collection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/geoip-data-collection.md): Use GeoIP data to validate network distribution, identify location-based compliance risks, and route remediation efforts.
- [Attack Surface Management detections](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections.md)
- [Attack surface rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/attack-surface-rules.md)
- [Attack Surface Testing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/attack-surface-testing.md)
- [Externally inferred CVEs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/externally-inferred-cves.md)
- [Digital Risk Protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/digital-risk-protection.md)
- [Attack surface assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-assets.md): The assets discovered in an attack surface management scan are called External Surface assets.
- [Deploy ASM and Exposure Management enrichment and remediation automation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/deploy-asm-and-exposure-management-enrichment-and-remediation-automation.md): Enable the Cortex Exposure Management playbooks to automate ASM and vulnerability issue enrichment and remediation.
- [ASM enrichment of cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/asm-enrichment-of-cloud-assets.md): ASM enrichment of cloud assets provides visibility into all the assets in your cloud infrastructure that are exposed to the internet.
- [Emerging Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/emerging-vulnerabilities.md): Identify external exposures linked to emerging vulnerabilities, zero-day exploits, and global threat events on the Emerging Vulnerabilities page.
- [Global Lookup](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/global-lookup.md)
- [Vulnerability management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management.md)
- [Vulnerability management in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-management-in-cortex-xsiam.md): Vulnerability management helps you identify, assess, prioritize, and remediate security vulnerabilities across your entire IT infrastructure, including endpoints, code, and cloud.
- [Cortex Vulnerability Risk Score](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/cortex-vulnerability-risk-score.md): Learn how Cortex XSIAM calculates and displays Cortex Vulnerability Risk Scores (CVRS).
- [Vulnerability policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-policies.md): A vulnerability policy defines the action you want to take for a specific set of vulnerability findings.
- [Investigate and remediate vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/investigate-and-remediate-vulnerabilities.md): Investigate, prioritize, and remediate vulnerabilities through issues, findings, and vulnerable assets.
- [Vulnerability Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-intelligence.md): Vulnerability Intelligence is an in-product, real-time feed that provides vulnerability data and threat intelligence from a variety of certified upstream sources.
- [Emerging Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/emerging-vulnerabilities.md): The Emerging Vulnerabilities page is a a centralized hub for security teams to research, assess, and respond to global, emergent threats and zero-day exploits.
- [Recast CVSS scores and CVSS severities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/recast-cvss-scores-and-cvss-severities.md): Customize CVSS scores and CVSS severities in the platform to align your risk management approach with your organizational context and priorities.
- [Exposure management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management.md)
- [Learn about Exposure Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/exposure-management.md): Assess, prioritize, and remediate organizational exposures with unified vulnerability data and automated workflows.
- [Get started with Exposure Management](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/get-started-with-exposure-management.md): Set up Exposure Management by configuring scanners, integrations, policies, security controls, and automation.
- [Ingest assets and vulnerabilities from third-party applications](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/ingest-assets-and-vulnerabilities-from-third-party-applications.md): Ingest assets and vulnerabilities into Cortex Exposure Management from Palo Alto Networks sensors and third-party applications.
- [Security controls](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/security-controls.md): Detect, create, and manage security controls to assess compensating-control effectiveness and residual risk.
- [Cortex Network Scanner](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/cortex-network-scanner.md): Deploy and manage network scans to discover assets, assess vulnerabilities, and investigate issues.
- [Exposure Management Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management/exposure-management-command-center.md): Monitor vulnerability findings, prioritize cases, and track remediation across your environment.
- [Cortex Advanced Email Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security.md): Configure, monitor, and respond to email security threats.
- [Cortex Advanced Email Security module overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-overview.md)
- [Cortex Advanced Email Security module architecture and data flow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-architecture-and-data-flow.md)
- [Getting started with the Cortex Advanced Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/getting-started-with-the-cortex-advanced-email-security-module.md): High level deployment workflow
- [Deploy and configure the Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/deploy-and-configure-the-email-security-module.md)
- [Cortex Advanced Email Security threat detection and issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-threat-detection-and-issues.md)
- [Email Security Analytics Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-threat-detection-and-issues/email-security-analytics-rules.md)
- [Investigate and respond to email security issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/investigate-and-respond-to-email-security-issues.md): Investigate the issues generated by the Cortex Advanced Email Security module.
- [Automate remediation for the Cortex Advanced Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module.md)
- [Email Remediation Response Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module/email-remediation-response-rules.md)
- [Email Security Remediation Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module/email-security-remediation-action-center.md)
- [Email Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/email-command-center.md): View a dynamic overview of your email security status in the Email Command Center.
- [Malicious Email Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/malicious-email-inventory.md)
- [Mailbox Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/mailbox-inventory.md)
- [Advanced Email Security module security and compliance](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/advanced-email-security-module-security-and-compliance.md)
- [Identity Threat Detection and Response (ITDR)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr.md)
- [Get started with ITDR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/get-started-with-itdr.md)
- [Manage role based access control (RBAC) in ITDR](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/manage-role-based-access-control-rbac-in-itdr.md)
- [Monitor user risk exposure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/monitor-user-risk-exposure.md)
- [Investigate user risk](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/investigate-user-risk.md)
- [Manage user asset roles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/asset-roles.md)
- [Improve Active Directory posture with AD-SPM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/active-directory-security-posture-management.md)
- [Enforce dynamic access control with CAP](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/conditional-access-policy.md)
- [Prevent malicious LDAP queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/prevent-malicious-ldap-queries.md)
- [Monitor and track compliance adherence](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence.md): Evaluate and track asset compliance against industry standards and organizational policies.
- [Choose compliance standards from the compliance catalog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog.md): Select built-in or custom compliance standards and controls from the compliance catalogs.
- [Standards catalog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/standards-catalog.md): Browse available compliance standards.
- [Controls catalog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/controls-catalog.md): Browse, filter, and review built-in and custom compliance controls.
- [Use a built-in or custom standard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-standard.md): Use built-in standards or create and edit custom standards for your organization.
- [Use a built-in or custom control](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md): Add built-in controls or create and manage custom controls for custom standards.
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/create-a-new-custom-detection-rule.md): Create custom detection rules to enforce compliance requirements and security best practices.
- [Use an assessment profile to run compliance checks on your assets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets.md): Create assessment profiles to evaluate selected asset groups against compliance standards.
- [Configuring assessments for custom compliance standards based on custom cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets/configuring-assessments-for-custom-compliance-standards-based-on-custom-cloud-security-rules.md): Configure policies and assessments for custom standards that use custom cloud security rules.
- [View and manage compliance assessments and reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports.md): Review assessment results and generate or schedule downloadable compliance reports.
- [Review assessments](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/assessments.md): View assessment results and drill into control, rule, and asset compliance details.
- [Review reports](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/reports.md): View, export, and manage historical compliance assessment reports.
- [Compliance Overview Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence/compliance-overview-dashboard.md): Monitor organization-wide compliance scores, standards, failed controls, and asset group performance.
- [Cloud security rules and policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies.md): Learn how cloud security rules and policies detect threats and misconfigurations across your environment.
- [Cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/cloud-security-rules.md): Learn about out-of-the-box and custom cloud security rules.
- [Cloud security policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/cloud-security-policies.md): Learn about cloud security policies.
- [Create and manage cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules.md): Create and manage custom cloud security rules for detecting cloud security risks.
- [Create a graph rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-graph-rule.md): Create custom graph detection rules that identify risky relationships and attack paths.
- [Create a configuration rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-configuration-rule.md): Create configuration rules that identify cloud resource misconfigurations and policy violations.
- [Create a data rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-data-rule.md): Create data rules to detect data risks, malware, and classification issues.
- [Create an identity rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-identity-rule.md): Create identity rules to detect excessive or unused cloud permissions.
- [Create a network exposure rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-network-exposure-rule.md): Create network exposure rules to detect risky inbound, outbound, and east-west access.
- [Create an AI rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-ai-rule.md): Create AI rules to detect risks and misconfigurations across your AI ecosystem.
- [Create an attack path rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-attack-path-rule.md): Create attack path rules that identify breach paths to high-value cloud assets.
- [View cloud security rule status](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/view-cloud-security-rule-status.md): View, filter, and sort the status of cloud security rules.
- [Edit a cloud security rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/edit-a-cloud-security-rule.md): Edit cloud security rules and understand how changes affect related issues.
- [Enable or disable a rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/enable-or-disable-a-rule.md): Enable or disable cloud security rules to control when they evaluate assets.
- [Use an existing rule to create a new one](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/use-an-existing-rule-to-create-a-new-one.md): Duplicate an existing cloud security rule and customize it for your needs.
- [Delete a custom cloud security rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/delete-a-custom-cloud-security-rule.md): Delete custom cloud security rules that are no longer needed.
- [Create and manage cloud security policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies.md): Create and manage cloud security policies.
- [Create a cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/create-a-cloud-security-policy.md): Create a cloud security policy that applies security rules to selected cloud assets.
- [Edit a cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/edit-a-cloud-security-policy.md): Edit cloud security policies to update their details, rules, and scopes.
- [Enable or disable a policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/enable-or-disable-a-policy.md): Enable or disable custom and default cloud security policies.
- [Use an existing policy to create a new one](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/use-an-existing-policy-to-create-a-new-one.md): Duplicate an existing cloud security policy and tailor it to your needs.
- [Delete a custom cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/delete-a-custom-cloud-security-policy.md): Remove custom cloud security policies that are no longer needed.
- [Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification.md)
- [How to create and validate a custom data pattern](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-pattern.md)
- [Custom data patterns: Guardrails and syntax guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-pattern/custom-data-patterns-guardrails-and-syntax-guide.md)
- [How to disable and enable data patterns in Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification/how-to-disable-and-enable-data-patterns-in-data-classification.md)
- [How to create and validate a custom data profile](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-profile.md)
- [How to disable and enable data profiles in Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification/how-to-disable-and-enable-data-profiles-in-cortex-cloud-data-classification.md)
- [How to report a false positive in Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification/how-to-report-a-false-positive-in-cortex-cloud-data-classification.md)
- [Topic classification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-data-classification/topic-classification.md)
- [Cortex Data Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-data-security.md)
- [Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security.md)
- [What is Cloud Identity Security?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/what-is-cortex-cloud-identity-security.md): Cloud Identity Security can help you address the security challenges of managing identity in cloud environments.
- [Review and improve your Identity Security posture](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/review-and-improve-your-identity-security-posture.md): Learn how to review and improve your Identity Security posture with the provided use case examples.
- [How does Effective Permission Calculation work?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/how-does-effective-permission-calculation-work.md): An explanation of how Effective Permission Calculation works in Cloud Identity Security.
- [Cloud Identity Security functionality](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/cortex-cloud-identity-security-functionality.md): About the functionalities of Cloud Identity Security.
- [Configure Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/configure-cortex-cloud-identity-security.md)
- [Unified Human Identities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/unified-human-identities.md)
- [Achieve the principle of least privilege access](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/achieve-the-principle-of-least-privilege-access.md): Use Cloud Identity Security to achieve the principle of least privilege access.
- [Explore permissions using the simple and advanced access tables](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/explore-permissions-using-the-simple-and-advanced-access-tables.md): Learn how to explore permissions in Cloud Identity Security using the Simple and Advanced access tables.
- [Create a custom detection rule in Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/create-a-custom-detection-rule-in-cortex-cloud-identity-security.md): Learn how to create a custom detection rule in Cloud Identity Security.
- [Perform advanced Identity Security investigations using XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/perform-advanced-identity-security-investigations-using-xql.md): Working with datasets in Cloud Identity Security.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/ingest-logs-and-data-from-okta.md): Learn more about Ingesting logs and data from Okta.
- [Enable inactive human identity logs on Azure in Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/enable-inactive-human-identity-logs-on-azure-in-cortex-cloud-identity-security.md): Configuration information for enabling inactive human identity logs on Azure.
- [Manage RBAC and SBAC in Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-identity-security/manage-rbac-and-sbac-in-cortex-cloud-identity-security.md): Working with RBAC and SBAC in Cloud Identity Security.
- [Network exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/network-exposure-detection.md): Identify, prioritize, and remediate internet, outbound, and lateral network exposure risks in public cloud environments.
- [What is Cloud Network Analyzer?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/network-exposure-detection/what-is-cloud-network-analyzer.md): Understand how CNA identifies internet, outbound, and lateral exposure across cloud accounts.
- [Internet exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/network-exposure-detection/internet-exposure-detection.md): Learn how CNA detects publicly reachable cloud assets and validates exposure through external network scanning.
- [Outbound exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/network-exposure-detection/outbound-exposure-detection.md): Learn about detecting workloads with unrestricted outbound internet access based on security configurations.
- [East-west exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/network-exposure-detection/east-west-exposure-detection.md): Learn about workloads with unrestricted lateral access and the controls causing that exposure.
- [Investigate an internet exposure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/network-exposure-detection/investigate-an-internet-exposure.md): Investigate internet-exposed assets through Issues and Graph Search.
- [Configure trusted IPs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/network-exposure-detection/configure-trusted-ips.md): Configure trusted public IP ranges excluded from CNA internet exposure evaluations.
- [Cortex Cloud SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security.md): SaaS Security delivers continuous visibility and control across SaaS identities, connected apps, and AI agents.
- [Setup SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/setup-saas-security.md): Get started with SaaS Security.
- [Connect a SaaS application](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application.md): Connect a supported SaaS application to track and monitor misconfigurations and compliance violations.
- [Onboard Aha.io](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-aha.io.md): Onboard Aha.io to track misconfigurations and monitor application compliance.
- [Onboard Asana](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-asana.md): Connect an Asana instance to detect posture risks and compliance violations.
- [Onboard Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-atlassian.md): Connect an Atlassian instance to detect posture and compliance risks.
- [Onboard Automox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-automox.md): Connect an Automox  instance to detect posture risks and compliance violations.
- [Onboard Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-businessmap.md): Connect a Businessmap instance to detect posture risks and compliance violations.
- [Onboard Celonis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-celonis.md): Connect a Celonis instance to detect posture risks and compliance violations.
- [Onboard Cisco Duo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-cisco-duo.md): Connect Cisco Duo instance to detect posture risks and compliance violations.
- [Onboard Cisco Meraki](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-cisco-meraki.md): Connect a Cisco Meraki instance to detect posture risks and compliance violations.
- [Onboard ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-clickup.md): Connect a ClickUp instance to detect posture risks and compliance violations.
- [Onboard Contentful](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-contentful.md): Connect a Contentful instance to detect posture risks and compliance violations.
- [Onboard Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-couchbase.md): Connect a Couchbase instance to detect posture risks and compliance violations.
- [Onboard Coveo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-coveo.md): Connect a Coveo instance to detect posture risks and compliance violations.
- [Onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-databricks.md): Connect a Databricks instance to detect posture risks and compliance violations.
- [Onboard Datadog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-datadog.md): Connect a Datadog instance to detect posture risks and compliance violations.
- [Onboard Gainsight PX](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-gainsight-px.md): Connect a Gainsight PX instance to detect posture risks and compliance violations.
- [Onboard Grammarly](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-grammarly.md): Connect a Grammarly instance to detect posture risks and compliance violations.
- [Onboard Harness](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-harness.md): Connect a Harness instance to detect posture risks and compliance violations.
- [Onboard Intercom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-intercom.md): Connect an Intercom instance to detect posture risks and compliance violations.
- [Onboard Jamf Pro](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-jamf-pro.md): Connect a Jamf Pro instance to detect posture risks and compliance violations.
- [Onboard JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-jumpcloud.md): Connect a JumpCloud instance to detect posture risks and compliance violations.
- [Onboard Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-kustomer.md): Connect a Kustomer instance to detect posture risks and compliance violations.
- [Onboard Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-microsoft-entra-id.md): Connect a Microsoft Entra ID instance to detect posture risks and compliance violations.
- [Onboard Monday.com](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-monday.com.md): Connect a Monday.com instance to detect posture risks and compliance violations.
- [Onboard MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-mongodb-atlas.md): Connect a MongoDB Atlas instance to detect posture risks and compliance violations.
- [Onboard MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-mulesoft.md): Connect a MuleSoft instance to detect posture risks and compliance violations.
- [Onboard Mural](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-mural.md): Connect a Mural instance to detect posture risks and compliance violations.
- [Onboard Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-office-365.md): Connect an Office 365 instance to detect posture risks and compliance violations.
- [Onboard Okta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-okta.md): Connect an Okta instance to detect posture risks and compliance violations.
- [Onboard PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-pagerduty.md): Connect a PagerDuty instance to detect posture risks and compliance violations.
- [Onboard Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-redis-labs.md): Connect a Redis Labs instance to detect posture risks and compliance violations.
- [Onboard Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-salesforce.md): Connect a Salesforce instance to detect posture risks and compliance violations.
- [Onboard SAP Ariba](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-sap-ariba.md): Connect a SAP Ariba instance to detect posture risks and compliance violations.
- [Onboard Sentry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-sentry.md): Connect a Sentry instance to detect posture risks and compliance violations.
- [Onboard ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-servicenow.md): Connect a ServiceNow instance to detect posture risks and compliance violations.
- [Onboard Shopify](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-shopify.md): Connect a Shopify instance to detect posture risks and compliance violations.
- [Onboard Slack Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-slack-enterprise.md): Connect a Slack instance to detect posture risks and compliance violations.
- [Onboard Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-sumo-logic.md): Connect a Sumo Logic instance to detect posture risks and compliance violations.
- [Onboard Workday](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-workday.md): Connect a Workday instance to detect posture risks and compliance violations.
- [Onboard Wrike](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-wrike.md): Connect a Wrike instance to detect posture risks and compliance violations.
- [Onboard YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/connect-a-saas-application/onboard-youtrack.md): Connect a YouTrack instance to detect posture risks and compliance violations.
- [SaaS Security Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-security-overview.md): This dashboard aggregates and presents security data from all four core SaaS Security pillars including: SSPM (Posture), SaaS Identity Security, SaaS Data Security, and SaaS Agent Security.
- [SaaS Security Checks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-security-checks.md): The dashboard captures key metrics to help you remediate SaaS assets at risk
- [Provider Instances Security Check](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/provider-instances-security-check.md): This page consolidates application security posture data across all onboarded instances
- [Detection Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/detection-rules.md): View Cloud Security Posture Rules
- [Remediation Actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/remediation-actions.md): Learn more about actions available to remediate Issues.
- [Create and monitor tickets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/create-and-monitor-tickets.md): Learn more about creating a synced ticket to remediate an issue.
- [SaaS AI Agent Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security.md): SaaS AI Agent Security helps you secure AI agents deployed across enterprise SaaS environments.
- [Setup SaaS Security for AISPM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/setup-saas-security-for-aispm.md): Get started with SaaS Agent Security.
- [Onboard SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents.md): Learn more about how to onboard specific AI Agents.
- [Onboard Atlassian Rovo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-atlassian-rovo.md): Connect Atlassian Rovo to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Box AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-box-ai-agents.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-chatgpt-enterprise.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Cursor Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-cursor-enterprise.md): Connect Cursor Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-gemini-enterprise.md): Connect Gemini Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard M365 Copilot](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-m365-copilot.md): Connect M365 Copilot to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Microsoft Copilot Studio](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-microsoft-copilot-studio.md): Connect Microsoft Copilot Studio to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Service Now](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-service-now.md): Connect Service Now to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Manage SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents.md)
- [View AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-ai-agents.md)
- [View Datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-datasets.md): The Datasets view provides a detailed look at the Inference Datasets.
- [View Agent Tools](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-agent-tools.md): SaaS Agent Tools go beyond traditional scans that  focus on an inventory of previously vendor vetted, underlying tools.
- [Cortex Cloud AI Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security.md)
- [What is Cortex Cloud AI Security?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/what-is-cortex-cloud-ai-security.md): A basic overview of the Cortex Cloud AI Security overview page, assets inventory, risks, and benefits.
- [Supported services in Cortex Cloud AI Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/supported-services-in-cortex-cloud-ai-security.md): A list of platforms and services that are compatible with Cortex Cloud AI Security.
- [Cortex Cloud AI Security concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-ai-security-concepts.md): Basic concepts of Cloud AI Security.
- [Cortex Cloud AI Security use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-ai-security-use-cases.md): Learn about use cases that are relevant for Cortex Cloud AI Security.
- [Cortex Cloud SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security.md): SaaS Security delivers continuous visibility and control across SaaS identities, connected apps, and AI agents.
- [Setup SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/setup-saas-security.md): Get started with SaaS Security.
- [Onboard a Supported SaaS Application](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application.md): Onboard a supported SaaS application to track and monitor misconfigurations and compliance violations.
- [Onboard Aha.io](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-aha.io.md): Onboard Aha.io to track misconfigurations and monitor application compliance.
- [Onboard Asana](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-asana.md): Connect an Asana instance to detect posture risks and compliance violations.
- [Onboard Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-atlassian.md): Connect an Atlassian instance to detect posture and compliance risks.
- [Onboard Automox](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-automox.md): Connect an Automox  instance to detect posture risks and compliance violations.
- [Onboard Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-businessmap.md): Connect a Businessmap instance to detect posture risks and compliance violations.
- [Onboard Celonis](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-celonis.md): Connect a Celonis instance to detect posture risks and compliance violations.
- [Onboard Cisco Duo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-cisco-duo.md): Connect Cisco Duo instance to detect posture risks and compliance violations.
- [Onboard Cisco Meraki](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-cisco-meraki.md): Connect a Cisco Meraki instance to detect posture risks and compliance violations.
- [Onboard ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-clickup.md): Connect a ClickUp instance to detect posture risks and compliance violations.
- [Onboard Contentful](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-contentful.md): Connect a Contentful instance to detect posture risks and compliance violations.
- [Onboard Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-couchbase.md): Connect a Couchbase instance to detect posture risks and compliance violations.
- [Onboard Coveo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-coveo.md): Connect a Coveo instance to detect posture risks and compliance violations.
- [Onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-databricks.md): Connect a Databricks instance to detect posture risks and compliance violations.
- [Onboard Datadog](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-datadog.md): Connect a Datadog instance to detect posture risks and compliance violations.
- [Onboard Gainsight PX](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-gainsight-px.md): Connect a Gainsight PX instance to detect posture risks and compliance violations.
- [Onboard Grammarly](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-grammarly.md): Connect a Grammarly instance to detect posture risks and compliance violations.
- [Onboard Harness](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-harness.md): Connect a Harness instance to detect posture risks and compliance violations.
- [Onboard Intercom](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-intercom.md): Connect an Intercom instance to detect posture risks and compliance violations.
- [Onboard Jamf Pro](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-jamf-pro.md): Connect a Jamf Pro instance to detect posture risks and compliance violations.
- [Onboard JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-jumpcloud.md): Connect a JumpCloud instance to detect posture risks and compliance violations.
- [Onboard Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-kustomer.md): Connect a Kustomer instance to detect posture risks and compliance violations.
- [Onboard Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-microsoft-entra-id.md): Connect a Microsoft Entra ID instance to detect posture risks and compliance violations.
- [Onboard Monday.com](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-monday.com.md): Connect a Monday.com instance to detect posture risks and compliance violations.
- [Onboard MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-mongodb-atlas.md): Connect a MongoDB Atlas instance to detect posture risks and compliance violations.
- [Onboard MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-mulesoft.md): Connect a MuleSoft instance to detect posture risks and compliance violations.
- [Onboard Mural](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-mural.md): Connect a Mural instance to detect posture risks and compliance violations.
- [Onboard Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-office-365.md): Connect an Office 365 instance to detect posture risks and compliance violations.
- [Onboard Okta](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-okta.md): Connect an Okta instance to detect posture risks and compliance violations.
- [Onboard PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-pagerduty.md): Connect a PagerDuty instance to detect posture risks and compliance violations.
- [Onboard Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-redis-labs.md): Connect a Redis Labs instance to detect posture risks and compliance violations.
- [Onboard Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-salesforce.md): Connect a Salesforce instance to detect posture risks and compliance violations.
- [Onboard SAP Ariba](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-sap-ariba.md): Connect a SAP Ariba instance to detect posture risks and compliance violations.
- [Onboard Sentry](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-sentry.md): Connect a Sentry instance to detect posture risks and compliance violations.
- [Onboard ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-servicenow.md): Connect a ServiceNow instance to detect posture risks and compliance violations.
- [Onboard Shopify](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-shopify.md): Connect a Shopify instance to detect posture risks and compliance violations.
- [Onboard Slack Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-slack-enterprise.md): Connect a Slack instance to detect posture risks and compliance violations.
- [Onboard Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-sumo-logic.md): Connect a Sumo Logic instance to detect posture risks and compliance violations.
- [Onboard Workday](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-workday.md): Connect a Workday instance to detect posture risks and compliance violations.
- [Onboard Wrike](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-wrike.md): Connect a Wrike instance to detect posture risks and compliance violations.
- [Onboard YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-youtrack.md): Connect a YouTrack instance to detect posture risks and compliance violations.
- [SaaS Security Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-security-overview.md): This dashboard aggregates and presents security data from all four core SaaS Security pillars including: SSPM (Posture), SaaS Identity Security, SaaS Data Security, and SaaS Agent Security.
- [SaaS Security Checks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-security-checks.md): The dashboard captures key metrics to help you remediate SaaS assets at risk
- [Provider Instances Security Check](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/provider-instances-security-check.md): This page consolidates application security posture data across all onboarded instances
- [Detection Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/detection-rules.md): View Cloud Security Posture Rules
- [Remediation Actions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/remediation-actions.md): Learn more about actions available to remediate Issues.
- [Create and monitor tickets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/create-and-monitor-tickets.md): Learn more about creating a synced ticket to remediate an issue.
- [SaaS AI Agent Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security.md): SaaS AI Agent Security helps you secure AI agents deployed across enterprise SaaS environments.
- [Setup SaaS Security for AISPM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/setup-saas-security-for-aispm.md): Get started with SaaS Agent Security.
- [Onboard SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents.md): Learn more about how to onboard specific AI Agents.
- [Onboard Atlassian Rovo](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-atlassian-rovo.md): Connect Atlassian Rovo to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Box AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-box-ai-agents.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-chatgpt-enterprise.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Cursor Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-cursor-enterprise.md): Connect Cursor Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-gemini-enterprise.md): Connect Gemini Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard M365 Copilot](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-m365-copilot.md): Connect M365 Copilot to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Microsoft Copilot Studio](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-microsoft-copilot-studio.md): Connect Microsoft Copilot Studio to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Service Now](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-service-now.md): Connect Service Now to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Manage SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents.md)
- [View AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-ai-agents.md)
- [View Datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-datasets.md): The Datasets view provides a detailed look at the Inference Datasets.
- [View Agent Tools](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/cortex-cloud-saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-agent-tools.md): SaaS Agent Tools go beyond traditional scans that  focus on an inventory of previously vendor vetted, underlying tools.
- [How to perform advanced AI Security investigations using XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-ai-security/how-to-perform-advanced-ai-security-investigations-using-xql.md): Working with datasets in Cortex Cloud AI Security.
- [Serverless function posture security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security.md)
- [Onboard cloud providers for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/onboard-cloud-providers-for-serverless-functions.md)
- [Serverless function posture rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-rules.md)
- [Manage serverless function rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-rules/manage-serverless-function-rules.md)
- [Create serverless function rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-rules/create-serverless-function-rules.md)
- [Create an attack path rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-rules/create-an-attack-path-rule-for-serverless-functions.md)
- [Create a configuration rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-rules/create-a-configuration-rule-for-serverless-functions.md)
- [Create a network exposure rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-rules/create-a-network-exposure-rule-for-serverless-functions.md)
- [Serverless function posture policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-policies.md): Create and manage serverless function policies to detect threats and drive remediation.
- [Manage serverless function policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-policies/manage-serverless-function-policies.md)
- [Create serverless function policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-posture-policies/create-serverless-function-policies.md)
- [Serverless function usage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/serverless-function-posture-security/serverless-function-usage.md)
- [Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cortex-cloud-application-security.md)
- [Cloud workload policies and rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules.md)
- [How policies and rules work together](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/how-policies-and-rules-work-together.md)
- [Cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies.md)
- [Types of cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies.md)
- [Trusted image cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies/types-of-cloud-workload-policies.md)
- [Cloud Workload Policies page](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page.md)
- [Enable or disable a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/enable-or-disable-a-cloud-workload-policy.md)
- [Create a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/create-a-cloud-workload-policy.md)
- [Use an existing policy to create a new cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/use-an-existing-policy-to-create-a-new-cloud-workload-policy.md)
- [Edit a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/edit-a-cloud-workload-policy.md)
- [Delete a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/delete-a-cloud-workload-policy.md)
- [Cloud workload preventive action](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action.md)
- [Cloud workload rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules.md)
- [Default (pre-defined) rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules.md)
- [Custom (user-defined) rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules.md)
- [Cloud Workload Rules page](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page.md)
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules/create-a-new-custom-detection-rule.md)
- [Use an existing rule to create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules/use-an-existing-rule-to-create-a-new-custom-detection-rule.md)
- [Edit a custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules/edit-a-custom-detection-rule.md)
- [Delete a custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/cloud-workload-policies-and-rules/cloud-workload-rules/delete-a-custom-detection-rule.md)
- [Base image rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/base-images-rule.md)
- [Create a base image rule](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/base-images-rule/create-a-base-images-rule.md)
- [Find the base image for an asset](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/base-images-rule/prerequisites.md)
- [Web and API Security (WAAS)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview.md)
- [Personas workflow](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/personas-workflow.md): Cortex API security distributes responsibilities across SOC analysts, security practitioners, and workload owners.
- [Secure your API landscape](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape.md)
- [Gain visibility and assess risk of API endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/gain-visibility-and-assess-risk-of-api-endpoints.md)
- [Monitor and investigate API threats](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/monitor-and-investigate-api-threats.md)
- [Configure API security from end to end](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end.md): Secure your API landscape through third-party integrations and agent-based protection policies.
- [Ingest AWS API Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/ingest-aws-api-gateway.md)
- [Ingest Azure APIM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/ingest-azure-apim.md)
- [Ingest Apigee Proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/ingest-apigee-proxy.md)
- [Ingest Kong](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/ingest-kong.md)
- [Ingest F5](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/ingest-f5.md)
- [Agent-based protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection.md)
- [Set up Web and API Security profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection/set-up-web-and-api-security-profiles.md)
- [Apply Web and API Security profiles to workloads](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection/apply-web-and-api-security-profiles-to-workloads.md)
- [Manage Web and API Security prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection/manage-web-and-api-security-prevention-profiles.md)
- [Add a disable prevention rule for cloud workloads](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection/add-a-disable-prevention-rule-for-cloud-workloads.md)
- [Add a support exception rule for cloud workloads](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection/add-a-support-exception-rule-for-cloud-workloads.md)
- [Add a legacy exception rule for cloud workloads](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection/add-a-legacy-exception-rule-for-cloud-workloads.md)
- [Additional workload management tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/agent-based-protection/additional-workload-management-tasks.md)
- [API specification inventory](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview/secure-your-api-landscape/api-specification-inventory.md)
- [Serverless function runtime security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview-1.md)
- [Set up serverless function protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview-1/set-up-serverless-function-protection.md)
- [Serverless runtime issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/cloud-security/overview-1/serverless-runtime-issues.md)
- [Cortex XSIAM XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql.md)
- [Get started with XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql.md): XQL is the Palo Alto Networks Cortex Query Language used in Cortex XSIAM.
- [XQL language features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/xql-language-features.md): Learn more about the Cortex Query Language features to query for raw network and endpoint data.
- [XQL Language Structure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/xql-language-structure.md): Learn more about the Cortex Query Language structure when creating a query.
- [Supported operators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/supported-operators.md): Cortex Query Language supports specific comparison, boolean, and set operators in Cortex XSIAM.
- [Datasets and presets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/datasets-and-presets.md): The Cortex Query Language supports built-in datasets, custom datasets, and presets.
- [About examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/about-examples.md): Learn more about the Cortex Query Language (XQL) examples provided.
- [JSON functions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/json-functions.md): Learn more about how Cortex XSIAM treats JSON functions in the Cortex Query Language.
- [How to filter for empty values in the results table](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/how-to-filter-for-empty-values-in-the-results-table.md): Learn how to filter for empty values in the results table in Cortex Query Language.
- [Understanding string manipulation in XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/understanding-string-manipulation-in-xql.md): Learn more about string manipulation in Cortex Query Language (XQL) using double and triple quotes.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md)
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md)
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md)
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md)
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/create-xql-query.md)
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md)
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md)
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/graph-query-results.md)
- [Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates.md): Use Query Builder templates to query your data sets without using the Cortex Query Language.
- [Get started with Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/get-started-with-query-builder-templates.md)
- [Considerations for using Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/considerations-for-using-query-builder-templates.md)
- [Create a query from a template](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/create-a-query-from-a-template.md)
- [Run a free text query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/run-a-free-text-query.md)
- [Query Builder template examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/query-builder-template-examples.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md)
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/overview-of-the-query-center/query-center-reference-information.md)
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md)
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-your-personal-query-library.md): Cortex XSIAM provides as part of the Query Library a personal library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-your-macros.md)
- [Federated Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/federated-search.md)
- [Federated Search configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/federated-search/federated-search-configuration.md)
- [Query using Federated Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/federated-search/query-using-federated-search.md)
- [Manage external datasets](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/federated-search/manage-external-datasets.md)
- [Legacy Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder.md): Learn more about the entities in the Legacy Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-authentication-query.md)
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-event-log-query.md)
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-file-query.md)
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-image-load-query.md)
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-network-connections-query.md)
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-network-query.md)
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-process-query.md)
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-registry-query.md)
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/query-across-all-entities.md)
- [Cortex XQL syntax, parameters, and examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/cortex-xql-syntax-parameters-and-examples.md): Comprehensive syntax rules and structural requirements for XQL queries
- [Graph Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search.md): Learn more about Graph Search in Cortex XSIAM.
- [What is Graph Search?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/what-is-graph-search.md): Learn more about how to use Graph Search to search assets, findings, and their contextual data.
- [Get started with Graph Search queries](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/get-started-with-graph-search-queries.md): Learn more about how to get started before building a Graph Search query.
- [How to build Graph Search queries?](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/how-to-build-graph-search-queries.md): Learn more about building Graph Search queries using the built-in query interface.
- [Understand Graph Search query results](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/understand-graph-search-query-results.md): Learn more about the Graph Search query results.
- [Create Graph Search query](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/create-graph-search-query.md): Learn how to create Graph Search queries in Cortex XSIAM.
- [Graph Search examples](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/graph-search-examples.md): Learn how to build Graph Search queries by working through a few examples.
- [Manage the Graph Search Query Library](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/manage-the-graph-search-query-library.md): Learn more about the Cortex XSIAM Graph Search Query Library to manage your queries.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/edit-and-run-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Supported assets and findings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/supported-assets-and-findings.md)
- [FAQ on Graph Search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/faq-on-graph-search.md): Answer some frequently asked questions relating to Graph Search.
- [Create detection rules based on graph search](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/graph-search/create-detection-rules-based-on-graph-search.md)
- [About Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli.md): The Cortex CLI is a unified command-line tool integrating Cloud Workload Protection, API Security, and Code Security scans into a single executable.
- [Connect Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/connect-cortex-cli.md)
- [Installation workflows](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/connect-cortex-cli/installation-workflows.md): Install Cortex CLI using a package manager, manual download, or the Cortex Cloud interface.
- [Manage the CLI after installation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/connect-cortex-cli/manage-the-cli-after-installation.md): Upgrade, pin, uninstall, or update Cortex CLI through automated downloads.
- [Authenticate credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/connect-cortex-cli/authenticate-credentials.md): Configure Cortex CLI credentials using a file, environment variables, or command-line flags.
- [Self-service API keys for CLI scans](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/connect-cortex-cli/self-service-api-keys-for-cli-scans.md)
- [Cortex CLI usage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-usage.md)
- [Cortex CLI common command line reference guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-common-command-line-reference-guide.md)
- [Cortex CLI for Code Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security.md)
- [Cortex CLI usage for Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security/cortex-cli-usage-for-application-security.md)
- [Cortex CLI Cortex Cloud Application Security command line reference](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security/cortex-cli-application-security-command-line-reference.md)
- [Custom Cortex checks and signature verification](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security/cortex-cli-application-security-command-line-reference/custom-cortex-checks-and-signature-verification.md): Load custom Cortex checks and optionally verify their signatures.
- [Cortex CLI pre-commit hooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-commit-hooks.md)
- [Pre-commit hook usage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-commit-hooks/pre-commit-hook-usage.md)
- [Cortex CLI pre-receive hooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-receive-hooks.md)
- [Pre-receive hook usage](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-receive-hooks/pre-receive-hook-usage.md)
- [Cortex CLI for Cloud Workload Protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-cloud-workload-protection.md)
- [Cloud Workload Protection command line reference](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-cloud-workload-protection/cloud-workload-protection-command-line-reference.md)
- [Cortex CLI for API Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-api-security.md)
- [Cortex CLI API Security command line reference guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-api-security/cortex-cli-api-security-command-line-reference-guide.md)
- [API Security scan report schema](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-api-security/cortex-cli-api-security-command-line-reference-guide/api-security-scan-report-schema.md): Reference schema for API Security scan reports.
- [API Security scan output example](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/about-cortex-cli/cortex-cli-for-api-security/cortex-cli-api-security-command-line-reference-guide/api-security-scan-output-example.md): Example API Security scan report output.
- [Role-Based Access Control](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control.md): Learn how to limit role permissions in Cortex XSIAM.
- [Role permissions by component](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/role-permissions-by-component.md): Learn how to manage role permissions in Cortex XSIAM.
- [Core tenant and administrative permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/core-tenant-and-administrative-permissions.md)
- [Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions.md): Learn about role permissions for Cortex XSIAM configuration components.
- [Auditing permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/auditing-permissions.md): Manage access to Cortex XSIAM audit logs and administrative activity records.
- [Alert Notifications permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/alert-notifications-permissions.md): Manage Cortex XSIAM alert notification rules, templates, and forwarding settings.
- [General Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/general-configuration-permissions.md): Manage access to Cortex XSIAM general settings and system-wide configuration.
- [Cortex XDR Analytics permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/cortex-xdr-analytics-permissions.md): Manage access to Cortex XSIAM analytics configuration and related settings.
- [Access management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/access-management-permissions.md): Manage access to Cortex XSIAM users, roles, and access management settings.
- [Data Broker permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/data-broker-permissions.md): Manage access to Cortex XSIAM Data Broker configuration and operations.
- [Log Collection permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/log-collection-permissions.md): Manage access to Cortex XSIAM log collection configuration and data sources.
- [Data Sources permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/data-sources-permissions.md): Manage access to Cortex XSIAM data source configuration and ingestion settings.
- [External Issues Mapping permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/external-issues-mapping-permissions.md): Manage access to Cortex XSIAM mappings for external issue integrations.
- [Integrations - instance permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/integrations-instance-permissions.md): Manage access to individual Cortex XSIAM integration instances and settings.
- [Integrations Permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/integrations-permissions.md): Manage access to Cortex XSIAM integration configuration and available instances.
- [Data Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/data-management-permissions.md): Manage access to Cortex XSIAM data management and retention settings.
- [Public API](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/public-api.md): Manage access to Cortex XSIAM public API configuration and credentials.
- [Threat Intelligence permission - API configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/threat-intelligence-permission-api-configuration.md): Manage access to Cortex XSIAM Threat Intelligence API configuration.
- [Long-running HTTP Integrations configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/long-running-http-integrations-configuration.md): Manage access to Cortex XSIAM long-running HTTP integration configuration.
- [Credentials permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/credentials-permissions.md): Manage access to Cortex XSIAM credentials and secure connection settings.
- [Network Scanners permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/network-scanners-permissions.md): Manage access to Cortex XSIAM network scanner configuration and operations.
- [Apps - Instance permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/apps-instance-permissions.md): Manage access to Cortex XSIAM app instances and their configuration.
- [Object Setup permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions.md): Manage access to Cortex XSIAM object setup and related configuration.
- [Case Properties permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/case-properties-permissions.md): Configure access to case domains, custom statuses, and resolution statuses in Cortex XSIAM.
- [Exclusion List permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/exclusion-list-permissions.md): Control access to manage excluded threat indicators and their exclusion settings in Cortex XSIAM.
- [Fields and Types permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/fields-and-types-permissions.md): Control access to custom fields, indicator types, and SLA rule configurations in Cortex XSIAM.
- [Layout permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/layout-permissions.md): Control access to case and issue layouts, including their layout rules in Cortex XSIAM.
- [Sync Profile permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/sync-profile-permissions.md): Control access to sync profiles for mirroring cases with external platforms  in Cortex XSIAM.
- [Marketplace permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/marketplace-permissions.md): Control access to discover, install, and manage Marketplace content packs in Cortex XSIAM.
- [Help permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/help-permissions.md): Control access to create and manage in-product technical support cases  in Cortex XSIAM.
- [SOC Operations, Investigation & Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/soc-operations-investigation-and-response-permissions.md)
- [Dashboards and Reports permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions.md): Set permissions for dashboards and reports in Cortex XSIAM.
- [Dashboards permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/dashboards-permissions.md): Manage access to Cortex XSIAM dashboards, widgets, and dashboard sharing.
- [Command Center Dashboard permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/command-center-dashboard-permissions.md): Manage access to Cortex XSIAM Command Center dashboards and their security metrics.
- [Ingestion Monitoring dashboard permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/ingestion-monitoring-dashboard-permissions.md): Manage access to Cortex XSIAM data ingestion monitoring dashboards.
- [Reports permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/reports-permissions.md): Manage access to Cortex XSIAM reports and custom report templates.
- [Email Command Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/email-command-center-permissions.md): Manage access to the Cortex XSIAM Email Command Center and email threat metrics.
- [Cloud Security Command Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/cloud-security-command-center-permissions.md): Manage access to the Cortex XSIAM Cloud Security Command Center.
- [Cases and Issues permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cases-and-issues-permissions.md): Control access to investigate, manage, and respond to cases and issues in Cortex XSIAM.
- [Investigation and Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions.md): Configure role permissions for search, response, and automation capabilities in Cortex XSIAM.
- [Search permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions.md): Configure access to threat hunting, query, and forensic investigation tools in Cortex XSIAM.
- [Query Library permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/query-library-permissions.md): Manage access to saved XQL queries in Cortex XSIAM's Query Library.
- [Query Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/query-center-permissions.md): Manage access to write, run, schedule, and export XQL queries in Cortex XSIAM.
- [Forensics permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/forensics-permissions.md): Manage access to Cortex XSIAM forensic investigations, collections, and threat hunts.
- [Host Insights permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/host-insights-permissions.md): Manage access to Cortex XSIAM's endpoint inventory, host details, and hygiene data.
- [Graph Search permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/graph-search-permissions.md): Manage access to Cortex XSIAM's Graph Search for cloud assets and security findings.
- [Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions.md): Configure access to endpoint and network response actions and tools in Cortex XSIAM.
- [Action Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/action-center-permissions.md): Manage access to Cortex XSIAM endpoint response actions and action history.
- [EDL permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/edl-permissions.md): Manage Cortex XSIAM External Dynamic Lists for firewall-enforced threat blocking.
- [Agent Scripts Library permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/agent-scripts-library-permissions.md): Manage Cortex XSIAM endpoint scripts for response, collection, and automation.
- [Live Terminal permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/live-terminal-permissions.md): Manage Cortex XSIAM interactive endpoint shell access for investigation and remediation.
- [Automation permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions.md): Configure permissions for playbooks, scripts, playground, and automated exclusions in Cortex XSIAM.
- [Playbook permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/playbook-permissions.md): Manage access to Cortex XSIAM playbooks and automated response workflows.
- [Script permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/script-permissions.md): Manage access to Cortex XSIAM scripts for automation and remediation.
- [Jobs permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/jobs-permissions.md): Manage access to Cortex XSIAM scheduled automation jobs and their execution.
- [Playground permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/playground-permissions.md): Manage access to the Cortex XSIAM playground for testing commands and scripts.
- [Automation Exclusion Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/automation-exclusion-center-permissions.md): Manage Cortex XSIAM automation exclusions for commands, scripts, and remediation.
- [Jupyter and Observability apps permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/jupyter-and-observability-apps-permissions.md): Configure permissions to use Jupyter and Observability applications.
- [Threat Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/threat-management-permissions.md): Configure Detection Rules and Threat Intel permissions in Cortex XSIAM.
- [Detection Rules permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/threat-management-permissions/detection-rules-permissions.md): Configure Detection Rules permissions in Cortex XSIAM.
- [Threat Intelligence permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/threat-management-permissions/threat-intelligence-permissions.md): Configure Threat Intelligence permissions in Cortex XSIAM
- [Exceptions Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions.md): Configure issue exclusion permissions in Cortex XSIAM.
- [Issue Exclusions permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions/issue-exclusions-permissions.md): Configure Issue Exclusions permissions in Cortex XSIAM.
- [Exception Management Admin permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions/exception-management-admin-permissions.md): Configure Exception Management Admin permissions in Cortex XSIAM.
- [Exception Approver Admin permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions/exception-approver-admin-permissions.md): Configure Exception Approver Admin permissions in Cortex XSIAM.
- [Managed Services permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/managed-services-permissions.md): Configure access to Managed Services for Unit 42 Managed Threat Hunting and Managed Detection and Response.
- [Cortex Agentic Assistant permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cortex-agentic-assistant-permissions.md): Configure the Cortex Agentic Assistant permissions, which includes AI Prompts and Agent permissions in Cortex XSIAM.
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cortex-agentic-assistant-permissions/ai-prompts.md): Configure AI Prompts permissions in Cortex XSIAM.
- [Cortex Agentic Assistant Agents](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cortex-agentic-assistant-permissions/cortex-agentic-assistant-agents.md): Configure Cortex Agentic Assistant Agents permissions in Cortex XSIAM.
- [Agents and endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/agents-and-endpoint-protection.md): Configure permissions for XDR Agent infrastructure and endpoint data loss prevention in Cortex XSIAM.
- [Inventory - Agent permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions.md): Configure permissions for Endpoints (XDR Agent) in Cortex XSIAM.
- [Agent Administrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-administrations.md): Control access to endpoint inventory, agent health, and lifecycle operations in Cortex XSIAM.
- [Agent Groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-groups.md): Manage endpoint groups and policy targeting in Cortex XSIAM.
- [Agent Prevention Policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-prevention-policies.md): Configure endpoint prevention policies and protection settings in Cortex XSIAM.
- [Global Exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/global-exceptions.md): Manage global prevention exceptions and their endpoint scope in Cortex XSIAM.
- [Agent Profiles](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-profiles.md): Configure endpoint agent profiles and communication settings in Cortex XSIAM.
- [Agent Extension Policies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-extension-policies.md): Configure endpoint extension policies and capabilities in Cortex XSIAM.
- [Agent Installations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-installations.md): Manage Cortex XSIAM agent installation packages and deployments.
- [Host Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/host-firewall.md): Configure host firewall rules and review firewall events in Cortex XSIAM.
- [Device Control](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/device-control.md): Manage device control policies, rules, and exceptions in Cortex XSIAM.
- [Data Security - Endpoint DLP permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions.md): Configure Endpoint Data Loss Prevention permissions in Cortex XSIAM.
- [Data-in-Motion Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/data-in-motion-rules.md): Configure endpoint data-in-motion protection rules in Cortex XSIAM.
- [Endpoint Applications](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/endpoint-applications.md): Manage endpoint applications monitored by Data Loss Prevention in Cortex XSIAM.
- [Endpoint Applications Groups](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/endpoint-applications-groups.md): Manage endpoint application groups for Data Loss Prevention policies in Cortex XSIAM.
- [Endpoint DLP Settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/endpoint-dlp-settings.md): Configure endpoint Data Loss Prevention settings in Cortex XSIAM.
- [Inventory - Assets permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions.md): Configure inventory permissions for assets and endpoints in Cortex XSIAM.
- [Network Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/network-configuration-permissions.md): Configure network topology, ranges, and trusted networks in Cortex XSIAM.
- [Compliance (Legacy) permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/compliance-legacy-permissions.md): View legacy cloud compliance violations for assets in Cortex XSIAM.
- [Asset Inventory permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-inventory-permissions.md): Control access to asset inventory data and metadata in Cortex XSIAM.
- [Asset Roles configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-roles-configuration-permissions.md): Configure functional asset roles and endpoint assignments in Cortex XSIAM.
- [Asset Groups permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-groups-permissions.md): Manage asset groups and scoped access controls in Cortex XSIAM.
- [Exposure and Vulnerability Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exposure-and-vulnerability-management-permissions.md): Configure exposure, vulnerability, and attack surface management permissions in Cortex XSIAM.
- [Attack Surface permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exposure-and-vulnerability-management-permissions/attack-surface-permissions.md): Configure Attack Surface Management permissions in Cortex XSIAM.
- [Vulnerability Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exposure-and-vulnerability-management-permissions/vulnerability-management-permissions.md): Configure Vulnerability Management permissions in Cortex XSIAM.
- [Exposure Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exposure-and-vulnerability-management-permissions/exposure-management-permissions.md): Configure Exposure Management permissions in Cortex XSIAM.
- [Cloud Security and Posture Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions.md): Configure Cloud Security and Posture Management permissions in Cortex XSIAM.
- [CLI Tool permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/cli-tool-permissions.md): Configure CLI Tool permissions in Cortex XSIAM.
- [Application Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions.md): Configure Application Security permissions in Cortex XSIAM.
- [Application Security - Generic Collector permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-generic-collector-permissions.md): Configure Generic Collector permissions for Application Security in Cortex XSIAM.
- [Application Security - Issues permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-issues-permissions.md): Configure Application Security issue permissions in Cortex XSIAM.
- [Application Security - Scans permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-scans-permissions.md): Configure Application Security scan permissions in Cortex XSIAM.
- [Application Security - Policy Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-policy-management-permissions.md): Configure Application Security policy management permissions in Cortex XSIAM.
- [Application Security - 3rd Party tools permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-3rd-party-tools-permissions.md): Configure third-party tool permissions for Application Security in Cortex XSIAM.
- [Configurations - Application Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/configurations-application-security-permissions.md): Configure Application Security configuration permissions in Cortex XSIAM.
- [Policies - Cloud Workload permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/policies-cloud-workload-permissions.md): Configure Cloud Workload policy permissions in Cortex XSIAM.
- [Cloud Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/cloud-security-permissions.md): Configure Cloud Security permissions in Cortex XSIAM.
- [Compliance - Cloud permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/compliance-cloud-permissions.md): Configure cloud compliance permissions in Cortex XSIAM.
- [Data Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/data-security-permissions.md): Configure Data Security permissions in Cortex XSIAM.
- [AI Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/ai-security-permissions.md): Configure AI Security permissions in Cortex XSIAM.
- [Data Classification permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/data-classification-permissions.md): Configure Data Classification permissions in Cortex XSIAM.
- [Identity Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/identity-security-permissions.md): Configure Identity Security permissions in Cortex XSIAM.
- [API documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/api-documentation.md): Use the Cortex XSIAM APIs to integrate Cortex XSIAM with third-party apps or services to ingest alerts and to leverage alert stitching and investigation capabilities.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference.md)
- [Cloud service provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/cloud-service-provider-permissions.md): Grant the correct cloud service provider permissions for Cortex XSIAM.
- [Microsoft Windows security auditing setup](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup.md)
- [Enable security auditing event IDs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids.md)
- [Enable security auditing event IDs with GPO](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-security-auditing-event-ids-with-gpo.md)
- [Set up local machine security auditing without GPO](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/set-up-local-machine-security-auditing-with-gpo.md)
- [Additional setup for Active Directory Certificate Services (ADCS) events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/additional-setup-for-active-directory-certificate-services-adcs-events.md)
- [Enable auditing access to AD domain objects - 4662](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-auditing-access-to-ad-domain-objects-4662.md)
- [Enable additional event logs using Event Viewer](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-additional-event-logs-using-event-viewer.md)
- [Enable LDAP server events logging (1644)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644.md)
- [Enable LDAP server events logging using RegEdit](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-regedit.md)
- [Enable LDAP server events logging using GPO](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-gpo.md)
- [Validate log collection for LDAP Server events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/validate-log-collection-for-ldap-server-events.md)
- [XDM fields for mapping authentication events](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/xdm-fields-for-mapping-authentication-events.md): Learn more about the Cortex Data Model (XDM) fields to map for authentication events.
- [Cortex Network Scanner OSS](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/cortex-network-scanner-oss.md)
- [Fair Usage policy for Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/reference/fair-usage-policy-for-cortex-xsiam.md)
- [Learn more about migrating to the latest broker VM image](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/migrating-to-a-new-broker-vm-image/migrating-to-a-new-broker-vm-image.md)
- [Standalone Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/migrating-to-a-new-broker-vm-image/standalone-broker-vm.md): Learn more about migrating a standalone broker VM image.
- [Broker VM high availability cluster node](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/migrating-to-a-new-broker-vm-image/broker-vm-high-availability-cluster-node.md): Learn more about migrating a broker VM High Availability (HA) cluster node.

## Cortex XDR 5.x Documentation

- [Navigate the Cortex XDR 5.x docs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/readme.md): Start here for a visual overview of the main Cortex XDR 5.x documentation areas.
- [What is Cortex XDR ?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/readme-1.md): Learn about Cortex XDR and the security challenges it addresses.
- [Cortex XDR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/readme-1/cortex-xdr-architecture.md): Learn more about the Cortex XDR architecture.
- [Agentic AI in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/agentic-ai-in-cortex-xdr.md): Use the Cortex Agentic Assistant to investigate cases, perform threat hunting, and create scripts. Embed and run LLM prompts in playbooks. View AI case summaries.
- [Agentic Assistant use cases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/agentic-ai-in-cortex-xdr/agentic-assistant-use-cases.md): Recommended prompts to automate your SOC using the Cortex Agentic Assistant
- [Agentic Assistant security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/agentic-ai-in-cortex-xdr/agentic-assistant-security.md): Learn about how the Agentic Assistant is built using responsible AI principles.
- [What is Cortex Gateway?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/what-is-cortex-gateway.md): A brief introduction to Cortex Gateway
- [Fair Usage policy for Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/fair-usage-policy-for-cortex-xdr.md)
- [Cortex XDR license plan](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/cortex-xdr-license-plan.md)
- [Data retention in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/cortex-xdr-license-plan/data-retention-in-cortex-xdr.md): Learn more about the default retention periods for all Cortex XDR licenses, and the available retention add-ons.
- [Data storage lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/cortex-xdr-license-plan/data-storage-lifecycle.md)
- [License allocation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/cortex-xdr-license-plan/license-allocation.md): Learn more about how Cortex XDR regulates licenses.
- [License expiration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/cortex-xdr-license-plan/license-expiration.md): Learn more about the Cortex XDR license expiration and validation period.
- [Security Operations Center roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/security-operations-center-roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [In-product support ticket creation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/in-product-support-case-creation.md): Open a support ticket directly in Cortex XDR and record your console to capture your issues and have the ticket handled efficiently.
- [Use the interface](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/use-the-interface.md): Learn more about how to use the Cortex XDR interface.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/supported-web-browsers.md)
- [Upgrade to Cortex XDR 5.x](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/upgrade-to-cortex-xdr-5.x.md)
- [Extend Cortex XDR 5.x with Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/learn-about-cortex-xdr-5.x/extend-cortex-xdr-5.x-with-cortex-cloud-runtime-security.md)
- [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps.md)
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/plan-and-prepare.md): Learn more about deployment considerations and onboarding steps.
- [Cortex XDR onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/cortex-xdr-onboarding-checklist.md): Review the steps to deploy and onboard Cortex XDR.
- [Activate Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr.md): Learn how to activate your tenant.
- [Cortex XDR supported regions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/cortex-xdr-supported-regions.md)
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources.md): Configure firewall access for Cortex XDR resources.
- [Regional egress resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/regional-egress-resources.md)
- [Engines IP addresses (outbound)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/engines-ip-addresses-outbound.md): Allow outbound engine IP addresses to access your network resources.
- [Inbound source resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/inbound-source-resources.md): Allow Cortex XDR source IP addresses to access your resources.
- [FedRamp and the US Federal Government required resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md): Configure required resources for FedRAMP and US federal deployments.
- [Set up users, groups, and roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles.md): Learn how to set up users, groups, and roles in Cortex XDR.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles/user-group-management.md): Create and manage user groups, group mappings, and group-based access in Cortex XDR.
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles/assign-user-roles-and-groups.md)
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication.md): Authenticate Cortex XDR users using SAML 2.0 or Customer Support Portal (CSP).
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Add Customer Support Portal users and grant them access to Cortex Gateway and Cortex XDR.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso.md)
- [Set up okta as the Identity provider using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-through-the-customer-support-portal-1.md): Add Customer Support Portal users and grant tenant access.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso-1.md): Configure SAML 2.0 single sign-on for Cortex XDR users.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso-1/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta SAML single sign-on for Cortex XDR.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso-1/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID SAML single sign-on for Cortex XDR.
- [Pre-installation steps for Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/pre-installation-steps-for-cortex-xdr-agents.md)
- [Install Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents.md): Learn about the initial steps required to deploy Cortex XDR agent software to endpoints.
- [Plan your agent deployment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/plan-your-agent-deployment.md)
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md)
- [Create an installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/create-an-installation-package.md)
- [Deploy agent installation packages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/deploy-agent-installation-packages.md)
- [Configure XDR Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/configure-xdr-analytics.md)
- [Set up Cloud Identity Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-cloud-identity-engine.md)
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/manage-api-keys.md)
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps.md)
- [Set up your environment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment.md): Learn more about setting up the Cortex XDR environment based on your preferences.
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-server-settings.md)
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-security-settings.md)
- [Data and log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding.md)
- [Forward logs and data from Cortex XDR to external services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services.md)
- [Configure external applications for forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding.md)
- [Forward notifications to Amazon SQS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqs.md)
- [Forward notifications to Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-s3.md)
- [Forward notifications to Splunk](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-splunk.md)
- [Forward notifications to webhook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-webhook.md)
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver.md)
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/integrate-slack-for-outbound-notifications.md)
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-notification-forwarding.md)
- [Set up email notifications for tenant updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/set-up-email-notifications-for-tenant-updates.md)
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/monitor-administrative-activity.md)
- [Data and log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats.md)
- [Management audit log messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-messages.md)
- [Issue notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/issue-notification-format.md)
- [Agent Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/agent-audit-log-notification-format.md)
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-notification-format.md)
- [Log format for IOC and BIOC issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/log-format-for-ioc-and-bioc-issues.md)
- [Analytics log format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/analytics-log-format.md)
- [Manage user roles and access management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management.md): Learn how to manage access for users, user roles, user groups, and Single Sign-On (SSO) for users on a specific Cortex XDR tenant.
- [Manage user roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-roles.md)
- [Manage user access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md)
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope.md): Configure Scope-Based Access Control (SBAC) to limit access to Cortex XDR data and content.
- [Manage access to objects](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects.md)
- [Manage access to custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-custom-dashboards.md)
- [Manage access to report templates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-report-templates.md)
- [Manage access to playbooks and scripts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-playbooks-and-scripts.md)
- [Manage access to saved queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-saved-queries.md)
- [Configure the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant.md): Create and manage agents and actions in the Agents Hub and configure access to the Cortex Agentic Assistant.
- [Agents Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub.md)
- [Manage actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-actions.md)
- [Register actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/register-actions.md)
- [Manage agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-agents.md)
- [Build agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/build-agents.md)
- [Expand agent capabilities with MCP integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/expand-agent-capabilities-with-mcp-integrations.md)
- [Agentic Assistant role based access control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agentic-assistant-role-based-access-control.md): Configure role-based access to the Cortex Agentic Assistant and Agents Hub.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/dashboards-and-reports.md)
- [Multi-Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant.md)
- [What is Cortex XDR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/what-is-cortex-xdr-multi-tenant.md): Learn about Cortex multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a single console.
- [Multi-tenant central licensing management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/multi-tenant-central-licensing-management.md)
- [Onboard Cortex multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/onboard-cortex-multi-tenant.md): Learn how to activate and manage tenants.
- [Dynamic license allocation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/dynamic-license-allocation.md): In a multi-tenant central licensing management environment, you can dynamically edit child tenant allocations, add child tenants, and delete child tenants with the license pool automatically updated.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management.md): Track, manage, and investigate child tenant data from the parent tenant.
- [Track your tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/track-your-tenant-management.md)
- [Investigate child tenant data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/investigate-child-tenant-data.md)
- [Create and allocate configurations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/create-and-allocate-configurations.md)
- [Create a security managed action](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/create-a-security-managed-action.md)
- [About managed threat hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/about-managed-threat-hunting.md): Understand how Managed Threat Hunting can help your organization.
- [Configure and deploy Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr.md)
- [Cortex XDR - Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/cortex-xdr-analytics.md): Learn how to enable Cortex XDR - Analytics, which allows Cortex XDR to analyze data from a variety of sensors and develop a baseline to raise analytics alerts.
- [Configure Cortex XDR network parameters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-cortex-xdr-network-parameters.md): Define the IP address ranges and domain names used by Cortex XDR to identify your network assets.
- [Enable the Analytics Engine and Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/enable-the-analytics-engine-and-identity-analytics.md): Learn how to enable the Analytics Engine and Identity Analytics.
- [Set up Cloud Identity Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/set-up-cloud-identity-engine.md): Learn how to set up Cloud Identity Engine to use with Cortex XDR.
- [Configure the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant.md)
- [Agentic Assistant components and concepts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agentic-assistant-components-and-concepts.md): Learn about the key components and concepts, such as agents and actions in the Cortex Agentic Assistant
- [Agentic Assistant Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agents-hub.md): Learn about personal and system agents in in the Agentic Assistant Hub
- [Manage actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agents-hub/manage-actions.md)
- [Register actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agents-hub/register-actions.md)
- [Manage agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agents-hub/manage-agents.md)
- [Build agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agents-hub/build-agents.md)
- [Manage knowledge sources (preview)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agents-hub/manage-knowledge-sources-preview.md): Enhance AI agent capabilities by leveraging the Knowledge Center (preview) to provide agents with your business-specific source of truth and built-in Cortex (system) knowledge.
- [Expand agent capabilities with MCP integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agents-hub/expand-agent-capabilities-with-mcp-integrations.md)
- [Agentic Assistant role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/configure-the-cortex-agentic-assistant/agentic-assistant-role-based-access-control.md): Configure permissions to access Cortex Agentic Assistant features.
- [About the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/cortex-mcp-server.md): Install, configure, use, and extend the Cortex MCP server.
- [Install the Cortex MCP sever](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/cortex-mcp-server/install-the-cortex-mcp-sever.md)
- [Confgure the MCP client](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/cortex-mcp-server/confgure-the-mcp-client.md)
- [Use the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/cortex-mcp-server/use-the-cortex-mcp-server.md): Investigate Cortex data with built-in MCP tools.
- [Create custom Cortex MCP server tools](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/configure-and-deploy-cortex-xdr/cortex-mcp-server/create-custom-cortex-mcp-server-tools.md): Extend the Cortex MCP server with OpenAPI or Python tools.
- [Data management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm.md)
- [What is the Broker VM?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/what-is-the-broker-vm.md)
- [Set up and configure Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm.md)
- [Broker VM image installations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations.md)
- [Set up Broker VM on Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-alibaba-cloud.md)
- [Set up Broker VM on Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-amazon-web-services.md)
- [Set up Broker VM on Google Cloud Platform (GCP)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-google-cloud-platform-gcp.md)
- [Set up Broker VM on KVM using Ubuntu](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-kvm-using-ubuntu.md)
- [Set up Broker VM on Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-azure.md)
- [Set up Broker VM on Microsoft Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-hyper-v.md)
- [Set up Broker VM on Nutanix Hypervisor](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-nutanix-hypervisor.md)
- [Set up Broker VM on VMware ESXi using vSphere Client](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-vmware-esxi-using-vsphere-client.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets.md)
- [Manage Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm.md)
- [Edit Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/edit-broker-vm-configuration.md)
- [Increase Broker VM storage allocated for data caching](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/increase-broker-vm-storage-allocated-for-data-caching.md)
- [Monitor Broker VM using Prometheus](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/monitor-broker-vm-using-prometheus.md)
- [Collect Broker VM Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/collect-broker-vm-logs.md)
- [Upgrade Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/upgrade-broker-vm.md)
- [Update Broker VM applets independently](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/update-broker-vm-applets-independently.md)
- [Import Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/import-broker-vm-configuration.md)
- [Open Live Terminal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/open-live-terminal.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/add-broker-vm-to-cluster.md)
- [Switchover Primary Node in Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/switchover-primary-node-in-cluster.md)
- [Remove from Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm/remove-from-cluster.md)
- [Manage Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/manage-broker-vm-data-collector-applets.md)
- [Broker VM High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster.md)
- [Configure High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster/configure-high-availability-cluster.md)
- [Manage Broker VM clusters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters.md)
- [View cluster details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/view-cluster-details.md)
- [Edit cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/edit-cluster.md)
- [Add applet to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-applet-to-cluster.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-broker-vm-to-cluster.md)
- [Remove cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/remove-cluster.md)
- [Broker VM notifications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/broker-vm-notifications.md)
- [Monitor Broker VM activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/monitor-broker-vm-activity.md)
- [Troubleshoot Broker VM applet errors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/broker-vm/troubleshoot-broker-vm-applet-errors.md)
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period-based retention.
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/dataset-management/lookup-datasets.md)
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/dataset-management/lookup-datasets/import-a-lookup-dataset.md)
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/dataset-management/lookup-datasets/download-json-file-of-lookup-dataset.md)
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/dataset-management/lookup-datasets/set-time-to-live-for-lookup-datasets.md)
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/dataset-management/lookup-datasets/monitor-datasets-and-dataset-views-activity.md)
- [Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules.md): Learn more about Cortex XDR Parsing Rules.
- [Parsing Rules file structure and syntax](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax.md)
- [INGEST](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest.md)
- [parse\_cef](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cef.md)
- [parse\_cisco](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cisco.md)
- [parse\_json](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_json.md)
- [COLLECT](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/collect.md)
- [CONST](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/const.md)
- [RULE](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/rule.md)
- [Create Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/create-parsing-rules.md)
- [Troubleshooting Parsing rules errors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/troubleshooting-parsing-rules-errors.md)
- [Parsing Rules Raw Dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/parsing-rules/parsing-rules-raw-dataset.md)
- [Manage Event Forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/manage-event-forwarding.md): Save your ingested, parsed data in an external location by exporting your event logs to a temporary GCP storage bucket.
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/manage-compute-units.md): Learn more about managing and tracking your compute units usage for API and Cold Storage XQL queries.
- [Compute units usage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/data-management/manage-compute-units/compute-units-usage.md)
- [Cortex XDR Data Sources and Connectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources.md)
- [What are Cortex XDR data sources and connectors?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/what-are-cortex-xdr-data-sources.md): Learn more about Cortex XDR data sources and connectors with a unified approach to integrations.
- [Complete data source and connector catalog](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/complete-data-source-catalog.md): Learn more about the complete data source and connector catalog available in Cortex XDR.
- [Vendor-specific data sources and connectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/abuseipdb.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/abuseipdb/abuseipdb.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/aiops.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/aiops/aiops.md)
- [Amazon](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon.md)
- [Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/amazon-s3.md)
- [Ingest audit logs from AWS CloudTrail](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/amazon-s3/ingest-audit-logs-from-aws-cloudtrail.md)
- [Ingest network flow logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/amazon-s3/ingest-network-flow-logs-from-amazon-s3.md)
- [Ingest network Route 53 logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/amazon-s3/ingest-network-route-53-logs-from-amazon-s3.md)
- [Create an assumed role](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/amazon-s3/create-an-assumed-role.md)
- [Configure data collection from Amazon S3 manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/amazon-s3/configure-data-collection-from-amazon-s3-manually.md)
- [Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/amazon-web-services.md)
- [AWS Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/amazon/aws-automation-and-collection.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/anomali.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/anomali/anomali.md)
- [API Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/api-security.md)
- [Ingest data for API security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/api-security/ingest-data-for-api-security.md)
- [Ingest AWS API Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-aws-api-gateway.md)
- [Ingest Azure APIM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-azure-apim.md)
- [Ingest Apigee Proxy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-apigee-proxy.md)
- [Ingest Kong](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-kong.md)
- [Ingest F5](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-f5.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/atlassian.md)
- [Atlassian Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/atlassian/atlassian-automation-and-collection.md)
- [BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/beyondtrust-privilege-management-cloud.md)
- [Ingest logs from BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/beyondtrust-privilege-management-cloud/ingest-logs-from-beyondtrust-privilege-management-cloud.md)
- [Box](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/box.md)
- [Ingest logs and data from Box](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/box/ingest-logs-and-data-from-box.md)
- [Check Point](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/check-point.md)
- [Check Point FW1/VPN1](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/check-point/check-point-fw1-vpn1.md)
- [Cisco](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/cisco.md)
- [Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/cisco/cisco-asa-firewalls-and-anyconnect.md)
- [Corelight](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/corelight.md)
- [Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/corelight/corelight-zeek.md)
- [Cribl](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/cribl.md)
- [Cribl connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/cribl/cribl-connector.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/cyberark.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/cyberark/cyberark.md)
- [Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/dropbox.md)
- [Ingest logs and data from Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/dropbox/ingest-logs-and-data-from-dropbox.md)
- [Elastic](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/elastic.md)
- [Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/elastic/elasticsearch-filebeat.md)
- [Ingest logs from Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/elastic/elasticsearch-filebeat/ingest-logs-from-elasticsearch-filebeat.md)
- [Windows DHCP via Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/elastic/windows-dhcp-via-elasticsearch-filebeat.md)
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/elastic/windows-dhcp-via-elasticsearch-filebeat/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md)
- [ElasticSearch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/elastic/elasticsearch.md)
- [Envoy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/envoy.md)
- [Envoy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/envoy/envoy.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/forcepoint.md)
- [Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/forcepoint/forcepoint-dlp.md)
- [Fortinet](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/fortinet.md)
- [Fortinet Fortigate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/fortinet/fortinet-fortigate.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/freshworks.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/freshworks/freshworks.md)
- [Generic](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/generic.md)
- [Generic MCP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/generic/generic-mcp.md)
- [Generic SQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/generic/generic-sql.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/github.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/github/github.md)
- [Google](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google.md)
- [Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google/google-cloud-platform.md)
- [Ingest logs and data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google/google-cloud-platform/ingest-logs-and-data-from-a-gcp-pub-sub.md)
- [Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google/google-kubernetes-engine.md)
- [Ingest logs from Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google/google-kubernetes-engine/ingest-logs-from-google-kubernetes-engine.md)
- [Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google/google-workspace.md)
- [Ingest logs and data from Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google/google-workspace/ingest-logs-and-data-from-google-workspace.md)
- [Google Workspace Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/google/google-workspace/google-workspace-automation-and-collection.md)
- [HTTP log collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/http-log-collector.md)
- [Set up an HTTP log collector to receive logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/http-log-collector/set-up-an-http-log-collector-to-receive-logs.md)
- [IBM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/ibm.md)
- [IBM QRadar](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/ibm/ibm-qradar.md)
- [Intellum](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/intellum.md)
- [Intellum](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/intellum/intellum.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/izoologic.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/izoologic/izoologic.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/koi.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/koi/koi.md)
- [Kubernetes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/kubernetes.md)
- [Onboard the Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/kubernetes/onboard-the-kubernetes-connector.md)
- [What's new in Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/kubernetes/whats-new-in-kubernetes-connector.md)
- [Supported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/kubernetes/supported-kubernetes-distributions.md)
- [LOLBAS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/lolbas.md)
- [LOLBAS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/lolbas/lolbas.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/mail-utilities.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/mail-utilities/mail-utilities.md)
- [Microsoft](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft.md)
- [Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/azure-event-hub.md)
- [Ingest logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/azure-event-hub/ingest-logs-from-microsoft-azure-event-hub.md)
- [Azure Network Watcher](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/azure-network-watcher.md)
- [Ingest network flow logs from Microsoft Azure Network Watcher](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/azure-network-watcher/ingest-network-flow-logs-from-microsoft-azure-network-watcher.md)
- [Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-azure.md)
- [Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-365.md)
- [Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-office-365.md)
- [Ingest logs from Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-office-365/ingest-logs-from-microsoft-office-365.md)
- [Microsoft Office 365 (email)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-office-365-email.md)
- [Ingest logs and data from Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-office-365-email/ingest-logs-and-data-from-microsoft-365.md)
- [Microsoft Active Directory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-active-directory.md)
- [Microsoft Graph](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-graph.md)
- [Microsoft Identity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-identity.md)
- [Microsoft Security Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/microsoft-security-automation-and-collection.md)
- [M365 Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/microsoft/m365-automation-and-collection.md)
- [Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/okta.md)
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/okta/ingest-logs-and-data-from-okta.md)
- [Okta Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/okta/okta-automation-and-collection.md)
- [OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/onelogin.md)
- [Ingest logs and data from OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/onelogin/ingest-logs-and-data-from-onelogin.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/oracle.md)
- [Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/oracle/oracle-cloud-infrastructure.md)
- [PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/pagerduty.md)
- [PagerDuty Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/pagerduty/pagerduty-automation-and-collection.md)
- [Ping Identity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/ping-identity.md)
- [PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/ping-identity/pingfederate.md)
- [PingOne](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/ping-identity/pingone.md)
- [Ingest authentication logs and data from PingOne](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/ping-identity/pingone/ingest-authentication-logs-and-data-from-pingone.md)
- [Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/salesforce.md)
- [Ingest logs and data from Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/salesforce/ingest-logs-and-data-from-salesforce.md)
- [Salesforce connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/salesforce/ingest-and-run-salesforce-automation-and-remediation.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/servicenow.md)
- [ServiceNow Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/servicenow/servicenow-automation-and-collection.md)
- [Slack](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/slack.md)
- [Slack Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/slack/slack-automation-and-collection.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/smb.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/smb/smb.md)
- [Workday](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/workday.md)
- [Ingest report data from Workday](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/workday/ingest-report-data-from-workday.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zendesk.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zendesk/zendesk.md)
- [Zoom](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zoom.md)
- [Zoom](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zoom/zoom.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zscaler.md)
- [Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zscaler/zscaler-internet-access.md)
- [Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zscaler/zscaler-private-access.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/vendor-specific-data-sources/zscaler/zscaler.md)
- [Connectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/connectors.md)
- [Standard data sources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/standard-data-sources.md)
- [Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding.md): Learn about onboarding your cloud service provider to Cortex XDR.
- [Amazon Web Services cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding.md): Follow the AWS onboarding wizard, and Cortex XDR creates a custom authentication template to be deployed in AWS.
- [AWS security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-capabilities-and-deployment-planning.md)
- [AWS resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-resource-inventory.md)
- [AWS security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-model-and-authentication.md)
- [Cortex Cloud and AWS audit log collection architecture](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/cortex-cloud-and-aws-audit-log-collection-architecture.md)
- [Onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/onboard-amazon-web-services.md): Follow the AWS onboarding wizard, and Cortex Cloud creates a custom authentication template to be executed in AWS.
- [Prerequisites for onboarding AWS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/prerequisites-for-onboarding-aws.md): Before you begin onboarding AWS, you must review the following prerequisites.
- [How to onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/how-to-onboard-amazon-web-services.md): Follow the AWS onboarding wizard and Cortex Cloud creates a custom authentication template to be deployed in AWS CloudFormation.
- [Deploy the authentication template in AWS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/deploy-the-authentication-template-in-aws.md): Learn how to deploy the Terraform or CloudFormation authentication template in Amazon Web Services.
- [Post-deployment: Custom (BYOB) and Control Tower audit log collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/post-deployment-custom-byob-audit-log-collection.md)
- [Grant cross-account KMS key access for Control Tower BYOB log collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/grant-cross-account-kms-key-access-for-control-tower-byob-log-collection.md): Learn how to configure cross-account AWS KMS key permissions for Cortex Control Tower BYOB log collection. Step-by-step guide to updating KMS key policies.
- [AWS post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-post-deployment-verification.md): After you have completed the AWS onboarding wizard and you have deployed the authentication template in AWS (using CloudFormation or Terraform), verify that the deployment succeeded.
- [Microsoft Azure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding.md)
- [Onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Prerequisites for onboarding Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/prerequisites-for-onboarding-azure.md): Before you begin onboarding Microsoft Azure, you must review the following prerequisites.
- [How to onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Finalize Microsoft Azure onboarding by executing the authentication template](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/finalize-microsoft-azure-onboarding-by-executing-the-authentication-template.md): Learn how to execute the authentication template file in Microsoft Azure for subscriptions, tenants, and management groups. We provide instructions both for applying the Terraform template's configura
- [Microsoft Azure offboarding overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview.md): This section contains the technical procedures required to safely decommission and offboard your Cortex Cloud resources in Microsoft Azure.
- [Offboard Terraform-based Azure deployments (all scopes)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-terraform-based-azure-deployments-all-scopes.md): How to offboard all Terraform-based Microsoft Azure scopes from Cortex Cloud: A step-by-step technical guide to safely running Terraform destroy and cleaning up policy-deployed resources.
- [Offboard Azure subscription (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-subscription-arm.md): How to offboard a Microsoft Azure subscription scope that was onboarded using ARM: A step-by-step technical guide to safely running the interactive offboarding script and cleaning up all resources.
- [Offboard Azure management group or tenant scope (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-management-group-or-tenant-scope-arm.md): How to offboard Microsoft Azure management group or tenant scopes from Cortex Cloud: A step-by-step technical guide to safely removing all Azure resources deployed by Cortex onboarding templates.
- [Offboard Azure tenant with Entra ID only](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-tenant-with-entra-id-only.md): How to offboard a Microsoft Azure tenant onboarded with the Entra ID only option from Cortex Cloud: A step-by-step technical guide to safely removing deployed resources.
- [Google Cloud Platform cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding.md)
- [Onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex creates a custom authentication template to be executed in GCP.
- [Prerequisites for onboarding GCP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/prerequisites-for-onboarding-gcp.md): Before you begin onboarding GCP, you must review the following prerequisites.
- [How to onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex Cloud creates a custom authentication template to be applied in GCP.
- [Deploy the Terraform authentication template in GCP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/deploy-the-terraform-authentication-template-in-gcp.md): Learn how to deploy the Terraform authentication template in Google Cloud Console.
- [Connect Google Workspace with your GCP cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/connect-google-workspace-with-your-gcp-cloud-instance.md)
- [Monitor GCP resources inside service perimeters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/monitor-gcp-resources-inside-service-perimeters.md): Learn how to grant authorization to Cortex Cloud to scan within your GCP service perimeter.
- [Oracle Cloud Infrastructure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding.md): Follow the Oracle Cloud Infrastructure onboarding wizard and Cortex Cloud creates a custom Terraform authentication template to be deployed in Oracle Cloud Infrastructure.
- [Onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard, and Cortex creates a custom authentication template to be executed in OCI.
- [Prerequisites for onboarding OCI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/prerequisites-for-onboarding-oci.md): Before you begin onboarding Oracle Cloud Infrastructure, you must review the following prerequisites.
- [How to onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/how-to-onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard and Cortex Cloud creates a custom authentication template to be applied in OCI.
- [Deploy the Terraform authentication template in OCI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/deploy-the-terraform-authentication-template-in-oci.md): Learn how to deploy the Terraform authentication template in Oracle Cloud Infrastructure.
- [Alibaba Cloud cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding.md): Follow the Alibaba Cloud onboarding wizard and Cortex Cloud creates a custom Terraform authentication template to be deployed in Alibaba Cloud.
- [Alibaba security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-security-capabilities-and-deployment-planning.md)
- [Alibaba Cloud resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-resource-inventory.md)
- [Alibaba Cloud security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-security-model-and-authentication.md)
- [Onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/onboard-alibaba-cloud.md): Follow the Alibaba Cloud onboarding wizard and Cortex Cloud creates a custom CloudFormation authentication template to be deployed in Alibaba Cloud.
- [Prerequisites for onboarding Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/prerequisites-for-onboarding-alibaba-cloud.md): Before you begin onboarding Alibaba Cloud, you must review the following prerequisites.
- [How to onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/how-to-onboard-alibaba-cloud.md)
- [Alibaba Cloud post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-post-deployment-verification.md): After you have completed the Alibaba Cloud onboarding wizard and you have deployed the authentication template in Alibaba Cloud, verify that the deployment succeeded.
- [Outpost onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding.md): Learn about outposts, which are a dedicated set of infrastructure resources that extends the reach of Cortex XDR into your environment.
- [Outpost fundamentals and planning](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-fundamentals-and-planning.md): An outpost enables you to have security scans performed on infrastructure in a cloud account owned by you. Learn about outpost fundamentals and what to consider when planning your outpost.
- [Outpost creation workflow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-creation-workflow.md): Learn about the creation process for an outposts, which facilitate security scanning performed on infrastructure in a cloud account owned by you.
- [Working with standard outposts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts.md): Standard outposts are the recommended way to create dedicated set of infrastructure resources that extends the reach of Cortex XDR into your environment.
- [Create a standard outpost](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts/create-a-standard-outpost.md): Instructions for creating a standard outpost while onboarding your CSP.
- [Working with Bringing your own Azure app (BYOA) outposts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts.md): Using advanced settings while creating your outpost, you can deploy a Cortex XDR Azure outpost using your own pre-created Entra ID app registration.
- [Task 1: Meet the prerequisites for Azure BYOA outposts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-1-meet-the-prerequisites-for-azure-byoa-outposts.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page lists the prerequisites that must be met before customizing your outpost in this way.
- [Task 2: Create the app registration for the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-2-create-the-app-registration-for-the-azure-byoa-outpost.md): You can customize your own outpost for Azure by bringing your own app (BYOA). This page describes the steps for creating the app registration.
- [Task 3: Deploy the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-3-deploy-the-azure-byoa-outpost.md): You can customize your own outpost by bringing your own app (BYOA). This page describes the steps for deploying the Azure BYOA outpost.
- [Task 4: Verify the BYOA outpost deployment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-4-verify-the-byoa-outpost-deployment.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page describes the steps for verifying your BYOA outpost deployment.
- [The shell script for Azure app registration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/the-shell-script-for-azure-app-registration.md): You can run this helper shell script to set up your resources and retrieve their IDs for use while creating your Azure BYOA outpost. This page provides technical, "read-me style" details about the scr
- [Outpost troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-troubleshooting.md): Check here for solutions to issues that might occur while configuring, deploying, and operating outposts.
- [Outpost Cloud Service Provider (CSP) permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions.md): This page lists and explains the various roles and permissions needed for working with resources for outposts by CSP.
- [Amazon Web Services (AWS) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/amazon-web-services-aws-outpost-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex XDR outpost onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/microsoft-azure-outpost-permissions.md): List of Microsoft Azure provider outpost permissions for Cortex XDR.
- [Google Cloud Platform (GCP) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/google-cloud-platform-gcp-outpost-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex XDR onboarding outposts to enable continuous monitoring in your cloud environment.
- [Introduction to Terraform for Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/introduction-to-terraform-for-cloud-service-provider-csp-onboarding.md): Learn how to onboard Cloud Service Providers (CSPs) using Terraform. Discover step-by-step workflows for initial provisioning, updates, and Cloud Shell deployment.
- [Manually connect a cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/manually-connect-a-cloud-instance.md)
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/manage-cloud-instances.md): Learn how to manage, edit, and troubleshoot cloud instances in Cortex Cloud. Monitor connector health, view security capabilities, and investigate errors.
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/pending-cloud-instances.md)
- [Edit your onboarded CSP configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/edit-your-onboarded-csp-configuration.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/update-cloud-permissions-after-cortex-release-updates.md): Manage permission updates for your cloud instances following new feature releases or bug fixes.
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/troubleshoot-errors-on-cloud-instances.md): You can troubleshoot errors on cloud instances by drilling down on an instance from the Data Sources & Integrations page.
- [Cloud service provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions.md): Grant the correct cloud service provider permissions for Cortex XDR.
- [Amazon Web Services (AWS) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/amazon-web-services-aws-provider-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex XDR onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/microsoft-azure-provider-permissions.md): List of Microsoft Azure provider permissions for Cortex XDR.
- [Google Cloud Platform (GCP) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/google-cloud-platform-gcp-provider-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex XDR onboarding to enable continuous monitoring in your cloud environment.
- [Oracle Cloud Infrastructure (OCI) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/oracle-cloud-infrastructure-oci-provider-permissions.md): List of Oracle Cloud Infrastructure provider permissions for Cortex XDR.
- [Generic on-premise data collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets.md)
- [Activate Apache Kafka Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-apache-kafka-collector.md)
- [Activate Cortex Network Scanner](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-cortex-network-scanner.md)
- [Activate CSV Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-csv-collector.md)
- [Activate Database Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-database-collector.md)
- [Activate DSPM Fileshare](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-fileshare.md)
- [Activate Files and Folders Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-files-and-folders-collector.md)
- [Activate FTP Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-ftp-collector.md)
- [Activate Local Agent Settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-local-agent-settings.md)
- [Activate NetFlow Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-netflow-collector.md)
- [Activate Network Mapper](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-network-mapper.md)
- [Activate Registry Scanner](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-registry-scanner.md)
- [Syslog Collector applet](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet.md)
- [Activate Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/activate-syslog-collector.md)
- [Ingest logs from a Syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/ingest-logs-from-a-syslog-receiver.md): To extend visibility, Cortex XDR can receive Syslog from additional vendors that use CEF or LEEF formatted over Syslog (TLS not supported).
- [Check Point FW1 VPN1](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1.md)
- [Ingest logs from Check Point firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1/ingest-logs-from-check-point-firewalls.md)
- [Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect.md)
- [Ingest logs from Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect/ingest-logs-from-cisco-asa-firewalls-and-anyconnect.md)
- [Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/corelight-zeek.md)
- [Ingest logs from Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/corelight-zeek/ingest-logs-from-corelight-zeek.md)
- [Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/forcepoint-dlp.md)
- [Ingest logs from Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/forcepoint-dlp/ingest-logs-from-forcepoint-dlp.md)
- [Fortinet Fortigate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/fortinet-fortigate.md)
- [Ingest logs from Fortinet Fortigate firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/fortinet-fortigate/ingest-logs-from-fortinet-fortigate-firewalls.md)
- [Next Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/next-generation-firewall.md)
- [Ingest Next-Generation Firewall logs using the Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md)
- [PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/pingfederate.md)
- [Ingest authentication logs from PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/pingfederate/ingest-authentication-logs-from-pingfederate.md)
- [Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access.md)
- [Ingest logs from Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access/ingest-logs-from-zscaler-internet-access.md)
- [Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-private-access.md)
- [Ingest logs from Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-private-access/ingest-logs-from-zscaler-private-access.md)
- [Activate Transporter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter.md)
- [Activate Windows Event Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector.md)
- [Activate Windows Event Collector on Windows Core](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector/activate-windows-event-collector-on-windows-core.md)
- [Renew WEC certificates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector/renew-wec-certificates.md)
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors.md)
- [XDR Collector audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-audit-logs.md)
- [XDR Collector machine requirements and supported operating systems](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-machine-requirements-and-supported-operating-systems.md)
- [Resources required to enable access to XDR collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/resources-required-to-enable-access-to-xdr-collectors.md)
- [Manage XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors.md)
- [XDR Collectors installation resource for Windows and Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/xdr-collectors-installation-resource-for-windows-and-linux.md)
- [Create an XDR Collector installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/create-an-xdr-collector-installation-package.md)
- [Install the XDR Collector installation package for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows.md)
- [Install the XDR collector on Windows using the MSI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-the-msi.md)
- [Install the XDR Collector on Windows using Msiexec](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-msiexec.md)
- [Install the XDR Collector installation package for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-linux.md)
- [Configure XDR Collector upgrade scheduler](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/configure-xdr-collector-upgrade-scheduler.md)
- [Set an application proxy for XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/set-an-application-proxy-for-xdr-collectors.md)
- [Set an alias for an XDR Collector machine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/set-an-alias-for-an-xdr-collector-machine.md)
- [Upgrade XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/upgrade-xdr-collectors.md)
- [Uninstall the XDR Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/uninstall-the-xdr-collector.md)
- [Define XDR Collector machine groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/define-xdr-collector-machine-groups.md)
- [About Cortex XDR Collector content updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/about-cortex-xdr-collector-content-updates.md)
- [XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles.md)
- [Add an XDR Collector profile for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows.md)
- [How to configure XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/how-to-configure-xdr-collector-profiles.md)
- [Additional XDR Collector profile management options](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/additional-xdr-collector-profile-management-options.md)
- [Query Windows Event Log records](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/query-windows-event-log-records.md)
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md)
- [Ingest Windows DNS debug logs using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/ingest-windows-dns-debug-logs-using-elasticsearch-filebeat.md)
- [Add an XDR Collector profile for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-linux.md)
- [Apply profiles to collection machine policies](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/apply-profiles-to-collection-machine-policies.md)
- [XDR Collector datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-datasets.md)
- [Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations.md)
- [Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/cloud-next-generation-firewall.md)
- [Ingest data from Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/cloud-next-generation-firewall/ingest-data-from-cloud-next-generation-firewall.md)
- [Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/next-generation-firewall.md)
- [Ingest data from Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-data-from-next-generation-firewall.md)
- [Ingest Next-Generation Firewall logs using the Syslog collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md)
- [Panorama](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/next-generation-firewall/panorama.md)
- [Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/prisma-access.md)
- [Ingest data from Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/prisma-access/ingest-data-from-prisma-access.md)
- [Palo Alto Networks Prisma](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/prisma-access/palo-alto-networks-prisma.md)
- [Prisma Access Browser](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/prisma-access-browser.md)
- [Ingest logs from Prisma Access Browser](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/prisma-access-browser/ingest-logs-from-prisma-access-browser.md)
- [Prisma Browser Integration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/prisma-browser-integration.md)
- [Ingest detection data from Strata Logging Service](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/ingest-detection-data-from-strata-logging-service.md)
- [IoT Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/iot-security.md)
- [Ingest alerts and assets from IoT Security (Deprecated)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/iot-security/ingest-alerts-and-assets-from-iot-security.md)
- [Ingest alerts and assets from Device Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/iot-security/ingest-alerts-and-assets-from-device-security.md)
- [Cortex Internals](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/cortex-internals.md)
- [Enterprise DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/enterprise-dlp.md)
- [Palo Alto Networks Cortex](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/palo-alto-networks-cortex.md)
- [SaaS Security (Aperture)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/saas-security-aperture.md)
- [WildFire Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/wildfire-cloud.md)
- [Log type filtering](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/log-type-filtering.md)
- [Collecting URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/collecting-url-and-file-log-types.md)
- [Detectors connected to URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/palo-alto-networks-integrations/collecting-url-and-file-log-types/detectors-connected-to-url-and-file-log-types.md)
- [Cloud Posture and Runtime Security data sources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources.md): Learn more about the Cloud Posture and Runtime Security data sources in Cortex XSIAM.
- [How to onboard on-premise assets to Cloud Data Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-on-premise-assets-to-cloud-data-security.md)
- [Activate DSPM Fileshare](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-on-premise-assets-to-cloud-data-security/activate-dspm-fileshare.md): Activate the DSPM Fileshare applet on a Broker VM.
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-databricks.md): Add Databricks as a Cortex Cloud Data Security data source.
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-microsoft-365.md): Add Microsoft 365 as a Cortex Cloud Data Security data source.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/ingest-logs-and-data-from-okta.md): Configure Okta log and configuration data ingestion.
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/how-to-onboard-snowflake.md): Add Snowflake as a Cortex Cloud Data Security data source.
- [Activate AppSec Transporter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/activate-appsec-transporter.md)
- [Container Registry Scanning](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning.md)
- [Registry Components](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/registry-components.md)
- [How Container Registry Scanning Works](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/how-container-registry-scanning-works.md)
- [Configure registry scanning for cloud accounts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/configure-registry-scanning-for-cloud-accounts.md)
- [Modify the container registry scanning scope](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/modify-the-container-registry-scanning-scope.md)
- [Scan re-evaluation process](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/scan-re-evaluation-process.md)
- [Connect Docker Hub registry](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry.md)
- [Manage a Docker Hub connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry/manage-a-docker-hub-connector.md)
- [Connect Docker V2 compliant container registry](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry.md)
- [Manage a Docker V2 connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry/manage-a-docker-v2-connector.md)
- [Connect GitLab container registry](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry.md)
- [Manage a GitLab Container Registry connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry/manage-a-gitlab-container-registry-connector.md)
- [Connect Harbor registry](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry.md)
- [Manage a Harbor connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry/manage-a-harbor-connector.md)
- [Connect JFrog container registry](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry.md)
- [Manage a JFrog connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry/manage-a-jfrog-connector.md)
- [Connect Sonatype Nexus registry](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry.md)
- [Manage a Sonatype connector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry/manage-a-sonatype-connector.md)
- [Administration and troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting.md): Learn more about the administration and troubleshooting of the different data collector integrations in Cortex XDR.
- [Manage instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances.md)
- [Add a new data source or instance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances/add-a-new-data-source-or-instance.md)
- [How to configure the scanning settings for supported services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances/how-to-configure-the-scanning-settings-for-supported-services.md)
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances/manage-cloud-instances.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances/update-cloud-permissions-after-cortex-release-updates.md)
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances/pending-cloud-instances.md)
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances/troubleshoot-errors-on-cloud-instances.md)
- [Manage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/manage-instances/manage-kubernetes-connector-instances.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/integrations.md)
- [Integrations in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/integrations/integrations-in-cortex-xdr.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/integrations/add-an-integration-instance.md)
- [Use integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/integrations/use-integration-commands-in-the-cli.md)
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/integrations/configure-integration-permissions.md)
- [Troubleshoot Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/integrations/troubleshoot-integrations.md)
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/integrations/manage-credentials.md)
- [Verify collector connectivity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/verify-collector-connectivity.md)
- [Overview of data ingestion metrics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics.md)
- [Creating correlation rules to monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics/creating-correlation-rules-to-monitor-data-ingestion-health.md)
- [Measuring data freshness](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics/measuring-data-freshness.md)
- [About health issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/about-health-issues.md)
- [Investigate and resolve health issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/about-health-issues/investigate-and-resolve-health-issues.md)
- [Monitor data ingestion health (BETA)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/about-health-issues/monitor-data-ingestion-health.md)
- [Monitor Correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/cortex-xdr-data-sources/administration-and-troubleshooting/about-health-issues/monitor-correlation-rules.md)
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/marketplace.md): Use the Marketplace, a centralized content portal, to manage content packs in Cortex XDR.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/marketplace/content-pack-support-types.md): Types of content packs support - Cortex supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Cortex XDR content](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/marketplace/cortex-xdr-content.md): The type of content in Cortex XDR
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/marketplace/marketplace-faqs.md): Frequently Asked Questions about Cortex XDR Marketplace Content
- [Content changes when upgrading Cortex XDR versions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/marketplace/content-changes-when-upgrading-cortex-xdr-versions.md): Content updates when upgrading Cortex XDR versions.
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/manage-api-keys.md)
- [XQL query management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/xql-query-management.md): Administrators can set controls on running XQL queries.
- [Customize cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues.md)
- [External integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/external-integrations.md): Integrate external threat intelligence and case management services with Cortex XDR.
- [Set up case scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/set-up-case-scoring.md): Enable SmartScore and configure scoring rules for cases and issues.
- [Create a starring configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-a-starring-configuration.md): Create rules that automatically star matching issues and their linked cases.
- [Create SLAs for case and issue resolution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-slas-for-issue-resolution.md): Create SLA rules to set and track issue-resolution timers and time goals.
- [Create additional case timers and SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas.md)
- [Update case timer and SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas/update-case-timer-and-sla-fields.md)
- [Create issue exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-issue-exceptions.md): Create time-bound exceptions that pause issue SLA timers during approved remediation delays.
- [Configure the issue exception approval workflow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-issue-exceptions/configure-the-issue-exception-approval-workflow.md): Manage approvers and approval requirements for issue exception rules.
- [Create issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-issue-exceptions/create-issue-exception-rules.md): Create approval-based rules that temporarily pause SLA timers for selected issues.
- [Create an exception rule from an issue](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-issue-exceptions/create-an-exception-rule-from-an-issue.md)
- [View issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-issue-exceptions/view-issue-exception-rules.md)
- [Disable issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-issue-exceptions/disable-issue-exception-rules.md)
- [View excepted issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/create-issue-exceptions/view-excepted-issues.md)
- [Optimize case grouping in correlations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/customize-cases-and-issues/optimize-case-grouping-in-correlations.md)
- [Managed Services configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/managed-services-configuration.md)
- [Configure report forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/managed-services-configuration/configure-report-forwarding.md)
- [Configure actions permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/managed-services-configuration/configure-actions-permissions.md)
- [Manage escalation contacts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/configure-cortex-xdr/managed-services-configuration/manage-escalation-contacts.md)
- [Endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection.md)
- [Malware protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/malware-protection.md)
- [Exploit protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/exploit-protection.md)
- [File analysis and protection flow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/file-analysis-and-protection-flow.md)
- [Endpoint protection capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/endpoint-protection-capabilities.md)
- [Processes protected by exploit security policy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/processes-protected-by-exploit-security-policy.md)
- [File Integrity Monitoring (FIM)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/file-integrity-monitoring-fim.md)
- [CaaS Workloads](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/caas-workloads.md)
- [WildFire analysis concepts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/wildfire-analysis-concepts.md)
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md)
- [About content updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/about-content-updates.md)
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/endpoint-data-collection.md)
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/endpoint-data-collection/endpoint-data-collection-1.md)
- [Install and manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints.md): Learn how to set up profiles, policies and other settings for endpoint protection, how to install Cortex XDR agent on endpoints, and how to manage them after installation.
- [Set up endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection.md)
- [Set up endpoint profiles and exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules.md)
- [Set up malware prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md)
- [Set up exploit prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md)
- [Set up agent settings profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md)
- [Set up restrictions prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-restrictions-prevention-profiles.md)
- [Set up exception profiles and rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules.md)
- [Exception configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/exception-configuration.md)
- [Issue exclusions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions.md)
- [Add an issue exclusion rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions/add-an-issue-exclusion-rule.md)
- [Add an IOC or BIOC rule exception](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-an-ioc-or-bioc-rule-exception.md)
- [Add a disable prevention rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-prevention-rule-for-endpoints.md)
- [Add a disable injection and prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-injection-and-prevention-rule.md)
- [Add a support exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-support-exception-rule-for-endpoints.md)
- [Add a legacy exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints.md)
- [Add a new exceptions security profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-new-exceptions-security-profile.md)
- [Add a global endpoint policy exception](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-global-endpoint-policy-exception.md)
- [Set up Identity profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-identity-profiles.md): Configure the Identity Profile to unify AD-SPM, Conditional Access, and LDAP Protection controls in one centralized hub.
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/define-endpoint-groups.md)
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/configure-global-agent-settings.md)
- [Apply profiles to endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/apply-profiles-to-endpoints.md)
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package.md)
- [Manage an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package/manage-an-agent-installation-package.md)
- [Harden endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security.md)
- [Device control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/device-control.md)
- [Host firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/host-firewall.md)
- [Host firewall for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-windows.md)
- [Host firewall for macos](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-macos.md)
- [Disk encryption](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/disk-encryption.md)
- [Host Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/host-inventory.md)
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/vulnerability-assessment.md)
- [Set a Cortex XDR agent Critical Environment version](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/harden-endpoint-security/set-a-cortex-dr-agent-critical-environment-version.md)
- [Manage endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection.md)
- [Move agents between managing servers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/move-agents-between-managing-servers.md)
- [Manage endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags.md)
- [Create an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/create-an-endpoint-tag.md)
- [Remove an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/remove-an-endpoint-tag.md)
- [Track your endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/track-your-endpoint-tags.md)
- [Permanently remove Endpoint tags from the system](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/permanently-remove-endpoint-tags-from-the-system.md)
- [Set an alias for an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/set-an-alias-for-an-endpoint.md)
- [Manage endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-prevention-profiles.md)
- [Create a new prevention policy rule for serverless function](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/create-a-new-prevention-policy-rule-for-serverless-function.md)
- [View information about your endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/view-information-about-your-endpoint-prevention-profiles.md)
- [Upgrade Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/upgrade-cortex-xdr-agents.md)
- [Restart agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/restart-agent.md)
- [Uninstall the Cortex XDR agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/uninstall-the-cortex-xdr-agent.md)
- [Clear agent database](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/clear-agent-database.md)
- [Delete Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/delete-cortex-xdr-agents.md)
- [Manage agent tokens](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/manage-agent-tokens.md)
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/retrieve-support-file-password.md)
- [Send push notifications to iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/send-push-notifications-to-ios.md)
- [Monitor agent operational status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-operational-status.md)
- [Monitor agent activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md)
- [Monitor agent upgrade status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-upgrade-status.md)
- [Web and API Security (WAAS)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/web-and-api-security-waas.md)
- [Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/web-and-api-security-waas/overview.md)
- [Personas workflow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/web-and-api-security-waas/personas-workflow.md): Cortex API security distributes responsibilities across SOC analysts, security practitioners, and workload owners.
- [Secure your API landscape](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/web-and-api-security-waas/secure-your-api-landscape.md)
- [Endpoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp.md)
- [Cortex Data Loss Prevention (DLP) module overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview.md): Learn about Cortex Data Loss Prevention (DLP) module, which provides a solution to prevent sensitive data exfiltration.
- [Archive file classification](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/archive-file-classification.md)
- [True-file type detection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/true-file-type-detection.md)
- [Personas workflow for DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/personas-workflow-for-dlp.md): The data security administrator and data security viewer are responsible for identifying DLP requirements for creating data-in-motion rules and investigating issues and cases.
- [Best Practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/best-practices.md)
- [Configure DLP end-to-end](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/configure-dlp-end-to-end.md)
- [DLP status in all endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/dlp-status-in-all-endpoints.md)
- [Cortex DLP threat detection and issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-dlp/cortex-dlp-threat-detection-and-issues.md)
- [Monitor dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports.md)
- [Overview of dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports.md)
- [Dashboard interface basics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basics.md)
- [Dashboard types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-types.md)
- [Report basics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/report-basics.md)
- [Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/widget-library.md)
- [Access and visibility for dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports.md)
- [Visibility settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settings.md)
- [Access to widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgets.md)
- [Sharing icons](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-icons.md)
- [Access and sharing cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-and-sharing-cheat-sheet.md)
- [Manage dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports.md)
- [Dashboard Manager](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/dashboard-manager.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/reports.md)
- [Duplicate dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reports.md)
- [Share custom dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templates.md)
- [Change ownership to dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templates.md)
- [Import and export dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templates.md)
- [Configure the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-report.md)
- [Deleted content](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/deleted-content.md)
- [Create dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards.md)
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards/create-a-dashboard.md)
- [Create reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports.md)
- [Create a report template from scratch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports/create-a-report-template-from-scratch.md)
- [Advanced configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration.md)
- [Create custom widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets.md)
- [Create widgets using AI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-ai.md)
- [Create XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets.md)
- [Add parameters to a custom XQL widget](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widget.md)
- [Create script-based widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgets.md)
- [Configure global filters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-global-filters.md)
- [Configure drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-drilldowns.md)
- [Dashboard reference](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference.md)
- [Command Center reference](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference.md)
- [Cloud Detection and Response (CDR) Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cloud-detection-and-response-cdr-command-center.md)
- [Cortex Cloud Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-cloud-command-center.md)
- [System dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md)
- [Cloud Security Operations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cloud-security-operations.md)
- [Data Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/data-ingestion.md)
- [Asset management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management.md)
- [Asset inventory overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-inventory-overview.md): Learn about the core concepts, features, and lifecycle of assets within the Asset Inventory.
- [All assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/all-assets.md): Learn about the All Assets page, under Asset Inventory.
- [All cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets.md): Learn about the All Cloud Assets page to view and assess your cloud footprint.
- [Discovery Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets/discovery-engine.md)
- [Asset hierarchy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/all-cloud-assets/asset-hierarchy.md)
- [Asset classes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes.md): Accelerating remediation: Automated fix suggestions and manual remediation guidance enable developers to resolve code weaknesses directly in the source repository without context-switching to external
- [AI assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/ai-assets.md)
- [API assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/api-assets.md)
- [Application assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/application-assets.md)
- [Code and Supply Chain Security assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/code-and-ci-cd-assets.md)
- [Compute assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets.md)
- [Container image assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/container-image-assets.md)
- [Serverless functions assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/serverless-functions-assets.md)
- [VM images assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/compute-assets/vm-images-assets.md)
- [Data assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/data-assets.md)
- [Device assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/device-assets.md)
- [External Surface assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets.md)
- [Identity assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/identity-assets.md)
- [Network assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/network-assets.md)
- [Security services assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes/security-services-assets.md)
- [Asset groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-groups.md): Group assets based on shared attributes to address them collectively, simplify filtering, and enable strict access control boundaries.
- [Manage Risk Scores](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/manage-asset-scores.md): View and investigate User Scores and Host Scores using the Risk Scores page to identify high-risk assets and detect compromised accounts or malicious activities.
- [Asset configurations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-configurations.md)
- [Network configurations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/network-configuration.md): Configure your internal network parameters, trusted networks, and external IP ranges to help Cortex XDR identify and map your network assets.
- [Application criteria](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/application-criteria.md)
- [Asset Roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles.md): View asset roles and the number of assets that are associated with each role. Learn how to manage asset roles for users and endpoints.
- [Manage Asset Roles for Endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-endpoints.md)
- [Manage Asset Roles for Users](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-users.md)
- [Honey user](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-configurations/asset-roles/manage-asset-roles-for-users/honey-user.md)
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/vulnerability-assessment.md): Perform a vulnerability assessment of all endpoints in your network using Cortex XDR. This includes CVE, endpoint, and application analysis.
- [Investigate and respond to cases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases.md)
- [Overview of cases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases.md): Understand how cases work in Cortex XDR.
- [What are cases?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases/what-are-cases.md)
- [Resolving cases with AI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases/resolving-cases-with-ai.md)
- [Case lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases/case-lifecycle.md)
- [Case thresholds](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases/case-thresholds.md)
- [Case scope and impact](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases/case-scope-and-impact.md)
- [Case and issue domains](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases/case-and-issue-domains.md)
- [Overview of case teams and roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/overview-of-cases/overview-of-case-teams-and-roles.md)
- [Case concepts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/case-concepts.md)
- [Issues, findings, and events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/case-concepts/issues-findings-and-events.md)
- [Case grouping](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/case-concepts/case-grouping.md)
- [Case scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/case-concepts/case-scoring.md)
- [Case starring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/case-concepts/case-starring.md)
- [What is Causality?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/case-concepts/what-is-causality.md)
- [Analyze and resolve cases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases.md): Learn how to analyze and resolve cases.
- [Review all cases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/review-all-cases.md): Monitor and prioritize cases across your environment.
- [Start case analysis](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/start-case-analysis.md): Open a case and begin an investigation.
- [Establish Case context](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/establish-case-context.md): Establish the case context before deeper analysis.
- [AI-generated case summaries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/establish-case-context/ai-generated-case-summaries.md)
- [Assess case severity and score](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/establish-case-context/assess-case-severity-and-score.md)
- [Update case attributes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/establish-case-context/update-case-attributes.md)
- [Analyze case details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details.md): Investigate case evidence, relationships, and activity.
- [Grouping graph](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/grouping-graph.md)
- [Evidence](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/evidence.md)
- [Issue feed](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/issue-feed.md)
- [Associated assets and artifacts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/associated-assets-and-artifacts.md)
- [MITRE ATT\&CK tactics and techniques](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/mitre-att-and-ck-tactics-and-techniques.md)
- [Compliance standards and controls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/compliance-standards-and-controls.md)
- [Case timeline](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/case-timeline.md)
- [Detailed View](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/analyze-case-details/detailed-view.md)
- [Resolve the case](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/resolve-the-case.md): Remediate findings and close the case.
- [Resolution Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/resolve-the-case/resolution-center.md)
- [Collaborative notes and comments](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/resolve-the-case/collaborative-notes-and-comments.md)
- [How to resolve a case](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/resolve-the-case/resolve-a-case.md)
- [Resolution reasons for cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/resolve-the-case/resolution-reasons-for-cases-and-issues.md)
- [Monitor and track resolution times](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/resolve-the-case/monitor-and-track-resolution-times.md)
- [Use Cortex Agentic Assistant chat in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/use-cortex-agentic-assistant-chat-in-an-investigation.md): Use Agentic Assistant chat during an investigation.
- [Additional case actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/additional-case-actions.md)
- [Create a case](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/additional-case-actions/create-a-case.md)
- [Merge a case](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/additional-case-actions/merge-a-case.md)
- [Assign a case team and restrict access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access.md)
- [Playbook examples](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access/playbook-examples.md)
- [Unified case view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/analyze-and-resolve-cases/additional-case-actions/unified-case-view.md)
- [Investigate issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues.md): Cortex XDR generates issues to bring your attention to security risks in your framework.
- [Overview of the Issues page](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/overview-of-the-issues-page.md)
- [Issue card](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-card.md)
- [Resolution actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/resolution-actions.md)
- [Link or unlink issues from a case](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/link-or-unlink-issues-from-a-case.md)
- [Run an automation on an issue](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/run-an-automation-on-an-issue.md)
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/use-the-war-room-in-an-investigation.md)
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/use-the-work-plan-in-an-investigation.md)
- [Issue deduplication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-deduplication.md)
- [Causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view.md)
- [Network causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/network-causality-view.md)
- [Cloud causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/cloud-causality-view.md)
- [Cloud causality view for audit log issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/cloud-causality-view-for-audit-log-issues.md): Investigate cloud attacks faster with entity context directly in the Cloud causality view.
- [Saas causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/saas-causality-view.md)
- [Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/timeline.md)
- [Causality icons key](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/causality-view/causality-icons-key.md)
- [Issue investigation actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions.md)
- [Copy issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/copy-issues.md)
- [Analyze an issue](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/analyze-an-issue.md)
- [Create profile exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/create-profile-exceptions.md)
- [Retrieve additional issue details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/retrieve-additional-issue-details.md)
- [Add a file path to a malware profile allow list](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/add-a-file-path-to-a-malware-profile-allow-list.md)
- [Investigate contributing events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/investigate-contributing-events.md)
- [Create a featured field](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/create-a-featured-field.md)
- [View generating BIOC or IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/view-generating-bioc-or-ioc-rule.md)
- [Export issue details to a file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/export-issue-details-to-a-file.md)
- [Exclude an issue](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/exclude-an-issue.md)
- [Query case and issue data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md)
- [Update issue fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/update-issue-fields.md)
- [Close an issue](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/close-an-issue.md)
- [Review findings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/review-findings.md): Review findings for an asset to gain insights into an asset’s posture status.
- [Findings card](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/review-findings/findings-card.md)
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-artifacts-and-assets.md): You can investigate specific artifacts and assets on dedicated views related to IP address, Network Assets, and File and Process Hash information.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-artifacts-and-assets/investigate-an-ip-address.md)
- [Investigate an asset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-artifacts-and-assets/investigate-an-asset.md)
- [Investigate a host](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-artifacts-and-assets/investigate-a-host.md)
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md)
- [Investigate a user](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-artifacts-and-assets/investigate-a-user.md)
- [Investigate endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints.md): You can investigate and take actions on your endpoints in the Action Center.
- [Overview of the Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/overview-of-the-action-center.md)
- [Initiate and monitor endpoint actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/overview-of-the-action-center/initiate-and-monitor-endpoint-actions.md)
- [Action Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/overview-of-the-action-center/action-center-reference-information.md)
- [Manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/manage-endpoints.md)
- [Retrieve files from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/retrieve-files-from-an-endpoint.md)
- [Retrieve support logs from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/retrieve-support-logs-from-an-endpoint.md)
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/retrieve-support-file-password.md)
- [Scan an endpoint for malware](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-endpoints/scan-an-endpoint-for-malware.md)
- [Investigate files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-files.md)
- [Manage file execution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-files/manage-file-execution.md)
- [Manage quarantined files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-files/manage-quarantined-files.md)
- [Review WildFire analysis details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-files/review-wildfire-analysis-details.md)
- [Import file hash exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-files/import-file-hash-exceptions.md)
- [Automation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation.md)
- [Quick Actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/quick-actions.md)
- [Automation Exclusion Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/automation-exclusion-center.md)
- [Manage automation exclusion policies](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/manage-automation-exclusion-policies.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks.md)
- [Playbooks overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/playbooks-overview.md)
- [Access to playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/access-to-playbooks.md)
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/playbook-development-checklist.md)
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/plan-your-playbook.md)
- [Manage playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/manage-playbooks.md)
- [Build your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook.md)
- [Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/choose-from-existing-playbooks-or-create-your-own.md)
- [Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/configure-playbook-settings.md)
- [Add objects from the Task Library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library.md)
- [Add commands and scripts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-commands-and-scripts.md)
- [Add sub-playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-sub-playbooks.md)
- [Add AI Prompt tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-ai-prompt-tasks.md)
- [Add manual tasks and blank tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks.md): Add manual and blank tasks to a playbook.
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-standard-task.md): Define a Standard task in Cortex XDR.
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-conditional-task.md): Create a Conditional task in a playbook.
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-communication-task.md): Communication tasks let you send surveys and collect issue data.
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/create-a-section-header.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/configure-script-error-handling-in-a-playbook.md)
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook.md)
- [Configure a sub-playbook loop](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/configure-a-sub-playbook-loop.md)
- [Filter and Transform data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/filter-and-transform-data.md)
- [Create custom filter and transformers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/create-custom-filter-and-transformers.md)
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/filter-considerations-categories-and-built-in-filters.md)
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/transformer-considerations-categories-and-built-in-transformers.md)
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/extend-context.md)
- [Extract Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/extract-indicators.md)
- [Update issue fields with playbook tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/customize-your-playbook/update-issue-fields-with-playbook-tasks.md)
- [Test your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/test-your-playbook.md): Set breakpoints, conditional breakpoints, skips, and input or output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/test-your-playbook/troubleshoot-playbook-performance.md)
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/build-your-playbook/manage-playbook-content.md)
- [Accelerate playbook development using the Automation Engineer agent (preview)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview.md)
- [Automation Engineer prompt examples](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview/automation-engineer-prompt-examples.md)
- [Best practices for playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/playbooks/best-practices-for-playbooks.md)
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/ai-prompts.md)
- [AI prompts role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/ai-prompts/ai-prompts-role-based-access-control.md): Manage AI prompt permissions with role-based access control.
- [Use existing prompts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/ai-prompts/use-existing-prompts.md): Find, duplicate, and edit prompts from the Prompts Library.
- [Create a prompt](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/ai-prompts/create-a-prompt.md): Create or edit prompts, configure settings, and use them in agents or playbooks.
- [Write effective prompts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/ai-prompts/write-effective-prompts.md): Tips for creating effective AI prompts.
- [Create an automation rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/create-an-automation-rule.md): Learn how to create an automation rule for an issue.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/scripts.md)
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/scripts/use-existing-scripts.md)
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/scripts/create-a-script.md)
- [Accelerate script development using the Automation Engineer agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/scripts/accelerate-script-development-using-the-automation-engineer-agent.md)
- [Change the Docker image in a script](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/scripts/change-the-docker-image-in-a-script.md)
- [Connect an engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/scripts/change-the-docker-image-in-a-script/connect-an-engine-to-an-image-registry.md)
- [Context data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data.md): Use context data to assist with the investigation and remediation process.
- [Issue context data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data/issue-context-data.md)
- [Case context data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data/case-context-data.md)
- [Search context data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data/search-context-data.md)
- [Add context data to an issue](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data/add-context-data-to-an-issue.md)
- [Add context data to a case](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data/add-context-data-to-a-case.md)
- [Delete context data from a case](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data/delete-context-data-from-a-case.md)
- [Use context data in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/context-data/use-context-data-in-a-playbook.md)
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/lists.md)
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/lists/create-a-list.md)
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/lists/list-commands.md)
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/lists/use-cases-json-lists.md)
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/lists/transform-a-list-into-an-array.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/integrations.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/integrations/add-an-integration-instance.md)
- [Use integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/integrations/use-integration-commands-in-the-cli.md)
- [Troubleshoot integations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/integrations/troubleshoot-integations.md)
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/integrations/manage-credentials.md)
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine.md): Install, deploy and configure Cortex XDR engines.
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker.md): Install, configure, secure, and troubleshoot Docker for Cortex XDR engines.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/install-docker.md): Install Docker and verify engine user permissions.
- [Install Docker distribution for Red Hat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/install-docker-distribution-for-red-hat.md): Configure Docker and SELinux on Red Hat engine servers.
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-image-security.md): Secure, harden, and troubleshoot Docker images and containers.
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-faqs.md)
- [Troubleshoot Docker Issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
- [Change the Docker Installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide.md)
- [Docker network hardening](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide/docker-network-hardening.md)
- [Configure Docker images](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-docker-images.md)
- [Run Docker with non-root internal users](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
- [Configure the memory limit support without swap capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limit-support-without-swap-capabilities.md)
- [Configure the memory limitation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limitation.md)
- [Configure the CPU, PIDs, and open the file descriptors limit](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-cpu-pids-and-open-the-file-descriptors-limit.md)
- [Check Docker hardening configurations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/docker/docker-hardening-guide/check-docker-hardening-configurations.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/podman.md): Install, configure, and troubleshoot Podman for Cortex XDR engines.
- [Change the Container storage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/podman/change-the-container-storage.md): Configure Podman container storage for an engine.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/podman/install-podman.md): Install and configure Podman for Cortex XDR engines.
- [Migrate from Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/podman/migrate-from-docker-to-podman.md): Migrate an existing engine from Docker to Podman.
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/install-an-engine/podman/troubleshoot-podman.md): Resolve common Podman issues on Cortex XDR engines.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/manage-engines.md): Manage engines and load balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XDR or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/configure-engines.md): Configure Cortex XDR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md)
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/configure-engines/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/use-an-engine-in-an-integration.md): Use an engine or a load-balancing group of engines to fetch issues and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/automation/engines/troubleshoot-integrations-running-on-engines.md)
- [Response actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions.md): During the case investigation, various response actions are available.
- [Initiate a Live Terminal session](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/initiate-a-live-terminal-session.md)
- [Isolate an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/isolate-an-endpoint.md)
- [Pause endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/pause-endpoint-protection.md)
- [Remediate changes from malicious activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/remediate-changes-from-malicious-activity.md)
- [Search and destroy malicious files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/search-and-destroy-malicious-files.md)
- [Manage external dynamic lists](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/manage-external-dynamic-lists.md)
- [Collect a memory image](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/collect-a-memory-image.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics.md)
- [Forensic investigations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations.md)
- [Manage an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/manage-an-investigation.md)
- [Create a new investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/manage-an-investigation/create-a-new-investigation.md): Create a forensic investigation, assign access, and start a data collection.
- [Edit an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/manage-an-investigation/edit-an-investigation.md): Update an active investigation's details and user access.
- [Close an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/manage-an-investigation/close-an-investigation.md): Close an investigation and manage its 24-hour grace period.
- [User permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/manage-an-investigation/user-permissions.md): You can assign users to the investigation for them to view and manage the investigation.
- [Data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/data-collection.md)
- [Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/data-collection/hunting.md)
- [Triage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/data-collection/triage.md)
- [Configure collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/data-collection/configure-collection.md)
- [Analysis and documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/analysis-and-documentation.md)
- [Review alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/analysis-and-documentation/review-alerts.md)
- [Investigation timeline](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/analysis-and-documentation/investigation-timeline.md)
- [Key assets & artifacts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/analysis-and-documentation/key-assets-and-artifacts.md)
- [Export](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/forensics/forensic-investigations/export.md)
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md)
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md)
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md)
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md)
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/create-xql-query.md)
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md)
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md)
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/how-to-build-xql-queries/graph-query-results.md)
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder.md): Learn more about the entities in the Legacy Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-authentication-query.md)
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-event-log-query.md)
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-file-query.md)
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-image-load-query.md)
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-network-connections-query.md)
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-network-query.md)
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-process-query.md)
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/create-registry-query.md)
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/legacy-query-builder/query-across-all-entities.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md)
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/overview-of-the-query-center/query-center-reference-information.md)
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md)
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/manage-your-personal-query-library.md): Cortex XDR provides as part of the Query Library a personal library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/build-xql-queries/manage-your-macros.md)
- [Quick Launcher](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/quick-launcher.md): The Quick Launcher provides a quick, in-context shortcut that you can use to search for information, perform common investigation tasks, or initiate actions.
- [Research a known threat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/research-a-known-threat.md): Cortex XDR enables you to investigate any threat, also referred to as a lead, which has been detected.
- [Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat.md): Chat with the Cortex Agentic Assistant using natural language prompts.
- [Get started with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat/get-started-with-agentic-assistant-chat.md): Enable Agentic Assistant and access the chat interface.
- [Choose an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat/choose-an-agentic-assistant-agent.md): Choose a system or custom agent for your chat.
- [Chat with an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-an-agentic-assistant-agent.md): Tips for chatting with the Cortex Agentic Assistant
- [Chat with the Agentic Assistant from Slack](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-the-agentic-assistant-from-slack.md): Enable chatting with an Agentic Assistant agent from Slack.
- [Create and run XQL queries with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat/create-and-run-xql-queries-with-agentic-assistant-chat.md): Interact with Cortex Agentic Assistant agents to build and run XQL queries.
- [Use natural language to query and visualize your data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat/use-natural-language-to-query-and-visualize-your-data.md): Prompt Cortex Agentic Assistant agents to create graphs and charts from its findings.
- [Manage chat history](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/agentic-assistant-chat/manage-chat-history.md): Manage and navigate your past chats with the Cortex Agentic Assistant.
- [Threat management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management.md)
- [Extended Threat Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence.md): Research threats, investigate indicators, and apply intelligence across Cortex XDR workflows.
- [XTI Threat Intel Library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-threat-intel-library.md): Research curated threat actors, malware families, vulnerabilities, and reports from Unit 42.
- [XTI Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicators.md): Investigate, manage, and enrich threat indicators, including domains, IP addresses, URLs, and file hashes.
- [Threat intel context in cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md): Analyze indicator intelligence and Behavioral Threat Analysis (BTA) findings in cases and issues.
- [XTI indicator rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicator-rules.md): Create rules that detect known threat indicators and generate issues from matching data.
- [Threat intel investigation through XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-investigation-through-xql.md): Query XTI indicators, threat objects, and their relationships using Cortex Query Language.
- [Threat Intel Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-dashboard.md): Visualize threat intelligence data to monitor distribution, ingestion health, and emerging trends.
- [Using XTI with Threat Intel Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-with-threat-intel-agent.md): Use the Threat Intel Agent to list, enrich, and update XTI indicators.
- [Using XTI in playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-in-playbooks.md): Automate XTI indicator triage, enrichment, and response with supported playbook commands.
- [Detection rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules.md)
- [What's an IOC?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-an-ioc.md)
- [IOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-an-ioc/ioc-rule-details.md)
- [Create an IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-an-ioc/create-an-ioc-rule.md)
- [What's a BIOC?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-bioc.md)
- [BIOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-bioc/bioc-rule-details.md)
- [Create a BIOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-bioc/create-a-bioc-rule.md)
- [Manage Global BIOC Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-bioc/manage-global-bioc-rules.md)
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-correlation-rule.md)
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-correlation-rule/correlation-rule-details.md)
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-correlation-rule/create-a-correlation-rule.md)
- [Field replacement syntax in correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rules.md)
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-correlation-rule/manage-correlation-rules.md)
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-correlation-rule/monitor-correlation-rules.md)
- [Troubleshoot server errors in scheduled correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rules.md)
- [Manage IOC and BIOC rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/detection-rules/manage-ioc-and-bioc-rules.md)
- [Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics.md)
- [Analytics overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview.md)
- [Analytics engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-engine.md)
- [Analytics sensors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-sensors.md)
- [Coverage of MITRE Attack tactics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/coverage-of-mitre-attack-tactics.md)
- [Review MITRE ATT\&CK framework coverage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/review-mitre-att-and-ck-framework-coverage.md)
- [Analytics detection time intervals](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-detection-time-intervals.md)
- [Analytics issues and Analytics BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-issues-and-analytics-biocs.md)
- [View and manage Analytics rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/view-and-manage-analytics-rules.md)
- [AI Detection & Response in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr.md)
- [Data sources and supported services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/data-sources-and-supported-services.md)
- [Collect prompt logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/collect-prompt-logs.md)
- [Prompt log collection in AWS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/collect-prompt-logs/prompt-log-collection-in-aws.md)
- [Enable prompt log collection in Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/collect-prompt-logs/enable-prompt-log-collection-in-azure.md)
- [Configure the Azure Event Hub collection in Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-xsiam.md)
- [Set up prompt logging](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-logging.md)
- [Log HTTP data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-data.md)
- [Configure diagnostic settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xdr/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settings.md)
- [Attack surface management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management.md): Learn how to discover, monitor, and remediate external asset exposures with attack surface management.
- [Learn about Attack Surface Management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management.md): Learn about Cortex XDR Attack Surface Management capabilities for finding, prioritizing, and remediating external asset exposures.
- [Network mapping](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/network-mapping.md): Learn how Cortex XDR discovers, attributes, and validates internet-facing assets to map your public attack surface.
- [Scanning](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/scanning.md): Learn how Cortex XDR ASM scans internet-facing assets, monitors known assets, and identifies exposed services.
- [GeoIP data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-management/geoip-data-collection.md): Use GeoIP data to validate network distribution, identify location-based compliance risks, and route remediation efforts.
- [Attack Surface Management detections](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections.md)
- [Attack surface rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/attack-surface-rules.md)
- [Attack Surface Testing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/attack-surface-testing.md)
- [Externally inferred CVEs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/externally-inferred-cves.md)
- [Digital Risk Protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-management-detections/digital-risk-protection.md)
- [Attack surface assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/attack-surface-assets.md): The assets discovered in an attack surface management scan are called External Surface assets.
- [Deploy ASM and Exposure Management enrichment and remediation automation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/deploy-asm-and-exposure-management-enrichment-and-remediation-automation.md): Enable the Cortex Exposure Management playbooks to automate ASM and vulnerability issue enrichment and remediation.
- [ASM enrichment of cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/asm-enrichment-of-cloud-assets.md): ASM enrichment of cloud assets provides visibility into all the assets in your cloud infrastructure that are exposed to the internet.
- [Emerging Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/emerging-vulnerabilities.md): Identify external exposures linked to emerging vulnerabilities, zero-day exploits, and global threat events on the Emerging Vulnerabilities page.
- [Global Lookup](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/attack-surface-management/global-lookup.md)
- [Monitor and track compliance adherence](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence.md): Evaluate and track asset compliance against industry standards and organizational policies.
- [Choose compliance standards from the compliance catalog](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog.md): Select built-in or custom compliance standards and controls from the compliance catalogs.
- [Standards catalog](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/standards-catalog.md): Browse available compliance standards.
- [Controls catalog](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/controls-catalog.md): Browse, filter, and review built-in and custom compliance controls.
- [Use a built-in or custom standard](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-standard.md): Use built-in standards or create and edit custom standards for your organization.
- [Use a built-in or custom control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md): Add built-in controls or create and manage custom controls for custom standards.
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/create-a-new-custom-detection-rule.md): Create custom detection rules to enforce compliance requirements and security best practices.
- [Use an assessment profile to run compliance checks on your assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets.md): Create assessment profiles to evaluate selected asset groups against compliance standards.
- [Configuring assessments for custom compliance standards based on custom cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets/configuring-assessments-for-custom-compliance-standards-based-on-custom-cloud-security-rules.md): Configure policies and assessments for custom standards that use custom cloud security rules.
- [View and manage compliance assessments and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports.md): Review assessment results and generate or schedule downloadable compliance reports.
- [Review assessments](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/assessments.md): View assessment results and drill into control, rule, and asset compliance details.
- [Review reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/reports.md): View, export, and manage historical compliance assessment reports.
- [Compliance Overview Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/monitor-and-track-compliance-adherence/compliance-overview-dashboard.md): Monitor organization-wide compliance scores, standards, failed controls, and asset group performance.
- [Exposure management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management.md)
- [Exposure Management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/exposure-management.md): Consolidate, prioritize, and remediate exposures across Palo Alto Networks and third-party data sources.
- [Get started with Exposure Management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/get-started-with-exposure-management.md): Set up Exposure Management by configuring scanners, integrations, policies, security controls, and automation.
- [Ingest assets and vulnerabilities from third-party applications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/ingest-assets-and-vulnerabilities-from-third-party-applications.md): Ingest assets and vulnerabilities into Cortex Exposure Management from Palo Alto Networks sensors and third-party applications.
- [Security controls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/security-controls.md): Detect, create, and manage security controls to assess compensating-control effectiveness and residual risk.
- [Cortex Network Scanner](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/cortex-network-scanner.md)
- [Exposure Management Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/exposure-management-command-center.md)
- [Vulnerability management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/vulnerability-management.md): Learn how to identify, prioritize, and remediate vulnerabilities across your environment.
- [Vulnerability management in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-management-in-cortex-xdr.md): Vulnerability management helps you identify, assess, prioritize, and remediate security vulnerabilities across your entire IT infrastructure, including endpoints, code, and cloud.
- [Cortex Vulnerability Risk Score](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/vulnerability-management/cortex-vulnerability-risk-score.md): Learn how Cortex Vulnerability Risk Score prioritizes vulnerabilities using asset context and threat intelligence.
- [Vulnerability policies](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-policies.md): A vulnerability policy defines the action you want to take for a specific set of vulnerability findings.
- [Investigate and remediate vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/vulnerability-management/investigate-and-remediate-vulnerabilities.md): Learn how to investigate vulnerability issues, findings, and affected assets, then track remediation.
- [Vulnerability Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-intelligence.md): Vulnerability Intelligence is an in-product, real-time feed that provides vulnerability data and threat intelligence from a variety of certified upstream sources.
- [Recast CVSS scores and CVSS severities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/vulnerability-management/recast-cvss-scores-and-cvss-severities.md): Customize CVSS scores and CVSS severities in the platform to align your risk management approach with your organizational context and priorities.
- [Cortex Advanced Email Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security.md): Configure, monitor, and respond to email security threats.
- [Cortex Advanced Email Security module overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-overview.md): Learn how to onboard, configure, and operate the Email Security module.
- [Cortex Advanced Email Security module architecture and data flow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-architecture-and-data-flow.md): The Cortex Advanced Email Security module, a cloud-native system, integrates multiple components to ingest, analyze, and respond to email-borne threats effectively.
- [Getting started with the Cortex Advanced Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/getting-started-with-the-cortex-advanced-email-security-module.md): High level deployment workflow
- [Deploy and configure the Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/deploy-and-configure-the-email-security-module.md): Configure the Microsoft O365 integration and the module.
- [Cortex Advanced Email Security threat detection and issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-threat-detection-and-issues.md): The Cortex Advanced Email Security module uses artifact-based, metadata-driven, and LLM-powered engines to generate detections and insights.
- [Email Security Analytics Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-threat-detection-and-issues/email-security-analytics-rules.md)
- [Investigate and respond to email security issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/investigate-and-respond-to-email-security-issues.md): Investigate the issues generated by the Cortex Advanced Email Security module.
- [Automate remediation for the Cortex Advanced Email Security module](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module.md): Automated response actions through the Cortex Advanced Email Security module improve efficiency and reduce noise.
- [Email Remediation Response Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module/email-remediation-response-rules.md)
- [Email Security Remediation Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-module/email-security-remediation-action-center.md)
- [Email Command Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/email-command-center.md): View a dynamic overview of your email security status in the Email Command Center.
- [Malicious Email Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/malicious-email-inventory.md): Triage, analyze, and act on malicious email threats
- [Mailbox Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/mailbox-inventory.md): View and manage your active email security assets
- [Advanced Email Security module security and compliance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/advanced-email-security-module-security-and-compliance.md)
- [Identity Threat Detection and Response (ITDR)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr.md)
- [Get started with ITDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/get-started-with-itdr.md)
- [Manage role based access control (RBAC) in ITDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/manage-role-based-access-control-rbac-in-itdr.md)
- [Monitor user risk exposure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/monitor-user-risk-exposure.md)
- [Investigate user risk](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/investigate-user-risk.md)
- [Manage user asset roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/asset-roles.md)
- [Improve Active Directory posture with AD-SPM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/active-directory-security-posture-management.md)
- [Enforce dynamic access control with CAP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/conditional-access-policy.md)
- [Prevent malicious LDAP queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/prevent-malicious-ldap-queries.md)
- [Cortex XDR XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql.md)
- [Get started with XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql.md): XQL is the Palo Alto Networks Cortex Query Language used in Cortex XDR.
- [XQL language features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/xql-language-features.md): Learn more about the Cortex Query Language features to query for raw network and endpoint data.
- [XQL Language Structure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/xql-language-structure.md): Learn more about the Cortex Query Language structure when creating a query.
- [Supported operators](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/supported-operators.md): Cortex Query Language supports specific comparison, boolean, and set operators in Cortex XDR.
- [Datasets and presets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/datasets-and-presets.md): The Cortex Query Language supports built-in datasets, custom datasets, and presets.
- [About examples](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/about-examples.md): Learn more about the Cortex Query Language (XQL) examples provided.
- [JSON functions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/json-functions.md): Learn more about how Cortex XDR treats JSON functions in the Cortex Query Language.
- [How to filter for empty values in the results table](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/how-to-filter-for-empty-values-in-the-results-table.md): Learn how to filter for empty values in the results table in Cortex Query Language.
- [Understanding string manipulation in XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/get-started-with-xql/understanding-string-manipulation-in-xql.md): Learn more about string manipulation in Cortex Query Language (XQL) using double and triple quotes.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md)
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md)
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md)
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md)
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/create-xql-query.md)
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md)
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md)
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/graph-query-results.md)
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder.md): Learn more about the entities in the Legacy Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-authentication-query.md)
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-event-log-query.md)
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-file-query.md)
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-image-load-query.md)
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-network-connections-query.md)
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-network-query.md)
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-process-query.md)
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/create-registry-query.md)
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/legacy-query-builder/query-across-all-entities.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md)
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center/query-center-reference-information.md)
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md)
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/manage-your-personal-query-library.md): Cortex XDR provides as part of the Query Library a personal library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/build-xql-queries/manage-your-macros.md)
- [Cortex XQL syntax, parameters, and examples](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql/cortex-xql-syntax-parameters-and-examples.md): Comprehensive syntax rules and structural requirements for XQL queries
- [Graph Search](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search.md): Learn more about Graph Search in Cortex XDR.
- [What is Graph Search?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/what-is-graph-search.md): Learn more about how to use Graph Search to search assets, findings, and their contextual data.
- [Get started with Graph Search queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/get-started-with-graph-search-queries.md): Learn more about how to get started before building a Graph Search query.
- [How to build Graph Search queries?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/how-to-build-graph-search-queries.md): Learn more about building Graph Search queries using the built-in query interface.
- [Understand Graph Search query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/understand-graph-search-query-results.md): Learn more about the Graph Search query results.
- [Create Graph Search query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/create-graph-search-query.md): Learn how to create Graph Search queries in Cortex XDR.
- [Graph Search examples](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/graph-search-examples.md): Learn how to build Graph Search queries by working through a few examples.
- [Manage the Graph Search Query Library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/manage-the-graph-search-query-library.md): Learn more about the Cortex XDR Graph Search Query Library to manage your queries.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/edit-and-run-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Supported assets and findings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/supported-assets-and-findings.md)
- [FAQ on Graph Search](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/faq-on-graph-search.md): Answer some frequently asked questions relating to Graph Search.
- [Create detection rules based on graph search](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/create-detection-rules-based-on-graph-search.md)
- [Cortex XDR API Reference](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-api-reference.md)
- [Role-Based Access Control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control.md): Learn how to limit role permissions in Cortex XDR.
- [Role permissions by component](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/role-permissions-by-component.md): Learn how to manage role permissions in Cortex XDR.
- [Core tenant and administrative permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/core-tenant-and-administrative-permissions.md)
- [Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions.md)
- [Auditing permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/auditing-permissions.md)
- [Alert Notifications permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/alert-notifications-permissions.md)
- [General Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/general-configuration-permissions.md)
- [Cortex XDR Analytics permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/cortex-xdr-analytics-permissions.md)
- [Access management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/access-management-permissions.md)
- [Data Broker permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/data-broker-permissions.md)
- [Log Collection permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/log-collection-permissions.md)
- [Data Sources permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/data-sources-permissions.md)
- [External Issues Mapping permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/external-issues-mapping-permissions.md)
- [Integrations - instance permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/integrations-instance-permissions.md)
- [Integrations Permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/integrations-permissions.md)
- [Data Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/data-management-permissions.md)
- [Public API](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/public-api.md)
- [Threat Intelligence permission - API configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/threat-intelligence-permission-api-configuration.md)
- [Long-running HTTP Integrations configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/long-running-http-integrations-configuration.md)
- [Credentials permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/credentials-permissions.md)
- [Object Setup permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions.md)
- [Case Properties permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/case-properties-permissions.md)
- [Exclusion List permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/exclusion-list-permissions.md)
- [Fields and Types permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/fields-and-types-permissions.md)
- [Sync Profile permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/configuration-permissions/object-setup-permissions/sync-profile-permissions.md)
- [Marketplace permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/marketplace-permissions.md): Configure Marketplace permissions for RBAC.
- [Help permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/help-permissions.md)
- [SOC Operations, Investigation & Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/soc-operations-investigation-and-response-permissions.md)
- [Dashboards and Reports permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions.md): Set permissions for dashboards and reports in Cortex XDR.
- [Dashboards permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/dashboards-permissions.md)
- [Command Center Dashboard permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/command-center-dashboard-permissions.md)
- [Ingestion Monitoring dashboard permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/ingestion-monitoring-dashboard-permissions.md)
- [Reports permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/reports-permissions.md)
- [Email Command Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/email-command-center-permissions.md)
- [Cloud Security Command Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/dashboards-and-reports-permissions/cloud-security-command-center-permissions.md)
- [Cases and Issues permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cases-and-issues-permissions.md): Set up Cases and Issues permissions.
- [Investigation and Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions.md): Configure investigation and response permissions, which include search, response, and automation permissions.
- [Search permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions.md)
- [Query Library permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/query-library-permissions.md)
- [Query Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/query-center-permissions.md)
- [Forensics permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/forensics-permissions.md)
- [Host Insights permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/host-insights-permissions.md)
- [Graph Search permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions/graph-search-permissions.md)
- [Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions.md)
- [Action Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/action-center-permissions.md)
- [EDL permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/edl-permissions.md)
- [Agent Scripts Library permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/agent-scripts-library-permissions.md)
- [Live Terminal permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/live-terminal-permissions.md)
- [Automation Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions/automation-rules.md)
- [Automation permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions.md)
- [Playbook permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/playbook-permissions.md)
- [Script permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/script-permissions.md)
- [Playground permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/playground-permissions.md)
- [Automation Exclusion Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions/automation-exclusion-center-permissions.md)
- [Search permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions-1.md)
- [Query Library permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions-1/query-library-permissions.md)
- [Query Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions-1/query-center-permissions.md)
- [Forensics permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions-1/forensics-permissions.md)
- [Host Insights permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions-1/host-insights-permissions.md)
- [Graph Search permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/search-permissions-1/graph-search-permissions.md)
- [Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions-1.md)
- [Action Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions-1/action-center-permissions.md)
- [EDL permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions-1/edl-permissions.md)
- [Agent Scripts Library permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions-1/agent-scripts-library-permissions.md)
- [Live Terminal permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/response-permissions-1/live-terminal-permissions.md)
- [Automation permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions-1.md)
- [Playbook permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions-1/playbook-permissions.md)
- [Script permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions-1/script-permissions.md)
- [Playground permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions-1/playground-permissions.md)
- [Automation Exclusion Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/investigation-and-response-permissions/automation-permissions-1/automation-exclusion-center-permissions.md)
- [Threat Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/threat-management-permissions.md): Configure Detection Rules and Threat Intel permissions.
- [Detection Rules permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/threat-management-permissions/detection-rules-permissions.md): Configure Detection Rules permissions.
- [Threat Intelligence permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/threat-management-permissions/threat-intelligence-permissions.md)
- [Exceptions Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions.md): Configure issue exclusion permissions.
- [Issue Exclusions permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions/issue-exclusions-permissions.md): Configure Issue Exclusions permissions.
- [Exception Management Admin permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions/exception-management-admin-permissions.md): Configure Exception Management Admin permissions.
- [Exception Approver Admin permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/exceptions-configuration-permissions/exception-approver-admin-permissions.md): Configure Exception Approver Admin permissions.
- [Cortex Agentic Assistant permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cortex-agentic-assistant-permissions.md): Configure the Cortex Agentic Assistant permissions, which include AI Prompts and Agent permissions.
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cortex-agentic-assistant-permissions/ai-prompts.md): Configure AI Prompts permissions.
- [Cortex Agentic Assistant Agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cortex-agentic-assistant-permissions/cortex-agentic-assistant-agents.md): Configure Cortex Agentic Assistant Agents permissions.
- [Agents and endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/agents-and-endpoint-protection.md)
- [Inventory - Agent permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions.md): Configure permissions for Endpoints (XDR Agent).
- [Agent Administrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-administrations.md)
- [Agent Groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-groups.md)
- [Agent Prevention Policies](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-prevention-policies.md)
- [Global Exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/global-exceptions.md)
- [Agent Profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-profiles.md)
- [Agent Extension Policies](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-extension-policies.md)
- [Agent Installations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-installations.md)
- [Host Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/host-firewall.md)
- [Device Control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/device-control.md)
- [Data Security - Endpoint DLP permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions.md)
- [Data-in-Motion Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/data-in-motion-rules.md)
- [Endpoint Applications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/endpoint-applications.md)
- [Endpoint Applications Groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/endpoint-applications-groups.md)
- [Endpoint DLP Settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/data-security-endpoint-dlp-permissions/endpoint-dlp-settings.md)
- [Inventory - Assets permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions.md): Consider adding inventory permissions for Assets and Agents (Endpoints).
- [Network Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/network-configuration-permissions.md)
- [Compliance (Legacy) permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/compliance-legacy-permissions.md)
- [Asset Inventory permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-inventory-permissions.md)
- [Asset Roles configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-roles-configuration-permissions.md)
- [Asset Groups permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-assets-permissions/asset-groups-permissions.md)
- [Attack Surface permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/attack-surface-permissions.md)
- [Vulnerability Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/vulnerability-management-permissions.md)
- [Cloud Security and Posture Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions.md)
- [CLI Tool permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/cli-tool-permissions.md)
- [Application Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions.md)
- [Application Security - Generic Collector permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-generic-collector-permissions.md)
- [Application Security - Issues permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-issues-permissions.md)
- [Application Security - Scans permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-scans-permissions.md)
- [Application Security - Policy Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-policy-management-permissions.md)
- [Application Security - 3rd Party tools permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/application-security-3rd-party-tools-permissions.md)
- [Configurations - Application Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/application-security-permissions/configurations-application-security-permissions.md)
- [Policies - Cloud Workload permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/policies-cloud-workload-permissions.md)
- [Cloud Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/cloud-security-permissions.md)
- [Compliance - Cloud permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/compliance-cloud-permissions.md)
- [Data Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/data-security-permissions.md)
- [AI Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/ai-security-permissions.md)
- [Data Classification permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/data-classification-permissions.md)
- [Identity Security permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/cloud-security-and-posture-management-permissions/identity-security-permissions.md)
- [Cloud service provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cloud-service-provider-permissions.md): Grant the correct cloud service provider permissions for Cortex XDR.
- [Amazon Web Services provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cloud-service-provider-permissions/amazon-web-services-provider-permissions.md)
- [Google Cloud Platform provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cloud-service-provider-permissions/google-cloud-platform-provider-permissions.md)
- [Microsoft Azure provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cloud-service-provider-permissions/microsoft-azure-provider-permissions.md)
- [Cortex secure deployment practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-secure-deployment-practices.md)
- [Microsoft Windows security auditing setup](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup.md)
- [Enable security auditing event IDs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids.md)
- [Enable security auditing event IDs with GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-security-auditing-event-ids-with-gpo.md)
- [Set up local machine security auditing without GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/set-up-local-machine-security-auditing-with-gpo.md)
- [Additional setup for Active Directory Certificate Services (ADCS) events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/additional-setup-for-active-directory-certificate-services-adcs-events.md)
- [Enable auditing access to AD domain objects - 4662](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-auditing-access-to-ad-domain-objects-4662.md)
- [Enable additional event logs using Event Viewer](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-additional-event-logs-using-event-viewer.md)
- [Enable LDAP server events logging (1644)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644.md)
- [Enable LDAP server events logging using RegEdit](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-regedit.md)
- [Enable LDAP server events logging using GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-gpo.md)
- [Validate log collection for LDAP Server events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/validate-log-collection-for-ldap-server-events.md)
- [Learn more about migrating to the latest Broker VM image](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/migrate-to-a-new-broker-vm-image/migrating-to-a-new-broker-vm-image.md): Learn more about migrating to the latest broker VM image in Cortex XDR.
- [Standalone Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/migrate-to-a-new-broker-vm-image/standalone-broker-vm.md): Learn more about migrating a standalone broker VM image.
- [Broker VM high availability cluster node](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/migrate-to-a-new-broker-vm-image/broker-vm-high-availability-cluster-node.md): Learn more about migrating a broker VM High Availability (HA) cluster node.

## Cortex XDR 3.x Documentation

- [Get started with Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme.md): Learn about key functionality within Cortex XDR, the available license plans, and the typical roles and responsibilities in a Security Operations Center (SOC) team.
- [What is Cortex XDR?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/what-is-cortex-xdr.md): Learn about Cortex XDR and the security challenges it addresses.
- [Concepts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/concepts.md): Learn more about the Cortex XDR main concepts.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/supported-web-browsers.md)
- [Use the interface](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/use-the-interface.md): Learn more about how to use the Cortex XDR interface.
- [What is Cortex Gateway?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/what-is-cortex-gateway.md): A brief introduction to Cortex Gateway
- [Understand Cortex XDR license plans](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans.md): Learn more about the available Cortex XDR licenses and add-ons.
- [Data retention in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/data-retention-in-cortex-xdr.md): Learn more about the default retention periods for all Cortex XDR licenses, and the available retention add-ons.
- [Data storage lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/data-storage-lifecycle.md)
- [License allocation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/license-allocation.md): Learn more about how Cortex XDR regulates licenses.
- [License expiration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/license-expiration.md): Learn more about the Cortex XDR license expiration and validation period.
- [Upgrade your tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/upgrade-your-tenant.md)
- [Security Operations Center roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/security-operations-center-roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [In-product support case creation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/in-product-support-case-creation.md): Open a support case directly in Cortex XDR and record your console to capture your issues and have the case handled efficiently.
- [Upgrade to Cortex XDR 5.x](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/upgrade-to-cortex-xdr-5.x.md)
- [Onboard and configure Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr.md): Learn about the deployment preparation and procedures to onboard and configure Cortex XDR.
- [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps.md): Follow the steps in the onboarding checklist to successfully deploy and onboard Cortex XDR.
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/plan-and-prepare.md): Learn more about deployment considerations and onboarding steps.
- [Cortex XDR onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/cortex-xdr-onboarding-checklist.md): Review the steps to deploy and onboard Cortex XDR.
- [Step 1: Activate Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-1-activate-cortex-xdr.md): Learn how to activate your tenant.
- [Cortex XDR supported regions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-1-activate-cortex-xdr/cortex-xdr-supported-regions.md): Supported regions in which you want to host Cortex XDR and any associated services.
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-1-activate-cortex-xdr/enable-access-to-required-panw-resources.md): Learn more about enabling network access to the Cortex XDR resources.
- [Step 2: Pre-installation steps for Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents.md)
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/assign-user-roles-and-groups.md): Learn how to assign users to roles and user groups.
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication.md): Authenticate Cortex XDR users using SAML 2.0 or Cortex Gateway.
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate Cortex XDR users when using the Customer Support Portal.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XDR tenant using SSO.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/define-endpoint-groups.md): Define an endpoint group and then apply policy rules and manage specific endpoints.
- [Manage endpoint profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/manage-endpoint-profiles.md): Endpoint security profiles can be used immediately, or customized, to protect your endpoints from threats.
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/endpoint-data-collection.md): To aid in endpoint detection and alert investigation, the Cortex XDR agent collects endpoint information when an alert is triggered.
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/configure-global-agent-settings.md): Learn how to configure the Cortex XDR agent global settings that operate on your endpoints.
- [Step 3: Install Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents.md): Learn about the initial steps required to deploy Cortex XDR agent software to endpoints.
- [Plan your agent deployment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/plan-your-agent-deployment.md)
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Learn more about how to control Cortex XDR agent and content upgrades.
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/create-an-agent-installation-package.md): Learn how to create a Cortex XDR agent installation package to deploy to your endpoints.
- [Deploy agent installation packages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/deploy-agent-installation-packages.md): Learn how to deploy an agent installation package on endpoints.
- [Step 4: Configure and deploy Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr.md)
- [Cortex XDR - Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/cortex-xdr-analytics.md)
- [Configure Cortex XDR network parameters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/cortex-xdr-analytics/configure-cortex-xdr-network-parameters.md)
- [Enable the Analytics Engine and Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/cortex-xdr-analytics/enable-the-analytics-engine-and-identity-analytics.md)
- [Set up Cloud Identity Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/set-up-cloud-identity-engine.md): Learn how to set up Cloud Identity Engine to use with Cortex XDR.
- [Step 5: Define data sources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-5-define-data-sources.md): Learn how to configure data ingestion ingest data from a variety of Palo Alto Networks and third-party sources.
- [Step 6: Perform health checks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-6-perform-health-checks.md): Learn which health checks to perform after deployment.
- [Monitor agent operational status in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-6-perform-health-checks/monitor-agent-operational-status-in-cortex-xdr.md): View the operational status of any Cortex XDR agent that you manage.
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps.md)
- [Set up your environment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment.md)
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-server-settings.md): Configure server settings such as keyboard shortcuts, timezone, and timestamp format.
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-security-settings.md): Configure security settings such as session expiration, user login expiration, and dashboard expiration.
- [Log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding.md): Stay informed and updated about events in your system by forwarding alerts and reports to an external service, such as a syslog receiver, a Slack channel, or an email account.
- [Forward logs from Cortex XDR to external services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services.md): Learn how to forward logs from Cortex XDR to external services such as email, Slack, or a syslog receiver.
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/integrate-a-syslog-receiver.md): Define syslog settings and then configure notification forwarding to receive notifications about alerts and reports.
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/integrate-slack-for-outbound-notifications.md): Learn how to integrate Cortex XDR with your Slack workspace and stay updated on important alerts and events.
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/configure-notification-forwarding.md): Learn how to create a forwarding configuration that specifies the log type you want to forward.
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/monitor-administrative-activity.md): View all Cortex XDR administrator-initiated actions taken on alerts, incidents, and live terminal sessions.
- [Log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats.md): Cortex XDR provides you with different formats for its log notifications.
- [Management audit log messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/management-audit-log-messages.md): View the types of Cortex XDR management audit log messages that are sent.
- [Alert notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/alert-notification-format.md): Learn about the formats used to forward Cortex XDR agent, BIOC, IOC, analytics, correlation, and third-party alerts.
- [Agent Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/agent-audit-log-notification-format.md): An email account or a syslog receiver are the notification channels through which the Agent Audit log is communicated.
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/management-audit-log-notification-format.md): An email account or a syslog receiver are the notification channels through which the Management Audit log is communicated.
- [Log format for IOC and BIOC alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/log-format-for-ioc-and-bioc-alerts.md): An email account or a syslog receiver are the notification channels through which IOC and BIOC alerts are communicated.
- [Analytics log format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/analytics-log-format.md): Learn about the syntax and different variables that are used in the analytics log format.
- [Log formats](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/log-formats.md): Learn about the different log formats that Cortex XDR can forward to an external server or email account.
- [Automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules.md): Use automation rules to define alert conditions that trigger an action that you specify within the rule.
- [Manage automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/manage-automation-rules.md): Learn how to manage automation rules for Cortex XDR.
- [Automation settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/automation-settings.md): Threshold limits may be implemented for settings of automation rules.
- [Automation rule actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/automation-rule-actions.md): Includes the list of actions to take when the alert condition of the automation rule is triggered for Cortex XDR.
- [Automation Audit Log](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/automation-audit-log.md): Includes the list of fields included in the Automation Audit Log for Cortex XDR.
- [Manage user roles and access management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management.md): Learn how to manage access for users, user roles, user groups, and Single Sign-On (SSO) for users on a specific Cortex XDR tenant.
- [Manage user roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-roles.md): Manage user roles that are assigned to Cortex XDR users or user groups in Cortex XDR Access Management.
- [Manage user access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md): Manage access permissions for Cortex XDR users.
- [User access reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access/user-access-reference-information.md)
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope.md): Learn about Scope-Based Access Control (SBAC) and how to assign users to specific tags of different types in your organization.
- [XQL query management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/xql-query-management.md): Administrators can set controls on running XQL queries.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/dashboards-and-reports.md)
- [Endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security.md): Learn about configuring and managing endpoint security.
- [Endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection.md): This topic provides an overview of traditional endpoint protection versus the protection of endpoints using Cortex XDR.
- [Malware protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/malware-protection.md): Cortex XDR prevents malware attacks and provides protection on endpoints based on the different operating systems.
- [Exploit protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/exploit-protection.md): Cortex XDR prevents exploit attempts and provides protection on endpoints based on the different operating systems.
- [File analysis and protection flow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/file-analysis-and-protection-flow.md): The Cortex XDR agent utilizes advanced multi-method protection and prevention techniques to protect from both known and unknown malware and software exploits.
- [Endpoint protection capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/endpoint-protection-capabilities.md): The endpoint protection capabilities vary depending on the platform (operating system) that is used on each of your endpoints.
- [Endpoint protection modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/endpoint-protection-modules.md): Security modules are activated for your endpoints depending on the chosen security profile and the operating system on the endpoint.
- [Processes protected by exploit security policy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/processes-protected-by-exploit-security-policy.md): Application processes that run on your endpoint are protected by the exploit security policy.
- [WildFire analysis concepts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/wildfire-analysis-concepts.md): Learn about the analysis concepts used by Wildfire.
- [About content updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/about-content-updates.md): To increase security coverage and quickly resolve any issues in policy, Palo Alto Networks can seamlessly deliver software packages called content updates.
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/endpoint-data-collection.md): To aid in endpoint detection and alert investigation, the Cortex XDR agent collects endpoint information when an alert is triggered.
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Learn more about how to control Cortex XDR agent and content upgrades.
- [Install and manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints.md): Learn how to set up profiles, policies and other settings for endpoint protection, how to install Cortex XDR agent on endpoints, and how to manage them after installation.
- [Set up endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection.md): Set up endpoint protection profiles and policies, exceptions, endpoint hardening, and other endpoint settings.
- [Set up endpoint profiles and exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules.md): Endpoint security profiles can be used immediately, or customized, to protect your endpoints from threats.
- [Set up malware prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md): Configure malware prevention profiles to control the actions taken by Cortex XDR agents when known malware, macros, and unknown files try to run.
- [Set up exploit prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md): Exploit prevention profiles control the action that the Cortex XDR agent takes when attempts to exploit software vulnerabilities or flaws occur.
- [Set up agent settings profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md): Use agent settings profiles to customize Cortex XDR agent settings for different platforms and groups of users.
- [Set up restrictions prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-restrictions-prevention-profiles.md): Restrictions prevention profiles limit where executables can run on an endpoint.
- [Set up exception profiles and rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules.md): Exception profiles can be configured to override security policies for known processes, files, digital signers, URLs, BTP rules, telephone numbers, and other exceptions.
- [Exception configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/exception-configuration.md): Learn how to configure exceptions from your baseline policy.
- [Alert exclusions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/alert-exclusions.md): Learn how to review and manage alert exclusions.
- [Add an alert exclusion rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/alert-exclusions/add-an-alert-exclusion-rule.md): Learn how to create a rule to exclude certain criteria from raising alerts in Cortex XDR.
- [Add an IOC or BIOC rule exception](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-an-ioc-or-bioc-rule-exception.md): Learn how to add an IOC or BIOC rule exception.
- [Add a disable prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-prevention-rule.md): You can create granular exceptions to prevention actions defined for your endpoints.
- [Add a disable injection and prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-injection-and-prevention-rule.md): You can generate a temporary exception to bypass a process from prevention modules and injections.
- [Add a support exception rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-support-exception-rule.md): Learn how to add a support exception rule.
- [Add a legacy exception rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule.md): Learn how to use Cortex XDR Legacy Exception rules to configure an exception to prevention and protection modules on endpoints for selected profiles.
- [Add a new exceptions security profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-new-exceptions-security-profile.md): Learn how to add a new exceptions security profile.
- [Add a global endpoint policy exception](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-global-endpoint-policy-exception.md): Learn how to define and manage global endpoint policy exceptions in Cortex XDR.
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/define-endpoint-groups.md): Define an endpoint group and then apply policy rules and manage specific endpoints.
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/configure-global-agent-settings.md): Learn how to configure the Cortex XDR agent global settings that operate on your endpoints.
- [Apply profiles to endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/apply-profiles-to-endpoints.md): Learn how to apply security profiles to your endpoints, depending on the platform used.
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package.md): Learn how to create a Cortex XDR agent installation package to deploy to your endpoints.
- [Manage an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package/manage-an-agent-installation-package.md): Learn how to make changes such as deleting an agent installation package or editing the package name.
- [Harden endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security.md): By hardening your endpoints with Cortex XDR agent, you can make these endpoints more secure and safer from attackers.
- [Device control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/device-control.md): Protect your Windows and macOS-based endpoints from connecting to malicious USB-connected removable devices, to Bluetooth devices, and to print jobs.
- [Host firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-firewall.md): Control communications on your endpoints based on the network location of your device by using the Cortex XDR host firewall.
- [Host firewall for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-firewall/host-firewall-for-windows.md): Control communications on your endpoints based on the network location of your device by using the host firewall.
- [Host firewall for macOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-firewall/host-firewall-for-macos.md): Control communications on your endpoints based on the network location of your device by using the host firewall.
- [Disk encryption](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/disk-encryption.md): For enhanced security, you can configure and apply disk encryption profiles to the disks of your Windows and Mac endpoints.
- [Host Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-inventory.md): Review the inventory of all your hosts (endpoints), and identify in the inventory any IT and security issues in your network.
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/vulnerability-assessment.md): Perform a vulnerability assessment of all endpoints in your network using Cortex XDR. This includes CVE, endpoint, and application analysis.
- [Set a Cortex XDR agent Critical Environment version](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-a-cortex-xdr-agent-critical-environment-version.md): Set the Cortex XDR agent as a Critical Environment (CE) version.
- [Set an application proxy for Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-an-application-proxy-for-cortex-xdr-agents.md): Set an application-specific proxy for the Cortex XDR agent without affecting the communication of other applications on the endpoint.
- [Pairing Prisma Cloud Compute with Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/pairing-prisma-cloud-compute-with-cortex-xdr.md): Learn how to pair Prisma Cloud Compute with Cortex XDR for use with the Cortex XDR Agent for Cloud.
- [Manage endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection.md)
- [Manage endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags.md): Segment your endpoints according to dynamic tags.
- [Set an alias for an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/set-an-alias-for-an-endpoint.md): Configure an alias to identify one or more endpoints by a name that is different from the endpoint hostname.
- [Manage endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-prevention-profiles.md): You can manage the endpoint prevention profiles of your Cortex XDR agent endpoints in various ways, including editing, duplicating, and populating endpoint prevention policy rules.
- [Upgrade Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/upgrade-cortex-xdr-agents.md): You can upgrade the Cortex XDR agent software by using the appropriate method for the endpoint operating system.
- [Restart agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/restart-agent.md): Learn how to restart the agent on the endpoint.
- [Uninstall the Cortex XDR agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/uninstall-the-cortex-xdr-agent.md): Uninstall Cortex XDR agent from one or more endpoints at any time using the Action Center, or one-by-one using the All Endpoints page.
- [Delete Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/delete-cortex-xdr-agents.md): Delete endpoints from Cortex XDR tenant views.
- [Manage agent tokens](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-agent-tokens.md): Manage tokens per agent to retrieve the password used to run functions at the agent.
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/retrieve-support-file-password.md): Learn how to retrieve the password to access files from the Tech Support File (TSF), which is generated in a zip format protected by an encrypted password.
- [Move agents between managing servers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/move-agents-between-managing-servers.md): You can move Cortex XDR agents to other Cortex XDR managing servers.
- [Clear agent database](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/clear-agent-database.md): Learn how to clear the Cortex XDR agent database.
- [Send push notifications to iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/send-push-notifications-to-ios.md): Learn how to send push notifications to an iOS endpoint.
- [Monitor agent operational status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-operational-status.md): You can view the operational status of any Cortex XDR agent that you manage.
- [Monitor agent activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md): You can monitor the activity of any Cortex XDR Broker VM that you manage.
- [Monitor agent upgrade status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-upgrade-status.md)
- [Detect threats and analyze data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data.md)
- [Detection rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules.md): Cortex XDR uses rules to detect threats and raise alerts.
- [What's an IOC?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-an-ioc.md): Indicators of compromise (IOCs) alert you about known malicious objects on your endpoints.
- [IOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-an-ioc/ioc-rule-details.md): Manage all indicators of compromise (IOCs) configured from or uploaded to Cortex XDR.
- [Create an IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-an-ioc/create-an-ioc-rule.md): From the Cortex XDR management console, you can upload or configure indicator of compromise (IOC) rules criteria.
- [What's a BIOC?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc.md): Behavioral indicators of compromise (BIOCs) alert you to respond to potentially compromising behaviors.
- [BIOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/bioc-rule-details.md): From the Cortex XDR management console, you can define your own rules based on behavior with the behavioral indicator of compromise (BIOC) rules.
- [Create a BIOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/create-a-bioc-rule.md): You can configure rules for behavioral indicators of compromise (BIOCs) to trigger an alert on an identified threat.
- [Manage Global BIOC Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/manage-global-bioc-rules.md): Update and copy BIOC rules, and add rule exceptions in Cortex XDR.
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule.md)
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/correlation-rule-details.md): In the Correlation Rules page, you can view all of your enabled rules in a table format and the various fields displayed.
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/create-a-correlation-rule.md): Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file.
- [Field replacement syntax in correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rules.md): Learn more about how to use field replacement syntax when creating correlation rules.
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/manage-correlation-rules.md): View and manage your correlation rules
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/monitor-correlation-rules.md): You can monitor your correlation executions with the correlations\_auditing dataset.
- [Troubleshoot server errors in scheduled correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rules.md): Learn more about how to troubleshoot server errors in scheduled correlation rules.
- [Manage existing indicators](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/manage-existing-indicators.md): Edit, export, copy, disable, or remove rules, and add rule exceptions for existing indicators in Cortex XDR.
- [Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics.md): Cortex XDR uses an Analytics engine to examine logs and data from your sensors.
- [Analytics engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-engine.md)
- [Analytics sensors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-sensors.md)
- [Coverage of MITRE Attack tactics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/coverage-of-mitre-attack-tactics.md)
- [Analytics detection time intervals](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-detection-time-intervals.md)
- [Analytics alerts and Analytics BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-alerts-and-analytics-biocs.md)
- [View and manage Analytics rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/view-and-manage-analytics-rules.md): View and manage all Analytics rules
- [Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/identity-analytics.md)
- [Identity Threat Module](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/identity-threat-module.md)
- [Forensic investigations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations.md): Learn about forensics, how to create forensic investigations, how to create and manage data collections, and how to assess other forensic related settings.
- [Manage an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation.md): Manage an investigation by adding collections, managing alerts, adjusting the timeline, analyzing assets and artifacts.
- [Create a new investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/create-a-new-investigation.md): Learn how to create a forensics investigation. This includes adding a collection, exporting the data collection, managing alerts and key assets & artifacts.
- [Edit an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/edit-an-investigation.md): Edit an existing investigation from the Forensic Investigations page.
- [Close an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/close-an-investigation.md): Close an existing investigation from the Forensic Investigations page.
- [User permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/user-permissions.md): You can assign users to the investigation for them to view and manage the investigation.
- [Data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection.md)
- [Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting.md): Search for specific data across a large number of hosts.
- [Create a hunt](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting/create-a-hunt.md): Hunt collections enable you to search endpoints for suspicious activity to contribute to helping resolve the investigation.
- [Hunt results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting/hunt-results.md): The hunt results page consolidates information collected by the Cortex XDR agent enabling you to investigate and take action on your endpoints.
- [Hunt status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting/hunt-status.md): In the Actions table, you can scroll or use the filters to see the status of any search within a hunt across any of the targeted endpoints.
- [Triage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage.md): Triage collection gathers a wide range of artifacts that can be used to help understand the event that occurred on an endpoint.
- [Create a triage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/create-a-triage.md): Triage collections enable you to obtain additional information for certain activities that have occurred on the endpoints. This helps towards the forensics analytics of an investigation.
- [Upload an offline triage package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/upload-an-offline-triage-package.md): Use the Upload Offline Triage to upload archives containing forensic data collected by the offline collector.
- [Offline triage collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/offline-triage-collection.md): Offline triage collection is supported for endpoints with no network connection or no Cortex XDR agent currently installed.
- [Triage results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/triage-results.md): You can drill down from the triage collection to review the results.
- [Triage status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/triage-status.md): From the Actions table, you can view the search status of all the artifacts for the triage.
- [Analysis and documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation.md): Learn more about your investigation by reviewing the additional data for analysis and documentation purposes.
- [Review alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation/review-alerts.md): The alerts table displays all the collections within the investigation that has identified suspicious or malicious activity within the forensics data sets.
- [Investigation timeline](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation/investigation-timeline.md): Investigation timeline shows the tagged forensic artifacts that were tagged. The tags display details of the forensic data collected from the endpoints.
- [Key assets & artifacts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation/key-assets-and-artifacts.md): Displays the forensic investigation based on the tagged data and aligns it to the corresponding category.
- [Export](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/export.md): Select the export option to export data collection for long-term retention or offline analysis.
- [Asset management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management.md)
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/vulnerability-assessment.md): Perform a vulnerability assessment of all endpoints in your network using Cortex XDR. This includes CVE, endpoint, and application analysis.
- [Network configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/network-configuration.md): Cortex XDR Network Configuration provides a representation of your network assets by collecting and analyzing your network resources.
- [Configure your network parameters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/network-configuration/configure-your-network-parameters.md): Define the IP address ranges and domain names used by Cortex XDR to identify your network assets.
- [Cloud Compliance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-compliance.md): Learn more about Cloud Compliance in Cortex XDR.
- [Manage Asset Scores](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/manage-asset-scores.md): Learn how to view and investigate User Scores and Host Scores using the Asset Scores page.
- [Asset Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-inventory.md): From the Cortex XDR management console, you can manage your different network assets.
- [All Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-inventory/all-assets.md): Cortex XDR enables you to view all external assets from the various asset categories on the All Assets page.
- [Specific Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-inventory/specific-assets.md): Cortex XDR enables you to view specific external assets from a designated assets category in the Specific Assets page.
- [Asset Roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles.md): View asset roles and the number of assets that are associated with each role. Learn how to manage asset roles for users and endpoints.
- [Manage Asset Roles for Users](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-users.md): Learn how to edit the user lists assigned to asset roles.
- [Honey user](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-users/honey-user.md): Honey users are decoy users designed to attract potential attackers.
- [Manage Asset Roles for Endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-endpoints.md): Learn how to edit the host lists assigned to asset roles.
- [Cloud Inventory Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets.md): Cortex XDR provides a unified, normalized asset inventory for cloud assets to provide deeper visibility and context for incident investigation.
- [All Cloud Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/all-cloud-assets.md): Cortex XDR enables you to view all your cloud assets from the various cloud assets categories on the All Cloud Assets page.
- [Specific Cloud Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/specific-cloud-assets.md): Cortex XDR enables you to view specific cloud assets from a designated cloud assets category in the Specific Cloud Asset pages.
- [Manage Your Cloud Inventory Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/manage-your-cloud-inventory-assets.md): Cortex XDR provides a central location to view and investigate information relating to inventory assets in the cloud.
- [Configure incidents and alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts.md)
- [External integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/external-integrations.md): Gain additional verification on key artifacts by integrating Cortex XDR with other Palo Alto Networks and third-party security products.
- [Prioritize incidents with starring and scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring.md): Prioritize and filter your incidents by using incident starring and incident scoring.
- [Incident starring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring/incident-starring.md): Starring incidents can help you to prioritize and filter your incidents.
- [Incident scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring/incident-scoring.md): Learn about the different incident scoring methods.
- [Set up incident scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring/incident-scoring/set-up-incident-scoring.md): Set up incident scoring by enabling SmartScore and defining scoring rules.
- [Automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules.md): Automation rules enable you to create rules comprised of alert conditions that trigger an action.
- [Automation settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules/automation-settings.md): Threshold limits may be implemented for settings of automation rules.
- [Automation rule actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules/automation-rule-actions.md): Includes the list of actions to take when the alert condition of the automation rule is triggered for Cortex XDR.
- [Automation audit log](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules/automation-audit-log.md): Includes the list of fields included in the automation audit log for Cortex XDR.
- [Investigate and respond to incidents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents.md): Learn about the Cortex XDR investigation and response operations.
- [Incident handling](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling.md): Learn about how incidents are created, the information contained in an incident, and how to prioritize and manage incidents.
- [What are incidents?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/what-are-incidents.md): Learn about how incidents are created, incident terminology, incident thresholds, and incident planning and response
- [Understanding the Incidents page](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/understanding-the-incidents-page.md): Use the Incidents page to review incident details and take remedial action.
- [Incidents table view reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/understanding-the-incidents-page/incidents-table-view-reference-information.md): Describes the fields in the table view.
- [Manage incidents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents.md): Lean how to investigate and manage your incidents.
- [Resolution reasons for incidents and alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents/resolution-reasons-for-incidents-and-alerts.md): Describes the resolution reasons for incidents and alerts.
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets.md): You can investigate specific artifacts and assets on dedicated views related to IP address, Network Assets, and File and Process Hash information.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-an-ip-address.md): Investigate incidents, connections, and threat intelligence reports related to a specific IP address on the IP View.
- [Investigate an asset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-an-asset.md): Investigate host assets and view host insights on the Asset View.
- [Investigate a host](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-host.md): Investigate host assets associated with your incidents
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md): Investigate incidents, actions, and threat intelligence reports related to a specific file or process hash on the Hash View.
- [Investigate a user](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-user.md): Investigate user assets associated with your incidents.
- [Investigate alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts.md): Cortex XDR generates alerts to bring your attention to security risks in your framework.
- [Overview of the Alerts page](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/overview-of-the-alerts-page.md): The Alerts page consolidates all non-informational alerts from your detection sources, and helps you to analyze and triage the alerts on your system.
- [Triage and investigate alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts.md): You can triage, investigate, and take actions on alerts from the Alerts page.
- [Copy alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/copy-alerts.md): You can copy an alert into memory.
- [Analyze an alert](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/analyze-an-alert.md): Learn more about analyzing alerts in the alert side panel and the causality view.
- [Create profile exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/create-profile-exceptions.md): You can create profile exceptions for agent alerts.
- [Add a file path to a malware profile allow list](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/add-a-file-path-to-a-malware-profile-allow-list.md): You can add a file path to an existing malware profile.
- [Create a featured alert field](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/create-a-featured-alert-field.md): You can label specific alert attributes as featured alert fields.
- [View generating BIOC or IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/view-generating-bioc-or-ioc-rule.md): You can view the BIOC or IOC rules that generated alerts directly from the Alerts table.
- [Retrieve additional alert details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/retrieve-additional-alert-details.md): Access additional information relating to an alert, including related files and memory content analysis.
- [Alert deduplication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/alert-deduplication.md): Learn about how Cortex XDR deduplicates alerts
- [Export alert details to a file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/export-alert-details-to-a-file.md): You can review alert details offline by exporting alerts to a TSV file.
- [Exclude an alert](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/exclude-an-alert.md): You can exclude alerts that are not deemed to be a threat.
- [Investigate contributing events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/investigate-contributing-events.md): You can investigate the events created by an alert.
- [Query incident and alert data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/query-incident-and-alert-data.md): You can run queries on incident and alert data with the incidents and alerts datasets.
- [Manage automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/manage-automation-rules.md): Procedure of how to manage the automation rules of Cortex XDR as needed, which includes to edit, save as new, disable, delete or copy.
- [Alert investigation views](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views.md): From the Alerts page, you can pivot on an alert to open the alert investigation views.
- [Alert side panel](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/alert-side-panel.md): The alert side panel provides detailed information about alerts at a glance and in the context of the incident.
- [Causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/causality-view.md): See the causality of an alert—the entire process execution chain that led up to the alert in the Cortex XDR app.
- [Network causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/network-causality-view.md): The network causality view shows a chain of individual network processes that together and in a particular sequence of operation triggered an alert.
- [Cloud causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/cloud-causality-view.md): See the causality of a cloud-type alert—the entire process execution chain that led up to the alert in the Cortex XDR app.
- [SaaS causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/saas-causality-view.md): Learn more about the SaaS causality view used to identify and investigate SaaS-specific data associated with SaaS-related alerts and SaaS audit logs.
- [Analytics alert view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/analytics-alert-view.md): From the Cortex XDR management console, you can view a detailed summary of the behavior that triggered analytics alerts.
- [Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/timeline.md): From the Cortex XDR tenant you can view the sequence (or timeline) of events and alerts that are involved in any particular threat.
- [Investigate endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints.md): You can investigate and take actions on your endpoints in the Action Center.
- [Overview of the Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/overview-of-the-action-center.md): From the Action Center, you can track the progress of all investigation, response, and maintenance actions performed on your endpoints.
- [Initiate and monitor endpoint actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/overview-of-the-action-center/initiate-and-monitor-endpoint-actions.md): Take these steps to initiate and monitor actions on your endpoints.
- [Action Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/overview-of-the-action-center/action-center-reference-information.md): See descriptions of the fields in the Action Center.
- [Manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/manage-endpoints.md): You can view and take actions on endpoints on the All Endpoints page.
- [Retrieve files from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/retrieve-files-from-an-endpoint.md): You can retrieve files from one or more endpoints by initiating a files retrieval request.
- [Retrieve support logs from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/retrieve-support-logs-from-an-endpoint.md): Retrieve support logs from an endpoint when additional forensic data is needed.
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/retrieve-support-file-password.md): Learn how to retrieve the password to access files from the Tech Support File (TSF), which is generated in a zip format protected by an encrypted password.
- [Scan an endpoint for malware](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/scan-an-endpoint-for-malware.md): The agent can scan your Windows and Mac endpoints and attached removable drives for dormant malware that is not actively attempting to run.
- [Investigate files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files.md)
- [Manage file execution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/manage-file-execution.md): Set rules for the execution (or running) of particular files on your endpoints in Cortex XDR.
- [Manage quarantined files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/manage-quarantined-files.md): You can review and manage all files that have been quarantined by the agent due to a security incident.
- [Review WildFire analysis details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/review-wildfire-analysis-details.md): For each file, Cortex XDR receives a file verdict and the WildFire Analysis Report detailing additional information you can use to assess the nature of a file.
- [Import file hash exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/import-file-hash-exceptions.md): You can import file hash exceptions from the Endpoint Security Manager or from external feeds.
- [Response actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions.md): As a result of an incident investigation, different response actions are possible.
- [Initiate a Live Terminal session](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/initiate-a-live-terminal-session.md): Initiate a Live Terminal session from the Cortex XDR management console to control the endpoint remotely.
- [Isolate an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/isolate-an-endpoint.md): In the event that an endpoint is compromised, you can immediately isolate it to reduce an attacker’s mobility.
- [Pause endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/pause-endpoint-protection.md): Disable the Cortex XDR agent protection capabilities on an endpoint.
- [Remediate changes from malicious activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/remediate-changes-from-malicious-activity.md): You can obtain action remediation suggestions from Cortex XDR about malicious causality chains that have been detected.
- [Run scripts on an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/run-scripts-on-an-endpoint.md): Execute Python scripts from Cortex XDR directly on the endpoint to perform actions, retrieve data, and retrieve files.
- [Search and destroy malicious files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/search-and-destroy-malicious-files.md): Cortex XDR enables you to effectively hunt down any identified malicious file that may exist on any of your endpoints.
- [Manage external dynamic lists](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/manage-external-dynamic-lists.md): Configure and manage your external dynamic lists in Cortex XDR.
- [Collect a memory image](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/collect-a-memory-image.md): Collect a memory image from a Windows endpoint.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, incident expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md): Learn more about some important information before getting started with XQL queries.
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md): Learn about useful XQL query features in the user interface.
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md): Learn about best practices for streamlining XQL queries.
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md): Learn what to expect in the query results when querying fields.
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/create-xql-query.md): Learn how to create queries using the Cortex Query Language (XQL).
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md): Learn more about reviewing the results returned from an XQL query.
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md): Learn how to translate your Splunk queries to XQL queries in Cortex XDR.
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/graph-query-results.md): Cortex XDR enables you to generate helpful visualizations of your XQL query results.
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities.md): Learn more about the Cortex Query Language (XQL) entities available in the Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-authentication-query.md): Learn more about creating a query to investigate any authentication activity.
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-event-log-query.md): Learn more about creating a query to investigate Windows and Linux event log attributes and investigate event logs across endpoints.
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-file-query.md): Learn more about creating a query to investigate the connections between file activity and endpoints.
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-image-load-query.md): Learn more about create a query to investigate the connections between image load activity, acting processes, and endpoints.
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-network-connections-query.md): Learn more about creating a query to investigate the connections between firewall logs, endpoints, and network activity.
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-network-query.md): Learn more about creating a query to investigate the connections between network activity, acting processes, and endpoints.
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-process-query.md): Learn more about creating a query to investigate connections between processes, child processes, and endpoints.
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-registry-query.md): Learn more about creating a query to investigate connections between registry activity, processes, and endpoints.
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/query-across-all-entities.md): From the Cortex XDR management console, you can search for endpoints and processes across all endpoint activity.
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and rerun queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center/query-center-reference-information.md): Descriptions of the fields in the Query Center table.
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md): Descriptions of the fields in the Scheduled Queries table.
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/manage-your-personal-query-library.md): Cortex XDR provides as part of the Query Library a personal library for saving and managing your own queries.
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards.md): Cortex XDR dashboards help you to monitor system activity in your environment. You can use any of the predefined dashboards that are provided in Cortex XDR, or you can create your own custom dashboard
- [About dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/about-dashboards.md): Dashboards help you to monitor system activity in your environment. Select a dashboard from the drop-down menu, or take actions on your dashboards from the Dashboard Manager.
- [Predefined dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/predefined-dashboards.md): Predefined dashboards are set up to help you monitor different aspects of your environment.
- [Custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards.md): Custom dashboards can support your day-to-day operations by providing options that are tailored to your unique workflow.
- [Build a custom dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/build-a-custom-dashboard.md): Build customized dashboards to display and filter the information that is most relevant to you.
- [Manage your Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/manage-your-widget-library.md): Create, search, and view custom widgets in Cortex XDR, or use predefined widgets.
- [Create a text widget](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/create-a-text-widget.md): Create a text-based widget to present information in a dashboard or report. Markdown is supported for formatting.
- [Create custom XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/create-custom-xql-widgets.md): You can create custom XQL widgets based on a Cortex Query Language (XQL) query, and add parameters that you can configure as fixed filters or dashboard drilldowns.
- [Configure fixed dashboard filters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/configure-fixed-dashboard-filters.md): Configure fixed filters that enable dashboard users to alter the scope of the dashboard by selecting predefined and dynamic values.
- [Configure dashboard drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/configure-dashboard-drilldowns.md): Configure drilldowns on custom dashboards to provide users with interactive data insights when clicking on data points in a widget
- [Variables in drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/configure-dashboard-drilldowns/variables-in-drilldowns.md): Learn about the widget variable values that you can use in dashboard drilldowns.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/reports.md): Create, edit, and customize reports in Cortex XDR. Schedule reports with Cron expressions.
- [Report templates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/reports/report-templates.md): View, import, export, create, and modify report templates
- [Run or schedule reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/reports/run-or-schedule-reports.md): You can run reports that are based on dashboard templates, or you can create reports from scratch.
- [Quick Launcher](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/quick-launcher.md): The Quick Launcher provides a quick, in-context shortcut that you can use to search for information, perform common investigation tasks, or initiate actions.
- [Research a known threat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/research-a-known-threat.md): Cortex XDR enables you to investigate any threat, also referred to as a lead, which has been detected.
- [Data management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm.md): Set up a Broker VM to establish a secure connection in which you can route your endpoints, and collect and forward logs and files for analysis.
- [What is the Broker VM?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/what-is-the-broker-vm.md): Learn about the Cortex XDR Broker virtual machine (VM) and why use it in your network configuration.
- [Set up and configure Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm.md): Learn more about how to set up and configure a Broker VM as a standalone broker or add the broker to a high availability (HA) cluster.
- [Broker VM image installations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations.md): Learn more about the Broker VM image types available that are compatible with your viirtual machine (VM).
- [Set up Broker VM on Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-alibaba-cloud.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Alibaba Cloud.
- [Set up Broker VM on Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-amazon-web-services.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on AWS.
- [Set up Broker VM on Google Cloud Platform (GCP)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-google-cloud-platform-gcp.md): Learn more about how to set up your Cortex XDR Broker VM on Google Cloud Platform.
- [Set up Broker VM on KVM using Ubuntu](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-kvm-using-ubuntu.md): Learn set up your Cortex XDR Broker virtual machine (VM) on a KVM using Ubuntu.
- [Set up Broker VM on Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-azure.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Microsoft Azure.
- [Set up Broker VM on Microsoft Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-hyper-v.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Microsoft Hyper-V.
- [Set up Broker VM on Nutanix Hypervisor](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-nutanix-hypervisor.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Nutanix Hypervisor.
- [Set up Broker VM on VMware ESXi using vSphere Client](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-vmware-esxi-using-vsphere-client.md): Learn more about how to set up you Cortex XDR Broker VM on VMware ESXi.
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets.md): Learn more about the different Broker VM data collector applets available to configure.
- [Activate Apache Kafka Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-apache-kafka-collector.md): Learn more about activating the Broker VM with an Apache Kafka Collector applet.
- [Activate CSV Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-csv-collector.md): Learn more about activating the Broker VM with a CSV Collector applet.
- [Activate Database Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-database-collector.md): Learn more about activating a Broker VM with a Database Collector applet.
- [Activate Files and Folders Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-files-and-folders-collector.md): Learn more about activating a Broker VM with a Files and Folders Collector applet.
- [Activate FTP Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-ftp-collector.md): Learn more about activating a Broker VM with a FTP Collector applet.
- [Activate Local Agent Settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-local-agent-settings.md): Learn more about activating a Local Agent Settings applet on a Broker VM.
- [Activate NetFlow Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-netflow-collector.md): Learn more about activating a Broker VM with a NetflFlow Collector applet.
- [Activate Network Mapper](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-network-mapper.md): Learn more about activating the Network Mapper to scan your network.
- [Activate Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-syslog-collector.md): Learn how to set up and activate the Syslog Collector applet on a Broker VM within your network.
- [Activate Windows Event Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-windows-event-collector.md): Set up your Windows Event Collector to connect with the Cortex XDR Broker VM and collect events.
- [Activate Windows Event Collector on Windows Core](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-windows-event-collector/activate-windows-event-collector-on-windows-core.md): Learn more about activating the Windrows Event Collector on Windows Core OS to connect with the Broker VM.
- [Renew WEC certificates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-windows-event-collector/renew-wec-certificates.md): Learn more about renewing your WEC certificates in Cortex XDR.
- [Manage Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm.md): Learn more about managing your Broker VMs from the management console.
- [Edit Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/edit-broker-vm-configuration.md): Learn more about editing the configuration of a Broker VM.
- [Increase Broker VM storage allocated for data caching](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/increase-broker-vm-storage-allocated-for-data-caching.md): Learn more about increasing the storage allocated for data caching in the Broker VM.
- [Monitor Broker VM using Prometheus](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/monitor-broker-vm-using-prometheus.md): Learn more on monitoring the Broker VM using Prometheus.
- [Collect Broker VM Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/collect-broker-vm-logs.md): Learn more about collecting logs from a Broker VM to review them as part of an investigation.
- [Upgrade Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/upgrade-broker-vm.md): Learn more about upgrading the Broker VM from the Cortex XDR management console.
- [Update Broker VM applets independently](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/update-broker-vm-applets-independently.md)
- [Import Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/import-broker-vm-configuration.md): Learn more about importing one Broker VM configuration to another.
- [Open Live Terminal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/open-live-terminal.md): Learn more about remotely connecting to a Cortex XDR Broker VM.
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/add-broker-vm-to-cluster.md): Learn more about adding a Broker VM to a high availability cluster.
- [Switchover Primary Node in Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/switchover-primary-node-in-cluster.md): Learning more about changing the role of the current Primary node in a HA cluster.
- [Remove from Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/remove-from-cluster.md): Learn more about removing a Broker VM node from a high availability cluster.
- [Broker VM High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster.md): Learn more about creating Broker VMs in a High Availability cluster
- [Configure High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/configure-high-availability-cluster.md): Learn how to configure a High Availablity Cluster.
- [Manage Broker VM clusters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters.md): Learn more about managing your broker VM clusters from the Clusters tab of the Broker VMs page.
- [View cluster details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/view-cluster-details.md): Learn more about viewing the details of any particular cluster.
- [Edit cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/edit-cluster.md): Learn how to edit a High Availability cluster.
- [Add applet to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-applet-to-cluster.md): Learn more about adding an applet to a High Availability cluster.
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-broker-vm-to-cluster.md): Learn more about adding a Broker VM to a high availability cluster.
- [Remove cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/remove-cluster.md): Learn more about removing a high availability cluster.
- [Manage Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm-data-collector-applets.md): Learn more about managing your Broker VM data collector applets from the Broker VMs page.
- [Broker VM notifications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-notifications.md): Learn about the notifications that are relevant to Cortex XDR Broker VMs.
- [Monitor Broker VM activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/monitor-broker-vm-activity.md): Learn more about the monitored Cortex XDR Broker VM activities.
- [Troubleshoot Broker VM applet errors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/troubleshoot-broker-vm-applet-errors.md): Learn more about how to verify the Broker VM applet application, connectivity, and processing errors and troubleshoot.
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors.md): Learn how XDR Collectors can be used for on-premise data collection on Windows and Linux machines.
- [XDR Collector audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-audit-logs.md): Learn more about XDR Collector audit logs.
- [XDR Collector machine requirements and supported operating systems](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-machine-requirements-and-supported-operating-systems.md): Learn about the supported operating systems and requirements for the collector machines used for the Cortex XDR Collectors.
- [Resources required to enable access to XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/resources-required-to-enable-access-to-xdr-collectors.md): Depending on your network environment settings, you should enable network access to the Cortex XDR Collectors resources.
- [Manage XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors.md): Manage Cortex XDR collectors.
- [Configure the XDR Collector upgrade scheduler](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/configure-the-xdr-collector-upgrade-scheduler.md): You can configure the Cortex XDR Collector upgrade scheduler and the number of parallel upgrades.
- [Create an XDR Collector installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/create-an-xdr-collector-installation-package.md): Learn how to create an XDR Collector installation package for a Windows or Linux collector machine.
- [Install the XDR Collector installation package for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows.md): Learn about the Cortex XDR Collector installation options on Windows collector machines.
- [Install the XDR Collector on Windows using the MSI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-the-msi.md): Learn how to install the Cortex XDR Collector on Windows using the MSI.
- [Install the XDR Collector on Windows using Msiexec](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-msiexec.md): Learn how to install the Cortex XDR Collectors on Windows using the Msiexec.
- [Install the XDR Collector installation package for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-linux.md): Learn how to install the Cortex XDR Collector on Linux collector machines.
- [XDR Collectors installation resource for Windows and Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/xdr-collectors-installation-resource-for-windows-and-linux.md): Cortex XDR Collectors installation resource for Windows and Linux.
- [Set an application proxy for XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/set-an-application-proxy-for-xdr-collectors.md): You can set an application-specific proxy for a Cortex XDR Collector without affecting the communication of other applications on the collector machine.
- [Upgrade XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/upgrade-xdr-collectors.md): You can upgrade the Cortex XDR Collector software by using the appropriate method for the collector machine operating system.
- [Uninstall the XDR Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/uninstall-the-xdr-collector.md): You can uninstall the Cortex XDR Collector from one or more Windows or Linux collector machines at any time.
- [Set an alias for an XDR Collector machine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/set-an-alias-for-an-xdr-collector-machine.md): Configure an alias to identify one or more collector machines by a name that is different from the collector machine hostname.
- [Define XDR Collector machine groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/define-xdr-collector-machine-groups.md): To easily apply policy rules and manage specific collector machines, you can define a collector machine group.
- [About Cortex XDR Collector content updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/about-cortex-xdr-collector-content-updates.md): To quickly resolve any issues in policy, Palo Alto Networks can seamlessly deliver software packages called content updates.
- [XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-profiles.md): Add an XDR collector profile to define the type of data to collect from a Linux or Windows platform.
- [Add an XDR Collector Profile for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows.md): Add a Cortex XDR Collector profile, which defines the data that is collected from a Windows collector machine, and defines automatic XDR Collector upgrade settings.
- [Ingest Logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md): Learn how to configure Cortex XDR to receive Windows DHCP logs.
- [Ingest Windows DNS debug logs using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows/ingest-windows-dns-debug-logs-using-elasticsearch-filebeat.md): Extend Cortex XDR visibility into Windows DNS Debug logs using Elasticsearch Filebeat with an XDR Collectors profile.
- [Query Windows Event Log records](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows/query-windows-event-log-records.md)
- [Add an XDR Collector profile for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-linux.md): Add a Cortex XDR Collector profile, which defines the data that is collected from a Linux collector machine, and defines automatic XDR Collector upgrade settings.
- [Apply profiles to collection machine policies](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/apply-profiles-to-collection-machine-policies.md): Enable a Cortex XDR Collector profile by mapping it to a policy.
- [XDR Collector datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-datasets.md): After Cortex XDR begins receiving data from your XDR Collectors configuration, the app automatically creates an XQL dataset.
- [Data Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion.md): Data can be ingested both from Palo Alto Networks products, and from third-party vendor products.
- [Visibility of logs and alerts from external sources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/visibility-of-logs-and-alerts-from-external-sources.md): Cortex XDR provides visibility into your external logs. The availability of logs and alerts varies by the data source.
- [Visibility of Cortex XDR audit and authentication logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/visibility-of-cortex-xdr-audit-and-authentication-logs.md): Monitor Cortex XDR authentication and audit logs for detecting attacks on Cortex XDR.
- [External data ingestion vendor support](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion-vendor-support.md): To augment your Cortex XDR data, you can set up Cortex XDR to ingest data from a variety of external third-party sources.
- [Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations.md): Cortex XDR supports Palo Alto Networks data ingestion.
- [About Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/about-palo-alto-networks-integrations.md): Stream data directly from other Palo Alto Networks products to Cortex XDR.
- [Ingest data from Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-data-from-next-generation-firewall.md): Learn how to ingest detection data from Next-Generation Firewall and Panorama.
- [Ingest Next-Generation Firewall logs using the Syslog collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-data-from-next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md): Use the Syslog collector to ingest NGFW logs in CEF format. This method is useful when your firewalls are located in a different region, or bandwidth issues are encountered due to large log size.
- [Ingest data from Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-data-from-prisma-access.md): Learn how to ingest detection data from Prisma Access.
- [Ingest logs from Prisma Access Browser](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-logs-from-prisma-access-browser.md): Ingest Prisma Browser logs into Cortex XDR.
- [Ingest Alerts from Prisma Cloud Compute](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-from-prisma-cloud-compute.md): Configure Data Collection Settings to receive alerts from Prisma Cloud Compute.
- [Ingest Alerts from Prisma Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-from-prisma-cloud.md): Configure Data Collection Settings in Cortex XDR to receive alerts from Prisma Cloud.
- [Ingest detection data from Strata Logging Service](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-detection-data-from-strata-logging-service.md): Learn how to ingest detection data from Strata Logging Service.
- [Ingest Alerts and Assets from PAN IoT Security (Deprecated)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-and-assets-from-pan-iot-security.md): Ingest alerts and device data from IoT Security.
- [Ingest alerts and assets from Device Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-and-assets-from-device-security.md)
- [Collecting URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/collecting-url-and-file-log-types.md): Learn about the implications of turning off or on collection of URL and File logs.
- [Detectors connected to URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/collecting-url-and-file-log-types/detectors-connected-to-url-and-file-log-types.md): A list of detectors connected to URL and File log types.
- [External data ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion.md): Cortex XDR supports external data ingestion for a variety of service types and vendors.
- [External applications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/external-applications.md): Learn more about integrating Slack and a Syslog Receiver to Cortex XDR.
- [Ingest network connection logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs.md): Cortex XDR can ingest network connection logs from different third-party sources.
- [Ingest network flow logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-amazon-s3.md): Take advantage of Cortex XDR investigation capabilities and set up network flow log ingestion for your Amazon S3 logs using an AWS CloudFormation Script.
- [Create an assumed role](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-amazon-s3/create-an-assumed-role.md): Learn about creating an AWS Assumed Role for Cortex XDR.
- [Configure data collection from Amazon S3 manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-amazon-s3/configure-data-collection-from-amazon-s3-manually.md): Set up network flow log ingestion for your Amazon S3 logs manually (without a script).
- [Ingest Network Route 53 Logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-route-53-logs-from-amazon-s3.md): Take advantage of Cortex XDR investigation capabilities and set up network Route 53 ingestion for your Amazon S3 logs using an AWS CloudFormation Script.
- [Ingest logs from Check Point firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-check-point-firewalls.md): To take advantage of Cortex XDR investigation and detection capabilities while using Check Point firewalls, forward your firewall logs to Cortex XDR.
- [Ingest logs from Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-cisco-asa-firewalls-and-anyconnect.md): Extend Cortex XDR visibility into logs from Cisco ASA firewalls and Cisco AnyConnect VPN.
- [Ingest logs from Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-corelight-zeek.md): Extend Cortex XDR visibility into logs from Corelight Zeek.
- [Ingest logs from Fortinet Fortigate firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-fortinet-fortigate-firewalls.md): Extend Cortex XDR visibility into logs from Fortinet Fortigate firewalls.
- [Ingest Logs and Data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-and-data-from-a-gcp-pubsub.md): If you use the Pub/Sub messaging service from Global Cloud Platform (GCP), you can send logs and data from GCP to Cortex XDR.
- [Ingest Logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-microsoft-azure-event-hub.md): Ingest logs from Microsoft Azure Event Hub with an option to ingest audit logs to use in Cortex XDR authentication stories.
- [Ingest network flow logs from Microsoft Azure Network Watcher](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-microsoft-azure-network-watcher.md): Ingest network security group (NSG) or Virtual network (VNet) flow logs from Microsoft Azure Network Watcher for use in Cortex XDR network stories.
- [Ingest Logs and Data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-and-data-from-okta.md): Ingest authentication logs and data from Okta for use in Cortex XDR authentication stories.
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md): Learn how to configure Cortex XDR to receive Windows DHCP logs.
- [Ingest logs from Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-zscaler-internet-access.md): Extend Cortex XDR visibility into logs from Zscaler Internet Access (ZIA).
- [Ingest logs from Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-zscaler-private-access.md): Extend Cortex XDR visibility into logs from Zscaler Private Access (ZPA).
- [Ingest authentication logs and data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data.md): Ingest authentication logs from external authentication services—such as Okta and Azure AD—into authentication stories with Cortex XDR.
- [Ingest audit logs from AWS Cloud Trail](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-audit-logs-from-aws-cloud-trail.md): Take advantage of Cortex XDR investigation capabilities and set up audit log ingestion for your AWS CloudTrail logs.
- [Ingest Logs and Data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-a-gcp-pubsub.md): If you use the Pub/Sub messaging service from Global Cloud Platform (GCP), you can send logs and data from GCP to Cortex XDR.
- [Ingest Logs and Data from Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-google-workspace.md): Ingest logs and data from Google Workspace for use in Cortex XDR.
- [Ingest Logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-from-microsoft-azure-event-hub.md): Ingest logs from Microsoft Azure Event Hub with an option to ingest audit logs to use in Cortex XDR authentication stories.
- [Ingest logs and data from Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-microsoft-365.md): Learn more about collecting logs and data from Microsoft 365.
- [Ingest Logs from Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-from-microsoft-office-365.md): Ingest logs and data from Microsoft Office 365 Management Activity API and Microsoft Graph API for use in Cortex XDR.
- [Ingest Logs and Data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-okta.md): Ingest authentication logs and data from Okta for use in Cortex XDR authentication stories.
- [Ingest Logs and Data from OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-onelogin.md): Learn how to ingest different types of logs and data from OneLogin.
- [Ingest authentication logs from PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-authentication-logs-from-pingfederate.md): Ingest authentication logs and data from PingFederate for use in Cortex XDR authentication stories.
- [Ingest Authentication Logs and Data from PingOne](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-authentication-logs-and-data-from-pingone.md): Ingest authentication logs and data from PingOne for Enterprise for use in Cortex XDR authentication stories.
- [Ingest operation and system logs from cloud providers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers.md): Learn how to ingest operation and system logs from supported cloud providers into Cortex XDR.
- [Ingest generic logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-generic-logs-from-amazon-s3.md)
- [Ingest logs from Amazon CloudWatch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-from-amazon-cloudwatch.md): Take advantage of Cortex XDR investigation capabilities and set up generic or EKS log ingestion for your Amazon CloudWatch logs.
- [Ingest Logs and Data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-and-data-from-a-gcp-pubsub.md): If you use the Pub/Sub messaging service from Global Cloud Platform (GCP), you can send logs and data from GCP to Cortex XDR.
- [Ingest logs from Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-from-google-kubernetes-engine.md): Forward your Google Kubernetes Engine (GKE) logs directly to Cortex XDR using Elasticsearch Filebeat.
- [Ingest Logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-from-microsoft-azure-event-hub.md): Ingest logs from Microsoft Azure Event Hub with an option to ingest audit logs to use in Cortex XDR authentication stories.
- [Ingest Logs and Data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-and-data-from-okta.md): Ingest authentication logs and data from Okta for use in Cortex XDR authentication stories.
- [Ingest endpoint data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-endpoint-data.md): Cortex XDR enables you to ingest endpoint data.
- [Ingest cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets.md): You can ingest cloud assets from different third-party sources using Cortex XDR.
- [Ingest Cloud Assets from AWS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets/ingest-cloud-assets-from-aws.md): Extend Cortex XDR visibility into cloud assets from AWS.
- [Ingest Cloud Assets from Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets/ingest-cloud-assets-from-google-cloud-platform.md): Extend Cortex XDR visibility into cloud assets from Google Cloud Platform.
- [Ingest Cloud Assets from Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets/ingest-cloud-assets-from-microsoft-azure.md): Extend Cortex XDR visibility into cloud assets from Microsoft Azure.
- [Additional log ingestion methods](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods.md): Cortex XDR supports custom log ingestion methods.
- [Ingest logs from a Syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-a-syslog-receiver.md): To extend visibility, Cortex XDR can receive Syslog from additional vendors that use CEF or LEEF formatted over Syslog (TLS not supported).
- [Ingest Apache Kafka events as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-apache-kafka-events-as-datasets.md): Cortex XDR can receive logs and data from Apache Kafka directly to your log repository for query and visualization purposes.
- [Ingest CSV files as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-csv-files-as-datasets.md): Cortex XDR can receive CSV log files from a shared Windows directory, where the CSV log files must conform to specific guidelines.
- [Ingest database data as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-database-data-as-datasets.md): Cortex XDR can receive data from a client relational database directly to your log repository.
- [Ingest logs in a network share as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-in-a-network-share-as-datasets.md): Cortex XDR can receive logs from files and folders in a network share directly to your log repository for query and visualization purposes.
- [Ingest FTP files as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-ftp-files-as-datasets.md): Cortex XDR can receive logs from files and folders via FTP, FTPS, and SFTP directly to your log repository for query and visualization purposes.
- [Ingest NetFlow flow records as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-netflow-flow-records-as-datasets.md): Cortex XDR can receive NetFlow flow records and IPFIX from a UDP port directly to your log repository for query and visualization purposes.
- [Set up an HTTP Log Collector to Receive Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/set-up-an-http-log-collector-to-receive-logs.md): You can set up Cortex XDR to receive logs from third-party sources, and automatically parse and process these logs.
- [Ingest logs from BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-beyondtrust-privilege-management-cloud.md): Extend Cortex XDR visibility into logs from BeyondTrust Privilege Management Cloud.
- [Ingest Logs and Data from Box](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-and-data-from-box.md): Ingest logs and data from Box enterprise accounts via the Box REST APIs.
- [Ingest Logs and Data from Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-and-data-from-dropbox.md): Ingest logs and data from Dropbox Business accounts via the Dropbox Business API.
- [Ingest Logs from Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-elasticsearch-filebeat.md): Cortex XDR can ingest logs from Elasticsearch Filebeat, a file system logger that logs file activity on your endpoints and servers.
- [Ingest logs from Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-forcepoint-dlp.md): Extend Cortex XDR visibility into logs from Forcepoint DLP.
- [Ingest Logs from Proofpoint Targeted Attack Protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-proofpoint-targeted-attack-protection.md): Ingest logs from Proofpoint Targeted Attack Protection (TAP).
- [Ingest logs and data from Salesforce.com](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-and-data-from-salesforce.com.md): Use the Cortex XDR data collector to collect Audit Trail and Security Monitoring event logs from Salesforce.com.
- [Ingest Data from ServiceNow CMDB](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-data-from-servicenow-cmdb.md): Extend Cortex XDR visibility into data from ServiceNow CMDB.
- [Ingest Report Data from Workday](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-report-data-from-workday.md): Extend Cortex XDR visibility into reports data from Workday.
- [Ingest external alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-external-alerts.md): For a more complete and detailed picture of the activity involved in an incident, Cortex XDR can ingest alerts from any external source.
- [Overview of data ingestion metrics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/overview-of-data-ingestion-metrics.md): Learn more about the data ingestion health metrics in the metrics\_source dataset and the metrics\_view preset.
- [Creating correlation rules to monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/creating-correlation-rules-to-monitor-data-ingestion-health.md): See examples of correlation rules for monitoring data ingestion health.
- [Measuring data freshness](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/measuring-data-freshness.md): Learn more about the data freshness metrics collected by Cortex XDR.
- [Verifying collector connectivity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/verifying-collector-connectivity.md): Verify collector connectivity and troubleshoot collector errors.
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period based retention.
- [What are datasets?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/what-are-datasets.md): Learn how to import, delete, and interact with custom or third-party datasets in Cortex XDR.
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets.md): Learn more about lookup datasets to correlate data from a data source with events in your environment.
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets/import-a-lookup-dataset.md): Learn more about importing data from an external file to create or update a lookup dataset in Cortex XDR.
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets/download-json-file-of-lookup-dataset.md): Learn more about downloading a lookup dataset as a JSON file.
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets/set-time-to-live-for-lookup-datasets.md): Learn more about setting the time to live (TTL) for lookup datasets in Cortex XDR.
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md): Learn more about the monitored Cortex XDR datasets and dataset views activities.
- [Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules.md): Learn more about Cortex XDR Parsing Rules.
- [What are Parsing Rules?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/what-are-parsing-rules.md): Learn more about what are Parsing Rules and what they are used for.
- [Parsing Rules editor views](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-editor-views.md): Learn about the Parsing Rules editor User Defined Rules, Default Rules, Both, and Simulate views.
- [Parsing Rules file structure and syntax](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax.md): The Parsing Rules file consists of multiple sections of three types, which also represent the custom syntax specific to Parsing Rules.
- [INGEST](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest.md): Understanding how to write an \\\[INGEST\\] section in a Parsing Rules file and the syntax to use.
- [parse\_cef](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cef.md)
- [parse\_cisco](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cisco.md): Learn more about the parse\_cisco() parsing rule function that parses a Cisco string to an object.
- [parse\_json](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_json.md)
- [COLLECT](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/collect.md): Understand how to write a \\\[COLLECT\\] section in a Parsing Rules file, and the syntax to use.
- [CONST](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/const.md): Learn how to write a \\\[CONST\\] section in a Parsing Rules file and the syntax to use.
- [RULE](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/rule.md): Understanding how to write a \\\[RULE\\] section in a Parsing Rules file and the syntax to use.
- [Create Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/create-parsing-rules.md): Cortex XDR includes an editor for creating 3rd party Parsing Rules.
- [Troubleshooting Parsing rules errors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/troubleshooting-parsing-rules-errors.md): Learn how to easily identify and resolve parsing errors.
- [Parsing Rules Raw Dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-raw-dataset.md): Each vendor and product has its own raw dataset with its own default format that can be overridden in an INGEST section.
- [Manage Event Forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-event-forwarding.md): Save your ingested, parsed data in an external location by exporting your event logs to a temporary GCP storage bucket.
- [Endpoints Event Forwarding - included/excluded fields by event type](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-event-forwarding/endpoints-event-forwarding-includedexcluded-fields-by-event-type.md): Learn more about the included/excluded fields by event type for Endpoint Event Forwarding in Cortex XDR.
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-compute-units.md): Learn more about managing and tracking your compute units usage for API and Cold Storage XQL queries.
- [Compute units usage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-compute-units/compute-units-usage.md): Learn more about how to compute units (CU) works according to your license and available options after reaching your quota.
- [Cortex XDR XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql.md)
- [Get started with XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql.md): XQL is the Palo Alto Networks Cortex Query Language used in Cortex XDR.
- [XQL language features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/xql-language-features.md): Learn more about the Cortex Query Language features to query for raw network and endpoint data.
- [XQL Language Structure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/xql-language-structure.md): Learn more about the Cortex Query Language structure when creating a query.
- [Adding comments in queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/xql-language-structure/adding-comments-in-queries.md): Learn more about adding comments in Cortex Query Language queries.
- [Supported operators](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/supported-operators.md): Cortex Query Language supports specific comparison, boolean, and set operators in Cortex XDR.
- [Datasets and presets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/datasets-and-presets.md): The Cortex Query Language supports built-in datasets, custom datasets, and presets.
- [About examples](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/about-examples.md): Learn more about the Cortex Query Language (XQL) examples provided.
- [JSON functions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/json-functions.md): Learn more about how Cortex XDR treats JSON functions in the Cortex Query Language.
- [How to filter for empty values in the results table](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/how-to-filter-for-empty-values-in-the-results-table.md): Learn how to filter for empty values in the results table in Cortex Query Language.
- [Understanding string manipulation in XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/understanding-string-manipulation-in-xql.md): Learn more about string manipulation in Cortex Query Language (XQL) using double and triple quotes.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, incident expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md): Learn more about some important information before getting started with XQL queries.
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md): Learn about useful XQL query features in the user interface.
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md): Learn about best practices for streamlining XQL queries.
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md): Learn what to expect in the query results when querying fields.
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/create-xql-query.md): Learn how to create queries using the Cortex Query Language (XQL).
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md): Learn more about reviewing the results returned from an XQL query.
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md): Learn how to translate your Splunk queries to XQL queries in Cortex XDR.
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/graph-query-results.md): Cortex XDR enables you to generate helpful visualizations of your XQL query results.
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities.md): Learn more about the Cortex Query Language (XQL) entities available in the Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-authentication-query.md): Learn more about creating a query to investigate any authentication activity.
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-event-log-query.md): Learn more about creating a query to investigate Windows and Linux event log attributes and investigate event logs across endpoints.
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-file-query.md): Learn more about creating a query to investigate the connections between file activity and endpoints.
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-image-load-query.md): Learn more about create a query to investigate the connections between image load activity, acting processes, and endpoints.
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-network-connections-query.md): Learn more about creating a query to investigate the connections between firewall logs, endpoints, and network activity.
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-network-query.md): Learn more about creating a query to investigate the connections between network activity, acting processes, and endpoints.
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-process-query.md): Learn more about creating a query to investigate connections between processes, child processes, and endpoints.
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-registry-query.md): Learn more about creating a query to investigate connections between registry activity, processes, and endpoints.
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/query-across-all-entities.md): From the Cortex XDR management console, you can search for endpoints and processes across all endpoint activity.
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and rerun queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center/query-center-reference-information.md): Descriptions of the fields in the Query Center table.
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md): Descriptions of the fields in the Scheduled Queries table.
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/manage-your-personal-query-library.md): Cortex XDR provides as part of the Query Library a personal library for saving and managing your own queries.
- [Stages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages.md): Learn more about the Cortex Query Language supported stages.
- [alter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/alter.md): Learn more about the Cortex Query Language alter stage.
- [arrayexpand](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/arrayexpand.md): Learn more about the Cortex Query Language arrayexpand stage.
- [bin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/bin.md): Learn more about the Cortex Query Language bin stage to group events by quantity or time span.
- [call](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/call.md): Learn more about the Cortex Query Language call stage to reference a predefined query from the Query Library.
- [comp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/comp.md): Learn more about the Cortex Query Language comp stage that precedes functions calculating statistics.
- [config](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config.md): Learn more about the Cortex Query Language config stage that configures the query behavior.
- [case\_sensitive](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config/case_sensitive.md): Learn more about the Cortex Query Language case\_sensitive config stage.
- [timeframe](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config/timeframe.md): Cortex Query Language timeframe configuration enables performing searches within a specific time frame from the query execution.
- [max\_runtime\_minutes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config/max_runtime_minutes.md): Learn more about the Cortex Query Language max\_runtime\_minutes config stage.
- [dedup](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/dedup.md): Learn more about the Cortex Query Language dedup stage that removes duplicate occurrences of field values.
- [fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/fields.md): Learn more about the Cortex Query Language fields stage that defines the fields returned in the result set.
- [filter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/filter.md): Learn more about the Cortex Query Language filter stage that narrows down the displayed results.
- [getrole](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/getrole.md): Learn more about the Cortex Query Language getrole stage that enriches events with specific roles associated with usernames or endpoints.
- [iploc](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/iploc.md): Learn more about the Cortex Query Language iploc stage that associates IPv4 addresses of fields to a list of predefined attributes related to the geolocation.
- [join](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/join.md): Learn more about the Cortex Query Language join stage that combines the results of two queries into a single result set.
- [limit](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/limit.md): Learn more about the Cortex Query Language limit stage that sets the maximum number of records that can be returned in the result set.
- [replacenull](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/replacenull.md): Learn more about the Cortex Query Language replacenull stage that replaces null field values with a text string.
- [sort](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/sort.md): Learn more about the Cortex Query Language sort stage that identifies the sort order for records returned in the result set.
- [Tag](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/tag.md): Learn more about the Cortex Query Language tag stage that adds a single tag or list of tags to the \\\_tag system ﬁeld.
- [target](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/target.md): Learn more about the Cortex Query Language target stage that saves query results to a dataset or lookup dataset.
- [top](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/top.md): Learn more about the Cortex Query Language top stage that returns the approximate count of top elements for a field and percentage of the count results.
- [transaction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/transaction.md): Learn more about the Cortex Query Language transaction stage used to find transactions based on events that meet certain constraints.
- [union](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/union.md): Learn more about the Cortex Query Language union stage that combines two result sets into a single result set.
- [view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/view.md): Learn more about the Cortex Query Language view stage that configures the display of the result set.
- [windowcomp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/windowcomp.md): Learn more about the Cortex Query Language windowcomp stage that precedes functions calculating statistics.
- [Functions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions.md): Learn more the functions that can be used with Cortex Query Language (XQL) stages in Cortex XDR.
- [add](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/add.md): Learn more about the Cortex Query Language add() function that adds two integers.
- [approx\_count](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/approx_count.md): Learn more about the Cortex Query Language approx\_count approximate aggregate comp function.
- [approx\_quantiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/approx_quantiles.md): Learn more about the Cortex Query Language approx\_quantiles approximate aggregate comp function.
- [approx\_top](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/approx_top.md): Learn more about the Cortex Query Language approx\_top approximate aggregate comp function.
- [array\_all](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/array_all.md): Learn more about the Cortex Query Language array\_all() function.
- [array\_any](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/array_any.md): Learn more about the Cortex Query Language array\_any() function.
- [arrayconcat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayconcat.md): Learn more about the Cortex Query Language arrayconcat() function that returns an array containing unique values found in the original array.
- [arraycreate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraycreate.md): Learn more about the Cortex Query Language arraycreate() function that returns an array based on the given parameters defined for the array elements.
- [arraydistinct](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraydistinct.md): Learn more about the Cortex Query Language arraydistinct() function that returns an array containing unique values found in the original array.
- [arrayfilter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayfilter.md): Learn more about the Cortex Query Language arrayfilter() function.
- [arrayindex](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayindex.md): Learn more about the Cortex Query Language arrayindex() function that returns the array element contained at the specified index.
- [arrayindexof](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayindexof.md): Learn more about the Cortex Query Language arrayindexof() function that returns the index value of an array.
- [array\_length](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/array_length.md): Learn more about the Cortex Query Language array\_length() function that returns the length of an array.
- [arraymap](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraymap.md): Learn more about the Cortex Query Language arraymap() function that applies a callable function to every element of an array.
- [arraymerge](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraymerge.md): Learn more about the Cortex Query Language arraymerge() function that returns an array created from a merge of the inner json-string arrays.
- [arrayrange](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayrange.md): Learn more about the Cortex Query Language arrayrange() function that returns a portion of an array based on specified array indices.
- [arraystring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraystring.md): Learn more about the Cortex Query Language arraystring() function that returns a string from an array, where each array element is joined by a defined delimiter.
- [avg](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/avg.md): Learn more about the Cortex Query Language avg used with both comp and windowcomp stages.
- [coalesce](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/coalesce.md): Learn more about the Cortex Query Language coalesce() function that returns the first value that is not null from a defined list of fields.
- [concat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/concat.md): Learn more about the Cortex Query Language concat() function joins multiple strings into a single string.
- [convert\_from\_base\_64](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/convert_from_base_64.md): Learn more about the Cortex Query Language convert\_from\_base\_64 function.
- [count](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/count.md): Learn more about the Cortex Query Language count function used with both comp and windowcomp stages.
- [count\_distinct](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/count_distinct.md): Learn more about the Cortex Query Language count\_distinct aggregate comp function that counts the number of unique values found for a field in the result set.
- [current\_time](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/current_time.md): Learn more about the Cortex Query Language current\_time() function that returns the current time as a timestamp.
- [date\_floor](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/date_floor.md): Learn more about the Cortex Query Language date\_floor() function.
- [divide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/divide.md): Learn more about the Cortex Query Language divide() function that divides two integers.
- [earliest](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/earliest.md): Learn more about the Cortex Query Language earliest aggregate comp function that returns the earliest field value found with the matching criteria.
- [extract\_time](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_time.md): Learn more about the Cortex Query Language extract\_time() function that returns a specified portion of a timestamp.
- [extract\_url\_host](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_url_host.md): Learn more about the Cortex Query Language extract\_url\_host() function.
- [extract\_url\_pub\_suffix](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_url_pub_suffix.md): Learn more about the Cortex Query Language extract\_url\_pub\_suffix() function.
- [extract\_url\_registered\_domain](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_url_registered_domain.md): Learn more about the Cortex Query Language extract\_url\_registered\_domain() function.
- [first](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/first.md): Learn more about the Cortex Query Language first aggregate comp function that returns the first field value found in the dataset with the matching criteria.
- [first\_value](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/first_value.md): Learn more about the Cortex Query Language first\_value() navigation function that is used with a windowcomp stage.
- [floor](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/floor.md): Learn more about the Cortex Query Language floor() function that rounds a field that contains a number down to the nearest whole integer.
- [format\_string](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/format_string.md): Learn more about the Cortex Query Language format\_string() function.
- [format\_timestamp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/format_timestamp.md): Learn more about the Cortex Query Language format\_timestamp() function that returns a string after formatting a timestamp according to a specified string format.
- [if](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/if.md): Learn more about the Cortex Query Language if() function that returns a result after evaluating a condition.
- [incidr](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/incidr.md): Learn more about the Cortex Query Language incidr() function.
- [incidr6](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/incidr6.md): Learn more about the Cortex Query Language incidr6() function.
- [incidrlist](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/incidrlist.md): Learn more about the Cortex Query Language incidrlist() function.
- [int\_to\_ip](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/int_to_ip.md): Learn more about the Cortex Query Language int\_to\_ip() function that safely converts a signed integer representation of an IPv4 address to a string equivalent.
- [ip\_to\_int](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/ip_to_int.md): Learn more about the Cortex Query Language ip\_to\_int() function that safely converts a string representation of an IPv4 address to an integer equivalent.
- [is\_ipv4](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_ipv4.md): Learn more about the Cortex Query Language is\_ipv4() function.
- [is\_known\_private\_ipv4](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_known_private_ipv4.md): Learn more about the Cortex Query Language is\_known\_private\_ipv4() function.
- [is\_ipv6](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_ipv6.md): Learn more about the Cortex Query Language is\_ipv6() function.
- [is\_known\_private\_ipv6](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_known_private_ipv6.md): Learn more about the Cortex Query Language is\_known\_private\_ipv6() function.
- [json\_extract](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract.md): Learn more about the Cortex Query Language json\_extract() function that accepts a string representing a JSON object, and returns a field value from that object.
- [json\_extract\_array](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract_array.md): Learn more about the Cortex Query Language json\_extract\_array() function that accepts a string representing a JSON array, and returns an XQL-native array.
- [json\_extract\_scalar](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract_scalar.md): Learn more about the Cortex Query Language json\_extract\_scalar() function.
- [json\_extract\_scalar\_array](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract_scalar_array.md): Learn more about the Cortex Query Language json\_extract\_scalar\_array() function.
- [lag](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/lag.md): Learn more about the Cortex Query Language lag() navigation function that is used with a windowcomp stage.
- [last](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/last.md): Learn more about the Cortex Query Language last aggregate comp function that returns the last field value found in the dataset with the matching criteria.
- [last\_value](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/last_value.md): Learn more about the Cortex Query Language last\_value() navigation function that is used with a windowcomp stage.
- [latest](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/latest.md): Learn more about the Cortex Query Language latest aggregate comp function that returns the latest field value found with the matching criteria.
- [len](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/len.md): Learn more about the Cortex Query Language len function that returns the number of characters contained in a string.
- [list](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/list.md): Learn more about the Cortex Query Language list aggregate comp function that returns an array for up to 100 values for a field in the result set.
- [lowercase](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/lowercase.md): Learn more about the Cortex Query Language lowercase() function that converts a string field to all lowercase letters.
- [ltrim, rtrim, trim](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/ltrim-rtrim-trim.md): Learn more about the Cortex Query Language ltrim(), rtrim(), and trim() functions that remove trim\_characters from a string.
- [max](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/max.md): Learn more about the Cortex Query Language max function used with both comp and windowcomp stages.
- [median](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/median.md): Learn more about the Cortex Query Language median function used with both comp and windowcomp stages.
- [min](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/min.md): Learn more about the Cortex Query Language min function used with both comp and windowcomp stages.
- [multiply](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/multiply.md): Learn more about the Cortex Query Language multiply() function that multiplies two integers.
- [object\_merge](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/object_merge.md): Learn more about the Cortex Query Language object\_merge() function.
- [object\_create](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/object_create.md): Learn more about the Cortex Query Language object\_create() function.
- [parse\_epoch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/parse_epoch.md): Learn more about the Cortex Query Language parse\_epoch() function that returns a Unix epoch TIMESTAMP object.
- [parse\_timestamp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/parse_timestamp.md): Learn more about the Cortex Query Language parse\_timestamp() function that returns a TIMESTAMP object.
- [pow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/pow.md): Learn more about the Cortex Query Language pow() function that returns the value of a number raised to the power of another number.
- [rank](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/rank.md): Learn more about the Cortex Query Language rank() numbering function that is used with a windowcomp stage.
- [regexcapture](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/regexcapture.md): Learn more about the Cortex Query Language regexcapture() function used in Parsing Rules to extract data from fields using regular expression named groups from a given string.
- [regextract](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/regextract.md): Learn more about the Cortex Query Language regextract() function that uses regular expressions to assemble an array of matching substrings from a string.
- [replace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/replace.md): Learn more about the Cortex Query Language replace() function that performs a substring replacement.
- [replex](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/replex.md): Learn more about the Cortex Query Language replex() function that uses a regular expression to identify and replace substrings.
- [round](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/round.md): Learn more about the Cortex Query Language round() function that returns the input value rounded to the nearest integer.
- [row\_number](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/row_number.md): Learn more about the Cortex Query Language row\_number() numbering function that is used with a windowcomp stage.
- [split](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/split.md): Learn more about the Cortex Query Language split() function that splits a string and returns an array of string parts.
- [stddev\_population](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/stddev_population.md): Learn more about the Cortex Query Language stddev\_population() function used with both comp and windowcomp stages.
- [stddev\_sample](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/stddev_sample.md): Learn more about the Cortex Query Language stddev\_sample() function used with both comp and windowcomp stages.
- [string\_count](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/string_count.md): Learn more about the Cortex Query Language string\_count() function that returns the number of times a substring appears in a string.
- [subtract](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/subtract.md): Learn more about the Cortex Query Language subtract() function that subtracts two integers.
- [sum](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/sum.md): Cortex Query Language sum function used with both comp and windowcomp stages.
- [time\_frame\_end](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/time_frame_end.md): Learn more about the Cortex Query Language time\_frame\_end() function that returns the end time of the time range specified for the query.
- [timestamp\_diff](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/timestamp_diff.md): Learn more about the Cortex Query Language timestamp\_diff() function that returns the difference between two timestamp objects.
- [timestamp\_seconds](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/timestamp_seconds.md): Learn more about the Cortex Query Language timestamp\_seconds() function.
- [to\_boolean](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_boolean.md): Learn more about the Cortex Query Language to\_boolean() function that converts a string to a boolean.
- [to\_epoch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_epoch.md): Learn more about the Cortex Query Language to\_epoch() function that converts a timestamp value for a field or function to the Unix epoch timestamp format.
- [to\_float](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_float.md): Learn more about the Cortex Query Language to\_float() function that converts a string to a floating point number.
- [to\_integer](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_integer.md): Learn more about the Cortex Query Language to\_integer() function that converts a string field to an integer.
- [to\_json\_string](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_json_string.md): Learn more about the Cortex Query Language to\_json\_string() function that accepts all data types and returns its contents as a JSON formatted string.
- [to\_number](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_number.md): Learn more about the Cortex Query Language to\_number() function that converts a string to a number.
- [to\_string](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_string.md): Learn more about the Cortex Query Language to\_string function that converts a number value to a string.
- [to\_timestamp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_timestamp.md): Learn more about the Cortex Query Language to\_timestamp() function that converts an integer to a timestamp.
- [uppercase](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/uppercase.md): Learn more about the Cortex Query Language uppercase() function that converts a string field to all uppercase letters.
- [values](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/values.md): Cortex Query Language comp values aggregate returns an array for all the values seen for the field in the result set.
- [var](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/var.md): Learn more about the Cortex Query Language var aggregate comp function that returns the variance value of a field in the result set.
- [Multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant.md)
- [What is Cortex XDR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/what-is-cortex-xdr-multi-tenant.md): Learn about Cortex multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a single console.
- [MSSP multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/what-is-cortex-xdr-multi-tenant/mssp-multi-tenant.md): MSSP multi-tenancy allows managed security service providers to ensure strict data segregation along with the flexibility to monitor alerts across tenants and dynamically allocate licenses.
- [Enterprise multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/what-is-cortex-xdr-multi-tenant/enterprise-multi-tenant.md)
- [Multi-tenant central licensing management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/multi-tenant-central-licensing-management.md)
- [Onboard Cortex multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant.md): Learn how to activate and manage tenants.
- [Onboarding checklist for multi-tenant central licensing deployments](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments.md): Onboard MSSP/Enterprise multi-tenant central licensing deployments.
- [Step 1. Activate Cortex XDR (main account)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments/step-1.-activate-cortex-xdr-main-account.md): Learn how to activate Cortex XDR in Cortex Gateway.
- [Step 2. Create a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments/step-2.-create-a-child-tenant.md): Create child tenants in the Cortex Gateway.
- [Onboarding checklist for multi-tenant customer-owned license deployments](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments.md): Onboard MSSP/Enterprise multi-tenant customer-owned license deployments.
- [Step 1. Activate Cortex Cortex XDR (parent and child tenants)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-1.-activate-cortex-cortex-xdr-parent-and-child-tenants.md): Learn how to activate Cortex XDR from Cortex Gateway.
- [Step 2. Define access configurations and role permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-2.-define-access-configurations-and-role-permissions.md): Define the correct access configuration and role permissions for multi-tenant customer-owned license deployment.
- [Step 3. Pair a parent tenant with child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-3.-pair-a-parent-tenant-with-child-tenant.md): In multi-tenant customer-owned license deployments, you must manually pair the parent tenant with each child tenant.
- [Dynamic license allocation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/dynamic-license-allocation.md): In a multi-tenant central licensing management environment, you can dynamically edit child tenant allocations, add child tenants, and delete child tenants with the license pool automatically updated.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management.md): Track, manage, and investigate child tenant data from the parent tenant.
- [Manage a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/manage-a-child-tenant.md): From the Cortex XDR management console you can view and investigate child tenant data and initiate security actions.
- [Track your tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/track-your-tenant-management.md): You can view the details of your tenants at any time.
- [Investigate child tenant data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/investigate-child-tenant-data.md): In multi-tenant environments, you can view, track, and investigate data across your Cortex XDR child tenants.
- [Create and allocate configurations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/create-and-allocate-configurations.md): From the Cortex XDR management console, you can create and allocate configurations for child tenants.
- [Create a security managed action](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/create-a-security-managed-action.md): Create a security type action to perform on behalf of your child tenants.
- [About managed threat hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/about-managed-threat-hunting.md): Understand how Managed Threat Hunting can help your organization.
- [Set up Managed Threat Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/about-managed-threat-hunting/set-up-managed-threat-hunting.md): Get started with the Managed Threat Hunting service, an add-on security service provided with Cortex XDR.
- [Investigate Managed Threat Hunting reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/about-managed-threat-hunting/investigate-managed-threat-hunting-reports.md): Investigate your Managed Threat Hunting reports.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference.md)
- [RBAC permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions.md): Learn more about the RBAC permissions specifically about role permissions by component and the default Palo Alto Networks roles.
- [Role permissions by components](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/role-permissions-by-components.md): Learn how to manage role permissions in Cortex XDR.
- [Default PANW roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles.md): Learn more about the default Palo Alto Networks user roles included in Cortex XDR.
- [Account Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/account-admin.md): Learn more about the Cortex XDR predefined user role called Account Admin.
- [Deployment Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/deployment-admin.md): Learn more about the Cortex XDR predefined user role called Deployment Admin.
- [Instance Administrator](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/instance-administrator.md): Learn more about the Cortex XDR predefined user role called Instance Administrator.
- [Investigation Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/investigation-admin.md): Learn more about the Cortex XDR predefined user role called Investigation Admin.
- [Investigator](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/investigator.md): Learn more about the Cortex XDR predefined user role called Investigator.
- [IT Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/it-admin.md): Learn more about the Cortex XDR predefined user role called IT Admin.
- [Privileged Investigator](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-investigator.md): Learn more about the Cortex XDR predefined user role called Privileged Investigator.
- [Privileged IT Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-it-admin.md): Learn more about the Cortex XDR predefined user role called Privileged IT Admin.
- [Privileged Responder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-responder.md): Learn more about the Cortex XDR predefined user role called Privileged Responder.
- [Privileged Security Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-security-admin.md): Learn more about the predefined user role called Privileged Security Admin.
- [Responder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/responder.md): Learn more about the Cortex XDR predefined user role called Responder.
- [Scoped Endpoint Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/scoped-endpoint-admin.md): Learn more about the Cortex XDR predefined user role called Scoped Endpoint Admin.
- [Security Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/security-admin.md): Learn more about the Cortex XDR predefined user role called Security Admin.
- [Viewer](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/viewer.md): Learn more about the Cortex XDR predefined user role called Viewer.
- [Microsoft Windows security auditing setup](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup.md)
- [Enable security auditing event IDs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids.md)
- [Enable security auditing event IDs with GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-security-auditing-event-ids-with-gpo.md)
- [Set up local machine security auditing without GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/set-up-local-machine-security-auditing-without-gpo.md)
- [Additional setup for Active Directory Certificate Services (ADCS) events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/additional-setup-for-active-directory-certificate-services-adcs-events.md)
- [Enable auditing access to AD domain objects - 4662](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-auditing-access-to-ad-domain-objects-4662.md)
- [Enable additional event logs using Event Viewer](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-additional-event-logs-using-event-viewer.md)
- [Enable LDAP server events logging (1644)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644.md)
- [Enable LDAP server events logging using RegEdit](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-regedit.md)
- [Enable LDAP server events logging using GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-gpo.md)
- [Validate log collection for LDAP Server events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/validate-log-collection-for-ldap-server-events.md)
- [Cortex secure deployment practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/cortex-secure-deployment-practices.md)

## Upgrade to Cortex XDR 5

- [What's New in Cortex XDR 5](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/whats-new-in-cortex-xdr-5.md)
- [Integrated Cloud Posture capabilities](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/integrated-cloud-posture-capabilities.md)
- [Improved incident management workflow with cases and issues](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/improved-incident-management-workflow-with-cases-and-issues.md)
- [Navigation bar and menu enhancements](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/navigation-bar-and-menu-enhancements.md)
- [New unified Asset Inventory and cloud data sources](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/new-unified-asset-inventory-and-cloud-data-sources.md)
- [Built-in automations](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/built-in-automations.md)
- [Scope-Based Access Control (SBAC) changes and enhancements](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/scope-based-access-control-sbac-changes-and-enhancements.md)
- [Additional features and enhancements](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/additional-features-and-enhancements.md)
- [Early upgrade with flexible scheduling](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/early-upgrade-with-flexible-scheduling.md)

## Cortex CLOUD Runtime Security

- [Navigate the Cortex Cloud Runtime Security docs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/readme.md): Start here for a visual overview of the main Runtime Security documentation areas.
- [What is Cortex Cloud?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/readme-1.md)
- [Key features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/readme-1/key-features.md)
- [What is Cortex Cloud Runtime Security?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/what-is-cortex-cloud-runtime-security.md): Learn about Cortex Cloud and the key integrated capabilities.
- [Agentic AI in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/agentic-ai-in-cortex-cloud.md): Use the Cortex Agentic Assistant to investigate cases, perform threat hunting, and create scripts. Embed and run LLM prompts in playbooks. View AI case summaries.
- [Agentic Assistant use cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/agentic-ai-in-cortex-cloud/agentic-assistant-use-cases.md): Recommended prompts to automate your SOC using the Cortex Agentic Assistant
- [Agentic Assistant security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/agentic-ai-in-cortex-cloud/agentic-assistant-security.md): Learn about how the Agentic Assistant is built using responsible AI principles.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/supported-web-browsers.md)
- [Use the interface](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/use-the-interface.md)
- [In-product support ticket creation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/in-product-support-case-creation.md): Open a support ticket directly in Cortex Cloud and record your console to capture your issues and have the ticket handled efficiently.
- [Understand your user persona](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/understand-your-user-persona.md)
- [Understand license plans](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/understand-license-plans.md)
- [Data retention](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/understand-license-plans/data-retention.md): Learn more about the default retention periods for all Cortex Cloud licenses and the available retention add-ons.
- [Fair Usage policy for Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/get-started/fair-usage-policy-for-cortex-cloud.md)
- [Learn how to onboard and configure Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/onboard-and-configure-cortex-cloud.md): Learn about the deployment preparation and procedures to onboard and configure Cortex Cloud.
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/plan-and-prepare.md): Learn more about deployment considerations and onboarding steps.
- [Prepare for deployment](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/plan-and-prepare/prepare-for-deployment.md): Learn more about deployment considerations and onboarding steps.
- [Deployment steps and checklist](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist.md): Review the steps to onboard and configure Cortex Cloud.
- [Activate Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud.md): Learn how to activate your tenant.
- [Cortex Cloud supported regions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/cortex-cloud-supported-regions.md)
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources.md)
- [Regional egress resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/regional-egress-resources.md)
- [Engines IP addresses (outbound)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/engines-ip-addresses-outbound.md)
- [Inbound source resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/inbound-source-resources.md)
- [FedRAMP and the US Federal Government required resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md)
- [Upgrade from Prisma Cloud to Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud.md)
- [About the Upgrade Helper](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/about-the-upgrade-helper.md)
- [Link Cortex Cloud to Prisma Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/link-cortex-cloud-to-prisma-cloud.md)
- [Copy content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content.md)
- [Copy Global configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-global-configurations.md)
- [Copy CSPM configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-cspm-configurations.md)
- [Copy CWP configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-cwp-configurations.md)
- [Copy Cortex Cloud Application Security configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-cortex-cloud-application-security-configurations.md)
- [Migrate Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/migrate-cortex-cli.md)
- [Set up users, groups, and roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles.md): Learn how to set up users and roles in Cortex Cloud.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles/user-group-management.md)
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles/assign-user-roles-and-groups.md): Assign roles and group memberships to users.
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/manage-api-keys.md)
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication.md): Authenticate Cortex Cloud users using SAML 2.0 or Customer Support Portal (CSP).
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate users through the Customer Support Portal.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/authenticate-users-using-sso.md): Configure SAML single sign-on for Cortex Cloud users.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta as a SAML 2.0 identity provider.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID as a SAML 2.0 identity provider.
- [Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding.md): Learn about onboarding your cloud service provider to Cortex Cloud.
- [Amazon Web Services cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding.md): Follow the AWS onboarding wizard, and Cortex Cloud creates a custom authentication template to be deployed in AWS.
- [AWS security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-capabilities-and-deployment-planning.md)
- [AWS resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-resource-inventory.md)
- [AWS security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-model-and-authentication.md)
- [Cortex Cloud and AWS audit log collection architecture](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/cortex-cloud-and-aws-audit-log-collection-architecture.md)
- [Onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/onboard-amazon-web-services.md): Follow the AWS onboarding wizard, and Cortex Cloud creates a custom authentication template to be executed in AWS.
- [Prerequisites for onboarding AWS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/prerequisites-for-onboarding-aws.md): Before you begin onboarding AWS, you must review the following prerequisites.
- [How to onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/how-to-onboard-amazon-web-services.md): Follow the AWS onboarding wizard and Cortex Cloud creates a custom authentication template to be deployed in AWS CloudFormation.
- [Deploy the authentication template in AWS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/deploy-the-authentication-template-in-aws.md): Learn how to deploy the Terraform or CloudFormation authentication template in Amazon Web Services.
- [Post-deployment: Custom (BYOB) and Control Tower audit log collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/post-deployment-custom-byob-audit-log-collection.md)
- [Grant cross-account KMS key access for Control Tower BYOB log collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/grant-cross-account-kms-key-access-for-control-tower-byob-log-collection.md): Learn how to configure cross-account AWS KMS key permissions for Cortex Control Tower BYOB log collection. Step-by-step guide to updating KMS key policies.
- [AWS post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-post-deployment-verification.md): After you have completed the AWS onboarding wizard and you have deployed the authentication template in AWS (using CloudFormation or Terraform), verify that the deployment succeeded.
- [Microsoft Azure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding.md)
- [Onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Prerequisites for onboarding Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/prerequisites-for-onboarding-azure.md): Before you begin onboarding Microsoft Azure, you must review the following prerequisites.
- [How to onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Finalize Microsoft Azure onboarding by executing the authentication template](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/finalize-microsoft-azure-onboarding-by-executing-the-authentication-template.md): Learn how to execute the authentication template file in Microsoft Azure for subscriptions, tenants, and management groups. We provide instructions both for applying the Terraform template's configura
- [Microsoft Azure offboarding overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview.md): This section contains the technical procedures required to safely decommission and offboard your Cortex Cloud resources in Microsoft Azure.
- [Offboard Terraform-based Azure deployments (all scopes)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-terraform-based-azure-deployments-all-scopes.md): How to offboard all Terraform-based Microsoft Azure scopes from Cortex Cloud: A step-by-step technical guide to safely running Terraform destroy and cleaning up policy-deployed resources.
- [Offboard Azure subscription (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-subscription-arm.md): How to offboard a Microsoft Azure subscription scope that was onboarded using ARM: A step-by-step technical guide to safely running the interactive offboarding script and cleaning up all resources.
- [Offboard Azure management group or tenant scope (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-management-group-or-tenant-scope-arm.md): How to offboard Microsoft Azure management group or tenant scopes from Cortex Cloud: A step-by-step technical guide to safely removing all Azure resources deployed by Cortex onboarding templates.
- [Offboard Azure tenant with Entra ID only](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-tenant-with-entra-id-only.md): How to offboard a Microsoft Azure tenant onboarded with the Entra ID only option from Cortex Cloud: A step-by-step technical guide to safely removing deployed resources.
- [Google Cloud Platform cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding.md)
- [Onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex creates a custom authentication template to be executed in GCP.
- [Prerequisites for onboarding GCP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/prerequisites-for-onboarding-gcp.md): Before you begin onboarding GCP, you must review the following prerequisites.
- [How to onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex Cloud creates a custom authentication template to be applied in GCP.
- [Deploy the Terraform authentication template in GCP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/deploy-the-terraform-authentication-template-in-gcp.md): Learn how to deploy the Terraform authentication template in Google Cloud Console.
- [Connect Google Workspace with your GCP cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/connect-google-workspace-with-your-gcp-cloud-instance.md)
- [Monitor GCP resources inside service perimeters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/monitor-gcp-resources-inside-service-perimeters.md): Learn how to grant authorization to Cortex Cloud to scan within your GCP service perimeter.
- [Oracle Cloud Infrastructure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding.md): Follow the Oracle Cloud Infrastructure onboarding wizard and Cortex Cloud creates a custom Terraform authentication template to be deployed in Oracle Cloud Infrastructure.
- [Onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard, and Cortex creates a custom authentication template to be executed in OCI.
- [Prerequisites for onboarding OCI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/prerequisites-for-onboarding-oci.md): Before you begin onboarding Oracle Cloud Infrastructure, you must review the following prerequisites.
- [How to onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/how-to-onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard and Cortex Cloud creates a custom authentication template to be applied in OCI.
- [Deploy the Terraform authentication template in OCI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/deploy-the-terraform-authentication-template-in-oci.md): Learn how to deploy the Terraform authentication template in Oracle Cloud Infrastructure.
- [Alibaba Cloud cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding.md): Follow the Alibaba Cloud onboarding wizard and Cortex Cloud creates a custom Terraform authentication template to be deployed in Alibaba Cloud.
- [Alibaba security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-security-capabilities-and-deployment-planning.md)
- [Alibaba Cloud resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-resource-inventory.md)
- [Alibaba Cloud security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-security-model-and-authentication.md)
- [Onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/onboard-alibaba-cloud.md): Follow the Alibaba Cloud onboarding wizard and Cortex Cloud creates a custom CloudFormation authentication template to be deployed in Alibaba Cloud.
- [Prerequisites for onboarding Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/prerequisites-for-onboarding-alibaba-cloud.md): Before you begin onboarding Alibaba Cloud, you must review the following prerequisites.
- [How to onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/how-to-onboard-alibaba-cloud.md)
- [Alibaba Cloud post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-post-deployment-verification.md): After you have completed the Alibaba Cloud onboarding wizard and you have deployed the authentication template in Alibaba Cloud, verify that the deployment succeeded.
- [Outpost onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding.md): Learn about outposts, which are a dedicated set of infrastructure resources that extends the reach of Cortex Cloud into your environment.
- [Outpost fundamentals and planning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-fundamentals-and-planning.md): An outpost enables you to have security scans performed on infrastructure in a cloud account owned by you. Learn about outpost fundamentals and what to consider when planning your outpost.
- [Outpost creation workflow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-creation-workflow.md): Learn about the creation process for an outposts, which facilitate security scanning performed on infrastructure in a cloud account owned by you.
- [Working with standard outposts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts.md): Standard outposts are the recommended way to create dedicated set of infrastructure resources that extends the reach of Cortex Cloud into your environment.
- [Create a standard outpost](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts/create-a-standard-outpost.md): Instructions for creating a standard outpost while onboarding your CSP.
- [Working with Bringing your own Azure app (BYOA) outposts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts.md): Using advanced settings while creating your outpost, you can deploy a Cortex Cloud Azure outpost using your own pre-created Entra ID app registration.
- [Task 1: Meet the prerequisites for Azure BYOA outposts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-1-meet-the-prerequisites-for-azure-byoa-outposts.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page lists the prerequisites that must be met before customizing your outpost in this way.
- [Task 2: Create the app registration for the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-2-create-the-app-registration-for-the-azure-byoa-outpost.md): You can customize your own outpost for Azure by bringing your own app (BYOA). This page describes the steps for creating the app registration.
- [Task 3: Deploy the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-3-deploy-the-azure-byoa-outpost.md): You can customize your own outpost by bringing your own app (BYOA). This page describes the steps for deploying the Azure BYOA outpost.
- [Task 4: Verify the BYOA outpost deployment](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-4-verify-the-byoa-outpost-deployment.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page describes the steps for verifying your BYOA outpost deployment.
- [The shell script for Azure app registration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/the-shell-script-for-azure-app-registration.md): You can run this helper shell script to set up your resources and retrieve their IDs for use while creating your Azure BYOA outpost. This page provides technical, "read-me style" details about the scr
- [Outpost troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-troubleshooting.md): Check here for solutions to issues that might occur while configuring, deploying, and operating outposts.
- [Outpost Cloud Service Provider (CSP) permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions.md): This page lists and explains the various roles and permissions needed for working with resources for outposts by CSP.
- [Amazon Web Services (AWS) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/amazon-web-services-aws-outpost-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex Cloud outpost onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/microsoft-azure-outpost-permissions.md): List of Microsoft Azure provider outpost permissions for Cortex Cloud.
- [Google Cloud Platform (GCP) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/google-cloud-platform-gcp-outpost-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex Cloud onboarding outposts to enable continuous monitoring in your cloud environment.
- [Introduction to Terraform for Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/introduction-to-terraform-for-cloud-service-provider-csp-onboarding.md): Learn how to onboard Cloud Service Providers (CSPs) using Terraform. Discover step-by-step workflows for initial provisioning, updates, and Cloud Shell deployment.
- [Manually connect a cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/manually-connect-a-cloud-instance.md)
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/manage-cloud-instances.md): Learn how to manage, edit, and troubleshoot cloud instances in Cortex Cloud. Monitor connector health, view security capabilities, and investigate errors.
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/pending-cloud-instances.md)
- [Edit your onboarded CSP configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/edit-your-onboarded-csp-configuration.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/update-cloud-permissions-after-cortex-release-updates.md): Manage permission updates for your cloud instances following new feature releases or bug fixes.
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/troubleshoot-errors-on-cloud-instances.md): You can troubleshoot errors on cloud instances by drilling down on an instance from the Data Sources & Integrations page.
- [Cloud service provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions.md): Grant the correct cloud service provider permissions for Cortex Cloud.
- [Amazon Web Services (AWS) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/amazon-web-services-aws-provider-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex Cloud onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/microsoft-azure-provider-permissions.md): List of Microsoft Azure provider permissions for Cortex Cloud.
- [Google Cloud Platform (GCP) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/google-cloud-platform-gcp-provider-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex Cloud onboarding to enable continuous monitoring in your cloud environment.
- [Oracle Cloud Infrastructure (OCI) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/oracle-cloud-infrastructure-oci-provider-permissions.md): List of Oracle Cloud Infrastructure provider permissions for Cortex Cloud.
- [Onboard the Kubernetes Connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/onboard-the-kubernetes-connector.md)
- [What's new in Kubernetes Connector?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/onboard-the-kubernetes-connector/whats-new-in-kubernetes-connector.md)
- [Supported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/onboard-the-kubernetes-connector/supported-kubernetes-distributions.md)
- [FedRAMP overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview.md)
- [Cortex Cloud federal compliance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview/cortex-cloud-federal-compliance.md)
- [Onoarding & configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview/onoarding-and-configuration.md)
- [Limitations & supported regions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview/limitations-and-supported-regions.md)
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps.md)
- [Set up your environment](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment.md): Learn more about setting up the Cortex Cloud environment based on your preferences.
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/configure-server-settings.md)
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/configure-security-settings.md)
- [Data and log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding.md)
- [Forward logs and data from Cortex Cloud to external services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services.md)
- [Configure external applications for forwarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding.md)
- [Forward notifications to Amazon SQS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqs.md)
- [Forward notifications to Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-s3.md)
- [Forward notifications to Splunk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-splunk.md)
- [Forward notifications to webhook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-webhook.md)
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver.md)
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/integrate-slack-for-outbound-notifications.md)
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-notification-forwarding.md)
- [Set up email notifications for tenant updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/set-up-email-notifications-for-tenant-updates.md)
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/monitor-administrative-activity.md)
- [Data and log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats.md)
- [Management audit log messages](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-messages.md)
- [Issue notification format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/issue-notification-format.md)
- [Agent Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/agent-audit-log-notification-format.md)
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-notification-format.md)
- [Log format for IOC and BIOC issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/log-format-for-ioc-and-bioc-issues.md)
- [Analytics log format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/analytics-log-format.md)
- [Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/cortex-mcp-server.md): The Cortex MCP server enables you to leverage Cortex's powerful capabilities directly through natural language.
- [Install the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/cortex-mcp-server/install-the-cortex-mcp-server.md)
- [Configure the MCP client](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/cortex-mcp-server/configure-the-mcp-client.md)
- [Use the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/cortex-mcp-server/use-the-cortex-mcp-server.md)
- [Create custom Cortex MCP server tools](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/cortex-mcp-server/create-custom-cortex-mcp-server-tools.md)
- [Manage user roles and access management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management.md): Learn how to manage access for users, user roles, user groups, and Single Sign-On (SSO) for users on a specific Cortex Cloud tenant.
- [Manage user roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-roles.md)
- [Manage user access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md)
- [User access reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access/user-access-reference-information.md)
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope.md)
- [Manage access to objects](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects.md)
- [Manage access to custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-custom-dashboards.md)
- [Manage access to report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-report-templates.md)
- [Manage access to playbooks and scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-playbooks-and-scripts.md)
- [Manage access to saved queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-saved-queries.md)
- [Configure the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant.md)
- [Agentic Assistant components and concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agentic-assistant-components-and-concepts.md): Learn about the key components and concepts, such as agents and actions in the Cortex Agentic Assistant
- [Agentic Assistant Hub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub.md): Learn about personal and system agents in in the Agentic Assistant Hub
- [Manage actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-actions.md)
- [Register actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/register-actions.md)
- [Manage agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-agents.md)
- [Build agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/build-agents.md)
- [Manage knowledge sources (preview)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-knowledge-sources-preview.md): Enhance AI agent capabilities by leveraging the Knowledge Center (preview) to provide agents with your business-specific source of truth and built-in Cortex (system) knowledge.
- [Expand agent capabilities with MCP integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/expand-agent-capabilities-with-mcp-integrations.md)
- [Agentic Assistant role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agentic-assistant-role-based-access-control.md): Configure permissions to access Cortex Agentic Assistant features.
- [XQL query management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/xql-query-management.md): Administrators can set controls on running XQL queries.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/dashboards-and-reports.md)
- [Endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection.md): This topic provides an overview of traditional endpoint protection versus the protection of endpoints using Cortex Cloud.
- [Malware protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/malware-protection.md): Cortex Cloud prevents malware attacks and provides protection on endpoints based on the different operating systems.
- [Exploit protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/exploit-protection.md): Cortex Cloud prevents exploit attempts and provides protection on endpoints based on the different operating systems.
- [File analysis and protection flow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/file-analysis-and-protection-flow.md): The Cortex XDR agent utilizes advanced multi-method protection and prevention techniques to protect from both known and unknown malware and software exploits.
- [Endpoint protection capabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/endpoint-protection-capabilities.md): The endpoint protection capabilities vary depending on the platform (operating system) that is used on each of your endpoints.
- [Endpoint protection modules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/endpoint-protection-modules.md): Security modules are activated for your endpoints depending on the chosen security profile and the operating system on the endpoint.
- [Processes protected by exploit security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/processes-protected-by-exploit-security-policy.md): Application processes that run on your endpoint are protected by the exploit security policy.
- [File Integrity Monitoring (FIM)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/file-integrity-monitoring-fim.md): Learn about File Integrity Monitoring (FIM) capabilities in Cortex Cloud.
- [CaaS Workloads](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/caas-workloads.md)
- [WildFire analysis concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/wildfire-analysis-concepts.md): Learn about the analysis concepts used by Wildfire.
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Learn more about how to control Cortex XDR agent and content upgrades.
- [About content updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/about-content-updates.md): To increase security coverage and quickly resolve any issues in policy, Palo Alto Networks can seamlessly deliver software packages called content updates.
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/endpoint-data-collection.md): To aid in endpoint detection and issue investigation, the Cortex XDR agent collects endpoint information when an issue is generated.
- [Install and manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints.md): Learn how to set up profiles, policies and other settings for endpoint protection, how to install Cortex XDR agent on endpoints, and how to manage them after installation.
- [Set up endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection.md)
- [Set up endpoint profiles and exception rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules.md)
- [Set up malware prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md)
- [Set up exploit prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md)
- [Set up agent settings profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md)
- [Set up restrictions prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-restrictions-prevention-profiles.md)
- [Set up exception profiles and rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules.md)
- [Exception configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/exception-configuration.md)
- [Issue exclusions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions.md)
- [Add an issue exclusion rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions/add-an-issue-exclusion-rule.md)
- [Add an IOC or BIOC rule exception](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-an-ioc-or-bioc-rule-exception.md)
- [Add a disable prevention rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-prevention-rule-for-endpoints.md)
- [Add a disable injection and prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-injection-and-prevention-rule.md)
- [Add a support exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-support-exception-rule-for-endpoints.md)
- [Add a legacy exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints.md)
- [Add a new exceptions security profile](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-new-exceptions-security-profile.md)
- [Add a global endpoint policy exception](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-global-endpoint-policy-exception.md)
- [Set up Identity profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-identity-profiles.md)
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/define-endpoint-groups.md)
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/configure-global-agent-settings.md)
- [Apply profiles to endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/apply-profiles-to-endpoints.md)
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package.md)
- [Manage an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package/manage-an-agent-installation-package.md)
- [Harden endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security.md)
- [Device control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/device-control.md)
- [Host firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall.md)
- [Host firewall for Windows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-windows.md)
- [Host firewall for macos](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-macos.md)
- [Disk encryption](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/disk-encryption.md)
- [Host Inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-inventory.md)
- [Set a Cortex XDR agent Critical Environment version](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/set-a-cortex-xdr-agent-critical-environment-version.md)
- [Manage endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection.md)
- [Move agents between managing servers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/move-agents-between-managing-servers.md)
- [Manage endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags.md)
- [Create an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/create-an-endpoint-tag.md)
- [Remove an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/remove-an-endpoint-tag.md)
- [Track your endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/track-your-endpoint-tags.md)
- [Permanently remove Endpoint tags from the system](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/permanently-remove-endpoint-tags-from-the-system.md)
- [Set an alias for an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/set-an-alias-for-an-endpoint.md)
- [Manage endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-prevention-profiles.md)
- [Create a new prevention policy rule for serverless function](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/create-a-new-prevention-policy-rule-for-serverless-function.md)
- [View information about your endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/view-information-about-your-endpoint-prevention-profiles.md)
- [Upgrade Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/upgrade-cortex-xdr-agents.md)
- [Restart agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/restart-agent.md)
- [Uninstall the Cortex XDR agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/uninstall-the-cortex-xdr-agent.md)
- [Clear agent database](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/clear-agent-database.md)
- [Delete Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/delete-cortex-xdr-agents.md)
- [Manage agent tokens](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-agent-tokens.md)
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/retrieve-support-file-password.md)
- [Send push notifications to iOS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/send-push-notifications-to-ios.md)
- [Monitor agent operational status](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-operational-status.md)
- [Monitor agent activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md)
- [Monitor agent upgrade status](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-upgrade-status.md)
- [Endpoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp.md)
- [Cortex Data Loss Prevention (DLP) module overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview.md): Learn about Cortex Data Loss Prevention (DLP) module, which provides a solution to prevent sensitive data exfiltration.
- [Archive file classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/archive-file-classification.md)
- [True-file type detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/true-file-type-detection.md)
- [Personas workflow for DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/personas-workflow-for-dlp.md): The data security administrator and data security viewer are responsible for identifying DLP requirements for creating data-in-motion rules and investigating issues and cases.
- [Best Practices](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/best-practices.md)
- [Configure DLP end-to-end](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/configure-dlp-end-to-end.md)
- [DLP status in all endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/dlp-status-in-all-endpoints.md)
- [Cortex DLP threat detection and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-dlp-threat-detection-and-issues.md)
- [Extended Threat Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence.md): Research threats, investigate indicators, and apply intelligence across Cortex Cloud Runtime Security workflows.
- [XTI Threat Intel Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/xti-threat-intel-library.md): Research curated threat actors, malware families, vulnerabilities, and reports from Unit 42.
- [XTI Indicators](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/xti-indicators.md): Investigate, manage, and enrich threat indicators, including domains, IP addresses, URLs, and file hashes.
- [Threat intel context in cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md): Analyze indicator intelligence and Behavioral Threat Analysis (BTA) findings in cases and issues.
- [XTI indicator rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/xti-indicator-rules.md): Create rules that detect known threat indicators and generate issues from matching data.
- [Threat intel investigation through XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/threat-intel-investigation-through-xql.md): Query XTI indicators, threat objects, and their relationships using Cortex Query Language.
- [Threat Intel Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/threat-intel-dashboard.md): Visualize threat intelligence data to monitor distribution, ingestion health, and emerging trends.
- [Using XTI with Threat Intel Agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/using-xti-with-threat-intel-agent.md): Use the Threat Intel Agent to list, enrich, and update XTI indicators.
- [Using XTI in playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/extended-threat-intelligence/using-xti-in-playbooks.md): Automate XTI indicator triage, enrichment, and response with supported playbook commands.
- [Detection rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules.md)
- [What are detection rules?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules.md)
- [What's an IOC?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc.md)
- [IOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/ioc-rule-details.md)
- [Create an IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-an-ioc/create-an-ioc-rule.md)
- [What's a BIOC?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc.md)
- [BIOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/bioc-rule-details.md)
- [Create a BIOC rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/create-a-bioc-rule.md)
- [Manage Global BIOC Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-bioc/manage-global-bioc-rules.md)
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule.md)
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/correlation-rule-details.md)
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/create-a-correlation-rule.md)
- [Field replacement syntax in correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rules.md)
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/manage-correlation-rules.md)
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/monitor-correlation-rules.md)
- [Troubleshoot server errors in scheduled correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rules.md)
- [Manage IOC and BIOC rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/detection-rules/what-are-detection-rules/manage-ioc-and-bioc-rules.md)
- [Analytics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics.md)
- [Analytics overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-overview.md): Cortex Cloud uses an Analytics engine to examine logs and data from your sensors.
- [Analytics engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-engine.md)
- [Analytics sensors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-sensors.md)
- [Coverage of MITRE Attack tactics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/coverage-of-mitre-attack-tactics.md)
- [Review MITRE ATT\&CK framework coverage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/review-mitre-att-and-ck-framework-coverage.md)
- [Analytics detection time intervals](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-detection-time-intervals.md)
- [Analytics issues and Analytics BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/analytics-issues-and-analytics-biocs.md)
- [View and manage Analytics rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/view-and-manage-analytics-rules.md)
- [Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/identity-analytics.md)
- [AI Detection & Response in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud.md)
- [Data sources and supported services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/data-sources-and-supported-services.md)
- [Collect prompt logs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs.md)
- [Prompt log collection in AWS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/prompt-log-collection-in-aws.md)
- [Enable prompt log collection in Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure.md)
- [Configure the Azure Event Hub collection in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-cloud.md)
- [Set up prompt logging](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-logging.md)
- [Log HTTP data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-data.md)
- [Configure diagnostic settings:](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/analytics/ai-detection-and-response-in-cortex-cloud/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settings.md)
- [Identity Threat Detection and Response (ITDR)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr.md)
- [Get started with ITDR](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/get-started-with-itdr.md)
- [Manage role based access control (RBAC) in ITDR](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/manage-role-based-access-control-rbac-in-itdr.md)
- [Monitor user risk exposure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/monitor-user-risk-exposure.md)
- [Investigate user risk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/investigate-user-risk.md)
- [Manage user asset roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/asset-roles.md)
- [Improve Active Directory posture with AD-SPM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/active-directory-security-posture-management.md)
- [Enforce dynamic access control with CAP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/conditional-access-policy.md)
- [Prevent malicious LDAP queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/threat-management/identity-threat-module-itdr/prevent-malicious-ldap-queries.md)
- [Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/overview.md)
- [Personas workflow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/personas-workflow.md): Cortex API security distributes responsibilities across SOC analysts, security practitioners, and workload owners.
- [Secure your API landscape](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape.md)
- [Gain visibility and assess risk of API endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/gain-visibility-and-assess-risk-of-api-endpoints.md)
- [Monitor and investigate API threats](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/monitor-and-investigate-api-threats.md)
- [Configure API security from end to end](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/configure-api-security-from-end-to-end.md): Secure your API landscape through third-party integrations and agent-based protection policies.
- [API specification inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/web-and-api-security-waas/secure-your-api-landscape/api-specification-inventory.md)
- [Asset management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-management.md)
- [Asset inventory overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-inventory-overview.md): Learn about the core concepts, features, and lifecycle of assets within the Asset Inventory.
- [All assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/all-assets.md): Learn about the All Assets page, under Asset Inventory.
- [All cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/all-cloud-assets.md): Learn about the All Cloud Assets page to view and assess your cloud footprint.
- [Discovery Engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/all-cloud-assets/discovery-engine.md)
- [Asset hierarchy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/all-cloud-assets/asset-hierarchy.md)
- [Asset classes](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes.md): Accelerating remediation: Automated fix suggestions and manual remediation guidance enable developers to resolve code weaknesses directly in the source repository without context-switching to external
- [AI assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/ai-assets.md)
- [API assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/api-assets.md)
- [Application assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/application-assets.md)
- [Code and CI/CD assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/code-and-ci-cd-assets.md)
- [IaC resources assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/code-and-ci-cd-assets/iac-resources-assets.md)
- [Repository assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/code-and-ci-cd-assets/repository-assets.md)
- [VCS organization assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/code-and-ci-cd-assets/vcs-organization-assets.md)
- [CI/CD pipeline assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/code-and-ci-cd-assets/ci-cd-pipeline-assets.md)
- [CI/CD instances assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/code-and-ci-cd-assets/ci-cd-instances-assets.md)
- [Software package assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/code-and-ci-cd-assets/software-package-assets.md)
- [Compute assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/compute-assets.md)
- [Container image assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/compute-assets/container-image-assets.md)
- [Serverless functions assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/compute-assets/serverless-functions-assets.md)
- [VM images assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/compute-assets/vm-images-assets.md)
- [Data assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/data-assets.md)
- [Device assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/device-assets.md)
- [External Surface assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/external-surface-assets.md)
- [Website assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/external-surface-assets/website-assets.md)
- [Service assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/external-surface-assets/service-assets.md)
- [Domain assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/external-surface-assets/domain-assets.md)
- [Certificate assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/external-surface-assets/certificate-assets.md)
- [External Surface attribution evidence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/external-surface-assets/external-surface-attribution-evidence.md)
- [Identity assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/identity-assets.md)
- [Network assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/network-assets.md)
- [Security services assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-classes/security-services-assets.md)
- [Asset groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-groups.md): Group assets based on shared attributes to address them collectively, simplify filtering, and enable strict access control boundaries.
- [Manage Risk Scores](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/manage-asset-scores.md): View and investigate User Scores and Host Scores using the Risk Scores page to identify high-risk assets and detect compromised accounts or malicious activities.
- [Asset configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-configurations.md)
- [Network configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-configurations/network-configuration.md): Configure your internal network parameters, trusted networks, and external IP ranges to help Cortex Cloud identify and map your network assets.
- [Application criteria](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-configurations/application-criteria.md)
- [Asset Roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-configurations/asset-roles.md): View asset roles and the number of assets that are associated with each role. Learn how to manage asset roles for users and endpoints.
- [Manage Asset Roles for Endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-configurations/asset-roles/manage-asset-roles-for-endpoints.md)
- [Manage Asset Roles for Users](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-configurations/asset-roles/manage-asset-roles-for-users.md)
- [Honey user](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/asset-managment/asset-configurations/asset-roles/manage-asset-roles-for-users/honey-user.md)
- [Overview of cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases.md)
- [What are cases?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases/what-are-cases.md)
- [Resolving cases with AI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases/resolving-cases-with-ai.md)
- [Case lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases/case-lifecycle.md)
- [Case thresholds](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases/case-thresholds.md)
- [Case scope and impact](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases/case-scope-and-impact.md)
- [Case and issue domains](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases/case-and-issue-domains.md)
- [Overview of case teams and roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/overview-of-cases/overview-of-case-teams-and-roles.md)
- [Case concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/case-concepts.md)
- [Issues, findings, and events](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/case-concepts/issues-findings-and-events.md)
- [Case grouping](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/case-concepts/case-grouping.md)
- [Case scoring](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/case-concepts/case-scoring.md)
- [What is Causality?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/case-concepts/what-is-causality.md)
- [Analyze and resolve cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases.md): Learn how to analyze and resolve cases.
- [Review all cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/review-all-cases.md)
- [Start case analysis](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/start-case-analysis.md)
- [Agentic Assistant- Case Investigation agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/start-case-analysis/agentic-assistant-case-investigation-agent.md)
- [Establish case context](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/establish-case-context.md)
- [AI-generated case summaries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/establish-case-context/ai-generated-case-summaries.md)
- [Assess case severity and score](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/establish-case-context/assess-case-severity-and-score.md)
- [Update case attributes](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/establish-case-context/update-case-attributes.md)
- [Analyze case details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details.md)
- [Grouping graph](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/grouping-graph.md)
- [Evidence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/evidence.md)
- [Issue feed](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/issue-feed.md)
- [Associated assets and artifacts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/associated-assets-and-artifacts.md)
- [MITRE ATT\&CK tactics and techniques](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/mitre-att-and-ck-tactics-and-techniques.md)
- [Compliance standards and controls](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/compliance-standards-and-controls.md)
- [Case timeline](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/case-timeline.md)
- [Detailed view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/detailed-view.md)
- [Resolve the case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/resolve-the-case.md)
- [Resolution Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/resolution-center.md)
- [Collaborative notes and comments](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/collaborative-notes-and-comments.md)
- [How to resolve a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/resolve-a-case.md)
- [Resolution reasons for cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/resolution-reasons-for-cases-and-issues.md)
- [Monitor and track resolution times](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/monitor-and-track-resolution-times.md)
- [Additional case actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/additional-case-actions.md)
- [Create a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/create-a-case.md)
- [Merge a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/merge-a-case.md)
- [Assign a case team and restrict access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access.md)
- [Playbook examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access/playbook-examples.md)
- [Investigation and response](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response.md)
- [Investigate issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues.md): Cortex Cloud generates issues to bring your attention to security risks in your framework.
- [Overview of the Issues page](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/overview-of-the-issues-page.md)
- [Issue card](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-card.md)
- [Resolution actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/resolution-actions.md)
- [Link or unlink issues from a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/link-or-unlink-issues-from-a-case.md)
- [Run an automation on an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/run-an-automation-on-an-issue.md)
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/use-the-war-room-in-an-investigation.md)
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md)
- [Issue syncing](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-syncing.md)
- [Issue deduplication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-deduplication.md)
- [Causality view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/causality-view.md)
- [Cloud causality view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/causality-view/cloud-causality-view.md)
- [Cloud causality view for audit log issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/causality-view/cloud-causality-view-for-audit-log-issues.md): Investigate cloud attacks faster with entity context directly in the Cloud causality view.
- [SaaS causality view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/causality-view/saas-causality-view.md)
- [Network causality view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/causality-view/network-causality-view.md)
- [Timeline](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/causality-view/timeline.md)
- [Causality icons key](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/causality-view/causality-icons-key.md)
- [Issue investigation actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions.md)
- [Copy issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/copy-issues.md)
- [Update issue fields](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/update-issue-fields.md)
- [Create profile exceptions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/create-profile-exceptions.md)
- [Investigate contributing events](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/investigate-contributing-events.md)
- [Create a featured field](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/create-a-featured-field.md)
- [View generating BIOC or IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/view-generating-bioc-or-ioc-rule.md)
- [Add a file path to a malware profile allow list](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/add-a-file-path-to-a-malware-profile-allow-list.md)
- [Retrieve additional issue details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/retrieve-additional-issue-details.md)
- [Export issue details to a file](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/export-issue-details-to-a-file.md)
- [Exclude an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/exclude-an-issue.md)
- [Query case and issue data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md)
- [Review findings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/review-findings.md): Review findings for an asset to gain insights into an asset’s posture status.
- [Findings card](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/review-findings/findings-card.md)
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets.md): You can investigate specific artifacts and assets on dedicated views related to IP address, Network Assets, and File and Process Hash information.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-an-ip-address.md)
- [Investigate an asset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-an-asset.md)
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md)
- [Investigate a user](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-a-user.md)
- [Investigate endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints.md)
- [Overview of the Action Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/overview-of-the-action-center.md)
- [Initiate and monitor endpoint actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/overview-of-the-action-center/initiate-and-monitor-endpoint-actions.md)
- [Action Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/overview-of-the-action-center/action-center-reference-information.md)
- [Manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/manage-endpoints.md)
- [Retrieve files from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/retrieve-files-from-an-endpoint.md)
- [Retrieve support logs from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/retrieve-support-logs-from-an-endpoint.md)
- [Scan an endpoint for malware](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/scan-an-endpoint-for-malware.md)
- [Investigate files](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-files.md)
- [Manage file execution](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-files/manage-file-execution.md)
- [Manage quarantined files](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-files/manage-quarantined-files.md)
- [Review WildFire analysis details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-files/review-wildfire-analysis-details.md)
- [Import file hash exceptions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-files/import-file-hash-exceptions.md)
- [Cortex Assistant](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/cortex-assistant.md): Cortex Assistant is designed to streamline processes by simplifying case triaging, investigation, and remediation. It enables you to seamlessly uncover new insights on hashes, hosts, and more. You can
- [Cortex Assistant layout](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/cortex-assistant/cortex-assistant-layout.md)
- [Cortex Assistant capabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/cortex-assistant/cortex-assistant-capabilities.md)
- [Automation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation.md)
- [Quick Actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/quick-actions.md)
- [Automation Exclusion Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/automation-exclusion-center.md)
- [Manage automation exclusion policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/manage-automation-exclusion-policies.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks.md)
- [Playbooks overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/playbooks-overview.md)
- [Access to playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/access-to-playbooks.md)
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/playbook-development-checklist.md)
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/plan-your-playbook.md)
- [Manage playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/manage-playbooks.md)
- [Build your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook.md)
- [Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/choose-from-existing-playbooks-or-create-your-own.md)
- [Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/configure-playbook-settings.md)
- [Add objects from the Task Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library.md)
- [Add commands and scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-commands-and-scripts.md)
- [Add sub-playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-sub-playbooks.md)
- [Add AI Prompt tasks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-ai-prompt-tasks.md)
- [Add manual tasks and blank tasks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks.md): Add manual and blank tasks to a playbook.
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-standard-task.md): Define a Standard task in Cortex Cloud.
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-conditional-task.md): Create a Conditional task in a playbook.
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-communication-task.md): Communication tasks let you send surveys and collect issue data.
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/create-a-section-header.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/configure-script-error-handling-in-a-playbook.md)
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook.md)
- [Configure a sub-playbook loop](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/configure-a-sub-playbook-loop.md)
- [Filter and Transform data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/filter-and-transform-data.md)
- [Create custom filter and transformers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/create-custom-filter-and-transformers.md)
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/filter-considerations-categories-and-built-in-filters.md)
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/transformer-considerations-categories-and-built-in-transformers.md)
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/extend-context.md)
- [Extract Indicators](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/extract-indicators.md)
- [Update issue fields with playbook tasks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/update-issue-fields-with-playbook-tasks.md)
- [Test your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/test-your-playbook.md): Set breakpoints, conditional breakpoints, skips, and input or output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/test-your-playbook/troubleshoot-playbook-performance.md)
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/manage-playbook-content.md)
- [Accelerate playbook development using the Automation Engineer agent (preview)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview.md)
- [Automation Engineer prompt examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview/automation-engineer-prompt-examples.md)
- [Best practices for playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/playbooks/best-practices-for-playbooks.md)
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/ai-prompts.md)
- [AI prompts role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/ai-prompts/ai-prompts-role-based-access-control.md): Manage AI prompt permissions with role-based access control.
- [Use existing prompts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/ai-prompts/use-existing-prompts.md): Find, duplicate, and edit prompts from the Prompts Library.
- [Create a prompt](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/ai-prompts/create-a-prompt.md): Create or edit prompts, configure settings, and use them in agents or playbooks.
- [Write effective prompts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/ai-prompts/write-effective-prompts.md): Tips for creating effective AI prompts.
- [Create an automation rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/create-an-automation-rule.md): Learn how to create an automation rule for an issue.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts.md)
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts/use-existing-scripts.md)
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts/create-a-script.md)
- [Accelerate script development using the Automation Engineer agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts/accelerate-script-development-using-the-automation-engineer-agent.md)
- [Change the Docker image in a script](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts/change-the-docker-image-in-a-script.md)
- [Connect an engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts/change-the-docker-image-in-a-script/connect-an-engine-to-an-image-registry.md)
- [Context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data.md): Use context data to assist with the investigation and remediation process.
- [Issue context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data/issue-context-data.md)
- [Case context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data/case-context-data.md)
- [Search context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data/search-context-data.md)
- [Add context data to an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data/add-context-data-to-an-issue.md)
- [Add context data to a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data/add-context-data-to-a-case.md)
- [Delete context data from a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data/delete-context-data-from-a-case.md)
- [Use context data in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/context-data/use-context-data-in-a-playbook.md)
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/lists.md)
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/lists/create-a-list.md)
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/lists/list-commands.md)
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/lists/use-cases-json-lists.md)
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/lists/transform-a-list-into-an-array.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/integrations.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/integrations/add-an-integration-instance.md)
- [Use integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/integrations/use-integration-commands-in-the-cli.md)
- [Troubleshoot integations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/integrations/troubleshoot-integations.md)
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/integrations/manage-credentials.md)
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine.md): Install, deploy and configure Cortex Cloud engines.
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker.md): Install, configure, secure, and troubleshoot Docker for Cortex Cloud engines.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/install-docker.md): Install Docker and verify engine user permissions.
- [Install Docker distribution for Red Hat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/install-docker-distribution-for-red-hat.md): Configure Docker and SELinux on Red Hat engine servers.
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-image-security.md): Secure, harden, and troubleshoot Docker images and containers.
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-faqs.md)
- [Troubleshoot Docker Issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
- [Change the Docker Installation folder](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide.md)
- [Docker network hardening](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/docker-network-hardening.md)
- [Configure Docker images](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-docker-images.md)
- [Run Docker with non-root internal users](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
- [Configure the memory limit support without swap capabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limit-support-without-swap-capabilities.md)
- [Configure the memory limitation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limitation.md)
- [Configure the CPU, PIDs, and open the file descriptors limit](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-cpu-pids-and-open-the-file-descriptors-limit.md)
- [Check Docker hardening configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/check-docker-hardening-configurations.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman.md): Install, configure, and troubleshoot Podman for Cortex Cloud engines.
- [Change the Container storage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/change-the-container-storage.md): Configure Podman container storage for an engine.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/install-podman.md): Install and configure Podman for Cortex Cloud engines.
- [Migrate from Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/migrate-from-docker-to-podman.md): Migrate an existing engine from Docker to Podman.
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/troubleshoot-podman.md): Resolve common Podman issues on Cortex Cloud engines.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/manage-engines.md): Manage engines and load balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/upgrade-an-engine.md): Upgrade an engine on Cortex Cloud or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/configure-engines.md): Configure Cortex Cloud engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md)
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/configure-engines/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/use-an-engine-in-an-integration.md): Use an engine or a load-balancing group of engines to fetch issues and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/engines/troubleshoot-integrations-running-on-engines.md)
- [Response actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions.md): During the case investigation, various response actions are available.
- [Initiate a Live Terminal session](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions/initiate-a-live-terminal-session.md)
- [Isolate an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions/isolate-an-endpoint.md)
- [Pause endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions/pause-endpoint-protection.md)
- [Remediate changes from malicious activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions/remediate-changes-from-malicious-activity.md)
- [Search and destroy malicious files](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions/search-and-destroy-malicious-files.md)
- [Manage external dynamic lists](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions/manage-external-dynamic-lists.md)
- [Collect a memory image](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/response-actions/collect-a-memory-image.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics.md)
- [Forensic investigations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations.md)
- [Manage an investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/manage-an-investigation.md)
- [Create a new investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/manage-an-investigation/create-a-new-investigation.md): Create a forensic investigation, assign access, and start a data collection.
- [Edit an investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/manage-an-investigation/edit-an-investigation.md): Update an active investigation's details and user access.
- [Close an investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/manage-an-investigation/close-an-investigation.md): Close an investigation and manage its 24-hour grace period.
- [User permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/manage-an-investigation/user-permissions.md): You can assign users to the investigation for them to view and manage the investigation.
- [Data collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/data-collection.md)
- [Hunting](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/data-collection/hunting.md)
- [Triage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/data-collection/triage.md)
- [Configure collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/data-collection/configure-collection.md)
- [Analysis and documentation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/analysis-and-documentation.md)
- [Review alerts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/analysis-and-documentation/review-alerts.md)
- [Investigation timeline](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/analysis-and-documentation/investigation-timeline.md)
- [Key assets & artifacts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/analysis-and-documentation/key-assets-and-artifacts.md)
- [Export](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/forensics/forensic-investigations/export.md)
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md)
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md)
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md)
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md)
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/create-xql-query.md)
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md)
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md)
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/graph-query-results.md)
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder.md): Learn more about the entities in the Legacy Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-authentication-query.md)
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-event-log-query.md)
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-file-query.md)
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-image-load-query.md)
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-network-connections-query.md)
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-network-query.md)
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-process-query.md)
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/create-registry-query.md)
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/query-across-all-entities.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md)
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/overview-of-the-query-center/query-center-reference-information.md)
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md)
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/manage-your-personal-query-library.md): Cortex Cloud provides as part of the Query Library a personal library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/build-xql-queries/manage-your-macros.md)
- [Quick Launcher](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/quick-launcher.md): The Quick Launcher provides a quick, in-context shortcut that you can use to search for information, perform common investigation tasks, or initiate actions.
- [Research a known threat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/research-a-known-threat.md): Cortex Cloud enables you to investigate any threat, also referred to as a lead, which has been detected.
- [Customize cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues.md): Customize your cases and issues for specific requirements.
- [Set up case scoring](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/set-up-case-scoring.md)
- [Create a starring configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-a-starring-configuration.md)
- [Create SLAs for case and issue resolution](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-slas-for-issue-resolution.md): Create SLA rules to set and track issue-resolution timers and time goals.
- [Create additional case timers and SLAs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas.md)
- [Update case timer and SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas/update-case-timer-and-sla-fields.md)
- [Create issue exceptions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-issue-exceptions.md): Create time-bound exceptions that pause issue SLA timers during approved remediation delays.
- [Configure the issue exception approval workflow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/configure-the-issue-exception-approval-workflow.md): Manage approvers and approval requirements for issue exception rules.
- [Create issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/create-issue-exception-rules.md): Create approval-based rules that temporarily pause SLA timers for selected issues.
- [Create an exception rule from an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/create-an-exception-rule-from-an-issue.md)
- [View issue Exception Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/view-issue-exception-rules.md)
- [Disable issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/disable-issue-exception-rules.md)
- [View excepted issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/view-excepted-issues.md)
- [Optimize case grouping in correlations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/optimize-case-grouping-in-correlations.md)
- [Create a sync profile](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/customize-cases-and-issues/create-a-sync-profile.md)
- [Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat.md): Chat with the Cortex Agentic Assistant using natural language prompts.
- [Get started with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat/get-started-with-agentic-assistant-chat.md): Enable Agentic Assistant and access the chat interface.
- [Choose an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat/choose-an-agentic-assistant-agent.md): Choose a system or custom agent for your chat.
- [Chat with an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat/chat-with-an-agentic-assistant-agent.md): Tips for chatting with the Cortex Agentic Assistant
- [Chat with the Agentic Assistant from Slack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat/chat-with-the-agentic-assistant-from-slack.md): Enable chatting with an Agentic Assistant agent from Slack.
- [Create and run XQL queries with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat/create-and-run-xql-queries-with-agentic-assistant-chat.md): Interact with Cortex Agentic Assistant agents to build and run XQL queries.
- [Use natural language to query and visualize your data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat/use-natural-language-to-query-and-visualize-your-data.md): Prompt Cortex Agentic Assistant agents to create graphs and charts from its findings.
- [Manage chat history](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/agentic-assistant-chat/agentic-assistant-chat/manage-chat-history.md): Manage and navigate your past chats with the Cortex Agentic Assistant.
- [Monitor dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports.md)
- [Overview of dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports.md)
- [Dashboard interface basics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basics.md)
- [Dashboard types](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-types.md)
- [Report basics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/report-basics.md)
- [Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/widget-library.md)
- [Access and visibility for dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports.md)
- [Visibility settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settings.md)
- [Access to widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgets.md)
- [Sharing icons](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-icons.md)
- [Access and sharing cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-and-sharing-cheat-sheet.md)
- [Manage dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports.md)
- [Dashboard Manager](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/dashboard-manager.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/reports.md)
- [Duplicate dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reports.md)
- [Share custom dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templates.md)
- [Change ownership to dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templates.md)
- [Import and export dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templates.md)
- [Configure the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-report.md)
- [Deleted content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/deleted-content.md)
- [Create dashboards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/create-dashboards.md)
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/create-dashboards/create-a-dashboard.md)
- [Create reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/create-reports.md)
- [Create a report template from scratch](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/create-reports/create-a-report-template-from-scratch.md)
- [Advanced configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration.md)
- [Create custom widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets.md)
- [Create widgets using AI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-ai.md)
- [Create XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets.md)
- [Add parameters to a custom XQL widget](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widget.md)
- [Create script-based widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgets.md)
- [Configure global filters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/configure-global-filters.md)
- [Configure drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/configure-drilldowns.md)
- [Dashboard reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference.md)
- [Command Center reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/command-center-reference.md)
- [Cortex Agentic Assistant dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-agentic-assistant-dashboard.md)
- [Cortex Cloud Command Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-cloud-command-center.md)
- [System dashboards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md)
- [Cortex Cloud Consumption](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cortex-cloud-consumption.md)
- [Cloud Security Operations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cloud-security-operations.md)
- [Learn about the Discovery Engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/discovery-engine/discovery-engine.md)
- [What is Cortex Cloud AI Security?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-ai-security/what-is-cortex-cloud-ai-security.md): A basic overview of the Cortex Cloud AI Security overview page, assets inventory, risks, and benefits.
- [Supported services in Cortex Cloud AI Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-ai-security/supported-services-in-cortex-cloud-ai-security.md): A list of platforms and services that are compatible with Cortex Cloud AI Security.
- [Cortex Cloud AI Security concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-ai-security/cortex-cloud-ai-security-concepts.md): Basic concepts of Cortex Cloud AI Security.
- [Cortex Cloud AI Security use cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-ai-security/cortex-cloud-ai-security-use-cases.md): Learn about use cases that are relevant for Cortex Cloud AI Security.
- [How to perform advanced AI Security investigations using XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-ai-security/how-to-perform-advanced-ai-security-investigations-using-xql.md): Working with datasets in Cortex Cloud AI Security.
- [About Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-application-security/about-cortex-cloud-application-security.md)
- [Code-to Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud.md)
- [How the C2C engine works](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/how-the-c2c-engine-works.md)
- [Identify and investigate gap](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/identify-and-investigate-gap.md)
- [Remediation workflows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/execute-remediation-workflows.md)
- [The Coverage dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/the-coverage-dashboard.md)
- [C2C in Unified Asset Inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/c2c-in-unified-asset-inventory.md)
- [C2C tab (asset level)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/c2c-tab-asset-level.md)
- [C2C tab (app level)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/c2c-tab-app-level.md)
- [Agentix for C2C](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/agentix-for-c2c.md)
- [Investigate issues with C2C](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/investigate-issues-with-c2c.md)
- [C2C in ASPM Command Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/c2c-in-aspm-command-center.md)
- [Enforce policies with C2C](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/enforce-policies-with-c2c.md)
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/troubleshooting.md)
- [FAQs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/faqs.md)
- [References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references.md)
- [Reference A: Supported integrations and asset stages](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references/reference-a-supported-integrations-and-asset-stages.md)
- [Reference B: Coverage % calculation and configuration toggles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references/reference-b-coverage-calculation-and-configuration-toggles.md)
- [Reference C: Dashboard filters by view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references/reference-c-dashboard-filters-by-view.md)
- [Reference D: Recommended actions by view and stage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references/reference-d-recommended-actions-by-view-and-stage.md)
- [Reference E: Code-to-Cloud Coverage public API](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references/reference-e-code-to-cloud-coverage-public-api.md)
- [Page Reference F: Call-to-action routing by asset type1](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references/page-reference-f-call-to-action-routing-by-asset-type1.md)
- [Reference G: Unified Asset Inventory fields and deep links](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/code-to-cloud/code-to-cloud/references/reference-g-unified-asset-inventory-fields-and-deep-links.md)
- [Learn about Cloud ASM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/cloud-asm-concepts.md): Learn about Cloud ASM, including scanning and network mapping.
- [What is Cloud ASM?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/cloud-asm-concepts/what-is-cloud-asm.md): Cloud ASM provides visibility into all the assets in your cloud infrastructure that are exposed to the internet.
- [Scanning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/cloud-asm-concepts/scanning.md): Cortex Cloud provides targeted scanning of customer networks from an attributed scanning infrastructure.
- [Network mapping](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/cloud-asm-concepts/network-mapping.md): Through a network mapping process, Cortex Cloud discovers and attributes assets to organizations.
- [Enable Cloud ASM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/enable-cloud-asm.md): Enable Cloud ASM data discovery to discover all your unmanaged cloud services and cloud services exposed to the internet.
- [Attack surface management detections](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/attack-surface-management-detections.md): Learn about Attack Surface Management detections, including rules and externally inferred CVEs.
- [Attack surface rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/attack-surface-management-detections/attack-surface-rules.md): Attack surface rules are used to identify risks in your attack surface.
- [Externally inferred CVEs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/attack-surface-management-detections/externally-inferred-cves.md)
- [Attack surface assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/attack-surface-assets.md): The assets discovered in an attack surface management scan are called attack surface assets or external surface assets.
- [Review your unmanaged cloud services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/review-your-unmanaged-cloud-services.md): Review your unmanaged cloud services in your Attack Surface inventory.
- [Review unmanaged cloud issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-attack-surface-management/review-unmanaged-cloud-issues.md): View your unmanaged cloud issues, including service details.
- [About network exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/network-exposure-detection/network-exposure-detection.md): Identify, prioritize, and remediate internet, outbound, and lateral network exposure risks in public cloud environments.
- [What is Cloud Network Analyzer?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/network-exposure-detection/what-is-cloud-network-analyzer.md): Understand how CNA identifies internet, outbound, and lateral exposure across cloud accounts.
- [Internet exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/network-exposure-detection/internet-exposure-detection.md): Learn how CNA detects publicly reachable cloud assets and validates exposure through external network scanning.
- [Outbound exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/network-exposure-detection/outbound-exposure-detection.md): Learn about detecting workloads with unrestricted outbound internet access based on security configurations.
- [East-west exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/network-exposure-detection/east-west-exposure-detection.md): Learn about workloads with unrestricted lateral access and the controls causing that exposure.
- [Investigate an internet exposure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/network-exposure-detection/investigate-an-internet-exposure.md): Investigate internet-exposed assets through Issues and Graph Search.
- [Configure trusted IPs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/network-exposure-detection/configure-trusted-ips.md): Configure trusted public IP ranges excluded from CNA internet exposure evaluations.
- [About Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/cortex-cloud-data-classification.md)
- [How to create and validate a custom data pattern](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-pattern.md)
- [Custom data patterns: Guardrails and syntax guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-pattern/custom-data-patterns-guardrails-and-syntax-guide.md)
- [How to disable and enable data patterns in Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/how-to-disable-and-enable-data-patterns-in-data-classification.md)
- [How to create and validate a custom data profile](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-profile.md)
- [How to disable and enable data profiles in Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/how-to-disable-and-enable-data-profiles-in-cortex-cloud-data-classification.md)
- [How to report a false positive in Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/how-to-report-a-false-positive-in-cortex-cloud-data-classification.md)
- [Topic classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-classification/topic-classification.md)
- [What is Cortex Cloud Data Security?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-security/what-is-cortex-cloud-data-security.md): Learn about Cortex Cloud Data Security capabilities and benefits.
- [What is Cortex Cloud Identity Security?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/what-is-cortex-cloud-identity-security.md): Cortex Cloud Identity Security can help you address the security challenges of managing identity in cloud environments.
- [Review and improve your Identity Security posture](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/review-and-improve-your-identity-security-posture.md): Learn how to review and improve your Identity Security posture with the provided use case examples.
- [How does Effective Permission Calculation work?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/how-does-effective-permission-calculation-work.md): An explanation of how Effective Permission Calculation works in Cortex Cloud Identity Security.
- [Cortex Cloud Identity Security functionality](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/cortex-cloud-identity-security-functionality.md): About the functionalities of Cortex Cloud Identity Security.
- [Configure Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/configure-cortex-cloud-identity-security.md)
- [Unified Human Identities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/unified-human-identities.md)
- [Achieve the principle of least privilege access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/achieve-the-principle-of-least-privilege-access.md): Use Cortex Cloud Identity Security to achieve the principle of least privilege access.
- [Explore permissions using the simple and advanced access tables](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/explore-permissions-using-the-simple-and-advanced-access-tables.md): Learn how to explore permissions in Cortex Cloud Identity Security using the Simple and Advanced access tables.
- [Create a custom detection rule in Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/create-a-custom-detection-rule-in-cortex-cloud-identity-security.md): Learn how to create a custom detection rule in Cortex Cloud Identity Security.
- [Perform advanced Identity Security investigations using XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/perform-advanced-identity-security-investigations-using-xql.md): Working with datasets in Cortex Cloud Identity Security.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/ingest-logs-and-data-from-okta.md): Learn more about Ingesting logs and data from Okta for use in Cortex Cloud.
- [Enable inactive human identity logs on Azure in Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/enable-inactive-human-identity-logs-on-azure-in-cortex-cloud-identity-security.md): Configuration information for enabling inactive human identity logs on Azure.
- [Manage RBAC and SBAC in Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/manage-rbac-and-sbac-in-cortex-cloud-identity-security.md): Working with RBAC and SBAC in Cortex Cloud Identity Security.
- [SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security.md): SaaS Security delivers continuous visibility and control across SaaS identities, connected apps, and AI agents.
- [Setup SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/setup-saas-security.md): Get started with SaaS Security.
- [Onboard a Supported SaaS Application](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application.md): Onboard a supported SaaS application to track and monitor misconfigurations and compliance violations.
- [Onboard Aha.io](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-aha.io.md): Onboard Aha.io to track misconfigurations and monitor application compliance.
- [Onboard Asana](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-asana.md): Connect an Asana instance to detect posture risks and compliance violations.
- [Onboard Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-atlassian.md): Connect an Atlassian instance to detect posture and compliance risks.
- [Onboard Automox](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-automox.md): Connect an Automox  instance to detect posture risks and compliance violations.
- [Onboard Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-businessmap.md): Connect a Businessmap instance to detect posture risks and compliance violations.
- [Onboard Celonis](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-celonis.md): Connect a Celonis instance to detect posture risks and compliance violations.
- [Onboard Cisco Duo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-cisco-duo.md): Connect Cisco Duo instance to detect posture risks and compliance violations.
- [Onboard Cisco Meraki](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-cisco-meraki.md): Connect a Cisco Meraki instance to detect posture risks and compliance violations.
- [Onboard ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-clickup.md): Connect a ClickUp instance to detect posture risks and compliance violations.
- [Onboard Contentful](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-contentful.md): Connect a Contentful instance to detect posture risks and compliance violations.
- [Onboard Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-couchbase.md): Connect a Couchbase instance to detect posture risks and compliance violations.
- [Onboard Coveo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-coveo.md): Connect a Coveo instance to detect posture risks and compliance violations.
- [Onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-databricks.md): Connect a Databricks instance to detect posture risks and compliance violations.
- [Onboard Datadog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-datadog.md): Connect a Datadog instance to detect posture risks and compliance violations.
- [Onboard Gainsight PX](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-gainsight-px.md): Connect a Gainsight PX instance to detect posture risks and compliance violations.
- [Onboard Grammarly](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-grammarly.md): Connect a Grammarly instance to detect posture risks and compliance violations.
- [Onboard Harness](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-harness.md): Connect a Harness instance to detect posture risks and compliance violations.
- [Onboard Intercom](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-intercom.md): Connect an Intercom instance to detect posture risks and compliance violations.
- [Onboard Jamf Pro](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-jamf-pro.md): Connect a Jamf Pro instance to detect posture risks and compliance violations.
- [Onboard JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-jumpcloud.md): Connect a JumpCloud instance to detect posture risks and compliance violations.
- [Onboard Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-kustomer.md): Connect a Kustomer instance to detect posture risks and compliance violations.
- [Onboard Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-microsoft-entra-id.md): Connect a Microsoft Entra ID instance to detect posture risks and compliance violations.
- [Onboard Monday.com](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-monday.com.md): Connect a Monday.com instance to detect posture risks and compliance violations.
- [Onboard MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-mongodb-atlas.md): Connect a MongoDB Atlas instance to detect posture risks and compliance violations.
- [Onboard MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-mulesoft.md): Connect a MuleSoft instance to detect posture risks and compliance violations.
- [Onboard Mural](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-mural.md): Connect a Mural instance to detect posture risks and compliance violations.
- [Onboard Office 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-office-365.md): Connect an Office 365 instance to detect posture risks and compliance violations.
- [Onboard Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-okta.md): Connect an Okta instance to detect posture risks and compliance violations.
- [Onboard PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-pagerduty.md): Connect a PagerDuty instance to detect posture risks and compliance violations.
- [Onboard Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-redis-labs.md): Connect a Redis Labs instance to detect posture risks and compliance violations.
- [Onboard Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-salesforce.md): Connect a Salesforce instance to detect posture risks and compliance violations.
- [Onboard SAP Ariba](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-sap-ariba.md): Connect a SAP Ariba instance to detect posture risks and compliance violations.
- [Onboard Sentry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-sentry.md): Connect a Sentry instance to detect posture risks and compliance violations.
- [Onboard ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-servicenow.md): Connect a ServiceNow instance to detect posture risks and compliance violations.
- [Onboard Shopify](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-shopify.md): Connect a Shopify instance to detect posture risks and compliance violations.
- [Onboard Slack Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-slack-enterprise.md): Connect a Slack instance to detect posture risks and compliance violations.
- [Onboard Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-sumo-logic.md): Connect a Sumo Logic instance to detect posture risks and compliance violations.
- [Onboard Workday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-workday.md): Connect a Workday instance to detect posture risks and compliance violations.
- [Onboard Wrike](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-wrike.md): Connect a Wrike instance to detect posture risks and compliance violations.
- [Onboard YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/onboard-a-supported-saas-application/onboard-youtrack.md): Connect a YouTrack instance to detect posture risks and compliance violations.
- [SaaS Security Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-security-overview.md): This dashboard aggregates and presents security data from all four core SaaS Security pillars including: SSPM (Posture), SaaS Identity Security, SaaS Data Security, and SaaS Agent Security.
- [SaaS Security Checks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-security-checks.md): The dashboard captures key metrics to help you remediate SaaS assets at risk
- [Provider Instances Security Check](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/provider-instances-security-check.md): This page consolidates application security posture data across all onboarded instances
- [Detection Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/detection-rules.md): View Cloud Security Posture Rules
- [Remediation Actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/remediation-actions.md): Learn more about actions available to remediate Issues.
- [Create and monitor tickets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/create-and-monitor-tickets.md): Learn more about creating a synced ticket to remediate an issue.
- [SaaS AI Agent Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security.md): SaaS AI Agent Security helps you secure AI agents deployed across enterprise SaaS environments.
- [Setup SaaS Security for AISPM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/setup-saas-security-for-aispm.md): Get started with SaaS Agent Security.
- [Onboard SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents.md): Learn more about how to onboard specific AI Agents.
- [Onboard Atlassian Rovo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-atlassian-rovo.md): Connect Atlassian Rovo to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Box AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-box-ai-agents.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-chatgpt-enterprise.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Cursor Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-cursor-enterprise.md): Connect Cursor Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-gemini-enterprise.md): Connect Gemini Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard M365 Copilot](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-m365-copilot.md): Connect M365 Copilot to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Microsoft Copilot Studio](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-microsoft-copilot-studio.md): Connect Microsoft Copilot Studio to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Service Now](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-service-now.md): Connect Service Now to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Manage SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents.md)
- [View AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-ai-agents.md)
- [View Datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-datasets.md): The Datasets view provides a detailed look at the Inference Datasets.
- [View Agent Tools](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-agent-tools.md): SaaS Agent Tools go beyond traditional scans that  focus on an inventory of previously vendor vetted, underlying tools.
- [Vulnerability management in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-management-in-cortex-cloud.md): Vulnerability management helps you identify, assess, prioritize, and remediate security vulnerabilities across your entire IT infrastructure, including endpoints, code, and cloud.
- [Cortex Cloud vulnerability concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-management-in-cortex-cloud/cortex-cloud-vulnerability-concepts.md): Familiarize yourself with Cortex Cloud vulnerability concepts.
- [Vulnerability Management dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-management-in-cortex-cloud/vulnerability-management-dashboard.md): Visualize your most pressing risks, changes to risk over time, and remediation progress on the Vulnerability Management dashboard.
- [Cortex Vulnerability Risk Score](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/cortex-vulnerability-risk-score.md): Learn how Cortex Cloud calculates and displays CVRS to prioritize vulnerability remediation.
- [Vulnerability policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-policies.md): A vulnerability policy defines the action you want to take for a specific set of vulnerability findings.
- [Create a vulnerability policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-policies/create-a-vulnerability-policy.md): Create vulnerability policies that create issues or prevent findings based on defined conditions and scope.
- [Update the Ignored CVEs, Asset Groups, and Assets policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-policies/update-the-ignored-cves-asset-groups-and-assets-policy.md): Update the ignored CVEs, asset groups, and assets policy to prevent matching vulnerability findings from creating issues.
- [Modify a vulnerability policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-policies/modify-a-vulnerability-policy.md): Update issue-creation and prevention policies through the policy wizard.
- [Configure a block grace period](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-policies/configure-a-block-grace-period.md): Configure remediation grace periods that delay Kubernetes deployment blocks or build failures after vulnerability disclosure.
- [Enable or disable a vulnerability policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-policies/enable-or-disable-a-vulnerability-policy.md): Enable or disable issue-creation and prevention policies to control actions for matching findings.
- [Investigate and remediate vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/investigate-and-remediate-vulnerabilities.md): Investigate, prioritize, and remediate vulnerabilities through issues, findings, and vulnerable assets.
- [Vulnerability Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/vulnerability-intelligence.md): Vulnerability Intelligence is an in-product, real-time feed that provides vulnerability data and threat intelligence from a variety of certified upstream sources.
- [Emerging Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/emerging-vulnerabilities.md): The Emerging Vulnerabilities page is a a centralized hub for security teams to research, assess, and respond to global, emergent threats and zero-day exploits.
- [Recast CVSS scores and CVSS severities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/vunerability-management/recast-cvss-scores-and-cvss-severities.md): Customize CVSS scores and CVSS severities in the platform to align your risk management approach with your organizational context and priorities.
- [Cloud security rules and policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/cloud-security-rules-and-policies.md): Learn how cloud security rules and policies detect threats and misconfigurations across your environment.
- [Cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/cloud-security-rules.md): Learn about out-of-the-box and custom cloud security rules.
- [Cloud security policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/cloud-security-policies.md): Learn about cloud security policies.
- [Create and manage cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules.md): Create and manage custom cloud security rules for detecting cloud security risks.
- [Create a graph rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-graph-rule.md): Create custom graph detection rules that identify risky relationships and attack paths.
- [Create a configuration rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-configuration-rule.md): Create configuration rules that identify cloud resource misconfigurations and policy violations.
- [Create a data rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-data-rule.md): Create data rules to detect data risks, malware, and classification issues.
- [Create an identity rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-identity-rule.md): Create identity rules to detect excessive or unused cloud permissions.
- [Create a network exposure rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-network-exposure-rule.md): Create network exposure rules to detect risky inbound, outbound, and east-west access.
- [Create an AI rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-ai-rule.md): Create AI rules to detect risks and misconfigurations across your AI ecosystem.
- [Create an attack path rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-attack-path-rule.md): Create attack path rules that identify breach paths to high-value cloud assets.
- [View cloud security rule status](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/view-cloud-security-rule-status.md): View, filter, and sort the status of cloud security rules.
- [Edit a cloud security rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/edit-a-cloud-security-rule.md): Edit cloud security rules and understand how changes affect related issues.
- [Enable or disable a rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/enable-or-disable-a-rule.md): Enable or disable cloud security rules to control when they evaluate assets.
- [Use an existing rule to create a new one](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/use-an-existing-rule-to-create-a-new-one.md): Duplicate an existing cloud security rule and customize it for your needs.
- [Delete a custom cloud security rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/delete-a-custom-cloud-security-rule.md): Delete custom cloud security rules that are no longer needed.
- [Create and manage cloud security policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies.md): Create and manage cloud security policies.
- [Create a cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/create-a-cloud-security-policy.md): Create a cloud security policy that applies security rules to selected cloud assets.
- [Edit a cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/edit-a-cloud-security-policy.md): Edit cloud security policies to update their details, rules, and scopes.
- [Enable or disable a policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/enable-or-disable-a-policy.md): Enable or disable custom and default cloud security policies.
- [Use an existing policy to create a new one](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/use-an-existing-policy-to-create-a-new-one.md): Duplicate an existing cloud security policy and tailor it to your needs.
- [Delete a custom cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/delete-a-custom-cloud-security-policy.md): Remove custom cloud security policies that are no longer needed.
- [About cloud workload policies and rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies-and-rules.md)
- [How policies and rules work together](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/how-policies-and-rules-work-together.md)
- [Cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies.md)
- [Types of cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies.md)
- [Trusted image cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies/types-of-cloud-workload-policies.md)
- [Cloud Workload Policies page](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page.md)
- [Enable or disable a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/enable-or-disable-a-cloud-workload-policy.md)
- [Create a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/create-a-cloud-workload-policy.md)
- [Use an existing policy to create a new cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/use-an-existing-policy-to-create-a-new-cloud-workload-policy.md)
- [Edit a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/edit-a-cloud-workload-policy.md)
- [Delete a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/delete-a-cloud-workload-policy.md)
- [Cloud workload preventive action](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action.md)
- [Cloud workload rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules.md)
- [Default (pre-defined) rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules.md)
- [Custom (user-defined) rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules.md)
- [Cloud Workload Rules page](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page.md)
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules/create-a-new-custom-detection-rule.md)
- [Use an existing rule to create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules/use-an-existing-rule-to-create-a-new-custom-detection-rule.md)
- [Edit a custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules/edit-a-custom-detection-rule.md)
- [Delete a custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cloud-workload-policies-and-rules/cloud-workload-rules/delete-a-custom-detection-rule.md)
- [Learn about base image rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/base-image-rules/base-images-rule.md)
- [Create a base image rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/base-image-rules/create-a-base-images-rule.md)
- [Find the base image for an asset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/base-image-rules/prerequisites.md)
- [Monitor and track compliance adherence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence.md): Evaluate and track asset compliance against industry standards and organizational policies.
- [Choose compliance standards from the compliance catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog.md): Select built-in or custom compliance standards and controls from the compliance catalogs.
- [Standards catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/standards-catalog.md): Browse available compliance standards.
- [Controls catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/controls-catalog.md): Browse, filter, and review built-in and custom compliance controls.
- [Use a built-in or custom standard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-standard.md): Use built-in standards or create and edit custom standards for your organization.
- [Use a built-in or custom control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md): Add built-in controls or create and manage custom controls for custom standards.
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/create-a-new-custom-detection-rule.md): Create custom detection rules to enforce compliance requirements and security best practices.
- [Use an assessment profile to run compliance checks on your assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets.md): Create assessment profiles to evaluate selected asset groups against compliance standards.
- [Configuring assessments for custom compliance standards based on custom cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets/configuring-assessments-for-custom-compliance-standards-based-on-custom-cloud-security-rules.md): Configure policies and assessments for custom standards that use custom cloud security rules.
- [View and manage compliance assessments and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports.md): Review assessment results and generate or schedule downloadable compliance reports.
- [Review assessments](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/assessments.md): View assessment results and drill into control, rule, and asset compliance details.
- [Review reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/reports.md): View, export, and manage historical compliance assessment reports.
- [Compliance Overview Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/compliance/monitor-and-track-compliance-adherence/compliance-overview-dashboard.md): Monitor organization-wide compliance scores, standards, failed controls, and asset group performance.
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm.md)
- [What is the Broker VM?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/what-is-the-broker-vm.md)
- [Set up and configure Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm.md)
- [Broker VM image installations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations.md)
- [Set up Broker VM on Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-alibaba-cloud.md)
- [Set up Broker VM on Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-amazon-web-services.md)
- [Set up Broker VM on Google Cloud Platform (GCP)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-google-cloud-platform-gcp.md)
- [Set up Broker VM on KVM using Ubuntu](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-kvm-using-ubuntu.md)
- [Set up Broker VM on Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-azure.md)
- [Set up Broker VM on Microsoft Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-hyper-v.md)
- [Set up Broker VM on Nutanix Hypervisor](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-nutanix-hypervisor.md)
- [Set up Broker VM on VMware ESXi using vSphere Client](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-vmware-esxi-using-vsphere-client.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets.md)
- [Manage Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm.md)
- [Edit Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/edit-broker-vm-configuration.md)
- [Increase Broker VM storage allocated for data caching](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/increase-broker-vm-storage-allocated-for-data-caching.md)
- [Monitor Broker VM using Prometheus](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/monitor-broker-vm-using-prometheus.md)
- [Collect Broker VM Logs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/collect-broker-vm-logs.md)
- [Upgrade Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/upgrade-broker-vm.md)
- [Update Broker VM applets independently](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/update-broker-vm-applets-independently.md)
- [Import Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/import-broker-vm-configuration.md)
- [Open Live Terminal](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/open-live-terminal.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/add-broker-vm-to-cluster.md)
- [Switchover Primary Node in Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/switchover-primary-node-in-cluster.md)
- [Remove from Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm/remove-from-cluster.md)
- [Manage Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/manage-broker-vm-data-collector-applets.md)
- [Broker VM High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster.md)
- [Configure High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster/configure-high-availability-cluster.md)
- [Manage Broker VM clusters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters.md)
- [View cluster details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/view-cluster-details.md)
- [Edit cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/edit-cluster.md)
- [Add applet to cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-applet-to-cluster.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-broker-vm-to-cluster.md)
- [Remove cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/remove-cluster.md)
- [Broker VM notifications](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/broker-vm-notifications.md)
- [Monitor Broker VM activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/monitor-broker-vm-activity.md)
- [Troubleshoot Broker VM applet errors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/broker-vm/troubleshoot-broker-vm-applet-errors.md)
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period-based retention.
- [What are datasets?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/dataset-management/what-are-datasets.md): Learn how to import, delete, and interact with custom or third-party datasets in Cortex Cloud.
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/dataset-management/lookup-datasets.md): Learn more about lookup datasets to correlate data from a data source with events in your environment.
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/dataset-management/lookup-datasets/import-a-lookup-dataset.md)
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/dataset-management/lookup-datasets/download-json-file-of-lookup-dataset.md)
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/dataset-management/lookup-datasets/set-time-to-live-for-lookup-datasets.md)
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md): Learn more about the monitored Cortex Cloud datasets and dataset views activities.
- [Manage Event Forwarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/manage-event-forwarding.md): Save your ingested, parsed data in an external location by exporting your event logs to a temporary GCP storage bucket.
- [Upload to a temporary GCP storage bucket](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/manage-event-forwarding/upload-to-a-temporary-gcp-storage-bucket.md): Save your ingested, parsed data in an external location by exporting your event logs to a temporary GCP storage bucket.
- [Endpoints Event Forwarding - included/excluded fields by event type](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/manage-event-forwarding/endpoints-event-forwarding-includedexcluded-fields-by-event-type.md): Learn more about the included/excluded fields by event type for Endpoint Event Forwarding in Cortex Cloud.
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/manage-compute-units.md): Learn more about managing and tracking your compute units usage for API and Cold Storage XQL queries.
- [Compute units usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/data-management/manage-compute-units/compute-units-usage.md): Learn more about how to compute units CU) works according to your license and available options after reaching your quota.
- [What are Cortex Cloud data sources and connectors?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/what-are-cortex-cloud-data-sources.md): Learn more about Cortex Cloud data sources and connectors with a unified approach to integrations.
- [Complete data source and connector catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/complete-data-source-catalog.md): Learn more about the complete data source and connector catalog available in Cortex Cloud.
- [Vendor-specific data sources and connectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/abuseipdb.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/abuseipdb/abuseipdb.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/aiops.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/aiops/aiops.md)
- [Amazon](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon.md)
- [Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-s3.md)
- [Ingest audit logs from AWS CloudTrail](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-s3/ingest-audit-logs-from-aws-cloudtrail.md)
- [Ingest network flow logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-s3/ingest-network-flow-logs-from-amazon-s3.md)
- [Ingest generic logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-s3/ingest-generic-logs-from-amazon-s3.md)
- [Ingest network Route 53 logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-s3/ingest-network-route-53-logs-from-amazon-s3.md)
- [Create an assumed role](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-s3/create-an-assumed-role.md)
- [Configure data collection from Amazon S3 manually](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-s3/configure-data-collection-from-amazon-s3-manually.md)
- [Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-web-services.md)
- [AWS Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/aws-automation-and-collection.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anomali.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anomali/anomali.md)
- [Anthropic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anthropic.md)
- [Claude](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anthropic/claude.md)
- [API Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/api-security.md)
- [Ingest data for API security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/api-security/ingest-data-for-api-security.md)
- [Ingest AWS API Gateway](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-aws-api-gateway.md)
- [Ingest Azure APIM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-azure-apim.md)
- [Ingest Apigee Proxy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-apigee-proxy.md)
- [Ingest Kong](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-kong.md)
- [Ingest F5](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/api-security/ingest-data-for-api-security/ingest-f5.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/atlassian.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/atlassian/atlassian.md)
- [Atlassian Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/atlassian/atlassian-automation-and-collection.md)
- [BeyondTrust](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/beyondtrust.md)
- [BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/beyondtrust/beyondtrust-privilege-management-cloud.md)
- [Ingest logs from BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/beyondtrust/beyondtrust-privilege-management-cloud/ingest-logs-from-beyondtrust-privilege-management-cloud.md)
- [Box](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/box.md)
- [Ingest logs and data from Box](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/box/ingest-logs-and-data-from-box.md)
- [Check Point](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/check-point.md)
- [Check Point FW1/VPN1](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/check-point/check-point-fw1-vpn1.md)
- [Cisco](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cisco.md)
- [Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cisco/cisco-asa-firewalls-and-anyconnect.md)
- [Corelight](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/corelight.md)
- [Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/corelight/corelight-zeek.md)
- [Cribl](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cribl.md)
- [Cribl connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cribl/cribl-connector.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cyberark.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cyberark/cyberark.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/databricks.md)
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/databricks/databricks.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/databricks/databricks-1.md)
- [Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/dropbox.md)
- [Ingest logs and data from Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/dropbox/ingest-logs-and-data-from-dropbox.md)
- [Elastic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic.md)
- [Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic/elasticsearch-filebeat.md)
- [Ingest logs from Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic/elasticsearch-filebeat/ingest-logs-from-elasticsearch-filebeat.md)
- [Windows DHCP via Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic/windows-dhcp-via-elasticsearch-filebeat.md)
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic/windows-dhcp-via-elasticsearch-filebeat/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md)
- [ElasticSearch](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic/elasticsearch.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/forcepoint.md)
- [Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/forcepoint/forcepoint-dlp.md)
- [Fortinet](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/fortinet.md)
- [Fortinet Fortigate](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/fortinet/fortinet-fortigate.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/freshworks.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/freshworks/freshworks.md)
- [Generic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/generic.md)
- [Generic MCP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/generic/generic-mcp.md)
- [Generic SQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/generic/generic-sql.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/github.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/github/github.md)
- [Google](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google.md)
- [Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-cloud-platform.md)
- [Ingest logs and data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-cloud-platform/ingest-logs-and-data-from-a-gcp-pub-sub.md)
- [Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-kubernetes-engine.md)
- [Ingest logs from Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-kubernetes-engine/ingest-logs-from-google-kubernetes-engine.md)
- [Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace.md)
- [Ingest logs and data from Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace/ingest-logs-and-data-from-google-workspace.md)
- [Google Workspace connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace/google-workspace-connector.md)
- [Google Workspace Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace/google-workspace-automation-and-collection.md)
- [HTTP log collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/http-log-collector.md)
- [Set up an HTTP log collector to receive logs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/http-log-collector/set-up-an-http-log-collector-to-receive-logs.md)
- [IBM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ibm.md)
- [IBM QRadar](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ibm/ibm-qradar.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/izoologic.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/izoologic/izoologic.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/koi.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/koi/koi.md)
- [Kubernetes](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes.md)
- [Onboard the Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/onboard-the-kubernetes-connector.md)
- [What's new in Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/whats-new-in-kubernetes-connector.md)
- [Supported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/supported-kubernetes-distributions.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mail-utilities.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mail-utilities/mail-utilities.md)
- [Microsoft](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft.md)
- [Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/azure-event-hub.md)
- [Ingest logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/azure-event-hub/ingest-logs-from-microsoft-azure-event-hub.md)
- [Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-azure.md)
- [Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-entra-id.md)
- [Microsoft365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft365.md)
- [Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365.md)
- [Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365.md)
- [Ingest logs from Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365/ingest-logs-from-microsoft-office-365.md)
- [Microsoft Office 365 (email)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365-email.md)
- [Ingest logs and data from Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365-email/ingest-logs-and-data-from-microsoft-365.md)
- [Microsoft 365 (Posture)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365-posture.md)
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365-posture/how-to-onboard-microsoft-365.md)
- [Microsoft Teams](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-teams.md)
- [Microsoft Active Directory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-active-directory.md)
- [Microsoft Graph](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-graph.md)
- [Microsoft Identity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-identity.md)
- [Microsoft Security Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-security-automation-and-collection.md)
- [M365 Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/m365-automation-and-collection.md)
- [Monday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/monday.md)
- [Monday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/monday/monday.md)
- [MongoDB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mongodb.md)
- [MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mongodb/mongodb-atlas.md)
- [Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/okta.md)
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/okta/ingest-logs-and-data-from-okta.md)
- [Okta Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/okta/okta-automation-and-collection.md)
- [OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/onelogin.md)
- [Ingest logs and data from OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/onelogin/ingest-logs-and-data-from-onelogin.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/oracle.md)
- [Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/oracle/oracle-cloud-infrastructure.md)
- [PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/pagerduty.md)
- [PagerDuty Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/pagerduty/pagerduty-automation-and-collection.md)
- [Ping Identity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ping-identity.md)
- [PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ping-identity/pingfederate.md)
- [PingOne](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ping-identity/pingone.md)
- [Ingest authentication logs and data from PingOne](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ping-identity/pingone/ingest-authentication-logs-and-data-from-pingone.md)
- [Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/salesforce.md)
- [Ingest logs and data from Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/salesforce/ingest-logs-and-data-from-salesforce.md)
- [Salesforce connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/salesforce/ingest-and-run-salesforce-automation-and-remediation.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/servicenow.md)
- [ServiceNow Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/servicenow/servicenow-automation-and-collection.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/servicenow/servicenow.md)
- [Slack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/slack.md)
- [Slack Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/slack/slack-automation-and-collection.md)
- [Slack Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/slack/slack-enterprise.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/smb.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/smb/smb.md)
- [Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/snowflake.md)
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/snowflake/how-to-onboard-snowflake.md)
- [Workday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/workday.md)
- [Ingest report data from Workday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/workday/ingest-report-data-from-workday.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zendesk.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zendesk/zendesk.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zscaler.md)
- [Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zscaler/zscaler-internet-access.md)
- [Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zscaler/zscaler-private-access.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zscaler/zscaler.md)
- [Connectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/connectors.md)
- [Standard data sources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/standard-data-sources.md)
- [Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-service-provider-csp-onboarding.md): Learn more about onboarding cloud data sources to Cortex Cloud.
- [Generic on-premise data collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets.md)
- [Activate Apache Kafka Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-apache-kafka-collector.md)
- [Activate CSV Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-csv-collector.md)
- [Activate Database Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-database-collector.md)
- [Activate DSPM Fileshare](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-fileshare.md)
- [Activate Files and Folders Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-files-and-folders-collector.md)
- [Activate FTP Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-ftp-collector.md)
- [Activate Local Agent Settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-local-agent-settings.md)
- [Activate NetFlow Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-netflow-collector.md)
- [Activate Network Mapper](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-network-mapper.md)
- [Activate Registry Scanner](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-registry-scanner.md)
- [Syslog Collector applet](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet.md)
- [Activate Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/activate-syslog-collector.md)
- [Ingest logs from a Syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/ingest-logs-from-a-syslog-receiver.md): To extend visibility, Cortex Cloud can receive Syslog from additional vendors that use CEF or LEEF formatted over Syslog (TLS not supported).
- [Check Point FW1 VPN1](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1.md)
- [Ingest logs from Check Point firewalls](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1/ingest-logs-from-check-point-firewalls.md)
- [Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect.md)
- [Ingest logs from Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect/ingest-logs-from-cisco-asa-firewalls-and-anyconnect.md)
- [Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/corelight-zeek.md)
- [Ingest logs from Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/corelight-zeek/ingest-logs-from-corelight-zeek.md)
- [Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/forcepoint-dlp.md)
- [Ingest logs from Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/forcepoint-dlp/ingest-logs-from-forcepoint-dlp.md)
- [Fortinet Fortigate](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/fortinet-fortigate.md)
- [Ingest logs from Fortinet Fortigate firewalls](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/fortinet-fortigate/ingest-logs-from-fortinet-fortigate-firewalls.md)
- [Next Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/next-generation-firewall.md)
- [Ingest Next-Generation Firewall logs using the Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md)
- [PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/pingfederate.md)
- [Ingest authentication logs from PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/pingfederate/ingest-authentication-logs-from-pingfederate.md)
- [Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access.md)
- [Ingest logs from Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access/ingest-logs-from-zscaler-internet-access.md)
- [Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-private-access.md)
- [Ingest logs from Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-private-access/ingest-logs-from-zscaler-private-access.md)
- [Activate Transporter](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter.md)
- [Activate Windows Event Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector.md)
- [Activate Windows Event Collector on Windows Core](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector/activate-windows-event-collector-on-windows-core.md)
- [Renew WEC certificates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-windows-event-collector/renew-wec-certificates.md)
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors.md)
- [XDR Collector audit logs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-audit-logs.md)
- [XDR Collector machine requirements and supported operating systems](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-machine-requirements-and-supported-operating-systems.md)
- [Resources required to enable access to XDR collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/resources-required-to-enable-access-to-xdr-collectors.md)
- [Manage XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors.md)
- [XDR Collectors installation resource for Windows and Linux](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/xdr-collectors-installation-resource-for-windows-and-linux.md)
- [Create an XDR Collector installation package](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/create-an-xdr-collector-installation-package.md)
- [Install the XDR Collector installation package for Windows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows.md)
- [Install the XDR collector on Windows using the MSI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-the-msi.md)
- [Install the XDR Collector on Windows using Msiexec](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-msiexec.md)
- [Install the XDR Collector installation package for Linux](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-linux.md)
- [Configure XDR Collector upgrade scheduler](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/configure-xdr-collector-upgrade-scheduler.md)
- [Set an application proxy for XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/set-an-application-proxy-for-xdr-collectors.md)
- [Set an alias for an XDR Collector machine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/set-an-alias-for-an-xdr-collector-machine.md)
- [Upgrade XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/upgrade-xdr-collectors.md)
- [Uninstall the XDR Collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/uninstall-the-xdr-collector.md)
- [Define XDR Collector machine groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/define-xdr-collector-machine-groups.md)
- [About Cortex Cloud Collector content updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/manage-xdr-collectors/about-cortex-cloud-collector-content-updates.md)
- [XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles.md)
- [Add an XDR Collector profile for Windows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows.md)
- [How to configure XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/how-to-configure-xdr-collector-profiles.md)
- [Additional XDR Collector profile management options](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/additional-xdr-collector-profile-management-options.md)
- [Query Windows Event Log records](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-windows/query-windows-event-log-records.md)
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md)
- [Ingest Windows DNS debug logs using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/ingest-windows-dns-debug-logs-using-elasticsearch-filebeat.md)
- [Add an XDR Collector profile for Linux](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-profiles/add-an-xdr-collector-profile-for-linux.md)
- [Apply profiles to collection machine policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/apply-profiles-to-collection-machine-policies.md)
- [XDR Collector datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/xdr-collectors/xdr-collector-datasets.md)
- [Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations.md): Cortex Cloud supports data ingestion from other Palo Alto Networks products.
- [About Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/about-palo-alto-networks-integrations.md): Stream data directly from other Palo Alto Networks products to Cortex Cloud.
- [Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/cloud-next-generation-firewall.md): Learn more ingesting firewall data from your Next-Generation Firewall (NGFW) and Panorama devices in Cortex Cloud.
- [Ingest data from Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/cloud-next-generation-firewall/ingest-data-from-cloud-next-generation-firewall.md)
- [Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/next-generation-firewall.md)
- [Ingest data from Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/next-generation-firewall/ingest-data-from-next-generation-firewall.md)
- [Ingest Next-Generation Firewall logs using the Syslog collector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md)
- [Panorama](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/next-generation-firewall/panorama.md)
- [Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/prisma-access.md)
- [Ingest data from Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/prisma-access/ingest-data-from-prisma-access.md): Learn how to ingest detection data from Prisma Access.
- [Palo Alto Networks Prisma](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/prisma-access/palo-alto-networks-prisma.md)
- [Ingest logs from Prisma Access Browser](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/ingest-logs-from-prisma-access-browser.md): Ingest Prisma Browser logs into Cortex Cloud.
- [Ingest detection data from Strata Logging Service](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/ingest-detection-data-from-strata-logging-service.md): Learn how to ingest detection data from Strata Logging Service.
- [IoT Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/iot-security.md)
- [Ingest alerts and assets from IoT Security (Deprecated)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/iot-security/ingest-alerts-and-assets-from-iot-security.md)
- [Ingest alerts and assets from Device Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/iot-security/ingest-alerts-and-assets-from-device-security.md)
- [Cortex Internals](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/cortex-internals.md)
- [Enterprise DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/enterprise-dlp.md)
- [Palo Alto Networks Cortex](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/palo-alto-networks-cortex.md)
- [SaaS Security (Aperture)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/saas-security-aperture.md)
- [WildFire Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/wildfire-cloud.md)
- [Collecting URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/collecting-url-and-file-log-types.md)
- [Detectors connected to URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/collecting-url-and-file-log-types/detectors-connected-to-url-and-file-log-types.md)
- [Cloud Posture and Runtime Security data sources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources.md): Learn more about the Cloud Posture and Runtime Security data sources in Cortex Cloud.
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-databricks.md): How to get started with the third-party Databricks data source.
- [How to onboard on-premise assets to Cortex Cloud Data Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-on-premise-assets-to-cortex-cloud-data-security.md): Set up Data Security for on-premise file shares and databases using Broker VM.
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-microsoft-365.md): How to get started with the Microsoft 365 data source.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/ingest-logs-and-data-from-okta.md): Learn more about Ingesting logs and data from Okta for use in Cortex Cloud.
- [Activate Registry Scanner](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/activate-registry-scanner.md)
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-snowflake.md): How to get started with the third-party Snowflake data source.
- [Activate AppSec Transporter](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/activate-transporter.md): Activate a Broker VM with a Transporter applet.
- [Container Registries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning.md)
- [Registry Components](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/registry-components.md)
- [How Container Registry Scanning Works](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/how-container-registry-scanning-works.md)
- [Configure registry scanning for cloud accounts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/configure-registry-scanning-for-cloud-accounts.md)
- [Modify the container registry scanning scope](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/modify-the-container-registry-scanning-scope.md)
- [Scan re-evaluation process](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/scan-re-evaluation-process.md)
- [Connect Docker Hub registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry.md)
- [Manage a Docker Hub connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry/manage-a-docker-hub-connector.md)
- [Connect Docker V2 compliant container registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry.md)
- [Manage a Docker V2 connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry/manage-a-docker-v2-connector.md)
- [Connect GitLab container registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry.md)
- [Manage a GitLab Container Registry connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry/manage-a-gitlab-container-registry-connector.md)
- [Connect Harbor registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry.md)
- [Manage a Harbor connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry/manage-a-harbor-connector.md)
- [Connect JFrog container registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry.md)
- [Manage a JFrog connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry/manage-a-jfrog-connector.md)
- [Connect Sonatype Nexus registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry.md)
- [Manage a Sonatype connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry/manage-a-sonatype-connector.md)
- [Administration and troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting.md): Learn more about the administration and troubleshooting of the different data collector integrations in Cortex Cloud.
- [Manage instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances.md)
- [Add a new data source or instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/add-a-new-data-source-or-instance.md)
- [How to configure the scanning settings for supported services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/how-to-configure-the-scanning-settings-for-supported-services.md)
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/manage-cloud-instances.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/update-cloud-permissions-after-cortex-release-updates.md)
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/pending-cloud-instances.md)
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/troubleshoot-errors-on-cloud-instances.md)
- [Manage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/manage-kubernetes-connector-instances.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations/add-an-integration-instance.md)
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations/configure-integration-permissions.md)
- [Troubleshoot Integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations/troubleshoot-integrations.md)
- [Verify collector connectivity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/verify-collector-connectivity.md)
- [Overview of data ingestion metrics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/overview-of-data-ingestion-metrics.md)
- [Creating correlation rules to monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/overview-of-data-ingestion-metrics/creating-correlation-rules-to-monitor-data-ingestion-health.md)
- [Measuring data freshness](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/overview-of-data-ingestion-metrics/measuring-data-freshness.md)
- [About health issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues.md)
- [Investigate and resolve health issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues/investigate-and-resolve-health-issues.md)
- [Monitor data ingestion health (BETA)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues/monitor-data-ingestion-health.md)
- [Monitor Correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues/monitor-correlation-rules.md)
- [What is the Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/marketplace/cortex-marketplace.md): Search Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/marketplace/content-pack-support-types.md): Types of content packs support - Cortex supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Cortex Cloud content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/marketplace/cortex-cloud-content.md): The type of content in Cortex Cloud
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/marketplace/marketplace-faqs.md): Frequently Asked Questions about Cortex Cloud Marketplace Content
- [Content changes when upgrading Cortex Cloud versions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/marketplace/content-changes-when-upgrading-cortex-cloud-versions.md): Content updates when upgrading Cortex Cloud versions.
- [Learn about Serverless function posture security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-security.md)
- [Onboard cloud providers for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/onboard-cloud-providers-for-serverless-functions.md)
- [Serverless function posture rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-rules.md)
- [Manage serverless function rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-rules/manage-serverless-function-rules.md)
- [Create serverless function rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-rules/create-serverless-function-rules.md)
- [Create an attack path rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-rules/create-an-attack-path-rule-for-serverless-functions.md)
- [Create a configuration rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-rules/create-a-configuration-rule-for-serverless-functions.md)
- [Create a network exposure rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-rules/create-a-network-exposure-rule-for-serverless-functions.md)
- [Serverless function posture policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-policies.md): Create and manage serverless function policies to detect threats and drive remediation.
- [Manage serverless function policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-policies/manage-serverless-function-policies.md)
- [Create serverless function policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-posture-policies/create-serverless-function-policies.md)
- [Serverless function usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-posture-security/serverless-function-usage.md)
- [Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-runtime-security/overview.md)
- [Set up serverless function protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-runtime-security/set-up-serverless-function-protection.md)
- [Serverless runtime issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/serverless-function-runtime-security/serverless-runtime-issues.md)
- [About Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli.md): The Cortex CLI is a unified command-line tool integrating Cloud Workload Protection, API Security, and Code Security scans into a single executable.
- [Connect Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/connect-cortex-cli.md)
- [Installation workflows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/connect-cortex-cli/installation-workflows.md): Install Cortex CLI using a package manager, manual download, or the Cortex Cloud interface.
- [Manage the CLI after installation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/connect-cortex-cli/manage-the-cli-after-installation.md): Upgrade, pin, uninstall, or update Cortex CLI through automated downloads.
- [Authenticate credentials](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/connect-cortex-cli/authenticate-credentials.md): Configure Cortex CLI credentials using a file, environment variables, or command-line flags.
- [Self-service API keys for CLI scans](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/connect-cortex-cli/self-service-api-keys-for-cli-scans.md)
- [Cortex CLI usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-usage.md)
- [Cortex CLI common command line reference guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-common-command-line-reference-guide.md)
- [Cortex CLI for Code Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security.md)
- [Cortex CLI usage for Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security/cortex-cli-usage-for-cortex-cloud-application-security.md)
- [Cortex CLI Cortex Cloud Application Security command line reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security/cortex-cli-cortex-cloud-application-security-command-line-reference.md)
- [Custom Cortex checks and signature verification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security/cortex-cli-cortex-cloud-application-security-command-line-reference/custom-cortex-checks-and-signature-verification.md): Load custom Cortex checks and optionally verify their signatures.
- [Cortex CLI pre-commit hooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-commit-hooks.md): Integrate Application Security secrets scanner as pre-commit hooks into your workflows to scan for errors on your machine before local commits.
- [Pre-commit hook usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-commit-hooks/pre-commit-hook-usage.md)
- [Cortex CLI pre-receive hooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-receive-hooks.md): Integrate the Application Security secrets scanner as a pre-receive hook into your workflows to scan for errors before code is accepted into your repository.
- [Pre-receive hook usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-receive-hooks/pre-receive-hook-usage.md)
- [Cortex CLI for Cloud Workload Protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-cloud-workload-protection.md)
- [Cloud Workload Protection command line reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-cloud-workload-protection/cloud-workload-protection-command-line-reference.md)
- [Cortex CLI for API Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-api-security.md)
- [Cortex CLI API Security command line reference guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-api-security/cortex-cli-api-security-command-line-reference-guide.md)
- [API Security scan report schema](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-api-security/cortex-cli-api-security-command-line-reference-guide/api-security-scan-report-schema.md): Reference schema for API Security scan reports.
- [API Security scan output example](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cli/cortex-cli-for-api-security/cortex-cli-api-security-command-line-reference-guide/api-security-scan-output-example.md): Example API Security scan report output.
- [Get started with XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql.md): XQL is the Palo Alto Networks Cortex Query Language used in Cortex Cloud.
- [XQL language features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/xql-language-features.md): Learn more about the Cortex Query Language features to query for raw network and endpoint data.
- [XQL Language Structure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/xql-language-structure.md): Learn more about the Cortex Query Language structure when creating a query.
- [Supported operators](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/supported-operators.md): Cortex Query Language supports specific comparison, boolean, and set operators in Cortex Cloud.
- [Datasets and presets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/datasets-and-presets.md): The Cortex Query Language supports built-in datasets, custom datasets, and presets.
- [About examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/about-examples.md): Learn more about the Cortex Query Language (XQL) examples provided.
- [JSON functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/json-functions.md): Learn more about how Cortex Cloud treats JSON functions in the Cortex Query Language.
- [How to filter for empty values in the results table](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/how-to-filter-for-empty-values-in-the-results-table.md): Learn how to filter for empty values in the results table in Cortex Query Language.
- [Understanding string manipulation in XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/get-started-with-xql/understanding-string-manipulation-in-xql.md): Learn more about string manipulation in Cortex Query Language (XQL) using double and triple quotes.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/xql-query-entities.md): Learn more about the Cortex Query Language (XQL) entities available in the Query Builder.
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Manage your query library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/manage-your-query-library.md): Cortex Cloud provides a Query Library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/build-xql-queries/manage-your-macros.md)
- [Cortex XQL syntax, parameters, and examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-xql/cortex-xql-syntax-parameters-and-examples.md): Comprehensive syntax rules and structural requirements for XQL queries
- [What is Graph Search?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/what-is-graph-search.md): Learn more about how to use Graph Search to search assets, findings, and their contextual data.
- [Get started with Graph Search queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/get-started-with-graph-search-queries.md): Learn more about how to get started before building a Graph Search query.
- [How to build Graph Search queries?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/how-to-build-graph-search-queries.md): Learn more about building Graph Search queries using the built-in query interface.
- [Understand Graph Search query results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/understand-graph-search-query-results.md): Learn more about the Graph Search query results.
- [Create Graph Search query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/create-graph-search-query.md): Learn how to create Graph Search queries in Cortex Cloud.
- [Graph Search examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/graph-search-examples.md): Learn how to build Graph Search queries by working through a few examples.
- [Manage the Graph Search Query Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/manage-the-graph-search-query-library.md): Learn more about the Cortex Cloud Graph Search Query Library to manage your queries.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/edit-and-run-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/edit-and-run-queries-in-query-center/query-center-reference-information.md): Descriptions of the fields in the Query Center table.
- [Supported assets and findings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/supported-assets-and-findings.md)
- [FAQ on Graph Search](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/faq-on-graph-search.md): Answer some frequently asked questions relating to Graph Search.
- [Create detection rules based on graph search](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/graph-search/create-detection-rules-based-on-graph-search.md)
- [Learn how to a migrate a new Broker VM image](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/migration-process-for-new-broker-vm-image/migrating-to-a-new-broker-vm-image.md): Learn more about migrating to the latest broker VM image in Cortex Cloud.
- [Standalone Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/migration-process-for-new-broker-vm-image/standalone-broker-vm.md): Learn more about migrating a standalone broker VM image.
- [Broker VM high availability cluster node](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/migration-process-for-new-broker-vm-image/broker-vm-high-availability-cluster-node.md): Learn more about migrating a broker VM High Availability (HA) cluster node.

## Cortex CLOUD Posture Management

- [Navigate the Cortex Cloud Posture Management docs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/readme.md): Start here for a visual overview of the main Cortex Cloud Posture Management documentation areas.
- [What is Cortex Cloud?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/what-is-cortex-cloud.md)
- [Key features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/what-is-cortex-cloud/key-features.md)
- [What is Cortex Cloud Posture Management?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/what-is-cortex-cloud-posture-management.md): Learn about Cortex Cloud Posture Management and the key integrated capabilities.
- [Agentic AI in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/agentic-ai-in-cortex-cloud.md): Use the Cortex Agentic Assistant to investigate cases, perform threat hunting, and create scripts. Embed and run LLM prompts in playbooks. View AI case summaries.
- [Agentic Assistant use cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/agentic-ai-in-cortex-cloud/agentic-assistant-use-cases.md): Recommended prompts to automate your SOC using the Cortex Agentic Assistant
- [Agentic Assistant security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/agentic-ai-in-cortex-cloud/agentic-assistant-security.md): Learn about how the Agentic Assistant is built using responsible AI principles.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/supported-web-browsers.md)
- [Use the interface](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/use-the-interface.md)
- [In-product support ticket creation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/in-product-support-case-creation.md): Open a support ticket directly in Cortex Cloud and record your console to capture your issues and have the ticket handled efficiently.
- [Understand your user persona](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/understand-your-user-persona.md)
- [Fair Usage policy for Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/fair-usage-policy-for-cortex-cloud.md)
- [Understand license plans](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/understand-license-plans.md)
- [Data retention](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/understand-license-plans/data-retention.md): Learn more about the default retention periods for all Cortex Cloud licenses and the available retention add-ons.
- [Learn how to onboard and configure Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/onboard-and-configure-cortex-cloud.md): Learn about the deployment preparation and procedures to onboard and configure Cortex Cloud.
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/plan-and-prepare.md): Learn more about deployment considerations and onboarding steps.
- [Prepare for deployment](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/plan-and-prepare/prepare-for-deployment.md): Learn more about deployment considerations and onboarding steps.
- [Deployment steps and checklist](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist.md): Review the steps to onboard and configure Cortex Cloud.
- [Activate Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud.md): Learn how to activate your tenant.
- [Cortex Cloud supported regions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/cortex-cloud-supported-regions.md)
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources.md)
- [Regional egress resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/regional-egress-resources.md)
- [Engines IP addresses (outbound)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/engines-ip-addresses-outbound.md)
- [Inbound source resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/inbound-source-resources.md)
- [FedRAMP and the US Federal Government required resources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/activate-cortex-cloud/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md)
- [Upgrade from Prisma Cloud to Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud.md)
- [About the Upgrade Helper](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/about-the-upgrade-helper.md)
- [Link Cortex Cloud to Prisma Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/link-cortex-cloud-to-prisma-cloud.md)
- [Copy content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content.md)
- [Copy Global configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-global-configurations.md)
- [Copy CSPM configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-cspm-configurations.md)
- [Copy CWP configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-cwp-configurations.md)
- [Copy Cortex Cloud Application Security configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/copy-content/copy-cortex-cloud-application-security-configurations.md)
- [Migrate Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/upgrade-from-prisma-cloud-to-cortex-cloud/migrate-cortex-cli.md)
- [Set up users, groups, and roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles.md): Learn how to set up users and roles in Cortex Cloud.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles/user-group-management.md): Create and manage user groups, roles, and scopes.
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles/assign-user-roles-and-groups.md): Assign roles and group memberships to users.
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/manage-api-keys.md)
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication.md): Authenticate Cortex Cloud users using SAML 2.0 or Customer Support Portal (CSP).
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate users through the Customer Support Portal.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/authenticate-users-using-sso.md): Configure SAML single sign-on for Cortex Cloud users.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta as a SAML 2.0 identity provider.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID as a SAML 2.0 identity provider.
- [Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding.md): Learn about onboarding your cloud service provider to Cortex Cloud.
- [Amazon Web Services cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding.md): Follow the AWS onboarding wizard, and Cortex Cloud creates a custom authentication template to be deployed in AWS.
- [AWS security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-capabilities-and-deployment-planning.md)
- [AWS resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-resource-inventory.md)
- [AWS security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-model-and-authentication.md)
- [Cortex Cloud and AWS audit log collection architecture](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/cortex-cloud-and-aws-audit-log-collection-architecture.md)
- [Onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/onboard-amazon-web-services.md): Follow the AWS onboarding wizard, and Cortex Cloud creates a custom authentication template to be executed in AWS.
- [Prerequisites for onboarding AWS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/prerequisites-for-onboarding-aws.md): Before you begin onboarding AWS, you must review the following prerequisites.
- [How to onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/how-to-onboard-amazon-web-services.md): Follow the AWS onboarding wizard and Cortex Cloud creates a custom authentication template to be deployed in AWS CloudFormation.
- [Deploy the authentication template in AWS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/deploy-the-authentication-template-in-aws.md): Learn how to deploy the Terraform or CloudFormation authentication template in Amazon Web Services.
- [Post-deployment: Custom (BYOB) and Control Tower audit log collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/post-deployment-custom-byob-audit-log-collection.md)
- [Grant cross-account KMS key access for Control Tower BYOB log collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/grant-cross-account-kms-key-access-for-control-tower-byob-log-collection.md): Learn how to configure cross-account AWS KMS key permissions for Cortex Control Tower BYOB log collection. Step-by-step guide to updating KMS key policies.
- [AWS post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/aws-post-deployment-verification.md): After you have completed the AWS onboarding wizard and you have deployed the authentication template in AWS (using CloudFormation or Terraform), verify that the deployment succeeded.
- [Microsoft Azure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding.md)
- [Onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Prerequisites for onboarding Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/prerequisites-for-onboarding-azure.md): Before you begin onboarding Microsoft Azure, you must review the following prerequisites.
- [How to onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Finalize Microsoft Azure onboarding by executing the authentication template](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/finalize-microsoft-azure-onboarding-by-executing-the-authentication-template.md): Learn how to execute the authentication template file in Microsoft Azure for subscriptions, tenants, and management groups. We provide instructions both for applying the Terraform template's configura
- [Microsoft Azure offboarding overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview.md): This section contains the technical procedures required to safely decommission and offboard your Cortex Cloud resources in Microsoft Azure.
- [Offboard Terraform-based Azure deployments (all scopes)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-terraform-based-azure-deployments-all-scopes.md): How to offboard all Terraform-based Microsoft Azure scopes from Cortex Cloud: A step-by-step technical guide to safely running Terraform destroy and cleaning up policy-deployed resources.
- [Offboard Azure subscription (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-subscription-arm.md): How to offboard a Microsoft Azure subscription scope that was onboarded using ARM: A step-by-step technical guide to safely running the interactive offboarding script and cleaning up all resources.
- [Offboard Azure management group or tenant scope (ARM)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-management-group-or-tenant-scope-arm.md): How to offboard Microsoft Azure management group or tenant scopes from Cortex Cloud: A step-by-step technical guide to safely removing all Azure resources deployed by Cortex onboarding templates.
- [Offboard Azure tenant with Entra ID only](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-tenant-with-entra-id-only.md): How to offboard a Microsoft Azure tenant onboarded with the Entra ID only option from Cortex Cloud: A step-by-step technical guide to safely removing deployed resources.
- [Google Cloud Platform cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding.md)
- [Onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex creates a custom authentication template to be executed in GCP.
- [Prerequisites for onboarding GCP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/prerequisites-for-onboarding-gcp.md): Before you begin onboarding GCP, you must review the following prerequisites.
- [How to onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex Cloud creates a custom authentication template to be applied in GCP.
- [Deploy the Terraform authentication template in GCP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/deploy-the-terraform-authentication-template-in-gcp.md): Learn how to deploy the Terraform authentication template in Google Cloud Console.
- [Connect Google Workspace with your GCP cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/connect-google-workspace-with-your-gcp-cloud-instance.md)
- [Monitor GCP resources inside service perimeters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/monitor-gcp-resources-inside-service-perimeters.md): Learn how to grant authorization to Cortex Cloud to scan within your GCP service perimeter.
- [Oracle Cloud Infrastructure cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding.md): Follow the Oracle Cloud Infrastructure onboarding wizard and Cortex Cloud creates a custom Terraform authentication template to be deployed in Oracle Cloud Infrastructure.
- [Onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard, and Cortex creates a custom authentication template to be executed in OCI.
- [Prerequisites for onboarding OCI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/prerequisites-for-onboarding-oci.md): Before you begin onboarding Oracle Cloud Infrastructure, you must review the following prerequisites.
- [How to onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/how-to-onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard and Cortex Cloud creates a custom authentication template to be applied in OCI.
- [Deploy the Terraform authentication template in OCI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/deploy-the-terraform-authentication-template-in-oci.md): Learn how to deploy the Terraform authentication template in Oracle Cloud Infrastructure.
- [Alibaba Cloud cloud onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding.md): Follow the Alibaba Cloud onboarding wizard and Cortex Cloud creates a custom Terraform authentication template to be deployed in Alibaba Cloud.
- [Alibaba security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-security-capabilities-and-deployment-planning.md)
- [Alibaba Cloud resource inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-resource-inventory.md)
- [Alibaba Cloud security model and authentication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-security-model-and-authentication.md)
- [Onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/onboard-alibaba-cloud.md): Follow the Alibaba Cloud onboarding wizard and Cortex Cloud creates a custom CloudFormation authentication template to be deployed in Alibaba Cloud.
- [Prerequisites for onboarding Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/prerequisites-for-onboarding-alibaba-cloud.md): Before you begin onboarding Alibaba Cloud, you must review the following prerequisites.
- [How to onboard Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/how-to-onboard-alibaba-cloud.md)
- [Alibaba Cloud post-deployment verification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/alibaba-cloud-post-deployment-verification.md): After you have completed the Alibaba Cloud onboarding wizard and you have deployed the authentication template in Alibaba Cloud, verify that the deployment succeeded.
- [Outpost onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding.md): Learn about outposts, which are a dedicated set of infrastructure resources that extends the reach of Cortex Cloud into your environment.
- [Outpost fundamentals and planning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-fundamentals-and-planning.md): An outpost enables you to have security scans performed on infrastructure in a cloud account owned by you. Learn about outpost fundamentals and what to consider when planning your outpost.
- [Outpost creation workflow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-creation-workflow.md): Learn about the creation process for an outposts, which facilitate security scanning performed on infrastructure in a cloud account owned by you.
- [Working with standard outposts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts.md): Standard outposts are the recommended way to create dedicated set of infrastructure resources that extends the reach of Cortex Cloud into your environment.
- [Create a standard outpost](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-standard-outposts/create-a-standard-outpost.md): Instructions for creating a standard outpost while onboarding your CSP.
- [Working with Bringing your own Azure app (BYOA) outposts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts.md): Using advanced settings while creating your outpost, you can deploy a Cortex Cloud Azure outpost using your own pre-created Entra ID app registration.
- [Task 1: Meet the prerequisites for Azure BYOA outposts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-1-meet-the-prerequisites-for-azure-byoa-outposts.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page lists the prerequisites that must be met before customizing your outpost in this way.
- [Task 2: Create the app registration for the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-2-create-the-app-registration-for-the-azure-byoa-outpost.md): You can customize your own outpost for Azure by bringing your own app (BYOA). This page describes the steps for creating the app registration.
- [Task 3: Deploy the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-3-deploy-the-azure-byoa-outpost.md): You can customize your own outpost by bringing your own app (BYOA). This page describes the steps for deploying the Azure BYOA outpost.
- [Task 4: Verify the BYOA outpost deployment](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-4-verify-the-byoa-outpost-deployment.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page describes the steps for verifying your BYOA outpost deployment.
- [The shell script for Azure app registration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/the-shell-script-for-azure-app-registration.md): You can run this helper shell script to set up your resources and retrieve their IDs for use while creating your Azure BYOA outpost. This page provides technical, "read-me style" details about the scr
- [Outpost troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-troubleshooting.md): Check here for solutions to issues that might occur while configuring, deploying, and operating outposts.
- [Outpost Cloud Service Provider (CSP) permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions.md): This page lists and explains the various roles and permissions needed for working with resources for outposts by CSP.
- [Amazon Web Services (AWS) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/amazon-web-services-aws-outpost-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex Cloud outpost onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/microsoft-azure-outpost-permissions.md): List of Microsoft Azure provider outpost permissions for Cortex Cloud.
- [Google Cloud Platform (GCP) outpost permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/google-cloud-platform-gcp-outpost-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex Cloud onboarding outposts to enable continuous monitoring in your cloud environment.
- [Introduction to Terraform for Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/introduction-to-terraform-for-cloud-service-provider-csp-onboarding.md): Learn how to onboard Cloud Service Providers (CSPs) using Terraform. Discover step-by-step workflows for initial provisioning, updates, and Cloud Shell deployment.
- [Manually connect a cloud instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/manually-connect-a-cloud-instance.md)
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/pending-cloud-instances.md)
- [Edit your onboarded CSP configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/edit-your-onboarded-csp-configuration.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/update-cloud-permissions-after-cortex-release-updates.md): Manage permission updates for your cloud instances following new feature releases or bug fixes.
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/troubleshoot-errors-on-cloud-instances.md): You can troubleshoot errors on cloud instances by drilling down on an instance from the Data Sources & Integrations page.
- [Cloud service provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions.md): Grant the correct cloud service provider permissions for Cortex Cloud.
- [Amazon Web Services (AWS) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/amazon-web-services-aws-provider-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex Cloud onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/microsoft-azure-provider-permissions.md): List of Microsoft Azure provider permissions for Cortex Cloud.
- [Google Cloud Platform (GCP) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/google-cloud-platform-gcp-provider-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex Cloud onboarding to enable continuous monitoring in your cloud environment.
- [Oracle Cloud Infrastructure (OCI) provider permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/oracle-cloud-infrastructure-oci-provider-permissions.md): List of Oracle Cloud Infrastructure provider permissions for Cortex Cloud.
- [Onboard the Kubernetes Connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/onboard-the-kubernetes-connector.md)
- [What's new in Kubernetes Connector?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/onboard-the-kubernetes-connector/whats-new-in-kubernetes-connector.md)
- [Supported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/onboard-the-kubernetes-connector/supported-kubernetes-distributions.md)
- [FedRAMP overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview.md)
- [Cortex Cloud federal compliance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview/cortex-cloud-federal-compliance.md)
- [Onoarding & configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview/onoarding-and-configuration.md)
- [Limitations & supported regions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/fedramp-overview/limitations-and-supported-regions.md)
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps.md)
- [Set up your environment](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment.md): Learn more about setting up the Cortex Cloud environment based on your preferences.
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/configure-server-settings.md)
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/configure-security-settings.md)
- [Data and log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding.md)
- [Forward logs and data from Cortex Cloud to external services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services.md)
- [Configure external applications for forwarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding.md)
- [Forward notifications to Amazon SQS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqs.md)
- [Forward notifications to Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-s3.md)
- [Forward notifications to Splunk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-splunk.md)
- [Forward notifications to webhook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-webhook.md)
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver.md)
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-external-applications-for-forwarding/integrate-slack-for-outbound-notifications.md)
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/configure-notification-forwarding.md)
- [Set up email notifications for tenant updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/set-up-email-notifications-for-tenant-updates.md)
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-cloud-to-external-services/monitor-administrative-activity.md)
- [Data and log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats.md)
- [Management audit log messages](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-messages.md)
- [Issue notification format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/issue-notification-format.md)
- [Agent Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/agent-audit-log-notification-format.md)
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-notification-format.md)
- [Log format for IOC and BIOC issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/log-format-for-ioc-and-bioc-issues.md)
- [Analytics log format](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/analytics-log-format.md)
- [Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/cortex-mcp-server.md): The Cortex MCP server enables you to leverage Cortex's powerful capabilities directly through natural language.
- [Install the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/cortex-mcp-server/install-the-cortex-mcp-server.md)
- [Configure the MCP client](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/cortex-mcp-server/configure-the-mcp-client.md)
- [Use the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/cortex-mcp-server/use-the-cortex-mcp-server.md)
- [Create custom Cortex MCP server tools](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/cortex-mcp-server/create-custom-cortex-mcp-server-tools.md)
- [Manage user roles and access management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management.md): Learn how to manage access for users, user roles, user groups, and Single Sign-On (SSO) for users on a specific Cortex Cloud tenant.
- [Manage user roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-roles.md)
- [Manage user access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md)
- [User access reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access/user-access-reference-information.md)
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope.md)
- [Manage access to objects](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects.md)
- [Manage access to custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-custom-dashboards.md)
- [Manage access to report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-report-templates.md)
- [Manage access to playbooks and scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-playbooks-and-scripts.md)
- [Manage access to saved queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-saved-queries.md)
- [Configure the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant.md)
- [Agentic Assistant components and concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agentic-assistant-components-and-concepts.md): Learn about the key components and concepts, such as agents and actions in the Cortex Agentic Assistant
- [Agentic Assistant Hub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub.md): Learn about personal and system agents in in the Agentic Assistant Hub
- [Manage actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-actions.md)
- [Register actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/register-actions.md)
- [Manage agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-agents.md)
- [Build agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/build-agents.md)
- [Manage knowledge sources (preview)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-knowledge-sources-preview.md): Enhance AI agent capabilities by leveraging the Knowledge Center (preview) to provide agents with your business-specific source of truth and built-in Cortex (system) knowledge.
- [Expand agent capabilities with MCP integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/expand-agent-capabilities-with-mcp-integrations.md)
- [Agentic Assistant role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/configure-the-cortex-agentic-assistant/agentic-assistant-role-based-access-control.md): Configure permissions to access Cortex Agentic Assistant features.
- [XQL query management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/xql-query-management.md): Administrators can set controls on running XQL queries.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/onboard-and-configure/post-deployment-steps/dashboards-and-reports.md)
- [Asset management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-management.md)
- [Asset inventory overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-inventory-overview.md): Learn about the core concepts, features, and lifecycle of assets within the Asset Inventory.
- [All assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/all-assets.md): Learn about the All Assets page, under Asset Inventory.
- [All cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/all-cloud-assets.md): Learn about the All Cloud Assets page to view and assess your cloud footprint.
- [Discovery Engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/all-cloud-assets/discovery-engine.md)
- [Asset hierarchy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/all-cloud-assets/asset-hierarchy.md)
- [Asset classes](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes.md): Accelerating remediation: Automated fix suggestions and manual remediation guidance enable developers to resolve code weaknesses directly in the source repository without context-switching to external
- [AI assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/ai-assets.md)
- [API assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/api-assets.md)
- [Application assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/application-assets.md)
- [Code and CI/CD assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/code-and-ci-cd-assets.md)
- [IaC resources assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/code-and-ci-cd-assets/iac-resources-assets.md)
- [Repository assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/code-and-ci-cd-assets/repository-assets.md)
- [VCS organization assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/code-and-ci-cd-assets/vcs-organization-assets.md)
- [CI/CD pipeline assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/code-and-ci-cd-assets/ci-cd-pipeline-assets.md)
- [CI/CD instances assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/code-and-ci-cd-assets/ci-cd-instances-assets.md)
- [Software package assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/code-and-ci-cd-assets/software-package-assets.md)
- [Compute assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/compute-assets.md)
- [Container image assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/compute-assets/container-image-assets.md)
- [Serverless functions assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/compute-assets/serverless-functions-assets.md)
- [VM images assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/compute-assets/vm-images-assets.md)
- [Data assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/data-assets.md)
- [Device assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/device-assets.md)
- [External Surface assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/external-surface-assets.md)
- [Website assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/external-surface-assets/website-assets.md)
- [Service assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/external-surface-assets/service-assets.md)
- [Domain assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/external-surface-assets/domain-assets.md)
- [Certificate assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/external-surface-assets/certificate-assets.md)
- [External Surface attribution evidence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/external-surface-assets/external-surface-attribution-evidence.md)
- [Identity assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/identity-assets.md)
- [Network assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/network-assets.md)
- [Security services assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-classes/security-services-assets.md)
- [Asset groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-groups.md): Group assets based on shared attributes to address them collectively, simplify filtering, and enable strict access control boundaries.
- [Manage Risk Scores](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/manage-asset-scores.md): View and investigate User Scores and Host Scores using the Risk Scores page to identify high-risk assets and detect compromised accounts or malicious activities.
- [Asset configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-configurations.md)
- [Network configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-configurations/network-configuration.md): Configure your internal network parameters, trusted networks, and external IP ranges to help Cortex Cloud identify and map your network assets.
- [Application criteria](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-configurations/application-criteria.md)
- [Asset Roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-configurations/asset-roles.md): View asset roles and the number of assets that are associated with each role. Learn how to manage asset roles for users and endpoints.
- [Manage Asset Roles for Endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-configurations/asset-roles/manage-asset-roles-for-endpoints.md)
- [Manage Asset Roles for Users](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-configurations/asset-roles/manage-asset-roles-for-users.md)
- [Honey user](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-inventory-and-environment/asset-configurations/asset-roles/manage-asset-roles-for-users/honey-user.md)
- [Overview of cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases.md)
- [What are cases?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases/what-are-cases.md)
- [Resolving cases with AI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases/resolving-cases-with-ai.md)
- [Case lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases/case-lifecycle.md)
- [Case thresholds](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases/case-thresholds.md)
- [Case scope and impact](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases/case-scope-and-impact.md)
- [Case and issue domains](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases/case-and-issue-domains.md)
- [Overview of case teams and roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/overview-of-cases/overview-of-case-teams-and-roles.md)
- [Case concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/case-concepts.md)
- [Issues, findings, and events](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/case-concepts/issues-findings-and-events.md)
- [Case grouping](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/case-concepts/case-grouping.md)
- [Case scoring](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/case-concepts/case-scoring.md)
- [What is Causality?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/case-concepts/what-is-causality.md)
- [Analyze and resolve cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases.md): Learn how to analyze and resolve cases.
- [Review all cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/review-all-cases.md)
- [Start case analysis](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/start-case-analysis.md)
- [Agentic Assistant- Case Investigation agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/start-case-analysis/agentic-assistant-case-investigation-agent.md)
- [Establish case context](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/establish-case-context.md)
- [AI-generated case summaries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/establish-case-context/ai-generated-case-summaries.md)
- [Assess case severity and score](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/establish-case-context/assess-case-severity-and-score.md)
- [Update case attributes](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/establish-case-context/update-case-attributes.md)
- [Analyze case details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details.md)
- [Grouping graph](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/grouping-graph.md)
- [Evidence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/evidence.md)
- [Issue feed](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/issue-feed.md)
- [Associated assets and artifacts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/associated-assets-and-artifacts.md)
- [MITRE ATT\&CK tactics and techniques](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/mitre-att-and-ck-tactics-and-techniques.md)
- [Compliance standards and controls](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/compliance-standards-and-controls.md)
- [Case timeline](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/case-timeline.md)
- [Detailed view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/analyze-case-details/detailed-view.md)
- [Resolve the case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/resolve-the-case.md)
- [Resolution Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/resolution-center.md)
- [Collaborative notes and comments](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/collaborative-notes-and-comments.md)
- [How to resolve a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/resolve-a-case.md)
- [Resolution reasons for cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/resolution-reasons-for-cases-and-issues.md)
- [Monitor and track resolution times](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/resolve-the-case/monitor-and-track-resolution-times.md)
- [Additional case actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/additional-case-actions.md)
- [Create a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/create-a-case.md)
- [Merge a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/merge-a-case.md)
- [Assign a case team and restrict access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access.md)
- [Playbook examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access/playbook-examples.md)
- [Investigation and response](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response.md)
- [Investigate issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues.md): Cortex Cloud generates issues to bring your attention to security risks in your framework.
- [Overview of the Issues page](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/overview-of-the-issues-page.md)
- [Issue card](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-card.md)
- [Resolution actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/resolution-actions.md)
- [Link or unlink issues from a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/link-or-unlink-issues-from-a-case.md)
- [Run an automation on an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/run-an-automation-on-an-issue.md)
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/use-the-war-room-in-an-investigation.md)
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md)
- [Issue deduplication](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-deduplication.md)
- [Issue investigation actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions.md)
- [Copy issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/copy-issues.md)
- [Update issue fields](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/update-issue-fields.md)
- [Export issue details to a file](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/export-issue-details-to-a-file.md)
- [Exclude an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/exclude-an-issue.md)
- [Query case and issue data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md)
- [Issue syncing](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-issues/issue-syncing.md)
- [Review findings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/review-findings.md): Review findings for an asset to gain insights into an asset’s posture status.
- [Findings card](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/review-findings/findings-card.md)
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets.md): You can investigate specific artifacts and assets on dedicated views related to IP address, Network Assets, and File and Process Hash information.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-an-ip-address.md)
- [Investigate an asset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-an-asset.md)
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md)
- [Investigate a user](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/investigate-artifacts-and-assets/investigate-a-user.md)
- [Cortex Assistant](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/cortex-assistant.md): Cortex Assistant is designed to streamline processes by simplifying case triaging, investigation, and remediation. It enables you to seamlessly uncover new insights on hashes, hosts, and more. You can
- [Cortex Assistant layout](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/cortex-assistant/cortex-assistant-layout.md)
- [Cortex Assistant capabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/cortex-assistant/cortex-assistant-capabilities.md)
- [Automation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation.md)
- [Quick Actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/quick-actions.md)
- [Automation Exclusion Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/automation-exclusion-center.md)
- [Manage automation exclusion policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/manage-automation-exclusion-policies.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks.md)
- [Playbooks overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/playbooks-overview.md)
- [Access to playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/access-to-playbooks.md)
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/playbook-development-checklist.md)
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/plan-your-playbook.md)
- [Manage playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/manage-playbooks.md)
- [Build your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook.md)
- [Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/choose-from-existing-playbooks-or-create-your-own.md)
- [Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/configure-playbook-settings.md)
- [Add objects from the Task Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library.md)
- [Add commands and scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-commands-and-scripts.md)
- [Add sub-playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-sub-playbooks.md)
- [Add AI Prompt tasks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-ai-prompt-tasks.md)
- [Add manual tasks and blank tasks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks.md): Add manual and blank tasks to a playbook.
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-standard-task.md): Define a Standard task in Cortex Cloud.
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-conditional-task.md): Create a Conditional task in a playbook.
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-communication-task.md): Communication tasks let you send surveys and collect issue data.
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/create-a-section-header.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/configure-script-error-handling-in-a-playbook.md)
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook.md)
- [Configure a sub-playbook loop](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/configure-a-sub-playbook-loop.md)
- [Filter and Transform data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/filter-and-transform-data.md)
- [Create custom filter and transformers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/create-custom-filter-and-transformers.md)
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/filter-considerations-categories-and-built-in-filters.md)
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/transformer-considerations-categories-and-built-in-transformers.md)
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/extend-context.md)
- [Extract Indicators](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/extract-indicators.md)
- [Update issue fields with playbook tasks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/customize-your-playbook/update-issue-fields-with-playbook-tasks.md)
- [Test your playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/test-your-playbook.md): Set breakpoints, conditional breakpoints, skips, and input or output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/test-your-playbook/troubleshoot-playbook-performance.md)
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/build-your-playbook/manage-playbook-content.md)
- [Accelerate playbook development using the Automation Engineer agent (preview)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview.md)
- [Automation Engineer prompt examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview/automation-engineer-prompt-examples.md)
- [Best practices for playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/playbooks/best-practices-for-playbooks.md)
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/ai-prompts.md)
- [AI prompts role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/ai-prompts/ai-prompts-role-based-access-control.md): Manage AI prompt permissions with role-based access control.
- [Use existing prompts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/ai-prompts/use-existing-prompts.md): Find, duplicate, and edit prompts from the Prompts Library.
- [Create a prompt](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/ai-prompts/create-a-prompt.md): Create or edit prompts, configure settings, and use them in agents or playbooks.
- [Write effective prompts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/ai-prompts/write-effective-prompts.md): Tips for creating effective AI prompts.
- [Create an automation rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/create-an-automation-rule.md): Learn how to create an automation rule for an issue.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/scripts.md)
- [Access to scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/scripts/access-to-scripts.md)
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/scripts/use-existing-scripts.md)
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/scripts/create-a-script.md)
- [Accelerate script development using the Automation Engineer agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/scripts/accelerate-script-development-using-the-automation-engineer-agent.md)
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/scripts/change-the-docker-image-in-an-integration-or-script.md)
- [Context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data.md): Use context data to assist with the investigation and remediation process.
- [Issue context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data/issue-context-data.md)
- [Case context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data/case-context-data.md)
- [Search context data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data/search-context-data.md)
- [Add context data to an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data/add-context-data-to-an-issue.md)
- [Add context data to a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data/add-context-data-to-a-case.md)
- [Delete context data from a case](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data/delete-context-data-from-a-case.md)
- [Use context data in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/context-data/use-context-data-in-a-playbook.md)
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/lists.md)
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/lists/create-a-list.md)
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/lists/list-commands.md)
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/lists/use-cases-json-lists.md)
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/lists/transform-a-list-into-an-array.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/integrations.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/integrations/add-an-integration-instance.md)
- [Use integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/integrations/use-integration-commands-in-the-cli.md)
- [Troubleshoot integations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/integrations/troubleshoot-integations.md)
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/integrations/manage-credentials.md)
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine.md): Install, deploy and configure Cortex Cloud engines.
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker.md): Install, configure, secure, and troubleshoot Docker for Cortex Cloud engines.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/install-docker.md): Install Docker and verify engine user permissions.
- [Install Docker distribution for Red Hat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/install-docker-distribution-for-red-hat.md): Configure Docker and SELinux on Red Hat engine servers.
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-image-security.md): Secure, harden, and troubleshoot Docker images and containers.
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-faqs.md)
- [Troubleshoot Docker Issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
- [Change the Docker Installation folder](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide.md)
- [Docker network hardening](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/docker-network-hardening.md)
- [Configure Docker images](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-docker-images.md)
- [Run Docker with non-root internal users](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
- [Configure the memory limit support without swap capabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limit-support-without-swap-capabilities.md)
- [Configure the memory limitation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-memory-limitation.md)
- [Configure the CPU, PIDs, and open the file descriptors limit](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/configure-the-cpu-pids-and-open-the-file-descriptors-limit.md)
- [Check Docker hardening configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/docker/docker-hardening-guide/check-docker-hardening-configurations.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman.md): Install, configure, and troubleshoot Podman for Cortex Cloud engines.
- [Change the Container storage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/change-the-container-storage.md): Configure Podman container storage for an engine.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/install-podman.md): Install and configure Podman for Cortex Cloud engines.
- [Migrate from Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/migrate-from-docker-to-podman.md): Migrate an existing engine from Docker to Podman.
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/install-an-engine/podman/troubleshoot-podman.md): Resolve common Podman issues on Cortex Cloud engines.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/manage-engines.md): Manage engines and load balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/upgrade-an-engine.md): Upgrade an engine on Cortex Cloud or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/configure-engines.md): Configure Cortex Cloud engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md)
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/configure-engines/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/use-an-engine-in-an-integration.md): Use an engine or a load-balancing group of engines to fetch issues and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/automation/engines/troubleshoot-integrations-running-on-engines.md)
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md)
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md)
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md)
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md)
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/create-xql-query.md)
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md)
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md)
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/how-to-build-xql-queries/graph-query-results.md)
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder.md): Learn more about the entities in the Legacy Query Builder.
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/legacy-query-builder/query-across-all-entities.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md)
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/overview-of-the-query-center/query-center-reference-information.md)
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md)
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/manage-your-personal-query-library.md): Cortex Cloud provides as part of the Query Library a personal library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/build-xql-queries/manage-your-macros.md)
- [Quick Launcher](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/investigation-and-response/quick-launcher.md): The Quick Launcher provides a quick, in-context shortcut that you can use to search for information, perform common investigation tasks, or initiate actions.
- [Customize cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues.md): Customize your cases and issues for specific requirements.
- [Set up case scoring](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/set-up-case-scoring.md)
- [Create a starring configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-a-starring-configuration.md)
- [Create SLAs for case and issue resolution](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-slas-for-issue-resolution.md): Create SLA rules to set and track issue-resolution timers and time goals.
- [Create additional case timers and SLAs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas.md)
- [Update case timer and SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-slas-for-issue-resolution/create-case-timers-and-slas/update-case-timer-and-sla-fields.md)
- [Create issue exceptions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-issue-exceptions.md): Create time-bound exceptions that pause issue SLA timers during approved remediation delays.
- [Configure the issue exception approval workflow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/configure-the-issue-exception-approval-workflow.md): Manage approvers and approval requirements for issue exception rules.
- [Create issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/create-issue-exception-rules.md): Create approval-based rules that temporarily pause SLA timers for selected issues.
- [Create an exception rule from an issue](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/create-an-exception-rule-from-an-issue.md)
- [View issue Exception Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/view-issue-exception-rules.md)
- [Disable issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/disable-issue-exception-rules.md)
- [View excepted issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-issue-exceptions/view-excepted-issues.md)
- [Optimize case grouping in correlations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/optimize-case-grouping-in-correlations.md)
- [Create a sync profile](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cases-and-issues/customize-cases-and-issues/create-a-sync-profile.md)
- [Learn more about the Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/agentic-assistant-chat.md): Chat with the Cortex Agentic Assistant using natural language prompts.
- [Get started with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/get-started-with-agentic-assistant-chat.md): Enable Agentic Assistant and access the chat interface.
- [Choose an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/choose-an-agentic-assistant-agent.md): Choose a system or custom agent for your chat.
- [Chat with an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/chat-with-an-agentic-assistant-agent.md): Tips for chatting with the Cortex Agentic Assistant
- [Chat with the Agentic Assistant from Slack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/chat-with-the-agentic-assistant-from-slack.md): Enable chatting with an Agentic Assistant agent from Slack.
- [Create and run XQL queries with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/create-and-run-xql-queries-with-agentic-assistant-chat.md): Interact with Cortex Agentic Assistant agents to build and run XQL queries.
- [Use natural language to query and visualize your data](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/use-natural-language-to-query-and-visualize-your-data.md): Prompt Cortex Agentic Assistant agents to create graphs and charts from its findings.
- [Manage chat history](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/agentic-assistant/manage-chat-history.md): Manage and navigate your past chats with the Cortex Agentic Assistant.
- [Monitor dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports.md)
- [Overview of dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports.md)
- [Dashboard interface basics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basics.md)
- [Dashboard types](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-types.md)
- [Report basics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/report-basics.md)
- [Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/widget-library.md)
- [Access and visibility for dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports.md)
- [Visibility settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settings.md)
- [Access to widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgets.md)
- [Sharing icons](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-icons.md)
- [Access and sharing cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-and-sharing-cheat-sheet.md)
- [Manage dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports.md)
- [Dashboard Manager](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/dashboard-manager.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/reports.md)
- [Duplicate dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reports.md)
- [Share custom dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templates.md)
- [Change ownership to dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templates.md)
- [Import and export dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templates.md)
- [Configure the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-report.md)
- [Deleted content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/manage-dashboards-and-reports/deleted-content.md)
- [Create dashboards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/create-dashboards.md)
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/create-dashboards/create-a-dashboard.md)
- [Create reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/create-reports.md)
- [Create a report template from scratch](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/create-reports/create-a-report-template-from-scratch.md)
- [Advanced configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration.md)
- [Create custom widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets.md)
- [Create widgets using AI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-ai.md)
- [Create XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets.md)
- [Add parameters to a custom XQL widget](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widget.md)
- [Create script-based widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgets.md)
- [Configure global filters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/configure-global-filters.md)
- [Configure drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/advanced-configuration/configure-drilldowns.md)
- [Dashboard reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference.md)
- [Command Center reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/command-center-reference.md)
- [Cortex Agentic Assistant dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-agentic-assistant-dashboard.md)
- [Cortex Cloud Command Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-cloud-command-center.md)
- [System dashboards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md)
- [Cortex Cloud Consumption](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cortex-cloud-consumption.md)
- [Cloud Security Operations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/dashboards-and-reports/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cloud-security-operations.md)
- [Monitor and track compliance adherence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence.md): Evaluate and track asset compliance against industry standards and organizational policies.
- [Choose compliance standards from the compliance catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog.md): Select built-in or custom compliance standards and controls from the compliance catalogs.
- [Standards catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/standards-catalog.md): Browse available compliance standards.
- [Controls catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/controls-catalog.md): Browse, filter, and review built-in and custom compliance controls.
- [Use a built-in or custom standard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-standard.md): Use built-in standards or create and edit custom standards for your organization.
- [Use a built-in or custom control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-control.md): Add built-in controls or create and manage custom controls for custom standards.
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/create-a-new-custom-detection-rule.md): Create custom detection rules to enforce compliance requirements and security best practices.
- [Use an assessment profile to run compliance checks on your assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets.md): Create assessment profiles to evaluate selected asset groups against compliance standards.
- [Configuring assessments for custom compliance standards based on custom cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/use-an-assessment-profile-to-run-compliance-checks-on-your-assets/configuring-assessments-for-custom-compliance-standards-based-on-custom-cloud-security-rules.md): Configure policies and assessments for custom standards that use custom cloud security rules.
- [View and manage compliance assessments and reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports.md): Review assessment results and generate or schedule downloadable compliance reports.
- [Review assessments](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/assessments.md): View assessment results and drill into control, rule, and asset compliance details.
- [Review reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/view-and-manage-compliance-assessments-and-reports/reports.md): View, export, and manage historical compliance assessment reports.
- [Compliance Overview Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/compliance/monitor-and-track-compliance-adherence/compliance-overview-dashboard.md): Monitor organization-wide compliance scores, standards, failed controls, and asset group performance.
- [What is Cortex Cloud AI Security?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-ai-security/what-is-cortex-cloud-ai-security.md): A basic overview of the Cortex Cloud AI Security overview page, assets inventory, risks, and benefits.
- [Supported services in Cortex Cloud AI Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-ai-security/supported-services-in-cortex-cloud-ai-security.md): A list of platforms and services that are compatible with Cortex Cloud AI Security.
- [Cortex Cloud AI Security concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-ai-security/cortex-cloud-ai-security-concepts.md): Basic concepts of Cortex Cloud AI Security.
- [Cortex Cloud AI Security use cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-ai-security/cortex-cloud-ai-security-use-cases.md): Learn about use cases that are relevant for Cortex Cloud AI Security.
- [How to perform advanced AI Security investigations using XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-ai-security/how-to-perform-advanced-ai-security-investigations-using-xql.md): Working with datasets in Cortex Cloud AI Security.
- [About Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-application-security/about-cortex-cloud-application-security.md)
- [Code-to Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud.md)
- [How the C2C engine works](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/how-the-c2c-engine-works.md)
- [Identify and investigate gap](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/identify-and-investigate-gap.md)
- [Execute remediation workflows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/execute-remediation-workflows.md)
- [The Coverage dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/the-coverage-dashboard.md)
- [C2C in Unified Asset Inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/c2c-in-unified-asset-inventory.md)
- [C2C tab (asset level)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/c2c-tab-asset-level.md)
- [C2C tab (app level)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/c2c-tab-app-level.md)
- [Agentix for C2C](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/agentix-for-c2c.md)
- [Investigate issues with C2C](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/investigate-issues-with-c2c.md)
- [C2C in ASPM Command Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/c2c-in-aspm-command-center.md)
- [Enforce policies with C2C](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/enforce-policies-with-c2c.md)
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/troubleshooting.md)
- [FAQs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/faqs.md)
- [References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references.md)
- [Reference A: Supported integrations and asset stages](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references/reference-a-supported-integrations-and-asset-stages.md)
- [Reference B: Coverage % calculation and configuration toggles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references/reference-b-coverage-calculation-and-configuration-toggles.md)
- [Reference C: Dashboard filters by view](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references/reference-c-dashboard-filters-by-view.md)
- [Reference D: Recommended actions by view and stage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references/reference-d-recommended-actions-by-view-and-stage.md)
- [Reference E: Code-to-Cloud Coverage public API](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references/reference-e-code-to-cloud-coverage-public-api.md)
- [Page Reference F: Call-to-action routing by asset type1](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references/page-reference-f-call-to-action-routing-by-asset-type1.md)
- [Reference G: Unified Asset Inventory fields and deep links](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/code-to-cloud/code-to-cloud/references/reference-g-unified-asset-inventory-fields-and-deep-links.md)
- [About Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/cortex-cloud-data-classification.md)
- [How to create and validate a custom data pattern](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-pattern.md): Learn how to use Cortex Cloud Data Classification to define specific criteria for identifying sensitive data for your unique needs.
- [Custom data patterns: Guardrails and syntax guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-pattern/custom-data-patterns-guardrails-and-syntax-guide.md): Details and examples about the capabilities and limitations with regular expressions in Cortex Cloud Data Classification.
- [How to disable and enable data patterns in Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/how-to-disable-and-enable-data-patterns-in-data-classification.md)
- [How to create and validate a custom data profile](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/how-to-create-and-validate-a-custom-data-profile.md)
- [How to disable and enable data profiles in Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/how-to-disable-and-enable-data-profiles-in-cortex-cloud-data-classification.md)
- [How to report a false positive in Cortex Cloud Data Classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/how-to-report-a-false-positive-in-cortex-cloud-data-classification.md)
- [Topic classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-classification/topic-classification.md)
- [What is Cortex Data Security?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-data-security/what-is-cortex-cloud-data-security.md): Learn about Cortex Cloud Data Security capabilities and benefits.
- [What is Cortex Cloud Identity Security?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/what-is-cortex-cloud-identity-security.md): Cortex Cloud Identity Security can help you address the security challenges of managing identity in cloud environments.
- [Review and improve your Identity Security posture](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/review-and-improve-your-identity-security-posture.md): Learn how to review and improve your Identity Security posture with the provided use case examples.
- [How does Effective Permission Calculation work?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/how-does-effective-permission-calculation-work.md): An explanation of how Effective Permission Calculation works in Cortex Cloud Identity Security.
- [Cortex Cloud Identity Security functionality](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/cortex-cloud-identity-security-functionality.md): About the functionalities of Cortex Cloud Identity Security.
- [Configure Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/configure-cortex-cloud-identity-security.md)
- [Unified Human Identities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/unified-human-identities.md)
- [Achieve the principle of least privilege access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/achieve-the-principle-of-least-privilege-access.md): Use Cortex Cloud Identity Security to achieve the principle of least privilege access.
- [Explore permissions using the simple and advanced access tables](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/explore-permissions-using-the-simple-and-advanced-access-tables.md): Learn how to explore permissions in Cortex Cloud Identity Security using the Simple and Advanced access tables.
- [Create a custom detection rule in Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/create-a-custom-detection-rule-in-cortex-cloud-identity-security.md): Learn how to create a custom detection rule in Cortex Cloud Identity Security.
- [Perform advanced Identity Security investigations using XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/perform-advanced-identity-security-investigations-using-xql.md): Working with datasets in Cortex Cloud Identity Security.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/ingest-logs-and-data-from-okta.md): Learn more about Ingesting logs and data from Okta for use in Cortex Cloud.
- [Enable inactive human identity logs on Azure in Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/enable-inactive-human-identity-logs-on-azure-in-cortex-cloud-identity-security.md): Configuration information for enabling inactive human identity logs on Azure.
- [Manage RBAC and SBAC in Cortex Cloud Identity Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-identity-security/manage-rbac-and-sbac-in-cortex-cloud-identity-security.md): Working with RBAC and SBAC in Cortex Cloud Identity Security.
- [Learn about Cloud ASM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/cloud-asm-concepts.md): Learn about Cloud ASM, including scanning and network mapping.
- [What is Cloud ASM?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/cloud-asm-concepts/what-is-cloud-asm.md): Cloud ASM provides visibility into all the assets in your cloud infrastructure that are exposed to the internet.
- [Scanning](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/cloud-asm-concepts/scanning.md): Cortex Cloud provides targeted scanning of customer networks from an attributed scanning infrastructure.
- [Network mapping](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/cloud-asm-concepts/network-mapping.md): Through a network mapping process, Cortex Cloud discovers and attributes assets to organizations.
- [Enable Cloud ASM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/enable-cloud-asm.md): Enable Cloud ASM data discovery to discover all your unmanaged cloud services and cloud services exposed to the internet.
- [Attack surface management detections](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/attack-surface-management-detections.md): Learn about Attack Surface Management detections, including rules and externally inferred CVEs.
- [Attack surface rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/attack-surface-management-detections/attack-surface-rules.md): Attack surface rules are used to identify risks in your attack surface.
- [Externally inferred CVEs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/attack-surface-management-detections/externally-inferred-cves.md)
- [Attack surface assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/attack-surface-assets.md): The assets discovered in an attack surface management scan are called attack surface assets or external surface assets.
- [Review your unmanaged cloud services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/review-your-unmanaged-cloud-services.md): Review your unmanaged cloud services in your Attack Surface inventory.
- [Review unmanaged cloud issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-attack-surface-management/review-unmanaged-cloud-issues.md): View your unmanaged cloud issues, including service details.
- [About Network Exposure Detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/network-exposure-detection/network-exposure-detection.md): Identify, prioritize, and remediate internet, outbound, and lateral network exposure risks in public cloud environments.
- [What is Cloud Network Analyzer?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/network-exposure-detection/what-is-cloud-network-analyzer.md): Understand how CNA identifies internet, outbound, and lateral exposure across cloud accounts.
- [Internet exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/network-exposure-detection/internet-exposure-detection.md): Learn how CNA detects publicly reachable cloud assets and validates exposure through external network scanning.
- [Outbound exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/network-exposure-detection/outbound-exposure-detection.md): Learn about detecting workloads with unrestricted outbound internet access based on security configurations.
- [East-west exposure detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/network-exposure-detection/east-west-exposure-detection.md): Learn about workloads with unrestricted lateral access and the controls causing that exposure.
- [Investigate an internet exposure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/network-exposure-detection/investigate-an-internet-exposure.md): Investigate internet-exposed assets through Issues and Graph Search.
- [Configure trusted IPs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/network-exposure-detection/configure-trusted-ips.md): Configure trusted public IP ranges excluded from CNA internet exposure evaluations.
- [SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security.md): SaaS Security delivers continuous visibility and control across SaaS identities, connected apps, and AI agents.
- [Setup SaaS Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/setup-saas-security.md): Get started with SaaS Security.
- [Onboard a Supported SaaS Application](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application.md): Onboard a supported SaaS application to track and monitor misconfigurations and compliance violations.
- [Onboard Aha.io](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-aha.io.md): Onboard Aha.io to track misconfigurations and monitor application compliance.
- [Onboard Asana](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-asana.md): Connect an Asana instance to detect posture risks and compliance violations.
- [Onboard Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-atlassian.md): Connect an Atlassian instance to detect posture and compliance risks.
- [Onboard Automox](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-automox.md): Connect an Automox  instance to detect posture risks and compliance violations.
- [Onboard Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-businessmap.md): Connect a Businessmap instance to detect posture risks and compliance violations.
- [Onboard Celonis](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-celonis.md): Connect a Celonis instance to detect posture risks and compliance violations.
- [Onboard Cisco Duo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-cisco-duo.md): Connect Cisco Duo instance to detect posture risks and compliance violations.
- [Onboard Cisco Meraki](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-cisco-meraki.md): Connect a Cisco Meraki instance to detect posture risks and compliance violations.
- [Onboard ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-clickup.md): Connect a ClickUp instance to detect posture risks and compliance violations.
- [Onboard Contentful](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-contentful.md): Connect a Contentful instance to detect posture risks and compliance violations.
- [Onboard Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-couchbase.md): Connect a Couchbase instance to detect posture risks and compliance violations.
- [Onboard Coveo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-coveo.md): Connect a Coveo instance to detect posture risks and compliance violations.
- [Onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-databricks.md): Connect a Databricks instance to detect posture risks and compliance violations.
- [Onboard Datadog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-datadog.md): Connect a Datadog instance to detect posture risks and compliance violations.
- [Onboard Gainsight PX](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-gainsight-px.md): Connect a Gainsight PX instance to detect posture risks and compliance violations.
- [Onboard Grammarly](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-grammarly.md): Connect a Grammarly instance to detect posture risks and compliance violations.
- [Onboard Harness](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-harness.md): Connect a Harness instance to detect posture risks and compliance violations.
- [Onboard Intercom](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-intercom.md): Connect an Intercom instance to detect posture risks and compliance violations.
- [Onboard Jamf Pro](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-jamf-pro.md): Connect a Jamf Pro instance to detect posture risks and compliance violations.
- [Onboard JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-jumpcloud.md): Connect a JumpCloud instance to detect posture risks and compliance violations.
- [Onboard Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-kustomer.md): Connect a Kustomer instance to detect posture risks and compliance violations.
- [Onboard Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-microsoft-entra-id.md): Connect a Microsoft Entra ID instance to detect posture risks and compliance violations.
- [Onboard Monday.com](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-monday.com.md): Connect a Monday.com instance to detect posture risks and compliance violations.
- [Onboard MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-mongodb-atlas.md): Connect a MongoDB Atlas instance to detect posture risks and compliance violations.
- [Onboard MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-mulesoft.md): Connect a MuleSoft instance to detect posture risks and compliance violations.
- [Onboard Mural](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-mural.md): Connect a Mural instance to detect posture risks and compliance violations.
- [Onboard Office 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-office-365.md): Connect an Office 365 instance to detect posture risks and compliance violations.
- [Onboard Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-okta.md): Connect an Okta instance to detect posture risks and compliance violations.
- [Onboard PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-pagerduty.md): Connect a PagerDuty instance to detect posture risks and compliance violations.
- [Onboard Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-redis-labs.md): Connect a Redis Labs instance to detect posture risks and compliance violations.
- [Onboard Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-salesforce.md): Connect a Salesforce instance to detect posture risks and compliance violations.
- [Onboard SAP Ariba](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-sap-ariba.md): Connect a SAP Ariba instance to detect posture risks and compliance violations.
- [Onboard Sentry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-sentry.md): Connect a Sentry instance to detect posture risks and compliance violations.
- [Onboard ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-servicenow.md): Connect a ServiceNow instance to detect posture risks and compliance violations.
- [Onboard Shopify](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-shopify.md): Connect a Shopify instance to detect posture risks and compliance violations.
- [Onboard Slack Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-slack-enterprise.md): Connect a Slack instance to detect posture risks and compliance violations.
- [Onboard Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-sumo-logic.md): Connect a Sumo Logic instance to detect posture risks and compliance violations.
- [Onboard Workday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-workday.md): Connect a Workday instance to detect posture risks and compliance violations.
- [Onboard Wrike](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-wrike.md): Connect a Wrike instance to detect posture risks and compliance violations.
- [Onboard YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/onboard-a-supported-saas-application/onboard-youtrack.md): Connect a YouTrack instance to detect posture risks and compliance violations.
- [SaaS Security Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-security-overview.md): This dashboard aggregates and presents security data from all four core SaaS Security pillars including: SSPM (Posture), SaaS Identity Security, SaaS Data Security, and SaaS Agent Security.
- [SaaS Security Checks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-security-checks.md): The dashboard captures key metrics to help you remediate SaaS assets at risk
- [Provider Instances Security Check](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/provider-instances-security-check.md): This page consolidates application security posture data across all onboarded instances
- [Detection Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/detection-rules.md): View Cloud Security Posture Rules
- [Remediation Actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/remediation-actions.md): Learn more about actions available to remediate Issues.
- [Create and monitor tickets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/create-and-monitor-tickets.md): Learn more about creating a synced ticket to remediate an issue.
- [SaaS AI Agent Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security.md): SaaS AI Agent Security helps you secure AI agents deployed across enterprise SaaS environments.
- [Setup SaaS Security for AISPM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/setup-saas-security-for-aispm.md): Get started with SaaS Agent Security.
- [Onboard SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents.md): Learn more about how to onboard specific AI Agents.
- [Onboard Atlassian Rovo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-atlassian-rovo.md): Connect Atlassian Rovo to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Box AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-box-ai-agents.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-chatgpt-enterprise.md): Connect Box AI Agents to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Cursor Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-cursor-enterprise.md): Connect Cursor Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-gemini-enterprise.md): Connect Gemini Enterprise to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard M365 Copilot](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-m365-copilot.md): Connect M365 Copilot to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Microsoft Copilot Studio](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-microsoft-copilot-studio.md): Connect Microsoft Copilot Studio to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Onboard Service Now](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/onboard-saas-ai-agents/onboard-service-now.md): Connect Service Now to SaaS Agent Security to gain total visibility and control over your AI ecosystem.
- [Manage SaaS AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents.md)
- [View AI Agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-ai-agents.md)
- [View Datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-datasets.md): The Datasets view provides a detailed look at the Inference Datasets.
- [View Agent Tools](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/saas-security/saas-security/saas-ai-agent-security/manage-saas-ai-agents/view-agent-tools.md): SaaS Agent Tools go beyond traditional scans that  focus on an inventory of previously vendor vetted, underlying tools.
- [Vulnerability management in Cortex Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-management-in-cortex-cloud.md): Vulnerability management helps you identify, assess, prioritize, and remediate security vulnerabilities across your entire IT infrastructure, including endpoints, code, and cloud.
- [Cortex Cloud vulnerability concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-management-in-cortex-cloud/cortex-cloud-vulnerability-concepts.md): Familiarize yourself with Cortex Cloud vulnerability concepts.
- [Vulnerability Management dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-management-in-cortex-cloud/vulnerability-management-dashboard.md): Visualize your most pressing risks, changes to risk over time, and remediation progress on the Vulnerability Management dashboard.
- [Cortex Vulnerability Risk Score](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/cortex-vulnerability-risk-score.md): Learn how Cortex Cloud calculates and displays CVRS to prioritize vulnerability remediation.
- [Vulnerability policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-policies.md): A vulnerability policy defines the action you want to take for a specific set of vulnerability findings.
- [Create a vulnerability policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-policies/create-a-vulnerability-policy.md): Create vulnerability policies that create issues or prevent findings based on defined conditions and scope.
- [Update the Ignored CVEs, Asset Groups, and Assets policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-policies/update-the-ignored-cves-asset-groups-and-assets-policy.md): Update the ignored CVEs, asset groups, and assets policy to prevent matching vulnerability findings from creating issues.
- [Modify a vulnerability policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-policies/modify-a-vulnerability-policy.md): Update vulnerability issue-creation and prevention policies through the policy wizard.
- [Configure a block grace period](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-policies/configure-a-block-grace-period.md): Configure remediation grace periods that delay Kubernetes deployment blocks or build failures after vulnerability disclosure.
- [Enable or disable a vulnerability policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-policies/enable-or-disable-a-vulnerability-policy.md): Enable or disable vulnerability issue-creation and prevention policies to control actions for matching findings.
- [Investigate and remediate vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/investigate-and-remediate-vulnerabilities.md): Investigate, prioritize, and remediate vulnerabilities through issues, findings, and vulnerable assets.
- [Vulnerability Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/vulnerability-intelligence.md): Vulnerability Intelligence is an in-product, real-time feed that provides vulnerability data and threat intelligence from a variety of certified upstream sources.
- [Emerging Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/emerging-vulnerabilities.md): The Emerging Vulnerabilities page is a a centralized hub for security teams to research, assess, and respond to global, emergent threats and zero-day exploits.
- [Recast CVSS scores and CVSS severities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/vunerability-management/recast-cvss-scores-and-cvss-severities.md): Customize CVSS scores and CVSS severities in the platform to align your risk management approach with your organizational context and priorities.
- [Cloud security rules and policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/cloud-security-rules-and-policies.md): Learn how cloud security rules and policies detect threats and misconfigurations across your environment.
- [Cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/cloud-security-rules.md): Learn about out-of-the-box and custom cloud security rules.
- [Cloud security policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/cloud-security-policies.md): Learn about cloud security policies.
- [Create and manage cloud security rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules.md): Create and manage custom cloud security rules for detecting cloud security risks.
- [Create a graph rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-graph-rule.md): Create custom graph detection rules that identify risky relationships and attack paths.
- [Create a configuration rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-configuration-rule.md): Create configuration rules that identify cloud resource misconfigurations and policy violations.
- [Create a data rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-data-rule.md): Create data rules to detect data risks, malware, and classification issues.
- [Create an identity rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-identity-rule.md): Create identity rules to detect excessive or unused cloud permissions.
- [Create a network exposure rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-a-network-exposure-rule.md): Create network exposure rules to detect risky inbound, outbound, and east-west access.
- [Create an AI rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-ai-rule.md): Create AI rules to detect risks and misconfigurations across your AI ecosystem.
- [Create an attack path rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/create-an-attack-path-rule.md): CreaCreate attack path rules that identify breach paths to high-value cloud assets.te rules that identify combined risks forming potential attack paths.
- [View cloud security rule status](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/view-cloud-security-rule-status.md): View, filter, and sort the status of cloud security rules.
- [Edit a cloud security rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/edit-a-cloud-security-rule.md): Edit cloud security rules and understand how changes affect related issues.
- [Enable or disable a rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/enable-or-disable-a-rule.md): Enable or disable cloud security rules to control when they evaluate assets.
- [Use an existing rule to create a new one](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/use-an-existing-rule-to-create-a-new-one.md): Duplicate an existing cloud security rule and customize it for your needs.
- [Delete a custom cloud security rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-rules/delete-a-custom-cloud-security-rule.md): Delete custom cloud security rules that are no longer needed.
- [Create and manage cloud security policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies.md): Create and manage cloud security policies.
- [Create a cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/create-a-cloud-security-policy.md): Create a cloud security policy that applies security rules to selected cloud assets.
- [Edit a cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/edit-a-cloud-security-policy.md): Edit cloud security policies to update their details, rules, and scopes.
- [Enable or disable a policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/enable-or-disable-a-policy.md): Enable or disable custom and default cloud security policies.
- [Use an existing policy to create a new one](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/use-an-existing-policy-to-create-a-new-one.md): Duplicate an existing cloud security policy and tailor it to your needs.
- [Delete a custom cloud security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-security-rules-and-policies/create-and-manage-cloud-security-policies/delete-a-custom-cloud-security-policy.md): Remove custom cloud security policies that are no longer needed.
- [About cloud workload policies and rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies-and-rules.md)
- [How policies and rules work together](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/how-policies-and-rules-work-together.md)
- [Cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies.md)
- [Types of cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies.md)
- [Trusted image cloud workload policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies/types-of-cloud-workload-policies.md)
- [Cloud Workload Policies page](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page.md)
- [Enable or disable a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/enable-or-disable-a-cloud-workload-policy.md)
- [Create a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/create-a-cloud-workload-policy.md)
- [Use an existing policy to create a new cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/use-an-existing-policy-to-create-a-new-cloud-workload-policy.md)
- [Edit a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/edit-a-cloud-workload-policy.md)
- [Delete a cloud workload policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/delete-a-cloud-workload-policy.md)
- [Cloud workload preventive action](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action.md)
- [Cloud workload rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules.md)
- [Default (pre-defined) rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules.md)
- [Custom (user-defined) rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules.md)
- [Cloud Workload Rules page](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page.md)
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules/create-a-new-custom-detection-rule.md)
- [Use an existing rule to create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules/use-an-existing-rule-to-create-a-new-custom-detection-rule.md)
- [Edit a custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules/edit-a-custom-detection-rule.md)
- [Delete a custom detection rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cloud-workload-policies-and-rules/cloud-workload-rules/delete-a-custom-detection-rule.md)
- [Learn about base image rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/base-image-rules/base-images-rule.md)
- [Create a base image rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/base-image-rules/create-a-base-images-rule.md)
- [Find the base image for an asset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/base-image-rules/prerequisites.md)
- [About serverless function posture security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-security.md)
- [Onboard cloud providers for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/onboard-cloud-providers-for-serverless-functions.md)
- [Serverless function posture rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-rules.md)
- [Manage serverless function rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-rules/manage-serverless-function-rules.md)
- [Create serverless function rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-rules/create-serverless-function-rules.md)
- [Create an attack path rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-rules/create-an-attack-path-rule-for-serverless-functions.md)
- [Create a configuration rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-rules/create-a-configuration-rule-for-serverless-functions.md)
- [Create a network exposure rule for serverless functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-rules/create-a-network-exposure-rule-for-serverless-functions.md)
- [Serverless function posture policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-policies.md)
- [Manage serverless function policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-policies/manage-serverless-function-policies.md)
- [Create serverless function policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-posture-policies/create-serverless-function-policies.md)
- [Serverless function usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/serverless-function-posture-security/serverless-function-usage.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm.md)
- [What is the Broker VM?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/what-is-the-broker-vm.md)
- [Set up and configure Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm.md)
- [Broker VM image installations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations.md)
- [Set up Broker VM on Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-alibaba-cloud.md)
- [Set up Broker VM on Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-amazon-web-services.md)
- [Set up Broker VM on Google Cloud Platform (GCP)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-google-cloud-platform-gcp.md)
- [Set up Broker VM on KVM using Ubuntu](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-kvm-using-ubuntu.md)
- [Set up Broker VM on Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-azure.md)
- [Set up Broker VM on Microsoft Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-hyper-v.md)
- [Set up Broker VM on Nutanix Hypervisor](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-nutanix-hypervisor.md)
- [Set up Broker VM on VMware ESXi using vSphere Client](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-vmware-esxi-using-vsphere-client.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets.md)
- [Manage Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm.md)
- [Edit Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/edit-broker-vm-configuration.md)
- [Increase Broker VM storage allocated for data caching](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/increase-broker-vm-storage-allocated-for-data-caching.md)
- [Monitor Broker VM using Prometheus](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/monitor-broker-vm-using-prometheus.md)
- [Collect Broker VM Logs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/collect-broker-vm-logs.md)
- [Upgrade Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/upgrade-broker-vm.md)
- [Update Broker VM applets independently](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/update-broker-vm-applets-independently.md)
- [Import Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/import-broker-vm-configuration.md)
- [Open Live Terminal](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/open-live-terminal.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/add-broker-vm-to-cluster.md)
- [Switchover Primary Node in Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/switchover-primary-node-in-cluster.md)
- [Remove from Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm/remove-from-cluster.md)
- [Manage Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/manage-broker-vm-data-collector-applets.md)
- [Broker VM High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster.md)
- [Configure High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster/configure-high-availability-cluster.md)
- [Manage Broker VM clusters](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters.md)
- [View cluster details](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/view-cluster-details.md)
- [Edit cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/edit-cluster.md)
- [Add applet to cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-applet-to-cluster.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-broker-vm-to-cluster.md)
- [Remove cluster](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/remove-cluster.md)
- [Broker VM notifications](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/broker-vm-notifications.md)
- [Monitor Broker VM activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/monitor-broker-vm-activity.md)
- [Troubleshoot Broker VM applet errors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/broker-vm/troubleshoot-broker-vm-applet-errors.md)
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period-based retention.
- [What are datasets?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management/what-are-datasets.md): Learn how to import, delete, and interact with custom or third-party datasets in Cortex Cloud.
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management/lookup-datasets.md): Learn more about lookup datasets to correlate data from a data source with events in your environment.
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management/lookup-datasets/import-a-lookup-dataset.md)
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management/lookup-datasets/download-json-file-of-lookup-dataset.md)
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management/lookup-datasets/set-time-to-live-for-lookup-datasets.md)
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md): Learn more about the monitored Cortex Cloud datasets and dataset views activities.
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/manage-compute-units.md): Learn more about managing and tracking your compute units usage for API and Cold Storage XQL queries.
- [Compute units usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/manage-compute-units/compute-units-usage.md): Learn more about how to compute units CU) works according to your license and available options after reaching your quota.
- [What are Cortex Cloud data sources and connectors?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/what-are-cortex-cloud-data-sources.md): Learn more about Cortex Cloud data sources and connectors with a unified approach to integrations.
- [Complete data source and connector catalog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/complete-data-source-catalog.md): Learn more about the complete data source and connector catalog available in Cortex Cloud.
- [Vendor-specific data sources and connectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/abuseipdb.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/abuseipdb/abuseipdb.md)
- [Aha](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/aha.md)
- [Aha!](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/aha/aha.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/aiops.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/aiops/aiops.md)
- [Amazon](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon.md)
- [Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-web-services.md)
- [AWS Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/amazon/aws-automation-and-collection.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anomali.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anomali/anomali.md)
- [Anthropic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anthropic.md)
- [Claude](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/anthropic/claude.md)
- [Apollo.io](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/apollo.io.md)
- [Apollo.io](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/apollo.io/apollo.io.md)
- [Articulate Global](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/articulate-global.md)
- [Articulate Global](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/articulate-global/articulate-global.md)
- [Asana](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/asana.md)
- [Asana](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/asana/asana.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/atlassian.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/atlassian/atlassian.md)
- [Atlassian Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/atlassian/atlassian-automation-and-collection.md)
- [Automox](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/automox.md)
- [Automox](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/automox/automox.md)
- [Box](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/box.md)
- [Box](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/box/box.md)
- [Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/businessmap.md)
- [Businessmap](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/businessmap/businessmap.md)
- [Celonis](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/celonis.md)
- [Celonis](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/celonis/celonis.md)
- [ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/chatgpt-enterprise.md)
- [ChatGPT Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/chatgpt-enterprise/chatgpt-enterprise.md)
- [Cisco](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cisco.md)
- [Cisco Duo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cisco/cisco-duo.md)
- [Cisco Meraki](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cisco/cisco-meraki.md)
- [ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/clickup.md)
- [ClickUp](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/clickup/clickup.md)
- [Contentful](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/contentful.md)
- [Contentful](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/contentful/contentful.md)
- [Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/couchbase.md)
- [Couchbase](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/couchbase/couchbase.md)
- [Coveo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/coveo.md)
- [Coveo](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/coveo/coveo.md)
- [Cribl](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cribl.md)
- [Cribl connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cribl/cribl-connector.md)
- [Cursor](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cursor.md)
- [Cursor](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cursor/cursor.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cyberark.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/cyberark/cyberark.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/databricks.md)
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/databricks/how-to-onboard-databricks.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/databricks/databricks.md)
- [DataDog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/datadog.md)
- [DataDog](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/datadog/datadog.md)
- [Elastic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic.md)
- [ElasticSearch](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/elastic/elasticsearch.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/forcepoint.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/forcepoint/forcepoint.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/freshworks.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/freshworks/freshworks.md)
- [Gainsight](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/gainsight.md)
- [Gainsight](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/gainsight/gainsight.md)
- [Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/gemini-enterprise.md)
- [Gemini Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/gemini-enterprise/gemini-enterprise.md)
- [Generic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/generic.md)
- [Generic MCP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/generic/generic-mcp.md)
- [Generic SQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/generic/generic-sql.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/github.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/github/github.md)
- [GitLab](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/gitlab.md)
- [GitLab](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/gitlab/gitlab.md)
- [Google](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google.md)
- [Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace.md)
- [Google Workspace connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace/google-workspace-connector.md)
- [Google Workspace Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace/google-workspace-automation-and-collection.md)
- [Harness](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/harness.md)
- [Harness](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/harness/harness.md)
- [IBM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ibm.md)
- [IBM QRadar](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ibm/ibm-qradar.md)
- [Intercom](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/intercom.md)
- [Intercom](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/intercom/intercom.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/izoologic.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/izoologic/izoologic.md)
- [Jamf](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/jamf.md)
- [Jamf Pro](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/jamf/jamf-pro.md)
- [JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/jumpcloud.md)
- [JumpCloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/jumpcloud/jumpcloud.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/koi.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/koi/koi.md)
- [Kubernetes](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes.md)
- [Onboard the Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/onboard-the-kubernetes-connector.md)
- [What's new in Kubernetes connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/whats-new-in-kubernetes-connector.md)
- [Supported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/supported-kubernetes-distributions.md)
- [Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kustomer.md)
- [Kustomer](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kustomer/kustomer.md)
- [LastPass](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/lastpass.md)
- [LastPass](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/lastpass/lastpass.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mail-utilities.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mail-utilities/mail-utilities.md)
- [Microsoft](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft.md)
- [Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-azure.md)
- [Microsoft Copilot Studio](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-copilot-studio.md)
- [Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-entra-id.md)
- [Microsoft365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft365.md)
- [Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365.md)
- [Microsoft 365 Copilot](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365-copilot.md)
- [Microsoft 365 (Posture)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365-posture.md)
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-365-posture/how-to-onboard-microsoft-365.md)
- [Microsoft Teams](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-teams.md)
- [Azure Log Analytics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/azure-log-analytics.md)
- [Azure Services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/azure-services.md)
- [Microsoft Active Directory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-active-directory.md)
- [Microsoft Graph](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-graph.md)
- [Microsoft Identity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-identity.md)
- [Microsoft Security Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-security-automation-and-collection.md)
- [M365 Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/microsoft/m365-automation-and-collection.md)
- [Monday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/monday.md)
- [Monday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/monday/monday.md)
- [Monday.com](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/monday/monday.com.md)
- [MongoDB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mongodb.md)
- [MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mongodb/mongodb-atlas.md)
- [MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mulesoft.md)
- [MuleSoft](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mulesoft/mulesoft.md)
- [Mural](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mural.md)
- [Mural](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/mural/mural.md)
- [Nintex Workflow Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/nintex-workflow-cloud.md)
- [Nintex Workflow Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/nintex-workflow-cloud/nintex-workflow-cloud.md)
- [Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/okta.md)
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/okta/ingest-logs-and-data-from-okta.md)
- [Okta Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/okta/okta-automation-and-collection.md)
- [Okta connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/okta/okta-connector.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/oracle.md)
- [Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/oracle/oracle-cloud-infrastructure.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/oracle/oracle.md)
- [PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/pagerduty.md)
- [PagerDuty Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/pagerduty/pagerduty-automation-and-collection.md)
- [PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/pagerduty/pagerduty.md)
- [Ping Identity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ping-identity.md)
- [Ping Identity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/ping-identity/ping-identity.md)
- [Pipedrive](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/pipedrive.md)
- [Pipedrive](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/pipedrive/pipedrive.md)
- [Qualtrics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/qualtrics.md)
- [Qualtrics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/qualtrics/qualtrics.md)
- [Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/redis-labs.md)
- [Redis Labs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/redis-labs/redis-labs.md)
- [Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/salesforce.md)
- [Salesforce connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/salesforce/ingest-and-run-salesforce-automation-and-remediation.md)
- [SAP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/sap.md)
- [SAP Ariba](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/sap/sap-ariba.md)
- [Sentry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/sentry.md)
- [Sentry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/sentry/sentry.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/servicenow.md)
- [ServiceNow Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/servicenow/servicenow-automation-and-collection.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/servicenow/servicenow.md)
- [Shopify](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/shopify.md)
- [Shopify](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/shopify/shopify.md)
- [Slack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/slack.md)
- [Slack Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/slack/slack-automation-and-collection.md)
- [Slack Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/slack/slack-enterprise.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/smb.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/smb/smb.md)
- [Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/snowflake.md)
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/snowflake/how-to-onboard-snowflake.md)
- [Splunk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/splunk.md)
- [Splunk Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/splunk/splunk-automation-and-collection.md)
- [Splunk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/splunk/splunk.md)
- [Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/sumo-logic.md)
- [Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/sumo-logic/sumo-logic.md)
- [Terraform](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/terraform.md)
- [Terraform](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/terraform/terraform.md)
- [VMware](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/vmware.md)
- [VMWare](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/vmware/vmware.md)
- [Workday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/workday.md)
- [Workday Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/workday/workday-automation-and-collection.md)
- [Workday](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/workday/workday.md)
- [YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/youtrack.md)
- [YouTrack](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/youtrack/youtrack.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zendesk.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zendesk/zendesk.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zscaler.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/zscaler/zscaler.md)
- [Connectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/connectors.md)
- [Standard data sources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/standard-data-sources.md)
- [Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-service-provider-csp-onboarding.md): Learn about onboarding your cloud service provider to Cortex Cloud.
- [Generic on-premise data collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets.md)
- [Activate DSPM Fileshare](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-fileshare.md)
- [Activate Registry Scanner](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-registry-scanner.md)
- [Activate Transporter](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter.md)
- [Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations.md)
- [Cortex Internals](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/cortex-internals.md)
- [Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/cloud-next-generation-firewall.md)
- [Ingest data from Cloud Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/cloud-next-generation-firewall/ingest-data-from-cloud-next-generation-firewall.md)
- [Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/next-generation-firewall.md)
- [Panorama](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/next-generation-firewall/panorama.md)
- [Palo Alto Networks Cortex](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/palo-alto-networks-cortex.md)
- [Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/prisma-access.md)
- [Palo Alto Networks Prisma](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/prisma-access/palo-alto-networks-prisma.md)
- [WildFire Cloud](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/palo-alto-networks-integrations/wildfire-cloud.md)
- [Cloud Posture and Runtime Security data sources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources.md): Learn more about the Cloud Posture and Runtime Security data sources in Cortex Cloud.
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-databricks.md): How to get started with the third-party Databricks data source.
- [How to onboard on-premise assets to Cortex Cloud Data Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-on-premise-assets-to-cortex-cloud-data-security.md): Set up Data Security for on-premise file shares and databases using Broker VM.
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-microsoft-365.md): How to get started with the Microsoft 365 data source.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/ingest-logs-and-data-from-okta.md): Learn more about Ingesting logs and data from Okta for use in Cortex Cloud.
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-snowflake.md): How to get started with the third-party Snowflake data source.
- [Container Registries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning.md)
- [Registry Components](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/registry-components.md)
- [How Container Registry Scanning Works](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/how-container-registry-scanning-works.md)
- [Configure registry scanning for cloud accounts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/configure-registry-scanning-for-cloud-accounts.md)
- [Modify the container registry scanning scope](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/modify-the-container-registry-scanning-scope.md)
- [Scan re-evaluation process](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/scan-re-evaluation-process.md)
- [Connect Docker Hub registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry.md)
- [Manage a Docker Hub connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry/manage-a-docker-hub-connector.md)
- [Connect Docker V2 compliant container registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry.md)
- [Manage a Docker V2 connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry/manage-a-docker-v2-connector.md)
- [Connect GitLab container registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry.md)
- [Manage a GitLab Container Registry connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry/manage-a-gitlab-container-registry-connector.md)
- [Connect Harbor registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry.md)
- [Manage a Harbor connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry/manage-a-harbor-connector.md)
- [Connect JFrog container registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry.md)
- [Manage a JFrog connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry/manage-a-jfrog-connector.md)
- [Connect Sonatype Nexus registry](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry.md)
- [Manage a Sonatype connector](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry/manage-a-sonatype-connector.md)
- [Administration and troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting.md): Learn more about the administration and troubleshooting of the different data collector integrations in Cortex Cloud.
- [Manage instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances.md)
- [Add a new data source or instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/add-a-new-data-source-or-instance.md)
- [How to configure the scanning settings for supported services](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/how-to-configure-the-scanning-settings-for-supported-services.md)
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/manage-cloud-instances.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/update-cloud-permissions-after-cortex-release-updates.md)
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/pending-cloud-instances.md)
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/troubleshoot-errors-on-cloud-instances.md)
- [Manage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/manage-kubernetes-connector-instances.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations/add-an-integration-instance.md)
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations/configure-integration-permissions.md)
- [Troubleshoot Integrations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/integrations/troubleshoot-integrations.md)
- [Verify collector connectivity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/verify-collector-connectivity.md)
- [About health issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues.md)
- [Investigate and resolve health issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues/investigate-and-resolve-health-issues.md)
- [Monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues/monitor-data-ingestion-health.md)
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/marketplace/cortex-marketplace.md): Search Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/marketplace/content-pack-support-types.md): Types of content packs support - Cortex supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Cortex Cloud content](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/marketplace/cortex-cloud-content.md): The type of content in Cortex Cloud
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/marketplace/marketplace-faqs.md): Frequently Asked Questions about Cortex Cloud Marketplace Content
- [Content changes when upgrading Cortex Cloud versions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/marketplace/content-changes-when-upgrading-cortex-cloud-versions.md): Content updates when upgrading Cortex Cloud versions.
- [About Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli.md): The Cortex CLI is a unified command-line tool integrating Cloud Workload Protection, API Security, and Code Security scans into a single executable.
- [Connect Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/connect-cortex-cli.md)
- [Installation workflows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/connect-cortex-cli/installation-workflows.md): Install Cortex CLI using a package manager, manual download, or the Cortex Cloud interface.
- [Manage the CLI after installation](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/connect-cortex-cli/manage-the-cli-after-installation.md): Upgrade, pin, uninstall, or update Cortex CLI through automated downloads.
- [Authenticate credentials](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/connect-cortex-cli/authenticate-credentials.md): Configure Cortex CLI credentials using a file, environment variables, or command-line flags.
- [Self-service API keys for CLI scans](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/connect-cortex-cli/self-service-api-keys-for-cli-scans.md)
- [Cortex CLI usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-usage.md)
- [Cortex CLI common command line reference guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-common-command-line-reference-guide.md)
- [Cortex CLI for Code Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security.md)
- [Cortex CLI usage for Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security/cortex-cli-usage-for-cortex-cloud-application-security.md)
- [Cortex CLI Cortex Cloud Application Security command line reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security/cortex-cli-cortex-cloud-application-security-command-line-reference.md)
- [Custom Cortex checks and signature verification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security/cortex-cli-cortex-cloud-application-security-command-line-reference/custom-cortex-checks-and-signature-verification.md): Load custom Cortex checks and optionally verify their signatures.
- [Cortex CLI pre-commit hooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-commit-hooks.md): Integrate Application Security secrets scanner as pre-commit hooks into your workflows to scan for errors on your machine before local commits.
- [Pre-commit hook usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-commit-hooks/pre-commit-hook-usage.md)
- [Cortex CLI pre-receive hooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-receive-hooks.md): Integrate the Application Security secrets scanner as a pre-receive hook into your workflows to scan for errors before code is accepted into your repository.
- [Pre-receive hook usage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-receive-hooks/pre-receive-hook-usage.md)
- [Cortex CLI for Cloud Workload Protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-cloud-workload-protection.md)
- [Cloud Workload Protection command line reference](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-cloud-workload-protection/cloud-workload-protection-command-line-reference.md)
- [Cortex CLI for API Security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-api-security.md)
- [Cortex CLI API Security command line reference guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-api-security/cortex-cli-api-security-command-line-reference-guide.md)
- [API Security scan report schema](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-api-security/api-security-scan-report-schema.md): Reference schema for API Security scan reports.
- [API Security scan output example](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cli/cortex-cli-for-api-security/api-security-scan-output-example.md): Example API Security scan report output.
- [About Cortex Cloud XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/cortex-cloud-xql.md)
- [Get started with XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql.md): XQL is the Palo Alto Networks Cortex Query Language used in Cortex Cloud.
- [XQL language features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/xql-language-features.md): Learn more about the Cortex Query Language features to query for raw network and endpoint data.
- [XQL Language Structure](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/xql-language-structure.md): Learn more about the Cortex Query Language structure when creating a query.
- [Supported operators](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/supported-operators.md): Cortex Query Language supports specific comparison, boolean, and set operators in Cortex Cloud.
- [Datasets and presets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/datasets-and-presets.md): The Cortex Query Language supports built-in datasets, custom datasets, and presets.
- [About examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/about-examples.md): Learn more about the Cortex Query Language (XQL) examples provided.
- [JSON functions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/json-functions.md): Learn more about how Cortex Cloud treats JSON functions in the Cortex Query Language.
- [How to filter for empty values in the results table](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/how-to-filter-for-empty-values-in-the-results-table.md): Learn how to filter for empty values in the results table in Cortex Query Language.
- [Understanding string manipulation in XQL](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/get-started-with-xql/understanding-string-manipulation-in-xql.md): Learn more about string manipulation in Cortex Query Language (XQL) using double and triple quotes.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities.md): Learn more about the Cortex Query Language (XQL) entities available in the Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-authentication-query.md)
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-event-log-query.md)
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-file-query.md)
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-image-load-query.md)
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-network-connections-query.md)
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-network-query.md)
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-process-query.md)
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/xql-query-entities/create-registry-query.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Manage your query library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/manage-your-query-library.md): Cortex Cloud provides a Query Library for saving and managing your own queries.
- [Cortex XQL syntax, parameters, and examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/cortex-xql-syntax-parameters-and-examples.md): Comprehensive syntax rules and structural requirements for XQL queries
- [What is Graph Search?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/what-is-graph-search.md): Learn more about how to use Graph Search to search assets, findings, and their contextual data.
- [Get started with Graph Search queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/get-started-with-graph-search-queries.md): Learn more about how to get started before building a Graph Search query.
- [How to build Graph Search queries?](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/how-to-build-graph-search-queries.md): Learn more about building Graph Search queries using the built-in query interface.
- [Understand Graph Search query results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/understand-graph-search-query-results.md): Learn more about the Graph Search query results.
- [Create Graph Search query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/create-graph-search-query.md): Learn how to create Graph Search queries in Cortex Cloud.
- [Graph Search examples](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/graph-search-examples.md): Learn how to build Graph Search queries by working through a few examples.
- [Manage the Graph Search Query Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/manage-the-graph-search-query-library.md): Learn more about the Cortex Cloud Graph Search Query Library to manage your queries.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/edit-and-run-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/edit-and-run-queries-in-query-center/query-center-reference-information.md): Descriptions of the fields in the Query Center table.
- [FAQ on Graph Search](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/faq-on-graph-search.md): Answer some frequently asked questions relating to Graph Search.
- [Supported assets and findings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/supported-assets-and-findings.md)
- [Create detection rules based on graph search](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/graph-search/create-detection-rules-based-on-graph-search.md)
- [About API specification inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/api-specification-inventory/api-specification-inventory.md)
- [Import API specification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/api-specification-inventory/import-api-specification.md)
- [Learn how to a migrate a new Broker VM image](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/migrate-to-a-new-broker-vm-image/migrating-to-a-new-broker-vm-image.md): Learn more about migrating to the latest broker VM image in Cortex Cloud.
- [Standalone Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/migrate-to-a-new-broker-vm-image/standalone-broker-vm.md): Learn more about migrating a standalone broker VM image.
- [Broker VM high availability cluster node](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/migrate-to-a-new-broker-vm-image/broker-vm-high-availability-cluster-node.md): Learn more about migrating a broker VM High Availability (HA) cluster node.

## Kubernetes Security

- [Kubernetes Security](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-security.md)
- [What's new in Kubernetes Connector?](https://cortex-docs.paloaltonetworks.com/kubernetes-security/whats-new-in-kubernetes-connector.md)
- [KSPM limitations and system components](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-limitations-and-system-components.md)
- [Supported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/kubernetes-security/supported-kubernetes-distributions.md)
- [Onboard the Kubernetes Connector](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector.md)
- [OpenShift container registry](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry.md)
- [Deploy the Kubernetes Connector via GitOps](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops.md)
- [Repository architecture and tenant management](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/repository-architecture-and-tenant-management.md)
- [Deploy with Flux CD](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/deploy-with-flux-cd.md)
- [Deploy with ArgoCD](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/deploy-with-argocd.md)
- [Mirror connector images to a private registry](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry.md)
- [Use kcli to mirror connector images](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry/use-kcli-to-mirror-connector-images.md)
- [KSPM dashboard](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-dashboard.md)
- [KSPM graph](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph.md)
- [Asset detail card](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/asset-detail-card.md)
- [Security finding categories](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/security-finding-categories.md)
- [Kubernetes clusters](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-clusters.md)
- [Agentless Kubernetes security](https://cortex-docs.paloaltonetworks.com/kubernetes-security/agentless-kubernetes-security.md)
- [Kubernetes Resources Inventory](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory.md)
- [Kubernetes pods](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods.md)
- [Manage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances.md): You can manage the Kubernetes Connector instances on the Data Sources & Integrations page. You can check the status, edit, or delete Kubernetes Connector instances.
- [Run an on-demand Kubernetes cluster scan](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan.md): Request an Inventory or Nodes and containers scan for an eligible Kubernetes cluster.
- [Cloud workload policies and rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules.md)
- [How policies and rules work together](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/how-policies-and-rules-work-together.md)
- [Cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies.md)
- [Types of cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies.md)
- [Trusted image cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies/trusted-image-cloud-workload-policies.md)
- [Cloud workload policies page](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page.md)
- [Widgets panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/widgets-panel.md)
- [Change the layout of the policies table](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/change-the-layout-of-the-policies-table.md)
- [Policy details panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/policy-details-panel.md)
- [Manage cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies.md): Create, copy, edit, enable, disable, and delete cloud workload policies.
- [Cloud workload preventive action](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action.md)
- [Cloud workload rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules.md)
- [Default (pre-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules.md)
- [Custom (user-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules.md)
- [Cloud workload rules page](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page.md)
- [Filter page results](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/filter-page-results.md)
- [Change the layout of the rules table](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/change-the-layout-of-the-rules-table.md)
- [Rule details panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/rule-details-panel.md)
- [Create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/create-a-new-custom-detection-rule.md): Create scanner-specific custom detection rules for Cloud Workload.
- [Use an existing rule to create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/use-an-existing-rule-to-create-a-new-custom-detection-rule.md)
- [Edit a custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/edit-a-custom-detection-rule.md)
- [Delete a custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/delete-a-custom-detection-rule.md)

## Application Security

- [Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/application-security/application-security/readme.md)
- [Onboard data sources](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources.md): Onboard VCS, integrate CI tools, registries and ingest third-party data for a comprehensive view of your application and supply chain security.
- [Onboard version control systems](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems.md)
- [AWS CodeCommit](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/aws-codecommit.md)
- [Onboard AWS CodeCommit](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/aws-codecommit/onboard-aws-codecommit.md): Connect AWS CodeCommit repositories to Cortex Cloud and manage the integration.
- [Reference A: IAM Service Role permissions](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/aws-codecommit/reference-a-iam-service-role-permissions.md): AWS CodeCommit permissions configured by the CloudFormation integration template
- [Azure DevOps](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/azure-devops.md)
- [Onboard Azure DevOps](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/azure-devops/onboard-azure-devops.md): Connect Azure DevOps repositories to Cortex Cloud and manage the integration.
- [Reference A: Subscribed events and permission scopes](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/azure-devops/reference-a-subscribed-events-and-permission-scopes.md)
- [Reference B: Instance-scope troubleshooting](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/azure-devops/reference-b-instance-scope-troubleshooting.md)
- [Reference C: Repository-scope troubleshooting](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/azure-devops/reference-c-repository-scope-troubleshooting.md)
- [Reference D: Azure DevOps onboarding system architecture](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/azure-devops/reference-d-azure-devops-onboarding-system-architecture.md)
- [Bitbucket Cloud](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/bitbucket-cloud.md): Integrate Bitbucket Cloud to scan for secrets, IaC misconfigurations, vulnerabilities, and license compliance to strengthen your VCS security posture.
- [Reference A: Authorization scopes and subscribed events](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/bitbucket-cloud/authorization-scopes-and-event-architecture.md): Review the OAuth scopes and Bitbucket Cloud events required for the integration.
- [Bitbucket Data Center](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/bitbucket-data-center.md)
- [Onboard Bitbucket Data Center](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/bitbucket-data-center/onboard-bitbucket-data-center.md): Connect Bitbucket Data Center to Cortex Cloud Application Security.
- [Reference C: Bitbucket Data Center events](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/bitbucket-data-center/reference-c-bitbucket-data-center-events.md): Events Cortex Cloud subscribes to for Bitbucket Data Center.
- [Reference B: Rotate Bitbucket Data Center tokens](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/bitbucket-data-center/reference-b-rotate-bitbucket-data-center-tokens.md): Rotate the PAT used by a Bitbucket Data Center integration.
- [Reference A: Create a Bitbucket Data Center PAT](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/bitbucket-data-center/reference-a-create-a-bitbucket-data-center-pat.md): Create a Personal Access Token for Bitbucket Data Center integration.
- [GitHub SaaS](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud.md)
- [Onboard the shared Cortex GitHub App](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/onboard-a-cortex-github-app.md)
- [Onboard a new customer-owned GitHub App](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/onboard-a-new-customer-owned-github-app.md)
- [Onboard an existing Customer-Owned GitHub App](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/reuse-an-existing-customer-owned-github-app.md)
- [Verify and manage VCS integrations.](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/post-onboarding-management-and-verification.md)
- [Reference A: Shared Cortex GitHub App permissions](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/reference-a-shared-cortex-github-app-permissions.md)
- [Reference B: Customer Owned GitHub App permissions](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/reference-b-customer-owned-github-app-permissions.md)
- [Reference C: Feature permission requirements](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/reference-c-feature-permission-requirements.md)
- [Reference D: Ownership model comparison](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/reference-d-ownership-model-comparison.md)
- [Reference E: Subscribed GitHub events](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-cloud/reference-e-subscribed-github-events.md)
- [GitHub Enterprise (On-Prem)](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-enterprise-on-prem.md)
- [Onboard GitHub Enterprise (On-Prem)](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-enterprise-on-prem/onboard-github-enterprise-on-prem.md): Connect GitHub Enterprise Server repositories to Cortex Cloud.
- [Reference A: GitHub Enterprise OAuth scopes](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-enterprise-on-prem/reference-a-github-enterprise-oauth-scopes.md): OAuth scopes required for GitHub Enterprise Server onboarding.
- [Reference B: Egress proxy IP addresses](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-enterprise-on-prem/reference-b-egress-proxy-ip-addresses.md): Egress proxy IP addresses for GitHub Enterprise Server allow lists.
- [Reference C: GitHub Enterprise subscribed events](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/github-enterprise-on-prem/reference-c-github-enterprise-subscribed-events.md): Events Cortex Cloud monitors for GitHub Enterprise Server.
- [GitLab SaaS](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/gitlab-saas.md)
- [Reference A: Subscribed events](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/gitlab-saas/reference-a-subscribed-events.md): Events Cortex Cloud subscribes to for GitLab SaaS.
- [GitLab Self Managed (On-Prem)](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-version-control-systems/gitlab-self-managed-on-prem.md)
- [Onboard CI/CD systems](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-cicd-systems.md)
- [CircleCI for CI/CD pipeline scans](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-cicd-systems/circleci-for-cicd-pipeline-scans.md)
- [Jenkins for CI/CD pipeline scans](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-cicd-systems/jenkins-for-cicd-pipeline-scans.md)
- [Integrate CI tools](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools.md)
- [AWS CodeBuild](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/aws-codebuild.md)
- [AWS CodeBuild code scan workflow template](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/aws-codebuild/aws-codebuild-code-scan-workflow-template.md): Configure Cortex CLI code scanning in an AWS CodeBuild buildspec.
- [CircleCI for code scans](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/circleci-for-code-scans.md)
- [CircleCI code scan workflow template](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/circleci-for-code-scans/circleci-code-scan-workflow-template.md): Configure Cortex CLI code scanning in a CircleCI workflow.
- [Cortex CLI](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/connect-cortex-cli.md)
- [GitHub Actions](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/github-actions.md)
- [GitHub Actions code scan workflow template](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/github-actions/github-actions-code-scan-workflow-template.md): Configure Cortex CLI code scanning in a GitHub Actions workflow.
- [Jenkins for code scans](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/jenkins-for-code-scans.md)
- [Reference A: Jenkins code scan workflow template without checkout](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/jenkins-for-code-scans/reference-a-jenkins-code-scan-workflow-template-without-checkout.md): Configure a Jenkins code scan workflow without repository checkout.
- [Reference B: Jenkins code scan workflow template with checkout](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/jenkins-for-code-scans/reference-b-jenkins-code-scan-workflow-template-with-checkout.md): Configure a Jenkins code scan workflow with repository checkout.
- [Terraform Cloud (Run Tasks)](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/terraform-cloud-run-tasks.md)
- [Terraform workflow for Run Tasks enforcement](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/terraform-cloud-run-tasks/terraform-workflow-for-run-tasks-enforcement.md): Configure policy-based Terraform Run Tasks enforcement.
- [Terraform Enterprise (Run Tasks)](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/terraform-enterprise-run-tasks.md)
- [Terraform workflow for Run Tasks enforcement](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/integrate-ci-tools/terraform-enterprise-run-tasks/terraform-workflow-for-run-tasks-enforcement.md): Configure policy-based Terraform Run Tasks enforcement.
- [CLI pipeline code snippets](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets.md): Add Cortex CLI code scans to supported CI/CD pipelines.
- [AWS CodeBuild](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets/aws-codebuild.md): Configure Cortex CLI code scanning in AWS CodeBuild.
- [Azure Pipelines](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets/azure-pipelines.md): Configure Cortex CLI code scanning in Azure Pipelines.
- [Bitbucket](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets/bitbucket.md): Configure Cortex CLI code scanning in Bitbucket Pipelines.
- [CircleCI](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets/circleci.md): Configure Cortex CLI code scanning in CircleCI.
- [GitHub Actions](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets/github-actions.md): Configure Cortex CLI code scanning in GitHub Actions.
- [GitLab Runner](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets/gitlab-runner.md): Configure Cortex CLI code scanning in GitLab Runner.
- [Jenkins](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/cli-pipeline-code-snippets/jenkins.md): Configure Cortex CLI code scanning in Jenkins.
- [Onboard private package registries](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-private-package-registries.md)
- [JFrog Artifactory](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-private-package-registries/jfrog-artifactory.md)
- [Onboard JFrog Artifactory](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/onboard-private-package-registries/onboard-jfrog-artifactory.md)
- [Ingest third-party data sources](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources.md): Centralize findings from supported third-party or SARIF-compatible scanners into Cortex Cloud. Unified triage, Urgency-based priority, and policy enforcement in one view.
- [Checkmarx](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx.md)
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/tenant-ui-workflow.md)
- [API workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/api-workflow.md)
- [Terraform workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/terraform-workflow.md)
- [Understand and manage Checkmarx SAST data ingestion](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/understand-and-manage-checkmarx-sast-data-ingestion.md): Ingest Checkmarx SAST findings into Cortex Cloud and view resulting code weakness issues.
- [Reference A: Supported Checkmarx One regions](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/supported-checkmarx-regions.md)
- [Reference B: Checkmarx workflow guidance](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/workflow-guidance.md)
- [Reference C: Checkmarx data deletion cleanup](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/data-deletion-cleanup.md)
- [Reference D: Checkmarx troubleshooting](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/troubleshooting.md)
- [Reference E: Checkmarx frequently asked questions](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/checkmarx/frequently-asked-questions.md)
- [Semgrep](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/semgrep.md): Cortex Cloud AppSec integrates with Semgrep to ingest SCA and SAST findings into the unified AppSec data model.
- [Onboard Semgrep](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/semgrep/onboard-semgrep.md): Connect Semgrep to Cortex Cloud, select findings, and manage the integration.
- [Understand and manage Semgrep SCA data ingestion](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/semgrep/semgrep-software-composition-analysis-sca-data-ingestion.md): Ingest Semgrep SCA findings into Cortex Cloud and view resulting vulnerability issues.
- [Understand and manage Semgrep SAST data ingestion](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/semgrep/semgrep-static-application-security-testing-sast-data-ingestion.md): Ingest Semgrep SAST findings into Cortex Cloud and view resulting code weakness issues.
- [Reference A: Semgrep data deletion cleanup](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/semgrep/reference-a-semgrep-data-deletion-cleanup.md): Understand which Semgrep integration data is removed when an instance is deleted.
- [Snyk](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/snyk.md): Configure the Snyk integration to ingest SAST and SCA vulnerability findings into Cortex Cloud, unifying your software package assets and security code.
- [Onboard Snyk](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/snyk/onboard-snyk.md): Connect Snyk to Cortex Cloud, select findings, and manage the integration.
- [Understand and manage Snyk SCA data ingestion](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/snyk/snyk-software-composition-analysis-sca-ingestion.md): Learn how Cortex Cloud ingests, normalizes, and displays Snyk SCA data.
- [Understand and manage Snyk SAST data ingestion](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/snyk/snyk-static-application-security-testing-sast-data-ingestion.md): Learn how Cortex Cloud ingests Snyk SAST findings and displays resulting code weakness issues.
- [SonarQube](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/sonarqube.md)
- [Onboard via tenant (UI)](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/sonarqube/onboard-via-tenant-ui.md)
- [Understand and manage SonarQube data ingestion](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/sonarqube/verify-view-and-manage.md)
- [Manage SonarQube through API](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/sonarqube/manage-sonarqube-through-api.md)
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/sonarqube/troubleshoot.md)
- [Veracode](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/veracode.md)
- [Understand and manage Veracode data ingestion](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/veracode/understand-and-manage-veracode-data-ingestion.md): Ingest Veracode SAST findings into Cortex Cloud and view resulting code weakness issues.
- [Generic 3rd Party AppSec Collector](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector.md): Streamline security by ingesting SARIF findings from any tool into Cortex Cloud. Achieve unified visibility and risk-based prioritization for all AppSec scans.
- [Tenant (console) workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/tenant-console-workflow.md)
- [API workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/api-workflow.md)
- [Upload findings from CI/CD pipelines](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/upload-findings-from-ci-cd-pipelines.md)
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/troubleshooting.md)
- [Reference A: System requirements](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/technical-requirements-and-sarif-specifications.md): Review system requirements before uploading SARIF findings.
- [Reference B: SARIF format and mapping](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/reference-b-sarif-format-and-mapping.md): Required and optional SARIF fields for collector uploads.
- [Reference C: Severity mapping](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/reference-c-severity-mapping.md): How SARIF severity levels map to Cortex Cloud severity values.
- [Reference D: Repository mapping](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/reference-d-repository-mapping.md): Map uploaded SARIF findings to Cortex Cloud repository assets.
- [Reference E: Validation statuses](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources/generic-3rd-party-appsec-collector/reference-e-validation-statuses.md): Interpret SARIF validation results before uploading findings.
- [Transporter over Broker VM](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/transporter-over-broker-vm.md): Transporter over Broker VM sets up a secure communication channel between your VCS and Cortex.
- [Set up a Transporter applet on Broker VM](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/transporter-over-broker-vm/set-up-a-transporter-applet-on-broker-vm.md): Setup a Transporter applet on Broker VM.
- [Set up a Transporter on your VCS](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/transporter-over-broker-vm/set-up-a-transporter-on-your-vcs.md): Setup a Transporter on your version control system.
- [Manage integrations via data source APIs](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/manage-integrations-via-data-source-apis.md)
- [Application Security dashboard](https://cortex-docs.paloaltonetworks.com/application-security/application-security/cortex-cloud-application-security-dashboard.md): Monitor and analyze your Application Security posture with the Application Security dashboard.
- [AppSec Objectives with Agentix](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix.md)
- [Track objectives](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/track-objectives.md)
- [Vulnerability objectives](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references.md)
- [Reference A: Objective scope filters](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references/reference-a-objective-scope-filters.md)
- [Reference B: Objective condition filters](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references/reference-b-objective-condition-filters.md)
- [Reference C: Metric calculations](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references/reference-c-metric-calculations.md)
- [Code-to Cloud](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud.md)
- [How the C2C engine works](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/how-the-c2c-engine-works.md)
- [Identify and investigate gap](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/identify-and-investigate-gap.md)
- [Execute remediation workflows](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/execute-remediation-workflows.md)
- [The Coverage dashboard](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/the-coverage-dashboard.md)
- [C2C in Unified Asset Inventory](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/c2c-in-unified-asset-inventory.md)
- [C2C tab (asset level)](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/c2c-tab-asset-level.md)
- [C2C tab (app level)](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/c2c-tab-app-level.md)
- [Agentix for C2C](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/agentix-for-c2c.md)
- [Investigate issues with C2C](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/investigate-issues-with-c2c.md)
- [C2C in ASPM Command Center](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/c2c-in-aspm-command-center.md)
- [Enforce policies with C2C](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/enforce-policies-with-c2c.md)
- [API endpoints for C2C](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/api-endpoints-for-c2c.md): Retrieve Code-to-Cloud coverage programmatically.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/troubleshooting.md)
- [FAQs](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/faqs.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references.md)
- [Reference A: Supported integrations and asset stages](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references/reference-a-supported-integrations-and-asset-stages.md)
- [Reference B: Coverage % calculation and configuration toggles](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references/reference-b-coverage-calculation-and-configuration-toggles.md)
- [Reference C: Dashboard filters by view](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references/reference-c-dashboard-filters-by-view.md)
- [Reference D: Recommended actions by view and stage](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references/reference-d-recommended-actions-by-view-and-stage.md)
- [Reference E: Code-to-Cloud Coverage public API](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references/reference-e-code-to-cloud-coverage-public-api.md)
- [Page Reference F: Call-to-action routing by asset type1](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references/page-reference-f-call-to-action-routing-by-asset-type1.md)
- [Reference G: Unified Asset Inventory fields and deep links](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud/references/reference-g-unified-asset-inventory-fields-and-deep-links.md)
- [What is Application Security Posture Management (ASPM)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-posture-management-aspm.md): ASPM centralizes AppSec monitoring across the SDLC. It aggregates findings from tools such as IaC and SCA to provide a holistic view and prioritize risks.
- [Code to Cloud](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud.md): Code to Cloud context maps asset lineage across the SDLC. By connecting repos, pipelines, and infra, it provides end-to-end traceability from code to runtime.
- [Core components and mechanisms](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud/core-components-and-mechanisms.md): Code to Cloud context maps asset lineage across the SDLC. By connecting repos, pipelines, and infra, it provides end-to-end traceability from code to runtime.
- [Supported integrations](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud/supported-integrations.md)
- [Code to Cloud context and visibility](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud/code-to-cloud-context-and-visibility.md): Manage security risk across the SDLC by tracing technical asset lineage. View asset dependencies and runtime context in assets, issues, and policies.
- [Code to Cloud troubleshooting](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud/code-to-cloud-troubleshooting.md)
- [ASPM Command Center](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center.md): The ASPM Command Center is your central hub for real-time application security posture management across the SDLC. It offers critical insights to identify risks, track compliance, and enable secure de
- [Operational workflows](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows.md)
- [Applications](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications.md): Build and manage applications as holistic entities. Gain centralized visibility across the SDLC to monitor assets and remediate threats based on business risk.
- [Define business applications by Criteria](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications.md): Define business applications automatically using tag-based criteria or manually with the Application Builder to map assets and prioritize app risk.
- [Define business applications by Criteria](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications/define-business-applications-by-criteria.md)
- [Define applications by Code Criteria](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications/define-applications-by-code-criteria.md)
- [Reference A: Code Criteria grouping and unification](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications/define-applications-by-code-criteria/reference-a-code-criteria-grouping-and-unification.md): Understand Code Criteria grouping, scope filters, and application unification.
- [Reference B: Code Criteria references and examples](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications/define-applications-by-code-criteria/reference-b-code-criteria-references-and-examples.md): Examples and reference rules for Code Criteria grouping, unification, and scope.
- [Define applications by Cloud Criteria](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications/define-applications-by-cloud-criteria.md)
- [Manage Criteria via the tenant (UI)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications/manage-criteria-via-the-tenant-ui.md)
- [Manage Criteria via the public API](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/defining-business-applications/manage-criteria-via-the-public-api.md)
- [Manually build an application](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/manually-build-an-application.md)
- [View and manage applications](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/application-management-and-visibility.md)
- [Manage applications via public APIs](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/manage-applications-via-public-apis.md): Automate application lifecycle management by creating, updating, and deleting applications programmatically via the Cortex Cloud public API endpoints.
- [Scope user access to applications (Application SBAC)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/scope-user-access-to-applications-application-sbac.md)
- [Business application assets](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/business-application-assets.md)
- [Repository as an asset](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/repository-as-an-asset.md)
- [Manage repository assets through the tenant (UI)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/repository-as-an-asset/understanding-repository-assets-via-the-ui.md)
- [Investigate repository assets](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/repository-as-an-asset/understanding-repository-assets-via-the-ui/investigate-repository-assets.md)
- [Reference: Repositories asset attributes](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/repository-as-an-asset/understanding-repository-assets-via-the-ui/reference-repositories-asset-attributes.md)
- [Manage repositories via API](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/repository-as-an-asset/manage-repositories-via-api.md)
- [Coverage](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage.md): The AppSec Coverage page provides centralized visibility into security scanner deployment across the SDLC. Monitor asset health, identify gaps, and orchestrate onboarding.
- [Coverage in the tenant (UI)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface.md)
- [Urgency](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/urgency.md): Prioritize issues using Urgency, a context-aware risk score that dynamically evaluates runtime exposure, business impact, and protection status.
- [Review Application Security posture and remediate issues by Urgency](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/urgency/view-urgency-in-the-tenant.md)
- [Understand Urgency and code-to-cloud traceability](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/urgency/urgency-and-code-to-cloud-traceability.md)
- [Understand Urgency metrics](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/urgency/urgency-metrics.md)
- [Prioritize issue types by Urgency level](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/urgency/prioritize-issues-by-urgency-levels.md)
- [Backlog baseline](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline.md): Backlog represents pre-existing code issues discovered by a scanner's first run or by new rules.
- [Backlog use cases](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline/backlog-use-cases.md)
- [Issue/Finding classification by scanner](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline/issuefinding-classification-by-scanner.md)
- [Using Backlog](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline/using-backlog.md)
- [Service Lead Agreements (SLA)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/service-lead-agreements-sla.md): Application Security SLA defines deadlines for fixing security issues based on severity, ensuring timely remediation and improving team performance.
- [Configure and monitor Cortex Cloud Application Security SLAs](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/service-lead-agreements-sla/configure-and-monitor-cortex-cloud-application-security-slas.md)
- [Compliance for Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security.md)
- [Monitor and track compliance adherence](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security/monitor-and-track-compliance-adherence.md)
- [Infrastructure-as-Code (IaC) compliance](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security/infrastructure-as-code-iac-compliance.md)
- [Manage IaC compliance](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security/manage-iac-compliance.md)
- [CI/CD Compliance](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security/cicd-compliance.md): CI/CD compliance ensures adherence to industry standards: CIS GitLab/GitHub and OWASP Top 10.
- [Terraform workflow for Compliance assessments](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security/terraform-workflow-for-compliance-assessments.md)
- [Unified Application Security policies](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies.md): AppSec policies define threat responses by setting conditions, scope, and actions. Use out-of-the-box policies or clone them to create custom ones.
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/tenant-ui-workflow.md)
- [Create a policy](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/tenant-ui-workflow/create-a-policy.md)
- [API workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/api-workflow.md)
- [Cortex CLI workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/cortex-cli-workflow.md)
- [IDE workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/ide-workflow.md)
- [Terraform workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/terraform-workflow-for-policies.md)
- [View and manage policy details](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/view-and-manage-policy-details.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references.md)
- [Reference: Core concepts](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/core-concepts.md)
- [Reference A: Finding type details](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-a-finding-type-details.md)
- [Reference B: Condition filters and logic](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-b-condition-filters-and-logic.md)
- [Reference C: Scope mapping details](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-c-scope-mapping-details.md)
- [Reference D: Trigger and actions mapping](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-d-trigger-and-actions-mapping.md)
- [Reference E: Grace period logic and configuration](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-e-grace-period-logic-and-configuration.md)
- [Reference F: Engine evaluation and Urgency logic](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-f-engine-evaluation-and-urgency-logic.md)
- [Reference G: Finding type to trigger mapping](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-g-finding-type-to-trigger-mapping.md)
- [Reference H: Action availability by trigger](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-h-action-availability-by-trigger.md)
- [Reference I: Audit logging](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/references/reference-i-audit-logging.md)
- [Application Security Rules](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules.md): AppSec rules detect security threats using predefined criteria based on standard compliance frameworks and best practices. Custom rules are supported.
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules/tenant-ui-workflow.md): Manage Application Security rules through the Cortex Cloud tenant.
- [Understand and investigate rules](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules/tenant-ui-workflow/rules-inventory.md)
- [Create custom Cortex Cloud Application Security rules](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules/tenant-ui-workflow/create-custom-cortex-cloud-application-security-rules.md)
- [Configure YAML file properties](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules/tenant-ui-workflow/create-custom-cortex-cloud-application-security-rules/configure-yaml-file-properties.md)
- [API workflows for rules](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules/api-workflows-for-rules.md): Manage Application Security rule definitions through the public API.
- [Terraform workflows for rules](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules/terraform-workflows-for-rules.md)
- [Manage custom rules](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-rules/manage-custom-rules.md)
- [Manage code weakness issues](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/manage-code-weakness-issues.md): Ingest third-party SAST findings to create actionable issues, enabling you to prioritize and track remediation and enhancing your security posture.
- [Navigate to SAST code weakness issues](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/manage-code-weakness-issues/navigate-to-sast-code-weakness-issues.md)
- [Understand the Code Weaknesses table](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/manage-code-weakness-issues/understand-the-code-weaknesses-table.md)
- [Investigate and remediate code weakness issues](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/manage-code-weakness-issues/investigate-and-remediate-code-weakness-issues.md)
- [Code weakness findings](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/manage-code-weakness-issues/code-weakness-findings.md)
- [Software Supply Chain Security](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/software-supply-chain-security.md): Software supply chain security protects the integrity and trustworthiness of all components, tools, and processes across the SDLC to proactively prevent risk.
- [Supply Chain Attacks](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/supply-chain-attacks.md)
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/supply-chain-attacks/tenant-ui-workflow.md)
- [CLI workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/supply-chain-attacks/cli-workflow.md)
- [Referenecs](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/supply-chain-attacks/referenecs.md)
- [Reference A: Supply Chain Attacks filters](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/supply-chain-attacks/referenecs/reference-a-supply-chain-attacks-filters.md)
- [Reference B: Exposure determination matrix](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/supply-chain-attacks/referenecs/reference-b-exposure-determination-matrix.md)
- [Reference C: Attack catalog and data freshness](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/supply-chain-attacks/referenecs/reference-c-attack-catalog-and-data-freshness.md)
- [Visibililty and inventory](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory.md)
- [Supply Chain assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets.md): Manage software supply chain assets like VCS organizations, code identities, and CI/CD pipelines to gain deep visibility and remediate risks directly.
- [VCS organization assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/vcs-organization-assets.md)
- [Understand and prioritize VCS organization assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/vcs-organization-assets/understand-and-prioritize-vcs-organization-assets.md): Access, review, filter, and prioritize VCS organization assets.
- [Investigate and manage VCS organization assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/vcs-organization-assets/investigate-and-manage-vcs-organization-assets.md): Investigate VCS organization security posture, remediate issues, and manage asset data.
- [VCS collaborators as assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/vcs-collaborators-as-assets.md)
- [Repository as an asset](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/repository-as-an-asset.md)
- [Manage repository assets through the tenant (UI)](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/repository-as-an-asset/manage-repository-assets-through-the-tenant-ui.md)
- [Investigate repository assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/repository-as-an-asset/manage-repository-assets-through-the-tenant-ui/investigate-repository-assets.md)
- [Reference: Repositories asset attributes](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/repository-as-an-asset/manage-repository-assets-through-the-tenant-ui/reference-repositories-asset-attributes.md)
- [Manage repositories via API](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/repository-as-an-asset/manage-repositories-via-api.md)
- [Technologies as assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/technologies-as-assets.md)
- [Troubleshoot repository technology detection](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/technologies-as-assets/troubleshoot-repository-technology-detection.md): Resolve technology detection issues and review common questions.
- [Software packages as assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/software-packages-as-assets.md)
- [Understand software package assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/software-packages-as-assets/understand-software-package-assets.md): Access, filter, investigate, and manage software package assets.
- [Investigate software package assets and security issues](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/software-packages-as-assets/investigate-software-package-assets-and-security-issues.md): Investigate dependency context and remediate software package security issues.
- [CI/CD instance as an asset](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/cicd-instance-as-an-asset.md)
- [Understand and prioritize CI/CD instance assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/cicd-instance-as-an-asset/understand-and-prioritize-ci-cd-instance-assets.md): Access, review, filter, and prioritize CI/CD instance assets.
- [Investigate and manage CI/CD instance assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/cicd-instance-as-an-asset/investigate-and-manage-ci-cd-instance-assets.md): Investigate CI/CD instance security posture, remediate issues, and manage asset data.
- [CI/CD pipeline as an asset](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/cicd-pipeline-as-an-asset.md)
- [Understand and prioritize CI/CD pipeline assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/cicd-pipeline-as-an-asset/understand-and-prioritize-ci-cd-pipeline-assets.md): Access, review, filter, and prioritize CI/CD pipeline assets.
- [Investigate and manage CI/CD pipeline assets](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/cicd-pipeline-as-an-asset/investigate-and-manage-ci-cd-pipeline-assets.md): Investigate CI/CD pipeline security posture, remediate issues, and manage asset data.
- [Tools as an asset](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/tools-as-an-asset.md): Supply Chain: Gain full visibility by tracking detected tools in your environment and cross-referencing them against a catalog of Cortex-recognized, trusted technologies.
- [Supply Chain tools](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/tools-as-an-asset/supply-chain-tools.md)
- [Supply Chain catalog](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/tools-as-an-asset/supply-chain-catalog.md)
- [Package Explorer](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/package-explorer.md)
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/package-explorer/tenant-ui-workflow.md)
- [Agentix package recommendations](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/package-explorer/agentix-package-recommendations.md)
- [API workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/package-explorer/api-workflow.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/package-explorer/references.md)
- [Reference A: Package table columns](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/package-explorer/references/reference-a-package-table-columns.md)
- [Reference B: Used In table columns](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/package-explorer/references/reference-b-used-in-table-columns.md)
- [Artifact Trust Score](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/artifact-trust-score.md)
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/artifact-trust-score/tenant-ui-workflow.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/artifact-trust-score/references.md)
- [Reference A: Trust Level bands](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/artifact-trust-score/references/reference-a-trust-level-bands.md)
- [Reference B: Supply Chain Security Category values](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/artifact-trust-score/references/reference-b-supply-chain-security-category-values.md)
- [Risk and remediation](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation.md)
- [Software Composition Analysis (SCA )](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners.md)
- [Supported Software Composition Analysis (SCA) frameworks and languages](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/supported-software-composition-analysis-sca-frameworks-and-languages.md)
- [Software Composition Analysis (SCA) vulnerability issues](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues.md): SCA scanners detect known CVEs in open-source dependencies, protecting your organization by keeping vulnerable third-party code out of production.
- [Understand the Vulnerabilities table](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/understand-the-vulnerabilities-table.md)
- [Investigate, prioritize and remediate vulnerability issues](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/investigate-prioritize-and-remediate-vulnerability-issues.md)
- [View and understand CVE findings](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/view-and-understand-cve-findings.md): Review the findings associated with CVE vulnerability issues.
- [References](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/references.md)
- [Reference A: Prioritization metrics](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/references/reference-a-prioritization-metrics.md)
- [Reference B: Investigation details](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/references/reference-b-investigation-details.md)
- [License miscompliance issues](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/license-miscompliance-issues.md)
- [Ingest third-party SCA data](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/software-composition-analysis-sca-scanners/ingest-third-party-sca-data.md)
- [CI/CD Risks](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/cicd-risks.md): CI/CD risks identify vulnerabilities and misconfigurations in pipelines, then prioritize them into actionable issues for efficient remediation.
- [Understand the CI/CD Risks table](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/cicd-risks/understand-the-ci-cd-risks-table.md)
- [Investigate, prioritize, and remediate CI/CD risk issues](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/cicd-risks/investigate-prioritize-and-remediate-ci-cd-risk-issues.md)
- [View and understand VCS and CI/CD pipeline risk findings](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/cicd-risks/vcs-and-cicd-pipeline-risk-findings.md)
- [Malicious packages](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages.md)
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/tenant-ui-workflow.md)
- [API Workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/api-workflow.md)
- [CLI workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/cli-workflow.md)
- [Pull request workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/pull-request-workflow.md)
- [IDE workflow](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/ide-workflow.md)
- [Reference A: Workflows](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/reference-a-workflows.md)
- [Reference B: RBAC permission levels by capability](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/reference-b-rbac-permission-levels-by-capability.md)
- [Reference C: Supported ecosystems](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/reference-c-supported-ecosystems.md)
- [Reference D: Malicious package finding and issue fields](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/reference-d-malicious-package-finding-and-issue-fields.md)
- [Governance and enforcement](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement.md)
- [CI/CD Rules](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-rules.md): CI/CD rules detect security threats within your pipelines.
- [CI/CD rules roles and permissions](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-rules/cicd-rules-roles-and-permissions.md)
- [CI/CD rules inventory](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-rules/cicd-rules-inventory.md)
- [CI/CD Policies](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies.md): Control CI/CD security: view system & custom policies. Create and manage policies to ensure pipeline integrity and compliance.
- [CI/CD policies user roles and permissions](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/cicd-policies-user-roles-and-permissions.md)
- [CI/CD policies inventory](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/cicd-policies-inventory.md)
- [Create CI/CD configuration policies](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/create-cicd-configuration-policies.md)
- [Manage CI/CD policies](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/manage-cicd-policies.md)
- [Reference A: CI/CD policy Condition attributes](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/reference-a-ci-cd-policy-condition-attributes.md): Supported CI/CD policy condition attributes and values.
- [Reference B: Scope Asset Types](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/reference-b-scope-asset-types.md): Supported asset types and values for CI/CD policy scope.
- [About Code security](https://cortex-docs.paloaltonetworks.com/application-security/code-security/about-code-security.md)
- [Code Security assets](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets.md)
- [Software packages as assets](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/software-packages-as-assets.md)
- [Supported Software Composition Analysis (SCA) frameworks and languages](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/software-packages-as-assets/supported-software-composition-analysis-sca-frameworks-and-languages.md)
- [SCA support matrix by language](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/software-packages-as-assets/supported-software-composition-analysis-sca-frameworks-and-languages/sca-support-matrix-by-language.md)
- [Understanding software package assets](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/software-packages-as-assets/understanding-software-package-assets.md)
- [Investigate software package assets and security issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/software-packages-as-assets/investigate-software-package-assets-and-security-issues.md)
- [Infrastructure-as-Code (IaC) resources as assets](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/infrastructure-as-code-iac-resources-as-assets.md): Infrastructure-as-Code (IaC) assets provide a governed inventory of cloud templates, enabling teams to detect misconfigurations and map code-to-cloud lineage.
- [Supported frameworks and languages](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/infrastructure-as-code-iac-resources-as-assets/supported-frameworks-and-languages.md)
- [Access and filter IaC assets](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/infrastructure-as-code-iac-resources-as-assets/access-and-filter-iac-assets.md)
- [Investigate IaC assets](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-assets/infrastructure-as-code-iac-resources-as-assets/investigate-iac-assets.md)
- [Code Security scanners](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners.md)
- [Software Composition Analysis (SCA ) scanners](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners.md)
- [Supported Software Composition Analysis (SCA) frameworks and languages](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/supported-software-composition-analysis-sca-frameworks-and-languages.md)
- [Software Composition Analysis (SCA) vulnerability issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues.md): SCA scanners detect known CVEs in open-source dependencies, protecting your organization by keeping vulnerable third-party code out of production.
- [Understand the Vulnerabilities table](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/understand-the-vulnerabilities-table.md)
- [Investigate, prioritize and remediate vulnerability issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/investigate-and-remediate-cve-vulnerability-issues.md)
- [View and understand CVE findings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/investigate-cve-vulnerabilities-findings.md): Review the findings associated with CVE vulnerability issues.
- [References](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/navigate-to-cve-vulnerability-issues.md)
- [Reference A: Prioritization metrics](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/navigate-to-cve-vulnerability-issues/reference-a-prioritization-metrics.md)
- [Reference B: Investigation details](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/software-composition-analysis-sca-vulnerability-issues/navigate-to-cve-vulnerability-issues/reference-b-investigation-details.md)
- [License miscompliance issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/license-miscompliance-issues.md)
- [Understand the Licenses misconfigurations table](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/license-miscompliance-issues/understand-the-licenses-table.md)
- [Investigate, prioritize, and remediate license miscompliance issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/license-miscompliance-issues/navigate-to-license-miscompliance-issues.md)
- [Understand license micompliance findings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/license-miscompliance-issues/understand-license-micompliance-findings.md)
- [Open-source software license categories](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/license-miscompliance-issues/open-source-software-license-categories.md)
- [Package operational risks](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner.md)
- [Understand the package operational risk table](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/understand-the-package-operational-risk-table.md)
- [Investigate, prioritize and remediate package operational risk issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/investigate-and-remediate-package-operational-risk-issues.md)
- [Understand package operational risk findings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/understand-package-operational-risk-findings.md)
- [Package operational risks findings reference](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/understand-package-operational-risk-findings/package-operational-risks-findings-reference.md)
- [Reference A: Findings tab columns](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/understand-package-operational-risk-findings/package-operational-risks-findings-reference/reference-a-findings-tab-columns.md)
- [Reference B: Finding side panel fields](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/understand-package-operational-risk-findings/package-operational-risks-findings-reference/reference-b-finding-side-panel-fields.md)
- [Reference C: Operational risk finding field model](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/understand-package-operational-risk-findings/package-operational-risks-findings-reference/reference-c-operational-risk-finding-field-model.md)
- [Reference: How package operational risk issues fit in the Application Security ecosystem](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/software-composition-analysis-sca-scanners/package-operational-risk-scanner/how-package-operational-risk-issues-fit-in-the-application-security-ecosystem.md)
- [Secrets scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/secrets-scans.md): Protect your organization by detecting hardcoded credentials, API keys, and tokens in source code. Secrets scanning prevents credential theft and lateral movement by closing security gaps from develop
- [Understand the secrets issues table](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/secrets-scans/understand-the-secrets-issues-table.md)
- [Investigate, prioritize, and remediate secrets issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/secrets-scans/investigate-and-remediate-secrets-issues.md)
- [Secrets findings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/secrets-scans/secrets-findings.md)
- [Secrets findings inventory](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/secrets-scans/secrets-findings/secrets-findings-inventory.md)
- [Infrastructure as Code (IaC) misconfiguration scanner](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/infrastructure-as-code-iac-misconfiguration-scanner.md): IaC scanners safeguard cloud infrastructure by identifying misconfigurations before deployment, preventing vulnerabilities in your operational environment.
- [Understand the IaC misconfigurations table](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/infrastructure-as-code-iac-misconfiguration-scanner/understand-the-iac-misconfigurations-table.md)
- [Investigate, prioritize, and remediate IaC misconfiguration issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/infrastructure-as-code-iac-misconfiguration-scanner/investigate-and-remediate-iac-misconfiguration-issues.md)
- [IaC misconfiguration findings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/infrastructure-as-code-iac-misconfiguration-scanner/iac-misconfiguration-findings.md)
- [Supported frameworks and languages](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/infrastructure-as-code-iac-misconfiguration-scanner/supported-frameworks-and-languages.md): Supported infrastructure-as-code frameworks for IaC misconfiguration scanning.
- [IaC Drift Detection scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/iac-drift-detection-scans.md): IaC Drift Detection identifies runtime configurations that diverge from code. It flags security-critical discrepancies to focus remediation efforts.
- [Understand the IaC drift detection table](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/iac-drift-detection-scans/understand-the-iac-drift-detection-table.md)
- [Investigate, prioritize and remediate IaC drift issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/iac-drift-detection-scans/investigate-and-remediate-iac-drift-issues.md)
- [Investigate IaC drift detection findings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/iac-drift-detection-scans/investigate-iac-drift-detection-findings.md)
- [Malicious packages](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages.md)
- [Tenant (UI) workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/tenant-ui-workflow.md)
- [API Workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/api-workflow.md)
- [CLI workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/cli-workflow.md)
- [Pull request workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/pull-request-workflow.md)
- [IDE workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/ide-workflow.md)
- [Reference A: Workflows](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/reference-a-workflows.md)
- [Reference B: RBAC permission levels by capability](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/reference-b-rbac-permission-levels-by-capability.md)
- [Reference C: Supported ecosystems](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/reference-c-supported-ecosystems.md)
- [Reference D: Malicious package finding and issue fields](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/malicious-packages/reference-d-malicious-package-finding-and-issue-fields.md)
- [Issue table attributes reference](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/issue-table-attributes-reference.md)
- [API workflows for Code Security issues](https://cortex-docs.paloaltonetworks.com/application-security/code-security/api-workflows-for-code-security-issues.md)
- [Manage Application Security scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management.md)
- [Manage scans through the tenant (UI)](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui.md)
- [Branch periodic scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans.md)
- [Branch periodic scan workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/branch-periodic-scan-workflow.md)
- [Configure repository scan coverage](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/branch-periodic-scan-workflow/configure-repository-scan-coverage.md)
- [Assess scan coverage and health across the portfolio](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/branch-periodic-scan-workflow/assess-scan-coverage-and-health-across-the-portfolio.md)
- [Investigate a scan result, prioritize the issues, and remediate](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/branch-periodic-scan-workflow/investigate-a-scan-result-prioritize-the-issues-and-remediate.md)
- [Triage a scan that failed or completed partially](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/branch-periodic-scan-workflow/triage-a-scan-that-failed-or-completed-partially.md)
- [Diagnose a scan failure through data source instance health](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/branch-periodic-scan-workflow/diagnose-a-scan-failure-through-data-source-instance-health.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references.md)
- [Reference A: Branch periodic scan concepts](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-a-branch-periodic-scan-concepts.md): Detailed concepts for interpreting branch periodic scans.
- [Reference B: Inventory columns](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-b-inventory-columns.md)
- [Reference C: Scan health values](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-c-scan-health-values.md)
- [Reference D: Issue category routing](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-d-issue-category-routing.md)
- [Reference E: Instance health error types](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-e-instance-health-error-types.md)
- [Reference F: Scan configuration settings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-f-scan-configuration-settings.md)
- [Reference G: Scanner to issue category mapping](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-g-scanner-to-issue-category-mapping.md)
- [Reference H: Permissions](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/branch-periodic-scans/references/reference-h-permissions.md)
- [Pull Request scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans.md)
- [Pull request scan workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/pull-request-scan-workflow.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references.md)
- [Reference A: Pull request scan concepts](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-a-pull-request-scan-concepts.md)
- [Reference B: Inventory columns](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-b-inventory-columns.md)
- [Reference C: Scan health values](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-c-scan-health-values.md)
- [Reference D: PR status values](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-d-pr-status-values.md)
- [Reference E: Issue category routing](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-e-issue-category-routing.md)
- [Reference F: Pull request scan configuration settings](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-f-pull-request-scan-configuration-settings.md)
- [Reference G: Scanner to issue category mapping](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-g-scanner-to-issue-category-mapping.md)
- [Reference H: Pull request comment feedback](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-h-pull-request-comment-feedback.md)
- [Reference I: Permissions](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/pull-request-scans/references/reference-i-permissions.md)
- [CI scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans.md)
- [CI scan workflow](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/ci-scan-workflow.md)
- [References](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references.md)
- [Reference A: CI scan concepts](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-a-ci-scan-concepts.md)
- [Reference B: Inventory columns](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-b-inventory-columns.md)
- [Reference C: Scan health values](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-c-scan-health-values.md)
- [Reference D: CI status values](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-d-ci-status-values.md)
- [Reference E: Issue category routing](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-e-issue-category-routing.md)
- [Reference F: CI scan sources](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-f-ci-scan-sources.md)
- [Reference G: Scanner to issue category mapping](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-g-scanner-to-issue-category-mapping.md)
- [Reference H: Permissions](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/ci-scans/references/reference-h-permissions.md)
- [Scan health and status reference](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/scan-health-and-status-reference.md)
- [Manage repository scan configurations](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/manage-repository-scan-configurations.md)
- [Monitor data source instances health](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/monitor-data-source-instances-health.md)
- [How to view an instance health](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-the-tenant-ui/monitor-data-source-instances-health/how-to-view-an-instance-health.md)
- [Manage scans through public APIs](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-public-apis.md)
- [Prerequisites](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-scans-management/manage-scans-through-public-apis/prerequisites.md)
- [Application Security Cortex CLI](https://cortex-docs.paloaltonetworks.com/application-security/code-security/application-security-cli.md)
- [IDE](https://cortex-docs.paloaltonetworks.com/application-security/code-security/ide.md): Integrating the AppSec IDE security plugin to scan for IaC misconfigurations, SCA vulnerabilities, license miscompliance and exposed secrets while coding, with in-IDE fixes.
- [System requirements](https://cortex-docs.paloaltonetworks.com/application-security/code-security/ide/system-requirements.md)
- [Visual Studio (VS) Code and VS Code compatible IDEs](https://cortex-docs.paloaltonetworks.com/application-security/code-security/ide/visual-studio-vs-code-and-vs-code-compatible-ides.md)
- [How to use the Cortex Cloud extension](https://cortex-docs.paloaltonetworks.com/application-security/code-security/ide/visual-studio-vs-code-and-vs-code-compatible-ides/how-to-use-the-cortex-cloud-extension-in-vs-code.md)
- [JetBrains](https://cortex-docs.paloaltonetworks.com/application-security/code-security/ide/jetbrains.md)
- [How to use the JetBrains Cortex Cloud extension](https://cortex-docs.paloaltonetworks.com/application-security/code-security/ide/jetbrains/how-to-use-the-jetbrains-cortex-cloud-extension.md)
- [Developer suppressions](https://cortex-docs.paloaltonetworks.com/application-security/code-security/developer-suppressions.md)
- [About API endpoints](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/api-endpoints.md)
- [Data source integrations](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/data-source-integrations.md)
- [Unified Application Security policies](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/unified-application-security-policies.md)
- [Application criteria](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/application-criteria.md)
- [Manage applications](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/manage-applications.md)
- [Repositories and scan configurations](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/repositories-and-scan-configurations.md)
- [Business applications](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/business-applications.md)
- [Scans, issues, and findings](https://cortex-docs.paloaltonetworks.com/application-security/api-endpoints/scans-issues-and-findings.md)
- [About Terraform workflows](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/terraform-workflows.md)
- [Authentication and configuration](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/authentication-and-configuration.md)
- [Manage resources](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources.md)
- [Manage Asset Groups](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources/manage-asset-groups.md): Manage Application Security asset groups with Terraform.
- [Manage Terraform Run Tasks enforcement](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources/manage-terraform-run-tasks-enforcement.md): Enforce Application Security guardrails during Terraform planning.
- [Manage policies](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources/manage-policies.md): Manage Application Security policies, rules, and compliance profiles with Terraform.
- [Manage custom rules](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources/manage-custom-rules.md): Manage custom Application Security detection rules with Terraform.
- [Manage compliance assessment profiles](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources/manage-compliance-assessment-profiles.md): Automate Application Security compliance assessments with Terraform.
- [Leverage Terraform data sources](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources/leverage-terraform-data-sources.md): Look up Application Security configuration with Terraform data sources.

## Cortex AgentiX Documentation

- [Navigate the Cortex AgentiX docs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/readme.md): Start here for a visual overview of the main Cortex AgentiX documentation areas.
- [Get Started with Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/get-started-with-cortex-agentix.md): Learn about Cortex AgentiX and the key integrated capabilities.
- [Understand Cortex AgentiX licenses](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/understand-cortex-agentix-licenses.md): The Cortex AgentiX license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
- [Agentic AI in Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/agentic-ai-in-cortex-agentix.md): Use AI agents to investigate threats, automate security tasks, and streamline operations in Cortex AgentiX.
- [Manage Cortex AgentiX agents](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/agentic-ai-in-cortex-agentix/manage-cortex-agentix-agents.md): Learn about personal and system agents in Cortex AgentiX.
- [Cortex AgentiX use cases](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/agentic-ai-in-cortex-agentix/cortex-agentix-use-cases.md): Recommended prompts to automate your SOC in Cortex AgentiX.
- [Agentic Assistant security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/agentic-ai-in-cortex-agentix/agentic-assistant-security.md): Learn how the Agentic Assistant protects data through RBAC, approvals, regional processing, and action auditing.
- [Key components and concepts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/key-components-and-concepts.md): Learn about the key components and concepts, such as agents and actions in Cortex AgentiX.
- [Data retention policy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/data-retention-policy.md): Learn more about the default retention periods for all Cortex AgentiX licenses and the available retention add-ons.
- [Supported ciphers](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/supported-ciphers.md): Review the TLS 1.2 and TLS 1.3 cipher suites supported by Cortex AgentiX.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-agentix/learn-about-cortex-agentix/supported-web-browsers.md): Review supported browser versions and HTTP/2 guidance for optimal Cortex AgentiX performance.
- [How to onboard Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/onboard-cortex-agentix.md): Follow the steps to successfully onboard and configure Cortex AgentiX.
- [Plan and prepare your deployment](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/plan-and-prepare-your-deployment.md): Plan your Cortex AgentiX deployment by selecting a region, data sources, agents, licensing, and access controls.
- [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/deployment-steps.md): Review the plan and prepare considerations, and then follow the steps in the onboarding checklist to successfully deploy and onboard Cortex AgentiX.
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/deployment-steps/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex AgentiX.
- [Activate Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/deployment-steps/activate-cortex-agentix.md): Activate a Cortex AgentiX tenant through Cortex Gateway and configure its name, region, and subdomain.
- [Cortex AgentiX supported regions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/deployment-steps/activate-cortex-agentix/cortex-agentix-supported-regions.md): Supported regions in which you want to host Cortex AgentiX and any associated services.
- [Enable access to Palo Alto Networks resources](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/deployment-steps/activate-cortex-agentix/enable-access-to-palo-alto-networks-resources.md): Depending on your network environment settings, you may need to enable network access to the Cortex AgentiX resources.
- [Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/deployment-steps/install-and-configure-content.md): Learn how content works in Cortex AgentiX.
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps.md): Complete post-deployment configuration for automation, integrations, users, roles, and access in Cortex AgentiX.
- [Post-deployment checklist](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/post-deployment-checklist.md): Complete your Cortex AgentiX post-deployment checklist for automations, integrations, users, dashboards, engines, and security settings.
- [Set up users, groups, and roles](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/set-up-users-and-roles.md): Set up Cortex AgentiX and Cortex Gateway users, user groups, roles, role-based access control (RBAC), and SAML SSO authentication.
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/configure-server-settings.md): Configure Cortex AgentiX server settings for user preferences, security controls, AI features, access, and tenant operations.
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/configure-security-settings.md): Configure Cortex AgentiX login sessions, approved domains and IP ranges, user expiration, and cookie security policies.
- [Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/set-up-an-engine.md): Set up a Cortex AgentiX engine on a remote machine.
- [Log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding.md): Configure Cortex AgentiX log forwarding and notifications for email, Slack, and syslog receivers.
- [Forward Cortex AgentiX logs and data to external services](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/forward-logs-and-data-from-cortex-agentix-to-external-services.md): Forward Cortex AgentiX logs, cases, and issues to Slack, syslog, email, Splunk, Amazon SQS, Amazon S3, and webhooks.
- [Configure external applications for forwarding](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/forward-logs-and-data-from-cortex-agentix-to-external-services/configure-external-applications-for-forwarding.md): Configure Cortex AgentiX external applications and Cortex Gateway egress for forwarding cases, issues, and logs to third-party services.
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/forward-logs-and-data-from-cortex-agentix-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver.md): Configure a Cortex AgentiX syslog receiver to forward logs and issues, allow regional IP addresses, and set TCP, UDP, or TLS connection settings.
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/forward-logs-and-data-from-cortex-agentix-to-external-services/configure-external-applications-for-forwarding/integrate-slack-for-outbound-notifications.md): Integrate Cortex AgentiX with a Slack workspace to forward issue and report notifications to dedicated Slack channels.
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/forward-logs-and-data-from-cortex-agentix-to-external-services/configure-notification-forwarding.md): Configure Cortex AgentiX notification forwarding for issues, cases, and audit logs to email, Slack, syslog, Splunk, Amazon S3, Amazon SQS, and webhooks.
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/forward-logs-and-data-from-cortex-agentix-to-external-services/monitor-administrative-activity.md): Monitor Cortex AgentiX management audit logs for administrative and investigative activity, filter log entries, and forward audit notifications to email, syslog, or Slack.
- [Data and log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/data-and-log-notification-formats.md): Learn about Cortex AgentiX notification formats for forwarded cases, issues, and logs, including alert-format issue notifications for email, syslog, and Slack.
- [Issue notification format](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/data-and-log-notification-formats/issue-notification-format.md): Review Cortex AgentiX issue notification formats for email, Slack, Splunk, Amazon S3, Amazon SQS, webhooks, and CEF-formatted syslog messages.
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-agentix/onboard-cortex-agentix/post-deployment-steps/log-forwarding/data-and-log-notification-formats/management-audit-log-notification-format.md): Review Cortex AgentiX Management Audit log notification formats for email and CEF-formatted syslog forwarding, including field mappings.
- [Learn how to configure Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-configuration.md): Configure Cortex AgentiX to match your use case.
- [Configure Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-cortex-agentix.md): Configure engines, playbooks, scripts, dashboards, etc., for your use case.
- [Cortex AgentiX Data Sources and Connectors](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources.md)
- [What are Cortex AgentiX data sources and connectors?](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/what-are-cortex-xsiam-data-sources.md): Learn more about Cortex AgentiX Data Sources and connectors with a unified approach to integrations.
- [Complete data source and connector catalog](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/complete-data-source-catalog.md): Learn more about the complete data source and connector catalog available in Cortex AgentiX.
- [Vendor-specific data sources and connectors](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors.md)
- [Absolute](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/absolute.md)
- [Absolute](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/absolute/absolute.md)
- [abuse.ch](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/abuse.ch.md)
- [abuse.ch](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/abuse.ch/abuse.ch.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/abuseipdb.md)
- [AbuseIPDB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/abuseipdb/abuseipdb.md)
- [Accenture](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/accenture.md)
- [Accenture](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/accenture/accenture.md)
- [AdminByRequest](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/adminbyrequest.md)
- [AdminByRequest](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/adminbyrequest/adminbyrequest.md)
- [Aha](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/aha.md)
- [Aha](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/aha/aha.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/aiops.md)
- [AIOps](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/aiops/aiops.md)
- [Akamai](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/akamai.md)
- [Akamai](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/akamai/akamai.md)
- [AlgoSec](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/algosec.md)
- [AlgoSec](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/algosec/algosec.md)
- [AlienVault](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/alienvault.md)
- [AlienVault](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/alienvault/alienvault.md)
- [Amazon](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/amazon.md)
- [AWS Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/amazon/aws-automation-and-collection.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/anomali.md)
- [Anomali](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/anomali/anomali.md)
- [Anthropic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/anthropic.md)
- [Claude Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/anthropic/claude-automation-and-collection.md)
- [Apache](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/apache.md)
- [Apache](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/apache/apache.md)
- [APIVoid](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/apivoid.md)
- [APIVoid](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/apivoid/apivoid.md)
- [ArcSight](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/arcsight.md)
- [ArcSight](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/arcsight/arcsight.md)
- [Arista Networks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/arista-networks.md)
- [Arista Networks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/arista-networks/arista-networks.md)
- [Arkime](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/arkime.md)
- [Arkime](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/arkime/arkime.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/atlassian.md)
- [Atlassian Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/atlassian/atlassian-automation-and-collection.md)
- [AttackIQ](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/attackiq.md)
- [AttackIQ](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/attackiq/attackiq.md)
- [Aurora Endpoint Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/aurora-endpoint-security.md)
- [Aurora Endpoint Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/aurora-endpoint-security/aurora-endpoint-security.md)
- [BeyondTrust](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/beyondtrust.md)
- [BeyondTrust](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/beyondtrust/beyondtrust.md)
- [Blocklist.de](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/blocklist.de.md)
- [Blocklist.de](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/blocklist.de/blocklist.de.md)
- [BlueCat Address Manager](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/bluecat-address-manager.md)
- [BlueCat Address Manager](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/bluecat-address-manager/bluecat-address-manager.md)
- [BMC](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/bmc.md)
- [BMC](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/bmc/bmc.md)
- [Box](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/box.md)
- [Box Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/box/box-automation-and-collection.md)
- [Broadcom](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/broadcom.md)
- [Broadcom](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/broadcom/broadcom.md)
- [BruteForceBlocker](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/bruteforceblocker.md)
- [BruteForceBlocker](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/bruteforceblocker/bruteforceblocker.md)
- [C2SEC](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/c2sec.md)
- [C2SEC](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/c2sec/c2sec.md)
- [CAPESandbox](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/capesandbox.md)
- [CAPESandbox](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/capesandbox/capesandbox.md)
- [Carbon Black](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/carbon-black.md)
- [Carbon Black](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/carbon-black/carbon-black.md)
- [Centreon](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/centreon.md)
- [Centreon](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/centreon/centreon.md)
- [Check Point](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/check-point.md)
- [Check Point FW1/VPN1](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/check-point/check-point-fw1-vpn1.md)
- [Checkpoint Firewall](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/check-point/checkpoint-firewall.md)
- [CheckPhish](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/checkphish.md)
- [CheckPhish](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/checkphish/checkphish.md)
- [CipherTrust](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ciphertrust.md)
- [CipherTrust](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ciphertrust/ciphertrust.md)
- [CIRCL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/circl.md)
- [CIRCL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/circl/circl.md)
- [CircleCI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/circleci.md)
- [CircleCI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/circleci/circleci.md)
- [Cisco](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco.md)
- [Cisco ASA firewalls and AnyConnect\`](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-asa-firewalls-and-anyconnect.md)
- [Cisco ASA](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-asa.md)
- [Cisco DUO Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-duo-automation-and-collection.md)
- [Cisco Firepower](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-firepower.md)
- [Cisco ISE](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-ise.md)
- [Cisco Meraki Automation and Remediation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-meraki-automation-and-remediation.md)
- [Cisco Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-security.md)
- [Cisco Umbrella](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-umbrella.md)
- [Cloaken](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cloaken.md)
- [Cloaken](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cloaken/cloaken.md)
- [CloudConvert](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cloudconvert.md)
- [CloudConvert](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cloudconvert/cloudconvert.md)
- [Cloudflare](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cloudflare.md)
- [Cloudflare](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cloudflare/cloudflare.md)
- [CounterTack](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/countertack.md)
- [CounterTack](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/countertack/countertack.md)
- [CrowdStrike](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike.md)
- [CrowdStrike](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike.md)
- [CryptoCurrency](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cryptocurrency.md)
- [CryptoCurrency](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cryptocurrency/cryptocurrency.md)
- [Cuckoo Sandbox](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cuckoo-sandbox.md)
- [Cuckoo Sandbox](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cuckoo-sandbox/cuckoo-sandbox.md)
- [CybelAngel](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cybelangel.md)
- [CybelAngel](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cybelangel/cybelangel.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cyberark.md)
- [CyberArk](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cyberark/cyberark.md)
- [Cyber Triage](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cyber-triage.md)
- [Cyber Triage](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cyber-triage/cyber-triage.md)
- [DeHashed](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/dehashed.md)
- [DeHashed](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/dehashed/dehashed.md)
- [DHS](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/dhs.md)
- [DHS](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/dhs/dhs.md)
- [dnstwist](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/dnstwist.md)
- [dnstwist](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/dnstwist/dnstwist.md)
- [EasyVista](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/easyvista.md)
- [EasyVista](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/easyvista/easyvista.md)
- [Email Hippo](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/email-hippo.md)
- [Email Hippo](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/email-hippo/email-hippo.md)
- [Elastic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/elastic.md)
- [ElasticSearch](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/elastic/elasticsearch.md)
- [Endgame](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/endgame.md)
- [Endgame](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/endgame/endgame.md)
- [Envoy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/envoy.md)
- [Envoy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/envoy/envoy.md)
- [Exabeam](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/exabeam.md)
- [Exabeam](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/exabeam/exabeam.md)
- [F5](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/f5.md)
- [F5 Automation and Remediation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/f5/f5-automation-and-remediation.md)
- [Fastly](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fastly.md)
- [Fastly](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fastly/fastly.md)
- [Fidelis](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fidelis.md)
- [Fidelis](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fidelis/fidelis.md)
- [Filigran](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/filigran.md)
- [Filigran OpenCTI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/filigran/filigran-opencti.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/forcepoint.md)
- [Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/forcepoint/forcepoint-dlp.md)
- [Forcepoint](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/forcepoint/forcepoint.md)
- [ForeScout](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/forescout.md)
- [ForeScout](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/forescout/forescout.md)
- [Fortinet](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fortinet.md)
- [Fortinet Fortigate](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortigate.md)
- [Fortinet FortiGate connector](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortigate/fortinet-fortigate-connector.md)
- [Fortinet](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet.md)
- [Fortinet FortiWeb VM](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortiweb-vm.md)
- [Fortra](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fortra.md)
- [Fortra](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fortra/fortra.md)
- [FraudWatch](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fraudwatch.md)
- [FraudWatch](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/fraudwatch/fraudwatch.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/freshworks.md)
- [Freshworks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/freshworks/freshworks.md)
- [Gamma.AI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/gamma.ai.md)
- [Gamma.AI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/gamma.ai/gamma.ai.md)
- [Generic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/generic.md)
- [Generic Intel Feed](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-intel-feed.md)
- [Generic MCP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-mcp.md)
- [Generic SQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/generic/generic-sql.md)
- [Gigamon](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/gigamon.md)
- [Gigamon](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/gigamon/gigamon.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/github.md)
- [GitHub](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/github/github.md)
- [GitLab](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/gitlab.md)
- [GitLab Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/gitlab/gitlab-automation-and-collection.md)
- [Giphy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/giphy.md)
- [Giphy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/giphy/giphy.md)
- [Google](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google.md)
- [Google AI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google/google-ai.md)
- [Google Cloud](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google/google-cloud.md)
- [Google SecOps](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google/google-secops.md)
- [Google Services](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google/google-services.md)
- [Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace.md)
- [Google Workspace connector](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace/google-workspace-connector.md)
- [Google Workspace Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspace/google-workspace-automation-and-collection.md)
- [GraphQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/graphql.md)
- [GraphQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/graphql/graphql.md)
- [Grouped Example Connector](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/grouped-example-connector.md)
- [Grouped Example Connector](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/grouped-example-connector/grouped-example-connector.md)
- [GRR](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/grr.md)
- [GRR](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/grr/grr.md)
- [Grafana](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/grafana.md)
- [Grafana](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/grafana/grafana.md)
- [HashiCorp](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hashicorp.md)
- [HashiCorp](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hashicorp/hashicorp.md)
- [Have I Been Pwnd](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/have-i-been-pwnd.md)
- [Have I Been Pwnd](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/have-i-been-pwnd/have-i-been-pwnd.md)
- [HCL BigFix](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hcl-bigfix.md)
- [HCL BigFix](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hcl-bigfix/hcl-bigfix.md)
- [HPE Aruba](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hpe-aruba.md)
- [HPE Aruba](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hpe-aruba/hpe-aruba.md)
- [Hostio Solutions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hostio-solutions.md)
- [Hostio Solutions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/hostio-solutions/hostio-solutions.md)
- [IBM](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ibm.md)
- [IBM QRadar](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-qradar.md)
- [IBM Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ibm/ibm-security.md)
- [Imperva](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/imperva.md)
- [Imperva](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/imperva/imperva.md)
- [InfoArmor](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/infoarmor.md)
- [InfoArmor](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/infoarmor/infoarmor.md)
- [Intellum](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/intellum.md)
- [Intellum](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/intellum/intellum.md)
- [IPInfo.io](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ipinfo.io.md)
- [IPInfo.io](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ipinfo.io/ipinfo.io.md)
- [IPstack](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ipstack.md)
- [IPstack](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ipstack/ipstack.md)
- [Ivanti](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ivanti.md)
- [Ivanti](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/ivanti/ivanti.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/izoologic.md)
- [iZOOlogic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/izoologic/izoologic.md)
- [Jamf](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/jamf.md)
- [Jamf](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/jamf/jamf.md)
- [Joe Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/joe-security.md)
- [Joe Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/joe-security/joe-security.md)
- [JSONWhoIs.com](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/jsonwhois.com.md)
- [JSONWhoIs.com](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/jsonwhois.com/jsonwhois.com.md)
- [Kafka](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/kafka.md)
- [Kafka](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/kafka/kafka.md)
- [Kaspersky](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/kaspersky.md)
- [Kaspersky](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/kaspersky/kaspersky.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/koi.md)
- [Koi](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/koi/koi.md)
- [Koodous](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/koodous.md)
- [Koodous](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/koodous/koodous.md)
- [Lastline](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lastline.md)
- [Lastline](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lastline/lastline.md)
- [LevelBlue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/levelblue.md)
- [LevelBlue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/levelblue/levelblue.md)
- [LogRhythm](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/logrhythm.md)
- [LogRhythm](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/logrhythm/logrhythm.md)
- [LOLBAS](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lolbas.md)
- [LOLBAS](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lolbas/lolbas.md)
- [Lookout](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lookout.md)
- [Lookout](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lookout/lookout.md)
- [Lumu](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lumu.md)
- [Lumu](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/lumu/lumu.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mail-utilities.md)
- [Mail Utilities](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mail-utilities/mail-utilities.md)
- [Majestic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/majestic.md)
- [Majestic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/majestic/majestic.md)
- [ManageEngine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/manageengine.md)
- [ManageEngine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/manageengine/manageengine.md)
- [Mattermost](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mattermost.md)
- [Mattermost](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mattermost/mattermost.md)
- [MaxMind](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/maxmind.md)
- [MaxMind](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/maxmind/maxmind.md)
- [Meta](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/meta.md)
- [Meta](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/meta/meta.md)
- [Mimecast](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mimecast.md)
- [Mimecast](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mimecast/mimecast.md)
- [Microsoft](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft.md)
- [Azure DevOps](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-devops.md)
- [Azure Firewall](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-firewall.md)
- [Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-365.md)
- [Azure Log Analytics](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-log-analytics.md)
- [Azure Services](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-services.md)
- [Azure WAF](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-waf.md)
- [Microsoft Active Directory](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-active-directory.md)
- [Microsoft Graph](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-graph.md)
- [Microsoft Identity](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-identity.md)
- [Microsoft Intune](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-intune.md)
- [Microsoft Security Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-security-automation-and-collection.md)
- [Microsoft Windows Tools](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-windows-tools.md)
- [M365 Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/microsoft/m365-automation-and-collection.md)
- [MISP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/misp.md)
- [MISP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/misp/misp.md)
- [MITRE](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mitre.md)
- [MITRE](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mitre/mitre.md)
- [MongoDB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mongodb.md)
- [MongoDB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mongodb/mongodb.md)
- [MxToolBox](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mxtoolbox.md)
- [MxToolBox](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/mxtoolbox/mxtoolbox.md)
- [Netcraft](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netcraft.md)
- [Netcraft](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netcraft/netcraft.md)
- [Netmiko](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netmiko.md)
- [Netmiko](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netmiko/netmiko.md)
- [NetQuest](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netquest.md)
- [NetQuest](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netquest/netquest.md)
- [Netskope](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netskope.md)
- [Netskope](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/netskope/netskope.md)
- [NIST](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/nist.md)
- [NIST](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/nist/nist.md)
- [nmap](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/nmap.md)
- [nmap](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/nmap/nmap.md)
- [NAVEX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/navex.md)
- [NAVEX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/navex/navex.md)
- [Nutanix](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/nutanix.md)
- [Nutanix](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/nutanix/nutanix.md)
- [Okta](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/okta.md)
- [Okta Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/okta/okta-automation-and-collection.md)
- [OpenAI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/openai.md)
- [OpenAI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/openai/openai.md)
- [OpenCVE](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opencve.md)
- [OpenCVE](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opencve/opencve.md)
- [OpenLDAP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/openldap.md)
- [OpenLDAP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/openldap/openldap.md)
- [OpenPhish](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/openphish.md)
- [OpenPhish](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/openphish/openphish.md)
- [OpenText](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opentext.md)
- [OpenText EnCase Endpoint Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-encase-endpoint-security.md)
- [OpenText Service Manager](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-service-manager.md)
- [OpenText Vertica](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opentext/opentext-vertica.md)
- [OPSWAT](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opswat.md)
- [OPSWAT MetaDefender](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/opswat/opswat-metadefender.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/oracle.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/oracle/oracle.md)
- [PacketMail.net](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/packetmail.net.md)
- [PacketMail.net](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/packetmail.net/packetmail.net.md)
- [PacketSled](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/packetsled.md)
- [PacketSled](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/packetsled/packetsled.md)
- [PagerDuty](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/pagerduty.md)
- [PagerDuty Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/pagerduty/pagerduty-automation-and-collection.md)
- [PAT Helpdesk Advanced](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/pat-helpdesk-advanced.md)
- [PAT Helpdesk Advanced](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/pat-helpdesk-advanced/pat-helpdesk-advanced.md)
- [PhishLabs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/phishlabs.md)
- [PhishLabs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/phishlabs/phishlabs.md)
- [Pipl](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/pipl.md)
- [Pipl](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/pipl/pipl.md)
- [Plainview](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/plainview.md)
- [Plainview](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/plainview/plainview.md)
- [Proofpoint](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/proofpoint.md)
- [Proofpoint](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/proofpoint/proofpoint.md)
- [ProtectWise](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/protectwise.md)
- [ProtectWise](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/protectwise/protectwise.md)
- [Qualys](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/qualys.md)
- [Qualys](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/qualys/qualys.md)
- [Quest KACE](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/quest-kace.md)
- [Quest KACE](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/quest-kace/quest-kace.md)
- [Rapid7](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/rapid7.md)
- [Rapid7](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/rapid7/rapid7.md)
- [Razor Group](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/razor-group.md)
- [Razor Group](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/razor-group/razor-group.md)
- [Recorded Future](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/recorded-future.md)
- [Recorded Future](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/recorded-future/recorded-future.md)
- [Red Hat](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/red-hat.md)
- [Red Hat Ansible](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/red-hat/red-hat-ansible.md)
- [Redmine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/redmine.md)
- [Redmine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/redmine/redmine.md)
- [ReliaQuest](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/reliaquest.md)
- [ReliaQuest](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/reliaquest/reliaquest.md)
- [RemoteAccess](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/remoteaccess.md)
- [RemoteAccess](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/remoteaccess/remoteaccess.md)
- [Retarus](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/retarus.md)
- [Retarus](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/retarus/retarus.md)
- [RSA](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/rsa.md)
- [RSA](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/rsa/rsa.md)
- [RTIR](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/rtir.md)
- [RTIR](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/rtir/rtir.md)
- [Salesforce](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/salesforce.md)
- [Salesforce connector](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/salesforce/ingest-and-run-salesforce-automation-and-remediation.md)
- [Samhaus](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/samhaus.md)
- [Samhaus](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/samhaus/samhaus.md)
- [SANS DShield](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sans-dshield.md)
- [SANS DShield](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sans-dshield/sans-dshield.md)
- [SAP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sap.md)
- [SAP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sap/sap.md)
- [Securonix](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/securonix.md)
- [Securonix](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/securonix/securonix.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/servicenow.md)
- [ServiceNow Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/servicenow/servicenow-automation-and-collection.md)
- [Shodan](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/shodan.md)
- [Shodan](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/shodan/shodan.md)
- [Skyhigh Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/skyhigh-security.md)
- [Skyhigh Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/skyhigh-security/skyhigh-security.md)
- [Slack](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/slack.md)
- [Slack Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/slack/slack-automation-and-collection.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/smb.md)
- [SMB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/smb/smb.md)
- [SMIME Messaging](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/smime-messaging.md)
- [SMIME Messaging](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/smime-messaging/smime-messaging.md)
- [Snowflake](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/snowflake.md)
- [Snowflake Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/snowflake/snowflake-automation-and-collection.md)
- [SolarWinds](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/solarwinds.md)
- [SolarWinds](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/solarwinds/solarwinds.md)
- [Sophos](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sophos.md)
- [Sophos](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sophos/sophos.md)
- [Splunk](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/splunk.md)
- [Splunk Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/splunk/splunk-automation-and-collection.md)
- [Sublime Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sublime-security.md)
- [Sublime Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sublime-security/sublime-security.md)
- [Sumo Logic](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sumo-logic.md)
- [Sumo Logic Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sumo-logic/sumo-logic-automation-and-collection.md)
- [SysAid](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sysaid.md)
- [SysAid](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/sysaid/sysaid.md)
- [Syslog Sender](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/syslog-sender.md)
- [Syslog Sender](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/syslog-sender/syslog-sender.md)
- [Tanium](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tanium.md)
- [Tanium](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tanium/tanium.md)
- [TAXII](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/taxii.md)
- [TAXII](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/taxii/taxii.md)
- [Telegram](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/telegram.md)
- [Telegram](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/telegram/telegram.md)
- [Tenable](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tenable.md)
- [Tenable](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tenable/tenable.md)
- [TheHive](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/thehive.md)
- [TheHive](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/thehive/thehive.md)
- [Thinkst Canary](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/thinkst-canary.md)
- [Thinkst Canary](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/thinkst-canary/thinkst-canary.md)
- [ThreatConnect](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/threatconnect.md)
- [ThreatConnect](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/threatconnect/threatconnect.md)
- [ThreatMiner.org](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/threatminer.org.md)
- [ThreatMiner.org](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/threatminer.org/threatminer.org.md)
- [ThreatX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/threatx.md)
- [ThreatX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/threatx/threatx.md)
- [Tidy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tidy.md)
- [Tidy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tidy/tidy.md)
- [TOPdesk](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/topdesk.md)
- [TOPdesk](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/topdesk/topdesk.md)
- [Tor Exit Adress](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tor-exit-adress.md)
- [Tor Exit Adress](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/tor-exit-adress/tor-exit-adress.md)
- [Trellix](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix.md)
- [Trellix Database Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-database-security.md)
- [Trellix Email Security (ETP)](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-email-security-etp.md)
- [Trellix Email Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-email-security.md)
- [Trellix Endpoint (HX)](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-endpoint-hx.md)
- [Trellix ePO](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-epo.md)
- [Trellix Network](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-network.md)
- [Trellix Sandbox](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-sandbox.md)
- [Trellix SIEM](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-siem.md)
- [Trellix Threat Intel](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trellix/trellix-threat-intel.md)
- [TrendAI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trendai.md)
- [TrendAI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/trendai/trendai.md)
- [Twilio](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/twilio.md)
- [Twilio](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/twilio/twilio.md)
- [Versa Networks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/versa-networks.md)
- [Versa Networks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/versa-networks/versa-networks.md)
- [VMware](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/vmware.md)
- [VMware Automation and Colection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/vmware/vmware-automation-and-colection.md)
- [VulnDB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/vulndb.md)
- [VulnDB](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/vulndb/vulndb.md)
- [WhatsMyBrowser.org](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/whatsmybrowser.org.md)
- [WhatsMyBrowser.org](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/whatsmybrowser.org/whatsmybrowser.org.md)
- [Whois](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/whois.md)
- [Whois](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/whois/whois.md)
- [Workday](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/workday.md)
- [Workday Automation and Collection](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/workday/workday-automation-and-collection.md)
- [X](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/x.md)
- [X Automation and Remediation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/x/x-automation-and-remediation.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zendesk.md)
- [Zendesk](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zendesk/zendesk.md)
- [Zimperium](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zimperium.md)
- [Zimperium](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zimperium/zimperium.md)
- [Zoom](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zoom.md)
- [Zoom](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zoom/zoom.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zscaler.md)
- [Zscaler](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscaler.md)
- [Connectors](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/connectors.md)
- [Standard data sources](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/standard-data-sources.md)
- [Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations.md)
- [Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/next-generation-firewall.md)
- [Panorama](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/next-generation-firewall/panorama.md)
- [Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/prisma-access.md)
- [Palo Alto Networks Prisma](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/prisma-access/palo-alto-networks-prisma.md)
- [IoT Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/iot-security.md)
- [IoT Security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/iot-security/iot-security.md)
- [Cortex Automation Developer Tools](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/cortex-automation-developer-tools.md)
- [Cortex Data Lake](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/cortex-data-lake.md)
- [Cortex Internals](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/cortex-internals.md)
- [Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/cortex-xdr.md)
- [Enterprise DLP](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/enterprise-dlp.md)
- [Palo Alto Networks Cortex](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/palo-alto-networks-cortex.md)
- [PAN PSIRT Advisories](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/pan-psirt-advisories.md)
- [Prisma Cloud Compute](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/prisma-cloud-compute.md)
- [Prisma Cloud CSPM](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/prisma-cloud-cspm.md)
- [SaaS Security (Aperture)](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/saas-security-aperture.md)
- [Threat Vault](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/threat-vault.md)
- [WildFire Cloud](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/palo-alto-networks-integrations/wildfire-cloud.md)
- [Administration and troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting.md): Learn more about the administration and troubleshooting of the different data collector and connector integrations in Cortex AgentiX.
- [Manage instances](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/manage-instances.md)
- [Add a new data source or instance](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/manage-instances/add-a-new-data-source-or-instance.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations.md): Set up an integration instance and start ingesting cases/indicators.
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/manage-api-keys.md)
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/integration-use-cases.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/add-an-integration-instance.md)
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/configure-integration-permissions.md)
- [Fetch issues from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/fetch-issues-from-an-integration-instance.md)
- [Map fields to issue types](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/fetch-issues-from-an-integration-instance/map-fields-to-issue-types.md)
- [Classify events using a classifier for issue types](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/fetch-issues-from-an-integration-instance/classify-events-using-a-classifier-for-issue-types.md)
- [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/forward-requests-to-long-running-integrations.md)
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/manage-credentials.md)
- [Troubleshoot Integrations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/integrations/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex AgentiX.
- [Verify collector connectivity](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/verify-collector-connectivity.md): Verify collector connectivity and troubleshoot collector errors.
- [Overview of data ingestion metrics](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics.md): Learn more about the data ingestion health metrics in the metrics\_source dataset and the metrics\_view preset.
- [Creating correlation rules to monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics/creating-correlation-rules-to-monitor-data-ingestion-health.md): See examples of correlation rules for monitoring data ingestion health.
- [Measuring data freshness](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/administration-and-troubleshooting/overview-of-data-ingestion-metrics/measuring-data-freshness.md): Learn more about the data freshness metrics collected by Cortex AgentiX.
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace.md): Use the Marketplace, a centralized content portal, to download and manage content packs in Cortex AgentiX.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace/cortex-marketplace.md)
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace/content-packs.md)
- [Content pack support types](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace/content-pack-support-types.md)
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace/manage-content-packs.md)
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace/marketplace-faqs.md)
- [Content changes when upgrading Cortex AgentiX versions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace/content-changes-when-upgrading-cortex-agentix-versions.md)
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/marketplace/content-pack-contributions.md)
- [Configure the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant.md)
- [Agentic Assistant components and concepts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agentic-assistant-components-and-concepts.md): Learn about the key components and concepts, such as agents and actions in the Cortex Agentic Assistant
- [Agentic Assistant Hub](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agents-hub.md): Learn about personal and system agents in in the Agentic Assistant Hub
- [Manage actions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agents-hub/manage-actions.md)
- [Register actions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agents-hub/register-actions.md)
- [Manage agents](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agents-hub/manage-agents.md)
- [Build agents](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agents-hub/build-agents.md)
- [Manage knowledge sources (preview)](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agents-hub/manage-knowledge-sources-preview.md): Enhance AI agent capabilities by leveraging the Knowledge Center (preview) to provide agents with your business-specific source of truth and built-in Cortex (system) knowledge.
- [Expand agent capabilities with MCP integrations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agents-hub/expand-agent-capabilities-with-mcp-integrations.md)
- [Agentic Assistant role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/configure-the-cortex-agentic-assistant/agentic-assistant-role-based-access-control.md): Configure permissions to access Cortex Agentic Assistant features.
- [Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-mcp-server.md): The Cortex MCP server enables you to leverage Cortex's powerful capabilities directly through natural language.
- [Install the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-mcp-server/install-the-cortex-mcp-server.md)
- [Configure the MCP client](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-mcp-server/configure-the-mcp-client.md)
- [Use the Cortex MCP server](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-mcp-server/use-the-cortex-mcp-server.md)
- [Create custom Cortex MCP server tools](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-mcp-server/create-custom-cortex-mcp-server-tools.md)
- [Remote repository management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/remote-repository-management.md)
- [Cortex AgentiX development tenant](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/remote-repository-management/cortex-agentix-development-tenant.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
- [Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/remote-repository-management/set-up-a-remote-repository.md): Use a remote repository in Cortex AgentiX to enable centralized version control and streamlined collaboration across multiple environments.
- [Set up a built-in remote repository](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/remote-repository-management/set-up-a-remote-repository/set-up-a-built-in-remote-repository.md)
- [Set up a Private Remote Repository](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/remote-repository-management/set-up-a-remote-repository/set-up-a-private-remote-repository.md)
- [Push and pull content](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/remote-repository-management/push-and-pull-content.md): Learn more about synchronizing content across different environments.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex AgentiX.
- [Users and roles management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management.md): Manage Cortex AgentiX users, roles, user groups, authentication, and access permissions.
- [Users, groups, and roles in Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/users-and-roles-in-cortex-agentix.md): Set up and configure roles and user groups for the Cortex AgentiX tenant and Cortex Gateway. Configure authentication and manage users.
- [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management.md): Manage Cortex AgentiX roles, permissions, and role assignments in Cortex Gateway and tenant environments.
- [Manage roles in the Cortex AgentiX tenant](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/manage-roles-in-the-cortex-agentix-tenant.md): Create, edit, and manage roles in your Cortex AgentiX tenant.
- [Role permissions by component](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component.md): Review the permissions available for each Cortex AgentiX component.
- [Dashboards and Reports permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/dashboards-and-reports-permissions.md): Configure Cortex AgentiX permissions for dashboards, reports, widgets, and security posture visibility.
- [Dashboards permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/dashboards-and-reports-permissions/dashboards-permissions.md): Configure Cortex AgentiX dashboard permissions for viewing, creating, sharing, and accessing widget data.
- [Reports permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/dashboards-and-reports-permissions/reports-permissions.md): Configure Cortex AgentiX permissions for reports, report templates, object access, and security data visibility.
- [Command Center Dashboard permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/dashboards-and-reports-permissions/command-center-dashboard-permissions.md): Configure Cortex Command Center Dashboard access and required permissions for dashboards, cases, and playbooks in Cortex AgentiX.
- [Cases and Issues permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/cases-and-issues-permissions.md): Configure Cortex AgentiX permissions for case and issue triage, investigation, playbook response, and security operations.
- [Investigation and Response permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions.md): Explore Cortex AgentiX permissions for investigation, response, automation, threat intelligence, and related workflows.
- [Query Library permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions/query-library-permissions.md): Configure Query Library permissions for saving, sharing, reusing, running, and scheduling XQL queries in Cortex AgentiX.
- [Query Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions/query-center-permissions.md): Configure Query Center permissions for writing, running, scheduling, and exporting XQL queries with scoped data access.
- [Playbook permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions/playbook-permissions.md): Configure Cortex AgentiX permissions for accessing, building, sharing, and running automated response playbooks.
- [Script permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions/script-permissions.md): Configure Cortex AgentiX permissions for accessing, creating, sharing, and running automation scripts, including elevated scripts.
- [Jobs permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions/jobs-permissions.md): Configure Cortex AgentiX permissions for viewing, managing, and running scheduled automation jobs and playbooks.
- [Playground permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions/playground-permissions.md): Configure Cortex AgentiX Playground permissions for testing automation commands, scripts, playbooks, and integrations.
- [Automation Exclusion Center permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/investigation-and-response-permissions/automation-exclusion-center-permissions.md): Configure Automation Exclusion Center permissions for managing remediation exclusions, assets, policies, and automation controls.
- [Threat Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/threat-management-permissions.md): Configure Cortex AgentiX permissions for detection rules, threat intelligence, Marketplace content, and exception workflows.
- [Detection Rules permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/threat-management-permissions/detection-rules-permissions.md): Configure Cortex AgentiX permissions for viewing and managing correlation and indicator detection rules.
- [Threat Intelligence permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/threat-management-permissions/threat-intelligence-permissions.md): Configure Cortex AgentiX permissions for indicators, threat intelligence feeds, TIM, and Extended Threat Intelligence.
- [Marketplace permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/marketplace-permissions.md): Configure Cortex AgentiX Marketplace permissions for browsing, installing, updating, and managing automation content packs.
- [Exceptions Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/exceptions-configuration-permissions.md): Configure Cortex AgentiX permissions for issue suppression, exception rules, and exception approval workflows.
- [Exception Management Admin permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/exceptions-configuration-permissions/exception-management-admin-permissions.md): Configure Exception Management Admin permissions in Cortex AgentiX.
- [Exception Approver Admin permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/exceptions-configuration-permissions/exception-approver-admin-permissions.md): Configure Exception Approver Admin permissions in Cortex AgentiX.
- [Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions.md): Explore Cortex AgentiX role permissions for configuration, administration, data, integrations, and platform settings.
- [Auditing permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/auditing-permissions.md): Control access to Cortex AgentiX management audit logs.
- [Alert Notifications permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/alert-notifications-permissions.md): Control access to Cortex AgentiX alert notification settings and forwarding.
- [General Configuration permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/general-configuration-permissions.md): Control access to Cortex AgentiX tenant-wide server and configuration settings.
- [Access management permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/access-management-permissions.md): Control access to Cortex AgentiX users, roles, groups, and authentication settings.
- [Data Sources permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/data-sources-permissions.md): Control access to Cortex AgentiX cloud and third-party data source integrations.
- [Integrations - instance permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/integrations-instance-permissions.md): Control access to Cortex AgentiX data collection integration instances.
- [Data Management permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/data-management-permissions.md): Control access to Cortex AgentiX dataset configuration and data lifecycle management.
- [Public API](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/public-api.md): Control access to Cortex AgentiX API keys and compute unit usage.
- [Threat Intelligence permission - API configuration](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/threat-intelligence-permission-api-configuration.md): Control access to Cortex AgentiX external threat intelligence API configuration.
- [Integrations Permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/integrations-permissions.md): Control Cortex AgentiX role-based access to integration commands.
- [Credentials permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/credentials-permissions.md): Control access to Cortex AgentiX credentials for integrations and automation.
- [Case Properties permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/case-properties-permissions.md): Control access to Cortex AgentiX case domains, statuses, and properties.
- [Exclusion list permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/exclusion-list-permissions.md): Control access to Cortex AgentiX indicator exclusion list configuration.
- [Fields and Types permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/fields-and-types-permissions.md): Control access to Cortex AgentiX custom fields and indicator types.
- [Layout permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/layout-permissions.md): Control access to Cortex AgentiX case and issue layout configuration.
- [Sync Profile permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/configuration-permissions/sync-profile-permissions.md): Control access to Cortex AgentiX case mirroring sync profile configuration.
- [Help permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/help-permissions.md): Configure Cortex AgentiX permissions for creating support cases, attaching troubleshooting artifacts, and contacting support.
- [Cortex Agentic Assistant permissions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/cortex-agentic-assistant-permissions.md): Configure Cortex AgentiX Agentic Assistant permissions for AI prompts, agents, natural-language investigations, and automated actions.
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/cortex-agentic-assistant-permissions/ai-prompts.md): Configure AI Prompt Library permissions for creating reusable prompts and managing AI tasks in Cortex AgentiX playbooks.
- [Cortex Agentic Assistant Agents](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/roles-management/role-permissions-by-component/cortex-agentic-assistant-permissions/cortex-agentic-assistant-agents.md): Configure Cortex AgentiX Agentic Assistant permissions for agent interactions, actions, custom agents, and administrator controls.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-group-management.md): Manage Cortex AgentiX user groups, role assignments, nested groups, SAML mapping, and scoped access.
- [User management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management.md): Manage Cortex AgentiX user accounts, roles, groups, SSO access, scopes, and user status in Gateway or tenants.
- [Manage users in the Cortex AgentiX tenant](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management/manage-users-in-the-cortex-agentix-tenant.md): Manage Cortex AgentiX tenant users, roles, groups, scoped access, deactivation, and bulk role assignments.
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management/manage-user-scope.md): Configure Scope-Based Access Control in Cortex AgentiX to apply granular case and issue access alongside RBAC.
- [Manage access to objects](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/manage-access-to-objects.md): Learn more about managing access to objects in Cortex AgentiX.
- [Manage access to custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/manage-access-to-objects/manage-access-to-custom-dashboards.md): Manage custom dashboard sharing, role permissions, ownership, widget visibility, and data access in Cortex AgentiX.
- [Manage access to report templates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/manage-access-to-objects/manage-access-to-report-templates.md): Manage report template sharing, role permissions, ownership, generated report access, and scoped data in Cortex AgentiX.
- [Manage access to playbooks and scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/manage-access-to-objects/manage-access-to-playbooks-and-scripts.md): Manage playbook and script sharing, role permissions, ownership, imports, and automation execution access in Cortex AgentiX.
- [Manage access to saved queries](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/manage-access-to-objects/manage-access-to-saved-queries.md): Manage saved XQL query sharing, role permissions, ownership, and public or restricted visibility in Cortex AgentiX.
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/set-up-authentication.md): Authenticate Cortex AgentiX users using SAML 2.0 or Customer Support Portal (CSP).
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate Cortex AgentiX users through the Customer Support Portal and assign roles for Gateway and tenant access.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Configure SAML 2.0 SSO for Cortex AgentiX with identity provider mapping, user groups, roles, and tenant access.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta SAML 2.0 SSO for Cortex AgentiX with user attributes, group mapping, and authentication testing.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID SAML 2.0 SSO for Cortex AgentiX with group claims, mappings, and authentication testing.
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/install-an-engine.md): Install, deploy and configure Cortex AgentiX engines.
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker.md): Install, configure, secure, and troubleshoot Docker for Cortex XSIAM engines.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/install-docker.md): Install Docker and verify engine user permissions.
- [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/install-docker-distribution-for-red-hat.md): Configure Docker and SELinux on Red Hat engine servers.
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-image-security.md): Secure, harden, and troubleshoot Docker images and containers.
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-faqs.md)
- [Troubleshoot Docker Issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/configure-docker-pull-rate-limit.md)
- [Change the Docker Installation folder](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/change-the-docker-installation-folder.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide.md)
- [Docker network hardening](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide/docker-network-hardening.md)
- [Configure Docker images](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide/configure-docker-images.md)
- [Run Docker with non-root internal users](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
- [Configure the memory limit support without swap capabilities](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide/configure-the-memory-limit-support-without-swap-capabilities.md)
- [Configure the memory limitation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide/configure-the-memory-limitation.md)
- [Configure the CPU, PIDs, and open the file descriptors limit](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide/configure-the-cpu-pids-and-open-the-file-descriptors-limit.md)
- [Check Docker hardening configurations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/docker/docker-hardening-guide/check-docker-hardening-configurations.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/podman.md): Install, configure, and troubleshoot Podman for Cortex XSIAM engines.
- [Change the Container storage](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/podman/change-the-container-storage.md): Configure Podman container storage for an engine.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/podman/install-podman.md): Install and configure Podman for Cortex XSIAM engines.
- [Migrate from Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/podman/migrate-from-docker-to-podman.md): Migrate an existing engine from Docker to Podman.
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/podman/troubleshoot-podman.md): Resolve common Podman issues on Cortex XSIAM engines.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/manage-engines.md): Manage engines and load balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/upgrade-an-engine.md): Upgrade an engine on Cortex AgentiX or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/configure-engines.md): Configure Cortex AgentiX engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md)
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/use-an-engine-in-an-integration.md): Use an engine or a load-balancing group of engines to fetch issues and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/engines/troubleshoot-integrations-running-on-engines.md)
- [Cases and issues configuration](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration.md): Configure cases and issues in Cortex AgentiX including domains, fields, and layouts. Set up correlation rules and configure an external dynamic list.
- [Case and issue lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/case-and-issue-lifecycle.md): Cases and issues go through various processes in Cortex AgentiX including ingestion, case/issue creation, planning, investigation, and response.
- [Customize your cases](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-your-cases.md)
- [Create a case domain](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-your-cases/create-a-case-domain.md)
- [Create a starring configuration](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-your-cases/create-a-starring-configuration.md)
- [Set up case scoring](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-your-cases/set-up-case-scoring.md)
- [Create custom case statuses and resolution reasons](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-your-cases/create-custom-case-statuses-and-resolution-reasons.md)
- [Customize issue fields and layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts.md): You can create custom issue fields and custom issue layouts for out-of-the-box and custom issue fields.
- [Issue fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields.md)
- [Issue field types](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/issue-field-types.md)
- [Create custom issue fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields.md)
- [Create a grid field for an issue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields/create-a-grid-field-for-an-issue.md)
- [Issue field triggered scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields/issue-field-triggered-scripts.md)
- [Issue timer fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields/issue-timer-fields.md)
- [Configure issue timer fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields/issue-timer-fields/configure-issue-timer-fields.md)
- [Configure a playbook to run timers](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields/issue-timer-fields/configure-a-playbook-to-run-timers.md)
- [Automate changes to issue fields using timer scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields/issue-timer-fields/automate-changes-to-issue-fields-using-timer-scripts.md)
- [Use issue timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-fields/create-custom-issue-fields/issue-timer-fields/use-issue-timer-field-commands-manually-in-the-cli.md)
- [Issue layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-layouts.md)
- [Create custom issue layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-layouts/create-custom-issue-layouts.md)
- [Add a custom widget to an issue layout](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-layouts/add-a-custom-widget-to-an-issue-layout.md)
- [Create rules for issue layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-issue-fields-and-layouts/issue-layouts/create-rules-for-issue-layouts.md)
- [Customize case fields and layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts.md): You can create custom case fields and custom case layouts for out-of-the-box and custom case fields.
- [Case fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-fields.md)
- [Case field types](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-fields/case-field-types.md)
- [Create custom case fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-fields/create-custom-case-fields.md)
- [Create a grid field for a case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-fields/create-custom-case-fields/create-a-grid-field-for-a-case.md)
- [Update case fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-fields/create-custom-case-fields/update-case-fields.md)
- [Create case timers and SLAs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-fields/create-case-timers-and-slas.md)
- [Case layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-layouts.md)
- [Create custom case layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-layouts/create-custom-case-layouts.md)
- [Create rules for case layouts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/customize-case-fields-and-layouts/case-layouts/create-rules-for-case-layouts.md)
- [Issue syncing](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/issue-syncing.md)
- [Create a sync profile](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/issue-syncing/create-a-sync-profile.md)
- [Create issue exceptions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/create-issue-exceptions.md): Create an issue exception to formally defer the remediation of an issue.
- [Configure the issue exception approval workflow](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/create-issue-exceptions/configure-the-issue-exception-approval-workflow.md)
- [Create an issue exception rule](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/create-issue-exceptions/create-an-issue-exception-rule.md)
- [Create an exception rule from an issue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/create-issue-exceptions/create-an-exception-rule-from-an-issue.md)
- [View issue Exception Rules](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/create-issue-exceptions/view-issue-exception-rules.md)
- [Disable issue exception rules](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/create-issue-exceptions/disable-issue-exception-rules.md)
- [View excepted issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/create-issue-exceptions/view-excepted-issues.md)
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/whats-a-correlation-rule.md): Correlation rules help you analyze correlations of multi-events from multiple sources by using the Cortex Query Language based engine for creating scheduled rules.
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/whats-a-correlation-rule/correlation-rule-details.md)
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/whats-a-correlation-rule/create-a-correlation-rule.md)
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/whats-a-correlation-rule/manage-correlation-rules.md)
- [Optimize case grouping in correlations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cases-and-issues-configuration/optimize-case-grouping-in-correlations.md)
- [Automations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations.md)
- [Automation in Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/automation-in-cortex-agentix.md): Automate response to issues, using playbooks and Quick Actions, triggered automatically by automation rules or manually from an issue.
- [Quick Actions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/quick-actions.md)
- [Automation Exclusion Center](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/automation-exclusion-center.md): Automation exclusion policies prevent commands and scripts from performing remediation on critical assets.
- [Manage automation exclusion policies](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/automation-exclusion-center/manage-automation-exclusion-policies.md): Edit, enable, disable, and configure automation exclusion policies.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks.md): Create, manage, and automate security response workflows with playbooks.
- [Playbooks overview](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/playbooks-overview.md): Learn how playbooks automate security response workflows.
- [Access to playbooks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/access-to-playbooks.md): Understand object-level access roles for playbooks.
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/playbook-development-checklist.md): Follow the key stages for planning, building, customizing, and testing a playbook.
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/plan-your-playbook.md): Plan an automated workflow before building a playbook.
- [Manage playbooks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/manage-playbooks.md): View, manage, and adopt playbooks from your organization and Marketplace.
- [Build your playbook](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook.md)
- [Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/choose-from-existing-playbooks-or-create-your-own.md)
- [Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/configure-playbook-settings.md)
- [Add objects from the Task Library](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library.md)
- [Add commands and scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-commands-and-scripts.md)
- [Add sub-playbooks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-sub-playbooks.md)
- [Add AI Prompt tasks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-ai-prompt-tasks.md)
- [Add manual tasks and blank tasks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks.md): Add manual and blank tasks to a playbook.
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-standard-task.md): Define a Standard task in Cortex AgentiX.
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-conditional-task.md): Create a Conditional task in a playbook.
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-manual-tasks-and-blank-tasks/create-a-communication-task.md): Create Cortex AgentiX playbook communication tasks to send surveys, collect issue data, and automate workflows.
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/create-a-section-header.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/configure-script-error-handling-in-a-playbook.md)
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook.md)
- [Configure a sub-playbook loop](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/configure-a-sub-playbook-loop.md)
- [Filter and Transform data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/filter-and-transform-data.md)
- [Create custom filter and transformers](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/create-custom-filter-and-transformers.md)
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/filter-considerations-categories-and-built-in-filters.md)
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/transformer-considerations-categories-and-built-in-transformers.md)
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/extend-context.md)
- [Extract Indicators](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/extract-indicators.md)
- [Update issue fields with playbook tasks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/customize-your-playbook/update-issue-fields-with-playbook-tasks.md)
- [Test your playbook](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/test-your-playbook.md): Set breakpoints, conditional breakpoints, skips, and input or output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/test-your-playbook/troubleshoot-playbook-performance.md)
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/build-your-playbook/manage-playbook-content.md)
- [Accelerate playbook development using the Automation Engineer agent (preview)](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview.md)
- [Automation Engineer prompt examples](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/accelerate-playbook-development-using-the-automation-engineer-agent-preview/automation-engineer-prompt-examples.md)
- [Best practices for playbooks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/playbooks/best-practices-for-playbooks.md)
- [AI Prompts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/ai-prompts.md)
- [AI prompts role-based access control](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/ai-prompts/ai-prompts-role-based-access-control.md): Manage AI prompt permissions with role-based access control.
- [Use existing prompts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/ai-prompts/use-existing-prompts.md): Find, duplicate, and edit prompts from the Prompts Library.
- [Create a prompt](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/ai-prompts/create-a-prompt.md): Create or edit prompts, configure settings, and use them in agents or playbooks.
- [Write effective prompts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/ai-prompts/write-effective-prompts.md): Tips for creating effective AI prompts.
- [Agentic Response (Preview)](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/agentic-response-preview.md): Learn how Agentic Response transitions automated SOC workflows from linear playbooks to dynamic, agentic automation by triggering AI agents directly from an automation rule.
- [Create an automation rule](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/create-an-automation-rule.md): Learn how to create an automation rule for an issue.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/scripts.md)
- [Access to scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/scripts/access-to-scripts.md)
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/scripts/use-exisiting-scripts.md)
- [Create a Script](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/scripts/create-a-script.md)
- [Accelerate script development using the Automation Engineer agent](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/scripts/accelerate-script-development-using-the-automation-engineer-agent.md)
- [Change the Docker image](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/scripts/change-the-docker-image.md): Select a different Docker image for scripts or integrations.
- [Context data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data.md): Use context data to assist with the investigation and remediation process.
- [Issue context data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data/issue-context-data.md)
- [Case context data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data/case-context-data.md)
- [Search context data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data/search-context-data.md)
- [Add context data to an issue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data/add-context-data-to-an-issue.md)
- [Add context data to a case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data/add-context-data-to-a-case.md)
- [Delete context data from a case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data/delete-context-data-from-a-case.md)
- [Use context data in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/context-data/use-context-data-in-a-playbook.md)
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists.md): Use lists to store data for use in playbooks and scripts.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists/create-a-list.md)
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists/list-commands.md)
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists/use-cases-json-lists.md)
- [Extract data from a JSON object](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists/use-cases-json-lists/extract-data-from-a-json-object.md)
- [Extract a subset of the data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists/use-cases-json-lists/extract-a-subset-of-the-data.md)
- [Filter extracted data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists/use-cases-json-lists/filter-extracted-data.md)
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/lists/transform-a-list-into-an-array-1.md)
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
- [Access to Jobs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/jobs/access-to-jobs.md)
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/jobs/manage-jobs.md): Create, manage, and schedule playbook jobs
- [Create a time-triggered job](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/jobs/create-a-time-triggered-job.md): Schedule a playbook to run at a specific time
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/automations/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Trigger a playbook when a feed changes
- [Data management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management.md): Learn how to use datasets, data model rules, and configure parsing rules.
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period-based retention.
- [What are datasets?](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/dataset-management/what-are-datasets.md)
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/dataset-management/lookup-datasets.md)
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/dataset-management/lookup-datasets/import-a-lookup-dataset.md)
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/dataset-management/lookup-datasets/download-json-file-of-lookup-dataset.md)
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/dataset-management/lookup-datasets/set-time-to-live-for-lookup-datasets.md)
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md)
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/manage-compute-units.md): Learn more about managing and tracking your compute units usage.
- [Manage Event Forwarding](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/data-management/manage-event-forwarding.md): Save your ingested, parsed data in an external location by exporting your event logs to a temporary GCP storage bucket.
- [Monitor dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports.md)
- [Overview of dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports.md)
- [Dashboard interface basics](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basics.md)
- [Dashboard types](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-types.md)
- [Report basics](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/report-basics.md)
- [Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/overview-of-dashboards-and-reports/widget-library.md)
- [Access and visibility for dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports.md)
- [Visibility settings](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settings.md)
- [Access to widgets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgets.md)
- [Sharing icons](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-icons.md)
- [Access and sharing cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-and-sharing-cheat-sheet.md)
- [Manage dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports.md)
- [Dashboard Manager](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/dashboard-manager.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/reports.md)
- [Duplicate dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reports.md)
- [Share custom dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templates.md)
- [Change ownership to dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templates.md)
- [Import and export dashboards and report templates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templates.md)
- [Configure the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-report.md)
- [Deleted content](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/manage-dashboards-and-reports/deleted-content.md)
- [Create dashboards](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards.md)
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-dashboards/create-a-dashboard.md)
- [Create reports](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports.md)
- [Create a report template from scratch](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/create-reports/create-a-report-template-from-scratch.md)
- [Advanced configuration](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration.md)
- [Create custom widgets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets.md)
- [Create widgets using AI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-ai.md)
- [Create XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets.md)
- [Add parameters to a custom XQL widget](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widget.md)
- [Create script-based widgets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgets.md)
- [Configure global filters](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-global-filters.md)
- [Configure drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/advanced-configuration/configure-drilldowns.md)
- [Dashboard reference](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference.md)
- [Command Center reference](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference.md)
- [Cortex Agentic Assistant dashboard](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-agentic-assistant-dashboard.md)
- [Cortex Cloud Command Center](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/command-center-reference/cortex-cloud-command-center.md)
- [System dashboards](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md)
- [Cortex Cloud Consumption](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cortex-cloud-consumption.md)
- [Cloud Security Operations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards/cloud-security-operations.md)
- [Investigation and Response](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response.md): Learn how to investigate cases and issues, run commands, use XQL to run queries, and use the Cortex Copilot.
- [Overview of cases](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases.md): Understand how cases work in Cortex AgentiX.
- [What are cases?](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/what-are-cases.md): A case provides the full contextual story of a problem that impacts your organization's security, giving you an end-to-end view of the problem and streamlining your understanding of what needs to be s
- [Resolving cases with AI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/resolving-cases-with-ai.md): AI tools can help you through the case analysis and resolution process.
- [Case lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-lifecycle.md): Understand the lifecycle of a case.
- [Case thresholds](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-thresholds.md): Case grouping thresholds are implemented to keep cases manageable.
- [Case scope and impact](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-scope-and-impact.md): A case's scope and impact is determined by the assigned severity, score, and domain.
- [Case and issue domains](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/case-and-issue-domains.md): Cortex AgentiX assigns each case and issue to a domain. Domains help you to organize and manage your work efforts, and differentiate between use cases.
- [Overview of case teams and roles](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/overview-of-cases/overview-of-case-teams-and-roles.md)
- [Case concepts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts.md)
- [Issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/issues.md)
- [Case grouping](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-grouping.md): Cortex AgentiX uses a specific case grouping logic to build cases.
- [Case scoring](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-scoring.md): Learn about case scoring methods.
- [Case starring](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/case-starring.md): Starring cases can help you to prioritize and filter your cases.
- [SLAs and tracking](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/case-concepts/slas-and-tracking.md): You can set up Service Level Agreements (SLAs) to track your cases against SLA targets.
- [Analyze and resolve cases](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases.md): Learn how to analyze and resolve cases.
- [Review all cases](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/review-all-cases.md): Start reviewing your open cases on the Cases page.
- [Start case analysis](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/start-case-analysis.md): Understand the case analysis and resolution process.
- [Agentic Assistant - Case Investigation agent](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/start-case-analysis/agentic-assistant-case-investigation-agent.md)
- [Establish case context](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/establish-case-context.md)
- [Analyze case details](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details.md): You can analyze detailed information about the case in the Overview section of the Case card.
- [Grouping graph](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/grouping-graph.md)
- [Evidence](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/evidence.md)
- [Issue feed](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/issue-feed.md)
- [Associated assets and artifacts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/associated-assets-and-artifacts.md)
- [MITRE ATT\&CK tactics and techniques](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/mitre-att-and-ck-tactics-and-techniques.md)
- [Case timeline](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/case-timeline.md)
- [Detailed view](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/detailed-view.md)
- [Resolve the case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case.md): You can start remediating a case by reviewing the actions in the Resolution Center.
- [Resolution Center](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolution-center.md)
- [Collaborative notes and comments](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/collaborative-notes-and-comments.md)
- [How to resolve a case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolve-a-case.md)
- [Resolution reasons for cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/resolve-the-case/resolution-reasons-for-cases-and-issues.md)
- [Additional case actions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions.md)
- [Create a case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/create-a-case.md): You can manually create a new case, assign it to a specific domain, and define custom fields for the case.
- [Merge a case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/merge-a-case.md)
- [Assign a case team and restrict access](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access.md)
- [Playbook examples](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/additional-case-actions/assign-a-case-team-and-restrict-access/playbook-examples.md)
- [Investigate issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues.md): Cortex AgentiX generates issues to bring your attention to security risks in your framework.
- [Overview of the Issues page](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/overview-of-the-issues-page.md): The Issues page consolidates all non-informational issues from your detection sources.
- [Issue card](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-card.md): On the Issue card, you can see details of the selected issue and take actions on an issue.
- [Resolution actions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/resolution-actions.md): See all recommended remediation actions for an issue on the Resolution tab.
- [Link or unlink issues from a case](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/link-or-unlink-issues-from-a-case.md)
- [Run an automation on an issue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/run-an-automation-on-an-issue.md): Save time and expense by using playbooks and Quick Actions to automatically investigate and take remedial action on issues.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into a case, to filter war room entries, and to disable indicator notifications.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to a case. Use it to monitor and manage a playbook workflow.
- [Manage synced tickets in issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/manage-synced-tickets-in-issues.md): Manually sync a ticket to an issue
- [Issue investigation actions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions.md)
- [Copy issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/copy-issues.md)
- [Investigate contributing events](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/investigate-contributing-events.md)
- [Export issue details to a file](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/export-issue-details-to-a-file.md)
- [Exclude an issue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/exclude-an-issue.md)
- [Query case and issue data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md)
- [Run indicator extraction in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/run-indicator-extraction-in-the-cli.md)
- [Update issue fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/update-issue-fields.md)
- [Close an issue](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/issue-investigation-actions/close-an-issue.md)
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets.md): You can investigate specific artifacts and assets on dedicated views related to IP address, Network Assets, and File and Process Hash information.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-an-ip-address.md): Investigate cases, connections, and threat intelligence reports related to a specific IP address on the IP View.
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md): Investigate cases, actions, and threat intelligence reports related to a specific file or process hash on the Hash View.
- [Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat.md): Chat with the Cortex Agentic Assistant using natural language prompts.
- [Get started with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat/get-started-with-agentic-assistant-chat.md): Enable Agentic Assistant and access the chat interface.
- [Choose an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat/choose-an-agentic-assistant-agent.md): Choose a system or custom agent for your chat.
- [Chat with an Agentic Assistant agent](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-an-agentic-assistant-agent.md): Tips for chatting with the Cortex Agentic Assistant
- [Chat with the Agentic Assistant from Slack](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat/chat-with-the-agentic-assistant-from-slack.md): Enable chatting with an Agentic Assistant agent from Slack.
- [Create and run XQL queries with Agentic Assistant chat](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat/create-and-run-xql-queries-with-agentic-assistant-chat.md): Interact with Cortex Agentic Assistant agents to build and run XQL queries.
- [Use natural language to query and visualize your data](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat/use-natural-language-to-query-and-visualize-your-data.md): Prompt Cortex Agentic Assistant agents to create graphs and charts from its findings.
- [Manage chat history](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/agentic-assistant-chat/manage-chat-history.md): Manage and navigate your past chats with the Cortex Agentic Assistant.
- [Extended Threat Intelligence](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence.md): Research threats, investigate indicators, and apply intelligence across Cortex AgentiX workflows.
- [XTI Threat Intel Library](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence/xti-threat-intel-library.md): Research curated threat actors, malware families, vulnerabilities, and reports from Unit 42.
- [XTI Indicators](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence/xti-indicators.md): Investigate, manage, and enrich threat indicators, including domains, IP addresses, URLs, and file hashes.
- [Threat intel context in cases and issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md): Analyze indicator intelligence and Behavioral Threat Analysis (BTA) findings in cases and issues.
- [Threat intel investigation through XQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence/threat-intel-investigation-through-xql.md): Query XTI indicators, threat objects, and their relationships using Cortex Query Language.
- [Threat Intel Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence/threat-intel-dashboard.md): Visualize threat intelligence data to monitor distribution, ingestion health, and emerging trends.
- [Using XTI with Threat Intel Agent](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence/using-xti-with-threat-intel-agent.md): Use the Threat Intel Agent to list, enrich, and update XTI indicators.
- [Using XTI in playbooks](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/extended-threat-intelligence/using-xti-in-playbooks.md): Automate XTI indicator triage, enrichment, and response with supported playbook commands.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management.md): Manage, configure, and investigate threat indicators to enrich security operations.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigations
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md): Understand indicator ingestion, enrichment, merging, expiration, and exclusions.
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with issues and are an essential part of the case management and remediation process.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types and fields, customize the exclusion list, indicator reputation, and indicator extraction.
- [Customize indicator fields and types](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types.md): Customize your indicators to your specific needs. Edit existing indicator types and fields, add scripts, and configure tailored extraction and expiration settings for optimal insights.
- [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type.md): Create custom indicator types and define their profiles, fields, and enrichment behavior.
- [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/indicator-type-profile.md): Configure indicator type profiles, including scripts, commands, expiration, and cache settings.
- [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/file-indicators.md): Understand file indicator properties, hash handling, and automatic indicator merging.
- [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/formatting-scripts.md): Format and validate extracted indicator values with formatting scripts.
- [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/enhancement-scripts.md): Use enhancement scripts to manually enrich indicators and investigate additional context.
- [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/reputation-scripts.md): Use reputation scripts to calculate indicator verdicts with custom logic.
- [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/reputation-commands.md): Use reputation commands to retrieve indicator verdicts from supported integrations.
- [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-type/map-custom-indicator-fields.md): Map enrichment context data to custom indicator fields automatically.
- [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field.md): Create custom indicator fields and assign them to one or more indicator types.
- [Indicator field structure](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field/indicator-field-structure.md): Reference the STIX 2.1-based structure and fields for supported indicator types.
- [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-fields-and-types/create-an-indicator-field/indicator-field-trigger-scripts.md): Configure scripts that run when an indicator field value changes.
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Indicator extraction extracts indicators from Cortex AgentiX issue fields and enriches them with commands and scripts.
- [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md): Choose how a playbook task extracts indicators from its inputs and outputs.
- [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md): Disable automatic indicator extraction for selected scripts or integrations.
- [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex AgentiX indicators have an active or expired status, which can be set to expire after a specific period or never to expire. Set default expiration method.
- [Configure Threat Intelligence feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-feed-integrations.md): Set up feed integrations to ingest threat indicators from external sources.
- [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
- [Generate issues from indicator rules](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/generate-issues-from-indicator-rules.md): Create issues from indicator rules in Cortex AgentiX.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
- [Manage external dynamic lists](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/manage-external-dynamic-lists.md): Configure and manage your external dynamic lists in Cortex AgentiX.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex AgentiX Indicators page.
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, investigating an indicator and creating indicator relationships.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex AgentiX analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex AgentiX.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex AgentiX and how it benefits an investigation.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex AgentiX.
- [Cortex AgentiX XQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql.md)
- [Get started with XQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql.md): XQL is the Palo Alto Networks Cortex Query Language used in Cortex AgentiX.
- [XQL language features](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/xql-language-features.md): Learn more about the Cortex Query Language features to query for raw network and endpoint data.
- [XQL Language Structure](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/xql-language-structure.md): Learn more about the Cortex Query Language structure when creating a query.
- [Adding comments in queries](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/xql-language-structure/adding-comments-in-queries.md)
- [Supported operators](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/supported-operators.md): Cortex Query Language supports specific comparison, boolean, and set operators in Cortex AgentiX.
- [Datasets and presets](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/datasets-and-presets.md): The Cortex Query Language supports built-in datasets, custom datasets, and presets.
- [About examples](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/about-examples.md): Learn more about the Cortex Query Language (XQL) examples provided.
- [JSON functions](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/json-functions.md): Learn more about how Cortex AgentiX treats JSON functions in the Cortex Query Language.
- [How to filter for empty values in the results table](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/how-to-filter-for-empty-values-in-the-results-table.md): Learn how to filter for empty values in the results table in Cortex Query Language.
- [Understanding string manipulation in XQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/understanding-string-manipulation-in-xql.md): Learn more about string manipulation in Cortex Query Language (XQL) using double and triple quotes.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, case expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md)
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md)
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md)
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md)
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/create-xql-query.md)
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md)
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md)
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/how-to-build-xql-queries/graph-query-results.md)
- [Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates.md): Use Query Builder templates to query your data sets without using the Cortex Query Language.
- [Get started with Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/get-started-with-query-builder-templates.md)
- [Considerations for using Query Builder templates](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/considerations-for-using-query-builder-templates.md)
- [Create a query from a template](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/create-a-query-from-a-template.md)
- [Run a free text query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/run-a-free-text-query.md)
- [Query Builder template examples](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/query-builder-templates/query-builder-template-examples.md)
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and run queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center.md)
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/overview-of-the-query-center/edit-and-run-queries-in-query-center/query-center-reference-information.md)
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md)
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-your-personal-query-library.md): Cortex AgentiX provides as part of the Query Library a personal library for saving and managing your own queries.
- [XQL macros](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/xql-macros.md)
- [Manage your macros](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/manage-your-macros.md)
- [Legacy Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder.md): Learn more about the entities in the Legacy Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-authentication-query.md)
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-event-log-query.md)
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-file-query.md)
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-image-load-query.md)
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-network-connections-query.md)
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-network-query.md)
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-process-query.md)
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/create-registry-query.md)
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/build-xql-queries/legacy-query-builder/query-across-all-entities.md)
- [Cortex XQL syntax, parameters, and examples](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/cortex-agentix-xql/cortex-xql-syntax-parameters-and-examples.md): Comprehensive syntax rules and structural requirements for XQL queries
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/troubleshoot.md): Learn how to troubleshoot Cortex AgentiX, such as sending audit notifications to a Syslog Server.
- [About health issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/troubleshoot/about-health-issues.md): Cortex AgentiX provides health issues to help you monitor the health and integrity of supported Cortex AgentiX resources. Health issues comprise ingestion, collection, correlation, and event forwardin
- [Monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/troubleshoot/about-health-issues/monitor-data-ingestion-health.md): Learn more about data ingestion health monitoring.
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/troubleshoot/about-health-issues/monitor-correlation-rules.md): You can monitor your correlation executions with the correlations\_auditing dataset.
- [Investigate and resolve health issues](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/troubleshoot/about-health-issues/investigate-and-resolve-health-issues.md): You can investigate and take action on health issues from the Health Issues page and the Issues Table.
- [In-product support ticket creation](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/troubleshoot/in-product-support-case-creation.md): Open a support ticket directly in Cortex AgentiX and record your console to capture your issues and have the ticket handled efficiently.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/reference.md)
- [Cortex AgentiX API](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/reference/cortex-agentix-api.md): Generate an API key and make your first API call.
- [Fair Usage policy for Cortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix/reference-and-developer-docs/reference/fair-usage-policy-for-cortex-agentix.md)

## Cortex XDR Agent Documentation

- [Cortex XDR Agent Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/cortex-xdr-agent-documentation.md): Start here to choose the right Cortex XDR Agent version.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Cortex XDR agent for Windows requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
* [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md)
* [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
* [MacOS Bluetooth MDM profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-bluetooth-mdm-profile.md)
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
* [Cortex XDR supported Kernel Module versions by distribution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/cortex-xdr-supported-kernel-module-versions-by-distribution.md): To enable full endpoint protection features on Linux endpoints, you must use a supported Linux Kernel version.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
* [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

- [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/introduction.md)
- [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent 9.2 on Windows endpoints, see the references in this topic.
- [Cortex XDR agent for Windows requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
- [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
- [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
- [MacOS Bluetooth MDM profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-bluetooth-mdm-profile.md)
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
- [Cortex XDR supported Kernel Module versions by distribution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/cortex-xdr-supported-kernel-module-versions-by-distribution.md): To enable full endpoint protection features on Linux endpoints, you must use a supported Linux Kernel version.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
- [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
- [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Cortex XDR agent for Windows requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
* [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
* [MacOS Bluetooth MDM profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-bluetooth-mdm-profile.md)
* [DLP MDM profile for macOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/dlp-mdm-profile-for-macos.md)
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
* [Cortex XDR supported Kernel Module versions by distribution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/cortex-xdr-supported-kernel-module-versions-by-distribution.md): To enable full endpoint protection features on Linux endpoints, you must use a supported Linux Kernel version.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
* [Install the Cortex XDR agent on AWS ECS EC2 Clusters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-on-aws-ecs-ec2-clusters.md): Learn how to install the Cortex XDR agent on AWS ECS EC2 clusters
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
* [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

- [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/introduction.md): Learn about the Cortex XDR Agent installation procedures.
- [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
- [Cortex XDR agent for Windows requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
- [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
- [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
- [MacOS Bluetooth MDM profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-bluetooth-mdm-profile.md)
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
- [Cortex XDR supported Kernel Module versions by distribution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/cortex-xdr-supported-kernel-module-versions-by-distribution.md): To enable full endpoint protection features on Linux endpoints, you must use a supported Linux Kernel version.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
- [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
- [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Cortex XDR agent for Windows requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
* [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
* [MacOS Bluetooth MDM profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-bluetooth-mdm-profile.md)
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
* [Cortex XDR supported Kernel Module versions by distribution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/cortex-xdr-supported-kernel-module-versions-by-distribution.md): To enable full endpoint protection features on Linux endpoints, you must use a supported Linux Kernel version.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
* [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

- [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/introduction.md): Learn about the Cortex XDR Agent installation procedures.
- [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
- [Cortex XDR agent for Windows requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
- [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
- [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
- [MacOS Bluetooth MDM profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-bluetooth-mdm-profile.md)
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
- [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
- [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Cortex XDR agent for Windows requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
* [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 8.2
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
* [MacOS Bluetooth MDM profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-bluetooth-mdm-profile.md)
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
* [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.
* [Cortex XDR Agent and Content upgrades](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7/cortex-xdr-agent-and-content-upgrades.md): Palo Alto Networks deployment recommendations for Cortex XDR agents.

- [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/introduction.md): Learn about the Agent installation procedures.
- [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
- [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
- [Install the Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
- [Cortex XDR agent for virtual environments and desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 8.2
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
- [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
- [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): How to install the Cortex XDR agent on a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
- [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.
- [Cortex XDR Agent and Content upgrades](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-and-content-upgrades.md): Palo Alto Networks deployment recommendations for Cortex XDR agents.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
* [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md)
* [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 8.2
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [macOS 15 Sequoia system extensions configuration file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/macos-15-sequoia-system-extensions-configuration-file.md)
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
* [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.
* [Cortex XDR Agent and Content upgrades](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.5-eol/cortex-xdr-agent-and-content-upgrades.md): Palo Alto Networks deployment recommendations for Cortex XDR agents.

- [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/introduction.md): Learn about the Cortex XDR Agent installation procedures.
- [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
- [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
- [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 8.2
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
- [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
- [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
- [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.4-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR agent on unsupported-ACS OS versions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-on-unsupported-acs-os-versions.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
* [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 8.2
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
* [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.3-ce/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

- [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/introduction.md): Learn about the Cortex XDR Agent installation procedures.
- [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
- [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent on Windows endpoints using the latest content and installer package.
- [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 8.2
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
- [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
- [Install the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.
- [Cytool for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.2-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md): Cytool is a command-line tool integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
* [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent 8.2 on Windows endpoints using the latest content and installer package.
* [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 7.9
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-linux.md): To install, use, and uninstall the Cortex XDR agent on Linux endpoints, see the references in this topic.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.1-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.

- [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/introduction.md): Learn about the Cortex XDR Agent installation procedures.
- [Cortex XDR agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent on Windows endpoints, see the references in this topic.
- [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent 8.2 on Windows endpoints using the latest content and installer package.
- [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent for MacOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos.md): To install, use, and uninstall the Cortex XDR agent on MacOS endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 7.9
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
- [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-for-macos/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent 8.0 for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-8.0-for-linux.md): To install, use, and uninstall the Cortex XDR agent 8.0 on Linux endpoints, see the references in this topic.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-8.0-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
- [Install the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-8.0-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-8.0-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-8.0-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-8.0-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.0-eol/cortex-xdr-agent-8.0-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.

* [Introduction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/introduction.md): Learn about the Cortex XDR Agent installation procedures.
* [Cortex XDR Agent 7.9 for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent 7.9 on Windows endpoints, see the references in this topic.
* [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR agent on unsupported-ACS OS versions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/install-the-cortex-xdr-agent-on-unsupported-acs-os-versions.md): To install, use, upgrade, and uninstall the Cortex XDR agent 7.9 on Windows endpoints, see the references in this topic.
* [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent 8.2 on Windows endpoints using the latest content and installer package.
* [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent 7.9 for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac.md): To install, use, and uninstall the Cortex XDR agent 7.8 on Mac endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 7.9
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a unified configuration profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/install-the-cortex-xdr-agent-for-mac/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-mac/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent 7.9 for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-linux.md): To install, use, and uninstall the Cortex XDR agent 7.9 on Linux endpoints, see the references in this topic.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.9-ce/cortex-xdr-agent-7.9-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.

- [Cortex XDR Agent version 7.5CE](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.5ce-eol/cortex-xdr-agent-version-7.5ce.md)

* [Cortex XDR Agent 7.8 for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent 7.8 on Windows endpoints, see the references in this topic.
* [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
* [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on Windows endpoints.
* [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent 8.2 on Windows endpoints using the latest content and installer package.
* [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
* [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
* [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
* [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
* [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
* [Cortex XDR Agent 7.8 for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac.md): To install, use, and uninstall the Cortex XDR agent 7.8 on Mac endpoints, see the references in this topic.
* [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 7.8
* [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent on macOS endpoints.
* [Install with a Unified Configuration Profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
* [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
* [Configure Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/install-the-cortex-xdr-agent-for-mac/configure-cortex-xdr-agent-for-mac.md): Run the wizard to guide you through the settings to enable the agent to run on the macOS endpoint.
* [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
* [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
* [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-mac/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
* [Cortex XDR Agent 7.8 for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-linux.md): To install, use, and uninstall the Cortex XDR agent 7.8 on Linux endpoints, see the references in this topic.
* [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent
* [Install the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
* [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
* [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
* [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
* [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.

- [Cortex XDR Agent 7.7 for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows.md): To install, use, upgrade, and uninstall the Cortex XDR agent 7.7 on Windows endpoints, see the references in this topic.
- [Cortex XDR Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/cortex-xdr-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Cortex XDR agent.
- [Install the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/install-the-cortex-xdr-agent-for-windows.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent 7.7 on Windows endpoints.
- [Install the Cortex XDR Agent with Installer and Content Update Package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/install-the-cortex-xdr-agent-with-installer-and-content-update-package.md): Deploy the Cortex XDR agent 7.7 on Windows endpoints using the latest content and installer package.
- [Cortex XDR Agent for Virtual Environments and Desktops](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/cortex-xdr-agent-for-virtual-environments-and-desktops.md): Learn about the Cortex XDR agent virtual installation options and use the provided workflows to install the Cortex XDR agent on virtual Windows endpoints.
- [Use Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/use-cortex-xdr-agent-for-windows.md): Learn how to effectively use the Cortex XDR agent for Windows by the different options described in this topic.
- [Upgrade the Cortex XDR Agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/upgrade-the-cortex-xdr-agent.md): How to upgrade the Cortex XDR agent on Windows endpoints.
- [Uninstall the Cortex XDR Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/uninstall-the-cortex-xdr-agent-for-windows.md): Learn how to uninstall the Cortex XDR agent from a Windows endpoint.
- [Troubleshooting Resources for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/troubleshooting-resources-for-windows.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Windows.
- [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
- [Cortex XDR Agents Deployed in Advertise Mode](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-windows/troubleshooting-resources-for-windows/cortex-xdr-agents-deployed-in-advertise-mode.md): Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
- [Cortex XDR Agent 7.7 for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac.md): To install, use, and uninstall the Cortex XDR agent 7.7 on Mac endpoints, see the references in this topic.
- [Cortex XDR Agent for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/cortex-xdr-agent-for-mac-requirements.md): Mac (macOS) endpoints must meet the following requirements to install the Cortex XDR agent 7.7
- [Install the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/install-the-cortex-xdr-agent-for-mac.md): Learn about the Cortex XDR agent installation options and use the provided workflows to install the Cortex XDR agent 7.7 on macOS endpoints.
- [Install with a Unified Configuration Profile for MDMs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md): Use the Palo Alto Networks unified configuration profile for MDMs to seamlessly install the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Using JAMF](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md): Step-by-step instructions to configure a JAMF installation profile for the Cortex XDR agent on macOS endpoints.
- [Install the Cortex XDR Agent Manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-manually.md): Learn how to install the Cortex XDR agent manually on macOS endpoints.
- [Use the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/use-the-cortex-xdr-agent-for-mac.md): Learn how to effectively use the Cortex XDR agent for Mac by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/uninstall-the-cortex-xdr-agent-for-mac.md): Learn how to uninstall the Cortex XDR agent from a Mac endpoint.
- [Manage the Agent Deployment Notifications for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/manage-the-agent-deployment-notifications-for-mac.md): An overview of user notifications for the Cortex XDR agent during installation, upgrade, and removal on a Mac.
- [Troubleshooting Resources for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/troubleshooting-resources-for-mac.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Mac.
- [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-mac/troubleshooting-resources-for-mac/cytool-for-mac.md): In addition to being available for Windows and Linux endpoints, Cytool is also available for Mac endpoints.
- [Cortex XDR Agent 7.7 for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-linux.md): To install, use, and uninstall the Cortex XDR agent 7.7 on Linux endpoints, see the references in this topic.
- [Cortex XDR Agent for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-linux/cortex-xdr-agent-for-linux-requirements.md): Linux endpoints must meet the following requirements to install the Cortex XDR agent 7.8.
- [Install the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-linux/install-the-cortex-xdr-agent-for-linux.md): Learn how to install the Cortex XDR agent on a Linux endpoint.
- [Install the Cortex XDR Agent for Kubernetes Hosts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-linux/install-the-cortex-xdr-agent-for-kubernetes-hosts.md): Learn how to install the Cortex XDR agent for a Kubernetes host.
- [Use the Cortex XDR agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-linux/use-the-cortex-xdr-agent-for-linux.md): Learn how to effectively use the Cortex XDR agent for Linux by the different options described in this topic.
- [Uninstall the Cortex XDR Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-linux/uninstall-the-cortex-xdr-agent-for-linux.md): Learn how to uninstall the Cortex XDR agent from a Linux endpoint.
- [Troubleshooting Resources for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.7-eol/cortex-xdr-agent-7.7-for-linux/troubleshooting-resources-for-linux.md): Refer to the following troubleshooting resources for the Cortex XDR agent for Linux.

* [Cortex XDR Agent version 7.6](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.6-eol/cortex-xdr-agent-version-7.6.md)

- [Cortex XDR Agent version 7.5](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.5-eol/cortex-xdr-agent-version-7.5.md)

* [Cortex XDR Agent version 7.4](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.4-eol/cortex-xdr-agent-version-7.4.md)

- [Cortex XDR Agent version 7.3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.3-eol/cortex-xdr-agent-version-7.3.md)

* [Cortex XDR Agent version 7.2](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.2-eol/cortex-xdr-agent-version-7.2.md)

- [Cortex XDR Agent version 7.1](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.1-eol/cortex-xdr-agent-version-7.1.md)

* [Cortex XDR Agent version 7.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.0-eol/cortex-xdr-agent-version-7.0.md)

- [Cortex XDR Agent version 6.1](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/6.1-eol/cortex-xdr-agent-version-6.1.md)

* [Traps Agent 5.0 for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-windows.md): To uninstall, use, and upgrade the Traps agent 5.0 on Windows endpoints, follow the instructions in this section.
* [Traps Agent for Windows Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-windows/traps-agent-for-windows-requirements.md): Windows endpoints must meet the following requirements to install the Traps agent 5.0.
* [Install Traps Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-windows/install-traps-agent-for-windows.md): Use the following workflows to install the Traps agent 5.0 on Windows endpoints. This topic provides options to use the MSI, Msiexec, and how to configure on a non-persistent VDI.
* [Use Traps Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-windows/use-traps-agent-for-windows.md): Use the Traps console to view the agent status, initiate a connection to the server, view and send logs, view security events that occurred on the endpoint, and change the display language of the Trap
* [Uninstall Traps Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-windows/uninstall-traps-agent-for-windows.md): Use this workflow to uninstall Traps agent 5.0 on a Windows endpoint.
* [Troubleshooting Resources for Traps Agent for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-windows/troubleshooting-resources-for-traps-agent-for-windows.md): Use the resources in this topic to troubleshoot the Traps agent 5.0 on Windows endpoints.
* [Cytool for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-windows/troubleshooting-resources-for-traps-agent-for-windows/cytool-for-windows.md): To manage Traps functions from the command line on Windows endpoints, use Cytool.
* [Traps Agent 5.0 for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-mac.md): To uninstall, use, and upgrade the Traps agent 5.0 on Mac endpoints, follow the instructions in this section.
* [Traps for Mac Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-mac/traps-for-mac-requirements.md): Refer to requirements for Traps agent for Mac.
* [Install the Traps Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-mac/install-the-traps-agent-for-mac.md): Perform steps to install the traps agent for Mac.
* [Use the Traps Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-mac/use-the-traps-agent-for-mac.md)
* [Uninstall the Traps Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-mac/uninstall-the-traps-agent-for-mac.md)
* [Troubleshooting Resources for the Traps Agent for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-mac/troubleshooting-resources-for-the-traps-agent-for-mac.md)
* [Cytool for Mac](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-mac/troubleshooting-resources-for-the-traps-agent-for-mac/cytool-for-mac.md)
* [Traps Agent 5.0 for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-linux.md)
* [Traps for Linux Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-linux/traps-for-linux-requirements.md)
* [Traps for Linux Limitations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-linux/traps-for-linux-requirements/traps-for-linux-limitations.md)
* [Install the Traps Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-linux/install-the-traps-agent-for-linux.md)
* [Use the Traps Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-linux/use-the-traps-agent-for-linux.md)
* [Uninstall the Traps Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-linux/uninstall-the-traps-agent-for-linux.md)
* [Troubleshooting Resources for the Traps Agent for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-agent-5.0-for-linux/troubleshooting-resources-for-the-traps-agent-for-linux.md)
* [Traps App 5.0 for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-app-5.0-for-android.md)
* [Traps for Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-app-5.0-for-android/traps-for-android-requirements.md)
* [Install Traps App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-app-5.0-for-android/install-traps-app-for-android.md): Use this workflow to install Traps 5.0 for Android.
* [Use Traps for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-app-5.0-for-android/use-traps-for-android.md)
* [Troubleshoot Traps for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/5.0/traps-app-5.0-for-android/troubleshoot-traps-for-android.md)

## Cortex XDR Agent iOS Guides

- [Cortex XDR Agent iOS Guides](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/cortex-xdr-agent-ios-guides.md)

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/get-started.md): Learn more about the Cortex XDR Agent app for iOS.
* [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
* [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks.md)
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
* [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
* [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Configure Network Filtering on Supervised Devices (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task/configure-network-filtering-on-supervised-devices-administrator-task.md)
* [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md)
* [Install the Cortex XDR agent app on iOS using Microsoft Intune](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/administrator-tasks/prepare-for-installation-administrator-task/install-the-cortex-xdr-agent-app-on-ios-using-microsoft-intune.md)
* [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks.md)
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Check Links before Clicking or Using Them](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/check-links-before-clicking-or-using-them.md): Check that links aren't malicious before clicking or using them.
* [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

- [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
- [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
- [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
- [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
- [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
- [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
- [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
- [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
- [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
- [Configure Network Filtering on Supervised Devices (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task/configure-network-filtering-on-supervised-devices-administrator-task.md)
- [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md)
- [Install the Cortex XDR agent app on iOS using Microsoft Intune](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/install-the-cortex-xdr-agent-app-on-ios-using-microsoft-intune.md)
- [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
- [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
- [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
- [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
- [Check Links before Clicking or Using Them](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/check-links-before-clicking-or-using-them.md): Check that links aren't malicious before clicking or using them.
- [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
- [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
- [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
- [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
- [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/view-device-and-app-status-and-information.md)
- [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
- [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
- [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
- [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
* [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
* [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
* [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
* [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Install the Cortex XDR agent app on iOS using Microsoft Intune](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks/prepare-for-installation-administrator-task/install-the-cortex-xdr-agent-app-on-ios-using-microsoft-intune.md)
* [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Check Links before Clicking or Using Them](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/check-links-before-clicking-or-using-them.md): Check that links aren't malicious before clicking or using them.
* [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

- [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
- [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
- [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
- [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
- [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
- [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
- [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
- [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
- [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
- [Install the Cortex XDR agent app on iOS using Microsoft Intune](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/administrator-tasks/prepare-for-installation-administrator-task/install-the-cortex-xdr-agent-app-on-ios-using-microsoft-intune.md)
- [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
- [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
- [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
- [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
- [Check Links before Clicking or Using Them](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/check-links-before-clicking-or-using-them.md): Check that links aren't malicious before clicking or using them.
- [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
- [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
- [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
- [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
- [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/view-device-and-app-status-and-information.md)
- [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
- [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
- [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
- [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
* [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
* [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
* [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
* [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Check Links before Clicking or Using Them](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/check-links-before-clicking-or-using-them.md): Check that links aren't malicious before clicking or using them.
* [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

- [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
- [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
- [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
- [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
- [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
- [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
- [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
- [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
- [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
- [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
- [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
- [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
- [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
- [Check Links before Clicking or Using Them](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/check-links-before-clicking-or-using-them.md): Check that links aren't malicious before clicking or using them.
- [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
- [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
- [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
- [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
- [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/view-device-and-app-status-and-information.md)
- [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
- [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
- [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
- [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
* [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
* [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
* [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
* [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

- [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
- [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
- [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
- [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
- [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
- [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
- [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
- [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
- [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
- [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
- [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
- [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
- [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
- [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
- [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
- [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
- [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
- [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/view-device-and-app-status-and-information.md)
- [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
- [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
- [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
- [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
* [Cortex XDR Agent App for iOS Overview](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/get-started/cortex-xdr-agent-app-for-ios-overview.md): Learn about deploying and configuring the Cortex XDR agent app for iOS on iOS-based endpoints.
* [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
* [Add a Malware Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md): From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
* [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

- [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
- [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
- [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
- [Administrator Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/administrator-tasks.md): The tasks in this section are performed by the Cortex XDR or Cortex XSIAM administrator.
- [Add a Malware Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/administrator-tasks/add-a-malware-security-profile-administrator-task.md): From the Cortex XDR or Cortex XSIAM tenant, administrators can configure what action Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers.
- [Add an Agent Settings Prevention Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/administrator-tasks/add-an-agent-settings-prevention-profile-administrator-task.md): You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.
- [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/administrator-tasks/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
- [Configure Network Filtering on Supervised Devices (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/administrator-tasks/configuration-for-installation-by-mdm-administrator-task/configure-network-filtering-on-supervised-devices-administrator-task.md): When your organization manages iOS devices, the administrator can set up the Network Shield feature to block network activity for specific URLs.
- [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/administrator-tasks/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md): Instructions to configure Cortex XDR iOS app by JAMF MDM.
- [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/administrator-tasks/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required to prepare for installation of the Cortex XDR Agent app for iOS.
- [Device User Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks.md): The tasks in this section are performed by the iOS device user.
- [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
- [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
- [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
- [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
- [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
- [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
- [View and Modify Use of Security Modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/view-and-modify-use-of-security-modules.md): View and modify the use of security modules used by your device's Cortex XDR app.
- [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/view-device-and-app-status-and-information.md)
- [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
- [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
- [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
- [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4/device-user-tasks/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
* [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Install and Connect Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/install-and-connect-cortex-xdr-agent-app-for-ios.md)
* [Add a Malware Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/install-and-connect-cortex-xdr-agent-app-for-ios/add-a-malware-security-profile-administrator-task.md): From the Cortex XDR management console, administrators can configure what action Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers.
* [Add an Agent Settings Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/install-and-connect-cortex-xdr-agent-app-for-ios/add-an-agent-settings-security-profile-administrator-task.md): Agent Settings profiles enable you to customize Cortex XDR agent settings for different platforms and groups of users.
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/install-and-connect-cortex-xdr-agent-app-for-ios/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required prior to installation of the Cortex XDR Agent app for iOS.
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/install-and-connect-cortex-xdr-agent-app-for-ios/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md): Instructions to configure Cortex XDR iOS app by JAMF MDM.
* [Configure Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/configure-cortex-xdr-agent-app-for-ios.md)
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/configure-cortex-xdr-agent-app-for-ios/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/configure-cortex-xdr-agent-app-for-ios/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Configure Network Filtering on Supervised Devices (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/configure-cortex-xdr-agent-app-for-ios/configure-network-filtering-on-supervised-devices-administrator-task.md): When your organization supervises iOS devices, the administrator can set up network filtering to block network activity for specific URLs.
* [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/configure-cortex-xdr-agent-app-for-ios/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
* [Manage Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/manage-security-events.md)
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/manage-security-events/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/manage-security-events/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

- [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
- [Release Notes for Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/get-started/release-notes-for-cortex-xdr-agent-app-for-ios.md)
- [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
- [Install and Connect Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/install-and-connect-cortex-xdr-agent-app-for-ios.md)
- [Add a Malware Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/install-and-connect-cortex-xdr-agent-app-for-ios/add-a-malware-security-profile-administrator-task.md): From the Cortex XDR management console, administrators can configure what action Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers.
- [Add an Agent Settings Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/install-and-connect-cortex-xdr-agent-app-for-ios/add-an-agent-settings-security-profile-administrator-task.md): Agent Settings profiles enable you to customize Cortex XDR agent settings for different platforms and groups of users.
- [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/install-and-connect-cortex-xdr-agent-app-for-ios/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required prior to installation of the Cortex XDR Agent app for iOS.
- [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/install-and-connect-cortex-xdr-agent-app-for-ios/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
- [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
- [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md): Instructions to configure Cortex XDR iOS app by JAMF MDM.
- [Configure Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/configure-cortex-xdr-agent-app-for-ios.md)
- [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/configure-cortex-xdr-agent-app-for-ios/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
- [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/configure-cortex-xdr-agent-app-for-ios/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
- [Configure Network Filtering on Supervised Devices (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/configure-cortex-xdr-agent-app-for-ios/configure-network-filtering-on-supervised-devices-administrator-task.md): When your organization supervises iOS devices, the administrator can set up network filtering to block network activity for specific URLs.
- [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/configure-cortex-xdr-agent-app-for-ios/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
- [Manage Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/manage-security-events.md)
- [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/manage-security-events/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
- [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/manage-security-events/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
- [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/view-device-and-app-status-and-information.md)
- [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
- [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
- [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
- [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/get-started/release-notes.md): Learn about new features added to Cortex XDR agent app for iOS.
* [Install and Connect Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/install-and-connect-cortex-xdr-agent-app-for-ios.md)
* [Add a Malware Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/install-and-connect-cortex-xdr-agent-app-for-ios/add-a-malware-security-profile-administrator-task.md): From the Cortex XDR management console, administrators can configure what action Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers.
* [Add an Agent Settings Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/install-and-connect-cortex-xdr-agent-app-for-ios/add-an-agent-settings-security-profile-administrator-task.md): Agent Settings profiles enable you to customize Cortex XDR agent settings for different platforms and groups of users.
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/install-and-connect-cortex-xdr-agent-app-for-ios/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required prior to installation of the Cortex XDR Agent app for iOS.
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/install-and-connect-cortex-xdr-agent-app-for-ios/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md): Instructions to configure Cortex XDR iOS app by JAMF MDM.
* [Configure Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/configure-cortex-xdr-agent-app-for-ios.md)
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/configure-cortex-xdr-agent-app-for-ios/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/configure-cortex-xdr-agent-app-for-ios/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/configure-cortex-xdr-agent-app-for-ios/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
* [Manage Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/manage-security-events.md)
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/manage-security-events/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/manage-security-events/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

- [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
- [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
- [Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/get-started/release-notes.md): Learn about new features added to Cortex XDR agent app for iOS.
- [Install and Connect Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/install-and-connect-cortex-xdr-agent-app-for-ios.md)
- [Add a Malware Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/install-and-connect-cortex-xdr-agent-app-for-ios/add-a-malware-security-profile-administrator-task.md): From the Cortex XDR management console, administrators can configure what action Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers.
- [Add an Agent Settings Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/install-and-connect-cortex-xdr-agent-app-for-ios/add-an-agent-settings-security-profile-administrator-task.md)
- [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/install-and-connect-cortex-xdr-agent-app-for-ios/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required prior to installation of the Cortex XDR Agent app for iOS.
- [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/install-and-connect-cortex-xdr-agent-app-for-ios/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
- [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
- [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md): Instructions to configure Cortex XDR iOS app by JAMF MDM.
- [Configure Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/configure-cortex-xdr-agent-app-for-ios.md)
- [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/configure-cortex-xdr-agent-app-for-ios/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
- [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/configure-cortex-xdr-agent-app-for-ios/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
- [Report Spam Messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/configure-cortex-xdr-agent-app-for-ios/report-spam-messages.md): Learn how to enable your device to report spam messages from unknown senders.
- [Manage Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/manage-security-events.md)
- [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/manage-security-events/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
- [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/manage-security-events/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
- [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/view-device-and-app-status-and-information.md)
- [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
- [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
- [Using the Cortex XDR iOS Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/view-device-and-app-status-and-information/using-the-cortex-xdr-ios-widgets.md): Learn how to use the Cortex XDR widgets on your iOS device.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
- [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0/cortex-xdr-agent-ios-app/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

* [Get Started](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/get-started.md): Learn more about the Cortex XDR Agent app for iOS. The Cortex XDR Agent app enforces your organization’s security policy on iOS-based endpoints, as defined in Cortex XDR or Cortex XSIAM.
* [Cortex XDR Agent App for iOS Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/get-started/cortex-xdr-agent-app-for-ios-requirements.md): Learn about requirements for the Cortex XDR Agent app for iOS.
* [Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/get-started/release-notes.md): Learn about new features added to Cortex XDR agent app for iOS.
* [Install and Connect Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/install-and-connect-cortex-xdr-agent-app-for-ios.md)
* [Add a Malware Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/install-and-connect-cortex-xdr-agent-app-for-ios/add-a-malware-security-profile-administrator-task.md): From the Cortex XDR management console, administrators can configure what action Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers.
* [Add an Agent Settings Security Profile (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/install-and-connect-cortex-xdr-agent-app-for-ios/add-an-agent-settings-security-profile-administrator-task.md): Agent Settings profiles enable you to customize Cortex XDR agent settings for different platforms and groups of users.
* [Prepare for Installation (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/install-and-connect-cortex-xdr-agent-app-for-ios/prepare-for-installation-administrator-task.md): Learn about the Administrator’s tasks required prior to installation of the Cortex XDR Agent app for iOS.
* [Install Cortex XDR Agent iOS App on the iOS Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/install-and-connect-cortex-xdr-agent-app-for-ios/install-cortex-xdr-agent-ios-app-on-the-ios-device.md): Use this workflow to install Cortex XDR Agent for iOS on your device.
* [Configuration for Installation by MDM (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/configuration-for-installation-by-mdm-administrator-task.md): Instructions to configure the Cortex XDR iOS app by MDM.
* [Configuration for Installation by JAMF (Administrator Task)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/configuration-for-installation-by-mdm-administrator-task/configuration-for-installation-by-jamf-administrator-task.md): Instructions to configure Cortex XDR iOS app by JAMF MDM.
* [Configure Cortex XDR Agent App for iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/configure-cortex-xdr-agent-app-for-ios.md)
* [Configure Phone Call Blocking](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/configure-cortex-xdr-agent-app-for-ios/configure-phone-call-blocking.md): Learn how to configure phone call blocking on iPhones, using the Cortex XDR agent app for iOS.
* [Configure Message and Call Reporting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/configure-cortex-xdr-agent-app-for-ios/configure-message-and-call-reporting.md): Learn how to enable your iPhone to report spam messages.
* [Manage Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/manage-security-events.md)
* [Check Your Device](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/manage-security-events/check-your-device.md): Learn about checking Cortex XDR agent app activity on your iOS device.
* [View Security Events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/manage-security-events/view-security-events.md): Learn how to view the security events identified by the Cortex XDR Agent app installed on your iOS device.
* [View Device and App Status and Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/view-device-and-app-status-and-information.md)
* [View Device Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/view-device-and-app-status-and-information/view-device-information.md): Learn how to view Cortex XDR agent app for iOS device endpoint information.
* [View Connection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/view-device-and-app-status-and-information/view-connection.md): View general and connection information for your Cortex XDR agent app for iOS.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/troubleshooting.md): Learn about troubleshooting issues with the Cortex XDR Agent app for iOS.
* [Send Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9/troubleshooting/send-logs.md): Learn how to send logs from the Cortex XDR Agent app for iOS to Palo Alto Networks for analysis.

## Cortex XDR Agent Android Guides

- [Cortex XDR Agent Android Guides](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/cortex-xdr-agent-android-guides.md)

* [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/cortex-xdr-agent-app-for-android.md)
* [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/release-notes-for-cortex-xdr-app-for-android.md)
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/android-requirements.md)
* [Install the Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/install-the-agent-app-for-android.md)
* [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md)
* [Deploy Cortex XDR Agent App for Android with zero-touch installation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/deploy-cortex-xdr-agent-app-for-android-using-an-mdm/deploy-cortex-xdr-agent-app-for-android-with-zero-touch-installation.md)
* [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/use-the-cortex-xdr-agent-app-for-android.md)
* [Configure and View Settings for the Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/configure-and-view-settings-for-the-agent-app-for-android.md)
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/troubleshooting.md)

- [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/cortex-xdr-agent-app-for-android.md)
- [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/release-notes-for-cortex-xdr-app-for-android.md)
- [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/android-requirements.md)
- [Install the Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/install-the-agent-app-for-android.md)
- [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md)
- [Deploy Cortex XDR Agent App for Android with zero-touch installation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/deploy-cortex-xdr-agent-app-for-android-using-an-mdm/deploy-cortex-xdr-agent-app-for-android-with-zero-touch-installation.md)
- [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/use-the-cortex-xdr-agent-app-for-android.md)
- [Configure and View Settings for the Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/configure-and-view-settings-for-the-agent-app-for-android.md)
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/troubleshooting.md)

* [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
* [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
* [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
* [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
* [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
* [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

- [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
- [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
- [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
- [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
- [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
- [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

* [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
* [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
* [Features Introduced in Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/release-notes-for-cortex-xdr-app-for-android/features-introduced-in-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
* [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
* [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
* [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
* [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

- [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
- [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Features Introduced in Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/release-notes-for-cortex-xdr-app-for-android/features-introduced-in-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
- [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
- [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
- [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
- [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

* [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
* [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
* [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
* [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
* [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
* [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.7/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

- [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
- [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
- [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
- [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
- [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
- [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

* [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
* [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
* [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
* [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
* [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
* [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

- [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
- [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Features and Enhancements Introduced in Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/release-notes-for-cortex-xdr-app-for-android/features-and-enhancements-introduced-in-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
- [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
- [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
- [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
- [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

* [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
* [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
* [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
* [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
* [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
* [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

- [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
- [Release Notes for Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/release-notes-for-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Features and Enhancements Introduced in Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/release-notes-for-cortex-xdr-app-for-android/features-and-enhancements-introduced-in-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for this Android release.
- [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
- [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
- [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
- [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
- [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

* [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
* [Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/release-notes.md): Release notes for Cortex XDR agent app for Android releases.
* [Features Introduced in Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/release-notes/features-introduced-in-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for Android releases.
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
* [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
* [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE, to deploy Cortex XDR agent on your managed Android devices.
* [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/use-the-cortex-xdr-agent-app-for-android.md): Learn about using Cortex XDR agent app for Android after you have installed it.
* [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

- [Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/cortex-xdr-agent-app-for-android.md): Learn about the Cortex XDR agent app for Android-based endpoints.
- [Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/release-notes.md): Release notes for Cortex XDR agent app for Android releases.
- [Features Introduced in Cortex XDR App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/release-notes/features-introduced-in-cortex-xdr-app-for-android.md): Release notes for Cortex XDR agent app for Android releases.
- [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
- [Install the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/install-the-cortex-xdr-agent-app-for-android.md): Learn about the tasks required prior to and during installation of the Cortex XDR agent app for Android.
- [Deploy Cortex XDR Agent App for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/deploy-cortex-xdr-agent-app-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as Workspace ONE (formerly AirWatch), to deploy the Cortex XDR agent app to your managed Android devices.
- [Use the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/use-the-cortex-xdr-agent-app-for-android.md)
- [Configure and View Settings for the Cortex XDR Agent App for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/configure-and-view-settings-for-the-cortex-xdr-agent-app-for-android.md): Learn how to configure and view device settings.
- [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0/troubleshooting.md): Learn how to troubleshoot Cortex XDR agent app for Android.

* [Cortex XDR Agent App 7.1.3 for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3/cortex-xdr-agent-app-7.1.3-for-android.md)
* [Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3/release-notes.md): Release notes for Cortex XDR app 7.1 for Android releases.
* [Android Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3/android-requirements.md): Learn about requirements for installing Cortex XDR agent app for Android.
* [Install Cortex XDR Agent App 7.1 for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3/install-cortex-xdr-agent-app-7.1-for-android.md): Use this workflow to install Cortex XDR 7.1 for Android.
* [Deploy Cortex XDR Agent App 7.1 for Android Using an MDM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3/deploy-cortex-xdr-agent-app-7.1-for-android-using-an-mdm.md): For ease of deployment, you can use a mobile device management (MDM) system such as AirWatch, to deploy the Cortex XDR app to your managed Android devices.
* [Use the Cortex XDR Agent App 7.1 for Android](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3/use-the-cortex-xdr-agent-app-7.1-for-android.md)
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3/troubleshooting.md)

## Cortex XDR Agent OSS Listings

- [Cortex XDR OSS Listings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-oss-listings.md): Open-Source Software (OSS) licensing for Cortex XDR.
- [Cortex XDR Agent 9.3 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-9.2-oss-listing.md)
- [Cortex XDR Agent 9.2 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-9.2-oss-listing-1.md)
- [Cortex XDR Agent 9.1 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-9.1-oss-listing.md)
- [Cortex XDR Agent 9.0 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-9.0-oss-listing.md)
- [Cortex XDR Agent 8.9 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-8.9-oss-listing.md): Open-Source Software (OSS) licensing for the Cortex XDR agent 8.9 release.
- [Cortex XDR Agent 8.8 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-8.8-oss-listing.md): Open-Source Software (OSS) licensing for the Cortex XDR agent 8.8 release.
- [Cortex XDR Agent 8.7 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-8.7-oss-listing.md): Open-Source Software (OSS) licensing for the Cortex XDR agent 8.7 release.
- [Cortex XDR Agent 8.3 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-8.3-oss-listing.md): Open-Source Software (OSS) licensing for the Cortex XDR agent 8.3 release.
- [Cortex XDR Agent 7.9 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-7.9-oss-listing.md): Open-Source Software (OSS) licensing for the Cortex XDR agent 7.9 release.

## Cortex XSOAR 8 SaaS Documentation

- [Navigate the Cortex XSOAR 8 SaaS docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 8 SaaS documentation areas.
- [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/learn-about-cortex-xsoar.md): View information about how to get started with Cortex XSOAR SaaS, such as service limits, data retention policy, and licenses.
- [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR 8 SaaS features.
- [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/cortex-xsoar-architecture.md): Describes the Cortex XSOAR 8 SaaS architecture.
- [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR 8 SaaS.
- [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR 8 SaaS license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
- [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [Cortex XSOAR service limits](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/cortex-xsoar-service-limits.md): Describes the service limits for Cortex XSOAR 8 SaaS.
- [Data retention policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/data-retention-policy.md): Cortex XSOAR 8 SaaS retention policy and enforcement
- [Cortex service-level agreement](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/cortex-service-level-agreement.md): Describes the SLA agreement for all Cortex products including Cortex XSOAR 8 SaaS.
- [Supported ciphers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/supported-ciphers.md): Supported TLS 1.2 and TLS 1.3 cipher suites for Cortex XSOAR 8 SaaS.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/supported-web-browsers.md): Supported browser versions for Cortex XSOAR 8 SaaS and HTTP/2 performance requirements.
- [How to onboard XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR 8 SaaS.
- [Plan and prepare your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/plan-and-prepare-your-deployment.md): Before deploying your tenant, consider your use case and what you need to optimize your tenant for Cortex XSOAR 8 SaaS.
- [Deployment Steps](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps.md): Review the plan and prepare considerations, and then follow the steps in the onboarding checklist to successfully deploy and onboard Cortex XSOAR 8 SaaS.
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR 8 SaaS.
- [Step 1: Activate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar.md): Learn how to activate your Cortex XSOAR 8 SaaS tenant.
- [Supported host regions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/supported-host-regions.md): View Cortex XSOAR 8 SaaS host regions and data residency locations for stored data.
- [Enable access to Palo Alto Networks resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md): Enable network access to Cortex XSOAR 8 SaaS resources for your environment.
- [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR 8 SaaS engine on a remote machine.
- [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-3.-set-up-a-remote-repository.md): Set up Cortex XSOAR 8 SaaS content management for development and production environments.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-4.-set-up-users-and-roles.md): Set up Cortex XSOAR 8 SaaS roles, user groups, authentication, and users.
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content.md): Learn what content includes in Cortex XSOAR 8 SaaS.
- [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack in Cortex XSOAR 8 SaaS.
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): Use the Cortex XSOAR 8 SaaS Deployment Wizard to adopt your use case.
- [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/post-deployment.md): Configure optional Cortex XSOAR 8 SaaS communication and system settings after onboarding.
- [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/post-deployment/user-communication.md): Configure Cortex XSOAR 8 SaaS notifications and system emails.
- [Configure notifications in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/post-deployment/user-communication/configure-notifications-in-cortex-xsoar.md): Configure email and message notifications in Cortex XSOAR 8 SaaS.
- [Customize system emails](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/post-deployment/user-communication/customize-system-emails.md): Customize system email subjects and content in Cortex XSOAR 8 SaaS.
- [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/post-deployment/configure-system-settings.md): Configure Cortex XSOAR 8 SaaS security and server settings.
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/post-deployment/configure-system-settings/configure-security-settings.md): Configure Cortex XSOAR 8 SaaS session, access, and user security settings.
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/onboard-cortex-xsoar/post-deployment/configure-system-settings/configure-server-settings.md): Configure Cortex XSOAR 8 SaaS server settings and user preferences.
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot Cortex XSOAR 8 SaaS engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/what-is-an-engine.md): Learn how an engine connects Cortex XSOAR 8 SaaS to remote resources.
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/engine-requirements.md): Review hardware, operating system, and URL requirements for Cortex XSOAR 8 SaaS engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR 8 SaaS engines.
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker.md): Install, configure, secure, and troubleshoot Docker for Cortex XSOAR 8 SaaS engines.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md): Install Docker for a Cortex XSOAR 8 SaaS engine.
- [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker-distribution-for-red-hat-on-an-engine-server.md): Install Docker on a Red Hat Cortex XSOAR 8 SaaS engine server.
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/docker-image-security.md): Secure Docker images used by Cortex XSOAR 8 SaaS engines.
- [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/use-the-cortex-xsoar-container-registry.md): Use the Cortex XSOAR 8 SaaS Container Registry for engine images.
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/docker-faqs.md): Find Docker answers for Cortex XSOAR 8 SaaS engines.
- [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/troubleshoot-docker-issues.md): Troubleshoot Docker issues on Cortex XSOAR 8 SaaS engines.
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md): Configure Docker pull rate limits for Cortex XSOAR 8 SaaS engines.
- [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/change-the-docker-installation-folder.md): Change the Docker installation folder on a Cortex XSOAR 8 SaaS engine.
- [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md): Configure Docker integrations to trust custom certificates in Cortex XSOAR 8 SaaS.
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md): Harden Docker for Cortex XSOAR 8 SaaS engines.
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for Cortex XSOAR 8 SaaS engines on RHEL 8.
- [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md): Change the container storage directory for a Cortex XSOAR 8 SaaS engine.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md): Install Podman for a Cortex XSOAR 8 SaaS engine.
- [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md): Migrate a Cortex XSOAR 8 SaaS engine from Docker to Podman.
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md): Troubleshoot Podman on Cortex XSOAR 8 SaaS engines.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/manage-engines.md): Manage Cortex XSOAR 8 SaaS engines and load-balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade a Cortex XSOAR 8 SaaS engine on a remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/remove-an-engine.md): Remove a Cortex XSOAR 8 SaaS engine using the operating system command.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR 8 SaaS engines through d1.conf or the UI.
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR 8 SaaS engine to use a web proxy.
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure a Cortex XSOAR 8 SaaS engine to call the server without a proxy.
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md): Use NGINX as a reverse proxy for a Cortex XSOAR 8 SaaS engine.
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md): Configure custom CA certificates for Cortex XSOAR 8 SaaS engine communication.
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use Cortex XSOAR 8 SaaS engines to fetch alerts and run integration commands.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run scripts on Cortex XSOAR 8 SaaS engines or load-balancing groups.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot Cortex XSOAR 8 SaaS engines through logs and errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md): Troubleshoot integrations running on Cortex XSOAR 8 SaaS engines.
- [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management.md): Configure and manage remote repositories for Cortex XSOAR 8 SaaS dev/prod tenants.
- [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Learn how remote repositories work in Cortex XSOAR 8 SaaS.
- [Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/set-up-a-remote-repository.md): Set up a remote repository for Cortex XSOAR 8 SaaS development and production tenants.
- [Set up a built-in remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/set-up-a-remote-repository/set-up-a-built-in-remote-repository.md): Set up the built-in repository for Cortex XSOAR 8 SaaS production and development tenants.
- [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/set-up-a-remote-repository/set-up-a-private-remote-repository.md): Set up a private remote repository for Cortex XSOAR 8 SaaS.
- [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content from a Cortex XSOAR 8 SaaS development tenant to a remote repository.
- [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install remote repository content on a Cortex XSOAR 8 SaaS production tenant.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Troubleshoot remote repository content management in Cortex XSOAR 8 SaaS.
- [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management.md): Configure Cortex XSOAR 8 SaaS roles, users, groups, and authentication.
- [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Configure Cortex XSOAR 8 SaaS roles, user groups, authentication, and users.
- [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in Cortex XSOAR 8 SaaS tenants and Cortex Gateway.
- [Role-based permissions in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions-in-cortex-xsoar.md): Review role-based permissions available in Cortex XSOAR 8 SaaS.
- [Manage roles in Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-cortex-gateway.md): Manage Cortex Gateway roles for Cortex XSOAR 8 SaaS.
- [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in a Cortex XSOAR 8 SaaS tenant.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create Cortex XSOAR 8 SaaS user groups and assign roles and users.
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Authenticate Cortex XSOAR 8 SaaS users using SAML 2.0 or Cortex Gateway.
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate Cortex XSOAR 8 SaaS users through the Customer Support Portal.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up SSO authentication for a Cortex XSOAR 8 SaaS tenant.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Set up Okta SAML 2.0 authentication for Cortex XSOAR 8 SaaS.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Set up Microsoft Entra ID SAML 2.0 authentication for Cortex XSOAR 8 SaaS.
- [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/user-management.md): Manage Cortex XSOAR 8 SaaS users in Cortex Gateway or the tenant.
- [Manage users in Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/user-management/manage-users-in-cortex-gateway.md): Manage Cortex Gateway users for Cortex XSOAR 8 SaaS.
- [Manage users in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/user-management/manage-users-in-the-cortex-xsoar-tenant.md): View and edit users and roles in a Cortex XSOAR 8 SaaS tenant.
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace.md): Download content packs for your Cortex XSOAR 8 SaaS use case.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search Cortex Marketplace content for Cortex XSOAR 8 SaaS use cases.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-packs.md): Download Cortex XSOAR 8 SaaS content packs from Marketplace.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Review Cortex XSOAR 8 SaaS content pack support types.
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert Cortex XSOAR 8 SaaS content packs.
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): Use the Deployment Wizard to adopt a Cortex XSOAR 8 SaaS use case.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Find answers about Cortex XSOAR 8 SaaS Marketplace content.
- [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for Cortex XSOAR 8 SaaS content packs.
- [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize Cortex XSOAR 8 SaaS content pack update notifications.
- [Content changes when upgrading Cortex XSOAR versions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-changes-when-upgrading-cortex-xsoar-versions.md): Review content changes when upgrading Cortex XSOAR 8 SaaS versions.
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-pack-contributions.md): Create Cortex XSOAR 8 SaaS content packs for Marketplace submission.
- [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create and submit a Cortex XSOAR 8 SaaS content pack to Marketplace.
- [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an updated Cortex XSOAR 8 SaaS content pack from the UI.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations.md): Configure and troubleshoot integrations in Cortex XSOAR 8 SaaS.
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/integration-use-cases.md): Explore integration use cases for Cortex XSOAR 8 SaaS.
- [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/configure-integrations.md): Configure or create an integration for Cortex XSOAR 8 SaaS.
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Change Docker images for Cortex XSOAR 8 SaaS integrations and scripts.
- [Connect an engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-an-engine-to-an-image-registry.md): Connect a Cortex XSOAR 8 SaaS engine to an image registry.
- [Pull images from a private image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/pull-images-from-a-private-image-registry.md): Pull private registry images for Cortex XSOAR 8 SaaS.
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/manage-credentials.md): Manage credentials for Cortex XSOAR 8 SaaS integrations.
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up a Cortex XSOAR 8 SaaS integration instance.
- [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Fetch incidents into Cortex XSOAR 8 SaaS from an integration instance.
- [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Receive Cortex XSOAR 8 SaaS notifications for incident fetch errors.
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Configure permissions for Cortex XSOAR 8 SaaS integration commands.
- [Troubleshoot Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Troubleshoot integrations in Cortex XSOAR 8 SaaS.
- [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run Cortex XSOAR 8 SaaS integration commands in the CLI.
- [Forward Requests to Long-Running Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Forward requests to long-running Cortex XSOAR 8 SaaS integrations.
- [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration.md): Configure incidents, fields, and workflows in Cortex XSOAR 8 SaaS.
- [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): Learn the incident lifecycle in Cortex XSOAR 8 SaaS.
- [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization.md): Customize incident types, fields, and layouts in Cortex XSOAR 8 SaaS.
- [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize Cortex XSOAR 8 SaaS incident layouts.
- [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR 8 SaaS.
- [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR 8 SaaS.
- [Incident field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/incident-field-trigger-scripts.md): Configure incident field trigger scripts in Cortex XSOAR 8 SaaS.
- [Create dynamic fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/create-dynamic-fields.md): Create dynamic incident fields in Cortex XSOAR 8 SaaS.
- [Troubleshoot incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/troubleshoot-incident-fields.md): Troubleshoot incident fields in Cortex XSOAR 8 SaaS.
- [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR 8 SaaS.
- [Create an evidence field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/create-an-evidence-field.md): Create custom evidence fields in Cortex XSOAR 8 SaaS.
- [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map integration data in Cortex XSOAR 8 SaaS.
- [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Create incident classifiers in Cortex XSOAR 8 SaaS.
- [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create incident mappers in Cortex XSOAR 8 SaaS.
- [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up incident mirroring in Cortex XSOAR 8 SaaS.
- [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents in Cortex XSOAR 8 SaaS.
- [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create incident pre-process rules in Cortex XSOAR 8 SaaS.
- [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): Use incident post-processing scripts in Cortex XSOAR 8 SaaS.
- [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize incident close reasons in Cortex XSOAR 8 SaaS.
- [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Configure inline value fields in Cortex XSOAR 8 SaaS.
- [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export Cortex XSOAR 8 SaaS incidents to UTF8-BOM CSV files.
- [Export Cortex XSOAR incidents to cloud storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/export-cortex-xsoar-incidents-to-cloud-storage.md): Export Cortex XSOAR 8 SaaS incidents to cloud storage.
- [Configure access to external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/export-cortex-xsoar-incidents-to-cloud-storage/configure-access-to-external-storage.md): Configure external storage access for Cortex XSOAR 8 SaaS exports.
- [Schedule incident export](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/export-cortex-xsoar-incidents-to-cloud-storage/schedule-incident-export.md): Schedule Cortex XSOAR 8 SaaS incident exports to cloud storage.
- [Export incidents on demand](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/export-cortex-xsoar-incidents-to-cloud-storage/export-incidents-on-demand.md): Export Cortex XSOAR 8 SaaS incidents to cloud storage on demand.
- [Amazon S3 configuration example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/incident-configuration/export-cortex-xsoar-incidents-to-cloud-storage/amazon-s3-configuration-example.md): Configure Amazon S3 storage for Cortex XSOAR 8 SaaS incident exports.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/lists.md): Create and manage lists in Cortex XSOAR 8 SaaS.
- [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/lists/what-is-a-list.md): Learn about lists in Cortex XSOAR 8 SaaS.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/lists/create-a-list.md): Create lists for Cortex XSOAR 8 SaaS playbooks and scripts.
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/lists/list-commands.md): Use list commands in Cortex XSOAR 8 SaaS.
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR 8 SaaS.
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Transform lists into arrays in Cortex XSOAR 8 SaaS.
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/jobs.md): Create time-triggered and event-triggered jobs in Cortex XSOAR 8 SaaS.
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/jobs/manage-jobs.md): Manage time-triggered and event-triggered Cortex XSOAR 8 SaaS jobs.
- [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time-triggered job in Cortex XSOAR 8 SaaS.
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create feed-delta jobs in Cortex XSOAR 8 SaaS.
- [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Create Cortex XSOAR 8 SaaS jobs to process indicators.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks.md): Build automated workflows with Cortex XSOAR 8 SaaS playbooks.
- [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Learn about playbooks in Cortex XSOAR 8 SaaS.
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the Cortex XSOAR 8 SaaS playbook development checklist.
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Plan a Cortex XSOAR 8 SaaS playbook.
- [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Develop and customize Cortex XSOAR 8 SaaS playbooks.
- [Task 1. Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-existing-playbooks-or-create-your-own.md): Choose or create a Cortex XSOAR 8 SaaS playbook.
- [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Configure Cortex XSOAR 8 SaaS playbook settings.
- [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Add tasks to a Cortex XSOAR 8 SaaS playbook.
- [Set playbook inputs and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/set-playbook-inputs-and-outputs.md): Set Cortex XSOAR 8 SaaS playbook inputs and outputs.
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-section-header.md): Create Cortex XSOAR 8 SaaS playbook section headers.
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-standard-task.md): Create standard tasks in Cortex XSOAR 8 SaaS playbooks.
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-conditional-task.md): Create conditional tasks in Cortex XSOAR 8 SaaS playbooks.
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md): Create communication tasks in Cortex XSOAR 8 SaaS playbooks.
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md): Configure script error handling in Cortex XSOAR 8 SaaS playbooks.
- [Task 4. Add inline documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-inline-documentation.md): Add inline documentation to Cortex XSOAR 8 SaaS playbooks.
- [Task 5. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-add-custom-playbook-features.md): Add custom features to Cortex XSOAR 8 SaaS playbooks.
- [Task 6. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-test-and-debug-the-playbook.md): Test and debug Cortex XSOAR 8 SaaS playbooks.
- [Task 7. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-7.-manage-playbook-content.md): Manage Cortex XSOAR 8 SaaS playbook content.
- [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize a phishing playbook in Cortex XSOAR 8 SaaS.
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize Cortex XSOAR 8 SaaS playbooks.
- [Customize the SOC Name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Customize the SOC name in Cortex XSOAR 8 SaaS.
- [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure sub-playbooks in Cortex XSOAR 8 SaaS.
- [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Filter and transform data in Cortex XSOAR 8 SaaS playbooks.
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data/filter-considerations-categories-and-built-in-filters.md): Use filters in Cortex XSOAR 8 SaaS playbooks.
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data/transformer-considerations-categories-and-built-in-transformers.md): Use transformers in Cortex XSOAR 8 SaaS playbooks.
- [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators in Cortex XSOAR 8 SaaS playbooks.
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context in Cortex XSOAR 8 SaaS playbooks.
- [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Set and update incident fields in Cortex XSOAR 8 SaaS playbooks.
- [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Configure polling in Cortex XSOAR 8 SaaS playbooks.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/scripts.md): Create and manage Cortex XSOAR 8 SaaS scripts.
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/scripts/use-existing-scripts.md): Use existing scripts in Cortex XSOAR 8 SaaS.
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create scripts in Cortex XSOAR 8 SaaS.
- [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Debug Cortex XSOAR 8 SaaS playbooks.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Troubleshoot Cortex XSOAR 8 SaaS playbook performance.
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage Cortex XSOAR 8 SaaS playbook content and versions.
- [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/best-practices.md): Follow Cortex XSOAR 8 SaaS playbook best practices.
- [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas.md): Configure service-level agreements in Cortex XSOAR 8 SaaS.
- [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): Learn about SLAs in Cortex XSOAR 8 SaaS.
- [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Configure SLAs for incident types in Cortex XSOAR 8 SaaS.
- [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/configure-timersla-fields.md): Configure timer and SLA fields in Cortex XSOAR 8 SaaS.
- [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Configure Cortex XSOAR 8 SaaS playbooks to run SLA timers.
- [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Automate incident field changes using Cortex XSOAR 8 SaaS SLA scripts.
- [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/create-sla-scripts.md): Create SLA scripts in Cortex XSOAR 8 SaaS.
- [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use SLA and timer commands in the Cortex XSOAR 8 SaaS CLI.
- [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Configure the global SLA risk threshold in Cortex XSOAR 8 SaaS.
- [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search Cortex XSOAR 8 SaaS incidents by SLA or timer status.
- [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports.md): Create dashboards, reports, and widgets in Cortex XSOAR 8 SaaS.
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create and manage dashboards in Cortex XSOAR 8 SaaS.
- [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Manage dashboard actions in Cortex XSOAR 8 SaaS.
- [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize dashboards in Cortex XSOAR 8 SaaS.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create and manage reports in Cortex XSOAR 8 SaaS.
- [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create, customize, and schedule Cortex XSOAR 8 SaaS reports.
- [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Configure report timezones in Cortex XSOAR 8 SaaS.
- [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Troubleshoot report script timeouts in Cortex XSOAR 8 SaaS.
- [Troubleshoot Overlapping Text and Extra Pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Troubleshoot PDF report layout issues in Cortex XSOAR 8 SaaS.
- [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and manage widgets in Cortex XSOAR 8 SaaS.
- [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Customize widgets in Cortex XSOAR 8 SaaS.
- [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create widgets with the Cortex XSOAR 8 SaaS widget builder.
- [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create JSON widgets in Cortex XSOAR 8 SaaS.
- [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create script-based widgets in Cortex XSOAR 8 SaaS.
- [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create incident widgets in Cortex XSOAR 8 SaaS.
- [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create indicator widgets in Cortex XSOAR 8 SaaS.
- [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit widgets in Cortex XSOAR 8 SaaS.
- [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add War Room widgets in Cortex XSOAR 8 SaaS.
- [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved By Dbot ROI widget in Cortex XSOAR 8 SaaS.
- [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators in Cortex XSOAR 8 SaaS.
- [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Learn about incidents in Cortex XSOAR 8 SaaS.
- [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR 8 SaaS.
- [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Search for incidents in Cortex XSOAR 8 SaaS.
- [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create incidents in Cortex XSOAR 8 SaaS.
- [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Export Cortex XSOAR 8 SaaS incidents.
- [Export incidents from the Incidents table](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents/export-incidents-from-the-incidents-table.md): Export incidents from the Cortex XSOAR 8 SaaS Incidents table.
- [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and remediate incidents in Cortex XSOAR 8 SaaS.
- [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain incidents in Cortex XSOAR 8 SaaS.
- [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit investigation access in Cortex XSOAR 8 SaaS.
- [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Manage incident tasks in Cortex XSOAR 8 SaaS investigations.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for Cortex XSOAR 8 SaaS investigations.
- [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Run commands in the Cortex XSOAR 8 SaaS CLI.
- [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md): Schedule War Room commands in Cortex XSOAR 8 SaaS.
- [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/appsec-policies-migrated-with-the-new-trigger-and-finding-type-format..md): Manage investigation evidence in Cortex XSOAR 8 SaaS.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): Use Work Plans in Cortex XSOAR 8 SaaS investigations.
- [Add ad-hoc tasks to a Work Plan as part of your investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation/add-ad-hoc-tasks-to-a-work-plan-as-part-of-your-investigation.md): Add ad-hoc Work Plan tasks in Cortex XSOAR 8 SaaS.
- [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Investigate incidents with the Cortex XSOAR 8 SaaS canvas.
- [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in Cortex XSOAR 8 SaaS.
- [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create incident summary reports in Cortex XSOAR 8 SaaS.
- [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Manage indicators in Cortex XSOAR 8 SaaS.
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): Query indicators in Cortex XSOAR 8 SaaS.
- [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): View indicator relationships in Cortex XSOAR 8 SaaS investigations.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management.md): Manage threat intelligence in Cortex XSOAR 8 SaaS.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Get started with Threat Intel Management in Cortex XSOAR 8 SaaS.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Learn about Threat Intel Management in Cortex XSOAR 8 SaaS.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Explore Threat Intel Management use cases in Cortex XSOAR 8 SaaS.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Review Threat Intel Management roles in Cortex XSOAR 8 SaaS.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md): Learn about indicators in Cortex XSOAR 8 SaaS Threat Intel Management.
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Learn about the indicator lifecycle in Cortex XSOAR 8 SaaS.
- [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/understand-cortex-xsoar-licenses.md): Understand licenses for Cortex XSOAR 8 SaaS.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Configure indicators in Cortex XSOAR 8 SaaS Threat Intel Management.
- [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Customize indicators in Cortex XSOAR 8 SaaS.
- [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type.md): Create indicator types in Cortex XSOAR 8 SaaS.
- [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-type-profile.md): Configure indicator type profiles in Cortex XSOAR 8 SaaS.
- [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/file-indicators.md): Manage file indicators in Cortex XSOAR 8 SaaS.
- [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/formatting-scripts.md): Use indicator formatting scripts in Cortex XSOAR 8 SaaS.
- [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/enhancement-scripts.md): Use indicator enhancement scripts in Cortex XSOAR 8 SaaS.
- [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-scripts.md): Use indicator reputation scripts in Cortex XSOAR 8 SaaS.
- [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-commands.md): Run indicator reputation commands in Cortex XSOAR 8 SaaS.
- [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/map-custom-indicator-fields.md): Map custom indicator fields in Cortex XSOAR 8 SaaS.
- [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field.md): Create indicator fields in Cortex XSOAR 8 SaaS.
- [Indicator fields structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-fields-structure.md): Understand indicator field structures in Cortex XSOAR 8 SaaS.
- [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-field-trigger-scripts.md): Configure indicator field trigger scripts in Cortex XSOAR 8 SaaS.
- [Indicator layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-layout-customization.md): Customize indicator layouts in Cortex XSOAR 8 SaaS.
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Classify and map indicators in Cortex XSOAR 8 SaaS.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract and enrich indicators in Cortex XSOAR 8 SaaS.
- [Indicator extraction modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/indicator-extraction-modes.md): Configure indicator extraction modes in Cortex XSOAR 8 SaaS.
- [Create indicator extraction rules for an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md): Create indicator extraction rules in Cortex XSOAR 8 SaaS.
- [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md): Set playbook indicator extraction modes in Cortex XSOAR 8 SaaS.
- [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md): Disable indicator extraction in Cortex XSOAR 8 SaaS.
- [Troubleshoot indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/troubleshoot-indicator-extraction.md): Troubleshoot indicator extraction in Cortex XSOAR 8 SaaS.
- [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Configure indicator expiration in Cortex XSOAR 8 SaaS.
- [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Configure the indicator timeline in Cortex XSOAR 8 SaaS.
- [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md): Configure Threat Intel feeds in Cortex XSOAR 8 SaaS.
- [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Exclude indicators from enrichment in Cortex XSOAR 8 SaaS.
- [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Configure indicator-processing playbooks in Cortex XSOAR 8 SaaS.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from Cortex XSOAR 8 SaaS.
- [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Customize Threat Intel Reports in Cortex XSOAR 8 SaaS.
- [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create Threat Intel Report types in Cortex XSOAR 8 SaaS.
- [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create Threat Intel Report fields in Cortex XSOAR 8 SaaS.
- [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Create Threat Intel Report layouts in Cortex XSOAR 8 SaaS.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Manage indicators in Cortex XSOAR 8 SaaS Threat Intel Management.
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators.md): Query indicators in Cortex XSOAR 8 SaaS.
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Investigate indicators in Cortex XSOAR 8 SaaS.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Manage indicator verdicts in Cortex XSOAR 8 SaaS.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): Extract and enrich indicators in Cortex XSOAR 8 SaaS.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire indicators in Cortex XSOAR 8 SaaS.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): Manage indicator relationships in Cortex XSOAR 8 SaaS.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Delete and exclude indicators in Cortex XSOAR 8 SaaS.
- [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): Manage Threat Intel Reports in Cortex XSOAR 8 SaaS.
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR 8 SaaS.
- [Logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/logs.md): View and troubleshoot logs in Cortex XSOAR 8 SaaS.
- [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): Manage audit logs in Cortex XSOAR 8 SaaS.
- [Syslog server management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/syslog-server-management.md): Configure syslog servers in Cortex XSOAR 8 SaaS.
- [Configure log and notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/configure-log-and-notification-forwarding.md): Forward logs and notifications from Cortex XSOAR 8 SaaS.
- [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR 8 SaaS.
- [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): View Guard Rails warnings and errors in Cortex XSOAR 8 SaaS.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference.md): Reference topics for Cortex XSOAR 8 SaaS.
- [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR 8 SaaS product support lifecycle.
- [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common Cortex XSOAR 8 SaaS concepts.
- [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR 8 SaaS with Lucene syntax and search tools.
- [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown in Cortex XSOAR 8 SaaS.
- [User preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/user-preferences.md): Set user preferences in Cortex XSOAR 8 SaaS.
- [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/server-configurations.md): Configure and troubleshoot Cortex XSOAR 8 SaaS server settings.
- [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate API keys and make API calls in Cortex XSOAR 8 SaaS.
- [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/new-user-faq.md): New user FAQ for Cortex XSOAR 8 SaaS.
- [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Telemetry collects usage data to improve Cortex XSOAR 8 SaaS.
- [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Common Cortex XSOAR 8 SaaS features and navigation.
- [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts for Cortex XSOAR 8 SaaS.
- [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a single console.
- [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to activate and manage tenants and configure single sign-on.
- [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
- [Step 1. Activate Cortex XSOAR (Main Tenant)](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-activate-cortex-xsoar-main-tenant.md): Learn how to activate Cortex XSOAR from the Cortex Gateway.
- [Step 2. Create a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-create-a-child-tenant.md): Create child tenants in the Cortex Gateway.
- [Step 3. Allocate incident retention licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-allocate-incident-retention-licenses.md): Retention policy for Cortex XSOAR multi-tenant and MSSP users.
- [Step 4. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
- [Step 5. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-set-up-a-remote-repository.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR for a multi-tenant deployment.
- [Step 6. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-6.-set-up-users-and-roles.md): Create user groups and roles, manage users in the Main Tenant, and Authenticate users using SAML 2.0 or the Cortex Gateway in a multi-tenant deployment
- [Step 7. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-7.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/child-tenant-management.md): You can change the subdomain of a child tenant, change the name of a child tenant, and delete a child tenant, in the Cortex Gateway.
- [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the Main Tenant to child tenants by applying corresponding propagation labels to content and child tenants.
- [Add propagation labels to content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-content.md)
- [Add propagation labels to a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-a-child-tenant.md)
- [Sync content to child tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/child-tenant-management/content-management-in-multi-tenant/sync-content-to-child-tenants.md)
- [Manage content using a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/child-tenant-management/content-management-in-multi-tenant/manage-content-using-a-remote-repository.md)
- [Incident management on the Main Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
- [Manage main tenant users in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/incident-management-on-the-main-tenant/manage-main-tenant-users-in-an-investigation.md): Open an incident in Cortex XSOAR and take action on child tenants
- [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
- [Indicator management on the Main Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the Main Tenant.

## Cortex XSOAR 8 On-prem Documentation

- [Cortex XSOAR 8 On-prem Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/cortex-xsoar-8-on-prem-documentation.md): Start here to choose the right Cortex XSOAR 8 on-prem version.

* [Navigate the Cortex XSOAR 8 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/navigate-the-cortex-xsoar-8-on-prem-docs.md): Start here for a visual overview of the main Cortex XSOAR 8.14 On-prem documentation areas.
* [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
* [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
* [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
* [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
* [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
* [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
* [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/learn-about-cortex-xsoar/supported-web-browsers.md)
* [How to onboard Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
* [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
* [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps.md): Review the plan and prepare considerations, and then follow the steps in the onboarding checklist to successfully deploy and onboard Cortex XSOAR.
* [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
* [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
* [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
* [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
* [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/post-deployment.md)
* [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/post-deployment/user-communication.md)
* [Configure user notifications in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/post-deployment/user-communication/configure-user-notifications-in-cortex-xsoar.md)
* [Customize system emails](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/post-deployment/user-communication/customize-system-emails.md)
* [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/onboard-cortex-xsoar/post-deployment/configure-system-settings.md)
* [How to install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/installation-overview.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
* [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
* [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
* [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
* [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
* [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
* [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
* [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
* [Task 1. Download the OVA Image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-2.-deploy-your-virtual-machine-on-aws.md)
* [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-3.-validate-tenant-network-and-ip-settings.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
* [Task 1. Download the OVA image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md)
* [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-3.-validate-tenant-network-and-ip-settings.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
* [Task 1. Download the VHD image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-1.-download-the-vhd-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-2.-deploy-your-virtual-machine-on-hyper-v.md)
* [Task 3. Configure tenant network and IP settings for each node](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-3.-configure-tenant-network-and-ip-settings-for-each-node.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log in to Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-8.-verify-you-can-log-in-to-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
* [Install Cortex XSOAR on a VM deployed on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm.md)
* [Task 1. Download the QCOW2 image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-1.-download-the-qcow2-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-2.-deploy-your-virtual-machine-on-kvm.md)
* [Task 3. Configure tenant network and IP settings for each node](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-3.-configure-tenant-network-and-ip-settings-for-each-node.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
* [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
* [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
* [Manage your SSH admin password](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/manage-your-ssh-admin-password.md)
* [Use a signed certificate instead of SSL verification](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/use-a-signed-certificate-instead-of-ssl-verification.md): Use HTTPS with a signed certificate in Cortex XSOAR for MSSP.
* [Manage custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/manage-custom-certificates.md): Manage the list of certificates that Cortex XSOAR trusts for outbound integrations or custom CA roots.
* [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Manage nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/manage-nodes-in-a-cluster.md)
* [Scale up hardware resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/scale-up-hardware-resources.md)
* [Auto expand PVC volumes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/auto-expand-pvc-volumes.md)
* [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu or via SSH using a CLI command.
* [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
* [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
* [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/install-cortex-xsoar/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
* [How to back up and restore Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/back-up-and-restore-cortex-xsoar/back-up-and-restore-cortex-xsoar.md): Perform on-demand backups or schedule recurring backups of the Cortex XSOAR cluster and then restore the cluster from a specific backup.
* [Set up access to an external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/back-up-and-restore-cortex-xsoar/set-up-access-to-an-external-storage.md): From the Cortex XSOAR tenant, set up up access to an external storage.
* [Back up data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/back-up-and-restore-cortex-xsoar/back-up-data.md): From the Cortex XSOAR tenant, perform scheduled backups and on-demand backup and restore of Cortex XSOAR data.
* [Backup guidelines and best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/back-up-and-restore-cortex-xsoar/back-up-data/backup-guidelines-and-best-practices.md)
* [Restore data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/back-up-and-restore-cortex-xsoar/restore-data.md): From the Cortex XSOAR tenant, perform on-demand restore of Cortex XSOAR data.
* [End-to-end example of Cortex XSOAR cluster backup and restore](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/back-up-and-restore-cortex-xsoar/end-to-end-example-of-cortex-xsoar-cluster-backup-and-restore.md): Example workflow for backup and restore in the Cortex XSOAR tenant.
* [Common backup and restore limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/back-up-and-restore-cortex-xsoar/common-backup-and-restore-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR backup and restore issues.
* [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
* [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/what-is-an-engine.md)
* [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
* [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
* [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
* [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
* [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md)
* [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker-distribution-for-red-hat-on-an-engine-server.md)
* [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/docker-image-security.md)
* [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/use-the-cortex-xsoar-container-registry.md)
* [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/docker-faqs.md)
* [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
* [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
* [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
* [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md)
* [Configure Python Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/configure-python-docker-integrations-to-trust-custom-certificates.md)
* [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md)
* [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
* [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md)
* [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md)
* [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md)
* [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md)
* [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
* [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
* [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
* [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
* [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
* [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
* [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
* [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/configure-an-engine-to-use-custom-certificates.md)
* [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
* [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
* [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
* [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
* [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
* [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
* [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
* [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
* [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
* [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
* [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
* [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
* [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
* [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
* [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
* [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
* [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO or LDAP in Cortex XSOAR On-prem.
* [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
* [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
* [Authenticate users using Active Directory or OpenLDAP](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-active-directory-or-openldap.md): Enable users to authenticate to Cortex XSOAR using their existing Active Directory or OpenLDAP credentials and manage their permissions based on directory group mapping
* [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
* [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
* [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
* [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
* [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
* [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
* [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
* [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
* [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
* [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
* [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
* [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
* [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
* [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
* [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
* [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
* [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
* [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
* [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
* [Pull images from a private image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/pull-images-from-a-private-image-registry.md): Create your own authenticated Docker image repository for Cortex XSOAR. View all available images.
* [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/manage-credentials.md)
* [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
* [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
* [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
* [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
* [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
* [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
* [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
* [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
* [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
* [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
* [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
* [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
* [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
* [Incident field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/incident-field-trigger-scripts.md)
* [Create dynamic fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/create-dynamic-fields.md)
* [Troubleshoot incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/troubleshoot-incident-fields.md)
* [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
* [Examples of using scripts in incident layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization/examples-of-using-scripts-in-incident-layouts.md)
* [Create an evidence field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/create-an-evidence-field.md): Create custom evidence fields in Cortex XSOAR.
* [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
* [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
* [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
* [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
* [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
* [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
* [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
* [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
* [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
* [Configure incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete.md): Export incidents from Cortex XSOAR to cloud or local storage. Delete incidents after export or delete without exporting.
* [Configure access to external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/configure-access-to-external-storage.md): As a prerequisite to export incidents to your external storage, add your storage solution to the external storage configuration settings.
* [Export incidents on demand](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/export-incidents-on-demand.md): Export incidents on demand to your external storage.
* [Schedule incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/schedule-incident-export-and-delete.md): Schedule automated incident export to an external storage solution and automatically delete incidents after export. You can also export without deleting or delete without exporting.
* [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
* [Amazon S3 configuration example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/incident-configuration/amazon-s3-configuration-example.md): See an example of configuring an Amazon S3 cloud storage solution in order to retrieve information necessary for configuring backup or export of incidentsCortex XSOAR.
* [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
* [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
* [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
* [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
* [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
* [Task 1. Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-existing-playbooks-or-create-your-own.md): Use or customize an existing playbook or create a new playbook based on your organization's needs.
* [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Set playbook inputs and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/set-playbook-inputs-and-outputs.md)
* [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-section-header.md)
* [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-standard-task.md)
* [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-conditional-task.md)
* [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md)
* [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md)
* [Task 4. Add inline documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-inline-documentation.md): Improve playbook clarity and collaboration by embedding context, logic explanations, and warnings directly within the playbook workflow.
* [Task 5. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 6. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 7. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/task-7.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
* [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
* [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
* [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
* [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
* [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
* [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
* [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
* [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
* [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/scripts/use-existing-scripts.md): Edit scripts to use in playbooks and run in the War Room.
* [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
* [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
* [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
* [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
* [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
* [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
* [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
* [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
* [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
* [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
* [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
* [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
* [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
* [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
* [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
* [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM. Provides an example of a job triggered by a delta in a
* [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
* [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
* [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
* [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
* [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
* [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
* [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
* [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
* [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
* [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
* [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
* [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
* [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
* [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
* [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
* [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
* [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
* [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
* [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
* [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
* [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
* [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
* [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
* [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
* [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
* [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
* [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
* [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
* [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
* [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
* [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
* [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Manually export incidents to an Excel or CSV file or automatically export and delete incidents on a scheduled basis.
* [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
* [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
* [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
* [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
* [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
* [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
* [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
* [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
* [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
* [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
* [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
* [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
* [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
* [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
* [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
* [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation.
* [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
* [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
* [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
* [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
* [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
* [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
* [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
* [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type.md)
* [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-type-profile.md)
* [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/file-indicators.md)
* [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/formatting-scripts.md)
* [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/enhancement-scripts.md)
* [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-scripts.md)
* [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-commands.md)
* [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/map-custom-indicator-fields.md)
* [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field.md)
* [Indicator fields structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-fields-structure.md)
* [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-field-trigger-scripts.md)
* [Indicator layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-layout-customization.md)
* [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
* [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Indicator extraction modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/indicator-extraction-modes.md)
* [Create indicator extraction rules for an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md)
* [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md)
* [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md)
* [Troubleshoot indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/troubleshoot-indicator-extraction.md)
* [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
* [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
* [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
* [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
* [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
* [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
* [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
* [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
* [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
* [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators.md): How to query indicators in the threat intel library
* [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, investigating an indicator and creating indicator relationships.
* [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
* [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
* [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
* [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
* [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
* [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
* [Manage syslog servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot/manage-syslog-servers.md): Add and manage syslog servers. Define the syslog server parameters.
* [Configure log and notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot/configure-log-and-notification-forwarding.md): Send Management Audit logs. Integration logs or Guard Rails to a syslog server.
* [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
* [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
* [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
* [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
* [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
* [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
* [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
* [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
* [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
* [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
* [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
* [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
* [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
* [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a main tenant.
* [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to install, pair and manage parent and child tenants in multi-tenant.
* [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
* [Step 1. Install Cortex XSOAR for multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-install-cortex-xsoar-for-multi-tenant.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
* [Step 2. Pair child tenant to main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-pair-child-tenant-to-main-tenant.md): Learn how to pair the child tenant from the main tenant.
* [Step 3. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-users-and-roles.md): Create user groups and roles, manage users in the main tenant, and authenticate users using SAML 2.0 in a multi-tenant deployment.
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
* [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/child-tenant-management.md): Manage the child tenants and it's content from the main tenant.
* [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the main tenant to child tenants by applying corresponding propagation labels to content and child tenants.
* [Add propagation labels to content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-content.md)
* [Add propagation labels to a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-a-child-tenant.md)
* [Sync content to child tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/child-tenant-management/content-management-in-multi-tenant/sync-content-to-child-tenants.md)
* [Manage content using a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/child-tenant-management/content-management-in-multi-tenant/manage-content-using-a-remote-repository.md)
* [Incident management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
* [Manage main tenant users in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/incident-management-on-the-main-tenant/manage-main-tenant-users-in-an-investigation.md): Open an incident in Cortex XSOAR and take action on child tenants
* [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
* [Indicator management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the main tenant.

- [Navigate the Cortex XSOAR 8 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 8.13 On-prem documentation areas.
- [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/readme-1.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
- [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
- [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
- [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
- [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
- [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/learn-about-cortex-xsoar/supported-web-browsers.md)
- [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
- [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
- [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps.md): Review the plan and prepare considerations, and then follow the steps in the onboarding checklist to successfully deploy and onboard Cortex XSOAR.
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
- [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
- [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
- [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
- [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/post-deployment.md)
- [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/post-deployment/user-communication.md)
- [Configure user notifications in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/post-deployment/user-communication/configure-user-notifications-in-cortex-xsoar.md)
- [Customize system emails](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/post-deployment/user-communication/customize-system-emails.md)
- [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/onboard-cortex-xsoar/post-deployment/configure-system-settings.md)
- [How to install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/installation-overview.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
- [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
- [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
- [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
- [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
- [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
- [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
- [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
- [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
- [Task 1. Download the OVA Image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-2.-deploy-your-virtual-machine-on-aws.md)
- [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-3.-validate-tenant-nework-and-ip-settings.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
- [Task 1. Download the OVA image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md)
- [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-3.-validate-tenant-network-and-ip-settings.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
- [Task 1. Download the VHD image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-1.-download-the-vhd-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-2.-deploy-your-virtual-machine-on-hyper-v.md)
- [Task 3. Configure tenant network and IP settings for each node](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-3.-configure-tenant-network-and-ip-settings-for-each-node.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log in to Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v/task-8.-verify-you-can-log-in-to-cortex-xsoar.md)
- [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
- [Install Cortex XSOAR on a VM deployed on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm.md)
- [Task 1. Download the QCOW2 image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-1.-download-the-qcow2-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-2.-deploy-your-virtual-machine-on-kvm.md)
- [Task 3. Configure tenant network and IP settings for each node](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-3.-configure-tenant-network-and-ip-settings-for-each-node.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
- [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
- [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
- [Manage your SSH admin password](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/manage-your-ssh-admin-password.md)
- [Use a signed certificate instead of SSL verification](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/use-a-signed-certificate-instead-of-ssl-verification.md): Use HTTPS with a signed certificate in Cortex XSOAR for MSSP.
- [Manage custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/manage-custom-certificates.md): Manage the list of certificates that Cortex XSOAR trusts for outbound integrations or custom CA roots.
- [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Manage nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/manage-nodes-in-a-cluster.md)
- [Scale up hardware resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/scale-up-hardware-resources.md)
- [Auto expand PVC volumes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/auto-expand-pvc-volumes.md)
- [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu or via SSH using a CLI command.
- [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
- [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
- [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/install-cortex-xsoar/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
- [How to back up and restore Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/back-up-and-restore-cortex-xsoar/back-up-and-restore-cortex-xsoar.md): Perform on-demand backups or schedule recurring backups of the Cortex XSOAR cluster and then restore the cluster from a specific backup.
- [Set up access to an external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/back-up-and-restore-cortex-xsoar/set-up-access-to-an-external-storage.md): From the Cortex XSOAR tenant, set up up access to an external storage.
- [Back up data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/back-up-and-restore-cortex-xsoar/back-up-data.md): From the Cortex XSOAR tenant, perform scheduled backups and on-demand backup and restore of Cortex XSOAR data.
- [Backup guidelines and best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/back-up-and-restore-cortex-xsoar/back-up-data/backup-guidelines-and-best-practices.md)
- [Restore data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/back-up-and-restore-cortex-xsoar/restore-data.md): From the Cortex XSOAR tenant, perform on-demand restore of Cortex XSOAR data.
- [End-to-end example of Cortex XSOAR cluster backup and restore](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/back-up-and-restore-cortex-xsoar/end-to-end-example-of-cortex-xsoar-cluster-backup-and-restore.md): Example workflow for backup and restore in the Cortex XSOAR tenant.
- [Common backup and restore limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/back-up-and-restore-cortex-xsoar/common-backup-and-restore-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR backup and restore issues.
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
- [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md)
- [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker-distribution-for-red-hat-on-an-engine-server.md)
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/docker-image-security.md)
- [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/use-the-cortex-xsoar-container-registry.md)
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/docker-faqs.md)
- [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
- [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
- [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md)
- [Configure Python Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/configure-python-docker-integrations-to-trust-custom-certificates.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
- [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md)
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md)
- [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md)
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md)
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
- [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
- [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
- [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
- [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
- [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
- [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
- [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
- [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
- [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
- [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO or LDAP in Cortex XSOAR On-prem.
- [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
- [Authenticate users using Active Directory or OpenLDAP](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-active-directory-or-openldap.md): Enable users to authenticate to Cortex XSOAR using their existing Active Directory or OpenLDAP credentials and manage their permissions based on directory group mapping
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
- [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
- [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
- [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
- [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
- [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
- [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
- [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
- [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
- [Pull images from a private image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/pull-images-from-a-private-image-registry.md): Create your own authenticated Docker image repository for Cortex XSOAR. View all available images.
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/manage-credentials.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
- [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
- [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
- [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
- [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
- [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
- [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
- [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
- [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
- [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
- [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
- [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
- [Incident field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/incident-field-trigger-scripts.md)
- [Create dynamic fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/create-dynamic-fields.md)
- [Troubleshoot incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/troubleshoot-incident-fields.md)
- [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
- [Examples of using scripts in incident layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization/examples-of-using-scripts-in-incident-layouts.md)
- [Create an evidence field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/create-an-evidence-field.md): Create custom evidence fields in Cortex XSOAR.
- [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
- [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
- [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
- [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
- [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
- [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
- [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
- [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
- [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
- [Configure incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete.md): Export incidents from Cortex XSOAR to cloud or local storage. Delete incidents after export or delete without exporting.
- [Configure access to external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/configure-access-to-external-storage.md): As a prerequisite to export incidents to your external storage, add your storage solution to the external storage configuration settings.
- [Export incidents on demand](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/export-incidents-on-demand.md): Export incidents on demand to your external storage.
- [Schedule incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/schedule-incident-export-and-delete.md): Schedule automated incident export to an external storage solution and automatically delete incidents after export. You can also export without deleting or delete without exporting.
- [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
- [Amazon S3 configuration example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/incident-configuration/amazon-s3-configuration-example.md): See an example of configuring an Amazon S3 cloud storage solution in order to retrieve information necessary for configuring backup or export of incidentsCortex XSOAR.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
- [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
- [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
- [Task 1. Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-existing-playbooks-or-create-your-own.md): Use or customize an existing playbook or create a new playbook based on your organization's needs.
- [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Set playbook inputs and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/set-playbook-inputs-and-outputs.md)
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-section-header.md)
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-standard-task.md)
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-conditional-task.md)
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md)
- [Task 4. Add inline documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-inline-documentation.md): Improve playbook clarity and collaboration by embedding context, logic explanations, and warnings directly within the playbook workflow.
- [Task 5. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 6. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 7. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/task-7.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
- [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
- [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
- [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data/filter-considerations-categories-and-built-in-filters.md)
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data/transformer-considerations-categories-and-built-in-transformers.md)
- [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
- [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
- [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/scripts/use-existing-scripts.md): Edit scripts to use in playbooks and run in the War Room.
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
- [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
- [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
- [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
- [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
- [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM. Provides an example of a job triggered by a delta in a
- [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
- [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
- [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
- [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
- [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
- [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
- [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
- [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
- [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
- [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
- [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
- [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
- [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
- [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
- [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
- [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
- [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
- [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
- [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
- [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
- [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
- [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
- [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
- [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
- [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
- [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
- [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
- [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
- [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
- [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
- [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Manually export incidents to an Excel or CSV file or automatically export and delete incidents on a scheduled basis.
- [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
- [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
- [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
- [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
- [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
- [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
- [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
- [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
- [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
- [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
- [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
- [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
- [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
- [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type.md)
- [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-type-profile.md)
- [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/file-indicators.md)
- [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/formatting-scripts.md)
- [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/enhancement-scripts.md)
- [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-scripts.md)
- [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-commands.md)
- [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/map-custom-indicator-fields.md)
- [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field.md)
- [Indicator fields structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-fields-structure.md)
- [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-field-trigger-scripts.md)
- [Indicator layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-layout-customization.md)
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Indicator extraction modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/indicator-extraction-modes.md)
- [Create indicator extraction rules for an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md)
- [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md)
- [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md)
- [Troubleshoot indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/troubleshoot-indicator-extraction.md)
- [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
- [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
- [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
- [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
- [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
- [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
- [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
- [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
- [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators.md): How to query indicators in the threat intel library
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, investigating an indicator and creating indicator relationships.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
- [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
- [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
- [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
- [Manage syslog servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot/manage-syslog-servers.md): Add and manage syslog servers. Define the syslog server parameters.
- [Configure log and notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot/configure-log-and-notification-forwarding.md): Send Management Audit logs. Integration logs or Guard Rails to a syslog server.
- [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
- [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
- [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
- [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
- [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
- [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
- [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
- [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
- [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
- [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
- [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
- [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
- [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a main tenant.
- [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to install, pair and manage parent and child tenants in multi-tenant.
- [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
- [Step 1. Install Cortex XSOAR for multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-install-cortex-xsoar-for-multi-tenant.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
- [Step 2. Pair child tenant to main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-pair-child-tenant-to-main-tenant.md): Learn how to pair the child tenant from the main tenant.
- [Step 3. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-users-and-roles.md): Create user groups and roles, manage users in the main tenant, and authenticate users using SAML 2.0 in a multi-tenant deployment.
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/child-tenant-management.md): Manage the child tenants and it's content from the main tenant.
- [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the main tenant to child tenants by applying corresponding propagation labels to content and child tenants.
- [Add propagation labels to content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-content.md)
- [Add propagation labels to a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-a-child-tenant.md)
- [Sync content to child tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/child-tenant-management/content-management-in-multi-tenant/sync-content-to-child-tenants.md)
- [Manage content using a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/child-tenant-management/content-management-in-multi-tenant/manage-content-using-a-remote-repository.md)
- [Incident management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
- [Manage main tenant users in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/incident-management-on-the-main-tenant/manage-main-tenant-users-in-an-investigation.md): Open an incident in Cortex XSOAR and take action on child tenants
- [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
- [Indicator management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the main tenant.

* [Navigate the Cortex XSOAR 8.12 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 8. 12 On-prem documentation areas.
* [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
* [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
* [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
* [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
* [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
* [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
* [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/learn-about-cortex-xsoar/supported-web-browsers.md)
* [How to onboard Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
* [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
* [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps.md): Review the plan and prepare considerations, and then follow the steps in the onboarding checklist to successfully deploy and onboard Cortex XSOAR.
* [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
* [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
* [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
* [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
* [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/deployment-steps/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/post-deployment.md)
* [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/post-deployment/user-communication.md)
* [Configure user notifications in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/post-deployment/user-communication/configure-user-notifications-in-cortex-xsoar.md)
* [Customize system emails](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/post-deployment/user-communication/customize-system-emails.md)
* [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/post-deployment/configure-system-settings.md)
* [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/post-deployment/configure-system-settings/configure-server-settings.md)
* [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/onboard-cortex-xsoar/post-deployment/configure-system-settings/configure-security-settings.md)
* [How to install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
* [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
* [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
* [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
* [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
* [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
* [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
* [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
* [Task 1. Download the OVA Image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-2.-deploy-your-virtual-machine-on-aws.md)
* [Task 3. Validate tenant nework and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-3.-validate-tenant-nework-and-ip-settings.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
* [Task 1. Download the OVA image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md)
* [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-3.-validate-tenant-network-and-ip-settings.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
* [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
* [Install Cortex XSOAR on a VM deployed on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm.md)
* [Task 1. Download the QCOW2 image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-1.-download-the-qcow2-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-2.-deploy-your-virtual-machine-on-kvm.md)
* [Task 3. Configure tenant network and IP settings for each node](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-3.-configure-tenant-network-and-ip-settings-for-each-node.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
* [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
* [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
* [Use a signed certificate instead of SSL verification](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/post-installation/use-a-signed-certificate-instead-of-ssl-verification.md): Use HTTPS with a signed certificate in Cortex XSOAR for MSSP.
* [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Manage nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/manage-nodes-in-a-cluster.md)
* [Scale up hardware resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/post-installation/optimize-performance-and-robustness-from-the-textual-ui/scale-up-hardware-resources.md)
* [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
* [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
* [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
* [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
* [How to back up and restore Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/back-up-and-restore-cortex-xsoar/back-up-and-restore-cortex-xsoar.md): Perform on-demand backups or schedule recurring backups of the Cortex XSOAR cluster and then restore the cluster from a specific backup.
* [Set up access to an external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/back-up-and-restore-cortex-xsoar/set-up-access-to-an-external-storage.md): From the Cortex XSOAR tenant, set up up access to an external storage.
* [Back up data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/back-up-and-restore-cortex-xsoar/back-up-data.md): From the Cortex XSOAR tenant, perform scheduled backups and on-demand backup and restore of Cortex XSOAR data.
* [Restore data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/back-up-and-restore-cortex-xsoar/restore-data.md): From the Cortex XSOAR tenant, perform on-demand restore of Cortex XSOAR data.
* [End-to-end example of Cortex XSOAR cluster backup and restore](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/back-up-and-restore-cortex-xsoar/end-to-end-example-of-cortex-xsoar-cluster-backup-and-restore.md): Example workflow for backup and restore in the Cortex XSOAR tenant.
* [Common backup and restore limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/back-up-and-restore-cortex-xsoar/common-backup-and-restore-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR backup and restore issues.
* [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
* [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/what-is-an-engine.md)
* [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
* [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
* [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
* [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
* [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md)
* [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker-distribution-for-red-hat-on-an-engine-server.md)
* [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/docker-image-security.md)
* [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/use-the-cortex-xsoar-container-registry.md)
* [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/docker-faqs.md)
* [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
* [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
* [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
* [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md)
* [Configure Python Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/configure-python-docker-integrations-to-trust-custom-certificates.md)
* [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md)
* [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
* [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md)
* [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md)
* [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md)
* [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md)
* [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
* [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
* [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
* [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
* [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
* [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
* [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
* [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/configure-an-engine-to-use-custom-certificates.md)
* [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
* [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
* [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
* [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
* [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
* [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
* [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
* [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
* [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
* [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
* [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
* [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
* [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
* [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
* [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
* [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
* [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
* [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
* [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
* [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
* [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
* [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
* [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
* [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
* [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
* [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
* [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
* [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
* [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
* [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
* [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
* [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
* [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
* [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
* [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
* [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
* [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
* [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
* [Pull images from a private image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/pull-images-from-a-private-image-registry.md): Create your own authenticated Docker image repository for Cortex XSOAR. View all available images.
* [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/manage-credentials.md)
* [Configure an external credentials vault](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/manage-credentials/configure-an-external-credentials-vault.md)
* [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
* [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
* [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
* [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
* [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
* [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
* [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
* [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
* [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
* [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
* [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
* [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
* [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
* [Incident field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/incident-field-trigger-scripts.md)
* [Create dynamic fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/create-dynamic-fields.md)
* [Troubleshoot incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/troubleshoot-incident-fields.md)
* [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
* [Create an evidence field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/create-an-evidence-field.md): Create custom evidence fields in Cortex XSOAR.
* [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
* [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
* [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
* [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
* [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
* [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
* [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
* [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
* [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
* [Configure incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete.md): Export incidents from Cortex XSOAR to cloud or local storage. Delete incidents after export or delete without exporting.
* [Configure access to external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/configure-access-to-external-storage.md): As a prerequisite to export incidents to your external storage, add your storage solution to the external storage configuration settings.
* [Export incidents on demand](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/export-incidents-on-demand.md): Export incidents on demand to your external storage.
* [Schedule incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/schedule-incident-export-and-delete.md): Schedule automated incident export to an external storage solution and automatically delete incidents after export. You can also export without deleting or delete without exporting.
* [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
* [Amazon S3 configuration example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/incident-configuration/amazon-s3-configuration-example.md): See an example of configuring an Amazon S3 cloud storage solution in order to retrieve information necessary for configuring backup or export of incidentsCortex XSOAR.
* [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
* [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
* [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
* [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
* [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
* [Task 1. Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-existing-playbooks-or-create-your-own.md): Use or customize an existing playbook or create a new playbook based on your organization's needs.
* [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Set playbook inputs and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/set-playbook-inputs-and-outputs.md)
* [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-section-header.md)
* [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-standard-task.md)
* [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-conditional-task.md)
* [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md)
* [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md)
* [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
* [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
* [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
* [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
* [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
* [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data/transformer-considerations-categories-and-built-in-transformers.md)
* [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
* [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
* [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
* [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
* [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/scripts/use-existing-scripts.md): Edit scripts to use in playbooks and run in the War Room.
* [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
* [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
* [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
* [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
* [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
* [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
* [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
* [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
* [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
* [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
* [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
* [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
* [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
* [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
* [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
* [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM.
* [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
* [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
* [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
* [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
* [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
* [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
* [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
* [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
* [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
* [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
* [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
* [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
* [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
* [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
* [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
* [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
* [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
* [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
* [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
* [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
* [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
* [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
* [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
* [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
* [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
* [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
* [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
* [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
* [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
* [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
* [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
* [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Manually export incidents to an Excel or CSV file or automatically export and delete incidents on a scheduled basis.
* [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
* [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
* [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
* [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
* [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
* [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
* [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
* [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
* [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
* [Add ad hoc tasks to a Work Plan as part of your investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation/add-ad-hoc-tasks-to-a-work-plan-as-part-of-your-investigation.md)
* [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
* [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
* [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
* [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
* [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
* [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
* [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation.
* [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
* [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
* [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
* [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
* [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
* [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
* [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
* [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type.md)
* [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/indicator-type-profile.md)
* [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/file-indicators.md)
* [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/formatting-scripts.md)
* [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/enhancement-scripts.md)
* [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/reputation-scripts.md)
* [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/reputation-commands.md)
* [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/map-custom-indicator-fields.md)
* [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field.md)
* [Indicator fields structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-fields-structure.md)
* [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-field-trigger-scripts.md)
* [Indicator layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-layout-customization.md)
* [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
* [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Indicator extraction modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/indicator-extraction-modes.md)
* [Create indicator extraction rules for an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md)
* [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md)
* [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md)
* [Troubleshoot indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/troubleshoot-indicator-extraction.md)
* [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
* [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
* [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
* [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
* [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
* [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
* [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
* [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
* [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
* [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators.md): How to query indicators in the threat intel library
* [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, investigating an indicator and creating indicator relationships.
* [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
* [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
* [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
* [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
* [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
* [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
* [Manage syslog servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/manage-syslog-servers.md): Add and manage syslog servers. Define the syslog server parameters.
* [Configure log and notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/configure-log-and-notification-forwarding.md): Send Management Audit logs. Integration logs or Guard Rails to a syslog server.
* [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
* [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
* [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
* [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
* [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
* [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
* [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
* [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
* [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
* [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
* [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
* [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
* [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
* [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a main tenant.
* [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to install, pair and manage parent and child tenants in multi-tenant.
* [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
* [Step 1. Install Cortex XSOAR for multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-install-cortex-xsoar-for-multi-tenant.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
* [Step 2. Pair child tenant to main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-pair-child-tenant-to-main-tenant.md): Learn how to pair the child tenant from the main tenant.
* [Step 3. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-users-and-roles.md): Create user groups and roles, manage users in the main tenant, and authenticate users using SAML 2.0 in a multi-tenant deployment.
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
* [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/child-tenant-management.md): Manage the child tenants and it's content from the main tenant.
* [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the main tenant to child tenants by applying corresponding propagation labels to content and child tenants.
* [Add propagation labels to content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-content.md)
* [Add propagation labels to a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-a-child-tenant.md)
* [Sync content to child tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/child-tenant-management/content-management-in-multi-tenant/sync-content-to-child-tenants.md)
* [Manage content using a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/child-tenant-management/content-management-in-multi-tenant/manage-content-using-a-remote-repository.md)
* [Incident management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
* [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
* [Indicator management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the main tenant.

- [Navigate the Cortex XSOAR 8.11 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the Cortex XSOAR 8.11 On-prem documentation.
- [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
- [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
- [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
- [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
- [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
- [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/supported-web-browsers.md)
- [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
- [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
- [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
- [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
- [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
- [What is content?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/what-is-content.md): What content includes in Cortex XSOAR.
- [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment.md)
- [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication.md)
- [Configure user notifications in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication/configure-user-notifications-in-cortex-xsoar.md)
- [Customize system emails](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication/customize-system-emails.md)
- [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings.md)
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings/configure-server-settings.md)
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings/configure-security-settings.md)
- [Cortex XSOAR Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
- [Installation overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/installation-overview.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
- [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
- [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
- [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
- [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
- [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
- [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
- [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
- [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
- [Task 1. Download the OVA Image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-2.-deploy-your-virtual-machine-on-aws.md)
- [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-3.-validate-tenant-nework-and-ip-settings.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
- [Task 1. Download the OVA image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md)
- [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-3.-validate-tenant-network-and-ip-settings.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
- [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
- [Install Cortex XSOAR on a VM deployed on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm.md)
- [Task 1. Download the QCOW2 image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-1.-download-the-qcow2-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on KVM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-2.-deploy-your-virtual-machine-on-kvm.md)
- [Task 3. Configure tenant network and IP settings for each node](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-3.-configure-tenant-network-and-ip-settings-for-each-node.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-kvm/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
- [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
- [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
- [Use a signed certificate instead of SSL verification](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/use-a-signed-certificate-instead-of-ssl-verification.md): Use HTTPS with a signed certificate in Cortex XSOAR for MSSP.
- [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Manage your SSH admin password](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/manage-your-ssh-admin-password.md): Change the SSH admin password from the textual UI.
- [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
- [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
- [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
- [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/cortex-xsoar-installation/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
- [Back up and Restore Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar.md): Perform on-demand backups or schedule recurring backups of the Cortex XSOAR cluster and then restore the cluster from a specific backup.
- [Set up access to an external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/set-up-access-to-an-external-storage.md): From the Cortex XSOAR tenant, set up up access to an external storage.
- [Back up data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/back-up-data.md): From the Cortex XSOAR tenant, perform scheduled backups and on-demand backup and restore of Cortex XSOAR data.
- [Backup guidelines and best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/back-up-data/backup-guidelines-and-best-practices.md)
- [Restore data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/restore-data.md): From the Cortex XSOAR tenant, perform on-demand restore of Cortex XSOAR data.
- [End-to-end example of Cortex XSOAR cluster backup and restore](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/end-to-end-example-of-cortex-xsoar-cluster-backup-and-restore.md): Example workflow for backup and restore in the Cortex XSOAR tenant.
- [Common backup and restore limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/common-backup-and-restore-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR backup and restore issues.
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
- [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md)
- [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker-distribution-for-red-hat-on-an-engine-server.md)
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/docker-image-security.md)
- [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/use-the-cortex-xsoar-container-registry.md)
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/docker-faqs.md)
- [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
- [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
- [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md)
- [Configure Python Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/configure-python-docker-integrations-to-trust-custom-certificates.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md)
- [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md)
- [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md)
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md)
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/configure-engines/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
- [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
- [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
- [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
- [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
- [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
- [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
- [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
- [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
- [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
- [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
- [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
- [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
- [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
- [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
- [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
- [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
- [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
- [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
- [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
- [Pull images from a private image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/pull-images-from-a-private-image-registry.md): Create your own authenticated Docker image repository for Cortex XSOAR. View all available images.
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/manage-credentials.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
- [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
- [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
- [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
- [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
- [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
- [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
- [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
- [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
- [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
- [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
- [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
- [Incident field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/incident-field-trigger-scripts.md)
- [Create dynamic fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/create-dynamic-fields.md)
- [Troubleshoot incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/troubleshoot-incident-fields.md)
- [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
- [Examples of using scripts in incident layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization/examples-of-using-scripts-in-incident-layouts.md)
- [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
- [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
- [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
- [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
- [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
- [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
- [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
- [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
- [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
- [Configure incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete.md): Export incidents from Cortex XSOAR to cloud or local storage. Delete incidents after export or delete without exporting.
- [Configure access to external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/configure-access-to-external-storage.md): As a prerequisite to export incidents to your external storage, add your storage solution to the external storage configuration settings.
- [Export incidents on demand](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/export-incidents-on-demand.md): Export incidents on demand to your external storage.
- [Schedule incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/schedule-incident-export-and-delete.md): Schedule automated incident export to an external storage solution and automatically delete incidents after export. You can also export without deleting or delete without exporting.
- [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
- [Amazon S3 configuration example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/incident-configuration/amazon-s3-configuration-example.md): See an example of configuring an Amazon S3 cloud storage solution in order to retrieve information necessary for configuring backup or export of incidentsCortex XSOAR.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
- [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
- [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
- [Task 1. Choose from existing playbooks or create your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-existing-playbooks-or-create-your-own.md): Use or customize an existing playbook or create a new playbook based on your organization's needs.
- [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Set playbook inputs and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/set-playbook-inputs-and-outputs.md)
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-section-header.md)
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-standard-task.md)
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-conditional-task.md)
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md)
- [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
- [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
- [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
- [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
- [Filter considerations, categories, and built-in filters](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data/filter-considerations-categories-and-built-in-filters.md)
- [Transformer considerations, categories, and built-in transformers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data/transformer-considerations-categories-and-built-in-transformers.md)
- [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
- [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
- [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
- [Use existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/scripts/use-existing-scripts.md): Edit scripts to use in playbooks and run in the War Room.
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
- [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
- [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
- [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
- [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
- [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM.
- [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
- [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
- [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
- [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
- [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
- [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
- [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
- [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
- [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
- [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
- [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
- [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
- [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
- [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
- [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
- [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
- [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
- [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
- [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
- [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
- [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
- [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
- [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
- [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
- [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
- [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
- [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
- [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
- [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
- [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
- [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Manually export incidents to an Excel or CSV file or automatically export and delete incidents on a scheduled basis.
- [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
- [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
- [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
- [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
- [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
- [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
- [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
- [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
- [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
- [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
- [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
- [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
- [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
- [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type.md)
- [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/indicator-type-profile.md)
- [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/file-indicators.md)
- [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/formatting-scripts.md)
- [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/enhancement-scripts.md)
- [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/reputation-scripts.md)
- [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/reputation-commands.md)
- [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type/map-custom-indicator-fields.md)
- [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field.md)
- [Indicator fields structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-fields-structure.md)
- [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-field-trigger-scripts.md)
- [Indicator layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-layout-customization.md)
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Indicator extraction modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/indicator-extraction-modes.md)
- [Create indicator extraction rules for an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md)
- [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md)
- [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md)
- [Troubleshoot indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/troubleshoot-indicator-extraction.md)
- [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
- [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
- [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
- [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
- [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
- [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
- [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
- [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
- [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators.md): How to query indicators in the threat intel library
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, investigating an indicator and creating indicator relationships.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
- [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
- [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
- [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
- [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
- [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
- [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
- [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
- [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
- [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
- [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
- [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
- [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
- [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
- [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
- [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
- [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a main tenant.
- [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to install, pair and manage parent and child tenants in multi-tenant.
- [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
- [Step 1. Install Cortex XSOAR for multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-install-cortex-xsoar-for-multi-tenant.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
- [Step 2. Pair the child tenant to main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-pair-child-tenant-to-main-tenant.md): Learn how to pair the child tenant from the main tenant.
- [Step 3. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-users-and-roles.md): Create user groups and roles, manage users in the main tenant, and authenticate users using SAML 2.0 in a multi-tenant deployment.
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/child-tenant-management.md): Manage the child tenants and it's content from the main tenant.
- [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the main tenant to child tenants by applying corresponding propagation labels to content and child tenants.
- [Add propagation labels to content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-content.md)
- [Add propagation labels to a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/child-tenant-management/content-management-in-multi-tenant/add-propagation-labels-to-a-child-tenant.md)
- [Sync content to child tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/child-tenant-management/content-management-in-multi-tenant/sync-content-to-child-tenants.md)
- [Manage content using a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/child-tenant-management/content-management-in-multi-tenant/manage-content-using-a-remote-repository.md)
- [Incident management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
- [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
- [Indicator management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the main tenant.

* [Navigate the Cortex XSOAR 8.10 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the Cortex XSOAR 8.10 On-prem documentation.
* [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
* [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
* [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
* [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
* [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
* [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
* [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/supported-web-browsers.md)
* [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
* [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
* [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
* [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
* [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
* [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
* [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment.md)
* [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication.md)
* [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings.md)
* [Configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/configure-cortex-xsoar.md): Configure engines, playbooks, scripts, dashboards, etc., for your use case.
* [Cortex XSOAR Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
* [Installation overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/installation-overview.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
* [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
* [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
* [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
* [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
* [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
* [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
* [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
* [Task 1. Download the OVA Image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-2.-deploy-your-virtual-machine-on-aws.md)
* [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-3.-validate-tenant-nework-and-ip-settings.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
* [Task 1. Download the OVA image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md)
* [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-3.-validate-tenant-network-and-ip-settings.md)
* [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-4.-configure-ntp-servers.md)
* [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-5.-optional-configure-proxy-settings.md)
* [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
* [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
* [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
* [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
* [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
* [Use a signed certificate instead of SSL verification](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/use-a-signed-certificate-instead-of-ssl-verification.md): Use HTTPS with a signed certificate in Cortex XSOAR for MSSP.
* [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Manage nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui/manage-nodes-in-a-cluster.md): Add, taint, remove, drain, and uncordon nodes from the textual UI.
* [Scale up hardware resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui/optimize-performance-and-robustness-from-the-textual-ui.md)
* [Auto expand PVC volumes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui/auto-expand-pvc-volumes.md)
* [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
* [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
* [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
* [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/cortex-xsoar-installation/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
* [Back up and Restore Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar.md): Perform on-demand backups or schedule recurring backups of the Cortex XSOAR cluster and then restore the cluster from a specific backup.
* [Set up access to an external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/set-up-access-to-an-external-storage.md): From the Cortex XSOAR tenant, set up up access to an external storage.
* [Back up data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/back-up-data.md): From the Cortex XSOAR tenant, perform scheduled backups and on-demand backup and restore of Cortex XSOAR data.
* [Backup guidelines and best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/back-up-data/backup-guidelines-and-best-practices.md)
* [Restore data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/restore-data.md): From the Cortex XSOAR tenant, perform on-demand restore of Cortex XSOAR data.
* [End-to-end example of Cortex XSOAR cluster backup and restore](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/end-to-end-example-of-cortex-xsoar-cluster-backup-and-restore.md): Example workflow for backup and restore in the Cortex XSOAR tenant.
* [Common backup and restore limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/common-backup-and-restore-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR backup and restore issues.
* [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
* [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/what-is-an-engine.md)
* [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
* [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
* [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
* [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
* [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md)
* [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/install-docker-distribution-for-red-hat-on-an-engine-server.md)
* [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/docker-image-security.md)
* [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/use-the-cortex-xsoar-container-registry.md)
* [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/docker-faqs.md)
* [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/troubleshoot-docker-issues.md)
* [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/configure-docker-pull-rate-limit.md)
* [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/change-the-docker-installation-folder.md)
* [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md)
* [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md)
* [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
* [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md)
* [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md)
* [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md)
* [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md)
* [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
* [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
* [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
* [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
* [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
* [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
* [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
* [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/configure-an-engine-to-use-custom-certificates.md)
* [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
* [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
* [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
* [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
* [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
* [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
* [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
* [How to set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository/how-to-set-up-a-private-remote-repository.md): Set up the private content repository feature.
* [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
* [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
* [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
* [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
* [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
* [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
* [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
* [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
* [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
* [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
* [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
* [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
* [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
* [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
* [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
* [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
* [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
* [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
* [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
* [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
* [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
* [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
* [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
* [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
* [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
* [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
* [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
* [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
* [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
* [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
* [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
* [Pull images from a private image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/pull-images-from-a-private-image-registry.md): Create your own authenticated Docker image repository for Cortex XSOAR. View all available images.
* [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/manage-credentials.md)
* [Configure an external credentials vault](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/manage-credentials/configure-an-external-credentials-vault.md)
* [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
* [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
* [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
* [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
* [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
* [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
* [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
* [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
* [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
* [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
* [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
* [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
* [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
* [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
* [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
* [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
* [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
* [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
* [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
* [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
* [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
* [Create a post-processing script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident/create-a-post-processing-script.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
* [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
* [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
* [Configure incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete.md): Export incidents from Cortex XSOAR to cloud or local storage. Delete incidents after export or delete without exporting.
* [Configure access to external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/configure-access-to-external-storage.md): As a prerequisite to export incidents to your external storage, add your storage solution to the external storage configuration settings.
* [Export incidents on demand](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/export-incidents-on-demand.md): Export incidents on demand to your external storage.
* [Schedule incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/schedule-incident-export-and-delete.md): Schedule automated incident export to an external storage solution and automatically delete incidents after export. You can also export without deleting or delete without exporting.
* [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
* [Amazon S3 configuration example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/incident-configuration/amazon-s3-configuration-example.md): See an example of configuring an Amazon S3 cloud storage solution in order to retrieve information necessary for configuring backup or export of incidentsCortex XSOAR.
* [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
* [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
* [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
* [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
* [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
* [Task 1. Choose from out-of-the-box playbooks or customize your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-out-of-the-box-playbooks-or-customize-your-own.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
* [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
* [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
* [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
* [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
* [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
* [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
* [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
* [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
* [Configure existing scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/scripts/common-scripts.md)
* [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
* [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
* [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
* [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
* [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
* [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
* [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
* [Use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/lists/what-is-a-list/use-cases.md): Create and manage lists in Cortex XSOAR.
* [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
* [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
* [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
* [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
* [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
* [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
* [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
* [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
* [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM.
* [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
* [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
* [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
* [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
* [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
* [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
* [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
* [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
* [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
* [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Default dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/dashboards/default-dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
* [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
* [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
* [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
* [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
* [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
* [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
* [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
* [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
* [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
* [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
* [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
* [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
* [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
* [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
* [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
* [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
* [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
* [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
* [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
* [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
* [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
* [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Manually export incidents to an Excel or CSV file or automatically export and delete incidents on a scheduled basis.
* [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
* [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
* [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
* [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
* [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
* [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
* [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
* [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
* [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
* [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
* [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
* [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
* [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
* [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
* [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
* [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
* [Licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/licenses.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
* [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
* [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
* [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
* [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
* [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
* [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
* [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
* [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
* [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
* [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
* [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
* [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
* [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
* [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
* [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
* [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
* [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
* [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, accessing and using Unit 42 Intel data, investigating an indicator and creating indicator relationships.
* [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
* [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
* [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
* [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
* [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
* [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
* [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
* [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
* [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
* [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
* [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
* [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
* [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
* [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
* [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
* [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
* [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
* [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
* [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
* [Multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant.md): Activate and configure Cortex XSOAR multi-tenant.
* [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a main tenant.
* [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to install, pair and manage parent and child tenants in multi-tenant.
* [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
* [Step 1. Install Cortex XSOAR for multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-install-cortex-xsoar-for-multi-tenant.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
* [Step 2. Pair child tenant to main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-pair-child-tenant-to-main-tenant.md): Learn how to pair the child tenant from the main tenant.
* [Step 3. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-users-and-roles.md): Create user groups and roles, manage users in the main tenant, and authenticate users using SAML 2.0 in a multi-tenant deployment.
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
* [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/child-tenant-management.md): Manage the child tenants and it's content from the main tenant.
* [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the main tenant to child tenants by applying corresponding propagation labels to content and child tenants.
* [Incident management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
* [Manage main tenant users in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/incident-management-on-the-main-tenant/manage-main-tenant-users-in-an-investigation.md): Open an incident in Cortex XSOAR and take action on child tenants
* [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
* [Indicator management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/multi-tenant/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the main tenant.

- [Navigate the Cortex XSOAR 8.9 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme.md)
- [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme-1.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
- [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme-1/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
- [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme-1/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
- [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme-1/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
- [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme-1/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
- [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme-1/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/learn-about-cortex-xsoar/readme-1/supported-web-browsers.md)
- [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
- [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
- [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
- [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
- [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
- [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment.md)
- [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication.md)
- [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings.md)
- [Configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/configure-cortex-xsoar.md): Configure engines, playbooks, scripts, dashboards, etc., for your use case.
- [Cortex XSOAR Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
- [Installation overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/installation-overview.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
- [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
- [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
- [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
- [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
- [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
- [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
- [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
- [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
- [Task 1. Download the OVA Image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-2.-deploy-your-virtual-machine-on-aws.md)
- [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-3.-validate-tenant-nework-and-ip-settings.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
- [Task 1. Download the OVA image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
- [Task 2. Deploy your virtual machine on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md)
- [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-3.-validate-tenant-network-and-ip-settings.md)
- [Task 4. Configure NTP servers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-4.-configure-ntp-servers.md)
- [Task 5. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-5.-optional-configure-proxy-settings.md)
- [Task 6. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
- [Task 7. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-7.-install-cortex-xsoar-on-your-vm.md)
- [Task 8. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-8.-verify-you-can-log-into-cortex-xsoar.md)
- [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
- [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
- [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
- [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
- [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
- [Use a signed certificate instead of SSL verification](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/use-a-signed-certificate-instead-of-ssl-verification.md): Use HTTPS with a signed certificate in Cortex XSOAR for MSSP.
- [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Manage nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui/manage-nodes-in-a-cluster.md)
- [Scale up hardware resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui/scale-up-hardware-resources.md)
- [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
- [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
- [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
- [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/cortex-xsoar-installation/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
- [Back up and Restore Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar.md): Perform on-demand backups or schedule recurring backups of the Cortex XSOAR cluster and then restore the cluster from a specific backup.
- [Set up access to an external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/set-up-access-to-an-external-storage.md): From the Cortex XSOAR tenant, set up up access to an external storage.
- [Back up data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/back-up-data.md): From the Cortex XSOAR tenant, perform scheduled backups and on-demand backup and restore of Cortex XSOAR data.
- [Backup guidelines and best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/back-up-data/backup-guidelines-and-best-practices.md)
- [Restore data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/restore-data.md): From the Cortex XSOAR tenant, perform on-demand restore of Cortex XSOAR data.
- [End-to-end example of Cortex XSOAR cluster backup and restore](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/end-to-end-example-of-cortex-xsoar-cluster-backup-and-restore.md): Example workflow for backup and restore in the Cortex XSOAR tenant.
- [Common backup and restore limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/common-backup-and-restore-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR backup and restore issues.
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy and configure Cortex XSOAR engines.
- [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
- [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md)
- [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/install-docker-distribution-for-red-hat-on-an-engine-server.md)
- [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/docker-image-security.md)
- [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/use-the-cortex-xsoar-container-registry.md)
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/docker-faqs.md)
- [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/troubleshoot-docker-issues.md)
- [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/configure-docker-pull-rate-limit.md)
- [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker/change-the-docker-installation-folder.md)
- [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md)
- [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md)
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
- [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md)
- [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md)
- [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md)
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md)
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
- [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
- [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
- [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
- [How to set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository/how-to-set-up-a-private-remote-repository.md): Set up the private content repository feature.
- [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
- [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
- [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
- [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
- [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
- [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
- [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
- [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
- [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
- [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
- [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
- [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
- [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
- [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
- [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
- [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
- [Pull images from a private image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/pull-images-from-a-private-image-registry.md): Create your own authenticated Docker image repository for Cortex XSOAR. View all available images.
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/manage-credentials.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
- [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
- [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
- [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
- [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
- [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
- [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
- [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
- [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
- [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
- [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
- [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
- [Incident field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/incident-field-trigger-scripts.md)
- [Create dynamic fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/create-dynamic-fields.md)
- [Troubleshoot incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/troubleshoot-incident-fields.md)
- [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
- [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
- [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
- [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
- [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
- [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
- [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
- [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
- [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
- [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
- [Configure incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete.md): Export incidents from Cortex XSOAR to cloud or local storage. Delete incidents after export or delete without exporting.
- [Configure access to external storage](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/configure-access-to-external-storage.md): As a prerequisite to export incidents to your external storage, add your storage solution to the external storage configuration settings.
- [Export incidents on demand](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/export-incidents-on-demand.md): Export incidents on demand to your external storage.
- [Schedule incident export and delete](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/configure-incident-export-and-delete/schedule-incident-export-and-delete.md): Schedule automated incident export to an external storage solution and automatically delete incidents after export. You can also export without deleting or delete without exporting.
- [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
- [Amazon S3 configuration example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/incident-configuration/amazon-s3-configuration-example.md): See an example of configuring an Amazon S3 cloud storage solution in order to retrieve information necessary for configuring backup or export of incidentsCortex XSOAR.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
- [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
- [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
- [Task 1. Choose from out-of-the-box playbooks or customize your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-out-of-the-box-playbooks-or-customize-your-own.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
- [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
- [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
- [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
- [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
- [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
- [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
- [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
- [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
- [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
- [Use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/lists/what-is-a-list/use-cases.md): Create and manage lists in Cortex XSOAR.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
- [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
- [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM. Provides an example of a job triggered by a delta in a
- [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
- [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
- [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
- [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
- [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
- [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
- [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
- [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
- [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
- [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
- [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
- [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
- [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
- [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
- [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
- [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
- [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
- [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
- [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
- [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
- [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
- [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
- [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
- [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
- [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
- [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
- [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
- [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
- [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
- [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
- [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Manually export incidents to an Excel or CSV file or automatically export and delete incidents on a scheduled basis.
- [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
- [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
- [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
- [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
- [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
- [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
- [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
- [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
- [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
- [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
- [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
- [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
- [Licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/licenses.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
- [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
- [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
- [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
- [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
- [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
- [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
- [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
- [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
- [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, accessing and using Unit 42 Intel data, investigating an indicator and creating indicator relationships.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
- [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
- [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
- [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
- [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
- [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
- [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
- [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
- [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
- [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
- [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
- [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
- [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
- [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
- [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
- [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
- [Multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant.md): Activate and configure Cortex XSOAR multi-tenant.
- [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a main tenant.
- [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to install, pair and manage parent and child tenants in multi-tenant.
- [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
- [Step 1. Install Cortex XSOAR for multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-install-cortex-xsoar-for-multi-tenant.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
- [Step 2. Pair child tenant to main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-pair-child-tenant-to-main-tenant.md): Learn how to pair the child tenant from the main tenant.
- [Step 3. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-users-and-roles.md): Create user groups and roles, manage users in the main tenant, and authenticate users using SAML 2.0 in a multi-tenant deployment.
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/child-tenant-management.md): Manage the child tenants and it's content from the main tenant.
- [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the main tenant to child tenants by applying corresponding propagation labels to content and child tenants.
- [Incident management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
- [Manage main tenant users in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/incident-management-on-the-main-tenant/manage-main-tenant-users-in-an-investigation.md): Open an incident in Cortex XSOAR and take action on child tenants
- [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
- [Indicator management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the main tenant.
- [Upgrade of Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/multi-tenant/multi-tenant/upgrade-of-cortex-xsoar-multi-tenant.md): Cortex offers a simple process for upgrading the main and child tenants within your multi-tenant environment.

* [Navigate the Cortex XSOAR 8.8 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/readme.md)
* [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
* [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
* [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
* [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
* [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
* [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
* [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/supported-web-browsers.md)
* [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
* [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
* [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
* [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
* [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
* [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
* [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment.md)
* [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication.md)
* [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings.md)
* [Configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/configure-cortex-xsoar.md): Configure engines, playbooks, scripts, dashboards, etc., for your use case.
* [Cortex XSOAR Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
* [Installation overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/installation-overview.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
* [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
* [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
* [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
* [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
* [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
* [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
* [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
* [Task 1. Download the OVA Image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-2.-deploy-your-virtual-machine-on-aws.md)
* [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-3.-validate-tenant-nework-and-ip-settings.md)
* [Task 4. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-5.-optional-configure-proxy-settings.md)
* [Task 5. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 6. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 7. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
* [Task 1. Download the OVA image and license from Cortex Gateway](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-1.-download-the-ova-image-and-license-from-cortex-gateway.md)
* [Task 2. Deploy your virtual machine on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-2.-deploy-your-virtual-machine-on-oci.md)
* [Task 3. Validate tenant network and IP settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-3.-validate-tenant-network-and-ip-settings.md)
* [Task 4. (Optional) Configure proxy settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-5.-optional-configure-proxy-settings.md)
* [Task 5. Establish trust between all nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-6.-establish-trust-between-all-nodes-in-a-cluster.md)
* [Task 6. Install Cortex XSOAR on your VM](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-7.-install-cortex-xsoar-on-your-vm.md)
* [Task 7. Verify you can log into Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci/task-8.-verify-you-can-log-into-cortex-xsoar.md)
* [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
* [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
* [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
* [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
* [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
* [Use a signed certificate instead of SSL](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/use-a-signed-certificate-instead-of-ssl.md): Use HTTPS with a signed certificate in Cortex XSOAR for MSSP.
* [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
* [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
* [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
* [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
* [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/cortex-xsoar-installation/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
* [Back up and Restore Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar.md): Schedule recurring backups of the Cortex XSOAR cluster and then restore the cluster from a specific backup.
* [Set up backup and restore in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/set-up-backup-and-restore-in-cortex-xsoar.md): Set up Cortex XSOAR backup and run the command to connect to the server.
* [Run backup and restore operations from the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/run-backup-and-restore-operations-from-the-cli.md): From the CLI, schedule recurring backups of the Cortex XSOAR cluster and subsequently restore the cluster from a specific backup.
* [Restore backups between clusters](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/onboard-cortex-xsoar/back-up-and-restore-cortex-xsoar/restore-backups-between-clusters.md): From the CLI, schedule recurring backups of the Cortex XSOAR cluster and subsequently restore the cluster from a specific backup.
* [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
* [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/what-is-an-engine.md)
* [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
* [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
* [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
* [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
* [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
* [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
* [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
* [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
* [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
* [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
* [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
* [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
* [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/configure-an-engine-to-use-custom-certificates.md)
* [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
* [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
* [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
* [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
* [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
* [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
* [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
* [How to set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository/how-to-set-up-a-private-remote-repository.md): Set up the private content repository feature.
* [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
* [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
* [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
* [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
* [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
* [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
* [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
* [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
* [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
* [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
* [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
* [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
* [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
* [Set up Azure AD as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-azure-ad-as-the-identity-provider-using-saml-2.0.md)
* [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
* [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
* [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
* [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
* [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
* [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
* [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
* [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
* [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
* [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
* [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
* [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
* [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
* [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
* [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
* [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
* [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
* [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/manage-credentials.md)
* [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
* [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
* [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
* [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
* [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
* [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
* [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
* [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
* [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
* [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
* [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
* [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
* [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
* [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
* [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
* [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
* [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
* [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
* [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
* [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
* [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
* [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
* [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
* [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
* [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
* [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
* [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
* [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
* [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
* [Task 1. Choose from out-of-the-box playbooks or customize your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-out-of-the-box-playbooks-or-customize-your-own.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
* [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
* [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
* [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
* [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
* [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
* [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
* [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
* [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
* [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
* [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
* [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
* [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
* [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
* [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
* [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
* [Use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/lists/what-is-a-list/use-cases.md): Create and manage lists in Cortex XSOAR.
* [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
* [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
* [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
* [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
* [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
* [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
* [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
* [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
* [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM.
* [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
* [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
* [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
* [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
* [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
* [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
* [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
* [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
* [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
* [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
* [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
* [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
* [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
* [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
* [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
* [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
* [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
* [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
* [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
* [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
* [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
* [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
* [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
* [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
* [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
* [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
* [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
* [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
* [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
* [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
* [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
* [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Export incidents to an Excel or CSV file.
* [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
* [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
* [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
* [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
* [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
* [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
* [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
* [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
* [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
* [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
* [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
* [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
* [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
* [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
* [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
* [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
* [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
* [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
* [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
* [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
* [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
* [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
* [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
* [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
* [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
* [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
* [Exclude indicators from enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/exclude-indicators-from-enrichment.md): Extract and save indicators but do not enrich them.
* [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
* [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
* [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
* [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
* [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
* [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
* [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, accessing and using Unit 42 Intel data, investigating an indicator and creating indicator relationships.
* [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
* [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
* [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
* [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
* [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
* [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
* [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
* [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
* [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
* [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
* [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
* [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
* [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
* [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
* [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
* [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
* [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
* [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
* [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
* [Multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant.md): Activate and configure Cortex XSOAR multi-tenant.
* [What is Cortex XSOAR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/what-is-cortex-xsoar-multi-tenant.md): Learn about Cortex XSOAR multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a main tenant.
* [Onboard Cortex XSOAR multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant.md): Learn how to install, pair and manage parent and child tenants in multi-tenant.
* [Onboarding checklist for multi-tenant deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/onboarding-checklist-for-multi-tenant-deployments.md): Onboard for Multi-tenant/MSSP deployments
* [Step 1. Install Cortex XSOAR for multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-1.-install-cortex-xsoar-for-multi-tenant.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
* [Step 2. Pair child tenant to main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-2.-pair-child-tenant-to-main-tenant.md): Learn how to pair the child tenant from the main tenant.
* [Step 3. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-set-up-an-engine.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and tenant.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-4.-set-up-users-and-roles.md): Create user groups and roles, manage users in the main tenant, and authenticate users using SAML 2.0 in a multi-tenant deployment.
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-5.-install-and-configure-content.md): Install and configure content when onboarding Cortex XSOAR. This step applies to Multi-tenant and MSSP environments.
* [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/child-tenant-management.md): Manage the child tenants and it's content from the main tenant.
* [Content management in multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/child-tenant-management/content-management-in-multi-tenant.md): Content is pushed from the main tenant to child tenants by applying corresponding propagation labels to content and child tenants.
* [Incident management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/incident-management-on-the-main-tenant.md): Open an incident in Cortex XSOAR and take action on child tenants
* [Manage main tenant users in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/incident-management-on-the-main-tenant/manage-main-tenant-users-in-an-investigation.md): Open an incident in Cortex XSOAR and take action on child tenants
* [Run a command on multiple tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/incident-management-on-the-main-tenant/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
* [Indicator management on the main tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/multi-tenant/multi-tenant/indicator-management-on-the-main-tenant.md): View and take action on indicators on the main tenant.

- [Navigate the Cortex XSOAR 8.7 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 8.7 On-prem documentation areas.
- [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
- [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
- [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
- [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
- [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
- [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/supported-web-browsers.md)
- [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
- [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
- [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
- [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
- [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
- [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment.md)
- [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication.md)
- [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings.md)
- [Configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/configure-cortex-xsoar.md): Configure engines, playbooks, scripts, dashboards, etc., for your use case.
- [Cortex XSOAR Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
- [Installation overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/installation-overview.md): Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
- [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/high-availability-for-cortex-xsoar.md): Ensure reliable and continuous operation with High Availability.
- [Load balancing for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/load-balancing-for-cortex-xsoar.md): Ensure reliable and continuous operation with load balancing.
- [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
- [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
- [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
- [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
- [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
- [Install Cortex XSOAR on a VM deployed on AWS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-aws.md)
- [Install Cortex XSOAR on a VM deployed on OCI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-oci.md)
- [Install Cortex XSOAR on a VM deployed on Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-hyper-v.md)
- [Install Cortex XSOAR on a VM deployed on VSphere](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-on-a-vm-deployed-on-vsphere.md)
- [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
- [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
- [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
- [Optimize performance and robustness from the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/optimize-performance-and-robustness-from-the-textual-ui.md): Configure system performance optimization from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Troubleshoot your installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation.md): Troubleshoot the installation from the textual UI menu by launching the web console from your VM or by SSH login from an external terminal.
- [Common installation limitations and fixes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/common-installation-limitations-and-fixes.md): Troubleshoot common Cortex XSOAR installation issues.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
- [Upload your license to the textual UI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/upload-your-license-to-the-textual-ui.md): Upload your license to the VM textual UI menu for a support session.
- [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/troubleshoot-your-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
- [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/onboard-cortex-xsoar/cortex-xsoar-installation/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
- [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
- [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/use-nginx-as-a-reverse-proxy.md)
- [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy/configure-an-engine-to-use-custom-certificates.md)
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
- [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
- [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
- [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
- [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
- [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
- [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
- [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
- [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
- [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
- [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
- [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Azure AD as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-azure-ad-as-the-identity-provider-using-saml-2.0.md)
- [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
- [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
- [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
- [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
- [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
- [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
- [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
- [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/manage-credentials.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
- [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
- [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
- [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
- [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
- [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
- [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
- [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
- [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
- [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
- [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
- [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
- [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
- [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
- [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
- [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
- [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
- [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
- [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
- [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
- [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
- [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
- [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
- [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
- [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
- [Task 1. Choose from out-of-the-box playbooks or customize your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-out-of-the-box-playbooks-or-customize-your-own.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md)
- [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
- [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
- [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
- [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
- [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
- [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
- [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
- [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
- [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
- [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
- [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
- [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM.
- [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
- [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
- [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
- [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
- [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
- [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
- [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
- [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
- [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
- [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
- [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
- [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
- [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
- [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
- [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
- [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
- [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
- [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
- [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
- [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
- [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
- [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
- [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
- [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
- [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
- [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
- [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
- [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
- [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
- [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
- [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Export incidents to an Excel or CSV file.
- [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
- [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
- [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
- [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
- [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
- [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
- [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
- [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
- [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
- [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
- [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
- [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
- [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
- [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
- [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
- [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
- [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
- [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
- [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, accessing and using Unit 42 Intel data, investigating an indicator and creating indicator relationships.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
- [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
- [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
- [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
- [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
- [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
- [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
- [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
- [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
- [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
- [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
- [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
- [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
- [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
- [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
- [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.

* [Navigate the Cortex XSOAR 8.6 On-prem docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 8.6 On-prem documentation areas.
* [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
* [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
* [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
* [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
* [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
* [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
* [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/supported-web-browsers.md)
* [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
* [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
* [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
* [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, including system requirements, and adding a license.
* [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
* [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
* [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
* [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
* [What is content?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/what-is-content.md): What content includes in Cortex XSOAR.
* [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment.md)
* [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication.md)
* [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings.md)
* [Cortex XSOAR Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
* [Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/installation.md): Download the image files from the Cortex Gateway and install Cortex XSOAR on your machine.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
* [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
* [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
* [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
* [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
* [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/high-availability-for-cortex-xsoar.md)
* [Install Cortex XSOAR from an OVA image](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-from-an-ova-image.md): Download an OVA image from Cortex Gateway, deploy the image, and use the textual user interface to configure network, IP, and environment settings, and to install a Cortex XSOAR tenant.
* [Install Cortex XSOAR from a VHD image](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-from-a-vhd-image.md): Download a VHD image from Cortex Gateway, deploy the image, and use the textual user interface to configure network, IP, and environment settings, and to install a Cortex XSOAR tenant.
* [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
* [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
* [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
* [Manage nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/manage-nodes-in-a-cluster.md): Add, drain, remove, taint, or uncordon a node in a cluster under the Cluster Administration textual UI menu item.
* [Scale up hardware resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/scale-up-hardware-resources.md): The Scale Settings textual UI menu item enables scaling up resources for CPU, memory, and disk size.
* [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
* [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
* [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/onboard-cortex-xsoar/cortex-xsoar-installation/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
* [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
* [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/what-is-an-engine.md)
* [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
* [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy, and configure Cortex XSOAR engines.
* [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
* [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
* [Install Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker.md)
* [Install Docker distribution for Red Hat on an engine server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/install-docker-distribution-for-red-hat-on-an-engine-server.md)
* [Docker image security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/docker-image-security.md)
* [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/use-the-cortex-xsoar-container-registry.md)
* [Docker FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/docker-faqs.md)
* [Troubleshoot Docker issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/troubleshoot-docker-issues.md)
* [Configure Docker pull rate limit](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-pull-rate-limit.md)
* [Change the Docker installation folder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/change-the-docker-installation-folder.md)
* [Configure Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/configure-docker-integrations-to-trust-custom-certificates.md)
* [Configure Python Docker integrations to trust custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/configure-python-docker-integrations-to-trust-custom-certificates.md)
* [Docker hardening guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/docker/docker-hardening-guide.md)
* [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
* [Change container storage directory](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/podman/change-container-storage-directory.md)
* [Install Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/podman/install-podman.md)
* [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/podman/migrate-from-docker-to-podman.md)
* [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/install-an-engine/podman/troubleshoot-podman.md)
* [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
* [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
* [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
* [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
* [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
* [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
* [Use NGINX as a reverse proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/configure-engines/use-nginx-as-a-reverse-proxy.md)
* [Configure an engine to use custom certificates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
* [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
* [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
* [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
* [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
* [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
* [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
* [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
* [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
* [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
* [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
* [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
* [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
* [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
* [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR .
* [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
* [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
* [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
* [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
* [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
* [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
* [Set up Azure AD as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-azure-ad-as-the-identity-provider-using-saml-2.0.md)
* [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
* [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
* [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
* [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
* [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
* [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
* [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
* [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
* [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
* [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
* [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
* [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
* [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
* [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
* [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
* [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
* [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
* [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
* [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
* [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/manage-credentials.md)
* [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
* [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
* [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
* [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
* [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
* [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
* [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
* [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
* [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
* [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
* [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
* [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
* [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
* [Incident field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/incident-field-trigger-scripts.md)
* [Create dynamic fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/create-dynamic-fields.md)
* [Troubleshoot incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field/troubleshoot-incident-fields.md)
* [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
* [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
* [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
* [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
* [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
* [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
* [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
* [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
* [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
* [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
* [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
* [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
* [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
* [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
* [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
* [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
* [Task 1. Choose from out-of-the-box playbooks or customize your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-out-of-the-box-playbooks-or-customize-your-own.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Set playbook inputs and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/set-playbook-inputs-and-outputs.md)
* [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-section-header.md)
* [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-standard-task.md)
* [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-conditional-task.md)
* [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md)
* [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md)
* [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
* [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
* [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
* [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
* [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
* [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
* [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
* [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
* [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
* [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
* [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
* [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
* [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
* [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
* [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
* [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
* [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
* [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
* [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
* [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
* [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
* [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
* [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
* [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
* [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
* [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM.
* [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
* [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
* [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
* [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
* [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
* [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
* [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
* [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
* [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
* [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Default dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/dashboards/default-dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
* [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
* [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
* [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
* [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report.
* [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
* [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
* [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
* [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
* [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
* [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
* [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
* [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
* [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
* [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
* [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
* [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
* [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
* [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
* [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
* [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
* [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
* [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Export incidents to an Excel or CSV file.
* [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
* [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
* [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
* [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
* [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
* [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
* [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
* [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
* [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
* [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
* [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
* [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
* [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
* [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
* [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
* [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
* [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
* [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
* [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
* [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
* [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
* [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
* [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type.md)
* [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-type-profile.md)
* [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/file-indicators.md)
* [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/formatting-scripts.md)
* [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/enhancement-scripts.md)
* [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-scripts.md)
* [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-commands.md)
* [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/map-custom-indicator-fields.md)
* [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field.md)
* [Indicator fields structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-fields-structure.md)
* [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-field-trigger-scripts.md)
* [Indicator layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-layout-customization.md)
* [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
* [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
* [Indicator extraction modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/indicator-extraction-modes.md)
* [Create indicator extraction rules for an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md)
* [Set the indicator extraction mode for a playbook task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/set-the-indicator-extraction-mode-for-a-playbook-task.md)
* [Disable indicator extraction for scripts or integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/disable-indicator-extraction-for-scripts-or-integrations.md)
* [Troubleshoot indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction/troubleshoot-indicator-extraction.md)
* [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
* [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
* [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
* [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
* [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
* [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
* [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
* [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
* [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, accessing and using Unit 42 Intel data, investigating an indicator and creating indicator relationships.
* [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
* [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
* [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
* [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
* [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
* [View system status in the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
* [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
* [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
* [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
* [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
* [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR.
* [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
* [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
* [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
* [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
* [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
* [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
* [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
* [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
* [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
* [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
* [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.

- [Navigate the Cortex XSOAR On-prem 8.5 docs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 8.9 On-prem documentation areas.
- [Get Started with Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/get-started-with-cortex-xsoar.md): View information about how to get started with Cortex XSOAR On-prem such as architecture, roles and responsibilities, and licenses.
- [What is Cortex XSOAR?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/what-is-cortex-xsoar.md): Learn about Cortex XSOAR features.
- [Cortex XSOAR architecture](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-architecture.md): Describes the XSOAR On-prem architecture.
- [Cortex XSOAR use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/cortex-xsoar-use-cases.md): Recommended ways to automate your SOC in Cortex XSOAR.
- [Understand Cortex XSOAR licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/understand-cortex-xsoar-licenses.md): The Cortex XSOAR license is downloaded from Cortex Gateway and determines which components users can use and how many users can access the tenant.
- [Roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/supported-web-browsers.md)
- [Onboard and configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar.md): Follow the steps to successfully onboard and configure Cortex XSOAR On-prem
- [Plan your deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/plan-your-deployment.md): Learn more about deployment considerations and onboarding steps for Cortex XSOAR.
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/onboarding-checklist.md): Activate, provision, grant access, and configure Cortex XSOAR.
- [Step 1. Install Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-1.-install-cortex-xsoar.md): Learn how to install Cortex XSOAR On-prem, view system requirements, and add a license.
- [Step 2. Set up an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-2.-set-up-an-engine.md): Set up a Cortex XSOAR engine on a remote machine.
- [Step 3. Set up a remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-3.-set-up-a-remote-repository.md): Set up a content management system with a development environment to create and test content before using it in a production environment.
- [Step 4. Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-4.-set-up-users-and-roles.md): View the permissions, and predefined roles in Cortex XSOAR On-prem
- [Step 5. Install and configure content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content.md): What content includes in Cortex XSOAR.
- [What is content?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/what-is-content.md): What content includes in Cortex XSOAR.
- [Install content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/install-content-packs.md): Install a content pack
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/step-5.-install-and-configure-content/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Post deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment.md)
- [User communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/user-communication.md)
- [Configure system settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/onboard-and-configure-cortex-xsoar/post-deployment/configure-system-settings.md)
- [Cortex XSOAR Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation.md): Install Cortex XSOAR On-prem and complete post-installation steps. Learn how to upgrade Cortex XSOAR.
- [Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/installation.md): Download the image files from the Cortex Gateway and then install Cortex XSOAR on your machine.
- [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
- [Hardware requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
- [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/port-requirements-for-cluster-communication.md): Add the required ports when installing Cortex XSOAR On-prem.
- [URL requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
- [Bandwidth and NTP requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/system-requirements/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.
- [High Availability for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/high-availability-for-cortex-xsoar.md)
- [Install Cortex XSOAR from an OVA image](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-from-an-ova-image.md): Download an OVA image from Cortex Gateway, deploy the image, and use the textual user interface to configure network, IP, and environment settings, and to install a Cortex XSOAR tenant.
- [Install Cortex XSOAR from a VHD image](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/install-cortex-xsoar-from-a-vhd-image.md): Download a VHD image from Cortex Gateway, deploy the image, and use the textual user interface to configure network, IP, and environment settings, and to install a Cortex XSOAR tenant.
- [Post-installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation.md): After installation, add your license to Cortex XSOAR, set up a signed certificate, and perform optional post-installation maintenance activities from the VM textual UI menu.
- [Add the Cortex XSOAR license](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/add-the-cortex-xsoar-license.md): Download the Cortex XSOAR license from Cortex Gateway. The license determines which components users can use and how many users can access the tenant.
- [HTTPS with a signed certificate](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/https-with-a-signed-certificate.md): Use HTTPS with a signed certificate in Cortex XSOAR. Concatenate the certificate chain.
- [Manage nodes in a cluster](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/manage-nodes-in-a-cluster.md): Add, drain, remove, taint, or uncordon a node in a cluster under the Cluster Administration textual UI menu item.
- [Scale up hardware resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/scale-up-hardware-resources.md): The Scale Settings textual UI menu item enables scaling up resources for CPU, memory, and disk size.
- [Open a support session](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/open-a-support-session.md): Open a support session from the VM textual UI menu.
- [Shut down Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/post-installation/shut-down-cortex-xsoar.md): Shut down a session from the VM textual UI menu.
- [Update Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/onboard-cortex-xsoar/cortex-xsoar-installation/update-cortex-xsoar.md): Upgrade your Cortex XSOAR On-prem tenant to the latest version.
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot engines.
- [What is an engine?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/what-is-an-engine.md)
- [Engine requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/engine-requirements.md): Hardware, OS, and required URLs for engines.
- [Install an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/install-an-engine.md): Install, deploy and configure Cortex XSOAR engines.
- [Engine air gap installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/install-an-engine/engine-air-gap-installation.md): Install a Cortex XSOAR engine offline when you don’t have access to the Internet (tested on RHEL v8).
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/install-an-engine/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/install-an-engine/podman.md): Run Podman containers instead of Docker for RHEL v8.
- [Manage engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/manage-engines.md): Manage engines and load-balancing groups.
- [Upgrade an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/upgrade-an-engine.md): Upgrade an engine on Cortex XSOAR or directly on the remote machine.
- [Remove an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Configure engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines by editing the d1.conf file or modifying the configuration in the UI (for shell installations).
- [Configure the engine to use a web proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md): Configure a Cortex XSOAR engine to use a web proxy by editing the d1.conf file.
- [Configure the engine to call the server without using a proxy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md): Configure an engine to call the server without using a proxy.
- [Use an engine in an integration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
- [Run a script using an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Troubleshoot engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Troubleshoot integrations running on engines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/engines/troubleshoot-integrations-running-on-engines.md)
- [Remote Repository Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/remote-repository-management.md): Configure and manage a remote repository in your dev/prod setup in Cortex XSOAR On-prem
- [Content management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/remote-repository-management/content-management-in-cortex-xsoar.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
- [Set up a private remote repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/remote-repository-management/set-up-a-private-remote-repository.md): Set up the private content repository feature.
- [Push content from a development tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/remote-repository-management/push-content-from-a-development-tenant.md): Push content to a remote repository and control access for pushing content.
- [Install content on a production tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/remote-repository-management/install-content-on-a-production-tenant.md): Install new content that has been pushed from the development tenant to the production tenant.
- [Remote repository troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/remote-repository-management/remote-repository-troubleshooting.md): Scenarios that occur when managing content with a remote repository in Cortex XSOAR.
- [Users and Roles Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management.md): Configure and manage roles, users, and user groups, and set up authentication in Cortex XSOAR On-prem.
- [Users and roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md): Set up and configure roles and user groups in Cortex XSOAR. Configure authentication, and manage and create users.
- [Roles management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/roles-management.md): Configure roles in the Cortex XSOAR tenant.
- [Role-based permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions.md): Describes the role-based permissions available in Cortex XSOAR.
- [Manage roles in the Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/roles-management/manage-roles-in-the-cortex-xsoar-tenant.md): Manage roles in Cortex XSOAR tenant.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/set-up-authentication.md): Decide whether you want to add users locally or through SSO in Cortex XSOAR On-prem.
- [Create users in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/create-users-in-cortex-xsoar.md): Create users in Cortex XSOAR on-prem by inviting users to access Cortex XSOAR using their username and password.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XSOAR tenant using SSO.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Azure AD as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-azure-ad-as-the-identity-provider-using-saml-2.0.md)
- [User management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/user-management.md): Invite users to the platform and set user roles and user groups in Cortex XSOAR On-prem.
- [Configure a password policy](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/users-and-roles-management/configure-a-password-policy.md): Configure and edit the Cortex XSOAR password policy
- [Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace.md): In Marketplace, download your content packs to suit your use case in Cortex XSOAR.
- [Cortex Marketplace](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/cortex-marketplace.md): Search the Cortex Marketplace and find content. Search by use cases, integrations, and categories.
- [Content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/content-packs.md): Download content packs in Marketplace for your use case.
- [Content Pack Support Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/content-pack-support-types.md): Types of content packs support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Manage content packs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/manage-content-packs.md): Install, delete, update, and revert content packs.
- [Set up your use case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/set-up-your-use-case-with-the-deployment-wizard.md): The Deployment Wizard guides you step-by-step to quickly adopt your use case.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
- [Content pack update notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs.
- [Customize content pack notifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md): Customize the frequency and time of content pack update notifications and how much information is included.
- [Content pack contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
- [Create a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md): Create a content pack and submit it to Cortex XSOAR for approval. Add your content pack to Marketplace.
- [Resubmit a content pack](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md): Resubmit an existing content pack with new changes from the Cortex XSOAR UI.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations.md): Configure integrations, manage credentials, run commands, and troubleshoot integrations in Cortex XSOAR On-prem
- [Integration use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/integration-use-cases.md): Common integration use cases for Cortex XSOAR, including analytics and SIEM, authentication, case management, data enrichment, threat intelligence, forensic and malware,
- [Configure integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/configure-integrations.md): Configure an integration including creating your own integration
- [Change the Docker image in an integration or script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
- [Connect your engine to an image registry](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/change-the-docker-image-in-an-integration-or-script/connect-your-engine-to-an-image-registry.md): Connect via an engine to your own authenticated Docker image registry.
- [Manage credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/manage-credentials.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/add-an-integration-instance.md): Set up an integration instance and start ingesting incidents/indicators.
- [Fetch incidents from an integration instance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/add-an-integration-instance/fetch-incidents-from-an-integration-instance.md): Configure a third-party integration instance to fetch incidents into Cortex XSOAR incidents for investigation.
- [Receive notifications on an incident fetch error](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/add-an-integration-instance/receive-notifications-on-an-incident-fetch-error.md): Add a server configuration to receive notifications if an integration experiences an incident fetch error.
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md): Integration permissions enable you to restrict running commands to specific roles in integrations.
- [Troubleshoot integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/add-an-integration-instance/troubleshoot-integrations.md): Learn how to troubleshoot your integration in Cortex XSOAR.
- [Integration commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/integration-commands-in-the-cli.md): Run integration commands in the CLI.
- [Forward requests to long-running integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/integrations/forward-requests-to-long-running-integrations.md): Configure and manage long-running integrations to export internal data from Cortex XSOAR.
- [Incident configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration.md): Customize how the incident appears, add deduplication rules, and add any other customizations you require for your workflow.
- [Incident lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/incident-lifecycle.md): An incident goes through various processes in Cortex XSOAR including defining an incident, classification and mapping, pre and post-processing, and running a playbook.
- [Incident Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/incident-customization.md): Create and edit incident types, fields, and layouts in Cortex XSOAR.
- [Use incident context data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/incident-customization/use-incident-context-data.md): Use context data to customize your incident layout and to populate your incidents in Cortex XSOAR.
- [Create an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-type.md): Create and edit incident types in Cortex XSOAR.
- [Create an incident field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/incident-customization/create-an-incident-field.md): Create custom incident fields in Cortex XSOAR.
- [Incident layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/incident-customization/incident-layout-customization.md): Customize incident layouts in Cortex XSOAR to view relevant information.
- [Classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/classification-and-mapping.md): Classify and map an integration instance.
- [Create an incident classifier](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-classifier.md): Classify events using a classification key in an integration ingestion. Create incident classifier in Cortex XSOAR
- [Create an incident mapper](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/classification-and-mapping/create-an-incident-mapper.md): Create a mapper and apply it to an integration in Cortex XSOAR.
- [Set up incident mirroring](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/set-up-incident-mirroring.md): Set up integrations such as ServiceNow v2 to mirror ServiceNow incidents to Cortex XSOAR.
- [Incident deduplication in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/incident-deduplication-in-cortex-xsoar.md): Deduplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
- [Pre-process rules](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
- [Use post-processing scripts in an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/use-post-processing-scripts-in-an-incident.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR
- [Customize incident close reasons](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
- [Configure inline value fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/configure-inline-value-fields.md): Remove the checkmark when an analyst edits specific fields in a layout.
- [Export an incident to CSV using the UTF8-BOM format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/incident-configuration/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format. Server configuration.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks.md): Playbooks are a series of tasks, conditions, automation, commands, and loops that run in a predefined flow, which are at the heart of the Cortex XSOAR system.
- [What is a playbook?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/what-is-a-playbook.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
- [Playbook development checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/playbook-development-checklist.md): Follow the playbook development flow to create playbooks that structure and automate many of your security processes.
- [Plan your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/plan-your-playbook.md): Considerations when planning your playbook.
- [Develop your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook.md): Create a new playbook or customize an existing one based on your organization's needs.
- [Task 1. Choose from out-of-the-box playbooks or customize your own](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-1.-choose-from-out-of-the-box-playbooks-or-customize-your-own.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 2. Configure playbook settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-2.-configure-playbook-settings.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 3. Add tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Set playbook inputs and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/set-playbook-inputs-and-outputs.md)
- [Create a section header](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-section-header.md)
- [Create a standard task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-standard-task.md)
- [Create a conditional task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-conditional-task.md)
- [Create a communication task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/create-a-communication-task.md)
- [Configure script error handling in a playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md)
- [Task 4. Add custom playbook features](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-4.-add-custom-playbook-features.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 5. Test and debug the playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-5.-test-and-debug-the-playbook.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Task 6. Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/task-6.-manage-playbook-content.md): Use an out-of-the-box playbook, create a new playbook, or customize an existing one based on your organization's needs.
- [Customize a playbook for a phishing use case example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/develop-your-playbook/customize-a-playbook-for-a-phishing-use-case-example.md): Customize an existing playbook based on your organization's needs.
- [Customize your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook.md): Customize your playbook to extract indicators, extend context, add incident fields, filter and transform data, run scripts, and perform triggered actions, sub-playbook loops, and polling.
- [Customize the SOC name](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks.
- [Configure a sub-playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook/configure-a-sub-playbook.md): Configure a sub-playbook, also to run in a loop.
- [Filter and transform data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook/filter-and-transform-data.md): Use filters and transformers to manipulate data. Use filters and transformers in playbook tasks or when mapping an instance.
- [Extract indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook/extract-indicators.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Extend context](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
- [Set and update incident fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md): Use the setIncident script to set and update all system incident fields.
- [Playbook polling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/customize-your-playbook/playbook-polling.md): Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/scripts.md): Create and edit a script, including detaching and attaching, and automation settings.
- [Create a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/scripts/create-a-script.md): Create or edit an out-of-the-box script, including detach and attach and automation settings.
- [Debug your playbook](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/debug-your-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the playbook debugger.
- [Troubleshoot playbook performance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/debug-your-playbook/troubleshoot-playbook-performance.md): Obtain playbook metadata to troubleshoot performance issues.
- [Manage playbook content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/manage-playbook-content.md): Manage playbook content by either using a remote repository, or by saving versions of your playbook.
- [Best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/playbooks/best-practices.md): Best practices for building and working with playbooks.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/lists.md): Create and manage lists and add them to your playbook or script.
- [What is a list?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/lists/what-is-a-list.md): Create and manage lists in Cortex XSOAR.
- [Create a list](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/lists/create-a-list.md): Create a list that can be accessed later such as in a playbook script or managed in the CLI.
- [List commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/lists/list-commands.md): Use list commands in the CLI, playbooks, and scripts
- [Use cases: JSON lists](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/lists/use-cases-json-lists.md): Manage JSON lists in Cortex XSOAR that can be accessed by automations, playbooks, etc. List commands, lists arrays separators delimiters
- [Transform a list into an array](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an integration instance in Cortex XSOAR.
- [Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/jobs.md): Create a time-triggered job or event-triggered job to run a playbook
- [Manage jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/jobs/manage-jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
- [Create a time triggered job](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
- [Create a job triggered by a delta in a feed](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-a-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
- [Create jobs to process indicators example](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/jobs/create-jobs-to-process-indicators-example.md): Provides an example of a job triggered by a delta in a feed to process incoming indicators and a time triggered job to push indicators to a SIEM.
- [SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas.md): SLAs enable you to define specific goals and responsibilities and improve quality and availability in your investigations.
- [SLAs in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/slas-in-cortex-xsoar.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
- [Configure an SLA in an incident type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/configure-an-sla-in-an-incident-type.md): Add SLA time/date to an incident type.
- [Configure Timer/SLA fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/configure-timersla-fields.md): Create a new SLA or timer and add an SLA script to trigger when SLA time has passed.
- [Configure a playbook to run Timers/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/configure-a-playbook-to-run-timersslas.md): Add or configure a playbook to run SLA timers.
- [Automate changes to incident fields using SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/automate-changes-to-incident-fields-using-sla-scripts.md): Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Create SLA scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/create-sla-scripts.md): Create scripts that perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Use SLA and Timer field commands manually in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/use-sla-and-timer-field-commands-manually-in-the-cli.md): Use timers and SLA commands for a specific incident, such as decreasing the required response time for a high-priority incident.
- [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change the SLA Risk threshold from the default 72 hours.
- [Search incidents for Timer/SLAs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/slas/search-incidents-for-timerslas.md): Search incidents based on their SLA status, a SLA field, or a timer field.
- [Dashboards and Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports.md): Create, edit, and share dashboards and reports in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
- [Dashboard actions](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
- [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/dashboards/manage-dashboards.md): Create and customize a dashboard in Cortex XSOAR, including adding widgets to a dashboard. Share a dashboard.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
- [Manage reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/reports/manage-reports.md): Create a new report or customize an existing report in Cortex XSOAR, including adding widgets and changing the timezone and time format in a report. Schedule and generate a report.
- [Configure the timezone in a report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/reports/configure-the-timezone-in-a-report.md): Change the timezone and time format in a report for report troubleshooting.
- [Troubleshoot script timeout for reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-script-timeout-for-reports.md): Change default timeout value for Cortex XSOAR reports, using a server configuration.
- [Troubleshoot overlapping text and extra pages](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/reports/troubleshoot-overlapping-text-and-extra-pages.md): Fix overlapping text and extra pages in PDF reports
- [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboards.
- [Widget customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/widget-customization.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
- [Create a widget using the widget builder](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in and then add the widget to a dashboard or report.
- [Create a custom widget using a JSON file](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
- [Create a custom widget using a script](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-custom-widget-using-a-script.md): Create a custom script based widget in using a script. Use custom widgets in dashboards and reports.
- [Create a widget from an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md): Create a custom widget from an incident search in Cortex XSOAR.
- [Create a widget from an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-indicator.md): Create a custom widget from an indicator and add it a dashboard or report in Cortex XSOAR.
- [Edit a widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
- [Add a widget in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/add-a-widget-in-the-war-room.md): Add a script-based widget in the War Room in Cortex XSOAR.
- [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/configure-cortex-xsoar/dashboards-and-reports/widgets/saved-by-dbot-roi-widget.md): Customize the Saved by Dbot widget that calculates the amount saved by Cortex XSOAR. Return on Investment (ROI) widget.
- [Incidents and indicators investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation.md): Investigate incidents and indicators that have been ingested into Cortex XSOAR.
- [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incidents.md): Incidents are potential security data threats that are ingested or created in Cortex XSOAR for investigation and remediation.
- [Incident management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md): View and manage incidents in Cortex XSOAR.
- [Search for incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/search-for-incidents.md): Create a search query for incidents and save search queries.
- [Create an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md): Create a new incident manually, through the API, ingest incidents, or import a JSON file.
- [Export incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md): Export incidents to an Excel or CSV file.
- [Investigate an incident](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md): Investigate and take remediation steps in Cortex XSOAR.
- [Retain incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md): Retain up to 1000 incidents.
- [Limit access to investigations using access control](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md): Limit access to incidents and investigations in Cortex XSOAR.
- [Incident Tasks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
- [Use the War Room in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md): Use the War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
- [Schedule a command in the War Room](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md)
- [Run commands in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/run-commands-in-the-cli.md): Cortex XSOAR enables you to run system commands, integration commands, scripts, and more, from an integrated CLI.
- [Evidence Handling](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the War Room by adding tags.
- [Use the Work Plan in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md): A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a Playbook workflow.
- [Investigate an incident using the canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/investigate-an-incident-using-the-canvas.md)
- [Link incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/link-incidents.md): Link incidents in the Linked Incidents section or the CLI.
- [Create an incident summary report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
- [Manage indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Indicators (no TIM license).
- [Query indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/query-indicators.md): How to query indicators in the threat intel library (without a TIM license).
- [View indicator relationships in an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/manage-indicators/view-indicator-relationships-in-an-investigation.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management.md): Cortex XSOAR Threat Intel Management includes features such as managing indicator relationships, enriching indicators, customizing indicator layouts, and managing TIM reports.
- [Get started with Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
- [Licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/licenses.md): Learn how to use TIM in your investigation, utilizing Unit 42 Intel in your investigation.
- [What is Threat Intel Management?](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/what-is-threat-intel-management.md): Why use TIM with use cases.
- [Threat Intel Management use cases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/threat-intel-management-use-cases.md): Typical use cases for analysts and how to set up the use cases by administrators.
- [Indicator concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-concepts.md)
- [Indicator lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/indicator-lifecycle.md): Indicators are artifacts associated with incidents and are an essential part of the incident management and remediation process.
- [Roles and responsibilities in Threat Intel Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/get-started-with-threat-intel-management/roles-and-responsibilities-in-threat-intel-management.md): Roles and responsibilities in a Threat Intel Management environment.
- [Indicator configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration.md): Create indicator types, fields, and layouts, customize the exclusion list, indicator reputation, and indicator extraction.
- [Customize indicator types, fields, and layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts.md): Learn more about the options available for customizing indicators.
- [Create an indicator type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-type.md): Create and configure custom indicator types in Cortex XSOAR.
- [Indicator type profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-type-profile.md): Configure indicator type settings, scripts, and enrichment behavior.
- [File indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/file-indicators.md): Configure file indicators and supported hash types.
- [Formatting scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/formatting-scripts.md): Format indicator values after extraction.
- [Enhancement scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/enhancement-scripts.md): Enrich indicators with additional data using scripts.
- [Reputation scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-scripts.md): Calculate indicator reputation using scripts.
- [Reputation commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/reputation-commands.md): Configure commands that retrieve indicator reputation.
- [Map custom indicator fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/map-custom-indicator-fields.md): Map context data to custom indicator fields.
- [Create an indicator field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field.md): Create and configure custom indicator fields.
- [Indicator fields structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-fields-structure.md): Reference the structure of indicator fields.
- [Indicator field trigger scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/create-an-indicator-field/indicator-field-trigger-scripts.md): Run actions when indicator field values change.
- [Indicator layout customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/customize-indicator-types-fields-and-layouts/indicator-layout-customization.md): Customize layouts for indicator types.
- [Indicator classification and mapping](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-classification-and-mapping.md): Learn about the classification and mapping for indicators.
- [Indicator extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/indicator-extraction.md): Extract indicators from Cortex XSOAR incident fields and enrich them with commands and scripts defined for the indicator type.
- [Configure the indicator timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
- [Configure indicator expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a specific period or never to expire. Set default expiration method.
- [Configure Threat Intel feed integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md)
- [Configure Threat Intelligence Management playbooks to process indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intelligence-management-playbooks-to-process-indicators.md): Jobs trigger TIM playbooks and process large numbers of indicators. TIM playbook configuration and settings.
- [Export indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/export-indicators.md): Export indicators from the Indicators table, using an integration, or playbook, or set up an External Dynamic list (EDL) by using the Generic Export Indicators integration.
- [Customize Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports.md): Set up and customize threat intel report types in Cortex XSOAR.
- [Create a Threat Intel Report type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-type.md): Create or detach a Threat Intel Report type to suit your use case.
- [Create a Threat Intel Report field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-field.md): Create a Threat Intel Report and add it to a report layout.
- [Create a Threat Intel Report layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/customize-threat-intel-reports/create-a-threat-intel-report-layout.md): Configure threat intel report layouts. Add script-based content in the layout.
- [Indicator management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Query indicators with Unit 42 Intel data](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators-with-unit-42-intel-data.md): How to query indicators in the threat intel library and in Unit 42 Intel.
- [Indicator investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation.md): Learn how to use TIM in your use case, such as creating a TIM report, accessing and using Unit 42 Intel data, investigating an indicator and creating indicator relationships.
- [Indicator verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts, exclusion lists, and indicator verdicts.
- [Extract and enrich an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/extract-and-enrich-an-indicator.md): How to extract and enrich an indicator in Cortex XSOAR.
- [Expire an indicator](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/expire-an-indicator.md): Expire an indicator in the CLI or in the UI.
- [Manage indicator relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/manage-indicator-relationships.md): How to use and create indicator relationships in Cortex XSOAR and how it benefits an investigation.
- [Delete and exclude indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/delete-and-exclude-indicators.md): Indicators added to an exclusion list are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
- [Investigate files using sample analysis](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/investigate-files-using-sample-analysis.md): View static and dynamic analysis of file samples to identify malware, investigate trends, and create reports.
- [Use sessions and submissions in your investigation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-investigation/use-sessions-and-submissions-in-your-investigation.md): Use firewall sessions and submissions to products such as Prisma Cloud, and Prisma Access with Cortex XSOAR, to find threats and protect your network.
- [Manage Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/manage-threat-intel-reports.md): An overview of working with threat intel reports in Cortex XSOAR.
- [Troubleshoot](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/troubleshoot.md): Troubleshoot errors in Cortex XSOAR On-prem.
- [View system status on the System Diagnostics page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/troubleshoot/view-system-status-in-the-system-diagnostics-page.md): View errors and take action on the System Diagnostics page for Cortex XSOAR On-prem.
- [View service limit errors and warnings in the Guard Rails page](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/troubleshoot/view-service-limit-errors-and-warnings-in-the-guard-rails-page.md): Use the Cortex XSOAR Guard Rails page to see details about service limit errors or warnings.
- [View Guard Rails warnings and errors](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/troubleshoot/view-guard-rails-warnings-and-errors.md): Use the Cortex XSOAR Guard Rails page to see details about errors or warnings that could affect system performance.
- [Access logs and log bundles](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md): View logs for monitoring system health and download log bundles for troubleshooting from the Cortex XSOAR System Diagnostics page or from your VM textual UI menu.
- [Management audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/troubleshoot/management-audit-logs.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
- [Integration logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/troubleshoot/integration-logs.md): View and export integration logs in Cortex XSOAR. Integration logs record integration details in Cortex XSOAR for troubleshooting.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference.md): Includes reference topics, such as a list of server configurations, and user details and preferences for Cortex XSOAR Cloud
- [Cortex XSOAR concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/cortex-xsoar-concepts.md): Common concepts in Cortex XSOAR.
- [How to search in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/how-to-search-in-cortex-xsoar.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
- [How to use markdown in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/how-to-use-markdown-in-cortex-xsoar.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
- [User details and preferences](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/user-details-and-preferences.md): Cortex XSOAR users can control user details and preferences, and notifications.
- [Server configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
- [New user FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/new-user-faq.md): New User FAQ for Cortex XSOAR.
- [Cortex XSOAR API](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/cortex-xsoar-api.md): Generate an API key and make your first API call.
- [Telemetry in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/telemetry-in-cortex-xsoar.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR.
- [Product support lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/product-support-lifecycle.md): Cortex XSOAR product support lifecycle.
- [Keyboard shortcuts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage playbooks, scripts, CLI, and incident pages.
- [Cortex XSOAR navigation cheat sheet](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/troubleshoot-and-reference/reference/cortex-xsoar-navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.

## Cortex XSOAR 8 FAQs

- [Cortex XSOAR 8 FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs.md): Frequently asked questions for Cortex XSOAR 8 SaaS and on-prem.
- [General information](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/general-information.md): General information about Cortex XSOAR 8.
- [Content Feature Requests](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/content-feature-requests.md): How to submit content feature requests for Cortex XSOAR.
- [Cortex XSOAR 8 SaaS FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs.md)
- [Customer Support Portal FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/customer-support-portal-faqs.md): Cortex XSOAR 8 SaaS FAQs for the CSP.
- [Cortex XSOAR 8 Updates](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/cortex-xsoar-8-updates.md): Describes the Cortex XSOAR 8 SaaS upgrade process.
- [Remote Content Repository (Dev/Prod)](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/remote-content-repository-dev-prod.md): Cortex XSOAR 8 SaaS FAQs for remote repositories.
- [Upgrade from Cortex XSOAR 6](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/upgrade-from-cortex-xsoar-6.md): Cortex XSOAR 8 FAQs for upgrades and migration from Cortex XSOAR 6.
- [MSSP and Multi-Tenancy Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/mssp-and-multi-tenancy-deployment.md): Cortex XSOAR 8 SaaS FAQs for MSSP and multi-tenant deployments.
- [Licensing & Pricing](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/licensing-and-pricing.md): Cortex XSOAR 8 Cloud FAQs for licensing and pricing.
- [Security](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/security.md): Cortex XSOAR 8 SaaS FAQs for security.
- [Backup and High Availability](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/backup-and-high-availability.md): Cortex XSOAR 8 SaaS FAQs for backup and high availability.
- [Regions and Locations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/regions-and-locations.md): Cortex XSOAR 8 SaaS FAQs for regions and locations.
- [Cortex XSOAR Tenant Health and Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/cortex-xsoar-tenant-health-and-troubleshooting.md): Cortex XSOAR 8 SaaS health monitoring and troubleshooting.
- [Access Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/access-management.md): Cortex XSOAR 8 SaaS FAQs for Access Management.
- [Cortex XSOAR Offboarding](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs/cortex-xsoar-offboarding.md): Cortex XSOAR 8 SaaS FAQs for offboarding.
- [Cortex XSOAR 8 On-Prem FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-on-prem-faqs.md): FAQs for Cortex XSOAR 8 on-prem.
- [Hardware Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-on-prem-faqs/hardware-requirements.md): View the hardware requirements when installing Cortex XSOAR On-prem.
- [Port requirements for cluster communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-on-prem-faqs/port-requirements-for-cluster-communication.md)
- [URL Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-on-prem-faqs/url-requirements.md): Add the required URLs for Cortex XSOAR On-prem.
- [Bandwidth and NTP Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-on-prem-faqs/bandwidth-and-ntp-requirements.md): The required bandwidth and node synchronization for Cortex XSOAR On-prem to operate properly.

## Cortex XSOAR 8 Feature Changes

- [Cortex XSOAR 8 Feature Changes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes.md): View the feature changes in Cortex XSOAR 8 Cloud and On-prem.
- [Comparison between Cortex XSOAR 6 and Cortex XSOAR 8](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/comparison-between-cortex-xsoar-6-and-cortex-xsoar-8.md): Compare features between Cortex XSOAR 6 and 8.
- [New Features for Users and Roles in Cortex XSOAR 8](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/new-features-for-users-and-roles-in-cortex-xsoar-8.md)
- [Integration Instance Changes in Cortex XSOAR 8](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/integration-instance-changes-in-cortex-xsoar-8.md)
- [Communication tasks through an engine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/integration-instance-changes-in-cortex-xsoar-8/communication-tasks-through-an-engine.md)
- [Cortex XSOAR 8 API Changes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/cortex-xsoar-8-api-changes.md)

## FS-ISAC STIX/TAXII Guide for Cortex XSOAR

- [FS-ISAC STIX/TAXII Guide for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/fs-isac-stix-taxii-guide-for-cortex-xsoar/fs-isac-stix-taxii-guide-for-cortex-xsoar.md)
- [Connect to the FS-ISAC IntelX Exchange in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/fs-isac-stix-taxii-guide-for-cortex-xsoar/fs-isac-stix-taxii-guide-for-cortex-xsoar/connect-to-the-fs-isac-intelx-exchange-in-cortex-xsoar.md): Learn how to connect to the FS-ISAC IntexX Exchange in Cortex XSOAR 8.

## Demisto SDK Development Guide

- [Introduction to Demisto SDK](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/readme.md): Introduction to the Demisto SDK Python library that assists with your content development needs.
- [Install Demisto SDK](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/install-demisto-sdk.md): How to install the Demisto SDK or upgrade it if it is already installed.
- [Environment variables setup](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/install-demisto-sdk/environment-variables-setup.md): Add environment variables for Cortex XSOAR and Cortex XSIAM.
- [Create a preset custom command configuration](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/install-demisto-sdk/create-a-preset-custom-command-configuration.md): Create a custom configuration for demisto-sdk commands.
- [Demisto SDK usage and configuration](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-usage-and-configuration.md)
- [Run the Demisto SDK in a Docker container](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-usage-and-configuration/run-the-demisto-sdk-in-a-docker-container.md): Run Demisto SDK validations from within a Docker container.
- [Using Docker](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-usage-and-configuration/using-docker.md): Use Docker to run Python scripts and integrations in a controlled environment.
- [Demisto SDK commands](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands.md): Learn about the arguments and usage of Demisto SDK commands to manage your content.
- [doc-review](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/doc-review.md)
- [download](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/download.md)
- [format](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/format.md)
- [generate-docs](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/generate-docs.md)
- [generate-integration](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/generate-integration.md)
- [generate-outputs](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/generate-outputs.md)
- [generate-test-playbook](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/generate-test-playbook.md)
- [generate-unit-tests](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/generate-unit-tests.md)
- [generate-yml-from-python](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/generate-yml-from-python.md)
- [graph commands](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/graph-commands.md)
- [init](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/init.md)
- [openapi-codegen](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/openapi-codegen.md)
- [postman-codegen](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/postman-codegen.md): The postman-codegen command generates an integration file (YAML) from a Postman Collection.
- [pre-commit](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/pre-commit.md)
- [prepare-content](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/prepare-content.md)
- [run](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/run.md)
- [run-playbook](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/run-playbook.md)
- [secrets](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/secrets.md)
- [setup-env](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/setup-env.md)
- [split](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/split.md)
- [update-release-notes](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/update-release-notes.md)
- [upload](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/upload.md)
- [validate](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/validate.md)
- [Validation checks](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/validate/validation-checks.md)
- [zip-packs](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/demisto-sdk-commands/zip-packs.md)
- [Contribute to the Demisto SDK](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/contribute-to-demisto-sdk.md)
- [How to Contribute](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/contribute-to-demisto-sdk/how-to-contribute.md)

## Cortex XSOAR Migration Guide

- [Navigate the Cortex XSOAR 8 Migration docs](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/learn-about-cortex-xsoar-migration/navigate-the-cortex-xsoar-8-migration-docs.md): Start here for a visual overview of the main Cortex XSOAR documentation areas.
- [Introduction to Cortex XSOAR 8 migration](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/learn-about-cortex-xsoar-migration/readme.md): Learn about migrating from Cortex XSOAR 6 to Cortex XSOAR 8.
- [Migrate Cortex XSOAR 6 On-prem to Cortex XSOAR 8 SaaS](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/learn-about-cortex-xsoar-migration/migrate-cortex-xsoar-6-on-prem-to-cortex-xsoar-8-saas.md): Migrate from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS (Enterprise or multi-tenant).
- [How to migrate from Cortex XSOAR 6 On-prem to Cortex XSOAR 8 SaaS](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/how-to-migrate-from-cortex-xsoar-6-on-prem-to-cortex-xsoar-8-saas.md): Learn how to migrate from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS.
- [Migration FAQs - XSOAR 6 On-Prem to XSOAR 8 SaaS](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migration-faqs-xsoar-6-on-prem-to-xsoar-8-saas.md): Frequently asked questions about the migration from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS.
- [Migration Prerequisites for Cortex XSOAR 8 SaaS](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migration-prerequisites-for-cortex-xsoar-8-saas.md): Before you start the migration, review the users' process and other requirements.
- [Migrate from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS (Self-Service)](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-self-service.md): Migrate manually from Cortex XSOAR 6 On-prem to XSOAR 8 SaaS (not using the wizard).
- [Migrate from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS using the pre-migration and migration wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard.md): Use the wizards to migrate your data from Cortex XSOAR 6 to 8.
- [Step 1. Activate the Cortex XSOAR 8 tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-1.-activate-the-cortex-xsoar-8-tenant.md)
- [Step 2. Set up the Cortex XSOAR 8 tenant using the pre-migration wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-2.-set-up-the-cortex-xsoar-8-tenant-using-the-pre-migration-wizard.md)
- [Configure a remote repository using the pre-migration wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-2.-set-up-the-cortex-xsoar-8-tenant-using-the-pre-migration-wizard/configure-a-remote-repository-using-the-pre-migration-wizard.md)
- [Step 3. Run user acceptance tests (UAT) using the migration wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard.md)
- [Incidents and Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/incidents-and-indicators.md)
- [Users, User Groups, and Roles](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/users-user-groups-and-roles.md)
- [Security and Authentication](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/security-and-authentication.md)
- [Engines](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/engines.md)
- [Remote Repositories](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/remote-repositories.md)
- [Jobs](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/jobs.md)
- [Integration Instance Configuration Changes](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/integration-instance-configuration-changes.md)
- [Mail Sender Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/integration-instance-configuration-changes/mail-sender-configuration.md)
- [Long Running Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/integration-instance-configuration-changes/long-running-integrations.md)
- [API Keys in Cortex XSOAR 8](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/api-keys-in-cortex-xsoar-8.md)
- [Syslog Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-3.-run-user-acceptance-tests-uat-using-the-migration-wizard/syslog-configuration.md)
- [Step 4. Select whether to resync data and set the switchover date](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/step-4.-select-whether-to-resync-data-and-set-the-switchover-date.md)
- [Post Migration Steps for Cortex XSOAR 6 On-prem to 8 SaaS](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard/post-migration-steps-for-cortex-xsoar-6-on-prem-to-8-saas.md)
- [How to migrate your Multi-Tenant Deployment from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/how-to-migrate-your-multi-tenant-deployment-from-cortex-xsoar-6-to-cortex-xsoar-8-saas.md): Learn how to migrate from Cortex XSOAR 6 multi-tenant/MSSP to Cortex XSOAR 8 SaaS multi-tenant/MSSP.
- [Migration FAQs - XSOAR 6 Multi-Tenant to XSOAR 8 SaaS Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migration-faqs-xsoar-6-multi-tenant-to-xsoar-8-saas-multi-tenant.md): Frequently asked questions about the migration from Cortex XSOAR 6 multi-tenant to Cortex XSOAR 8 SaaS multi-tenant.
- [Migration Prerequisites for Cortex XSOAR 8 SaaS Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migration-prerequisites-for-cortex-xsoar-8-saas-multi-tenant.md): Before you start the migration, review the migration prerequisites and other requirements for Cortex XSOAR 8 SaaS multi-tenant.
- [Migrate from Cortex XSOAR 6 Multi-Tenant to Cortex XSOAR 8 SaaS Multi-Tenant (Self-Service)](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-self-service.md): Migrate manually from Cortex XSOAR 6 Multi-Tenant to XSOAR 8 SaaS Multi-Tenant (not using the wizard).
- [Migrate from Cortex XSOAR 6 Multi-Tenant to Cortex XSOAR 8 Multi-Tenant using the migration wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz.md): Use the wizards to migrate your data from Cortex XSOAR 6 to 8.
- [Step 1. Activate Cortex XSOAR 8 SaaS Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-1.-activate-cortex-xsoar-8-saas-multi-tenant.md)
- [Step 2. Set up Cortex XSOAR 8 Multi-Tenant using the Pre-migration Wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-2.-set-up-cortex-xsoar-8-multi-tenant-using-the-pre-migration-wizard.md)
- [Configure a remote repository for multi-tenant using the pre-migration wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-2.-set-up-cortex-xsoar-8-multi-tenant-using-the-pre-migration-wizard/configure-a-remote-repository-for-multi-tenant-using-the-pre-migration-wizard.md)
- [Step 3. Run user acceptance tests (UAT) in a Multi-Tenant Deployment using the Migration Wizard](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard.md)
- [Incidents and Indicators - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/incidents-and-indicators-multi-tenant.md)
- [Users, User Groups, and Roles - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/users-user-groups-and-roles-multi-tenant.md)
- [Security and Authentication - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/security-and-authentication-multi-tenant.md)
- [Engines - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/engines-multi-tenant.md)
- [Remote Repositories - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/remote-repositories-multi-tenant.md)
- [Jobs - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/jobs-multi-tenant.md)
- [Integration Instance Configuration Changes - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/integration-instance-configuration-changes-multi-tenant.md)
- [API Keys in Cortex XSOAR 8 - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/api-keys-in-cortex-xsoar-8-multi-tenant.md)
- [Syslog Configuration - Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/syslog-configuration-multi-tenant.md)
- [Step 4. Select whether to resync data and set the switchover on Cortex XSOAR 8 SaaS Multi-tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-4.-select-whether-to-resync-data-and-set-the-switchover-on-cortex-xsoar-8-saas-multi-tenant.md)
- [Post Migration Steps for Cortex XSOAR 6 Multi-Tenant to 8 SaaS Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/post-migration-steps-for-cortex-xsoar-6-multi-tenant-to-8-saas-multi-tenant.md)
- [Cortex XSOAR 8 Privacy Datasheet](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/reference-docs/cortex-xsoar-8-privacy-datasheet.md): The privacy datasheet shows how personal info may be processed and stored.
- [Cortex XSOAR 8 Service Limits and Compliance](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/reference-docs/cortex-xsoar-8-service-limits-and-compliance.md): Read about encrypted security compliance reports.

## Cortex XSOAR 8 Retention Policy

- [Retention Policy and Enforcement](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy/cortex-xsoar-8-retention-policy-faqs/readme.md): Retention policy for Cortex XSOAR.

## Cortex XSOAR 8 On-prem OSS Listings

- [Cortex XSOAR On-prem OSS listings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem-oss-listings/cortex-xdr-oss-listings.md): Open-Source Software (OSS) licensing for Cortex XSOAR on-prem.
- [Cortex XSOAR on-prem 8.14 OSS listings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem-oss-listings/cortex-xdr-oss-listings/cortex-xdr-agent-9.2-oss-listing.md)

## Cortex XSOAR 8 SaaS Releases

- [Cortex XSOAR 8 SaaS Releases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-releases/cortex-xsoar-8-saas-releases.md): Major general availability releases for Cortex XSOAR 8 SaaS.

## Cortex XSOAR 6 Administrator Guides

- [Cortex XSOAR 6 Administrator Guides](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/cortex-xsoar-6-administrator-guides.md): Start here to choose the right Cortex XSOAR 6 version.

* [Navigate the Cortex XSOAR 6.14 Administrator Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 6.14 documentation areas.
* [Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/overview.md): Cortex XSOAR provides security orchestration, incident management, and interactive investigation. Overview of Cortex XSOAR features and concepts.
* [Get Started in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar.md): Learn about Cortex XSOAR concepts, licenses, and the product lifecycle, as well as basic functionality including the command line, API keys, search, CLI, etc.
* [Licenses](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/licenses.md): The Cortex XSOAR license type determines which components users can utilize. License types are community, starter, or enterprise. Users include audit and full.
* [FIPS Version](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/fips-version.md): Cortex XSOAR offers a FIPS version of Cortex XSOAR, using a software library validated against FIPS 140-3.
* [Concepts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/concepts.md): Cortex XSOAR concepts, including incidents, integrations, playbokos, automations, commands, war room, indicators, playground.
* [Product Support Lifecycle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/product-support-lifecycle.md): Cortex XSOAR's major releases support the product's lifecycle.
* [API Keys](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/api-keys.md): Generate and manage API keys in Cortex XSOAR.
* [Use the Command Line Interface](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/use-the-command-line-interface.md): Cortex XSOAR enables you to run system commands, integration commands, automations, and more, from an integrated CLI.
* [How to Search](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/how-to-search.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
* [How to Use Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/how-to-use-markdown.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
* [New User FAQ](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/new-user-faq.md): New User FAQ for Cortex XSOAR.
* [Onboarding in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/onboarding-in-cortex-xsoar.md): Onboarding process for Cortex XSOAR.
* [Deployment Checklist - Best Practices](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/deployment-checklist-best-practices.md): Overview of the deployment process, including best practices for Cortex XSOAR installation and maintenance.
* [Single Server Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment.md): Install Cortex XSOAR for a single server deployment.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
* [Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/deployment-guidelines.md): Review Cortex XSOAR deployment guidelines for AWS EC2, Azure, or GCP.
* [Install the Server for a Single Server Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/install-the-server-for-a-single-server-deployment.md): Installation instructions and requirements for standard Cortex XSOAR single server deployments, with the app server and database server on the same machine.
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/install-the-server-for-a-single-server-deployment/installer-flags.md)
* [Install the Server with Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/install-the-server-with-elasticsearch.md): Install Cortex XSOAR with Elasticsearch as the database. Prerequisites and instructions for installing a new Cortex XSOAR environment with Elasticsearch.
* [Install the Server Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline.md): Install Cortex XSOAR when you do not have internet access. Instructions for offline installation.
* [Dependencies for Offline Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline/dependencies-for-offline-installation.md)
* [Add a License](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/add-a-license.md): Add Cortex XSOAR license file, either through the UI or by saving the license file directly on the server.
* [Post-Installation Checklist](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist.md): Common post-installation steps to perform after installing Cortex XSOAR. Cortex XSOAR installation troubleshooting.
* [Monitor Components](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/monitor-components.md)
* [HTTPS with a Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/https-with-a-signed-certificate.md)
* [Create a Self-Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/create-a-self-signed-certificate.md)
* [Install or Renew a Custom Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/install-or-renew-a-custom-certificate.md)
* [Configure the Server to Listen on HTTP](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/configure-the-server-to-listen-on-http.md)
* [Troubleshoot WebSockets](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/troubleshoot-websockets.md)
* [Upgrade the Cortex XSOAR Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/upgrade-the-cortex-xsoar-server.md): Upgrading the Cortex XSOAR server including preparation, upgrade and post upgrade steps.
* [Uninstall the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/single-server-deployment/uninstall-the-server.md): Uninstall Cortex XSOAR. Configuration files and files created by engines are not removed.
* [Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch.md): Implementing Cortex XSOAR with Elasticsearch - setup, security, migration, and troubleshooting.
* [Elasticsearch Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-overview.md): Migrating Cortex XSOAR data to Elasticsearch. Object information in an existing Cortex XSOAR instance is copied to a designated Elasticsearch index.
* [Elasticsearch Setup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup.md): Elasticsearch best practices, sizing requirements, and configuration options for Cortex XSOAR.
* [Elasticsearch System Requirements](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-system-requirements.md)
* [Elasticsearch Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-configurations.md)
* [Elasticsearch Data Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-data-management.md)
* [Elasticsearch Security](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-security.md): Elasticsearch security and best practices guidelines for single server and multi-tenant deployments.
* [Elasticsearch General Security Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-security/elasticsearch-general-security-guidelines.md)
* [Elasticsearch Security Guidelines - Multi-tenant Deployments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/elasticsearch-security/elasticsearch-security-guidelines-multi-tenant-deployments.md)
* [Migration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration.md): Learn about migrating Cortex XSOAR data to Elasticsearch for a single server or multi-tenant environment.
* [Elasticsearch Migration Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/elasticsearch-migration-overview.md)
* [Migrate Objects to Elasticsearch for a Single Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-a-single-server.md)
* [Migrate Objects to Elasticsearch for Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-multi-tenant.md)
* [Migrate an Existing Elasticsearch Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/migrate-an-existing-elasticsearch-deployment.md)
* [Migrate Objects to Elasticsearch for a Distributed Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-a-distributed-database.md)
* [Manage Partial Migration to Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/manage-partial-migration-to-elasticsearch.md)
* [Validate the Migration to Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/validate-the-migration-to-elasticsearch.md)
* [Elasticsearch Post Migration Health Check](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/migration/elasticsearch-post-migration-health-check.md)
* [Disaster Recovery for Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch.md): Back up and restore a Cortex XSOAR elasticsearch deployment using snapshots.
* [Create Elasticsearch Snapshots](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/create-elasticsearch-snapshots.md)
* [Restore Elasticsearch Snapshots](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/restore-elasticsearch-snapshots.md)
* [Archive Data with Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/archive-data-with-elasticsearch.md): Archive Cortex XSOAR data you no longer need regular access to, using Elasticsearch index lifecycle management.
* [Troubleshoot Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/elasticsearch/troubleshoot-elasticsearch.md): Troubleshoot common issues in Cortex XSOAR Elasticsearch deployments.
* [Docker](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
* [Docker Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-overview.md): Overview of how Cortex XSOAR uses Docker for security and predictability.
* [Docker Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-installation.md): Install Docker on Enterprise Linux platforms and troubleshoot installation.
* [Configure Python Docker Integrations to Trust Custom Certificates](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/configure-python-docker-integrations-to-trust-custom-certificates.md): Configure CA signed and custom certificates for Docker. Trust custom certificates for python integrations in Cortex XSOAR.
* [Docker Images in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
* [Create a Docker Image In Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/create-a-docker-image-in-cortex-xsoar.md)
* [Install Docker Images Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/install-docker-images-offline.md)
* [Docker Image Security](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/docker-image-security.md)
* [Manage Docker Images](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/manage-docker-images.md)
* [Change the Docker Image for Automations and Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/change-the-docker-image-for-automations-and-integrations.md)
* [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/use-the-cortex-xsoar-container-registry.md)
* [Docker Hardening Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide.md): Use the Docker Hardening Guide to configure the Cortex XSOAR settings when running Docker containers.
* [Run Docker with Non-Root Internal Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
* [Configure Memory Limit Support Without Swap Limit Capabilities](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-memory-limit-support-without-swap-limit-capabilities.md)
* [Configure the Memory Limitation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-memory-limitation.md)
* [Test the Memory Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/test-the-memory-limit.md)
* [Limit Available CPU](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/limit-available-cpu.md)
* [Configure the PIDs Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-pids-limit.md)
* [Configure the Open File Descriptors Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-open-file-descriptors-limit.md)
* [Docker Network Hardening](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-hardening-guide/docker-network-hardening.md)
* [Docker FAQs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/docker-faqs.md): Frequently asked questions (FAQ) about Docker in Cortex XSOAR.
* [Troubleshoot Docker Networking Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/troubleshoot-docker-networking-issues.md): Troubleshoot Docker networking issues in Cortex XSOAR.
* [Troubleshoot Docker Performance Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/troubleshoot-docker-performance-issues.md): Troubleshoot Docker performance issues in Cortex XSOAR. Update Docker package and dependencies.
* [Configure Docker Pull Rate Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/configure-docker-pull-rate-limit.md): Configure the Docker pull rate limit on public images. Create Docker user account and receive higher pull limit.
* [Change the Docker Installation Folder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/docker/change-the-docker-installation-folder.md): Instructions for changing the default Docker folder.
* [Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/podman.md): Run Podman containers instead of Docker for RHEL v8.
* [Podman Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/podman/podman-overview.md): Run Podman containers instead of Docker for operating systems such as RHEL v8.
* [Change container storage directory](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/podman/change-container-storage-directory.md)
* [Podman Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/podman/podman-installation.md): Install Podman for Cortex XSOAR.
* [Configure the SELinux Policy for PowerShell Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/podman/configure-the-selinux-policy-for-powershell-integrations.md): Change the SELinux Policy when running Powershell Integrations in Cortex XSOAR. SELinux policy for Podman.
* [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/podman/migrate-from-docker-to-podman.md): Switch from Docker to Podman in Cortex XSOAR. Migrate from Docker to Podman, for RHEL 8 or later.
* [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/podman/troubleshoot-podman.md): Troubleshoot issues for Podman for Cortex XSOAR.
* [Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/proxy.md): Configure proxy settings in Cortex XSOAR.
* [Configure Proxy Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/proxy/configure-proxy-settings.md): Configure global proxy settings in Cortex XSOAR by adding a server configuration.
* [Configure how to bypass proxy settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/proxy/configure-how-to-bypass-proxy-settings.md): Configure option to bypass a proxy using a server configuration.
* [Use NGINX as a Reverse Proxy to the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/proxy/use-nginx-as-a-reverse-proxy-to-the-server.md): Use NGINX as a Reverse Proxy to the Cortex XSOAR Server.
* [High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability.md): Guide to high availability in Cortex XSOAR, using Elasticsearch. Includes sizing requirements, migration, additional app servers, and signed certificates.
* [High Availability Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/high-availability-overview.md): Overview of high availability in Cortex XSOAR, including information about the different deployment architectures.
* [Set Up High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/set-up-high-availability.md): Overview of the steps required to set up high availability for Cortex XSOAR.
* [Sizing Requirements for High Availability Deployments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/sizing-requirements-for-high-availability-deployments.md): Information about the sizing requirements for Cortex XSOAR High Availability deployments.
* [Monitor the Health of the App Servers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/monitor-the-health-of-the-app-servers.md): Monitor the health of the app servers in a Cortex XSOAR high availability environment.
* [Migrate a Single Instance for High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/migrate-a-single-instance-for-high-availability.md): Migrate your Cortex XSOAR single instance deployment to a high availability installation of Cortex XSOAR.
* [Migrate a Multi-Tenant Deployment for High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/migrate-a-multi-tenant-deployment-for-high-availability.md): Migrate your Cortex XSOAR Multi-tenant deployment to enable High Availability.
* [Install Additional App Servers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/install-additional-app-servers.md): Install additional app servers for a Cortex XSOAR high availability configuration.
* [Deploy Engines in a High Availability Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/deploy-engines-in-a-high-availability-environment.md): When adding application servers, update the engines to connect through the load balancer.
* [Use a Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/high-availability/use-a-signed-certificate.md): Use a signed certificate in a Cortex XSOAR high availability deployment.
* [Disaster Recovery and Live Backup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup.md): Live backup and disaster recovery options for Cortex XSOAR.
* [Disaster Recovery and Live Backup Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/disaster-recovery-and-live-backup-overview.md): Describes live backup, how to configure your environment, server DR status, and disaster recovery scenarios in Cortex XSOAR.
* [Host Names, DNS, and Disaster Recovery](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/host-names-dns-and-disaster-recovery.md): Unique host names and DNS considerations for disaster recovery for Cortex XSOAR.
* [Configure the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment.md): Configure a live backup environment by mirroring your production server to a backup server in Cortex XSOAR.
* [Configure Live Backup for Multiple SAMLs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/configure-live-backup-for-multiple-samls.md)
* [DR Scenario: Testing the DR Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/dr-scenario-testing-the-dr-environment.md): Test a Cortex XSOAR disaster recovery environment and restore the original server roles.
* [DR Scenario: Unrecoverable Active Server Failure](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/dr-scenario-unrecoverable-active-server-failure.md): Recover from an unrecoverable active server failure using a Cortex XSOAR live backup environment.
* [DR Scenario: Unrecoverable Standby Server Failure](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/dr-scenario-unrecoverable-standby-server-failure.md): Replace an unrecoverable standby server in a Cortex XSOAR live backup environment.
* [Transition an Active Server to Standby Mode](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-an-active-server-to-standby-mode.md): Change an active server to standby mode in Cortex XSOAR.
* [Transition a Standby Server to Active Mode](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-a-standby-server-to-active-mode.md): Transition a standby server to active mode (production) in Cortex XSOAR.
* [Transition Between DR States Through the Configuration File](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-between-dr-states-through-the-configuration-file.md): Transition disaster recovery states between active and standby using the configuration file when the server is new and starts for the first time.
* [Upgrade the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/upgrade-the-live-backup-environment.md): Upgrade your live backup environment for Cortex XSOAR.
* [Engines and Disaster Recovery Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/engines-and-disaster-recovery-troubleshooting.md): Troubleshoot Cortex XSOAR engine failover issues when an engine does not automatically fail over to the active node in a disaster recovery situation.
* [Back up the Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/back-up-the-database.md): Perform manual and automatic backups of the Cortex XSOAR database. Configure automated backup options. Schedule backups.
* [Restore the Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/restore-the-database.md): Restore the database from a manual backup or automated backup back up in Cortex XSOAR.
* [Restore a Partition](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/restore-a-partition.md): Restore one or more specific partitions in Cortex XSOAR.
* [Troubleshoot Live Backup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/disaster-recovery-and-live-backup/troubleshoot-live-backup.md): How to troubleshoot live backup scenarios in Cortex XSOAR.
* [Users and Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles.md): Users and roles in Cortex XSOAR, including permissions, user settings, shifts, and authentication options.
* [Users and Roles Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/users-and-roles-overview.md): Manage users, roles, invitations, password policies, and view information about users activities in Cortex XSOAR.
* [Roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar.md): The default admin is the super user role in XSOAR. Administrator, Analyst, and Read-Only roles are defined by the read-write level of access to XSOAR components.
* [Pre-set Query per Role](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/pre-set-query-per-role.md)
* [Define a Role](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/define-a-role.md)
* [Role-based Permission Levels](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/role-based-permission-levels.md)
* [Shift Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/shift-management.md)
* [Managing Shifts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/shift-management/managing-shifts.md)
* [User Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management.md): Invite and manage users in Cortex XSOAR. Edit user roles, reset passwords, disable or remove users.
* [User Invitations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/user-invitations.md)
* [Invite a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/user-invitations/invite-a-user.md)
* [Set the User as Default Administrator](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/user-invitations/set-the-user-as-default-administrator.md)
* [Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users.md)
* [Configure the Server for Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/configure-the-server-for-self-service-read-only-users.md)
* [Create the Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-self-service-read-only-users.md)
* [Create the Read-Only Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-read-only-dashboard.md)
* [Create the Read-Only Incident Type and Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-read-only-incident-type-and-layout.md)
* [Disable a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/disable-a-user.md)
* [Remove a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/remove-a-user.md)
* [Clear Users Data Using the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/clear-users-data-using-the-cli.md)
* [Clear Users Data Using a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/clear-users-data-using-a-playbook.md)
* [Configure Users Data Using Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/configure-users-data-using-server-configurations.md)
* [User Settings and Preferences](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/user-settings-and-preferences.md)
* [Configure User Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/configure-user-settings.md)
* [Manually Refresh the Number of Licenses in Use](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/user-management/manually-refresh-the-number-of-licenses-in-use.md)
* [Integration Permissions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/integration-permissions.md): Integration permissions enable you to assign permissions to commands in integrations. Use role based access control (RBAC) to assign commands.
* [Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/password-policy.md): Describes the password policy and how to set it in Cortex XSOAR.
* [Create a Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/password-policy/create-a-password-policy.md)
* [Edit a Default Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/password-policy/edit-a-default-password-policy.md)
* [Default Password Policy Keys](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/password-policy/edit-a-default-password-policy/default-password-policy-keys.md)
* [Change the Administrator Password](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/change-the-administrator-password.md): Create a new password for the Cortex XSOAR administrator account, if you are unable to log in, by manually adding a new administrator.
* [Authenticate Users with SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0.md): Authenticate users using SAML 2.0 with your identity provider, for Cortex XSOAR. Use Okta, Microsoft Entra ID, or ADFS.
* [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
* [Create Okta Groups for Cortex XSOAR Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/create-okta-groups-for-cortex-xsoar-users.md)
* [Define the Okta Application to authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/define-the-okta-application-to-authenticate-cortex-xsoar.md)
* [SAML Settings for the Okta Application](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/define-the-okta-application-to-authenticate-cortex-xsoar/saml-settings-for-the-okta-application.md)
* [Configure the SAML 2.0 Integration for Okta](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-okta.md)
* [SAML 2.0 Okta Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-okta/saml-2.0-okta-parameters.md)
* [Map Okta Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/map-okta-groups-to-cortex-xsoar-roles.md)
* [Set Up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
* [Configure Microsoft Entra ID to Authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-microsoft-entra-id-to-authenticate-cortex-xsoar.md)
* [Configure the SAML 2.0 Integration for Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-microsoft-entra-id.md)
* [SAML 2.0 Microsoft Entra ID Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-microsoft-entra-id/saml-2.0-microsoft-entra-id-parameters.md)
* [Set up ADFS as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0.md)
* [Create Relying Party Trust in ADFS](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/create-relying-party-trust-in-adfs.md)
* [Define the Claim Issuance Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/define-the-claim-issuance-policy.md)
* [Configure the SAML 2.0 Integration for ADFS](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-adfs.md)
* [SAML 2.0 ADFS Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-adfs/saml-2.0-adfs-parameters.md)
* [Map ADFS Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/map-adfs-groups-to-cortex-xsoar-roles.md)
* [Duo for Single Sign-On](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on.md)
* [Create Duo Groups for Cortex XSOAR Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/create-duo-groups-for-cortex-xsoar-users.md)
* [Define Duo to authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/define-duo-to-authenticate-cortex-xsoar.md)
* [Configure the SAML 2.0 Integration for Duo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/configure-the-saml-2.0-integration-for-duo.md)
* [Map Duo Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/map-duo-groups-to-cortex-xsoar-roles.md)
* [Change the Default Administrator to a SAML User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/change-the-default-administrator-to-a-saml-user.md)
* [Set Up SAML Logout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-saml-logout.md)
* [Set the Default Theme for New Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/set-the-default-theme-for-new-users.md): Set the default color theme for new Cortex XSOAR users by adding a server configuration. Users can change the theme in user preferences.
* [Authenticate Users with Active Directory](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-active-directory.md): Users can log in to Cortex XSOAR with their Active Directory username and passwords
* [Marketplace](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace.md): Access the Cortex XSOAR Marketplace and install content packs. Convert existing content to content pack format.
* [Marketplace Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/marketplace-overview.md): Use Cortex XSOAR Marketplace to install, exchange, contribute and manage your content.
* [Content Packs Support Types](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-packs-support-types.md): Types of content packs Support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
* [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
* [Search and Navigate in the Marketplace](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/search-and-navigate-in-the-marketplace.md): Search the Cortex XSOAR Marketplace and find free and paid content. Search by use cases, integrations, categories, etc.
* [Convert Existing Content to Content Pack Format](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/convert-existing-content-to-content-pack-format.md): Convert content to content pack format when upgrading from a version earlier than Cortex XSOAR 6.0.
* [Use Cases](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/use-cases.md): Common use cases for Cortex XSOAR, including analytics and siem, authentication, case management, data enrichment, threat intelligence, forensic and malware,
* [Content Pack Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-installation.md): Cortex XSOAR content pack dependencies, errors and warning messages.
* [Install a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-installation/install-a-content-pack.md): Install a content pack and its required dependencies from Marketplace.
* [Set up Your Use Case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-installation/install-a-content-pack/set-up-your-use-case-with-the-deployment-wizard.md): Configure a supported content pack for your use case.
* [Delete a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-installation/delete-a-content-pack.md): Delete an installed content pack from Marketplace.
* [Update a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-installation/update-a-content-pack.md): Update an installed content pack from Marketplace.
* [Revert a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-installation/revert-a-content-pack.md): Revert an installed content pack to an earlier version.
* [Install a Content Pack Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/install-a-content-pack-offline.md): Download Cortex XSOAR Marketplace content packs and then upload offline to install on a machine without an internet connection (air gapped).
* [Configure the Marketplace for Offline Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/install-a-content-pack-offline/configure-the-marketplace-for-offline-installation.md)
* [Content Pack Update Notifications](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs
* [Customize Content Pack Notifications](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-update-notifications/customize-content-pack-notifications.md)
* [Marketplace Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/marketplace-troubleshooting.md): Troubleshoot Marketplace issues regarding login, connectivity, timeouts, and certificates.
* [Content Pack Contributions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
* [Create a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md)
* [Resubmit a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md)
* [Remote Repositories in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar.md): Configure a remote repository on a development and production machine and edit and push content.
* [Content Management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/content-management-in-cortex-xsoar.md): Cortex XSOAR offers multiple options for developing content, including a remote repository and CI/CD.
* [Remote Repositories Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/remote-repositories-overview.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
* [Configure a Remote Repository on a Development Machine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/configure-a-remote-repository-on-a-development-machine.md): Configure a remote repository on a development machine. Add content repository in Cortex XSOAR.
* [Configure a Remote Repository on the Production Machine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/configure-a-remote-repository-on-the-production-machine.md): Configure a remote repository on a production machine. Define the repository and pull content.
* [Edit and Push Content to a Remote Repository](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/edit-and-push-content-to-a-remote-repository.md): Push content to a remote repository and control access for pushing content.
* [Upgrade Remote Repositories from Versions 5.5 and below](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/upgrade-remote-repositories-from-versions-5.5-and-below.md): Upgrade Cortex XSOAR remote repository environment from 5.5 to 6.5 and above.
* [Troubleshoot a Remote Repository Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/troubleshoot-a-remote-repository-configuration.md): Troubleshoot issues for a Cortex XSOAR remote repository configuration plus FAQs.
* [Troubleshoot a Remote Repository Definition](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/troubleshoot-a-remote-repository-configuration/troubleshoot-a-remote-repository-definition.md)
* [Troubleshoot Editing and Pushing Content](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/troubleshoot-a-remote-repository-configuration/troubleshoot-editing-and-pushing-content.md)
* [Troubleshoot Content Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/troubleshoot-a-remote-repository-configuration/troubleshoot-content-issues.md)
* [Troubleshoot a Remote Repository with an HTTP Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/troubleshoot-a-remote-repository-configuration/troubleshoot-a-remote-repository-with-an-http-proxy.md)
* [Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot Cortex XSOAR engines.
* [Cortex XSOAR Engines Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/cortex-xsoar-engines-overview.md): Understand Cortex XSOAR engine architecture, load balancing groups, installation and configurations.
* [Engine Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/engine-installation.md): Review system requirements and engine installation types (Shell, DEB, RPM, Zip, Configuration) available for Cortex XSOAR engines.
* [Install a Cortex XSOAR Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/engine-installation/install-a-cortex-xsoar-engine.md)
* [Install a Signed Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/engine-installation/install-a-signed-engine.md)
* [Install a Cortex XSOAR Engine Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/engine-installation/install-a-cortex-xsoar-engine-offline.md)
* [Use an Engine in an Integration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use a Cortex XSOAR engine or load-balancing group of engines to fetch incidents and run commands for an integration.
* [Run a Script using an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load balancing group. Run an automation from an engine or load balancing group.
* [Manage Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/manage-engines.md): Manage engines and load balancing groups in Cortex XSOAR.
* [Configure Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines to change the number of workers, access communication tasks, notify users if engine disconnects, and remove server from group.
* [Edit the Engine Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration.md)
* [Common Properties When Editing an Engine Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/common-properties-when-editing-an-engine-configuration.md)
* [Configure the Engine to Use a Web Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md)
* [Configure the Engine to Call the Server Without Using a Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
* [Configure the Number of Workers for the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/configure-the-number-of-workers-for-the-server.md)
* [Configure Access to Communication Tasks through an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/configure-access-to-communication-tasks-through-an-engine.md)
* [Configure an Engine to Use Custom Certificates](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
* [Notify Users When an Engine Disconnects](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/configure-engines/notify-users-when-an-engine-disconnects.md)
* [Remove an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/remove-an-engine.md): Remove a Cortex XSOAR engine. Commands vary depending on your operating system.
* [Troubleshoot Cortex XSOAR Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/onboard-cortex-xsoar/engines/troubleshoot-cortex-xsoar-engines.md): Troubleshoot Cortex XSOAR engines by accessing logs and viewing errors.
* [Customize and Configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar.md): Customize and configure your Cortex XSOAR deployment.
* [Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents.md): Manage and investigate incidents in Cortex XSOAR.
* [Incident Lifecycle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle.md): Incidents are potential security data threats that analysts identify and remediate in Cortex XSOAR.
* [Fetch Incidents From an Integration Instance](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle/fetch-incidents-from-an-integration-instance.md)
* [Receive Notification on an Incident Fetch Error](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle/receive-notification-on-an-incident-fetch-error.md)
* [Incident Context Data](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-context-data.md): Learn about incident context data, how it is stored in Cortex XSOAR, and how to access it.
* [Incident Customization](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization.md): Customize incidents in Cortex XSOAR. Attach and detach incident types. Customize indicator extraction, incident types, fields, and layouts.
* [Create an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/create-an-incident-type.md)
* [Customize Incident Layouts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/customize-incident-layouts.md)
* [Incident Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields.md)
* [Create a Custom Incident Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-a-custom-incident-field.md)
* [Create a Grid Field for an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-a-grid-field-for-an-incident-type.md)
* [Use Scripts with the Grid Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/use-scripts-with-the-grid-field.md)
* [Incident Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/incident-field-trigger-scripts.md)
* [Troubleshoot Closing Case Incident after Changing Field Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/troubleshoot-closing-case-incident-after-changing-field-type.md)
* [Create an Evidence Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-an-evidence-field.md)
* [Incident De-Duplication](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-de-duplication.md): De-duplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
* [Manually De-Duplicate Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-de-duplication/manually-de-duplicate-incidents.md)
* [Automatic De-Duplication Using Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-de-duplication/automatic-de-duplication-using-scripts.md)
* [Pre-Process Rules](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
* [Create Pre-Process Rules for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/pre-process-rules/create-pre-process-rules-for-incidents.md)
* [Rule Actions for Pre-Process Rules](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/pre-process-rules/create-pre-process-rules-for-incidents/rule-actions-for-pre-process-rules.md)
* [Post Processing for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR.
* [Create a Post-Processing Script](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents/create-a-post-processing-script.md)
* [Add a Post-Processing Script to the Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents/add-a-post-processing-script-to-the-incident-type.md)
* [War Room Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview.md): Use the Cortex XSOAR War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
* [Schedule a Command](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/schedule-a-command.md)
* [Add a Custom Widget in the War Room](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/add-a-custom-widget-in-the-war-room.md)
* [War Room Indexing](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing.md)
* [Index War Room Entries Using Bolt DB](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing/index-war-room-entries-using-bolt-db.md)
* [Index War Room Entries Using Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing/index-war-room-entries-using-elasticsearch.md)
* [Incident Access Control Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-access-control-configuration.md): Limit access to incidents and investigations in Cortex XSOAR, using role-based access control (RBAC).
* [Limit Access to Investigations using RBAC](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-access-control-configuration/limit-access-to-investigations-using-rbac.md)
* [Restrict an Investigation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-access-control-configuration/restrict-an-investigation.md)
* [Classification and Mapping](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/classification-and-mapping.md): Classify and map incoming data from an integration instance.
* [Classify Events Using a Classification Key](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/classification-and-mapping/classify-events-using-a-classification-key.md)
* [Create a Mapper](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/classification-and-mapping/create-a-mapper.md)
* [Incident Mirroring](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-mirroring.md): Set up your integration to mirror incidents between a third-party application and Cortex XSOAR.
* [Customize Incident Close Reasons](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
* [Change the Display Name of Security Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/change-the-display-name-of-security-incidents.md): Add a Cortex XSOAR server configuration to change the name of security incidents from ‘incident’ to another term - cases, issues, etc.
* [Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks.md): Cortex XSOAR playbooks enable you to organize and document security monitoring, orchestration, and response activities.
* [What Are Playbooks?](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/what-are-playbooks.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
* [Playbook Development](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-development.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes.
* [Configure IoT Security Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/configure-iot-security-playbooks.md): IoT Security playbooks enable you to structure and automate many of your third-party security processes. Parse incident information, interact with users, and remediate.
* [Manage Playbook Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/manage-playbook-settings.md): Manage Cortex XSOAR playbook settings, including role access, which incident type triggers it, and options for Quiet Mode.
* [Obtain Playbook Metadata](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/manage-playbook-settings/obtain-playbook-metadata.md)
* [Version Control](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/version-control.md): Save versions of your playbook as you are developing it.
* [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields.md): All of the fields available when defining a playbook task in Cortex XSOAR.
* [Create Section Headers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/create-section-headers.md)
* [Create a Conditional Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/create-a-conditional-task.md)
* [Communication Tasks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks.md)
* [Create an Ask Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task.md)
* [Ask Task Examples](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task/ask-task-examples.md)
* [Customize an Ask Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task/customize-an-ask-task.md)
* [Create a Data Collection Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task.md)
* [Data Collection Task Examples](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task/data-collection-task-examples.md)
* [Customize a Data Collection Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task/customize-a-data-collection-task.md)
* [Customize the SOC Name](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/customize-the-soc-name.md)
* [Create Communication Task Authentication](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-communication-task-authentication.md)
* [Add Ad Hoc Tasks to a Work Plan](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/add-ad-hoc-tasks-to-a-work-plan.md)
* [Handle Errors in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/handle-errors-in-a-playbook.md)
* [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/playbook-task-fields.md)
* [Playbook Inputs and Outputs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-inputs-and-outputs.md): Cortex XSOAR playbooks and tasks have inputs (data from incident or integration) and outputs that can then be used as input in other tasks.
* [Task Cheat Sheet](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-inputs-and-outputs/task-cheat-sheet.md)
* [Extend Context](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
* [Extend Context in a Playbook Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context/extend-context-in-a-playbook-task.md)
* [Extend Context using the Command Line](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context/extend-context-using-the-command-line.md)
* [Use DT syntax to get select keys from a list of dictionaries](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context/use-dt-syntax-to-get-select-keys-from-a-list-of-dictionaries.md)
* [Filters and Transformers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers.md): Use filters and transformers to manipulate data in Cortex XSOAR. Use filters and transformers in playbook tasks or when mapping an instance.
* [Create Filters and Transformers in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook.md)
* [Create a Filter Example](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-example.md)
* [Create a Filter (Advanced) Example](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-advanced-example.md)
* [Filter Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators.md)
* [Built-in Filters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/built-in-filters.md)
* [Transformers Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/transformers-operators.md)
* [Create Custom Filter and Transformer Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/create-custom-filter-and-transformer-operators.md)
* [Automations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/automations.md): Create and edit an automation in Cortex XSOAR, including detach and attach, automation settings, etc.
* [Special Automation Tags](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/automations/special-automation-tags.md)
* [Common Scripts to use in Automations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/automations/common-scripts-to-use-in-automations.md)
* [Configure a Sub-playbook Loop](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/configure-a-sub-playbook-loop.md): Configure a sub-playbook to run in a loop.
* [Playbook Polling](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-polling.md): Cortex XSOAR Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
* [Create Incident Fields in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/create-incident-fields-in-a-playbook.md): Use the setIncident automation to set and update all system incident fields.
* [Playbook Testing](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-testing.md): Test your playbook with ingested incidents.
* [Debug a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-testing/debug-a-playbook.md)
* [Debugger Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-testing/debugger-troubleshooting.md)
* [Best Practices](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/best-practices.md): Best practices for working with playbooks.
* [Jobs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
* [Create a Time Triggered Job](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
* [Create a Job Triggered by a Delta in Feed](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
* [Time Triggered Job Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/time-triggered-job-parameters.md): Description of the parameters available when creating a time triggered job.
* [Process Indicators Using a Job Triggered By Delta](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/process-indicators-using-a-job-triggered-by-delta.md): Provides an example of using a job triggered by a delta in a feed to process incoming indicators.
* [Add Indicators to SIEM Using a Time Triggered Job](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/add-indicators-to-siem-using-a-time-triggered-job.md): Use a time-triggered job to push indicators to a SIEM.
* [Work with SLAs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas.md): Create and manage SLAs and timers and SLA scripts. Search by SLA and timer fields. Configure global risk threshold in Cortex XSOAR.
* [SLA Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/sla-overview.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
* [Create an SLA Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/create-an-sla-field.md): Create new SLA or timer and add SLA script to trigger when SLA time has passed.
* [Manage SLA and Timer Fields in an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/manage-sla-and-timer-fields-in-an-incident.md): Manage timers and SLA for a specific incident, such as decreasing required response time for a high priority incident.
* [Create an SLA Trigger](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/create-an-sla-trigger.md): Trigger times to start, pause, or stop when a certain task occurs in a Cortex XSOAR playbook.
* [Customize SLA Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/customize-sla-scripts.md): Create scripts that will perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Search Incidents using SLA and Timer Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/search-incidents-using-sla-and-timer-fields.md): Search incidents based on their SLA status, a SLA field, or a timer field.
* [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change SLA Risk threshold from default 72 hours.
* [Machine Learning](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning.md): Understand machine learning models in Cortex XSOAR. P
* [Machine Learning Capabilities](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/machine-learning-capabilities.md): Machine Learning capabilities using the Phishing Classifier and automations.
* [Machine Learning Models](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/machine-learning-models.md): Use machine learning (ML) models in Cortex XSOAR to analyze and predict future behavior. Machine learning for phishing incidents.
* [Use the Phishing Classifier in Production](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/use-the-phishing-classifier-in-production.md): The phishing classifier enables you to train a machine learning model for incidents.
* [Create a Machine Learning Model](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/create-a-machine-learning-model.md): Create a machine learning (ml) model in Cortex XSOAR to predict the classification of phishing incidents.
* [Phishing Classifier Demo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/phishing-classifier-demo.md): Use the phishing classifier demo to see how a classifier works for machine learning (ml) in Cortex XSOAR.
* [Train a Phishing Classifier on Non-English Languages](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/train-a-phishing-classifier-on-non-english-languages.md): Train a phishing classifier for non English language emails through tokenization methods. Cortex XSOAR machine learning.
* [Additional Machine Learning Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/additional-machine-learning-scripts.md): Additional machine learning scripts
* [Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists.md): Create and manage lists in Cortex XSOAR.
* [Work With Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/work-with-lists.md): Manage lists in Cortex XSOAR that can be accessed by automations, playbooks, etc.
* [Work with JSON Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/work-with-lists/work-with-json-lists.md): Extract, filter, and transform JSON list data in playbooks.
* [Create a List](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/create-a-list.md): Create predefined lists in Cortex XSOAR that can be parsed by and modified by scripts.
* [Set the List Separator Character](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/set-the-list-separator-character.md): Set the list separator character in Cortex XSOAR. The default separator for lists is a comma.
* [Transform a List into an Array](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an instance in Cortex XSOAR.
* [Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts and an exclusion list.
* [Indicator Concepts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-concepts.md): Cortex XSOAR provides threat intelligence management. TIM concepts include fetch indicators, configure indicators, and export indicators. Threat intel management
* [Indicator Verdict](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-verdict.md): Indicator verdict affects how the indicator is processed and handled in Cortex XSOAR. Assigned by reputation returned by the source with highest reliability.
* [Indicator Ingestion](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-ingestion.md): Overview of how Cortex XSOAR indicators are detected and ingested.
* [Indicator Customization](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md): Customize indicator types, fields, and layouts.
* [Indicator Types](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types.md): Configure indicator types and their associated scripts and fields.
* [File Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/file-indicators.md): Manage file indicators and their associated hashes.
* [File Indicator Merging Strategy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/file-indicators/file-indicator-merging-strategy.md): Understand how file indicators merge by hash.
* [Create an Indicator Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/create-an-indicator-type.md): Create a custom indicator type.
* [Indicator Type Profile](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/indicator-type-profile.md): Configure indicator type profile settings.
* [Map Custom Indicator Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/map-custom-indicator-fields.md): Map custom fields to indicator data.
* [Formatting Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/formatting-scripts.md): Format indicator values and output.
* [Enhancement Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/enhancement-scripts.md): Configure scripts that enhance indicators on demand.
* [Reputation Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/reputation-scripts.md): Configure scripts that calculate indicator verdicts.
* [Reputation Commands](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/reputation-commands.md): Configure commands that calculate indicator verdicts.
* [Indicator Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields.md): Create and configure fields for indicators.
* [Create a Custom Indicator Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md): Create a custom field for indicators.
* [Configure the HTML Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field/configure-the-html-field.md): Configure HTML fields for indicators.
* [Indicator Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/indicator-field-trigger-scripts.md): Run scripts when indicator field values change.
* [Indicator Layouts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts.md): Customize layouts for indicator types.
* [Customize an Indicator Type Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts/customize-an-indicator-type-layout.md): Customize a layout for an indicator type.
* [Add a Script in the Indicator Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts/add-a-script-in-the-indicator-layout.md): Add dynamic script output to an indicator layout.
* [Indicator Extraction](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction.md): Indicator extraction extracts indicators from incident fields and enriches them with commands and scripts defined for the indicator type.
* [Indicator Extraction Modes](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/indicator-extraction-modes.md): Indicator extraction modes and their behavior.
* [Create Indicator Extraction Rules for an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md): Configure indicator extraction rules for incident types.
* [Run Indicator Extraction in the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/run-indicator-extraction-in-the-cli.md): Extract and enrich indicators from the command line.
* [Create Indicator Extract Rules for a Playbook Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/create-indicator-extract-rules-for-a-playbook-task.md): Configure indicator extraction for playbook tasks.
* [Disable Indicator Extraction for Automations or Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/disable-indicator-extraction-for-automations-or-integrations.md): Disable indicator extraction for specific automations or integrations.
* [Indicator Expiration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a period of time or never to expire. Set default expiration method.
* [Feed Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/feed-integrations.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
* [Set the Source Reliability of Enrichment Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/feed-integrations/set-the-source-reliability-of-enrichment-integrations.md)
* [Dashboards](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Dashboard Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/dashboard-overview.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
* [Create a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/create-a-dashboard.md): Create and customize a dashboard in Cortex SOAR. Add widgets to a dashboard.
* [Add a Widget to a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/add-a-widget-to-a-dashboard.md): Add a widget to an existing or new dashboard in Cortex XSOAR. Edit widget parameters including date range.
* [Share a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/share-a-dashboard.md): Share or stop sharing a Cortex XSOAR dashboard with other users by role. Set permissions for shared dashboards.
* [Edit a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/edit-a-dashboard.md): Edit an existing dashboard in Cortex XSOAR. Add, delete or change widgets. Change date range. Adjust size and position of widgets.
* [Reports](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
* [Reports Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/reports-overview.md): Overview of Cortex XSOAR reports and how to create and edit reports. Analyze data in PDF, Word, and CSV formats. Upload your own logo.
* [Create a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/create-a-report.md): Create a new report in Cortex XSOAR. Add widgets and customize report. Schedule a report.
* [Schedule a report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/schedule-a-report.md): Schedule a report in Cortex XSOAR to run at a specific time. Send reports by email, choose recipients.
* [Customize the Email When Sending a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/customize-the-email-when-sending-a-report.md): Changes the email subject, body, and body HTML when scheduling a report.
* [Create an Incident Summary Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
* [Select and Customize Sections to Export to a Summary Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/select-and-customize-sections-to-export-to-a-summary-report.md): Select sections to export from the legacy Summary page to a Summary report in Cortex XSOAR. Save report as a template.
* [Add a Widget to a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/add-a-widget-to-a-report.md): Add a widget to a report in Cortex XSOAR.
* [Edit a report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/edit-a-report.md): Edit a report by adding, editing, or removing widgets, and changing the layout and the output type. You cannot edit system reports or incident summary reports.
* [Change the Report Logo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/change-the-report-logo.md): Add a company or organization logo to a report in Cortex XSOAR. Customize report logo with a server configuration.
* [Configure the Time Zone and Format in a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/configure-the-time-zone-and-format-in-a-report.md): Change the time zone and time format in a Cortex XSOAR report. Report troubleshooting
* [Troubleshoot Reports](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/troubleshoot-reports.md): Troubleshoot Cortex XSOAR reports by viewing JSON file. Add temporary server configuration to download and view JSON file for troubleshooting.
* [Widgets](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboard
* [Widgets Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/widgets-overview.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
* [Create a Widget using the Widget Builder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in Cortex XSOAR and then add widget to a dashboard or report.
* [Create a Custom Widget Using a JSON File](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
* [Create a Custom Widget Using an Automation Script](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-custom-widget-using-an-automation-script.md): Create a custom script based widget in Cortex XSOAR using an Automation Script. Use custom widgets in dashboards and reports.
* [Edit a Widget](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
* [Create a Used Percentage Widget for a Disk Partition](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-used-percentage-widget-for-a-disk-partition.md): Add server configuration and create new dashboard for used percentage widget for a disk partition in Cortex XSOAR.
* [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/saved-by-dbot-roi-widget.md): Customize Saved by Dbot widget that calculates the amount saved by Cortex XSOAR, using a server configuration. Return on Investment (ROI) widget.
* [Manage Data](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data.md): Manage data in Cortex XSOAR, reindex database or specific index database, free up disk space, migrate data, restore an archive.
* [Reindex the Entire Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-the-entire-database.md): Reindex the database in Cortex XSOAR.
* [Reindex a Specific Index Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-a-specific-index-database.md): Reindex a specific index database in Cortex XSOAR. Reindex multiple index databases.
* [Reindex the Audit Log](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-the-audit-log.md): Reindex the audit log to recover audit trail historical data in Cortex XSOAR.
* [Free up Disk Space with Data Archiving](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/free-up-disk-space-with-data-archiving.md): Free up disk space by archiving Cortex XSOAR folders to condense the unused data within them.
* [Archive Artifacts and Attachments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/archive-artifacts-and-attachments.md): Archive artifacts and attachments folders.
* [Store Incident/Artifact Files in the Cloud](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/store-incidentartifact-files-in-the-cloud.md): Store incident attachments and artifact files including War Room, or through a Playbook.
* [Migrate Data to Another Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/migrate-data-to-another-server.md): Migrate Cortex XSOAR data to another server, move data, copy files and directories.
* [Migrate Data to Another Server for Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/migrate-data-to-another-server-for-multi-tenant.md): Migrate Cortex XSOAR data to another server in a multi-tenant environment.
* [Move Data Folders to Another Location on the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/move-data-folders-to-another-location-on-the-server.md): Move Cortex XSOAR data folders to a different location on the server.
* [Restore an Archived Folder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/restore-an-archived-folder.md): Restore an archived folder in Cortex XSOAR.
* [Logs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs.md): Cortex XSOAR includes a server log and an audit trail as well as the ability to download a log bundle.
* [Logs Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/logs-overview.md): Cortex XSOAR logs information you can use for troubleshooting.
* [Configure the Server Log](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/configure-the-server-log.md): Configure the server log for maximum size, log level, number of files to backup and days to retain log files, in Cortex SXSOAR.
* [Configure the Access Log for HTTPS Requests](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/configure-the-access-log-for-https-requests.md): Add a server configuration to view HTTP/HTTPS requests.
* [Create a Log Bundle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/create-a-log-bundle.md): Create a log bundle of additional logs for troubleshooting in Cortex XSOAR.
* [Audit Trail](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/audit-trail.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
* [Send the Audit Trail to an External Log Service](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/send-the-audit-trail-to-an-external-log-service.md): Send the Cortex XSOAR audit trail to an external log service by adding custom server configurations.
* [System Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings.md): Customize the logo, the login message, system emails, and system notifications.
* [Customize the Logo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-the-logo.md): Customize the full-size and minimized logo in Cortex XSOAR.
* [Customize the Login Message](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-the-login-message.md): Customize the message that appears to users on the login page before logging in to Cortex XSOAR.
* [Customize System Emails](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-system-emails.md): Customize subject and message body for Cortex XSOAR system emails and choose HTML and/or text format.
* [Configure System Notifications](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/configure-system-notifications.md): Configure email system notifications in Cortex XSOAR, choose mail sender with advanced server configuration settings.
* [Day to Day Tasks in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar.md): Manage daily incident and indicator management tasks in Cortex XSOAR.
* [Incident Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management.md): Open, investigate, and manage incidents in Cortex XSOAR.
* [Create an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-an-incident.md): Create a new incident in Cortex XSOAR, manually, through a feed, or by importing a JSON file.
* [Create a Search Query for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-a-search-query-for-incidents.md): Create a search query for Cortex XSOAR incidents. Customize which incidents are displayed. Save search queries.
* [Create a Widget From an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-a-widget-from-an-incident.md): Create a widget from an incident search in Cortex XSOAR. Create custom widgets from incidents.
* [Export an Incident to CSV Using the UTF8-BOM Format](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format.
* [Incident Investigation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-investigation.md): Open an incident in Cortex SOAR and view incident details.
* [Work Plan](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/work-plan.md): A Cortex XSOAR Work Plan is a visual representation of the running Playbook that is assigned to an incident. Monitor and manage a Playbook work flow.
* [Investigate an Incident Using the Canvas](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
* [Auto Populate the Canvas](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas/auto-populate-the-canvas.md)
* [Dbot Suggestions: Quick View Window](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas/dbot-suggestions-quick-view-window.md)
* [Edit Dbot Incident and Indicator Suggestions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas/edit-dbot-incident-and-indicator-suggestions.md)
* [Incident Actions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-actions.md): Incident actions - add child incidents, tasks, notes, create a report, edit, delete, and restrict an incident type in Cortex XSOAR.
* [Evidence Handling](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the Cortex XSOAR War Room.
* [Incident Tasks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
* [Link Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents.md): Link incidents in the Related Incidents tab, using a pre-process rule, or in the CLI.
* [Manage Related Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents/manage-related-incidents.md)
* [Link and Unlink incidents in the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents/link-and-unlink-incidents-in-the-cli.md)
* [Configure Incident Fields for Related Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/configure-incident-fields-for-related-incidents.md): Configure incident fields for related incidents by adding a server configuration for an allow or ignore list in Cortex XSOAR.
* [Indicator Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Indicator Query](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/indicator-query.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Configure the Indicator Timeline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Exclusion List](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/exclusion-list.md): When adding to an exclusion list, indicators are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Export Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/export-indicators.md): You can export indicators from Cortex XSOAR as a list, external dynamic list, or file, which can then be sent to or pulled by a SIEM, firewall, etc.
* [Manually Export Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/export-indicators/manually-export-indicators.md)
* [Export Indicators Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/export-indicators/export-indicators-integrations.md)
* [Export an Indicator to CSV Using the UTF8-BOM Format](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/export-indicators/export-an-indicator-to-csv-using-the-utf8-bom-format.md)
* [Reference](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference.md): Reference information for Cortex XSOAR.
* [Navigation Cheat Sheet](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
* [Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations.md): Server configurations for Cortex XSOAR, for customization and troubleshooting.
* [Modify Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/modify-server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
* [Active Directory Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/active-directory-server-configurations.md): Server configurations for Active Directory.
* [Automation Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/automation-server-configurations.md): Server configurations for automations.
* [Dashboard Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/dashboard-server-configurations.md): Server configurations for dashboards.
* [Database Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/database-server-configurations.md): Server configurations for the database.
* [Disaster Recovery Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/disaster-recovery-server-configurations.md): Server configurations for disaster recovery.
* [Docker Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/docker-server-configurations.md): Server configurations for Docker.
* [Elasticsearch Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/elasticsearch-server-configurations.md): Server configurations for Elasticsearch.
* [Engine Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/engine-server-configurations.md): Server configurations for engines.
* [General Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/general-server-configurations.md): Miscellaneous server configurations.
* [Google API Server Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/google-api-server-configuration.md): Server configuration for Google API.
* [Incident Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/incident-server-configurations.md): Server configurations for incidents.
* [Indicator Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/indicator-server-configurations.md): Server configurations for indicators.
* [Integration Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/integration-server-configurations.md): Server configurations for integrations.
* [List Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/list-server-configurations.md): Server configurations for lists.
* [Logs Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/logs-server-configurations.md): Server configurations for logs.
* [Marketplace Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/marketplace-server-configurations.md): Server configurations for Marketplace.
* [Multi-Tenant Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/multi-tenant-server-configurations.md): Server configurations for multi-tenant deployments.
* [Notification Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/notification-server-configurations.md): Server configurations for notifications.
* [Playbook Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/playbook-server-configurations.md): Server configurations for playbooks.
* [Proxy Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/proxy-server-configurations.md): Server configurations for proxy servers.
* [Remote Repository Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/remote-repository-server-configurations.md): Server configurations for remote repositories.
* [Report Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/report-server-configurations.md): Server configurations for reports.
* [Security Headers Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/security-headers-server-configurations.md): Server configurations for security headers.
* [SLA Server Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/sla-server-configuration.md): Server configuration for SLAs.
* [System Diagnostics Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/system-diagnostics-server-configurations.md): Server configurations for system diagnostics.
* [Users and Roles Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/users-and-roles-server-configurations.md): Server configurations for users and roles.
* [War Room Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/war-room-server-configurations.md): Server configurations for the War Room.
* [Widget Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/server-configurations/widget-server-configurations.md): Server configurations for widgets.
* [System Diagnostics](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/system-diagnostics.md): Find and fix system performance issues in Cortex XSOAR. System health, system monitoring.
* [Fix System Diagnostics Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/system-diagnostics/fix-system-diagnostics-issues.md): Fix alerts from the System Diagnostics page.
* [Performance Tuning for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/performance-tuning-for-cortex-xsoar.md)
* [Supported Ciphers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/supported-ciphers.md): List of Cipher Suites for TLS1.2 and TLS1.3 supported by Cortex XSOAR Server and Engines
* [Telemetry](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/telemetry.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR. Disable or enable telemetry.
* [Keyboard Shortcuts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage Cortex XSOAR, for playbooks, scripts, CLI, incident pages, and shoulders.
* [Indicator Fields Structure](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/reference-docs/reference/indicator-fields-structure.md): Indicator fields structure aligned with STIX standards to more easily share and work with IOCs.

- [Navigate the Cortex XSOAR 6.13 Administrator Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/navigate-the-cortex-xsoar-6.13-administrator-guide.md): Start here for a visual overview of the main Cortex XSOAR 6.14 documentation areas.
- [Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/readme.md): Cortex XSOAR provides security orchestration, incident management, and interactive investigation. Overview of Cortex XSOAR features and concepts.
- [Get Started in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar.md): Learn about Cortex XSOAR concepts, licenses, and the product lifecycle, as well as basic functionality including the command line, API keys, search, CLI, etc.
- [Licenses](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/licenses.md): The Cortex XSOAR license type determines which components users can utilize. License types are community, starter, or enterprise. Users include audit and full.
- [FIPS Version](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/fips-version.md): Cortex XSOAR offers a FIPS version of Cortex XSOAR, using a software library validated against FIPS 140-3.
- [Concepts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/concepts.md): Cortex XSOAR concepts, including incidents, integrations, playbokos, automations, commands, war room, indicators, playground.
- [Product Support Lifecycle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/product-support-lifecycle.md): Cortex XSOAR major releases product support lifecycle.
- [API Keys](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/api-keys.md): Generate and manage API keys in Cortex XSOAR.
- [Use the Command Line Interface](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/use-the-command-line-interface.md): Cortex XSOAR enables you to run system commands, integration commands, automations, and more, from an integrated CLI.
- [Common Arguments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/use-the-command-line-interface/common-arguments.md): Cortex XSOAR enables you to run system commands, integration commands, automations, and more, from an integrated CLI.
- [How to Search](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/how-to-search.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
- [Using the Search Query](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/how-to-search/using-the-search-query.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
- [How to Use Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/how-to-use-markdown.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
- [New User FAQ](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/new-user-faq.md): New User FAQ for Cortex XSOAR.
- [Onboarding in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/onboarding-in-cortex-xsoar.md): Onboarding process for Cortex XSOAR.
- [Deployment Checklist - Best Practices](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/deployment-checklist-best-practices.md): Overview of the deployment process, including best practices for Cortex XSOAR installation and maintenance.
- [Single Server Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment.md): Install Cortex XSOAR for a single server deployment.
- [System Requirements](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
- [Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/deployment-guidelines.md): Review Cortex XSOAR deployment guidelines for AWS EC2, Azure, or GCP.
- [Install the Server for a Single Server Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/install-the-server-for-a-single-server-deployment.md): Installation instructions and requirements for standard Cortex XSOAR single server deployments, with the app server and database server on the same machine.
- [Install the Server with Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/install-the-server-with-elasticsearch.md): Install Cortex XSOAR with Elasticsearch as the database. Prerequisites and instructions for installing a new Cortex XSOAR environment with Elasticsearch.
- [Install the Server Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline.md): Install Cortex XSOAR when you do not have internet access. Instructions for offline installation.
- [Dependencies for Offline Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline/dependencies-for-offline-installation.md)
- [Add a License](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/add-a-license.md): Add Cortex XSOAR license file, either through the UI or by saving the license file directly on the server.
- [Post-Installation Checklist](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist.md): Common post-installation steps to perform after installing Cortex XSOAR. Cortex XSOAR installation troubleshooting.
- [Monitor Components](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/monitor-components.md)
- [HTTPS with a Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/https-with-a-signed-certificate.md)
- [Install or Renew a Custom Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/https-with-a-signed-certificate/install-or-renew-a-custom-certificate.md)
- [Create a Self-Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/https-with-a-signed-certificate/create-a-self-signed-certificate.md)
- [Configure the Server to Listen on HTTP](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/configure-the-server-to-listen-on-http.md)
- [Troubleshoot WebSockets](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/troubleshoot-websockets.md)
- [Upgrade the Cortex XSOAR Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/upgrade-the-cortex-xsoar-server.md): Upgrading the Cortex XSOAR server including preparation, upgrade and post upgrade steps.
- [Uninstall the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/single-server-deployment/uninstall-the-server.md): Uninstall Cortex XSOAR. Configuration files and files created by engines are not removed.
- [Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch.md): Implementing Cortex XSOAR with Elasticsearch - setup, security, migration, and troubleshooting.
- [Elasticsearch Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-overview.md): Migrating Cortex XSOAR data to Elasticsearch. Object information in an existing Cortex XSOAR instance is copied to a designated Elasticsearch index.
- [Elasticsearch Setup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup.md): Elasticsearch best practices, sizing requirements, and configuration options for Cortex XSOAR.
- [Elasticsearch System Requirements](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-system-requirements.md)
- [Elasticsearch Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-configurations.md)
- [Elasticsearch Data Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-data-management.md)
- [Elasticsearch Security](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-security.md): Elasticsearch security and best practices guidelines for single server and multi-tenant deployments.
- [Elasticsearch General Security Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-security/elasticsearch-general-security-guidelines.md)
- [Elasticsearch Security Guidelines - Multi-tenant Deployments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/elasticsearch-security/elasticsearch-security-guidelines-multi-tenant-deployments.md)
- [Migration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration.md): Learn about migrating Cortex XSOAR data to Elasticsearch for a single server or multi-tenant environment.
- [Elasticsearch Migration Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/elasticsearch-migration-overview.md)
- [Migrate Objects to Elasticsearch for a Single Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-a-single-server.md)
- [Migrate Objects to Elasticsearch for Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-multi-tenant.md)
- [Migrate an Existing Elasticsearch Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/migrate-an-existing-elasticsearch-deployment.md)
- [Migrate Objects to Elasticsearch for a Distributed Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-a-distributed-database.md)
- [Manage Partial Migration to Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/manage-partial-migration-to-elasticsearch.md)
- [Validate the Migration to Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/validate-the-migration-to-elasticsearch.md)
- [Elasticsearch Post Migration Health Check](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/migration/elasticsearch-post-migration-health-check.md)
- [Disaster Recovery for Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch.md): Back up and restore a Cortex XSOAR elasticsearch deployment using snapshots.
- [Create Elasticsearch Snapshots](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/create-elasticsearch-snapshots.md)
- [Restore Elasticsearch Snapshots](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/restore-elasticsearch-snapshots.md)
- [Archive Data with Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/archive-data-with-elasticsearch.md): Archive Cortex XSOAR data you no longer need regular access to, using Elasticsearch index lifecycle management.
- [Troubleshoot Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/elasticsearch/troubleshoot-elasticsearch.md): Troubleshoot common issues in Cortex XSOAR Elasticsearch deployments.
- [Docker](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
- [Docker Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-overview.md): Overview of how Cortex XSOAR uses Docker for security and predictability.
- [Docker Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-installation.md): Install Docker on Enterprise Linux platforms and troubleshoot installation.
- [Configure Python Docker Integrations to Trust Custom Certificates](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/configure-python-docker-integrations-to-trust-custom-certificates.md): Configure CA signed and custom certificates for Docker. Trust custom certificates for python integrations in Cortex XSOAR.
- [Docker Images in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
- [Create a Docker Image In Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/create-a-docker-image-in-cortex-xsoar.md)
- [Install Docker Images Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/install-docker-images-offline.md)
- [Docker Image Security](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/docker-image-security.md)
- [Manage Docker Images](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/manage-docker-images.md)
- [Change the Docker Image for Automations and Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/change-the-docker-image-for-automations-and-integrations.md)
- [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/use-the-cortex-xsoar-container-registry.md)
- [Docker Hardening Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide.md): Use the Docker Hardening Guide to configure the Cortex XSOAR settings when running Docker containers.
- [Run Docker with Non-Root Internal Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
- [Configure Memory Limit Support Without Swap Limit Capabilities](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-memory-limit-support-without-swap-limit-capabilities.md)
- [Configure the Memory Limitation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-memory-limitation.md)
- [Test the Memory Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/test-the-memory-limit.md)
- [Limit Available CPU](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/limit-available-cpu.md)
- [Configure the PIDs Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-pids-limit.md)
- [Configure the Open File Descriptors Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-open-file-descriptors-limit.md)
- [Docker Network Hardening](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-hardening-guide/docker-network-hardening.md)
- [Docker FAQs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/docker-faqs.md): Frequently asked questions (FAQ) about Docker in Cortex XSOAR.
- [Troubleshoot Docker Networking Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/troubleshoot-docker-networking-issues.md): Troubleshoot Docker networking issues in Cortex XSOAR.
- [Troubleshoot Docker Performance Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/troubleshoot-docker-performance-issues.md): Troubleshoot Docker performance issues in Cortex XSOAR. Update Docker package and dependencies.
- [Configure Docker Pull Rate Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/configure-docker-pull-rate-limit.md): Configure the Docker pull rate limit on public images. Create Docker user account and receive higher pull limit.
- [Change the Docker Installation Folder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/docker/change-the-docker-installation-folder.md): Instructions for changing the default Docker folder.
- [Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/podman.md): Run Podman containers instead of Docker for RHEL v8.
- [Podman Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/podman/podman-overview.md): Run Podman containers instead of Docker for operating systems such as RHEL v8.
- [Change container storage directory](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/podman/change-container-storage-directory.md)
- [Podman Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/podman/podman-installation.md): Install Podman for Cortex XSOAR.
- [Configure the SELinux Policy for PowerShell Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/podman/configure-the-selinux-policy-for-powershell-integrations.md): Change the SELinux Policy when running Powershell Integrations in Cortex XSOAR. SELinux policy for Podman.
- [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/podman/migrate-from-docker-to-podman.md): Switch from Docker to Podman in Cortex XSOAR. Migrate from Docker to Podman, for RHEL 8 or later.
- [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/podman/troubleshoot-podman.md): Troubleshoot issues for Podman for Cortex XSOAR.
- [Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/proxy.md): Configure proxy settings in Cortex XSOAR.
- [Configure Proxy Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/proxy/configure-proxy-settings.md): Configure global proxy settings in Cortex XSOAR by adding a server configuration.
- [Configure how to bypass proxy settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/proxy/configure-how-to-bypass-proxy-settings.md): Configure option to bypass a proxy using a server configuration.
- [Use NGINX as a Reverse Proxy to the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/proxy/use-nginx-as-a-reverse-proxy-to-the-server.md): Use NGINX as a Reverse Proxy to the Cortex XSOAR Server.
- [High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability.md): Guide to high availability in Cortex XSOAR, using Elasticsearch. Includes sizing requirements, migration, additional app servers, and signed certificates.
- [High Availability Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/high-availability-overview.md): Overview of high availability in Cortex XSOAR, including information about the different deployment architectures.
- [Set Up High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/set-up-high-availability.md): Overview of the steps required to set up high availability for Cortex XSOAR.
- [Sizing Requirements for High Availability Deployments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/sizing-requirements-for-high-availability-deployments.md): Information about the sizing requirements for Cortex XSOAR High Availability deployments.
- [Monitor the Health of the App Servers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/monitor-the-health-of-the-app-servers.md): Monitor the health of the app servers in a Cortex XSOAR high availability environment.
- [Migrate a Single Instance for High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/migrate-a-single-instance-for-high-availability.md): Migrate your Cortex XSOAR single instance deployment to a high availability installation of Cortex XSOAR.
- [Migrate a Multi-Tenant Deployment for High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/migrate-a-multi-tenant-deployment-for-high-availability.md): Migrate your Cortex XSOAR Multi-tenant deployment to enable High Availability.
- [Install Additional App Servers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/install-additional-app-servers.md): Install additional app servers for a Cortex XSOAR high availability configuration.
- [Deploy Engines in a High Availability Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/deploy-engines-in-a-high-availability-environment.md): When adding application servers, update the engines to connect through the load balancer.
- [Use a Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/high-availability/use-a-signed-certificate.md): Use a signed certificate in a Cortex XSOAR high availability deployment.
- [Disaster Recovery and Live Backup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup.md): Live backup and disaster recovery options for Cortex XSOAR.
- [Disaster Recovery and Live Backup Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/disaster-recovery-and-live-backup-overview.md): Describes live backup, how to configure your environment, server DR status, and disaster recovery scenarios in Cortex XSOAR.
- [Host Names, DNS, and Disaster Recovery](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/host-names-dns-and-disaster-recovery.md): Unique host names and DNS considerations for disaster recovery for Cortex XSOAR.
- [Configure the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment.md): Configure a live backup environment by mirroring your production server to a backup server in Cortex XSOAR.
- [Configure Live Backup for Multiple SAMLs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/configure-live-backup-for-multiple-samls.md)
- [DR Scenario: Testing the DR Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/dr-scenario-testing-the-dr-environment.md)
- [DR Scenario: Unrecoverable Active Server Failure](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/dr-scenario-unrecoverable-active-server-failure.md)
- [DR Scenario: Unrecoverable Standby Server Failure](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment/dr-scenario-unrecoverable-standby-server-failure.md)
- [Transition an Active Server to Standby Mode](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-an-active-server-to-standby-mode.md): Change an active server to standby mode in Cortex XSOAR.
- [Transition a Standby Server to Active Mode](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-a-standby-server-to-active-mode.md): Transition a standby server to active mode (production) in Cortex XSOAR.
- [Transition Between DR States Through the Configuration File](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-between-dr-states-through-the-configuration-file.md): Transition disaster recovery states between active and standby using the configuration file when the server is new and starts for the first time.
- [Upgrade the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/upgrade-the-live-backup-environment.md): Upgrade your live backup environment for Cortex XSOAR.
- [Engines and Disaster Recovery Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/engines-and-disaster-recovery-troubleshooting.md): Troubleshoot Cortex XSOAR engine failover issues when an engine does not automatically fail over to the active node in a disaster recovery situation.
- [Back up the Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/back-up-the-database.md): Perform manual and automatic backups of the Cortex XSOAR database. Configure automated backup options. Schedule backups.
- [Restore the Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/restore-the-database.md): Restore the database from a manual backup or automated backup back up in Cortex XSOAR.
- [Restore a Partition](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/restore-a-partition.md): Restore one or more specific partitions in Cortex XSOAR.
- [Troubleshoot Live Backup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/disaster-recovery-and-live-backup/troubleshoot-live-backup.md): How to troubleshoot live backup scenarios in Cortex XSOAR.
- [Users and Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles.md): Users and roles in Cortex XSOAR, including permissions, user settings, shifts, and authentication options.
- [Users and Roles Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/users-and-roles-overview.md): Manage users, roles, invitations, password policies, and view information about users activities in Cortex XSOAR.
- [Roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar.md): The default admin is the super user role in XSOAR. Administrator, Analyst, and Read-Only roles are defined by the read-write level of access to XSOAR components.
- [Pre-set Query per Role](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/pre-set-query-per-role.md)
- [Define a Role](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/define-a-role.md)
- [Role-based Permission Levels](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/role-based-permission-levels.md)
- [Shift Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/shift-management.md)
- [Managing Shifts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/shift-management/managing-shifts.md)
- [User Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management.md): Invite and manage users in Cortex XSOAR. Edit user roles, reset passwords, disable or remove users.
- [User Invitations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/user-invitations.md)
- [Invite a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/user-invitations/invite-a-user.md)
- [Set the User as Default Administrator](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/set-the-user-as-default-administrator.md)
- [Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users.md)
- [Configure the Server for Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/configure-the-server-for-self-service-read-only-users.md)
- [Create the Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-self-service-read-only-users.md)
- [Create the Read-Only Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-read-only-dashboard.md)
- [Create the Read-Only Incident Type and Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-read-only-incident-type-and-layout.md)
- [Disable a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/disable-a-user.md)
- [Remove a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/remove-a-user.md)
- [Clear Users Data Using the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/clear-users-data-using-the-cli.md)
- [Clear Users Data Using a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/clear-users-data-using-a-playbook.md)
- [Configure Users Data Using Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/configure-users-data-using-server-configurations.md)
- [User Settings and Preferences](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/user-settings-and-preferences.md)
- [Configure User Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/configure-user-settings.md)
- [Manually Refresh the Number of Licenses in Use](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/user-management/manually-refresh-the-number-of-licenses-in-use.md)
- [Integration Permissions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/integration-permissions.md): Integration permissions enable you to assign permissions to commands in integrations. Use role based access control (RBAC) to assign commands.
- [Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/password-policy.md): Describes the password policy and how to set it in Cortex XSOAR.
- [Create a Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/password-policy/create-a-password-policy.md)
- [Edit a Default Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/password-policy/edit-a-default-password-policy.md)
- [Default Password Policy Keys](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/password-policy/edit-a-default-password-policy/default-password-policy-keys.md)
- [Change the Administrator Password](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/change-the-administrator-password.md): Create a new password for the Cortex XSOAR administrator account, if you are unable to log in, by manually adding a new administrator.
- [Authenticate Users with SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0.md): Authenticate users using SAML 2.0 with your identity provider, for Cortex XSOAR. Use Okta, Microsoft Entra ID, or ADFS.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Create Okta Groups for Cortex XSOAR Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/create-okta-groups-for-cortex-xsoar-users.md)
- [Define the Okta Application to authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/define-the-okta-application-to-authenticate-cortex-xsoar.md)
- [SAML Settings for the Okta Application](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/define-the-okta-application-to-authenticate-cortex-xsoar/saml-settings-for-the-okta-application.md)
- [Configure the SAML 2.0 Integration for Okta](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-okta.md)
- [SAML 2.0 Okta Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-okta/saml-2.0-okta-parameters.md)
- [Map Okta Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/map-okta-groups-to-cortex-xsoar-roles.md)
- [Set Up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
- [Configure Microsoft Entra ID to Authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-microsoft-entra-id-to-authenticate-cortex-xsoar.md)
- [Configure the SAML 2.0 Integration for Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-microsoft-entra-id.md)
- [SAML 2.0 Microsoft Entra ID Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-microsoft-entra-id/saml-2.0-microsoft-entra-id-parameters.md)
- [Set up ADFS as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0.md)
- [Create Relying Party Trust in ADFS](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/create-relying-party-trust-in-adfs.md)
- [Define the Claim Issuance Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/define-the-claim-issuance-policy.md)
- [Configure the SAML 2.0 Integration for ADFS](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-adfs.md)
- [SAML 2.0 ADFS Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-adfs/saml-2.0-adfs-parameters.md)
- [Map ADFS Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/map-adfs-groups-to-cortex-xsoar-roles.md)
- [Duo for Single Sign-On](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on.md)
- [Create Duo Groups for Cortex XSOAR Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/create-duo-groups-for-cortex-xsoar-users.md)
- [Define Duo to authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/define-duo-to-authenticate-cortex-xsoar.md)
- [Configure the SAML 2.0 Integration for Duo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/configure-the-saml-2.0-integration-for-duo.md)
- [Map Duo Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/map-duo-groups-to-cortex-xsoar-roles.md)
- [Set the Default Theme for New Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/set-the-default-theme-for-new-users.md): Set the default color theme for new Cortex XSOAR users by adding a server configuration. Users can change the theme in user preferences.
- [Authenticate Users with Active Directory](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-active-directory.md): Users can log in to Cortex XSOAR with their Active Directory username and passwords
- [Marketplace](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace.md): Access the Cortex XSOAR Marketplace and install content packs. Convert existing content to content pack format.
- [Marketplace Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/marketplace-overview.md): Use Cortex XSOAR Marketplace to install, exchange, contribute and manage your content.
- [Content Packs Support Types](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-packs-support-types.md): Types of content packs Support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
- [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
- [Search and Navigate in the Marketplace](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/search-and-navigate-in-the-marketplace.md): Search the Cortex XSOAR Marketplace and find free and paid content. Search by use cases, integrations, categories, etc.
- [Convert Existing Content to Content Pack Format](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/convert-existing-content-to-content-pack-format.md): Convert content to content pack format when upgrading from a version earlier than Cortex XSOAR 6.0.
- [Use Cases](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/use-cases.md): Common use cases for Cortex XSOAR, including analytics and siem, authentication, case management, data enrichment, threat intelligence, forensic and malware,
- [Content Pack Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-installation.md): Cortex XSOAR content pack dependencies, errors and warning messages.
- [Install a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-installation/install-a-content-pack.md): Install a content pack and its required dependencies from Marketplace.
- [Set up Your Use Case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-installation/install-a-content-pack/set-up-your-use-case-with-the-deployment-wizard.md): Configure a supported content pack for your use case.
- [Update a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-installation/update-a-content-pack.md): Update an installed content pack from Marketplace.
- [Delete a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-installation/delete-a-content-pack.md): Delete an installed content pack from Marketplace.
- [Revert a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-installation/revert-a-content-pack.md): Revert an installed content pack to an earlier version.
- [Install a Content Pack Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/install-a-content-pack-offline.md): Download Cortex XSOAR Marketplace content packs and then upload offline to install on a machine without an internet connection (air gapped).
- [Content Pack Update Notifications](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs
- [Marketplace Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/marketplace-troubleshooting.md): Troubleshoot Marketplace issues regarding login, connectivity, timeouts, and certificates.
- [Content Pack Contributions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
- [Create a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md)
- [Resubmit a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md)
- [Remote Repositories in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar.md): Configure a remote repository on a development and production machine and edit and push content.
- [Content Management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/content-management-in-cortex-xsoar.md): Cortex XSOAR offers multiple options for developing content, including a remote repository and CI/CD.
- [Remote Repositories Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/remote-repositories-overview.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
- [Configure a Remote Repository on a Development Machine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/configure-a-remote-repository-on-a-development-machine.md): Configure a remote repository on a development machine. Add content repository in Cortex XSOAR.
- [Configure a Remote Repository on the Production Machine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/configure-a-remote-repository-on-the-production-machine.md): Configure a remote repository on a production machine. Define the repository and pull content.
- [Edit and Push Content to a Remote Repository](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/edit-and-push-content-to-a-remote-repository.md): Push content to a remote repository and control access for pushing content.
- [Upgrade Remote Repositories from Versions 5.5 and below](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/upgrade-remote-repositories-from-versions-5.5-and-below.md): Upgrade Cortex XSOAR remote repository environment from 5.5 to 6.5 and above.
- [Troubleshoot a Remote Repository Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/troubleshoot-a-remote-repository-configuration.md): Troubleshoot issues for a Cortex XSOAR remote repository configuration plus FAQs.
- [Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot Cortex XSOAR engines.
- [Cortex XSOAR Engines Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/cortex-xsoar-engines-overview.md): Understand Cortex XSOAR engine architecture, load balancing groups, installation and configurations.
- [Engine Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/engine-installation.md): Review system requirements and engine installation types (Shell, DEB, RPM, Zip, Configuration) available for Cortex XSOAR engines.
- [Install a Cortex XSOAR Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/engine-installation/install-a-cortex-xsoar-engine.md)
- [Install a Signed Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/engine-installation/install-a-signed-engine.md)
- [Install a Cortex XSOAR Engine Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/engine-installation/install-a-cortex-xsoar-engine-offline.md)
- [Use an Engine in an Integration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use a Cortex XSOAR engine or load-balancing group of engines to fetch incidents and run commands for an integration.
- [Run a Script using an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load balancing group. Run an automation from an engine or load balancing group.
- [Manage Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/manage-engines.md): Manage engines and load balancing groups in Cortex XSOAR.
- [Configure Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines to change the number of workers, access communication tasks, notify users if engine disconnects, and remove server from group.
- [Edit the Engine Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration.md)
- [Common Properties When Editing an Engine Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/common-properties-when-editing-an-engine-configuration.md)
- [Configure the Engine to Use a Web Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/configure-the-engine-to-use-a-web-proxy.md)
- [Configure the Engine to Call the Server Without Using a Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
- [Configure the Number of Workers for the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/configure-the-number-of-workers-for-the-server.md)
- [Configure Access to Communication Tasks through an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/configure-access-to-communication-tasks-through-an-engine.md)
- [Configure an Engine to Use Custom Certificates](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/configure-an-engine-to-use-custom-certificates.md)
- [Notify Users When an Engine Disconnects](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/configure-engines/notify-users-when-an-engine-disconnects.md)
- [Remove an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/remove-an-engine.md): Remove a Cortex XSOAR engine. Commands vary depending on your operating system.
- [Troubleshoot Cortex XSOAR Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/troubleshoot-cortex-xsoar-engines.md): Troubleshoot Cortex XSOAR engines by accessing logs and viewing errors.
- [Troubleshoot Engine Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/troubleshoot-cortex-xsoar-engines/troubleshoot-engine-installation.md)
- [Troubleshoot Engine Upgrades](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/troubleshoot-cortex-xsoar-engines/troubleshoot-engine-upgrades.md)
- [Troubleshoot Engine Connectivity](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/troubleshoot-cortex-xsoar-engines/troubleshoot-engine-connectivity.md)
- [Troubleshoot Integrations Running on Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/onboard-cortex-xsoar/engines/troubleshoot-cortex-xsoar-engines/troubleshoot-integrations-running-on-engines.md)
- [Customize and Configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar.md): Customize and configure your Cortex XSOAR deployment.
- [Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents.md): Manage and investigate incidents in Cortex XSOAR.
- [Incident Lifecycle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle.md): Incidents are potential security data threats that analysts identify and remediate in Cortex XSOAR.
- [Fetch Incidents From an Integration Instance](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle/fetch-incidents-from-an-integration-instance.md)
- [Receive Notification on an Incident Fetch Error](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle/receive-notification-on-an-incident-fetch-error.md)
- [Incident Context Data](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-context-data.md): Learn about incident context data, how it is stored in Cortex XSOAR, and how to access it.
- [Incident Customization](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization.md): Customize incidents in Cortex XSOAR. Attach and detach incident types. Customize indicator extraction, incident types, fields, and layouts.
- [Create an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/create-an-incident-type.md)
- [Customize Incident Layouts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/customize-incident-layouts.md)
- [Incident Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields.md)
- [Create a Custom Incident Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-a-custom-incident-field.md)
- [Create a Grid Field for an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-a-grid-field-for-an-incident-type.md)
- [Use Scripts with the Grid Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/use-scripts-with-the-grid-field.md)
- [Incident Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/incident-field-trigger-scripts.md)
- [Troubleshoot Closing Case Incident after Changing Field Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/troubleshoot-closing-case-incident-after-changing-field-type.md)
- [Create an Evidence Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-an-evidence-field.md)
- [Incident De-Duplication](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-de-duplication.md): De-duplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
- [Manually De-Duplicate Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-de-duplication/manually-de-duplicate-incidents.md)
- [Automatic De-Duplication Using Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-de-duplication/automatic-de-duplication-using-scripts.md)
- [Pre-Process Rules](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
- [Create Pre-Process Rules for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/pre-process-rules/create-pre-process-rules-for-incidents.md)
- [Rule Actions for Pre-Process Rules](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/pre-process-rules/rule-actions-for-pre-process-rules.md)
- [Post Processing for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR.
- [Create a Post-Processing Script](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents/create-a-post-processing-script.md)
- [Add a Post-Processing Script to the Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents/add-a-post-processing-script-to-the-incident-type.md)
- [War Room Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview.md): Use the Cortex XSOAR War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
- [Schedule a Command](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/schedule-a-command.md)
- [Add a Custom Widget in the War Room](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/add-a-custom-widget-in-the-war-room.md)
- [War Room Indexing](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing.md)
- [Index War Room Entries Using Bolt DB](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing/index-war-room-entries-using-bolt-db.md)
- [Index War Room Entries Using Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing/index-war-room-entries-using-elasticsearch.md)
- [Incident Access Control Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-access-control-configuration.md): Limit access to incidents and investigations in Cortex XSOAR, using role-based access control (RBAC).
- [Limit Access to Investigations using RBAC](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-access-control-configuration/limit-access-to-investigations-using-rbac.md)
- [Restrict an Investigation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-access-control-configuration/restrict-an-investigation.md)
- [Classification and Mapping](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/classification-and-mapping.md): Classify and map incoming data from an integration instance.
- [Classify Events Using a Classification Key](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/classification-and-mapping/classify-events-using-a-classification-key.md)
- [Create a Mapper](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/classification-and-mapping/create-a-mapper.md)
- [Incident Mirroring](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-mirroring.md): Set up your integration to mirror incidents between a third-party application and Cortex XSOAR.
- [Customize Incident Close Reasons](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
- [Change the Display Name of Security Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/change-the-display-name-of-security-incidents.md): Add a Cortex XSOAR server configuration to change the name of security incidents from ‘incident’ to another term - cases, issues, etc.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks.md): Cortex XSOAR playbooks enable you to organize and document security monitoring, orchestration, and response activities.
- [What Are Playbooks?](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/what-are-playbooks.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
- [Playbook Development](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-development.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes.
- [Configure IoT Security Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/configure-iot-security-playbooks.md): IoT Security playbooks enable you to structure and automate many of your third-party security processes. Parse incident information, interact with users, and remediate.
- [Manage Playbook Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/manage-playbook-settings.md): Manage Cortex XSOAR playbook settings, including role access, which incident type triggers it, and options for Quiet Mode.
- [Obtain Playbook Metadata](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/manage-playbook-settings/obtain-playbook-metadata.md)
- [Version Control](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/version-control.md): Save versions of your playbook as you are developing it.
- [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields.md): All of the fields available when defining a playbook task in Cortex XSOAR.
- [Create Section Headers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/create-section-headers.md)
- [Create a Conditional Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/create-a-conditional-task.md)
- [Communication Tasks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks.md)
- [Create an Ask Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task.md)
- [Ask Task Examples](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task/ask-task-examples.md)
- [Customize an Ask Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task/customize-an-ask-task.md)
- [Create a Data Collection Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task.md)
- [Data Collection Task Examples](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task/data-collection-task-examples.md)
- [Customize a Data Collection Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task/customize-a-data-collection-task.md)
- [Customize the SOC Name](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/customize-the-soc-name.md)
- [Create Communication Task Authentication](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-communication-task-authentication.md)
- [Add Ad Hoc Tasks to a Work Plan](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/add-ad-hoc-tasks-to-a-work-plan.md)
- [Handle Errors in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/handle-errors-in-a-playbook.md)
- [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/playbook-task-fields.md)
- [Playbook Inputs and Outputs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-inputs-and-outputs.md): Cortex XSOAR playbooks and tasks have inputs (data from incident or integration) and outputs that can then be used as input in other tasks.
- [Extend Context](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
- [Extend Context in a Playbook Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context/extend-context-in-a-playbook-task.md)
- [Extend Context using the Command Line](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context/extend-context-using-the-command-line.md)
- [Use DT syntax to get select keys from a list of dictionaries](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context/use-dt-syntax-to-get-select-keys-from-a-list-of-dictionaries.md)
- [Filters and Transformers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers.md): Use filters and transformers to manipulate data in Cortex XSOAR. Use filters and transformers in playbook tasks or when mapping an instance.
- [Create Filters and Transformers in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook.md)
- [Create a Filter Example](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-example.md)
- [Create a Filter (Advanced) Example](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-advanced-example.md)
- [Filter Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators.md)
- [Built-in Filters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/built-in-filters.md)
- [Transformers Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/transformers-operators.md)
- [Create Custom Filter and Transformer Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/create-custom-filter-and-transformer-operators.md)
- [Automations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/automations.md): Create and edit an automation in Cortex XSOAR, including detach and attach, automation settings, etc.
- [Special Automation Tags](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/automations/special-automation-tags.md)
- [Common Scripts to use in Automations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/automations/common-scripts-to-use-in-automations.md)
- [Configure a Sub-playbook Loop](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/configure-a-sub-playbook-loop.md): Configure a sub-playbook to run in a loop.
- [Playbook Polling](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-polling.md): Cortex XSOAR Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
- [Create Incident Fields in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/create-incident-fields-in-a-playbook.md): Use the setIncident automation to set and update all system incident fields.
- [Playbook Testing](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-testing.md): Test your playbook with ingested incidents.
- [Debug a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-testing/debug-a-playbook.md)
- [Debugger Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-testing/debugger-troubleshooting.md)
- [Best Practices](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/best-practices.md): Best practices for working with playbooks.
- [Jobs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
- [Create a Time Triggered Job](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
- [Create a Job Triggered by a Delta in Feed](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
- [Time Triggered Job Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/time-triggered-job-parameters.md): Description of the parameters available when creating a time triggered job.
- [Process Indicators Using a Job Triggered By Delta](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/process-indicators-using-a-job-triggered-by-delta.md): Provides an example of using a job triggered by a delta in a feed to process incoming indicators.
- [Add Indicators to SIEM Using a Time Triggered Job](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/add-indicators-to-siem-using-a-time-triggered-job.md): Use a time-triggered job to push indicators to a SIEM.
- [Work with SLAs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas.md): Create and manage SLAs and timers and SLA scripts. Search by SLA and timer fields. Configure global risk threshold in Cortex XSOAR.
- [SLA Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/sla-overview.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
- [Create an SLA Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/create-an-sla-field.md): Create new SLA or timer and add SLA script to trigger when SLA time has passed.
- [Manage SLA and Timer Fields in an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/manage-sla-and-timer-fields-in-an-incident.md): Manage timers and SLA for a specific incident, such as decreasing required response time for a high priority incident.
- [Create an SLA Trigger](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/create-an-sla-trigger.md): Trigger times to start, pause, or stop when a certain task occurs in a Cortex XSOAR playbook.
- [Customize SLA Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/customize-sla-scripts.md): Create scripts that will perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
- [Search Incidents using SLA and Timer Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/search-incidents-using-sla-and-timer-fields.md): Search incidents based on their SLA status, a SLA field, or a timer field.
- [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change SLA Risk threshold from default 72 hours.
- [Machine Learning](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning.md): Understand machine learning models in Cortex XSOAR. P
- [Machine Learning Capabilities](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/machine-learning-capabilities.md): Machine Learning capabilities using the Phishing Classifier and automations.
- [Machine Learning Models](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/machine-learning-models.md): Use machine learning (ML) models in Cortex XSOAR to analyze and predict future behavior. Machine learning for phishing incidents.
- [Use the Phishing Classifier in Production](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/use-the-phishing-classifier-in-production.md): The phishing classifier enables you to train a machine learning model for incidents.
- [Create a Machine Learning Model](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/create-a-machine-learning-model.md): Create a machine learning (ml) model in Cortex XSOAR to predict the classification of phishing incidents.
- [Phishing Classifier Demo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/phishing-classifier-demo.md): Use the phishing classifier demo to see how a classifier works for machine learning (ml) in Cortex XSOAR.
- [Train a Phishing Classifier on Non-English Languages](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/train-a-phishing-classifier-on-non-english-languages.md): Train a phishing classifier for non English language emails through tokenization methods. Cortex XSOAR machine learning.
- [Additional Machine Learning Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/additional-machine-learning-scripts.md): Additional machine learning scripts
- [Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists.md): Create and manage lists in Cortex XSOAR.
- [Work With Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/work-with-lists.md): Manage lists in Cortex XSOAR that can be accessed by automations, playbooks, etc.
- [Work with JSON Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/work-with-lists/work-with-json-lists.md)
- [Create a List](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/create-a-list.md): Create predefined lists in Cortex XSOAR that can be parsed by and modified by scripts.
- [Set the List Separator Character](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/set-the-list-separator-character.md): Set the list separator character in Cortex XSOAR. The default separator for lists is a comma.
- [Transform a List into an Array](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an instance in Cortex XSOAR.
- [Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts and an exclusion list.
- [Indicator Concepts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-concepts.md): Cortex XSOAR provides threat intelligence management. TIM concepts include fetch indicators, configure indicators, and export indicators. Threat intel management
- [Indicator Verdict](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-verdict.md): Indicator verdict affects how the indicator is processed and handled in Cortex XSOAR. Assigned by reputation returned by the source with highest reliability.
- [Indicator Ingestion](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-ingestion.md): Overview of how Cortex XSOAR indicators are detected and ingested.
- [Indicator Customization](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md): Customize indicator types, fields, and layouts.
- [Indicator Types](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types.md): Configure indicator types and their associated scripts and fields.
- [File Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/file-indicators.md): Manage file indicators and their associated hashes.
- [File Indicator Merging Strategy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/file-indicators/file-indicator-merging-strategy.md): Understand how file indicators merge by hash.
- [Create an Indicator Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/create-an-indicator-type.md): Create a custom indicator type.
- [Indicator Type Profile](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/indicator-type-profile.md): Configure indicator type profile settings.
- [Map Custom Indicator Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/map-custom-indicator-fields.md): Map custom fields to indicator data.
- [Formatting Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/formatting-scripts.md): Format indicator values and output.
- [Enhancement Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/enhancement-scripts.md): Configure scripts that enhance indicators on demand.
- [Reputation Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/reputation-scripts.md): Configure scripts that calculate indicator verdicts.
- [Reputation Commands](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/reputation-commands.md): Configure commands that calculate indicator verdicts.
- [Indicator Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields.md): Create and configure fields for indicators.
- [Create a Custom Indicator Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md): Create a custom field for indicators.
- [Configure the HTML Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field/configure-the-html-field.md): Configure HTML fields for indicators.
- [Indicator Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/indicator-field-trigger-scripts.md): Run scripts when indicator field values change.
- [Indicator Layouts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts.md): Customize layouts for indicator types.
- [Customize an Indicator Type Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts/customize-an-indicator-type-layout.md): Customize a layout for an indicator type.
- [Add a Script in the Indicator Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts/add-a-script-in-the-indicator-layout.md): Add dynamic script output to an indicator layout.
- [Indicator Extraction](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction.md): Indicator extraction extracts indicators from incident fields and enriches them with commands and scripts defined for the indicator type.
- [Indicator Extraction Modes](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/indicator-extraction-modes.md): Indicator extraction modes and their behavior.
- [Create Indicator Extraction Rules for an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md): Configure indicator extraction rules for incident types.
- [Run Indicator Extraction in the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/run-indicator-extraction-in-the-cli.md): Extract and enrich indicators from the command line.
- [Create Indicator Extract Rules for a Playbook Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/create-indicator-extract-rules-for-a-playbook-task.md): Configure indicator extraction for playbook tasks.
- [Disable Indicator Extraction for Automations or Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/disable-indicator-extraction-for-automations-or-integrations.md): Disable indicator extraction for specific automations or integrations.
- [Indicator Expiration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a period of time or never to expire. Set default expiration method.
- [Feed Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/feed-integrations.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
- [Set the Source Reliability of Enrichment Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/feed-integrations/set-the-source-reliability-of-enrichment-integrations.md)
- [Dashboards](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
- [Dashboard Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/dashboard-overview.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
- [Create a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/create-a-dashboard.md): Create and customize a dashboard in Cortex SOAR. Add widgets to a dashboard.
- [Add a Widget to a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/add-a-widget-to-a-dashboard.md): Add a widget to an existing or new dashboard in Cortex XSOAR. Edit widget parameters including date range.
- [Share a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/share-a-dashboard.md): Share or stop sharing a Cortex XSOAR dashboard with other users by role. Set permissions for shared dashboards.
- [Edit a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/edit-a-dashboard.md): Edit an existing dashboard in Cortex XSOAR. Add, delete or change widgets. Change date range. Adjust size and position of widgets.
- [Reports](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
- [Reports Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/reports-overview.md): Overview of Cortex XSOAR reports and how to create and edit reports. Analyze data in PDF, Word, and CSV formats. Upload your own logo.
- [Create a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/create-a-report.md): Create a new report in Cortex XSOAR. Add widgets and customize report. Schedule a report.
- [Schedule a report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/schedule-a-report.md): Schedule a report in Cortex XSOAR to run at a specific time. Send reports by email, choose recipients.
- [Customize the Email When Sending a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/customize-the-email-when-sending-a-report.md): Changes the email subject, body, and body HTML when scheduling a report.
- [Create an Incident Summary Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
- [Select and Customize Sections to Export to a Summary Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/select-and-customize-sections-to-export-to-a-summary-report.md): Select sections to export from the legacy Summary page to a Summary report in Cortex XSOAR. Save report as a template.
- [Add a Widget to a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/add-a-widget-to-a-report.md): Add a widget to a report in Cortex XSOAR.
- [Edit a report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/edit-a-report.md): Edit a report by adding, editing, or removing widgets, and changing the layout and the output type. You cannot edit system reports or incident summary reports.
- [Change the Report Logo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/change-the-report-logo.md): Add a company or organization logo to a report in Cortex XSOAR. Customize report logo with a server configuration.
- [Configure the Time Zone and Format in a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/configure-the-time-zone-and-format-in-a-report.md): Change the time zone and time format in a Cortex XSOAR report. Report troubleshooting
- [Troubleshoot Reports](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/troubleshoot-reports.md): Troubleshoot Cortex XSOAR reports by viewing JSON file. Add temporary server configuration to download and view JSON file for troubleshooting.
- [Widgets](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboard
- [Widgets Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/widgets-overview.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
- [Create a Widget using the Widget Builder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in Cortex XSOAR and then add widget to a dashboard or report.
- [Create a Custom Widget Using a JSON File](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
- [Create a Custom Widget Using an Automation Script](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-custom-widget-using-an-automation-script.md): Create a custom script based widget in Cortex XSOAR using an Automation Script. Use custom widgets in dashboards and reports.
- [Edit a Widget](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
- [Create a Used Percentage Widget for a Disk Partition](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-used-percentage-widget-for-a-disk-partition.md): Add server configuration and create new dashboard for used percentage widget for a disk partition in Cortex XSOAR.
- [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/saved-by-dbot-roi-widget.md): Customize Saved by Dbot widget that calculates the amount saved by Cortex XSOAR, using a server configuration. Return on Investment (ROI) widget.
- [Manage Data](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data.md): Manage data in Cortex XSOAR, reindex database or specific index database, free up disk space, migrate data, restore an archive.
- [Reindex the Entire Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-the-entire-database.md): Reindex the database in Cortex XSOAR.
- [Reindex a Specific Index Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-a-specific-index-database.md): Reindex a specific index database in Cortex XSOAR. Reindex multiple index databases.
- [Reindex the Audit Log](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-the-audit-log.md): Reindex the audit log to recover audit trail historical data in Cortex XSOAR.
- [Free up Disk Space with Data Archiving](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/free-up-disk-space-with-data-archiving.md): Free up disk space by archiving Cortex XSOAR folders to condense the unused data within them.
- [Archive Artifacts and Attachments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/archive-artifacts-and-attachments.md): Archive artifacts and attachments folders.
- [Store Incident/Artifact Files in the Cloud](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/store-incidentartifact-files-in-the-cloud.md): Store incident attachments and artifact files including War Room, or through a Playbook.
- [Migrate Data to Another Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/migrate-data-to-another-server.md): Migrate Cortex XSOAR data to another server, move data, copy files and directories.
- [Migrate Data to Another Server for Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/migrate-data-to-another-server-for-multi-tenant.md): Migrate Cortex XSOAR data to another server in a multi-tenant environment.
- [Move Data Folders to Another Location on the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/move-data-folders-to-another-location-on-the-server.md): Move Cortex XSOAR data folders to a different location on the server.
- [Restore an Archived Folder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/restore-an-archived-folder.md): Restore an archived folder in Cortex XSOAR.
- [Logs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs.md): Cortex XSOAR includes a server log and an audit trail as well as the ability to download a log bundle.
- [Logs Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/logs-overview.md): Cortex XSOAR logs information you can use for troubleshooting.
- [Configure the Server Log](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/configure-the-server-log.md): Configure the server log for maximum size, log level, number of files to backup and days to retain log files, in Cortex SXSOAR.
- [Configure the Access Log for HTTPS Requests](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/configure-the-access-log-for-https-requests.md): Add a server configuration to view HTTP/HTTPS requests.
- [Create a Log Bundle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/create-a-log-bundle.md): Create a log bundle of additional logs for troubleshooting in Cortex XSOAR.
- [Audit Trail](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/audit-trail.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
- [Send the Audit Trail to an External Log Service](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/send-the-audit-trail-to-an-external-log-service.md): Send the Cortex XSOAR audit trail to an external log service by adding custom server configurations.
- [System Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings.md): Customize the logo, the login message, system emails, and system notifications.
- [Customize the Logo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-the-logo.md): Customize the full-size and minimized logo in Cortex XSOAR.
- [Customize the Login Message](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-the-login-message.md): Customize the message that appears to users on the login page before logging in to Cortex XSOAR.
- [Customize System Emails](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-system-emails.md): Customize subject and message body for Cortex XSOAR system emails and choose HTML and/or text format.
- [Configure System Notifications](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/configure-system-notifications.md): Configure email system notifications in Cortex XSOAR, choose mail sender with advanced server configuration settings.
- [Day to Day Tasks in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar.md): Manage daily incident and indicator management tasks in Cortex XSOAR.
- [Incident Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management.md): Open, investigate, and manage incidents in Cortex XSOAR.
- [Create an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-an-incident.md): Create a new incident in Cortex XSOAR, manually, through a feed, or by importing a JSON file.
- [Create a Search Query for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-a-search-query-for-incidents.md): Create a search query for Cortex XSOAR incidents. Customize which incidents are displayed. Save search queries.
- [Create a Widget From an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-a-widget-from-an-incident.md): Create a widget from an incident search in Cortex XSOAR. Create custom widgets from incidents.
- [Export an Incident to CSV Using the UTF8-BOM Format](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format.
- [Incident Investigation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-investigation.md): Open an incident in Cortex SOAR and view incident details.
- [Work Plan](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/work-plan.md): A Cortex XSOAR Work Plan is a visual representation of the running Playbook that is assigned to an incident. Monitor and manage a Playbook work flow.
- [Investigate an Incident Using the Canvas](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
- [Auto Populate the Canvas](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas/auto-populate-the-canvas.md)
- [Dbot Suggestions: Quick View Window](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas/dbot-suggestions-quick-view-window.md)
- [Edit Dbot Incident and Indicator Suggestions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas/edit-dbot-incident-and-indicator-suggestions.md)
- [Incident Actions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-actions.md): Incident actions - add child incidents, tasks, notes, create a report, edit, delete, and restrict an incident type in Cortex XSOAR.
- [Evidence Handling](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the Cortex XSOAR War Room.
- [Incident Tasks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
- [Link Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents.md): Link incidents in the Related Incidents tab, using a pre-process rule, or in the CLI.
- [Manage Related Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents/manage-related-incidents.md)
- [Link and Unlink incidents in the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents/link-and-unlink-incidents-in-the-cli.md)
- [Configure Incident Fields for Related Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/configure-incident-fields-for-related-incidents.md): Configure incident fields for related incidents by adding a server configuration for an allow or ignore list in Cortex XSOAR.
- [Indicator Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Indicator Query](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/indicator-query.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Configure the Indicator Timeline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
- [Exclusion List](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/exclusion-list.md): When adding to an exclusion list, indicators are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
- [Export Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/export-indicators.md): You can export indicators from Cortex XSOAR as a list, external dynamic list, or file, which can then be sent to or pulled by a SIEM, firewall, etc.
- [Reference](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference.md): Reference information for Cortex XSOAR.
- [Navigation Cheat Sheet](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
- [Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations.md): Server configurations for Cortex XSOAR, for customization and troubleshooting.
- [Modify Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/modify-server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
- [Active Directory Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/active-directory-server-configurations.md): Server configurations for Active Directory.
- [Automation Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/automation-server-configurations.md): Server configurations for automations.
- [Dashboard Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/dashboard-server-configurations.md): Server configurations for dashboards.
- [Database Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/database-server-configurations.md): Server configurations for the database.
- [Disaster Recovery Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/disaster-recovery-server-configurations.md): Server configurations for disaster recovery.
- [Docker Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/docker-server-configurations.md): Server configurations for Docker.
- [Elasticsearch Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/elasticsearch-server-configurations.md): Server configurations for Elasticsearch.
- [Engine Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/engine-server-configurations.md): Server configurations for engines.
- [General Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/general-server-configurations.md): Miscellaneous server configurations.
- [Google API Server Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/google-api-server-configuration.md): Server configuration for Google API.
- [Incident Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/incident-server-configurations.md): Server configurations for incidents.
- [Indicator Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/indicator-server-configurations.md): Server configurations for indicators.
- [Integration Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/integration-server-configurations.md): Server configurations for integrations.
- [List Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/list-server-configurations.md): Server configurations for lists.
- [Logs Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/logs-server-configurations.md): Server configurations for logs.
- [Marketplace Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/marketplace-server-configurations.md): Server configurations for Marketplace.
- [Multi-Tenant Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/multi-tenant-server-configurations.md): Server configurations for multi-tenant deployments.
- [Notification Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/notification-server-configurations.md): Server configurations for notifications.
- [Playbook Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/playbook-server-configurations.md): Server configurations for playbooks.
- [Proxy Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/proxy-server-configurations.md): Server configurations for proxy servers.
- [Remote Repository Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/remote-repository-server-configurations.md): Server configurations for remote repositories.
- [Report Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/report-server-configurations.md): Server configurations for reports.
- [Security Headers Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/security-headers-server-configurations.md): Server configurations for security headers.
- [SLA Server Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/sla-server-configuration.md): Server configuration for SLAs.
- [System Diagnostics Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/system-diagnostics-server-configurations.md): Server configurations for system diagnostics.
- [Users and Roles Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/users-and-roles-server-configurations.md): Server configurations for users and roles.
- [War Room Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/war-room-server-configurations.md): Server configurations for the War Room.
- [Widget Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/server-configurations/widget-server-configurations.md): Server configurations for widgets.
- [System Diagnostics](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/system-diagnostics.md): Find and fix system performance issues in Cortex XSOAR. System health, system monitoring.
- [Fix System Diagnostics Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/system-diagnostics/fix-system-diagnostics-issues.md): Fix alerts from the System Diagnostics page.
- [Performance Tuning for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/performance-tuning-for-cortex-xsoar.md)
- [Supported Ciphers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/supported-ciphers.md): List of Cipher Suites for TLS1.2 and TLS1.3 supported by Cortex XSOAR Server and Engines
- [Telemetry](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/telemetry.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR. Disable or enable telemetry.
- [Keyboard Shortcuts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage Cortex XSOAR, for playbooks, scripts, CLI, incident pages, and shoulders.
- [Indicator Fields Structure](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/reference-docs/reference/indicator-fields-structure.md): Indicator fields structure aligned with STIX standards to more easily share and work with IOCs.

* [Navigate the Cortex XSOAR 6.12 Administrator Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/readme.md): Start here for a visual overview of the main Cortex XSOAR 6.12 documentation areas.
* [Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/overview.md): Cortex XSOAR provides security orchestration, incident management, and interactive investigation. Overview of Cortex XSOAR features and concepts.
* [Get Started in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar.md): Learn about Cortex XSOAR concepts, licenses, and the product lifecycle, as well as basic functionality including the command line, API keys, search, CLI, etc.
* [Licenses](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/licenses.md): The Cortex XSOAR license type determines which components users can utilize. License types are community, starter, or enterprise. Users include audit and full.
* [FIPS Version](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/fips-version.md): Cortex XSOAR offers a FIPS version of Cortex XSOAR, using a software library validated against FIPS 140-3.
* [Concepts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/concepts.md): Cortex XSOAR concepts, including incidents, integrations, playbokos, automations, commands, war room, indicators, playground.
* [Product Support Lifecycle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/product-support-lifecycle.md): Cortex XSOAR major releases product support lifecycle.
* [API Keys](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/api-keys.md): Generate and manage API keys in Cortex XSOAR.
* [Use the Command Line Interface](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/use-the-command-line-interface.md): Cortex XSOAR enables you to run system commands, integration commands, automations, and more, from an integrated CLI.
* [How to Search](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/how-to-search.md): Search Cortex XSOAR using Lucene query syntax, the search box, or general search.
* [How to Use Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/how-to-use-markdown.md): Use markdown to add basic formatting to text in multiple contexts within Cortex XSOAR.
* [New User FAQ](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/new-user-faq.md): New User FAQ for Cortex XSOAR.
* [Onboarding in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/onboarding-in-cortex-xsoar.md): Onboarding process for Cortex XSOAR.
* [Deployment Checklist - Best Practices](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/deployment-checklist-best-practices.md): Overview of the deployment process, including best practices for Cortex XSOAR installation and maintenance.
* [Single Server Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment.md): Install Cortex XSOAR for a single server deployment.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/system-requirements.md): Verify that your Cortex XSOAR deployment meets the minimum system requirements.
* [Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/deployment-guidelines.md): Review Cortex XSOAR deployment guidelines for AWS EC2, Azure, or GCP.
* [AWS EC2 Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/deployment-guidelines/aws-ec2-deployment-guidelines.md)
* [Azure Virtual Machines Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/deployment-guidelines/azure-virtual-machines-deployment-guidelines.md)
* [GCP Compute Engine Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/deployment-guidelines/gcp-compute-engine-deployment-guidelines.md)
* [Install the Server for a Single Server Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/install-the-server-for-a-single-server-deployment.md): Installation instructions and requirements for standard Cortex XSOAR single server deployments, with the app server and database server on the same machine.
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/install-the-server-for-a-single-server-deployment/installer-flags.md)
* [Install the Server with Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/install-the-server-with-elasticsearch.md): Install Cortex XSOAR with Elasticsearch as the database. Prerequisites and instructions for installing a new Cortex XSOAR environment with Elasticsearch.
* [Install the Server Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline.md): Install Cortex XSOAR when you do not have internet access. Instructions for offline installation.
* [Dependencies for Offline Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline/dependencies-for-offline-installation.md)
* [Add a License](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/add-a-license.md): Add Cortex XSOAR license file, either through the UI or by saving the license file directly on the server.
* [Post-Installation Checklist](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist.md): Common post-installation steps to perform after installing Cortex XSOAR. Cortex XSOAR installation troubleshooting.
* [Server Post-Installation Health Check](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/server-post-installation-health-check.md)
* [Monitor Components](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/monitor-components.md)
* [HTTPS with a Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/https-with-a-signed-certificate.md)
* [Create a Self-Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/https-with-a-signed-certificate/create-a-self-signed-certificate.md)
* [Install or Renew a Custom Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/https-with-a-signed-certificate/install-or-renew-a-custom-certificate.md)
* [Configure the Server to Listen on HTTP](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/configure-the-server-to-listen-on-http.md)
* [Troubleshoot WebSockets](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/post-installation-checklist/troubleshoot-websockets.md)
* [Upgrade the Cortex XSOAR Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/upgrade-the-cortex-xsoar-server.md): Upgrading the Cortex XSOAR server including preparation, upgrade and post upgrade steps.
* [Uninstall the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/single-server-deployment/uninstall-the-server.md): Uninstall Cortex XSOAR. Configuration files and files created by engines are not removed.
* [Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch.md): Implementing Cortex XSOAR with Elasticsearch - setup, security, migration, and troubleshooting.
* [Elasticsearch Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-overview.md): Migrating Cortex XSOAR data to Elasticsearch. Object information in an existing Cortex XSOAR instance is copied to a designated Elasticsearch index.
* [Elasticsearch Setup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup.md): Elasticsearch best practices, sizing requirements, and configuration options for Cortex XSOAR.
* [Elasticsearch System Requirements](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-system-requirements.md)
* [Elasticsearch Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-configurations.md)
* [Elasticsearch Data Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-data-management.md)
* [Elasticsearch Security](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-security.md): Elasticsearch security and best practices guidelines for single server and multi-tenant deployments.
* [Elasticsearch General Security Guidelines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-security/elasticsearch-general-security-guidelines.md)
* [Elasticsearch Security Guidelines - Multi-tenant Deployments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/elasticsearch-security/elasticsearch-security-guidelines-multi-tenant-deployments.md)
* [Migration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration.md): Learn about migrating Cortex XSOAR data to Elasticsearch for a single server or multi-tenant environment.
* [Elasticsearch Migration Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/elasticsearch-migration-overview.md)
* [Migrate Objects to Elasticsearch for a Single Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-a-single-server.md)
* [Migrate Objects to Elasticsearch for Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-multi-tenant.md)
* [Migrate an Existing Elasticsearch Deployment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/migrate-an-existing-elasticsearch-deployment.md)
* [Migrate Objects to Elasticsearch for a Distributed Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/migrate-objects-to-elasticsearch-for-a-distributed-database.md)
* [Manage Partial Migration to Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/manage-partial-migration-to-elasticsearch.md)
* [Validate the Migration to Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/validate-the-migration-to-elasticsearch.md)
* [Elasticsearch Post Migration Health Check](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/migration/elasticsearch-post-migration-health-check.md)
* [Disaster Recovery for Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch.md): Back up and restore a Cortex XSOAR elasticsearch deployment using snapshots.
* [Create Elasticsearch Snapshots](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/create-elasticsearch-snapshots.md)
* [Restore Elasticsearch Snapshots](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/restore-elasticsearch-snapshots.md)
* [Archive Data with Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/archive-data-with-elasticsearch.md): Archive Cortex XSOAR data you no longer need regular access to, using Elasticsearch index lifecycle management.
* [Troubleshoot Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch/troubleshoot-elasticsearch.md): Troubleshoot common issues in Cortex XSOAR Elasticsearch deployments.
* [Docker](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker.md): Cortex XSOAR Docker installation, configuration, security, and troubleshooting guides.
* [Docker Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-overview.md): Overview of how Cortex XSOAR uses Docker for security and predictability.
* [Docker Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-installation.md): Install Docker on Enterprise Linux platforms and troubleshoot installation.
* [Configure Python Docker Integrations to Trust Custom Certificates](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/configure-python-docker-integrations-to-trust-custom-certificates.md): Configure CA signed and custom certificates for Docker. Trust custom certificates for python integrations in Cortex XSOAR.
* [Docker Images in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar.md): Use Docker to run Python scripts and integrations in a controlled environment in Cortex XSOAR.
* [Create a Docker Image In Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/create-a-docker-image-in-cortex-xsoar.md)
* [Install Docker Images Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/install-docker-images-offline.md)
* [Docker Image Security](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/docker-image-security.md)
* [Manage Docker Images](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/manage-docker-images.md)
* [Change the Docker Image for Automations and Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/change-the-docker-image-for-automations-and-integrations.md)
* [Use the Cortex XSOAR Container Registry](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-images-in-cortex-xsoar/use-the-cortex-xsoar-container-registry.md)
* [Docker Hardening Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide.md): Use the Docker Hardening Guide to configure the Cortex XSOAR settings when running Docker containers.
* [Run Docker with Non-Root Internal Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/run-docker-with-non-root-internal-users.md)
* [Configure Memory Limit Support Without Swap Limit Capabilities](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-memory-limit-support-without-swap-limit-capabilities.md)
* [Configure the Memory Limitation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-memory-limitation.md)
* [Test the Memory Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/test-the-memory-limit.md)
* [Limit Available CPU](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/limit-available-cpu.md)
* [Configure the PIDs Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-pids-limit.md)
* [Configure the Open File Descriptors Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/configure-the-open-file-descriptors-limit.md)
* [Docker Network Hardening](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-hardening-guide/docker-network-hardening.md)
* [Docker FAQs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/docker-faqs.md): Frequently asked questions (FAQ) about Docker in Cortex XSOAR.
* [Troubleshoot Docker Networking Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/troubleshoot-docker-networking-issues.md): Troubleshoot Docker networking issues in Cortex XSOAR.
* [Troubleshoot Docker Performance Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/troubleshoot-docker-performance-issues.md): Troubleshoot Docker performance issues in Cortex XSOAR. Update Docker package and dependencies.
* [Configure Docker Pull Rate Limit](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/configure-docker-pull-rate-limit.md): Configure the Docker pull rate limit on public images. Create Docker user account and receive higher pull limit.
* [Change the Docker Installation Folder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/docker/change-the-docker-installation-folder.md): Instructions for changing the default Docker folder.
* [Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/podman.md): Run Podman containers instead of Docker for RHEL v8.
* [Podman Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/podman/podman-overview.md): Run Podman containers instead of Docker for operating systems such as RHEL v8.
* [Change container storage directory](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/podman/change-container-storage-directory.md)
* [Podman Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/podman/podman-installation.md): Install Podman for Cortex XSOAR.
* [Configure the SELinux Policy for PowerShell Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/podman/configure-the-selinux-policy-for-powershell-integrations.md): Change the SELinux Policy when running Powershell Integrations in Cortex XSOAR. SELinux policy for Podman.
* [Migrate From Docker to Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/podman/migrate-from-docker-to-podman.md): Switch from Docker to Podman in Cortex XSOAR. Migrate from Docker to Podman, for RHEL 8 or later.
* [Troubleshoot Podman](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/podman/troubleshoot-podman.md): Troubleshoot issues for Podman for Cortex XSOAR.
* [Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/proxy.md): Configure proxy settings in Cortex XSOAR.
* [Configure Proxy Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/proxy/configure-proxy-settings.md): Configure global proxy settings in Cortex XSOAR by adding a server configuration.
* [Configure how to bypass proxy settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/proxy/configure-how-to-bypass-proxy-settings.md): Configure option to bypass a proxy using a server configuration.
* [Use NGINX as a Reverse Proxy to the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/proxy/use-nginx-as-a-reverse-proxy-to-the-server.md): Use NGINX as a Reverse Proxy to the Cortex XSOAR Server.
* [High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability.md): Guide to high availability in Cortex XSOAR, using Elasticsearch. Includes sizing requirements, migration, additional app servers, and signed certificates.
* [High Availability Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/high-availability-overview.md): Overview of high availability in Cortex XSOAR, including information about the different deployment architectures.
* [Set Up High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/set-up-high-availability.md): Overview of the steps required to set up high availability for Cortex XSOAR.
* [Sizing Requirements for High Availability Deployments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/sizing-requirements-for-high-availability-deployments.md): Information about the sizing requirements for Cortex XSOAR High Availability deployments.
* [Monitor the Health of the App Servers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/monitor-the-health-of-the-app-servers.md): Monitor the health of the app servers in a Cortex XSOAR high availability environment.
* [Migrate a Single Instance for High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/migrate-a-single-instance-for-high-availability.md): Migrate your Cortex XSOAR single instance deployment to a high availability installation of Cortex XSOAR.
* [Migrate a Multi-Tenant Deployment for High Availability](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/migrate-a-multi-tenant-deployment-for-high-availability.md): Migrate your Cortex XSOAR Multi-tenant deployment to enable High Availability.
* [Install Additional App Servers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/install-additional-app-servers.md): Install additional app servers for a Cortex XSOAR high availability configuration.
* [Deploy Engines in a High Availability Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/deploy-engines-in-a-high-availability-environment.md): When adding application servers, update the engines to connect through the load balancer.
* [Use a Signed Certificate](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/high-availability/use-a-signed-certificate.md): Use a signed certificate in a Cortex XSOAR high availability deployment.
* [Disaster Recovery and Live Backup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup.md): Live backup and disaster recovery options for Cortex XSOAR.
* [Disaster Recovery and Live Backup Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/disaster-recovery-and-live-backup-overview.md): Describes live backup, how to configure your environment, server DR status, and disaster recovery scenarios in Cortex XSOAR.
* [Host Names, DNS, and Disaster Recovery](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/host-names-dns-and-disaster-recovery.md): Unique host names and DNS considerations for disaster recovery for Cortex XSOAR.
* [Configure the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment.md): Configure a live backup environment by mirroring your production server to a backup server in Cortex XSOAR.
* [Transition an Active Server to Standby Mode](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-an-active-server-to-standby-mode.md): Change an active server to standby mode in Cortex XSOAR.
* [Transition a Standby Server to Active Mode](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-a-standby-server-to-active-mode.md): Transition a standby server to active mode (production) in Cortex XSOAR.
* [Transition Between DR States Through the Configuration File](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/transition-between-dr-states-through-the-configuration-file.md): Transition disaster recovery states between active and standby using the configuration file when the server is new and starts for the first time.
* [Upgrade the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/upgrade-the-live-backup-environment.md): Upgrade your live backup environment for Cortex XSOAR.
* [Engines and Disaster Recovery Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/engines-and-disaster-recovery-troubleshooting.md): Troubleshoot Cortex XSOAR engine failover issues when an engine does not automatically fail over to the active node in a disaster recovery situation.
* [Back up the Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/back-up-the-database.md): Perform manual and automatic backups of the Cortex XSOAR database. Configure automated backup options. Schedule backups.
* [Restore the Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/restore-the-database.md): Restore the database from a manual backup or automated backup back up in Cortex XSOAR.
* [Restore a Partition](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/restore-a-partition.md): Restore one or more specific partitions in Cortex XSOAR.
* [Troubleshoot Live Backup](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/disaster-recovery-and-live-backup/troubleshoot-live-backup.md): How to troubleshoot live backup scenarios in Cortex XSOAR.
* [Users and Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles.md): Users and roles in Cortex XSOAR, including permissions, user settings, shifts, and authentication options.
* [Users and Roles Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/users-and-roles-overview.md): Manage users, roles, invitations, password policies, and view information about users activities in Cortex XSOAR.
* [Roles in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar.md): The default admin is the super user role in XSOAR. Administrator, Analyst, and Read-Only roles are defined by the read-write level of access to XSOAR components.
* [Pre-set Query per Role](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/pre-set-query-per-role.md)
* [Define a Role](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/define-a-role.md)
* [Role-based Permission Levels](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/role-based-permission-levels.md)
* [Shift Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/shift-management.md)
* [Managing Shifts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/roles-in-cortex-xsoar/shift-management/managing-shifts.md)
* [User Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management.md): Invite and manage users in Cortex XSOAR. Edit user roles, reset passwords, disable or remove users.
* [User Invitations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/user-invitations.md)
* [Invite a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/user-invitations/invite-a-user.md)
* [Set the User as Default Administrator](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/set-the-user-as-default-administrator.md)
* [Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users.md)
* [Configure the Server for Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/configure-the-server-for-self-service-read-only-users.md)
* [Create the Self-Service Read-Only Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-self-service-read-only-users.md)
* [Create the Read-Only Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-read-only-dashboard.md)
* [Create the Read-Only Incident Type and Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/self-service-read-only-users/create-the-read-only-incident-type-and-layout.md)
* [Disable a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/disable-a-user.md)
* [Remove a User](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/remove-a-user.md)
* [Clear Users Data Using the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/clear-users-data-using-the-cli.md)
* [Clear Users Data Using a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/clear-users-data-using-a-playbook.md)
* [Configure Users Data Using Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/configure-users-data-using-server-configurations.md)
* [User Settings and Preferences](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/user-settings-and-preferences.md)
* [Configure User Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/configure-user-settings.md)
* [Manually Refresh the Number of Licenses in Use](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/user-management/manually-refresh-the-number-of-licenses-in-use.md)
* [Integration Permissions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/integration-permissions.md): Integration permissions enable you to assign permissions to commands in integrations. Use role based access control (RBAC) to assign commands.
* [Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/password-policy.md): Describes the password policy and how to set it in Cortex XSOAR.
* [Create a Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/password-policy/create-a-password-policy.md)
* [Edit a Default Password Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/password-policy/edit-a-default-password-policy.md)
* [Default Password Policy Keys](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/password-policy/edit-a-default-password-policy/default-password-policy-keys.md)
* [Change the Administrator Password](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/password-policy/change-the-administrator-password.md): Create a new password for the Cortex XSOAR administrator account, if you are unable to log in, by manually adding a new administrator.
* [Authenticate Users with SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0.md): Authenticate users using SAML 2.0 with your identity provider, for Cortex XSOAR. Use Okta, Microsoft Entra ID, or ADFS.
* [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
* [Create Okta Groups for Cortex XSOAR Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/create-okta-groups-for-cortex-xsoar-users.md)
* [Define the Okta Application to authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/define-the-okta-application-to-authenticate-cortex-xsoar.md)
* [SAML Settings for the Okta Application](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/define-the-okta-application-to-authenticate-cortex-xsoar/saml-settings-for-the-okta-application.md)
* [Configure the SAML 2.0 Integration for Okta](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-okta.md)
* [SAML 2.0 Okta Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-okta/saml-2.0-okta-parameters.md)
* [Map Okta Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-okta-as-the-identity-provider-using-saml-2.0/map-okta-groups-to-cortex-xsoar-roles.md)
* [Set Up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
* [Configure Microsoft Entra ID to Authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-microsoft-entra-id-to-authenticate-cortex-xsoar.md)
* [Configure the SAML 2.0 Integration for Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-microsoft-entra-id.md)
* [SAML 2.0 Microsoft Entra ID Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-microsoft-entra-id/saml-2.0-microsoft-entra-id-parameters.md)
* [Set up ADFS as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0.md)
* [Create Relying Party Trust in ADFS](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/create-relying-party-trust-in-adfs.md)
* [Define the Claim Issuance Policy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/define-the-claim-issuance-policy.md)
* [Configure the SAML 2.0 Integration for ADFS](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-adfs.md)
* [SAML 2.0 ADFS Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/configure-the-saml-2.0-integration-for-adfs/saml-2.0-adfs-parameters.md)
* [Map ADFS Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/set-up-adfs-as-the-identity-provider-using-saml-2.0/map-adfs-groups-to-cortex-xsoar-roles.md)
* [Duo for Single Sign-On](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on.md)
* [Create Duo Groups for Cortex XSOAR Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/create-duo-groups-for-cortex-xsoar-users.md)
* [Define Duo to authenticate Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/define-duo-to-authenticate-cortex-xsoar.md)
* [Configure the SAML 2.0 Integration for Duo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/configure-the-saml-2.0-integration-for-duo.md)
* [Map Duo Groups to Cortex XSOAR Roles](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-saml-2.0/duo-for-single-sign-on/map-duo-groups-to-cortex-xsoar-roles.md)
* [Set the Default Theme for New Users](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/set-the-default-theme-for-new-users.md): Set the default color theme for new Cortex XSOAR users by adding a server configuration. Users can change the theme in user preferences.
* [Authenticate Users with Active Directory](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/users-and-roles/authenticate-users-with-active-directory.md): Users can log in to Cortex XSOAR with their Active Directory username and passwords
* [Marketplace](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace.md): Access the Cortex XSOAR Marketplace and install content packs. Convert existing content to content pack format.
* [Marketplace Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/marketplace-overview.md): Use Cortex XSOAR Marketplace to install, exchange, contribute and manage your content.
* [Content Packs Support Types](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-packs-support-types.md): Types of content packs Support - Cortex XSOAR supported, Partner-Supported, Developer-Supported, Community-Supported.
* [Marketplace FAQs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/marketplace-faqs.md): Frequently asked questions about Cortex XSOAR Marketplace Content
* [Search and Navigate in the Marketplace](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/search-and-navigate-in-the-marketplace.md): Search the Cortex XSOAR Marketplace and find free and paid content. Search by use cases, integrations, categories, etc.
* [Convert Existing Content to Content Pack Format](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/convert-existing-content-to-content-pack-format.md): Convert content to content pack format when upgrading from a version earlier than Cortex XSOAR 6.0.
* [Use Cases](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/use-cases.md): Common use cases for Cortex XSOAR, including analytics and siem, authentication, case management, data enrichment, threat intelligence, forensic and malware,
* [Content Pack Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-installation.md): Cortex XSOAR content pack dependencies, errors and warning messages.
* [Install a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-installation/install-a-content-pack.md): Install a content pack and its required dependencies from Marketplace.
* [Set up Your Use Case with the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-installation/install-a-content-pack/set-up-your-use-case-with-the-deployment-wizard.md): Configure a supported content pack for your use case.
* [Update a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-installation/update-a-content-pack.md): Update an installed content pack from Marketplace.
* [Delete a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-installation/delete-a-content-pack.md): Delete an installed content pack from Marketplace.
* [Revert a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-installation/revert-a-content-pack.md): Revert an installed content pack to an earlier version.
* [Install a Content Pack Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/install-a-content-pack-offline.md): Download Cortex XSOAR Marketplace content packs and then upload offline to install on a machine without an internet connection (air gapped).
* [Content Pack Update Notifications](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-update-notifications.md): Enable update notifications for individual content packs
* [Marketplace Troubleshooting](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/marketplace-troubleshooting.md): Troubleshoot Marketplace issues regarding login, connectivity, timeouts, and certificates.
* [Content Pack Contributions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-contributions.md): You can create content packs for submission to the Cortex XSOAR Marketplace.
* [Create a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-contributions/create-a-content-pack.md)
* [Resubmit a Content Pack](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/marketplace/content-pack-contributions/resubmit-a-content-pack.md)
* [Remote Repositories in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar.md): Configure a remote repository on a development and production machine and edit and push content.
* [Content Management in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/content-management-in-cortex-xsoar.md): Cortex XSOAR offers multiple options for developing content, including a remote repository and CI/CD.
* [Remote Repositories Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/remote-repositories-overview.md): Overview of how remote repositories work and how to configure a remote repository in Cortex XSOAR.
* [Configure a Remote Repository on a Development Machine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/configure-a-remote-repository-on-a-development-machine.md): Configure a remote repository on a development machine. Add content repository in Cortex XSOAR.
* [Configure a Remote Repository on the Production Machine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/configure-a-remote-repository-on-the-production-machine.md): Configure a remote repository on a production machine. Define the repository and pull content.
* [Edit and Push Content to a Remote Repository](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/edit-and-push-content-to-a-remote-repository.md): Push content to a remote repository and control access for pushing content.
* [Upgrade Remote Repositories from Versions 5.5 and below](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/upgrade-remote-repositories-from-versions-5.5-and-below.md): Upgrade Cortex XSOAR remote repository environment from 5.5 to 6.5 and above.
* [Troubleshoot a Remote Repository Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar/troubleshoot-a-remote-repository-configuration.md): Troubleshoot issues for a Cortex XSOAR remote repository configuration plus FAQs.
* [Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines.md): Install, manage, configure, and troubleshoot Cortex XSOAR engines.
* [Cortex XSOAR Engines Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/cortex-xsoar-engines-overview.md): Understand Cortex XSOAR engine architecture, load balancing groups, installation and configurations.
* [Engine Installation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/engine-installation.md): Review system requirements and engine installation types (Shell, DEB, RPM, Zip, Configuration) available for Cortex XSOAR engines.
* [Install a Cortex XSOAR Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/engine-installation/install-a-cortex-xsoar-engine.md)
* [Install a Signed Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/engine-installation/install-a-signed-engine.md)
* [Install a Cortex XSOAR Engine Offline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/engine-installation/install-a-cortex-xsoar-engine-offline.md)
* [Use an Engine in an Integration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/use-an-engine-in-an-integration.md): Use a Cortex XSOAR engine or load-balancing group of engines to fetch incidents and run commands for an integration.
* [Run a Script using an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/run-a-script-using-an-engine.md): Run a script on an engine or load balancing group. Run an automation from an engine or load balancing group.
* [Manage Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/manage-engines.md): Manage engines and load balancing groups in Cortex XSOAR.
* [Configure Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines.md): Configure Cortex XSOAR engines to change the number of workers, access communication tasks, notify users if engine disconnects, and remove server from group.
* [Edit the Engine Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration.md)
* [Common Properties When Editing an Engine Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration/common-properties-when-editing-an-engine-configuration.md)
* [Configure the Engine to Use a Web Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration/common-properties-when-editing-an-engine-configuration/configure-the-engine-to-use-a-web-proxy.md)
* [Configure the Engine to Call the Server Without Using a Proxy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration/configure-the-engine-to-call-the-server-without-using-a-proxy.md)
* [Configure Access to Communication Tasks through an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration/configure-access-to-communication-tasks-through-an-engine.md)
* [Configure the Number of Workers for the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration/configure-the-number-of-workers-for-the-server.md)
* [Configure an Engine to Use Custom Certificates](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration/configure-an-engine-to-use-custom-certificates.md)
* [Notify Users When an Engine Disconnects](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/configure-engines/edit-the-engine-configuration/notify-users-when-an-engine-disconnects.md)
* [Remove an Engine](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/remove-an-engine.md): Remove a Cortex XSOAR engine. Commands vary depending on your operating system.
* [Troubleshoot Cortex XSOAR Engines](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/engines/troubleshoot-cortex-xsoar-engines.md): Troubleshoot Cortex XSOAR engines by accessing logs and viewing errors.
* [Customize and Configure Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar.md): Customize and configure your Cortex XSOAR deployment.
* [Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents.md): Manage and investigate incidents in Cortex XSOAR.
* [Incident Lifecycle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle.md): Incidents are potential security data threats that analysts identify and remediate in Cortex XSOAR.
* [Incident Context Data](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-context-data.md): Learn about incident context data, how it is stored in Cortex XSOAR, and how to access it.
* [Incident Customization](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization.md): Customize incidents in Cortex XSOAR. Attach and detach incident types. Customize indicator extraction, incident types, fields, and layouts.
* [Create an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/create-an-incident-type.md)
* [Customize Incident Layouts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/customize-incident-layouts.md)
* [Incident Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields.md)
* [Create a Custom Incident Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-a-custom-incident-field.md)
* [Create a Grid Field for an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-a-grid-field-for-an-incident-type.md)
* [Use Scripts with the Grid Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/use-scripts-with-the-grid-field.md)
* [Incident Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/incident-field-trigger-scripts.md)
* [Troubleshoot Closing Case Incident after Changing Field Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/troubleshoot-closing-case-incident-after-changing-field-type.md)
* [Create an Evidence Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-customization/incident-fields/create-an-evidence-field.md)
* [Incident De-Duplication](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-de-duplication.md): De-duplicate incidents either manually or automatically in Cortex XSOAR. Mark as duplicate using pre-process rules or playbooks.
* [Pre-Process Rules](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/pre-process-rules.md): Create pre-process rules to perform actions on incidents as soon as they are ingested.
* [Post Processing for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents.md): You can set up a post-processing script to run after an incident has been remediated, but before the incident is closed in Cortex XSOAR.
* [War Room Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview.md): Use the Cortex XSOAR War Room for real-time investigation into an incident, to filter war room entries, and to disable indicator notifications.
* [Schedule a Command](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/schedule-a-command.md)
* [Add a Custom Widget in the War Room](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/add-a-custom-widget-in-the-war-room.md)
* [War Room Indexing](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing.md)
* [Index War Room Entries Using Bolt DB](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing/index-war-room-entries-using-bolt-db.md)
* [Index War Room Entries Using Elasticsearch](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview/war-room-indexing/index-war-room-entries-using-elasticsearch.md)
* [Incident Access Control Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-access-control-configuration.md): Limit access to incidents and investigations in Cortex XSOAR, using role-based access control (RBAC).
* [Classification and Mapping](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/classification-and-mapping.md): Classify and map incoming data from an integration instance.
* [Incident Mirroring](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-mirroring.md): Set up your integration to mirror incidents between a third-party application and Cortex XSOAR.
* [Customize Incident Close Reasons](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/customize-incident-close-reasons.md): Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
* [Change the Display Name of Security Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/change-the-display-name-of-security-incidents.md): Add a Cortex XSOAR server configuration to change the name of security incidents from ‘incident’ to another term - cases, issues, etc.
* [Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks.md): Cortex XSOAR playbooks enable you to organize and document security monitoring, orchestration, and response activities.
* [What Are Playbooks?](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/what-are-playbooks.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
* [Playbook Development](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-development.md): Cortex XSOAR playbooks enable you to structure and automate many of your security processes.
* [Configure IoT Security Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/configure-iot-security-playbooks.md): IoT Security playbooks enable you to structure and automate many of your third-party security processes. Parse incident information, interact with users, and remediate.
* [Manage Playbook Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/manage-playbook-settings.md): Manage Cortex XSOAR playbook settings, including role access, which incident type triggers it, and options for Quiet Mode.
* [Version Control](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/version-control.md): Save versions of your playbook as you are developing it.
* [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields.md): All of the fields available when defining a playbook task in Cortex XSOAR.
* [Create Section Headers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/create-section-headers.md)
* [Create a Conditional Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/create-a-conditional-task.md)
* [Communication Tasks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks.md)
* [Create an Ask Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task.md)
* [Ask Task Examples](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task/ask-task-examples.md)
* [Customize an Ask Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-an-ask-task/customize-an-ask-task.md)
* [Create a Data Collection Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task.md)
* [Data Collection Task Examples](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task/data-collection-task-examples.md)
* [Customize a Data Collection Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-a-data-collection-task/customize-a-data-collection-task.md)
* [Customize the SOC Name](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/customize-the-soc-name.md)
* [Create Communication Task Authentication](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/create-communication-task-authentication.md)
* [Add Ad Hoc Tasks to a Work Plan](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/add-ad-hoc-tasks-to-a-work-plan.md)
* [Handle Errors in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/handle-errors-in-a-playbook.md)
* [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-task-fields/communication-tasks/playbook-task-fields.md)
* [Playbook Inputs and Outputs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-inputs-and-outputs.md): Cortex XSOAR playbooks and tasks have inputs (data from incident or integration) and outputs that can then be used as input in other tasks.
* [Extend Context](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields.
* [Filters and Transformers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers.md): Use filters and transformers to manipulate data in Cortex XSOAR. Use filters and transformers in playbook tasks or when mapping an instance.
* [Create Filters and Transformers in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook.md)
* [Create a Filter Example](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-example.md)
* [Create a Filter (Advanced) Example](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-advanced-example.md)
* [Filter Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators.md)
* [Built-in Filters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/built-in-filters.md)
* [Transformers Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/transformers-operators.md)
* [Create Custom Filter and Transformer Operators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/filters-and-transformers/filter-operators/create-custom-filter-and-transformer-operators.md)
* [Automations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/automations.md): Create and edit an automation in Cortex XSOAR, including detach and attach, automation settings, etc.
* [Configure a Sub-playbook Loop](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/configure-a-sub-playbook-loop.md): Configure a sub-playbook to run in a loop.
* [Playbook Polling](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-polling.md): Cortex XSOAR Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
* [Create Incident Fields in a Playbook](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/create-incident-fields-in-a-playbook.md): Use the setIncident automation to set and update all system incident fields.
* [Playbook Testing](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-testing.md): Test your playbook with ingested incidents.
* [Best Practices](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/best-practices.md): Best practices for working with playbooks.
* [Jobs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs.md): Jobs run playbooks and are either time-triggered (run at specific times) or event triggered (run when there are changes to a feed).
* [Create a Time Triggered Job](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/create-a-time-triggered-job.md): Create a time triggered or feed triggered job in Cortex XSOAR to run a playbook.
* [Create a Job Triggered by a Delta in Feed](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/create-a-job-triggered-by-a-delta-in-feed.md): Create a job that is triggered when a feed has complete an operation and there is a change in the content.
* [Time Triggered Job Parameters](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/time-triggered-job-parameters.md): Description of the parameters available when creating a time triggered job.
* [Process Indicators Using a Job Triggered By Delta](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/process-indicators-using-a-job-triggered-by-delta.md): Provides an example of using a job triggered by a delta in a feed to process incoming indicators.
* [Add Indicators to SIEM Using a Time Triggered Job](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs/add-indicators-to-siem-using-a-time-triggered-job.md): Use a time-triggered job to push indicators to a SIEM.
* [Work with SLAs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas.md): Create and manage SLAs and timers and SLA scripts. Search by SLA and timer fields. Configure global risk threshold in Cortex XSOAR.
* [SLA Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/sla-overview.md): SLA fields count down the time remaining. SLAs fields can be incorporated in cases. You can trigger actions in the event the SLA passes.
* [Create an SLA Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/create-an-sla-field.md): Create new SLA or timer and add SLA script to trigger when SLA time has passed.
* [Manage SLA and Timer Fields in an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/manage-sla-and-timer-fields-in-an-incident.md): Manage timers and SLA for a specific incident, such as decreasing required response time for a high priority incident.
* [Create an SLA Trigger](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/create-an-sla-trigger.md): Trigger times to start, pause, or stop when a certain task occurs in a Cortex XSOAR playbook.
* [Customize SLA Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/customize-sla-scripts.md): Create scripts that will perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.
* [Search Incidents using SLA and Timer Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/search-incidents-using-sla-and-timer-fields.md): Search incidents based on their SLA status, a SLA field, or a timer field.
* [Configure the Global Risk Threshold](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas/configure-the-global-risk-threshold.md): Add server configuration in Cortex XSOAR to change SLA Risk threshold from default 72 hours.
* [Machine Learning](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning.md): Understand machine learning models in Cortex XSOAR. P
* [Machine Learning Capabilities](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/machine-learning-capabilities.md): Machine Learning capabilities using the Phishing Classifier and automations.
* [Machine Learning Models](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/machine-learning-models.md): Use machine learning (ML) models in Cortex XSOAR to analyze and predict future behavior. Machine learning for phishing incidents.
* [Use the Phishing Classifier in Production](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/use-the-phishing-classifier-in-production.md): The phishing classifier enables you to train a machine learning model for incidents.
* [Create a Machine Learning Model](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/create-a-machine-learning-model.md): Create a machine learning (ml) model in Cortex XSOAR to predict the classification of phishing incidents.
* [Phishing Classifier Demo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/phishing-classifier-demo.md): Use the phishing classifier demo to see how a classifier works for machine learning (ml) in Cortex XSOAR.
* [Train a Phishing Classifier on Non-English Languages](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/train-a-phishing-classifier-on-non-english-languages.md): Train a phishing classifier for non English language emails through tokenization methods. Cortex XSOAR machine learning.
* [Additional Machine Learning Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning/additional-machine-learning-scripts.md): Additional machine learning scripts
* [Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/lists.md): Create and manage lists in Cortex XSOAR.
* [Work With Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/work-with-lists.md): Manage lists in Cortex XSOAR that can be accessed by automations, playbooks, etc.
* [Work with JSON Lists](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/work-with-lists/work-with-json-lists.md)
* [Create a List](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/create-a-list.md): Create predefined lists in Cortex XSOAR that can be parsed by and modified by scripts.
* [Set the List Separator Character](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/set-the-list-separator-character.md): Set the list separator character in Cortex XSOAR. The default separator for lists is a comma.
* [Transform a List into an Array](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/lists/transform-a-list-into-an-array.md): Create a transformer to split a list into an array when adding or editing a task in a playbook or when mapping an instance in Cortex XSOAR.
* [Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators.md): Cortex XSOAR analyzes indicators to determine whether they are malicious. Create indicator types and custom layouts and an exclusion list.
* [Indicator Concepts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-concepts.md): Cortex XSOAR provides threat intelligence management. TIM concepts include fetch indicators, configure indicators, and export indicators. Threat intel management
* [Indicator Verdict](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-verdict.md): Indicator verdict affects how the indicator is processed and handled in Cortex XSOAR. Assigned by reputation returned by the source with highest reliability.
* [Indicator Ingestion](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-ingestion.md): Overview of how Cortex XSOAR indicators are detected and ingested.
* [Indicator Customization](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md): Customize indicator types, fields, and layouts.
* [Indicator Types](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types.md): Configure indicator types and their associated scripts and fields.
* [File Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/file-indicators.md): Manage file indicators and their associated hashes.
* [File Indicator Merging Strategy](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/file-indicators/file-indicator-merging-strategy.md): Understand how file indicators merge by hash.
* [Create an Indicator Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/create-an-indicator-type.md): Create a custom indicator type.
* [Indicator Type Profile](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/indicator-type-profile.md): Configure indicator type profile settings.
* [Map Custom Indicator Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/map-custom-indicator-fields.md): Map custom fields to indicator data.
* [Formatting Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/formatting-scripts.md): Format indicator values and output.
* [Enhancement Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/enhancement-scripts.md): Configure scripts that enhance indicators on demand.
* [Reputation Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/reputation-scripts.md): Configure scripts that calculate indicator verdicts.
* [Reputation Commands](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-types/reputation-commands.md): Configure commands that calculate indicator verdicts.
* [Indicator Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields.md): Create and configure fields for indicators.
* [Create a Custom Indicator Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md): Create a custom field for indicators.
* [Configure the HTML Field](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field/configure-the-html-field.md): Configure HTML fields for indicators.
* [Indicator Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-fields/indicator-field-trigger-scripts.md): Run scripts when indicator field values change.
* [Indicator Layouts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts.md): Customize layouts for indicator types.
* [Customize an Indicator Type Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts/customize-an-indicator-type-layout.md): Customize a layout for an indicator type.
* [Add a Script in the Indicator Layout](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization/indicator-layouts/add-a-script-in-the-indicator-layout.md): Add dynamic script output to an indicator layout.
* [Indicator Extraction](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction.md): Indicator extraction extracts indicators from incident fields and enriches them with commands and scripts defined for the indicator type.
* [Indicator Extraction Modes](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/indicator-extraction-modes.md): Indicator extraction modes and their behavior.
* [Create Indicator Extraction Rules for an Incident Type](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md): Configure indicator extraction rules for incident types.
* [Run Indicator Extraction in the CLI](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/run-indicator-extraction-in-the-cli.md): Extract and enrich indicators from the command line.
* [Create Indicator Extract Rules for a Playbook Task](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/create-indicator-extract-rules-for-a-playbook-task.md): Configure indicator extraction for playbook tasks.
* [Disable Indicator Extraction for Automations or Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction/disable-indicator-extraction-for-automations-or-integrations.md): Disable indicator extraction for specific automations or integrations.
* [Indicator Expiration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a period of time or never to expire. Set default expiration method.
* [Feed Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/feed-integrations.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
* [Dashboards](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards.md): Create, edit, and share dashboards in Cortex XSOAR. Add widgets to a dashboard and configure a default dashboard.
* [Dashboard Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/dashboard-overview.md): Cortex XSOAR dashboards provide visual data from customizable widgets. Create, edit, import, share and delete Cortex XSOAR dashboards.
* [Create a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/create-a-dashboard.md): Create and customize a dashboard in Cortex SOAR. Add widgets to a dashboard.
* [Add a Widget to a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/add-a-widget-to-a-dashboard.md): Add a widget to an existing or new dashboard in Cortex XSOAR. Edit widget parameters including date range.
* [Share a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/share-a-dashboard.md): Share or stop sharing a Cortex XSOAR dashboard with other users by role. Set permissions for shared dashboards.
* [Edit a Dashboard](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards/edit-a-dashboard.md): Edit an existing dashboard in Cortex XSOAR. Add, delete or change widgets. Change date range. Adjust size and position of widgets.
* [Reports](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports.md): Create, edit, and customize reports in Cortex XSOAR. Schedule reports with Cron expressions.
* [Reports Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/reports-overview.md): Overview of Cortex XSOAR reports and how to create and edit reports. Analyze data in PDF, Word, and CSV formats. Upload your own logo.
* [Create a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/create-a-report.md): Create a new report in Cortex XSOAR. Add widgets and customize report. Schedule a report.
* [Schedule a report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/schedule-a-report.md): Schedule a report in Cortex XSOAR to run at a specific time. Send reports by email, choose recipients.
* [Customize the Email When Sending a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/customize-the-email-when-sending-a-report.md): Changes the email subject, body, and body HTML when scheduling a report.
* [Create an Incident Summary Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/create-an-incident-summary-report.md): Create and generate a custom Incident Summary report in Cortex XSOAR, from the incident page. Save reports as templates.
* [Select and Customize Sections to Export to a Summary Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/select-and-customize-sections-to-export-to-a-summary-report.md): Select sections to export from the legacy Summary page to a Summary report in Cortex XSOAR. Save report as a template.
* [Add a Widget to a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/add-a-widget-to-a-report.md): Add a widget to a report in Cortex XSOAR.
* [Edit a report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/edit-a-report.md): Edit a report by adding, editing, or removing widgets, and changing the layout and the output type. You cannot edit system reports or incident summary reports.
* [Change the Report Logo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/change-the-report-logo.md): Add a company or organization logo to a report in Cortex XSOAR. Customize report logo with a server configuration.
* [Configure the Time Zone and Format in a Report](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/configure-the-time-zone-and-format-in-a-report.md): Change the time zone and time format in a Cortex XSOAR report. Report troubleshooting
* [Troubleshoot Reports](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/reports/troubleshoot-reports.md): Troubleshoot Cortex XSOAR reports by viewing JSON file. Add temporary server configuration to download and view JSON file for troubleshooting.
* [Widgets](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets.md): Create and edit widgets in Cortex XSOAR for reports and for dashboard
* [Widgets Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/widgets-overview.md): Overview of widgets, including methods for creating and adding widgets. Use widgets to analyze and display data in a dashboard or report in Cortex XSOAR.
* [Create a Widget using the Widget Builder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-widget-using-the-widget-builder.md): Create a widget in the Widgets Library in Cortex XSOAR and then add widget to a dashboard or report.
* [Create a Custom Widget Using a JSON File](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-custom-widget-using-a-json-file.md): Create a custom widget using a JSON file for reports and dashboard in Cortex XSOAR.
* [Create a Custom Widget Using an Automation Script](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-custom-widget-using-an-automation-script.md): Create a custom script based widget in Cortex XSOAR using an Automation Script. Use custom widgets in dashboards and reports.
* [Edit a Widget](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/edit-a-widget.md): Edit a widget in the Widgets Library or in a dashboard or report in Cortex XSOAR.
* [Create a Used Percentage Widget for a Disk Partition](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/create-a-used-percentage-widget-for-a-disk-partition.md): Add server configuration and create new dashboard for used percentage widget for a disk partition in Cortex XSOAR.
* [Saved By Dbot (ROI) Widget](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets/saved-by-dbot-roi-widget.md): Customize Saved by Dbot widget that calculates the amount saved by Cortex XSOAR, using a server configuration. Return on Investment (ROI) widget.
* [Manage Data](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data.md): Manage data in Cortex XSOAR, reindex database or specific index database, free up disk space, migrate data, restore an archive.
* [Reindex the Entire Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-the-entire-database.md): Reindex the database in Cortex XSOAR.
* [Reindex a Specific Index Database](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-a-specific-index-database.md): Reindex a specific index database in Cortex XSOAR. Reindex multiple index databases.
* [Reindex the Audit Log](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/reindex-the-audit-log.md): Reindex the audit log to recover audit trail historical data in Cortex XSOAR.
* [Free up Disk Space with Data Archiving](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/free-up-disk-space-with-data-archiving.md): Free up disk space by archiving Cortex XSOAR folders to condense the unused data within them.
* [Archive Artifacts and Attachments](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/archive-artifacts-and-attachments.md): Archive artifacts and attachments folders.
* [Store Incident/Artifact Files in the Cloud](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/store-incidentartifact-files-in-the-cloud.md): Store incident attachments and artifact files including War Room, or through a Playbook.
* [Migrate Data to Another Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/migrate-data-to-another-server.md): Migrate Cortex XSOAR data to another server, move data, copy files and directories.
* [Migrate Data to Another Server for Multi-Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/migrate-data-to-another-server-for-multi-tenant.md): Migrate Cortex XSOAR data to another server in a multi-tenant environment.
* [Move Data Folders to Another Location on the Server](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/move-data-folders-to-another-location-on-the-server.md): Move Cortex XSOAR data folders to a different location on the server.
* [Restore an Archived Folder](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/restore-an-archived-folder.md): Restore an archived folder in Cortex XSOAR.
* [Logs](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/logs.md): Cortex XSOAR includes a server log and an audit trail as well as the ability to download a log bundle.
* [Logs Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/logs-overview.md): Cortex XSOAR logs information you can use for troubleshooting.
* [Configure the Server Log](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/configure-the-server-log.md): Configure the server log for maximum size, log level, number of files to backup and days to retain log files, in Cortex SXSOAR.
* [Configure the Access Log for HTTPS Requests](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/configure-the-access-log-for-https-requests.md): Add a server configuration to view HTTP/HTTPS requests.
* [Create a Log Bundle](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/create-a-log-bundle.md): Create a log bundle of additional logs for troubleshooting in Cortex XSOAR.
* [Audit Trail](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/audit-trail.md): View, export, extract, and purge the audit trail in Cortex XSOAR. The audit trail logs all administrative user actions in Cortex XSOAR.
* [Send the Audit Trail to an External Log Service](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/logs/send-the-audit-trail-to-an-external-log-service.md): Send the Cortex XSOAR audit trail to an external log service by adding custom server configurations.
* [System Settings](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings.md): Customize the logo, the login message, system emails, and system notifications.
* [Customize the Logo](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-the-logo.md): Customize the full-size and minimized logo in Cortex XSOAR.
* [Customize the Login Message](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-the-login-message.md): Customize the message that appears to users on the login page before logging in to Cortex XSOAR.
* [Customize System Emails](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/customize-system-emails.md): Customize subject and message body for Cortex XSOAR system emails and choose HTML and/or text format.
* [Configure System Notifications](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings/configure-system-notifications.md): Configure email system notifications in Cortex XSOAR, choose mail sender with advanced server configuration settings.
* [Day to Day Tasks in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar.md): Manage daily incident and indicator management tasks in Cortex XSOAR.
* [Incident Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management.md): Open, investigate, and manage incidents in Cortex XSOAR.
* [Create an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-an-incident.md): Create a new incident in Cortex XSOAR, manually, through a feed, or by importing a JSON file.
* [Create a Search Query for Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-a-search-query-for-incidents.md): Create a search query for Cortex XSOAR incidents. Customize which incidents are displayed. Save search queries.
* [Create a Widget From an Incident](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/create-a-widget-from-an-incident.md): Create a widget from an incident search in Cortex XSOAR. Create custom widgets from incidents.
* [Export an Incident to CSV Using the UTF8-BOM Format](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/export-an-incident-to-csv-using-the-utf8-bom-format.md): Export an incident using Cyrillic characters. Export an incident to CSV using UTF8-BOM format.
* [Incident Investigation](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-investigation.md): Open an incident in Cortex SOAR and view incident details.
* [Work Plan](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/work-plan.md): A Cortex XSOAR Work Plan is a visual representation of the running Playbook that is assigned to an incident. Monitor and manage a Playbook work flow.
* [Investigate an Incident Using the Canvas](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md): Visually map a Cortex XSOAR incident using the investigation canvas.
* [Incident Actions](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-actions.md): Incident actions - add child incidents, tasks, notes, create a report, edit, delete, and restrict an incident type in Cortex XSOAR.
* [Evidence Handling](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/evidence-handling.md): Add evidence to the evidence board to assist with your investigation. Mark any entity as evidence in the Cortex XSOAR War Room.
* [Incident Tasks](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-tasks.md): Playbook tasks and to-do tasks are tasks users complete as part of an investigation. Add incident tasks as part of your investigation process.
* [Link Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents.md): Link incidents in the Related Incidents tab, using a pre-process rule, or in the CLI.
* [Configure Incident Fields for Related Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/configure-incident-fields-for-related-incidents.md): Configure incident fields for related incidents by adding a server configuration for an allow or ignore list in Cortex XSOAR.
* [Indicator Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Indicator Query](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/indicator-query.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Configure the Indicator Timeline](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Exclusion List](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/exclusion-list.md): When adding to an exclusion list, indicators are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Export Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management/export-indicators.md): You can export indicators from Cortex XSOAR as a list, external dynamic list, or file, which can then be sent to or pulled by a SIEM, firewall, etc.
* [Reference](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference.md): Reference information for Cortex XSOAR.
* [Navigation Cheat Sheet](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/navigation-cheat-sheet.md): Learn about commonly used features of Cortex XSOAR.
* [Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations.md): Server configurations for Cortex XSOAR, for customization and troubleshooting.
* [Modify Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/modify-server-configurations.md): Customize and troubleshoot Cortex XSOAR with server configuration settings.
* [Active Directory Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/active-directory-server-configurations.md): Server configurations for Active Directory.
* [Automation Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/automation-server-configurations.md): Server configurations for automations.
* [Dashboard Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/dashboard-server-configurations.md): Server configurations for dashboards.
* [Database Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/database-server-configurations.md): Server configurations for the database.
* [Disaster Recovery Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/disaster-recovery-server-configurations.md): Server configurations for disaster recovery.
* [Docker Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/docker-server-configurations.md): Server configurations for Docker.
* [Elasticsearch Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/elasticsearch-server-configurations.md): Server configurations for Elasticsearch.
* [Engine Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/engine-server-configurations.md): Server configurations for engines.
* [General Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/general-server-configurations.md): Miscellaneous server configurations.
* [Google API Server Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/google-api-server-configuration.md): Server configuration for Google API.
* [Incident Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/incident-server-configurations.md): Server configurations for incidents.
* [Indicator Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/indicator-server-configurations.md): Server configurations for indicators.
* [Integration Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/integration-server-configurations.md): Server configurations for integrations.
* [List Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/list-server-configurations.md): Server configurations for lists.
* [Logs Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/logs-server-configurations.md): Server configurations for logs.
* [Marketplace Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/marketplace-server-configurations.md): Server configurations for Marketplace.
* [Multi-Tenant Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/multi-tenant-server-configurations.md): Server configurations for multi-tenant deployments.
* [Notification Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/notification-server-configurations.md): Server configurations for notifications.
* [Playbook Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/playbook-server-configurations.md): Server configurations for playbooks.
* [Proxy Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/proxy-server-configurations.md): Server configurations for proxy servers.
* [Remote Repository Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/remote-repository-server-configurations.md): Server configurations for remote repositories.
* [Report Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/report-server-configurations.md): Server configurations for reports.
* [Security Headers Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/security-headers-server-configurations.md): Server configurations for security headers.
* [SLA Server Configuration](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/sla-server-configuration.md): Server configuration for SLAs.
* [System Diagnostics Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/system-diagnostics-server-configurations.md): Server configurations for system diagnostics.
* [Users and Roles Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/users-and-roles-server-configurations.md): Server configurations for users and roles.
* [War Room Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/war-room-server-configurations.md): Server configurations for the War Room.
* [Widget Server Configurations](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/server-configurations/widget-server-configurations.md): Server configurations for widgets.
* [System Diagnostics](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/system-diagnostics.md): Find and fix system performance issues in Cortex XSOAR. System health, system monitoring.
* [Fix System Diagnostics Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/system-diagnostics/fix-system-diagnostics-issues.md): Fix alerts from the System Diagnostics page.
* [Performance Tuning for Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/performance-tuning-for-cortex-xsoar.md)
* [Supported Ciphers](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/supported-ciphers.md): List of Cipher Suites for TLS1.2 and TLS1.3 supported by Cortex XSOAR Server and Engines
* [Telemetry](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/telemetry.md): Cortex XSOAR uses telemetry to collect specific usage data. The data is analyzed and used to improve Cortex XSOAR. Disable or enable telemetry.
* [Keyboard Shortcuts](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/keyboard-shortcuts.md): Keyboard shortcuts to navigate and manage Cortex XSOAR, for playbooks, scripts, CLI, incident pages, and shoulders.
* [Indicator Fields Structure](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/reference-docs/reference/indicator-fields-structure.md): Indicator fields structure aligned with STIX standards to more easily share and work with IOCs.

## Cortex XSOAR 6 Threat Intel Management Guides

- [Cortex XSOAR 6 Threat Intel Management Guides](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/cortex-xsoar-6-threat-intel-management-guides.md): Start here to choose the right Cortex XSOAR 6 version.

* [Navigate the Threat Intel Management Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/learn-about-threat-intel-management/readme.md): Start here for a visual overview of the main Cortex XSOAR Threat Intel Management 6.14 documentation areas.
* [Threat Intel Management Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/learn-about-threat-intel-management/readme-1.md): Cortex XSOAR provides native threat intel capabilities.
* [Indicator Concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/learn-about-threat-intel-management/readme-1/indicator-concepts.md): Cortex XSOAR provides threat intelligence management. TIM concepts include fetch indicators, configure indicators, and export indicators. Threat intel management
* [Indicator Verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/learn-about-threat-intel-management/readme-1/indicator-verdict.md): Indicator verdict affects how the indicator is processed and handled in Cortex XSOAR. Assigned by reputation returned by the source with highest reliability.
* [Indicator Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/learn-about-threat-intel-management/readme-1/indicator-ingestion.md): Overview of how Cortex XSOAR indicators are detected and ingested.
* [Indicator Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization.md): Customize indicator types, fields, and layouts.
* [Indicator Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types.md): Indicator types are determined by searching for predefined regular expressions (regex) in the Cortex XSOAR War Room or by user assignment.
* [File Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/file-indicators.md): You can have a single file indicator for file objects in Cortex XSOAR or each file can have a hash as its own indicator.
* [Create an Indicator Type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/create-an-indicator-type.md): In addition to the system-level indicator types, you can create custom indicator types in Cortex XSOAR.
* [Indicator Type Profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/indicator-type-profile.md): Create or edit a Cortex XSOAR indicator type and configure fields that determine how the system interacts with indicators of that type.
* [Formatting Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/formatting-scripts.md): Formatting scripts validate input and modify how indicators display.
* [Enhancement Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/enhancement-scripts.md): Enhancement scripts are run manually and can enrich indicators, write to context, return entries to the War Room, etc.
* [Reputation Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/reputation-scripts.md): Reputation scripts for indicator enrichment
* [Reputation Commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/reputation-commands.md): Reputation commands run based on the indicator's type, and return a verdict for the indicator.
* [Map Custom Indicator Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/map-custom-indicator-fields.md): The value of the custom incident field is determined by the value of the key in Context data to which the field is mapped in Cortex XSOAR.
* [Indicator Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-fields.md): Indicator Fields are used to add specific indicator information to indicators. Associate fields to a specific indicator type or all indicator types in Cortex XSOAR.
* [Create a Custom Indicator Field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md): Create a custom indicator field in the Fields tab in Cortex XSOAR. Add specific indicator information to incidents.
* [Indicator Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-fields/indicator-field-trigger-scripts.md): Associate Cortex XSOAR indicator fields with scripts that are triggered when the field changes.
* [Indicator Fields Structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-fields/indicator-fields-structure.md): Indicator fields structure aligned with STIX standards to more easily share and work with IOCs.
* [Indicator Layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-layouts.md): Overview of the indicator view layout in Cortex XSOAR.
* [Customize an Indicator Type Layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-layouts/customize-an-indicator-type-layout.md): Customize Indicator layouts for each indicator type in Cortex XSOAR.
* [Add a Script in the Indicator Layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-layouts/add-a-script-in-the-indicator-layout.md): Add automation script based content to an indicator in Cortex XSOAR using the dynamic section layout builder. Add a script in the indicator layout.
* [Indicator Extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-extraction.md): Indicator extraction extracts indicators from incident fields and enriches them with commands and scripts defined for the indicator type.
* [Indicator Extraction Modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-extraction/indicator-extraction-modes.md): Configure the indicator extraction mode. Options are none (no extraction), inline, out-of-band, or use system default.
* [Create Indicator Extraction Rules for an Incident Type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md): Create indicator extraction rules for an incident type. Customize indicator extraction in Cortex XSOAR.
* [Run Indicator Extraction in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-extraction/run-indicator-extraction-in-the-cli.md): Use reputation commands, extractindicators command or the enrichIndicators command in the CLI.
* [Create Indicator Extract Rules for a Playbook Task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-extraction/create-indicator-extract-rules-for-a-playbook-task.md): Create indicator extraction rules for a playbook task in Cortex XSOAR. Set extraction for a playbook task.
* [Disable Indicator Extraction for Automations or Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-extraction/disable-indicator-extraction-for-automations-or-integrations.md): Disable indicator extraction for a specific automation or integration in Cortex XSOAR.
* [Indicator Expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a period of time or never to expire. Set default expiration method.
* [Threat Intel Feeds](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/threat-intel-feeds.md): Use integrations to import and export indicators of compromise in Cortex XSOAR and set the source reliability of enrichment integrations.
* [Feed Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/threat-intel-feeds/feed-integrations.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
* [Feed-Triggered Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/threat-intel-feeds/feed-integrations/feed-triggered-jobs.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
* [Set the Source Reliability of Enrichment Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/threat-intel-feeds/set-the-source-reliability-of-enrichment-integrations.md): Set the source reliability of enrichment integrations for Cortex XSOAR. servers
* [Threat Intelligence Management Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/threat-intel-feeds/threat-intelligence-management-playbooks.md): TIM playbooks are triggered by jobs and process large numbers of indicators. TIM playbook configuration and settings.
* [Indicator Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Indicator Query](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/indicator-query.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Configure the Indicator Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Exclusion List](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/exclusion-list.md): When adding to an exclusion list, indicators are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Export Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/export-indicators.md): You can export indicators from Cortex XSOAR as a list, external dynamic list, or file, which can then be sent to or pulled by a SIEM, firewall, etc.
* [Manually Export Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/export-indicators/manually-export-indicators.md): You can manually export indicators to a file directly from the Indicators page in Cortex XSOAR.
* [Export Indicators Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/export-indicators/export-indicators-integrations.md): There are several outbound-feed integrations that exports indicators to a file or list from Cortex XSOAR.
* [Export Indicators Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/export-indicators/export-indicators-playbooks.md): There are several generic playbooks and several vendor-specific playbooks you can use to process indicators in Cortex XSOAR.
* [Export an Indicator to CSV Using the UTF8-BOM Format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/export-indicators/export-an-indicator-to-csv-using-the-utf8-bom-format.md): Export an indicator to CSV using Cyrillic characters in Cortex XSOAR.
* [Indicator Relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/indicator-relationships.md): Relationships allow to you create connections between Cortex XSOAR indicators.
* [Create Indicator Relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/indicator-relationships/create-indicator-relationships.md): Create relationships between indicators to enhance your investigations.
* [Leverage Relationships in the Canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-management/indicator-relationships/leverage-relationships-in-the-canvas.md): Relationships are used to enrich your investigation based on information from other indicators.
* [Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports.md): Create a Threat Intel Report
* [Threat Intel Reports Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-overview.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Threat Intel Reports Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-customization.md): Set up and customize threat intel report types in Cortex XSOAR.
* [Configure Threat Intel Report Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-types.md): Configure threat intel report types.
* [Configure Threat Intel Report Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-fields.md): Configure threat intel report fields.
* [Configure Threat Intel Report Layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-layouts.md): Configure threat intel report layouts. Add automation script based content to an indicator in Cortex XSOAR. Add a script in the layout.
* [Threat Intel Reports Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-management.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Create a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-management/create-a-threat-intel-report.md): Create a threat intel report from a type/layout.
* [RBAC for Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-management/rbac-for-reports.md): Use role based access control to limit read/write access to threat intel reports to specific roles.
* [Generate a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-management/generate-a-threat-intel-report.md): Export a threat intel report, or share it with others (publish).
* [Publish a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/reports/threat-intel-reports/threat-intel-reports-management/publish-a-threat-intel-report.md): Publish a threat intel report, providing read-only access to all roles.

- [Navigate the Threat Intel Management Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/learn-about-threat-intel-management/readme.md): Start here for a visual overview of the main Cortex XSOAR Threat Intel Management 6.13 documentation areas.
- [Threat Intel Management Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/learn-about-threat-intel-management/readme-1.md): Cortex XSOAR provides native threat intel capabilities.
- [Indicator Concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/learn-about-threat-intel-management/readme-1/indicator-concepts.md): Cortex XSOAR provides threat intelligence management. TIM concepts include fetch indicators, configure indicators, and export indicators. Threat intel management
- [Indicator Verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/learn-about-threat-intel-management/readme-1/indicator-verdict.md): Indicator verdict affects how the indicator is processed and handled in Cortex XSOAR. Assigned by reputation returned by the source with highest reliability.
- [Indicator Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/learn-about-threat-intel-management/readme-1/indicator-ingestion.md): Overview of how Cortex XSOAR indicators are detected and ingested.
- [Indicator Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization.md): Customize indicator types, fields, and layouts.
- [Indicator Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types.md): Indicator types are determined by searching for predefined regular expressions (regex) in the Cortex XSOAR War Room or by user assignment.
- [File Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/file-indicators.md): You can have a single file indicator for file objects in Cortex XSOAR or each file can have a hash as its own indicator.
- [Create an Indicator Type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/create-an-indicator-type.md): In addition to the system-level indicator types, you can create custom indicator types in Cortex XSOAR.
- [Indicator Type Profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/indicator-type-profile.md): Create or edit a Cortex XSOAR indicator type and configure fields that determine how the system interacts with indicators of that type.
- [Formatting Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/formatting-scripts.md): Formatting scripts validate input and modify how indicators display.
- [Enhancement Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/enhancement-scripts.md): Enhancement scripts are run manually and can enrich indicators, write to context, return entries to the War Room, etc.
- [Reputation Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/reputation-scripts.md): Reputation scripts for indicator enrichment
- [Reputation Commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/reputation-commands.md): Reputation commands run based on the indicator's type, and return a verdict for the indicator.
- [Map Custom Indicator Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-types/map-custom-indicator-fields.md): The value of the custom incident field is determined by the value of the key in Context data to which the field is mapped in Cortex XSOAR.
- [Indicator Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-fields.md): Indicator Fields are used to add specific indicator information to indicators. Associate fields to a specific indicator type or all indicator types in Cortex XSOAR.
- [Create a Custom Indicator Field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md): Create a custom indicator field in the Fields tab in Cortex XSOAR. Add specific indicator information to incidents.
- [Indicator Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-fields/indicator-field-trigger-scripts.md): Associate Cortex XSOAR indicator fields with scripts that are triggered when the field changes.
- [Indicator Fields Structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-fields/indicator-fields-structure.md): Indicator fields structure aligned with STIX standards to more easily share and work with IOCs.
- [Indicator Layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-layouts.md): Overview of the indicator view layout in Cortex XSOAR.
- [Customize an Indicator Type Layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-layouts/customize-an-indicator-type-layout.md): Customize Indicator layouts for each indicator type in Cortex XSOAR.
- [Add a Script in the Indicator Layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-customization/indicator-layouts/add-a-script-in-the-indicator-layout.md): Add automation script based content to an indicator in Cortex XSOAR using the dynamic section layout builder. Add a script in the indicator layout.
- [Indicator Extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-extraction.md): Indicator extraction extracts indicators from incident fields and enriches them with commands and scripts defined for the indicator type.
- [Indicator Extraction Modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-extraction/indicator-extraction-modes.md): Configure the indicator extraction mode. Options are none (no extraction), inline, out-of-band, or use system default.
- [Create Indicator Extraction Rules for an Incident Type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md): Create indicator extraction rules for an incident type. Customize indicator extraction in Cortex XSOAR.
- [Run Indicator Extraction in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-extraction/run-indicator-extraction-in-the-cli.md): Use reputation commands, extractindicators command or the enrichIndicators command in the CLI.
- [Create Indicator Extract Rules for a Playbook Task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-extraction/create-indicator-extract-rules-for-a-playbook-task.md): Create indicator extraction rules for a playbook task in Cortex XSOAR. Set extraction for a playbook task.
- [Disable Indicator Extraction for Automations or Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-extraction/disable-indicator-extraction-for-automations-or-integrations.md): Disable indicator extraction for a specific automation or integration in Cortex XSOAR.
- [Indicator Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Indicator Query](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/indicator-query.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
- [Configure the Indicator Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
- [Exclusion List](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/exclusion-list.md): When adding to an exclusion list, indicators are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
- [Export Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/export-indicators.md): You can export indicators from Cortex XSOAR as a list, external dynamic list, or file, which can then be sent to or pulled by a SIEM, firewall, etc.
- [Manually Export Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/export-indicators/manually-export-indicators.md): You can manually export indicators to a file directly from the Indicators page in Cortex XSOAR.
- [Export Indicators Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/export-indicators/export-indicators-integrations.md): There are several outbound-feed integrations that exports indicators to a file or list from Cortex XSOAR.
- [Export Indicators Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/export-indicators/export-indicators-playbooks.md): There are several generic playbooks and several vendor-specific playbooks you can use to process indicators in Cortex XSOAR.
- [Export an Indicator to CSV Using the UTF8-BOM Format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/export-indicators/export-an-indicator-to-csv-using-the-utf8-bom-format.md): Export an indicator to CSV using Cyrillic characters in Cortex XSOAR.
- [Indicator Relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/indicator-relationships.md): Relationships allow to you create connections between Cortex XSOAR indicators.
- [Create Indicator Relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/indicator-relationships/create-indicator-relationships.md): Create relationships between indicators to enhance your investigations.
- [Leverage Relationships in the Canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-management/indicator-relationships/leverage-relationships-in-the-canvas.md): Relationships are used to enrich your investigation based on information from other indicators.
- [Indicator Expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a period of time or never to expire. Set default expiration method.
- [Threat Intel Feeds](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/threat-intel-feeds.md): Use integrations to import and export indicators of compromise in Cortex XSOAR and set the source reliability of enrichment integrations.
- [Feed Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/threat-intel-feeds/feed-integrations.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
- [Feed-Triggered Jobs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/threat-intel-feeds/feed-integrations/feed-triggered-jobs.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
- [Set the Source Reliability of Enrichment Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/threat-intel-feeds/set-the-source-reliability-of-enrichment-integrations.md): Set the source reliability of enrichment integrations for Cortex XSOAR. servers
- [Threat Intelligence Management Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/configure-indicators/threat-intel-feeds/threat-intelligence-management-playbooks.md): TIM playbooks are triggered by jobs and process large numbers of indicators. TIM playbook configuration and settings.
- [Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports.md): Create a Threat Intel Report
- [Threat Intel Reports Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-overview.md): An overview of working with threat intel reports in Cortex XSOAR.
- [Threat Intel Reports Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-customization.md): Set up and customize threat intel report types in Cortex XSOAR.
- [Configure Threat Intel Report Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-types.md): Configure threat intel report types.
- [Configure Threat Intel Report Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-fields.md): Configure threat intel report fields.
- [Configure Threat Intel Report Layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-layouts.md): Configure threat intel report layouts. Add automation script based content to an indicator in Cortex XSOAR. Add a script in the layout.
- [Threat Intel Reports Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-management.md): An overview of working with threat intel reports in Cortex XSOAR.
- [Create a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-management/create-a-threat-intel-report.md): Create a threat intel report from a type/layout.
- [RBAC for Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-management/rbac-for-reports.md): Use role based access control to limit read/write access to threat intel reports to specific roles.
- [Generate a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-management/generate-a-threat-intel-report.md): Export a threat intel report, or share it with others (publish).
- [Publish a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13/reports/threat-intel-reports/threat-intel-reports-management/publish-a-threat-intel-report.md): Publish a threat intel report, providing read-only access to all roles.

* [Navigate the Threat Intel Management Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/learn-about-threat-intel-management/readme.md): Start here for a visual overview of the main Cortex XSOAR Threat Intel Management 6.12 documentation areas.
* [Threat Intel Management Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/learn-about-threat-intel-management/threat-intel-management-overview.md): Cortex XSOAR provides native threat intel capabilities.
* [Indicator Concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/learn-about-threat-intel-management/threat-intel-management-overview/indicator-concepts.md): Cortex XSOAR provides threat intelligence management. TIM concepts include fetch indicators, configure indicators, and export indicators. Threat intel management
* [Indicator Verdict](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/learn-about-threat-intel-management/threat-intel-management-overview/indicator-verdict.md): Indicator verdict affects how the indicator is processed and handled in Cortex XSOAR. Assigned by reputation returned by the source with highest reliability.
* [Indicator Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/learn-about-threat-intel-management/threat-intel-management-overview/indicator-ingestion.md): Overview of how Cortex XSOAR indicators are detected and ingested.
* [Indicator Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization.md): Customize indicator types, fields, and layouts.
* [Indicator Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types.md): Indicator types are determined by searching for predefined regular expressions (regex) in the Cortex XSOAR War Room or by user assignment.
* [File Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/file-indicators.md): You can have a single file indicator for file objects in Cortex XSOAR or each file can have a hash as its own indicator.
* [Create an Indicator Type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/create-an-indicator-type.md): In addition to the system-level indicator types, you can create custom indicator types in Cortex XSOAR.
* [Indicator Type Profile](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/indicator-type-profile.md): Create or edit a Cortex XSOAR indicator type and configure fields that determine how the system interacts with indicators of that type.
* [Formatting Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/formatting-scripts.md): Formatting scripts validate input and modify how indicators display.
* [Enhancement Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/enhancement-scripts.md): Enhancement scripts are run manually and can enrich indicators, write to context, return entries to the War Room, etc.
* [Reputation Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/reputation-scripts.md): Reputation scripts for indicator enrichment
* [Reputation Commands](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/reputation-commands.md): Reputation commands run based on the indicator's type, and return a verdict for the indicator.
* [Map Custom Indicator Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-types/map-custom-indicator-fields.md): The value of the custom incident field is determined by the value of the key in Context data to which the field is mapped in Cortex XSOAR.
* [Indicator Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-fields.md): Indicator Fields are used to add specific indicator information to indicators. Associate fields to a specific indicator type or all indicator types in Cortex XSOAR.
* [Create a Custom Indicator Field](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md): Create a custom indicator field in the Fields tab in Cortex XSOAR. Add specific indicator information to incidents.
* [Indicator Field Trigger Scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-fields/indicator-field-trigger-scripts.md): Associate Cortex XSOAR indicator fields with scripts that are triggered when the field changes.
* [Indicator Fields Structure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-fields/indicator-fields-structure.md): Indicator fields structure aligned with STIX standards to more easily share and work with IOCs.
* [Indicator Layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-layouts.md): Overview of the indicator view layout in Cortex XSOAR.
* [Customize an Indicator Type Layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-layouts/customize-an-indicator-type-layout.md): Customize Indicator layouts for each indicator type in Cortex XSOAR.
* [Add a Script in the Indicator Layout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-customization/indicator-layouts/add-a-script-in-the-indicator-layout.md): Add automation script based content to an indicator in Cortex XSOAR using the dynamic section layout builder. Add a script in the indicator layout.
* [Indicator Extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-extraction.md): Indicator extraction extracts indicators from incident fields and enriches them with commands and scripts defined for the indicator type.
* [Indicator Extraction Modes](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-extraction/indicator-extraction-modes.md): Configure the indicator extraction mode. Options are none (no extraction), inline, out-of-band, or use system default.
* [Create Indicator Extraction Rules for an Incident Type](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-extraction/create-indicator-extraction-rules-for-an-incident-type.md): Create indicator extraction rules for an incident type. Customize indicator extraction in Cortex XSOAR.
* [Run Indicator Extraction in the CLI](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-extraction/run-indicator-extraction-in-the-cli.md): Use reputation commands, extractindicators command or the enrichIndicators command in the CLI.
* [Create Indicator Extract Rules for a Playbook Task](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-extraction/create-indicator-extract-rules-for-a-playbook-task.md): Create indicator extraction rules for a playbook task in Cortex XSOAR. Set extraction for a playbook task.
* [Disable Indicator Extraction for Automations or Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-extraction/disable-indicator-extraction-for-automations-or-integrations.md): Disable indicator extraction for a specific automation or integration in Cortex XSOAR.
* [Indicator Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management.md): Perform actions (create, edit, export, delete) and search for indicators on the Cortex XSOAR Threat Intel page.
* [Configure the Indicator Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/configure-the-indicator-timeline.md): Add a server configuration to manage the indicator timeline in Cortex XSOAR and improve indicator timeline performance.
* [Exclusion List](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/exclusion-list.md): When adding to an exclusion list, indicators are disregarded by the system. Add indicators to an exclusion list in Cortex XSOAR.
* [Export Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/export-indicators.md): You can export indicators from Cortex XSOAR as a list, external dynamic list, or file, which can then be sent to or pulled by a SIEM, firewall, etc.
* [Manually Export Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/export-indicators/manually-export-indicators.md): You can manually export indicators to a file directly from the Indicators page in Cortex XSOAR.
* [Export Indicators Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/export-indicators/export-indicators-integrations.md): There are several outbound-feed integrations that exports indicators to a file or list from Cortex XSOAR.
* [Export Indicators Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/export-indicators/export-indicators-playbooks.md): There are several generic playbooks and several vendor-specific playbooks you can use to process indicators in Cortex XSOAR.
* [Export an Indicator to CSV Using the UTF8-BOM Format](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/export-indicators/export-an-indicator-to-csv-using-the-utf8-bom-format.md): Export an indicator to CSV using Cyrillic characters in Cortex XSOAR.
* [Indicator Relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/indicator-relationships.md): Relationships allow to you create connections between Cortex XSOAR indicators.
* [Create Indicator Relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/indicator-relationships/create-indicator-relationships.md): Create relationships between indicators to enhance your investigations.
* [Leverage Relationships in the Canvas](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-management/indicator-relationships/leverage-relationships-in-the-canvas.md): Relationships are used to enrich your investigation based on information from other indicators.
* [Indicator Expiration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/indicator-expiration.md): Cortex XSOAR indicators have an active or expired status which can be set to expire after a period of time or never to expire. Set default expiration method.
* [Threat Intel Feeds](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/threat-intel-feeds.md): Use integrations to import and export indicators of compromise in Cortex XSOAR and set the source reliability of enrichment integrations.
* [Feed Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/threat-intel-feeds/feed-integrations.md): Feed integrations fetch indicators from a threat intelligence feed and add them to Cortex XSOAR for processing and handling.
* [Set the Source Reliability of Enrichment Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/threat-intel-feeds/set-the-source-reliability-of-enrichment-integrations.md): Set the source reliability of enrichment integrations for Cortex XSOAR. servers
* [Threat Intelligence Management Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/configure-indicators/threat-intel-feeds/threat-intelligence-management-playbooks.md): TIM playbooks are triggered by jobs and process large numbers of indicators. TIM playbook configuration and settings.
* [Threat Intel Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports.md): Create a Threat Intel Report
* [Threat Intel Reports Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-overview.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Threat Intel Reports Customization](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-customization.md): Set up and customize threat intel report types in Cortex XSOAR.
* [Configure Threat Intel Report Types](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-types.md): Configure threat intel report types.
* [Configure Threat Intel Report Fields](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-fields.md): Configure threat intel report fields.
* [Configure Threat Intel Report Layouts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-customization/configure-threat-intel-report-layouts.md): Configure threat intel report layouts. Add automation script based content to an indicator in Cortex XSOAR. Add a script in the layout.
* [Threat Intel Reports Management](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-management.md): An overview of working with threat intel reports in Cortex XSOAR.
* [Create a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-management/create-a-threat-intel-report.md): Create a threat intel report from a type/layout.
* [RBAC for Reports](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-management/rbac-for-reports.md): Use role based access control to limit read/write access to threat intel reports to specific roles.
* [Generate a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-management/generate-a-threat-intel-report.md): Export a threat intel report, or share it with others (publish).
* [Publish a Threat Intel Report](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12/reports/threat-intel-reports/threat-intel-reports-management/publish-a-threat-intel-report.md): Publish a threat intel report, providing read-only access to all roles.

## Cortex XSOAR 6 Multi-Tenant Guides

- [Cortex XSOAR 6 Multi-Tenant Guides](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/cortex-xsoar-6-multi-tenant-guides.md): Start here to choose the right Cortex XSOAR 6 version.

* [Navigate the Multi-Tenant Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/readme.md): Start here for a visual overview of the Cortex XSOAR Multi-Tenant 6.14 documentation areas.
* [Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/readme-1.md): Overview of Cortex XSOAR multi-tenant deployments for Managed Security Service Provider (MSSPs) and Enterprises.
* [Multi-Tenant Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/readme-1/multi-tenant-overview.md): Cortex XSOAR multi-tenant deployments for Managed Security Service Provider (MSSPs) and enterprises that require data segregation between tenant accounts.
* [Multi-Tenant High Availability Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/readme-1/multi-tenant-high-availability-overview.md): A conceptual overview of high availability for a Cortex XSOAR multi-tenant deployment.
* [Plan Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment.md): Sizing requirements and security settings for Cortex XSOAR multi-tenant deployments.
* [Multi-Tenant Sizing Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/multi-tenant-sizing-requirements.md): Sizing requirements for a Cortex XSOAR multi-tenant deployment depend on the number of hosts and tenants deployed.
* [Configure Security Settings for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/configure-security-settings-for-multi-tenant-deployments.md): Add server configurations to harden your Cortex XSOAR multi-tenant deployment. Security settings for multi-tenant deployments.
* [SAML for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/saml-for-multi-tenant-deployments.md): Authenticate Cortex XSOAR users using SAML 2.0 in a multi-tenant deployment.
* [Communication in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/communication-in-a-multi-tenant-deployment.md): Ports used in a multi-tenant deployment.
* [Configure unidirectional communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/communication-in-a-multi-tenant-deployment/configure-unidirectional-communication.md): Ports used in a multi-tenant deployment.
* [Change the Port for Host to Main Communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/learn-about-mult-tenant/plan-your-multi-tenant-deployment/change-the-port-for-host-to-main-communication.md): Set a custom port on the main account to enable communication from host to main in a multi-tenant deployment.
* [Multi-Tenant Deployment Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/onboard-multi-tenant/multi-tenant-deployment-installation.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database or Elasticsearch. Upgrade multi-tenant deployment.
* [Install Cortex XSOAR for a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database (not Elasticsearch).
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment/installer-flags.md): List of supported flags for installing Cortex XSOAR.
* [Install Cortex XSOAR for a Multi-Tenant Deployment with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment-with-elasticsearch.md): Install Cortex XSOAR for a multi-tenant deployment using an Elasticsearch database. Installer flags for multi-tenant deployment with Elasticsearch.
* [Upgrade Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/onboard-multi-tenant/multi-tenant-deployment-installation/upgrade-your-multi-tenant-deployment.md): Upgrading a Cortex XSOAR multi-tenant deployment including preparation, upgrade and post upgrade steps.
* [Multi-Tenant Upgrade Procedure](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/onboard-multi-tenant/multi-tenant-deployment-installation/upgrade-your-multi-tenant-deployment/multi-tenant-upgrade-procedure.md): Upgrading a Cortex XSOAR multi-tenant deployment including preparation, upgrade and post upgrade steps.
* [Get the Host Installer Manually](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/onboard-multi-tenant/multi-tenant-deployment-installation/get-the-host-installer-manually.md): Manually get the host installer file in cases where you can’t access the Cortex XSOAR server or platform. Copy installation file and run from the host.
* [Configure the Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment.md): Configure Cortex XSOAR Multi-Tenant Deployment. Manage hosts, tenants, backups, and engines.
* [Main Account to Tenant Communication Encryption](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/main-account-to-tenant-communication-encryption.md): Configure two-way communication between main account and tenant for Cortex XSOAR Multi-Tenant deployment. Manage encryption and API keys.
* [Add a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/add-a-host.md): Add a new host server and scale out Cortex XSOAR multi-tenant deployments by spreading tenants across host servers.
* [Add a Tenant to a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/add-a-tenant-to-a-host.md): Add a new tenant (account) to a host server for Cortex XSOAR Multi-Tenant deployment. Populate tenants with users by specifying user roles.
* [Delete a Tenant From a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/delete-a-tenant-from-a-host.md): Delete a tenant from a host using options on the the Account Management page.
* [Delete a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/delete-a-host.md): Delete a host from a Cortex XSOAR multi-tenant (MT) environment.
* [Configure Live Backup](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-live-backup.md): Configure Live Backup for an existing Cortex XSOAR multi-tenant deployment. Configure Live Backup for the main server and the host server.
* [Configure the HTTP Request Timeout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-the-http-request-timeout.md): Configure HTTP timeout for Cortex XSOAR multi-tenant deployments (main and tenant accounts). Default HTTP timeout is 30 seconds.
* [Configure the Account Timeout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-the-account-timeout.md): If you receive an error when moving large tenant accounts, configure the account timeout.
* [Forward Server Configurations to Tenant Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/forward-server-configurations-to-tenant-accounts.md): Forward server configurations from the main account to all tenant accounts for a Cortex XSOAR multi-tenant deployment.
* [Run a Command on Multiple Tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
* [Move a Tenant to a Different Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/move-a-tenant-to-a-different-host.md): Move a tenant to a different host in a Cortex XSOAR multi-tenant deployment. Backup the tenant first.
* [Stop and Start a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/stop-and-start-a-tenant.md): Stop and start a tenant in a Cortex XSOAR multi-tenant deployment, through the API or the UI. Reindex a tenant.
* [Block and Unblock a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/block-and-unblock-a-tenant.md): Block or unblock a tenant (account) at the proxy level for Cortex XSOAR multi-tenant deployment. Troubleshoot tenant performance issues.
* [Reindex a Tenant Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/reindex-a-tenant-database.md): Reindex a tenant database in the Cortex XSOAR multi-tenant environment.
* [Back Up a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/back-up-a-tenant.md): Create a backup of a tenant account for a Cortex XSOAR multi-tenant deployment. Perform manual and automatic backups of the database.
* [Reindex a Specific Index for a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/reindex-a-specific-index-for-a-tenant.md): Reindex one or more indexes for an individual tenant in a multi-tenant deployment.
* [Restore a Tenant Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/restore-a-tenant-database.md): Restore a tenant database from a manual backup or automated backup back up in Cortex XSOAR.
* [Restore a Partition for a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/restore-a-partition-for-a-tenant.md): Restore a partition for a specific tenant in a multi tenant environment
* [Index War Room Entries in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/index-war-room-entries-in-a-multi-tenant-deployment.md): Index Cortex XSOAR War Room entries to ensure that you can search for them in the Search Incidents. Re-index incidents for selected months.
* [Install Engines on Tenants in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/install-engines-on-tenants-in-a-multi-tenant-deployment.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and server.
* [Configure User Settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-user-settings.md): Cortex XSOAR users can control details, preferences, and notifications, by changing the notifications settings in their user profile.
* [Manage Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content.md): Apply propagation labels and sync content to tenant accounts in a Cortex XSOAR multi-tenant deployment.
* [Manage Content Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/manage-content-overview.md): Content is pushed from the master account to tenant accounts by applying corresponding propagation labels to content and tenant accounts.
* [Add Propagation Labels to an Existing Tenant Account](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/add-propagation-labels-to-an-existing-tenant-account.md): Add propagation labels to an existing tenant account in a Cortex XSOAR multi-tenant deployment to control which content items sync.
* [Add Propagation Labels to Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/add-propagation-labels-to-content.md): Apply propagation labels to control which content is synced from the main account to tenant accounts in a Cortex XSOAR multi-tenant deployment.
* [Add Propagation Labels in Remote Repositories](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/add-propagation-labels-in-remote-repositories.md): Add propagation labels to an existing tenant account in a Cortex XSOAR multi-tenant deployment using remote repositories, to control which content items sync.
* [Content Dependencies and Propagation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/content-dependencies-and-propagation.md): Understand how content that is dependent on other content is propagated to tenants.
* [Sync Content to Tenant Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/sync-content-to-tenant-accounts.md): Sync content to each tenant account individually or sync content to all tenants in a single operation in a Cortex XSOAR multi-tenant deployment.
* [Troubleshoot Errors When Syncing All Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/sync-content-to-tenant-accounts/troubleshoot-errors-when-syncing-all-accounts.md): Fix sync errors for large scale Cortex XSOAR multi-tenant environments by editing demisto.service file on host to limit the number of open files.
* [Disable Propagation Labels](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/disable-propagation-labels.md): Disable propagation labels and automatically sync content from the main account to tenant accounts for Cortex XSOAR multi-tenant deployment.
* [Restrict Actions for Custom Locked Content Items](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/manage-content/restrict-actions-for-custom-locked-content-items.md): Prevent users of tenant accounts from downloading, cloning and viewing codes for custom locked content items in Cortex XSOAR multi tenant deployment.
* [Share Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/share-indicators.md): Share indicators between tenant accounts in a Cortex XSOAR multi-tenant deployment.
* [Share Indicators Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/share-indicators/share-indicators-overview.md): Share indicators between tenant accounts by exporting a tenant’s indicators to a shared index and configuring tenants to ingest from shared index.
* [Manually Share Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/share-indicators/manually-share-indicators.md): Share indicators manually by sending one or more indicators from a tenant to a dedicated shard Elasticsearch index.
* [Export Indicators to the Shared Index](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/share-indicators/export-indicators-to-the-shared-index.md): The Cortex XSOAR Indicators Share integration is a dedicated integration that you configure on each tenant account to export its indicators to the shared index.
* [Ingest Indicators from the Shared Indicators Index](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/share-indicators/ingest-indicators-from-the-shared-indicators-index.md): Configure the Elasticsearch Feed integration on a tenant account to ingest indicators from the shared indexes in a Cortex XSOAR multi-tenant deployment.
* [Remote Repositories for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments.md): Configure remote repositories for Cortex XSOAR multi-tenant deployments.
* [Remote Repositories Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/remote-repositories-overview.md): Use a remote repository to develop and test content. Push content to tenants using propagation labels in a Cortex XSOAR multi-tenant deployment.
* [Configure a Remote Repository on a Development Machine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/configure-a-remote-repository-on-a-development-machine.md): Configure remote repository on development machine for Cortex XSOAR multi-tenant deployment and push content to repository. Enable selective propagation.
* [Configure a Remote Repository on the Main Account](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/configure-a-remote-repository-on-the-main-account.md): Configure development machine and production environment (main account) to work with remote repositories in a Cortex XSOAR multi-tenant deployment.
* [Edit and Push Content to a Remote Repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/edit-and-push-content-to-a-remote-repository.md): Push content to a remote repository and control access for pushing content.
* [Troubleshoot a Remote Repository Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration.md): Troubleshoot issues for a Cortex XSOAR remote repository configuration plus FAQs.
* [Troubleshoot a Remote Repository Definition](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-a-remote-repository-definition.md): Troubleshoot a remote repository definition. Remote repository error messages in Cortex XSOAR.
* [Troubleshoot Editing and Pushing Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-editing-and-pushing-content.md): Troubleshoot editing and pushing content to Cortex XSOAR remote repository.
* [Troubleshoot Content Issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-content-issues.md): Troubleshoot content issues in a remote repository. Restore content backup package to restore missing content.

- [Navigate the Multi-Tenant Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/learn-about-multi-tenant/readme.md): Start here for a visual overview of the Cortex XSOAR Multi-Tenant 6.13 documentation areas.
- [Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/learn-about-multi-tenant/readme-1.md): Overview of Cortex XSOAR multi-tenant deployments for Managed Security Service Provider (MSSPs) and Enterprises.
- [Multi-Tenant Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/learn-about-multi-tenant/readme-1/multi-tenant-overview.md): Cortex XSOAR multi-tenant deployments for Managed Security Service Provider (MSSPs) and enterprises that require data segregation between tenant accounts.
- [Multi-Tenant High Availability Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/learn-about-multi-tenant/readme-1/multi-tenant-high-availability-overview.md): A conceptual overview of high availability for a Cortex XSOAR multi-tenant deployment.
- [Plan Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/plan-your-multi-tenant-deployment.md): Sizing requirements and security settings for Cortex XSOAR multi-tenant deployments.
- [Multi-Tenant Sizing Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/plan-your-multi-tenant-deployment/multi-tenant-sizing-requirements.md): Sizing requirements for a Cortex XSOAR multi-tenant deployment depend on the number of hosts and tenants deployed.
- [Configure Security Settings for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/plan-your-multi-tenant-deployment/configure-security-settings-for-multi-tenant-deployments.md): Add server configurations to harden your Cortex XSOAR multi-tenant deployment. Security settings for multi-tenant deployments.
- [SAML for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/plan-your-multi-tenant-deployment/saml-for-multi-tenant-deployments.md): Authenticate Cortex XSOAR users using SAML 2.0 in a multi-tenant deployment.
- [Communication in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/plan-your-multi-tenant-deployment/communication-in-a-multi-tenant-deployment.md): Ports used in a multi-tenant deployment.
- [Change the Port for Host to Main Communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/plan-your-multi-tenant-deployment/change-the-port-for-host-to-main-communication.md): Set a custom port on the main account to enable communication from host to main in a multi-tenant deployment.
- [Multi-Tenant Deployment Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/multi-tenant-deployment-installation.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database or Elasticsearch. Upgrade multi-tenant deployment.
- [Install Cortex XSOAR for a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database (not Elasticsearch).
- [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment/installer-flags.md): List of supported flags for installing Cortex XSOAR.
- [Install Cortex XSOAR for a Multi-Tenant Deployment with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment-with-elasticsearch.md): Install Cortex XSOAR for a multi-tenant deployment using an Elasticsearch database. Installer flags for multi-tenant deployment with Elasticsearch.
- [Upgrade Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/multi-tenant-deployment-installation/upgrade-your-multi-tenant-deployment.md): Upgrading a Cortex XSOAR multi-tenant deployment including preparation, upgrade and post upgrade steps.
- [Get the Host Installer Manually](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/onboard-multi-tenant/multi-tenant-deployment-installation/get-the-host-installer-manually.md): Manually get the host installer file in cases where you can’t access the Cortex XSOAR server or platform. Copy installation file and run from the host.
- [Configure the Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment.md): Configure Cortex XSOAR Multi-Tenant Deployment. Manage hosts, tenants, backups, and engines.
- [Main Account to Tenant Communication Encryption](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/main-account-to-tenant-communication-encryption.md): Configure two-way communication between main account and tenant for Cortex XSOAR Multi-Tenant deployment. Manage encryption and API keys.
- [Add a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/add-a-host.md): Add a new host server and scale out Cortex XSOAR multi-tenant deployments by spreading tenants across host servers.
- [Add a Tenant to a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/add-a-tenant-to-a-host.md): Add a new tenant (account) to a host server for Cortex XSOAR Multi-Tenant deployment. Populate tenants with users by specifying user roles.
- [Delete a Tenant From a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/delete-a-tenant-from-a-host.md): Delete a tenant from a host using options on the the Account Management page.
- [Delete a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/delete-a-host.md): Delete a host from a Cortex XSOAR multi-tenant (MT) environment.
- [Configure Live Backup](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-live-backup.md): Configure Live Backup for an existing Cortex XSOAR multi-tenant deployment. Configure Live Backup for the main server and the host server.
- [Configure the HTTP Request Timeout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-the-http-request-timeout.md): Configure HTTP timeout for Cortex XSOAR multi-tenant deployments (main and tenant accounts). Default HTTP timeout is 30 seconds.
- [Configure the Account Timeout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-the-account-timeout.md): If you receive an error when moving large tenant accounts, configure the account timeout.
- [Forward Server Configurations to Tenant Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/forward-server-configurations-to-tenant-accounts.md): Forward server configurations from the main account to all tenant accounts for a Cortex XSOAR multi-tenant deployment.
- [Run a Command on Multiple Tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
- [Move a Tenant to a Different Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/move-a-tenant-to-a-different-host.md): Move a tenant to a different host in a Cortex XSOAR multi-tenant deployment. Backup the tenant first.
- [Stop and Start a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/stop-and-start-a-tenant.md): Stop and start a tenant in a Cortex XSOAR multi-tenant deployment, through the API or the UI. Reindex a tenant.
- [Block and Unblock a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/block-and-unblock-a-tenant.md): Block or unblock a tenant (account) at the proxy level for Cortex XSOAR multi-tenant deployment. Troubleshoot tenant performance issues.
- [Reindex a Tenant Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/reindex-a-tenant-database.md): Reindex a tenant database in the Cortex XSOAR multi-tenant environment.
- [Back Up a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/back-up-a-tenant.md): Create a backup of a tenant account for a Cortex XSOAR multi-tenant deployment. Perform manual and automatic backups of the database.
- [Reindex a Specific Index for a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/reindex-a-specific-index-for-a-tenant.md): Reindex one or more indexes for an individual tenant in a multi-tenant deployment.
- [Restore a Tenant Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/restore-a-tenant-database.md): Restore a tenant database from a manual backup or automated backup back up in Cortex XSOAR.
- [Restore a Partition for a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/restore-a-partition-for-a-tenant.md): Restore a partition for a specific tenant in a multi tenant environment
- [Index War Room Entries in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/index-war-room-entries-in-a-multi-tenant-deployment.md): Index Cortex XSOAR War Room entries to ensure that you can search for them in the Search Incidents. Re-index incidents for selected months.
- [Install Engines on Tenants in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-the-multi-tenant-deployment/install-engines-on-tenants-in-a-multi-tenant-deployment.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and server.
- [Configure User Settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/configure-user-settings.md): Cortex XSOAR users can control details, preferences, and notifications, by changing the notifications settings in their user profile.
- [Manage Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content.md): Apply propagation labels and sync content to tenant accounts in a Cortex XSOAR multi-tenant deployment.
- [Manage Content Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/manage-content-overview.md): Content is pushed from the master account to tenant accounts by applying corresponding propagation labels to content and tenant accounts.
- [Add Propagation Labels to an Existing Tenant Account](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/add-propagation-labels-to-an-existing-tenant-account.md): Add propagation labels to an existing tenant account in a Cortex XSOAR multi-tenant deployment to control which content items sync.
- [Add Propagation Labels to Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/add-propagation-labels-to-content.md): Apply propagation labels to control which content is synced from the main account to tenant accounts in a Cortex XSOAR multi-tenant deployment.
- [Add Propagation Labels in Remote Repositories](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/add-propagation-labels-in-remote-repositories.md): Add propagation labels to an existing tenant account in a Cortex XSOAR multi-tenant deployment using remote repositories, to control which content items sync.
- [Content Dependencies and Propagation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/content-dependencies-and-propagation.md): Understand how content that is dependent on other content is propagated to tenants.
- [Sync Content to Tenant Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/sync-content-to-tenant-accounts.md): Sync content to each tenant account individually or sync content to all tenants in a single operation in a Cortex XSOAR multi-tenant deployment.
- [Troubleshoot Errors When Syncing All Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/sync-content-to-tenant-accounts/troubleshoot-errors-when-syncing-all-accounts.md): Fix sync errors for large scale Cortex XSOAR multi-tenant environments by editing demisto.service file on host to limit the number of open files.
- [Disable Propagation Labels](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/disable-propagation-labels.md): Disable propagation labels and automatically sync content from the main account to tenant accounts for Cortex XSOAR multi-tenant deployment.
- [Restrict Actions for Custom Locked Content Items](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/manage-content/restrict-actions-for-custom-locked-content-items.md): Prevent users of tenant accounts from downloading, cloning and viewing codes for custom locked content items in Cortex XSOAR multi tenant deployment.
- [Share Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/share-indicators.md): Share indicators between tenant accounts in a Cortex XSOAR multi-tenant deployment.
- [Share Indicators Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/share-indicators/share-indicators-overview.md): Share indicators between tenant accounts by exporting a tenant’s indicators to a shared index and configuring tenants to ingest from shared index.
- [Manually Share Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/share-indicators/manually-share-indicators.md): Share indicators manually by sending one or more indicators from a tenant to a dedicated shard Elasticsearch index.
- [Export Indicators to the Shared Index](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/share-indicators/export-indicators-to-the-shared-index.md): The Cortex XSOAR Indicators Share integration is a dedicated integration that you configure on each tenant account to export its indicators to the shared index.
- [Ingest Indicators from the Shared Indicators Index](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/share-indicators/ingest-indicators-from-the-shared-indicators-index.md): Configure the Elasticsearch Feed integration on a tenant account to ingest indicators from the shared indexes in a Cortex XSOAR multi-tenant deployment.
- [Remote Repositories for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments.md): Configure remote repositories for Cortex XSOAR multi-tenant deployments.
- [Remote Repositories Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/remote-repositories-overview.md): Use a remote repository to develop and test content. Push content to tenants using propagation labels in a Cortex XSOAR multi-tenant deployment.
- [Configure a Remote Repository on a Development Machine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/configure-a-remote-repository-on-a-development-machine.md): Configure remote repository on development machine for Cortex XSOAR multi-tenant deployment and push content to repository. Enable selective propagation.
- [Configure a Remote Repository on the Main Account](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/configure-a-remote-repository-on-the-main-account.md): Configure development machine and production environment (main account) to work with remote repositories in a Cortex XSOAR multi-tenant deployment.
- [Edit and Push Content to a Remote Repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/edit-and-push-content-to-a-remote-repository.md): Push content to a remote repository and control access for pushing content.
- [Troubleshoot a Remote Repository Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration.md): Troubleshoot issues for a Cortex XSOAR remote repository configuration plus FAQs.
- [Troubleshoot a Remote Repository Definition](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-a-remote-repository-definition.md): Troubleshoot a remote repository definition. Remote repository error messages in Cortex XSOAR.
- [Troubleshoot Editing and Pushing Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-editing-and-pushing-content.md): Troubleshoot editing and pushing content to Cortex XSOAR remote repository.
- [Troubleshoot Content Issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-content-issues.md): Troubleshoot content issues in a remote repository. Restore content backup package to restore missing content.

* [Navigate the Multi-Tenant Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/learn-about-multi-tenant/readme.md): Start here for a visual overview of the Cortex XSOAR Multi-Tenant 6.12 documentation areas.
* [Multi-Tenant Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/learn-about-multi-tenant/multi-tenant-overview.md): Cortex XSOAR multi-tenant deployments for Managed Security Service Provider (MSSPs) and enterprises that require data segregation between tenant accounts.
* [Multi-Tenant High Availability Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/learn-about-multi-tenant/multi-tenant-high-availability-overview.md): A conceptual overview of high availability for a Cortex XSOAR multi-tenant deployment.
* [Plan Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/plan-your-multi-tenant-deployment.md): Sizing requirements and security settings for Cortex XSOAR multi-tenant deployments.
* [Multi-Tenant Sizing Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/plan-your-multi-tenant-deployment/multi-tenant-sizing-requirements.md): Sizing requirements for a Cortex XSOAR multi-tenant deployment depend on the number of hosts and tenants deployed.
* [Configure Security Settings for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/plan-your-multi-tenant-deployment/configure-security-settings-for-multi-tenant-deployments.md): Add server configurations to harden your Cortex XSOAR multi-tenant deployment. Security settings for multi-tenant deployments.
* [SAML for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/plan-your-multi-tenant-deployment/saml-for-multi-tenant-deployments.md): Authenticate Cortex XSOAR users using SAML 2.0 in a multi-tenant deployment.
* [Communication in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/plan-your-multi-tenant-deployment/communication-in-a-multi-tenant-deployment.md): Ports used in a multi-tenant deployment.
* [Change the Port for Host to Main Communication](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/plan-your-multi-tenant-deployment/change-the-port-for-host-to-main-communication.md): Set a custom port on the main account to enable communication from host to main in a multi-tenant deployment.
* [Multi-Tenant Deployment Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/multi-tenant-deployment-installation.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database or Elasticsearch. Upgrade multi-tenant deployment.
* [Install Cortex XSOAR for a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database (not Elasticsearch).
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment/installer-flags.md): List of supported flags for installing Cortex XSOAR.
* [Install Cortex XSOAR for a Multi-Tenant Deployment with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/multi-tenant-deployment-installation/install-cortex-xsoar-for-a-multi-tenant-deployment-with-elasticsearch.md): Install Cortex XSOAR for a multi-tenant deployment using an Elasticsearch database. Installer flags for multi-tenant deployment with Elasticsearch.
* [Upgrade Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/multi-tenant-deployment-installation/upgrade-your-multi-tenant-deployment.md): Upgrading a Cortex XSOAR multi-tenant deployment including preparation, upgrade and post upgrade steps.
* [Get the Host Installer Manually](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/onboard-multi-tenant/multi-tenant-deployment-installation/get-the-host-installer-manually.md): Manually get the host installer file in cases where you can’t access the Cortex XSOAR server or platform. Copy installation file and run from the host.
* [Configure the Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment.md): Configure Cortex XSOAR Multi-Tenant Deployment. Manage hosts, tenants, backups, and engines.
* [Main Account to Tenant Communication Encryption](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/main-account-to-tenant-communication-encryption.md): Configure two-way communication between main account and tenant for Cortex XSOAR Multi-Tenant deployment. Manage encryption and API keys.
* [Add a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/add-a-host.md): Add a new host server and scale out Cortex XSOAR multi-tenant deployments by spreading tenants across host servers.
* [Add a Tenant to a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/add-a-tenant-to-a-host.md): Add a new tenant (account) to a host server for Cortex XSOAR Multi-Tenant deployment. Populate tenants with users by specifying user roles.
* [Delete a Tenant From a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/delete-a-tenant-from-a-host.md): Delete a tenant from a host using options on the the Account Management page.
* [Delete a Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/delete-a-host.md): Delete a host from a Cortex XSOAR multi-tenant (MT) environment.
* [Configure Live Backup](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-live-backup.md): Configure Live Backup for an existing Cortex XSOAR multi-tenant deployment. Configure Live Backup for the main server and the host server.
* [Configure the HTTP Request Timeout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-the-http-request-timeout.md): Configure HTTP timeout for Cortex XSOAR multi-tenant deployments (main and tenant accounts). Default HTTP timeout is 30 seconds.
* [Configure the Account Timeout](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-the-account-timeout.md): If you receive an error when moving large tenant accounts, configure the account timeout.
* [Forward Server Configurations to Tenant Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/forward-server-configurations-to-tenant-accounts.md): Forward server configurations from the main account to all tenant accounts for a Cortex XSOAR multi-tenant deployment.
* [Run a Command on Multiple Tenants](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/run-a-command-on-multiple-tenants.md): Run a command on incidents residing on multiple tenants in a Cortex XSOAR multi-tenant deployment
* [Move a Tenant to a Different Host](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/move-a-tenant-to-a-different-host.md): Move a tenant to a different host in a Cortex XSOAR multi-tenant deployment. Backup the tenant first.
* [Stop and Start a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/stop-and-start-a-tenant.md): Stop and start a tenant in a Cortex XSOAR multi-tenant deployment, through the API or the UI. Reindex a tenant.
* [Block and Unblock a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/block-and-unblock-a-tenant.md): Block or unblock a tenant (account) at the proxy level for Cortex XSOAR multi-tenant deployment. Troubleshoot tenant performance issues.
* [Reindex a Tenant Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/reindex-a-tenant-database.md): Reindex a tenant database in the Cortex XSOAR multi-tenant environment.
* [Back Up a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/back-up-a-tenant.md): Create a backup of a tenant account for a Cortex XSOAR multi-tenant deployment. Perform manual and automatic backups of the database.
* [Reindex a Specific Index for a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/reindex-a-specific-index-for-a-tenant.md): Reindex one or more indexes for an individual tenant in a multi-tenant deployment.
* [Restore a Tenant Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/restore-a-tenant-database.md): Restore a tenant database from a manual backup or automated backup back up in Cortex XSOAR.
* [Restore a Partition for a Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/restore-a-partition-for-a-tenant.md): Restore a partition for a specific tenant in a multi tenant environment
* [Index War Room Entries in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/index-war-room-entries-in-a-multi-tenant-deployment.md): Index Cortex XSOAR War Room entries to ensure that you can search for them in the Search Incidents. Re-index incidents for selected months.
* [Install Engines on Tenants in a Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-the-multi-tenant-deployment/install-engines-on-tenants-in-a-multi-tenant-deployment.md): Install engines on tenants in a Cortex XSOAR multi-tenant deployment. Configure firewall to allow communication between engine and server.
* [Configure User Settings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/configure-user-settings.md): Cortex XSOAR users can control details, preferences, and notifications, by changing the notifications settings in their user profile.
* [Manage Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content.md): Apply propagation labels and sync content to tenant accounts in a Cortex XSOAR multi-tenant deployment.
* [Manage Content Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/manage-content-overview.md): Content is pushed from the master account to tenant accounts by applying corresponding propagation labels to content and tenant accounts.
* [Add Propagation Labels to an Existing Tenant Account](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/add-propagation-labels-to-an-existing-tenant-account.md): Add propagation labels to an existing tenant account in a Cortex XSOAR multi-tenant deployment to control which content items sync.
* [Add Propagation Labels to Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/add-propagation-labels-to-content.md): Apply propagation labels to control which content is synced from the main account to tenant accounts in a Cortex XSOAR multi-tenant deployment.
* [Add Propagation Labels in Remote Repositories](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/add-propagation-labels-in-remote-repositories.md): Add propagation labels to an existing tenant account in a Cortex XSOAR multi-tenant deployment using remote repositories, to control which content items sync.
* [Content Dependencies and Propagation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/content-dependencies-and-propagation.md): Understand how content that is dependent on other content is propagated to tenants.
* [Sync Content to Tenant Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/sync-content-to-tenant-accounts.md): Sync content to each tenant account individually or sync content to all tenants in a single operation in a Cortex XSOAR multi-tenant deployment.
* [Troubleshoot Errors When Syncing All Accounts](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/sync-content-to-tenant-accounts/troubleshoot-errors-when-syncing-all-accounts.md): Fix sync errors for large scale Cortex XSOAR multi-tenant environments by editing demisto.service file on host to limit the number of open files.
* [Disable Propagation Labels](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/disable-propagation-labels.md): Disable propagation labels and automatically sync content from the main account to tenant accounts for Cortex XSOAR multi-tenant deployment.
* [Restrict Actions for Custom Locked Content Items](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/manage-content/restrict-actions-for-custom-locked-content-items.md): Prevent users of tenant accounts from downloading, cloning and viewing codes for custom locked content items in Cortex XSOAR multi tenant deployment.
* [Share Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/share-indicators.md): Share indicators between tenant accounts in a Cortex XSOAR multi-tenant deployment.
* [Share Indicators Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/share-indicators/share-indicators-overview.md): Share indicators between tenant accounts by exporting a tenant’s indicators to a shared index and configuring tenants to ingest from shared index.
* [Manually Share Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/share-indicators/manually-share-indicators.md): Share indicators manually by sending one or more indicators from a tenant to a dedicated shard Elasticsearch index.
* [Export Indicators to the Shared Index](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/share-indicators/export-indicators-to-the-shared-index.md): The Cortex XSOAR Indicators Share integration is a dedicated integration that you configure on each tenant account to export its indicators to the shared index.
* [Ingest Indicators from the Shared Indicators Index](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/share-indicators/ingest-indicators-from-the-shared-indicators-index.md): Configure the Elasticsearch Feed integration on a tenant account to ingest indicators from the shared indexes in a Cortex XSOAR multi-tenant deployment.
* [Remote Repositories for Multi-Tenant Deployments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments.md): Configure remote repositories for Cortex XSOAR multi-tenant deployments.
* [Remote Repositories Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/remote-repositories-overview.md): Use a remote repository to develop and test content. Push content to tenants using propagation labels in a Cortex XSOAR multi-tenant deployment.
* [Configure a Remote Repository on a Development Machine](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/configure-a-remote-repository-on-a-development-machine.md): Configure remote repository on development machine for Cortex XSOAR multi-tenant deployment and push content to repository. Enable selective propagation.
* [Configure a Remote Repository on the Main Account](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/configure-a-remote-repository-on-the-main-account.md): Configure development machine and production environment (main account) to work with remote repositories in a Cortex XSOAR multi-tenant deployment.
* [Edit and Push Content to a Remote Repository](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/edit-and-push-content-to-a-remote-repository.md): Push content to a remote repository and control access for pushing content.
* [Troubleshoot a Remote Repository Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration.md): Troubleshoot issues for a Cortex XSOAR remote repository configuration plus FAQs.
* [Troubleshoot a Remote Repository Definition](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-a-remote-repository-definition.md): Troubleshoot a remote repository definition. Remote repository error messages in Cortex XSOAR.
* [Troubleshoot Editing and Pushing Content](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-editing-and-pushing-content.md): Troubleshoot editing and pushing content to Cortex XSOAR remote repository.
* [Troubleshoot Content Issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.12/configure-multi-tenant/remote-repositories-for-multi-tenant-deployments/troubleshoot-a-remote-repository-configuration/troubleshoot-content-issues.md): Troubleshoot content issues in a remote repository. Restore content backup package to restore missing content.

## Cortex XSOAR 6 Installation Guides

- [Cortex XSOAR Installation Guides](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/cortex-xsoar-installation-guides.md): Start here to choose the right Cortex XSOAR 6 version.

* [Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/readme.md): Installation for single server deployments and for multi-tenant deployments.
* [Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/readme/installation-overview.md): Overview of installation process for Cortex XSOAR, including single server, multi-tenant, BoltDB, Elasticsearch, and Elasticsearch with high availability.
* [Single Server Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/readme/single-server-installation-overview.md): Single server deployment overview with Bolt database, with Elasticsearch database, and with high availability.
* [Multi-Tenant Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/readme/multi-tenant-installation-overview.md): Multi-tenant installation overview with Bolt database, with Elasticsearch database and with high availability.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements.md): System requirements for installing Cortex XSOAR.
* [Cortex XSOAR System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/cortex-xsoar-system-requirements.md): Cortex XSOAR system requirements - operating system, hardware, Docker/Podman, etc.
* [Multi-Tenant System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/multi-tenant-system-requirements.md): Multi-tenant server requirements and examples.
* [Elasticsearch System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/elasticsearch-system-requirements.md): Review requirements for implementing Cortex XSOAR with Elasticsearch. Each option has specific sizing requirements.
* [Supported Web Browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/supported-web-browsers.md): Supported web browsers for Cortex XSOAR.
* [Cloud Deployment Specifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications.md): Deployment guidelines for AWS EC2, Azure virtual machines, and GCP compute engine.
* [AWS EC2 Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/aws-ec2-deployment-guidelines.md): Technical and sizing requirements for AWS EC2 Cortex XSOAR deployment, and AWS EC2 Cortex XSOAR best practices.
* [Azure Virtual Machines Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/azure-virtual-machines-deployment-guidelines.md): Technical and sizing requirements for Azure Virtual Machine (VM) Cortex XSOAR deployment, and Azure Cortex XSOAR best practices.
* [GCP Compute Engine Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/gcp-compute-engine-deployment-guidelines.md): Technical and sizing requirements for GCP compute engine Cortex XSOAR deployment, and GCP Cortex XSOAR best practices.
* [Single Server Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation.md): Links to single server deployment.
* [Install Cortex XSOAR with Bolt Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-bolt-database.md): Installation instructions for standard Cortex XSOAR single server deployments, with the app server and database server on the same machine.
* [Troubleshooting](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-bolt-database/troubleshooting.md): Installation instructions for standard Cortex XSOAR single server deployments, with the app server and database server on the same machine.
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-bolt-database/installer-flags.md): List of supported flags for installing Cortex XSOAR.
* [Install Cortex XSOAR with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch.md): Install Cortex XSOAR with Elasticsearch.
* [Elasticsearch Configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-configurations.md): Supported Elasticsearch configurations.
* [Elasticsearch General Security Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-general-security-guidelines.md): Best practices and security guidelines for Elasticsearch for Cortex XSOAR single-instance deployments.
* [Elasticsearch Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-installation.md): Instructions for installing a single server deployment with an Elasticsearch database.
* [Elasticsearch Best Practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-best-practices.md): Outline of how Elasticsearch should be configured to work with Cortex XSOAR for high availability.
* [Install Cortex XSOAR Offline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-offline.md): Install Cortex XSOAR when you do not have internet access.
* [Dependencies for Offline Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-offline/dependencies-for-offline-installation.md): Dependencies required when installing Cortex XSOAR with no internet connection for CentOS, Red Hat, Ubuntu and Debian operating systems.
* [Uninstall the Server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/single-server-installation/uninstall-the-server.md): Uninstall Cortex XSOAR. Configuration files and files created by engines are not removed.
* [Multi-Tenant Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/multi-tenant-installation.md): Planning your Multi-Tenant installation.
* [Install Multi-Tenant with Bolt Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-bolt-database.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database (not Elasticsearch).
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-bolt-database/installer-flags.md): List of supported flags for installing Cortex XSOAR.
* [Install Multi-Tenant with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-elasticsearch.md): List of files and folders created during the multi-tenant installation. Instructions for installing a Cortex XSOAR multi-tenant with Elasticsearch.
* [Post Installation Checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/post-installation-checklist.md): Use the Post installation checklist to monitor components and check that everything runs correctly.
* [Add a License](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/post-installation-checklist/add-a-license.md): Add Cortex XSOAR license file, either through the UI or by saving the license file directly on the server.
* [Server Post-Installation Health Check](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/post-installation-checklist/server-post-installation-health-check.md): Run Cortex XSOAR server post-installation health checks for Docker, integrations, commands, playground, reporting, and content.
* [Monitor Cortex XSOAR Components](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/post-installation-checklist/monitor-cortex-xsoar-components.md): Monitor Cortex XSOAR system components.
* [Upgrade Your Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/upgrade-your-installation.md): Upgrade a single server deployment, multi-tenant deployment, or a live backup environment.
* [Upgrade the Cortex XSOAR Server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-the-cortex-xsoar-server.md): Upgrade your Cortex XSOAR server.
* [Upgrade Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-your-multi-tenant-deployment.md): Upgrading a Cortex XSOAR multi-tenant deployment including preparation, upgrade, and post-upgrade steps.
* [Upgrade the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-the-live-backup-environment.md): Upgrade your live backup environment for Cortex XSOAR.

- [Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/readme.md): Installation for single server deployments and for multi-tenant deployments.
- [Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/readme/installation-overview.md): Overview of installation process for Cortex XSOAR, including single server, multi-tenant, BoltDB, Elasticsearch, and Elasticsearch with high availability.
- [Single Server Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/readme/single-server-installation-overview.md): Single server deployment overview with Bolt database, with Elasticsearch database, and with high availability.
- [Multi-Tenant Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/readme/multi-tenant-installation-overview.md): Multi-tenant installation overview with Bolt database, with Elasticsearch database and with high availability.
- [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements.md): System requirements for installing Cortex XSOAR.
- [Cortex XSOAR System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/cortex-xsoar-system-requirements.md): Cortex XSOAR system requirements - operating system, hardware, Docker/Podman, etc.
- [Multi-Tenant System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/multi-tenant-system-requirements.md): Multi-tenant server requirements and examples.
- [Elasticsearch System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/elasticsearch-system-requirements.md): Review requirements for implementing Cortex XSOAR with Elasticsearch. Each option has specific sizing requirements.
- [Supported Web Browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/supported-web-browsers.md): Supported web browsers for Cortex XSOAR.
- [Cloud Deployment Specifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications.md): Deployment guidelines for AWS EC2, Azure virtual machines, and GCP compute engine.
- [AWS EC2 Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/aws-ec2-deployment-guidelines.md): Technical and sizing requirements for AWS EC2 Cortex XSOAR deployment, and AWS EC2 Cortex XSOAR best practices.
- [Azure Virtual Machines Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/azure-virtual-machines-deployment-guidelines.md): Technical and sizing requirements for Azure Virtual Machine (VM) Cortex XSOAR deployment, and Azure Cortex XSOAR best practices.
- [GCP Compute Engine Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/gcp-compute-engine-deployment-guidelines.md): Technical and sizing requirements for GCP compute engine Cortex XSOAR deployment, and GCP Cortex XSOAR best practices.
- [Single Server Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation.md): Links to single server deployment.
- [Install Cortex XSOAR with Bolt Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-bolt-database.md): Installation instructions for standard Cortex XSOAR single server deployments, with the app server and database server on the same machine.
- [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-bolt-database/installer-flags.md): List of supported flags for installing Cortex XSOAR.
- [Install Cortex XSOAR with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch.md): Install Cortex XSOAR with Elasticsearch.
- [Elasticsearch Configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-configurations.md): Supported Elasticsearch configurations.
- [Elasticsearch General Security Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-general-security-guidelines.md): Best practices and security guidelines for Elasticsearch for Cortex XSOAR single-instance deployments.
- [Elasticsearch Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-installation.md): Instructions for installing a single server deployment with an Elasticsearch database.
- [Elasticsearch Best Practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-best-practices.md): Outline of how Elasticsearch should be configured to work with Cortex XSOAR for high availability.
- [Install Cortex XSOAR Offline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-offline.md): Install Cortex XSOAR when you do not have internet access.
- [Dependencies for Offline Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-offline/dependencies-for-offline-installation.md): Dependencies required when installing Cortex XSOAR with no internet connection for CentOS, Red Hat, Ubuntu and Debian operating systems.
- [Uninstall the Server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/single-server-installation/uninstall-the-server.md): Uninstall Cortex XSOAR. Configuration files and files created by engines are not removed.
- [Multi-Tenant Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/multi-tenant-installation.md): Planning your Multi-Tenant installation.
- [Install Multi-Tenant with Bolt Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-bolt-database.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database (not Elasticsearch).
- [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-bolt-database/installer-flags.md): List of supported flags for installing Cortex XSOAR.
- [Install Multi-Tenant with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-elasticsearch.md): List of files and folders created during the multi-tenant installation. Instructions for installing a Cortex XSOAR multi-tenant with Elasticsearch.
- [Post Installation Checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/post-installation-checklist.md): Use the Post installation checklist to monitor components and check that everything runs correctly.
- [Add a License](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/post-installation-checklist/add-a-license.md): Add Cortex XSOAR license file, either through the UI or by saving the license file directly on the server.
- [Server Post-Installation Health Check](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/post-installation-checklist/server-post-installation-health-check.md): Run Cortex XSOAR server post-installation health checks for Docker, integrations, commands, playground, reporting, and content.
- [Monitor Cortex XSOAR Components](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/post-installation-checklist/monitor-cortex-xsoar-components.md): Monitor Cortex XSOAR system components.
- [Upgrade Your Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/upgrade-your-installation.md): Upgrade a single server deployment, multi-tenant deployment, or a live backup environment.
- [Upgrade the Cortex XSOAR Server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-the-cortex-xsoar-server.md): Upgrade your Cortex XSOAR server.
- [Upgrade Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-your-multi-tenant-deployment.md): Upgrading a Cortex XSOAR multi-tenant deployment including preparation, upgrade, and post-upgrade steps.
- [Upgrade the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-the-live-backup-environment.md): Upgrade your live backup environment for Cortex XSOAR.

* [Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/readme.md): Installation for single server deployments and for multi-tenant deployments.
* [Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/readme/installation-overview.md): Overview of installation process for Cortex XSOAR, including single server, multi-tenant, BoltDB, Elasticsearch, and Elasticsearch with high availability.
* [Single Server Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/readme/single-server-installation-overview.md): Single server deployment overview with Bolt database, with Elasticsearch database, and with high availability.
* [Multi-Tenant Installation Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/readme/multi-tenant-installation-overview.md): Multi-tenant installation overview with Bolt database, with Elasticsearch database and with high availability.
* [System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements.md): System requirements for installing Cortex XSOAR.
* [Cortex XSOAR System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/cortex-xsoar-system-requirements.md): Cortex XSOAR system requirements - operating system, hardware, Docker/Podman, etc.
* [Multi-Tenant System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/multi-tenant-system-requirements.md): Multi-tenant server requirements and examples.
* [Elasticsearch System Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/elasticsearch-system-requirements.md): Review requirements for implementing Cortex XSOAR with Elasticsearch. Each option has specific sizing requirements.
* [Supported Web Browsers](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/supported-web-browsers.md): Supported web browsers for Cortex XSOAR.
* [Cloud Deployment Specifications](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications.md): Deployment guidelines for AWS EC2, Azure virtual machines, and GCP compute engine.
* [AWS EC2 Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/aws-ec2-deployment-guidelines.md): Technical and sizing requirements for AWS EC2 Cortex XSOAR deployment, and AWS EC2 Cortex XSOAR best practices.
* [Azure Virtual Machines Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/azure-virtual-machines-deployment-guidelines.md): Technical and sizing requirements for Azure Virtual Machine (VM) Cortex XSOAR deployment, and Azure Cortex XSOAR best practices.
* [GCP Compute Engine Deployment Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/system-requirements/cloud-deployment-specifications/gcp-compute-engine-deployment-guidelines.md): Technical and sizing requirements for GCP compute engine Cortex XSOAR deployment, and GCP Cortex XSOAR best practices.
* [Single Server Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation.md): Links to single server deployment.
* [Install Cortex XSOAR with Bolt Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-bolt-database.md): Installation instructions for standard Cortex XSOAR single server deployments, with the app server and database server on the same machine.
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-bolt-database/installer-flags.md): List of supported flags for installing Cortex XSOAR.
* [Install Cortex XSOAR with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch.md): Install Cortex XSOAR with Elasticsearch.
* [Elasticsearch Configurations](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-configurations.md): Supported Elasticsearch configurations.
* [Elasticsearch General Security Guidelines](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-general-security-guidelines.md): Best practices and security guidelines for Elasticsearch for Cortex XSOAR single-instance deployments.
* [Elasticsearch Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-installation.md): Instructions for installing a single server deployment with an Elasticsearch database.
* [Elasticsearch Best Practices](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-with-elasticsearch/elasticsearch-best-practices.md): Outline of how Elasticsearch should be configured to work with Cortex XSOAR for high availability.
* [Install Cortex XSOAR Offline](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-offline.md): Install Cortex XSOAR when you do not have internet access.
* [Dependencies for Offline Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/install-cortex-xsoar-offline/dependencies-for-offline-installation.md): Dependencies required when installing Cortex XSOAR with no internet connection for CentOS, Red Hat, Ubuntu and Debian operating systems.
* [Uninstall the Server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/single-server-installation/uninstall-the-server.md): Uninstall Cortex XSOAR. Configuration files and files created by engines are not removed.
* [Multi-Tenant Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/multi-tenant-installation.md): Planning your Multi-Tenant installation.
* [Install Multi-Tenant with Bolt Database](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-bolt-database.md): Install Cortex XSOAR for multi-tenant deployment with Bolt/Bleve database (not Elasticsearch).
* [Installer Flags](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-bolt-database/installer-flags.md): List of supported flags for installing Cortex XSOAR.
* [Install Multi-Tenant with Elasticsearch](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/multi-tenant-installation/install-multi-tenant-with-elasticsearch.md): List of files and folders created during the multi-tenant installation. Instructions for installing a Cortex XSOAR multi-tenant with Elasticsearch.
* [Post Installation Checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/post-installation-checklist.md): Use the Post installation checklist to monitor components and check that everything runs correctly.
* [Add a License](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/post-installation-checklist/add-a-license.md): Add Cortex XSOAR license file, either through the UI or by saving the license file directly on the server.
* [Server Post-Installation Health Check](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/post-installation-checklist/server-post-installation-health-check.md): Run Cortex XSOAR server post-installation health checks for Docker, integrations, commands, playground, reporting, and content.
* [Monitor Cortex XSOAR Components](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/post-installation-checklist/monitor-cortex-xsoar-components.md): Monitor Cortex XSOAR system components.
* [Upgrade Your Installation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/upgrade-your-installation.md): Upgrade a single server deployment, multi-tenant deployment, or a live backup environment.
* [Upgrade the Cortex XSOAR Server](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-the-cortex-xsoar-server.md): Upgrade your Cortex XSOAR server.
* [Upgrade Your Multi-Tenant Deployment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-your-multi-tenant-deployment.md): Upgrading a Cortex XSOAR multi-tenant deployment including preparation, upgrade, and post-upgrade steps.
* [Upgrade the Live Backup Environment](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-the-live-backup-environment.md): Upgrade your live backup environment for Cortex XSOAR.

## Playbook Design Guide

- [Playbooks](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme.md): Cortex XSOAR 6 playbooks enable you to organize and automate the security monitoring, orchestration, and response flow for your incident investigation.
- [What Are Playbooks?](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme/what-are-playbooks.md): Cortex XSOAR 6 playbooks enable you to structure and automate many of your security processes. Parse incident information, interact with users, and remediate.
- [Playbook Development](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme/playbook-development.md): Cortex XSOAR 6 playbooks enable you to structure and automate many of your security processes.
- [Configure IoT Security Playbooks](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme/configure-iot-security-playbooks.md): IoT Security playbooks in Cortex XSOAR 6 enable you to structure and automate many of your third-party security processes. Parse incident information, interact with users, and remediate.
- [Manage Playbook Settings](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/manage-playbook-settings.md): Manage Cortex XSOAR 6 playbook settings, including role access, which incident type triggers it, and options for Quiet Mode.
- [Obtain Playbook Metadata](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/manage-playbook-settings/obtain-playbook-metadata.md): Analyze Cortex XSOAR 6 playbook metadata for troubleshooting custom playbooks. Use the getInvPlaybookMetaData command.
- [Version Control](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/version-control.md): Save versions of your playbook in Cortex XSOAR 6 as you are developing it.
- [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields.md): All of the fields available when defining a playbook task in Cortex XSOAR 6.
- [Create Section Headers](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/create-section-headers.md): Section headers tasks are used to manage the flow of your playbook in Cortex XSOAR 6 and help you organize your tasks efficiently.
- [Create a Conditional Task](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/create-a-conditional-task.md): Create a conditional task in a Cortex XSOAR 6 playbook.
- [Communication Tasks](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks.md): Communication tasks in Cortex XSOAR 6 playbooks enable you to send surveys and collect data.
- [Create an Ask Task](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/create-an-ask-task.md): Create a conditional Ask task in a playbook in Cortex XSOAR 6. An Ask task is a single question survey that determines how the playbook proceeds. Answer is recorded in context.
- [Ask Task Examples](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/create-an-ask-task/ask-task-examples.md): Examples for using the Ask task to send email messages and recurring surveys in Cortex XSOAR 6.
- [Customize an Ask Task](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/create-an-ask-task/customize-an-ask-task.md): Customize the HTML and CSS template used for Ask task messages in Cortex XSOAR 6.
- [Create a Data Collection Task](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/create-a-data-collection-task.md): Create a data collection task in a Cortex XSOAR 6 playbook. Multi-question survey (form), responses are recorded in incident’s context data.
- [Data Collection Task Examples](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/create-a-data-collection-task/data-collection-task-examples.md): Common configurations for Data Collection tasks in Cortex XSOAR 6.
- [Customize a Data Collection Task](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/create-a-data-collection-task/customize-a-data-collection-task.md): Customize the HTML and CSS used in Data Collection task messages in Cortex XSOAR 6.
- [Customize the SOC Name](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/customize-the-soc-name.md): Add a server configuration to customize the name of the security operations center (SOC) that appears in communication tasks in Cortex XSOAR 6.
- [Create Communication Task Authentication](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/communication-tasks/create-communication-task-authentication.md): Configure user authentication for a communication task in Cortex XSOAR 6.
- [Add Ad Hoc Tasks to a Work Plan](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/add-ad-hoc-tasks-to-a-work-plan.md): Add ad hoc tasks to a Work Plan in Cortex XSOAR 6 for a specific iteration of a playbook.
- [Handle Errors in a Playbook](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/handle-errors-in-a-playbook.md): When defining a task in Cortex XSOAR 6, you can decide if the playbook continues, stops, or continues on an error path.
- [Playbook Task Fields](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-task-fields/playbook-task-fields.md): All of the fields available when defining a playbook task in Cortex XSOAR 6.
- [Playbook Inputs and Outputs](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-inputs-and-outputs.md): Cortex XSOAR 6 playbooks and tasks have inputs (data from incident or integration) and outputs that can then be used as input in other tasks.
- [Task Cheat Sheet](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-inputs-and-outputs/task-cheat-sheet.md): Use the Cortex XSOAR 6 playbook task cheat sheet to quickly access system and custom fields for task inputs and outputs.
- [Extend Context](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/extend-context.md): Extend context to retrieve specific information from integrations or commands and map to fields in Cortex XSOAR 6.
- [Extend Context in a Playbook Task](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/extend-context/extend-context-in-a-playbook-task.md): Extend context to retrieve additional data from integrations or commands and map to fields. Extend context in a Cortex XSOAR 6 playbook task.
- [Extend Context using the Command Line](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/extend-context/extend-context-using-the-command-line.md): Extend context to retrieve additional data from integrations or commands and map it to fields. Extend context from the Cortex XSOAR 6 command line (CLI).
- [Filters and Transformers](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers.md): Use filters and transformers to manipulate data in Cortex XSOAR 6. Use filters and transformers in playbook tasks or when mapping an instance.
- [Create Filters and Transformers in a Playbook](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers/create-filters-and-transformers-in-a-playbook.md): Create filters and transformers in Cortex XSOAR 6 playbooks.
- [Create a Filter Example](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-example.md): Example of how to create a filter in Cortex XSOAR 6. Filter all EWS Item names with a particular extension. filters objects transformers playbooks
- [Create a Filter (Advanced) Example](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers/create-filters-and-transformers-in-a-playbook/create-a-filter-advanced-example.md): Advanced example of how to create a filter in Cortex XSOAR 6.
- [Filter Operators](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers/filter-operators.md): Use filters to extract relevant data for use elsewhere in Cortex XSOAR 6.
- [Built-in Filters](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers/filter-operators/built-in-filters.md): Description of the built-in filters available for playbook tasks in Cortex XSOAR 6.
- [Transformers Operators](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers/transformers-operators.md): Transformers enable you to transfer or render one value to another value in Cortex XSOAR 6. Description of system transformer operators.
- [Create Custom Filter and Transformer Operators](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/filters-and-transformers/create-custom-filter-and-transformer-operators.md): Create a custom filter or transformer in Cortex XSOAR 6.
- [Automations](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/automations.md): Create and edit an automation in Cortex XSOAR 6, including detach and attach, automation settings, etc.
- [Special Automation Tags](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/automations/special-automation-tags.md): Special automation tags that make an automation available to a specific area in Cortex XSOAR 6.
- [Common Scripts to use in Automations](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/automations/common-scripts-to-use-in-automations.md): Scripts in the Common Scripts content pack and the Base content pack are available to use in other scripts in Cortex XSOAR 6.
- [Configure a Sub-playbook Loop](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/configure-a-sub-playbook-loop.md): Configure a sub-playbook to run in a loop Cortex XSOAR 6.
- [Sub-Playbook Loop Example](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/configure-a-sub-playbook-loop/sub-playbook-loop-example.md): This example illustrates the use of a sub-playbook loop using the Cortex XDR Investigation and Response integration Cortex XSOAR 6.
- [Playbook Polling](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-polling.md): Cortex XSOAR 6 Generic Polling playbook enables you to periodically poll the status of a process on a remote host.
- [Create Incident Fields in a Playbook](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/create-incident-fields-in-a-playbook.md): Use the setIncident automation to set and update all system incident fields Cortex XSOAR 6.
- [Playbook Testing](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-testing.md): Test your playbook with ingested incidents Cortex XSOAR 6.
- [Debug a Playbook](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-testing/debug-a-playbook.md): Set breakpoints, conditional breakpoints, skip tasks, and input and output overrides in the Cortex XSOAR 6 playbook debugger.
- [Debugger Troubleshooting](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/playbook-testing/debugger-troubleshooting.md): Find and fix potential issues with the Cortex XSOAR 6 Playbook Debugger.
- [Best Practices](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/best-practices.md): Best practices for working with playbooks Cortex XSOAR 6.

## Tutorials

- [Tutorials](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme.md): Tutorials that provide you with step by step instructions for setting up your workflows in Cortex XSOAR, with four example use cases.
- [Ingest Incidents from a SIEM Using QRadar](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/ingest-incidents-from-a-siem-using-qradar.md): Step-by-step tutorial for ingesting and handling incidents and events from QRadar.
- [Ingest Incidents from a SIEM Using Splunk](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/ingest-incidents-from-a-siem-using-splunk.md): A step-by-step tutorial for ingesting and handling incidents and events from Splunk.
- [Set up a Phishing Incident in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/set-up-a-phishing-incident-in-cortex-xsoar.md): A tutorial that takes you through a phishing incident from the initial planning stage to investigating an incident
- [Set up a Malware Incident Using the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/set-up-a-malware-incident-using-the-deployment-wizard.md): A tutorial that takes you through a malware incident from the initial planning stage through using the Deployment Wizard to set up and on to investigating an incident.

## Python Development Quick Start Guide

- [Cortex XSOAR Platform Overview](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/readme.md): How the Cortex XSOAR platform is structured.
- [Where Cortex XSOAR Uses Python Scripts](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/readme/where-cortex-xsoar-uses-python-scripts.md): Overview of Python script use in Cortex XSOAR.
- [Cortex XSOAR Script Development Process](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/cortex-xsoar-script-development-process.md): Development flows for the different scripts.
- [Development Tools and Resources](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources.md): Development tools include Demisto class, Common Server Python class, Common Scripts content pack, Cortex XSOAR IDE and script helper, and more.
- [Cortex XSOAR Automation Scripts](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts.md): Overview of automation scripts in Cortex XSOAR.
- [Set an Incident Field](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/set-an-incident-field.md): Example automation script for setting an incident field in Cortex XSOAR.
- [Close an Investigation](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/close-an-investigation.md): Example automation script for closing an investigation in Cortex XSOAR.
- [Query the Audit Trail](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/query-the-audit-trail.md): Example automation script for using the Cortex XSOAR REST API to query the audit trail.
- [Add a Table to the Incident Layout](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/add-a-table-to-the-incident-layout.md): Example automation script for creating a new incident field of type grid (table).
- [Field Change Trigger](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/field-change-trigger.md): Create an automation that is triggered by a field change.
- [Multi-select Field Display](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/multi-select-field-display.md): Create an automation script for a display field with custom multi-select options.
- [Export Incidents to CSV](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/export-incidents-to-csv.md): Create an automation script to export incidents to CSV.
- [Apply Tags to Indicators](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/development-tools-and-resources/cortex-xsoar-automation-scripts/apply-tags-to-indicators.md): Create an automation script to apply a list of tags to found indicators.
- [Script Code Snippets](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/script-code-snippets.md): Code snippets for common automation script actions.
- [Reference](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/reference.md): Additional information on the Visual Studio Code Cortex XSOAR extension, links to developer documentation, and links to third party tools.

## Cortex XSOAR 6.x FAQs

- [Cortex XSOAR 6 FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs.md)
- [Content Feature Requests](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/content-feature-requests.md): How to submit a content feature request in Cortex XSOAR 6.
- [Customer Support Portal FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/customer-support-portal-faqs.md): CSP FAQs for Cortex products.
- [Licensing](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/licensing.md)
- [Resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/resources.md)
- [Upgrade from Cortex XSOAR 6](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/upgrade-from-cortex-xsoar-6.md)

## Cortex XSOAR 6.12 Hosted Service Guide

- [Hosted Service](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service.md): Cortex XSOAR hosted service enables you to use Cortex XSOAR without the infrastructure required for an on-premise deployment.
- [Hosted Service Overview](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/hosted-service-overview.md): Cortex XSOAR hosted service enables you to use Cortex XSOAR without the infrastructure required for an on-premise deployment.
- [Service Limits](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/service-limits.md): Hosted Service limits for incidents, indicators, storage, data retention, and CIDR rules.
- [Security and Compliance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/security-and-compliance.md): Hosted Service Security and Compliance.
- [Demarcation of Responsibility](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/demarcation-of-responsibility.md): Hosted Service demarcation of responsibility. Palo Alto Networks manages service infrastructure, client manages application.
- [Cortex XSOAR and AWS Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/cortex-xsoar-and-aws-cloud.md): Cortex XSOAR uses Amazon Web Services (AWS) for the hosted service.
- [Data Backup and Retention](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/data-backup-and-retention.md): Palo Alto Networks maintains backups of hosted Cortex XSOAR workloads.
- [Hosted Service Constraints](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/hosted-service-constraints.md): Due to security and performance factors, there are limitations to the Hosted Service.
- [Support and Maintenance](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/support-and-maintenance.md): Cortex XSOAR Hosted Service provides support and maintenance. Premium support customers have 24/7 phone support.
- [Get Notifications About Hosted Instance Availability](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/support-and-maintenance/get-notifications-about-hosted-instance-availability.md): Cortex XSOAR Hosted Service provides support and maintenance. Premium support customers have 24/7 phone support.
- [Migration to Hosted Service](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/migration-to-hosted-service.md): Migrate Cortex XSOAR from an on-prem deployment to hosted service
- [Application Logs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/application-logs.md): Access application logs for your Cortex XSOAR Hosted Service
- [Multi-Tenant for Enterprise](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/multi-tenant-for-enterprise.md): Cortex XSOAR hosted service is available for Multi-Tenant deployments for Enterprise.

## Cortex Data Security Documentation

- [What is Cortex Data Security?](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/readme.md)
- [Key features](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/key-features.md)
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/supported-web-browsers.md)
- [Use the interface](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/use-the-interface.md)
- [Understand Cortex Data Security Licenses](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses.md)
- [Data retention in Cortex Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/data-retention-in-cortex-data-security.md)
- [Data storage lifecycle](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/data-storage-lifecycle.md)
- [License allocation](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/license-allocation.md)
- [License expiration](https://cortex-docs.paloaltonetworks.com/data-security-documentation/get-started-with-cortex-data-security/understand-cortex-data-security-licenses/license-expiration.md)
- [Cortex Data Security terminology](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/cortex-data-security-terminology.md)
- [Data Security Posture Management](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-security-posture-management.md)
- [Data Detection and Response](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-detection-and-response.md)
- [AI Security Posture Management](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/ai-security-posture-management.md)
- [Data Access Governance](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-access-governance.md)
- [Supported assets in Cortex Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/supported-assets-in-cortex-data-security.md)
- [Data Classification](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification.md)
- [What is Cortex Data Classification?](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/what-is-cortex-data-classification.md)
- [How to create and validate a custom data pattern](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/how-to-create-and-validate-a-custom-data-pattern.md)
- [Custom data patterns: Guardrails and syntax guide](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/how-to-create-and-validate-a-custom-data-pattern/custom-data-patterns-guardrails-and-syntax-guide.md)
- [How to disable and enable data patterns in Data Classification](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/how-to-disable-and-enable-data-patterns-in-data-classification.md)
- [How to create and validate a custom data profile](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/how-to-create-and-validate-a-custom-data-profile.md)
- [How to disable and enable data profiles in Cortex Data Classification](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/how-to-disable-and-enable-data-profiles-in-cortex-data-classification.md)
- [How to use information protection labels in Cortex Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/how-to-use-information-protection-labels-in-cortex-data-security.md)
- [Topic classification](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/data-classification/topic-classification.md)
- [About Agentic AI & the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/data-security-documentation/agentic-ai-and-cortex-agentic-assistant/agentic-ai.md)
- [Agentic Assistant use cases](https://cortex-docs.paloaltonetworks.com/data-security-documentation/agentic-ai-and-cortex-agentic-assistant/agentic-assistant-use-cases.md)
- [Agentic Assistant security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/agentic-ai-and-cortex-agentic-assistant/agentic-assistant-security.md)
- [Data security agent](https://cortex-docs.paloaltonetworks.com/data-security-documentation/agentic-ai-and-cortex-agentic-assistant/data-security-agent.md)
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/plan-and-prepare.md)
- [Deployment checklist](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist.md)
- [Activation](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/activation.md)
- [Supported regions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/activation/supported-regions.md)
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/activation/enable-access-to-required-panw-resources.md)
- [Regional egress resources](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/activation/enable-access-to-required-panw-resources/regional-egress-resources.md)
- [Engines IP addresses (outbound) - fix tables](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/activation/enable-access-to-required-panw-resources/engines-ip-addresses-outbound-fix-tables.md)
- [Inbound source resources - fix tables](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/activation/enable-access-to-required-panw-resources/inbound-source-resources-fix-tables.md)
- [FedRAMP and the US Federal Government required resources](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/activation/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md)
- [Set up users, groups, and roles](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-users-and-roles.md): Learn how to set up users and roles in Cortex Data Security.
- [User group management](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-users-and-roles/user-group-management.md): Create and manage user groups, roles, and scopes.
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-users-and-roles/assign-user-roles-and-groups.md): Assign roles and group memberships to users.
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/manage-api-keys.md)
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-authentication.md): Authenticate Cortex Data Security users using SAML 2.0 or Customer Support Portal (CSP).
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate users through the Customer Support Portal.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-authentication/authenticate-users-using-sso.md): Configure SAML single sign-on for Cortex Data Security users.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta as a SAML 2.0 identity provider.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/deployment-checklist/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID as a SAML 2.0 identity provider.
- [CSP onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding.md)
- [Amazon Web Services cloud onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding.md): Follow the AWS onboarding wizard, and Cortex Data Security creates a custom authentication template to be deployed in AWS.
- [AWS security capabilities and deployment planning](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-capabilities-and-deployment-planning.md)
- [AWS resource inventory](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/aws-resource-inventory.md)
- [AWS security model and authentication](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/aws-security-model-and-authentication.md)
- [Cortex Data Security and AWS audit log collection architecture](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/cortex-cloud-and-aws-audit-log-collection-architecture.md)
- [Onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/onboard-amazon-web-services.md): Follow the AWS onboarding wizard, and Cortex Data Security creates a custom authentication template to be executed in AWS.
- [Prerequisites for onboarding AWS](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/prerequisites-for-onboarding-aws.md): Before you begin onboarding AWS, you must review the following prerequisites.
- [How to onboard Amazon Web Services](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/how-to-onboard-amazon-web-services.md): Follow the AWS onboarding wizard and Cortex Data Security creates a custom authentication template to be deployed in AWS CloudFormation.
- [Deploy the authentication template in AWS](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/deploy-the-authentication-template-in-aws.md): Learn how to deploy the Terraform or CloudFormation authentication template in Amazon Web Services.
- [Post-deployment: Custom (BYOB) and Control Tower audit log collection](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/post-deployment-custom-byob-audit-log-collection.md)
- [Grant cross-account KMS key access for Control Tower BYOB log collection](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/grant-cross-account-kms-key-access-for-control-tower-byob-log-collection.md): Learn how to configure cross-account AWS KMS key permissions for Cortex Control Tower BYOB log collection. Step-by-step guide to updating KMS key policies.
- [AWS post-deployment verification](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/amazon-web-services-cloud-onboarding/aws-post-deployment-verification.md): After you have completed the AWS onboarding wizard and you have deployed the authentication template in AWS (using CloudFormation or Terraform), verify that the deployment succeeded.
- [Microsoft Azure cloud onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding.md)
- [Onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Prerequisites for onboarding Azure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/prerequisites-for-onboarding-azure.md): Before you begin onboarding Microsoft Azure, you must review the following prerequisites.
- [How to onboard Microsoft Azure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azure.md): Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.
- [Finalize Microsoft Azure onboarding by executing the authentication template](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/finalize-microsoft-azure-onboarding-by-executing-the-authentication-template.md): Learn how to execute the authentication template file in Microsoft Azure for subscriptions, tenants, and management groups. We provide instructions both for applying the Terraform template's configura
- [Microsoft Azure offboarding overview](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview.md): This section contains the technical procedures required to safely decommission and offboard your Cortex Data Security resources in Microsoft Azure.
- [Offboard Terraform-based Azure deployments (all scopes)](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-terraform-based-azure-deployments-all-scopes.md): How to offboard all Terraform-based Microsoft Azure scopes from Cortex Data Security: A step-by-step technical guide to safely running Terraform destroy and cleaning up policy-deployed resources.
- [Offboard Azure subscription (ARM)](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-subscription-arm.md): How to offboard a Microsoft Azure subscription scope that was onboarded using ARM: A step-by-step technical guide to safely running the interactive offboarding script and cleaning up all resources.
- [Offboard Azure management group or tenant scope (ARM)](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-management-group-or-tenant-scope-arm.md): How to offboard Microsoft Azure management group or tenant scopes from Cortex Cloud: A step-by-step technical guide to safely removing all Azure resources deployed by Cortex onboarding templates.
- [Offboard Azure tenant with Entra ID only](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/microsoft-azure-cloud-onboarding/microsoft-azure-offboarding-overview/offboard-azure-tenant-with-entra-id-only.md): How to offboard a Microsoft Azure tenant onboarded with the Entra ID only option from Cortex Data Security: A step-by-step technical guide to safely removing deployed resources.
- [Google Cloud Platform cloud onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/google-cloud-platform-cloud-onboarding.md)
- [Onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/google-cloud-platform-cloud-onboarding/onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex creates a custom authentication template to be executed in GCP.
- [Prerequisites for onboarding GCP](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/google-cloud-platform-cloud-onboarding/prerequisites-for-onboarding-gcp.md): Before you begin onboarding GCP, you must review the following prerequisites.
- [How to onboard Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-google-cloud-platform.md): Follow the GCP onboarding wizard, and Cortex Data Security creates a custom authentication template to be applied in GCP.
- [Deploy the Terraform authentication template in GCP](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/google-cloud-platform-cloud-onboarding/deploy-the-terraform-authentication-template-in-gcp.md): Learn how to deploy the Terraform authentication template in Google Cloud Console.
- [Connect Google Workspace with your GCP cloud instance](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/google-cloud-platform-cloud-onboarding/connect-google-workspace-with-your-gcp-cloud-instance.md)
- [Monitor GCP resources inside service perimeters](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/google-cloud-platform-cloud-onboarding/monitor-gcp-resources-inside-service-perimeters.md): Learn how to grant authorization to Cortex Data Security to scan within your GCP service perimeter.
- [Oracle Cloud Infrastructure cloud onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding.md): Follow the Oracle Cloud Infrastructure onboarding wizard and Cortex Data Security creates a custom Terraform authentication template to be deployed in Oracle Cloud Infrastructure.
- [Onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard, and Cortex creates a custom authentication template to be executed in OCI.
- [Prerequisites for onboarding OCI](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/prerequisites-for-onboarding-oci.md): Before you begin onboarding Oracle Cloud Infrastructure, you must review the following prerequisites.
- [How to onboard Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/how-to-onboard-oracle-cloud-infrastructure.md): Follow the OCI onboarding wizard and Cortex Data Security creates a custom authentication template to be applied in OCI.
- [Deploy the Terraform authentication template in OCI](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/deploy-the-terraform-authentication-template-in-oci.md): Learn how to deploy the Terraform authentication template in Oracle Cloud Infrastructure.
- [Outpost onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding.md): Learn about outposts, which are a dedicated set of infrastructure resources that extends the reach of Cortex Data Security into your environment.
- [Outpost fundamentals and planning](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/outpost-fundamentals-and-planning.md): An outpost enables you to have security scans performed on infrastructure in a cloud account owned by you. Learn about outpost fundamentals and what to consider when planning your outpost.
- [Outpost creation workflow](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/outpost-creation-workflow.md): Learn about the creation process for an outposts, which facilitate security scanning performed on infrastructure in a cloud account owned by you.
- [Working with standard outposts](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-standard-outposts.md): Standard outposts are the recommended way to create dedicated set of infrastructure resources that extends the reach of Cortex Data Security into your environment.
- [Create a standard outpost](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-standard-outposts/create-a-standard-outpost.md): Instructions for creating a standard outpost while onboarding your CSP.
- [Working with Bringing your own Azure app (BYOA) outposts](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts.md): Using advanced settings while creating your outpost, you can deploy a Cortex Data Security Azure outpost using your own pre-created Entra ID app registration.
- [Task 1: Meet the prerequisites for Azure BYOA outposts](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-1-meet-the-prerequisites-for-azure-byoa-outposts.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page lists the prerequisites that must be met before customizing your outpost in this way.
- [Task 2: Create the app registration for the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-2-create-the-app-registration-for-the-azure-byoa-outpost.md): You can customize your own outpost for Azure by bringing your own app (BYOA). This page describes the steps for creating the app registration.
- [Task 3: Deploy the Azure BYOA outpost](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-3-deploy-the-azure-byoa-outpost.md): You can customize your own outpost by bringing your own app (BYOA). This page describes the steps for deploying the Azure BYOA outpost.
- [Task 4: Verify the BYOA outpost deployment](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/task-4-verify-the-byoa-outpost-deployment.md): You can customize your own Azure outpost by bringing your own app (BYOA). This page describes the steps for verifying your BYOA outpost deployment.
- [The shell script for Azure app registration](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/working-with-bringing-your-own-azure-app-byoa-outposts/the-shell-script-for-azure-app-registration.md)
- [Outpost troubleshooting](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/outpost-troubleshooting.md): Check here for solutions to issues that might occur while configuring, deploying, and operating outposts.
- [Outpost Cloud Service Provider (CSP) permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions.md): This page lists and explains the various roles and permissions needed for working with resources for outposts by CSP.
- [Amazon Web Services (AWS) outpost permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/amazon-web-services-aws-outpost-permissions.md): List of Amazon Web Services (AWS) permissions for use during Cortex Data Security outpost onboarding to enable continuous monitoring in your cloud environment.
- [Microsoft Azure outpost permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/microsoft-azure-outpost-permissions.md): List of Microsoft Azure provider outpost permissions for Cortex Data Security.
- [Google Cloud Platform (GCP) outpost permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/outpost-onboarding/outpost-cloud-service-provider-csp-permissions/google-cloud-platform-gcp-outpost-permissions.md): List of Google Cloud Platform (GCP) permissions for use during Cortex Data Security onboarding outposts to enable continuous monitoring in your cloud environment.
- [Manually connect a cloud instance](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/manually-connect-a-cloud-instance-fix-tables.md)
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/manage-cloud-instances.md)
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/pending-cloud-instances.md)
- [Edit your onboarded CSP configuration](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/edit-your-onboarded-csp-configuration.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/update-cloud-permissions-after-cortex-release-updates.md)
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/troubleshoot-errors-on-cloud-instances.md)
- [Introduction to Terraform for Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/introduction-to-terraform-for-cloud-service-provider-csp-onboarding.md)
- [Cloud service provider permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/cloud-service-provider-permissions.md)
- [Amazon Web Services provider permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/cloud-service-provider-permissions/amazon-web-services-provider-permissions.md)
- [Microsoft Azure provider permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/cloud-service-provider-permissions/microsoft-azure-provider-permissions.md)
- [Google Cloud Platform provider permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/cloud-service-provider-permissions/google-cloud-platform-provider-permissions.md)
- [Oracle Cloud Infrastructure provider permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/csp-onboarding/cloud-service-provider-permissions/oracle-cloud-infrastructure-provider-permissions.md)
- [DBaaS onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/dbaas-onboarding.md)
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/dbaas-onboarding/how-to-onboard-databricks.md)
- [How to onboard MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/dbaas-onboarding/how-to-onboard-mongodb-atlas.md)
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/dbaas-onboarding/how-to-onboard-snowflake.md)
- [On premise onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/on-premise-onboarding.md)
- [How to onboard on-premise assets to Cortex Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/on-premise-onboarding/how-to-onboard-on-premise-assets-to-cortex-data-security.md)
- [FedRAMP onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/fedramp-onboarding.md)
- [Cortex Data Security federal compliance](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/fedramp-onboarding/cortex-cloud-federal-compliance.md)
- [Onboarding & configuration](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/fedramp-onboarding/onboarding-and-configuration.md)
- [Limitations & supported regions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/fedramp-onboarding/limitations-and-supported-regions.md)
- [Post-onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/post-onboarding.md)
- [How to configure the scanning settings for supported services](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/post-onboarding/how-to-configure-the-scanning-settings-for-supported-services.md)
- [How to review errors in Cortex Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/post-onboarding/how-to-review-errors-in-cortex-data-security.md)
- [Cortex MCP Server](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/post-onboarding/cortex-mcp-server.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm.md)
- [What is the Broker VM?](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/what-is-the-broker-vm.md)
- [Set up and configure Broker VM](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm.md)
- [Broker VM image installations](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations.md)
- [Set up Broker VM on Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-alibaba-cloud.md)
- [Set up Broker VM on Amazon Web Services](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-amazon-web-services.md)
- [Set up Broker VM on Google Cloud Platform (GCP)](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-google-cloud-platform-gcp.md)
- [Set up Broker VM on KVM using Ubuntu](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-kvm-using-ubuntu.md)
- [Set up Broker VM on Microsoft Azure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-azure.md)
- [Set up Broker VM on Microsoft Hyper-V](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-hyper-v.md)
- [Set up Broker VM on Nutanix Hypervisor](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-nutanix-hypervisor.md)
- [Set up Broker VM on VMware ESXi using vSphere Client](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-vmware-esxi-using-vsphere-client.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets.md)
- [Manage Broker VM](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm.md)
- [Edit Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/edit-broker-vm-configuration.md)
- [Increase Broker VM storage allocated for data caching](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/increase-broker-vm-storage-allocated-for-data-caching.md)
- [Monitor Broker VM using Prometheus](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/monitor-broker-vm-using-prometheus.md)
- [Collect Broker VM Logs](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/collect-broker-vm-logs.md)
- [Upgrade Broker VM](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/upgrade-broker-vm.md)
- [Update Broker VM applets independently](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/update-broker-vm-applets-independently.md)
- [Import Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/import-broker-vm-configuration.md)
- [Open Live Terminal](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/open-live-terminal.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/add-broker-vm-to-cluster.md)
- [Switchover Primary Node in Cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/switchover-primary-node-in-cluster.md)
- [Remove from Cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm/remove-from-cluster.md)
- [Manage Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/manage-broker-vm-data-collector-applets.md)
- [Broker VM High Availability Cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster.md)
- [Configure High Availability Cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/configure-high-availability-cluster.md)
- [Manage Broker VM clusters](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters.md)
- [View cluster details](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/view-cluster-details.md)
- [Edit cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/edit-cluster.md)
- [Add applet to cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-applet-to-cluster.md)
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-broker-vm-to-cluster.md)
- [Remove cluster](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/remove-cluster.md)
- [Broker VM notifications](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/broker-vm-notifications.md)
- [Monitor Broker VM activity](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/monitor-broker-vm-activity.md)
- [Troubleshoot Broker VM applet errors](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/broker-vm/troubleshoot-broker-vm-applet-errors.md)
- [Dataset management](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period-based retention.
- [What are datasets?](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/dataset-management/what-are-datasets.md): Learn how to import, delete, and interact with custom or third-party datasets in Cortex Data Security.
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/dataset-management/lookup-datasets.md): Learn more about lookup datasets to correlate data from a data source with events in your environment.
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/dataset-management/lookup-datasets/import-a-lookup-dataset.md)
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/dataset-management/lookup-datasets/download-json-file-of-lookup-dataset.md)
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/dataset-management/lookup-datasets/set-time-to-live-for-lookup-datasets.md)
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md): Learn more about the monitored Cortex Data Security datasets and dataset views activities.
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/manage-compute-units.md): Learn more about managing and tracking your compute units usage for API and Cold Storage XQL queries.
- [Compute units usage](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-management/manage-compute-units/compute-units-usage.md): Learn more about how to compute units CU) works according to your license and available options after reaching your quota.
- [What are Cortex Data Security data sources and connectors?](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/what-are-cortex-cloud-data-sources.md): Learn more about Cortex Data Security data sources and connectors with a unified approach to integrations.
- [Complete data source and connector catalog](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/complete-data-source-catalog.md): Learn more about the complete data source and connector catalog available in Cortex Data Security.
- [Vendor-specific data sources and connectors](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources.md)
- [Amazon](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/amazon.md)
- [Amazon Web Services](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/amazon/amazon-web-services.md)
- [Anthropic](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/anthropic.md)
- [Claude](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/anthropic/claude.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/atlassian.md)
- [Atlassian](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/atlassian/atlassian.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/databricks.md)
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/databricks/how-to-onboard-databricks.md)
- [Databricks](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/databricks/databricks.md)
- [Google](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/google.md)
- [Google Workspace](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace.md)
- [Ingest logs and data from Google Workspace](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace/ingest-logs-and-data-from-google-workspace.md)
- [Google Workspace connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/google/google-workspace/google-workspace-connector.md)
- [Microsoft](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft.md)
- [Microsoft Azure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-azure.md)
- [Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-entra-id.md)
- [Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365.md)
- [Ingest logs from Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365/ingest-logs-from-microsoft-office-365.md)
- [Microsoft 365 (new)](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365/microsoft-365-new.md)
- [Create a Microsoft Entra ID](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365/microsoft-365-new/create-a-microsoft-entra-id.md)
- [Microsoft365 (legacy)](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365/microsoft365-legacy.md)
- [Migrate to new Microsoft 365 connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-office-365/microsoft365-legacy/migrate-to-new-microsoft-365-connector.md)
- [Microsoft Teams](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/microsoft/microsoft-teams.md)
- [MongoDB](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/mongodb.md)
- [How to onboard MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/mongodb/how-to-onboard-mongodb-atlas.md)
- [MongoDB Atlas](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/mongodb/mongodb-atlas.md)
- [Oracle](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/oracle.md)
- [Oracle Cloud Infrastructure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/oracle/oracle-cloud-infrastructure.md)
- [Salesforce](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/salesforce.md)
- [Ingest logs and data from Salesforce](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/salesforce/ingest-logs-and-data-from-salesforce.md)
- [Salesforce connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/salesforce/ingest-and-run-salesforce-automation-and-remediation.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/servicenow.md)
- [ServiceNow](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/servicenow/servicenow.md)
- [Slack](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/slack.md)
- [Slack Enterprise](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/slack/slack-enterprise.md)
- [Snowflake](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/snowflake.md)
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/vendor-specific-data-sources/snowflake/how-to-onboard-snowflake.md)
- [Connectors](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/connectors.md)
- [Standard data sources](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/standard-data-sources.md)
- [Cloud service provider (CSP) onboarding](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-service-provider-csp-onboarding.md): Learn about onboarding your cloud service provider to Cortex Data Security.
- [Generic on-premise data collectors](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/generic-on-premise-data-collectors.md)
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets.md)
- [Activate DSPM Fileshare](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-fileshare.md)
- [Activate Registry Scanner](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-registry-scanner.md)
- [Activate Transporter](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter.md)
- [Cloud Posture and Runtime Security data sources](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources.md): Learn more about the Cloud Posture and Runtime Security data sources in Cortex Cloud.
- [How to onboard Databricks](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-databricks.md): How to get started with the third-party Databricks data source.
- [How to onboard on-premise assets to Cortex Cloud Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-on-premise-assets-to-cortex-cloud-data-security.md): Set up Data Security for on-premise file shares and databases using Broker VM.
- [How to onboard Microsoft 365](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-microsoft-365.md): How to get started with the Microsoft 365 data source.
- [Ingest logs and data from Okta](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/ingest-logs-and-data-from-okta.md): Learn more about Ingesting logs and data from Okta for use in Cortex Cloud.
- [How to onboard Snowflake](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/how-to-onboard-snowflake.md): How to get started with the third-party Snowflake data source.
- [Container Registries](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning.md)
- [Registry Components](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/registry-components.md)
- [How Container Registry Scanning Works](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/how-container-registry-scanning-works.md)
- [Configure registry scanning for cloud accounts](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/configure-registry-scanning-for-cloud-accounts.md)
- [Modify the container registry scanning scope](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/modify-the-container-registry-scanning-scope.md)
- [Scan re-evaluation process](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/scan-re-evaluation-process.md)
- [Connect Docker Hub registry](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry.md)
- [Manage a Docker Hub connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-hub-registry/manage-a-docker-hub-connector.md)
- [Connect Docker V2 compliant container registry](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry.md)
- [Manage a Docker V2 connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-docker-v2-compliant-container-registry/manage-a-docker-v2-connector.md)
- [Connect GitLab container registry](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry.md)
- [Manage a GitLab Container Registry connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-gitlab-container-registry/manage-a-gitlab-container-registry-connector.md)
- [Connect Harbor registry](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry.md)
- [Manage a Harbor connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-harbor-registry/manage-a-harbor-connector.md)
- [Connect JFrog container registry](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry.md)
- [Manage a JFrog connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-jfrog-container-registry/manage-a-jfrog-connector.md)
- [Connect Sonatype Nexus registry](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry.md)
- [Manage a Sonatype connector](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/cloud-posture-and-runtime-security-data-sources/container-registry-scanning/connect-sonatype-nexus-registry/manage-a-sonatype-connector.md)
- [Administration and troubleshooting](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting.md): Learn more about the administration and troubleshooting of the different data collector integrations in Cortex Cloud.
- [Manage instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances.md)
- [Add a new data source or instance](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/add-a-new-data-source-or-instance.md)
- [How to configure the scanning settings for supported services](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/how-to-configure-the-scanning-settings-for-supported-services.md)
- [Manage cloud instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/manage-cloud-instances.md)
- [Update cloud permissions after Cortex release updates](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/update-cloud-permissions-after-cortex-release-updates.md)
- [Pending cloud instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/pending-cloud-instances.md)
- [Troubleshoot errors on cloud instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/troubleshoot-errors-on-cloud-instances.md)
- [Manage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/manage-instances/manage-kubernetes-connector-instances.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/integrations.md)
- [Add an integration instance](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/integrations/add-an-integration-instance.md)
- [Configure integration permissions](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/integrations/configure-integration-permissions.md)
- [Troubleshoot Integrations](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/integrations/troubleshoot-integrations.md)
- [Verify collector connectivity](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/verify-collector-connectivity.md)
- [About health issues](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues.md)
- [Investigate and resolve health issues](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues/investigate-and-resolve-health-issues.md)
- [Monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/data-security-documentation/cortex-data-security-data-sources-and-connectors/administration-and-troubleshooting/about-health-issues/monitor-data-ingestion-health.md)
- [Asset management](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/asset-management.md)
- [Data Inventory](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/asset-management/data-inventory.md)
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports.md)
- [Overview of dashboards and reports](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/overview-of-dashboards-and-reports.md)
- [Dashboard interface basics](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-interface-basics.md)
- [Dashboard types](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/overview-of-dashboards-and-reports/dashboard-types.md)
- [Report basics](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/overview-of-dashboards-and-reports/report-basics.md)
- [Widget Library](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/overview-of-dashboards-and-reports/widget-library.md)
- [Data Security dashboards](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/data-security-dashboards.md)
- [Cortex Data Security Command Center](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/data-security-dashboards/cortex-data-security-command-center.md)
- [Data Security dashboard](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/data-security-dashboards/data-security-dashboard.md)
- [Access and visibility for dashboards and reports](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/access-and-visibility-for-dashboards-and-reports.md)
- [Visibility settings](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/visibility-settings.md)
- [Access to widgets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-to-widgets.md)
- [Sharing icons](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/sharing-icons.md)
- [Access and sharing cheat sheet](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/access-and-visibility-for-dashboards-and-reports/access-and-sharing-cheat-sheet.md)
- [Manage dashboards and reports](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports.md)
- [Dashboard Manager](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/dashboard-manager.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/reports.md)
- [Duplicate dashboards and reports](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/duplicate-dashboards-and-reports.md)
- [Share custom dashboards and report templates](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/share-custom-dashboards-and-report-templates.md)
- [Change ownership to dashboards and report templates](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/change-ownership-to-dashboards-and-report-templates.md)
- [Import and export dashboards and report templates](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/import-and-export-dashboards-and-report-templates.md)
- [Configure the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/configure-the-notification-rule-for-a-failed-report.md)
- [Deleted content](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/manage-dashboards-and-reports/deleted-content.md)
- [Create dashboards](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/create-dashboards.md)
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/create-dashboards/create-a-dashboard.md)
- [Create reports](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/create-reports.md)
- [Create a report template from scratch](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/create-reports/create-a-report-template-from-scratch.md)
- [Advanced configuration](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration.md)
- [Create custom widgets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration/create-custom-widgets.md)
- [Create widgets using AI](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration/create-custom-widgets/create-widgets-using-ai.md)
- [Create XQL widgets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets.md)
- [Add parameters to a custom XQL widget](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration/create-custom-widgets/add-parameters-to-a-custom-xql-widget.md)
- [Create script-based widgets](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration/create-custom-widgets/create-script-based-widgets.md)
- [Configure global filters](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration/configure-global-filters.md)
- [Configure drilldowns](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/dashboards-and-reports/advanced-configuration/configure-drilldowns.md)
- [Cases and issues](https://cortex-docs.paloaltonetworks.com/data-security-documentation/issue-management/cases-and-issues.md)
- [Investigation and response](https://cortex-docs.paloaltonetworks.com/data-security-documentation/issue-management/investigation-and-response.md)
- [How to report a false positive in Cortex Data Classification](https://cortex-docs.paloaltonetworks.com/data-security-documentation/issue-management/how-to-report-a-false-positive-in-cortex-data-classification.md)
- [Rules and policies](https://cortex-docs.paloaltonetworks.com/data-security-documentation/advanced-tools/rules-and-policies.md)
- [XQL query language](https://cortex-docs.paloaltonetworks.com/data-security-documentation/advanced-tools/xql-query-language.md)
- [Graph search](https://cortex-docs.paloaltonetworks.com/data-security-documentation/advanced-tools/graph-search.md)

## Xpanse Expander Documentation

- [Learn about Cortex Xpanse](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse.md): Understand how Cortex Xpanse discovers and enables you to protect your attack surface.
- [What is Cortex Xpanse?](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/what-is-cortex-xpanse.md): Cortex Xpanse is a cloud-based attack surface management (ASM) platform that collects and correlates information about every device and service connected to the public internet.
- [Network mapping](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/network-mapping.md): Cortex Xpanse discovers and intelligently attributes assets to organizations using AI and human experts.
- [Scanning](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/scanning.md): Cortex Xpanse provides targeted scanning of customer networks from an attributed scanning infrastructure.
- [Scanning cadences](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/scanning/scanning-cadences.md): Cortex Xpanse scans the internet to discover new services at varying cadences depending on several factors such as port, protocol, cloud provider ranges, and customer-attributed assets.
- [Known Assets Monitoring](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/scanning/known-assets-monitoring.md): Cortex Xpanse performs targeted daily scans of known assets for customers who opt in.
- [Scanning ports and protocols](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/scanning/scanning-ports-and-protocols.md): Cortex Xpanse detects protocol-validated services on the IPv4 and IPv6 space of the internet.
- [GeoIP data collection](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/geoip-data-collection.md): Cortex Xpanse geoIP data confirms your global network distribution.
- [Cortex Xpanse use cases](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/cortex-xpanse-use-cases.md): Common use cases for protecting your attack surface with Cortex Xpanse.
- [Cortex Xpanse licenses](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/cortex-xpanse-licenses.md): Cortex Xpanse offers several different products and licenses.
- [Onboard and configure Cortex Xpanse](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse.md)
- [Onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/onboarding-checklist.md): Review these steps to deploy and onboard Cortex Xpanse.
- [Step 1: Activate Cortex Xpanse](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/step-1-activate-cortex-xpanse.md): Learn how to activate Cortex Xpanse in the Cortex Gateway.
- [Step 2: Set up users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/step-2-set-up-users-and-roles.md): Set up users, roles, groups, and user scope as part of the onboarding process.
- [Step 3: Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/step-3-set-up-authentication.md): Authenticate users through the Customer Support Portal or using SAML SSO.
- [Step 4: Provide seed data for your enhanced production map](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/step-4-provide-seed-data-for-your-enhanced-production-map.md): Provide basic information about your organization to create a more comprehensive and customized inventory of your external-facing assets.
- [Step 5: Begin asset validation and asset enrichment](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/step-5-begin-asset-validation-and-asset-enrichment.md): Validate assets in your inventory as part of the onboarding process.
- [Step 6: Configure priority integrations](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/step-6-configure-priority-integrations.md): Set up collection, automation, and outbound integrations as part of the Cortex Xpanse onboarding process.
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/post-deployment-steps.md): Configure server settings, security settings, and log forwarding.
- [Server Settings](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/post-deployment-steps/server-settings.md): Configure server settings such as keyboard shortcuts and timestamp format.
- [Security Settings](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/post-deployment-steps/security-settings.md): Configure security settings such as session expiration, user login expiration, and dashboard expiration.
- [Log Forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/post-deployment-steps/log-forwarding.md): Cortex Xpanse enables you to forward alerts, management audit logs, and reports to external applications.
- [Configure Cortex Xpanse](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/onboard-and-configure-cortex-xpanse/configure-cortex-xpanse.md): Configure attack surface rules, risk scoring, dashboards, and other customizable features to match your use cases.
- [Users and roles](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles.md): Learn how to configure and manage users, roles, and user groups. Assign roles and set up authentication for users.
- [Manage Users](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/manage-users.md): Manage users and user permissions in the Access Management section of Cortex Xpanse.
- [Manage Roles](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/manage-roles.md): Cortex Xpanse enables you to manage roles in the Access Management console.
- [Predefined User Roles](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/manage-roles/predefined-user-roles.md): Use predefined roles to easily assign View and Edit permissions to Expander users.
- [Manage User Groups](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/manage-user-groups.md): User groups enable you to define a common role and scope for multiple users at once in a Cortex Xpanse tenant.
- [Manage User Scope](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/manage-user-scope.md): Use tags and business units to restrict user access to data in Expander.
- [User authentication](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/user-authentication.md): Authenticate Cortex Xpanse users using SAML 2.0 or the Cortex Gateway.
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/user-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate Cortex Xpanse users when using the Customer Support portal.
- [Authenticate users through the Cortex Xpanse tenant using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/user-authentication/authenticate-users-through-the-cortex-xpanse-tenant-using-sso.md): Set up authentication in the Cortex Xpanse tenant using SSO.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/user-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Use Okta to authenticate your Cortex Xpanse users.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/user-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Use Microsoft Entra ID to authenticate your Cortex Xpanse users.
- [Use Multiple SAML 2.0 Providers](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/user-authentication/use-multiple-saml-2.0-providers.md): Configure multiple SAML SSO providers and route users to the correct identity provider by email domain.
- [Troubleshoot SAML 2.0 Issues](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/users-and-roles/user-authentication/troubleshoot-saml-2.0-issues.md): Resolve common SAML 2.0 authentication issues, including IdP configuration, attribute mapping, and group mapping errors.
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period-based retention.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports.md): Create or modify dashboards and reports, schedule automated reports for recurring needs, and design custom widgets to suit your visualization goals.
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/dashboards.md): Cortex Xpanse provides a comprehensive set of predefined dashboards and the ability to create custom dashboards.
- [Predefined dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/dashboards/predefined-dashboards.md)
- [Create a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/dashboards/create-a-dashboard.md): Create custom Cortex Xpanse dashboards to display information that is most relevant to your organization.
- [Manage dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/dashboards/manage-dashboards.md): From Dashboards Manager, you can delete, edit, disable, and perform additional management actions on your dashboards.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/reports.md): Overview of Cortex Xpanse reports and how to create, edit, and download them.
- [Report templates](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/reports/report-templates.md)
- [Run a Report](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/reports/run-a-report.md): Run reports and download them in PDF format.
- [Create a report based on a dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/reports/create-a-report-based-on-a-dashboard.md): Create a report based on any dashboard in Cortex Xpanse.
- [Create a new report](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/reports/create-a-new-report.md): Create a new report template from scratch or by modifying an existing report template.
- [Create the notification rule for a failed report](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/reports/create-the-notification-rule-for-a-failed-report.md): You can receive an email notification if a report fails to run.
- [Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/dashboards-and-reports/widget-library.md): Create, search, and view custom widgets in Cortex Xpanse, or use predefined widgets.
- [Attack surface rules](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-rules.md): Cortex Xpanse attack surface rules can be customized for your organization's specific needs and priorities.
- [Customize risk scoring](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/customize-risk-scoring.md): Create custom risk-scoring rules or manually assign risk scores to prioritize incidents based on your organization's unique requirements.
- [Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations.md): Cortex Xpanse integrates with third-party tools and services to support many use cases.
- [Ingest Cloud Resources from Prisma Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/ingest-cloud-resources-from-prisma-cloud.md): Cortex Xpanse supports an integration with Prisma Cloud.
- [Generate an API Access Key in Prisma Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/ingest-cloud-resources-from-prisma-cloud/generate-an-api-access-key-in-prisma-cloud.md): Steps for generating an API access key in Prisma Cloud to use in the API integration with Cortex Xpanse.
- [Configure the Prisma Cloud Integration in Cortex Xpanse](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/ingest-cloud-resources-from-prisma-cloud/configure-the-prisma-cloud-integration-in-cortex-xpanse.md): Enable Cortex Xpanse to ingest Prisma Cloud data.
- [Prisma Cloud resource types](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/ingest-cloud-resources-from-prisma-cloud/prisma-cloud-resource-types.md): Review cloud resource types ingested from Prisma Cloud CSPM through the Cortex Xpanse cloud integration.
- [Configure Collection Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/configure-collection-integrations.md): Configure Cortex Xpanse collection integrations to ingest cloud assets from third-party sources.
- [Ingest Cloud Assets from AWS](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/configure-collection-integrations/ingest-cloud-assets-from-aws.md): Extend Cortex Xpanse visibility into cloud assets from AWS.
- [Ingest Cloud Assets from Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/configure-collection-integrations/ingest-cloud-assets-from-google-cloud-platform.md): Extend Cortex Xpanse visibility into cloud assets from Google Cloud Platform.
- [Ingest Cloud Assets from Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/configure-collection-integrations/ingest-cloud-assets-from-microsoft-azure.md): Extend Cortex Xpanse visibility into cloud assets from Microsoft Azure.
- [Generate an API Key](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations/generate-an-api-key.md): Before using the Expander API, generate an API Key and collect the API Key ID and FQDN.
- [Security rating](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/security-rating.md): The Cortex Xpanse Security Rating represents the overall hygiene of an organization’s external-facing attack surface and the risk of a breach originating from external-facing assets.
- [Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory.md): Access a comprehensive inventory of all the assets Cortex Xpanse has attributed to your organization.
- [Asset Types](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types.md): Explore the asset types available in the Cortex Xpanse Inventory.
- [Domains](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/domains.md): Cortex Xpanse gets its domains and DNS data from a combination of active and passive global collection techniques.
- [Certificates](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/certificates.md): View detailed information about each certificate in your inventory.
- [Cloud Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/cloud-inventory.md): View your Cloud Inventory, which includes assets discovered through our cloud integrations and Prisma Cloud integration.
- [Owned Responsive IPs](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/owned-responsive-ips.md): Owned responsive IPs provide a single IP reference point when an active service is detected on an IPv4 or IPv6 range that has been attributed to an organization.
- [Services](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/services.md): Cortex Xpanse provides a complete inventory of all of the public internet-facing services attributed to your organization.
- [Owned IPv4 Ranges](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/owned-ipv4-ranges.md): View all the IPv4 addresses, in the form of ranges, that Cortex Xpanse has attributed to your organization.
- [Owned IPv6 Ranges](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/owned-ipv6-ranges.md): View all the IPv6 addresses that you have provided or Cortex Xpanse has attributed to your organization.
- [Websites](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-types/websites.md): Cortex Xpanse scans your public-facing websites, identifying insecure websites, web components, and technologies running on your web assets.
- [Unified Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/unified-inventory.md): View all the assets Cortex Xpanse has attributed to your organization (excluding services, websites, and IP ranges) in the Unified Inventory table.
- [Manage Business Units](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/manage-business-units.md): Cortex Xpanse defines a business unit or BU as an organizational unit that is responsible for a specific set of assets.
- [Business Unit Management for Domains and Subdomains](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/manage-business-units/business-unit-management-for-domains-and-subdomains.md): Learn how to manage business unit assignments for domains and subdomains.
- [Business Unit Management for IP Ranges](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/manage-business-units/business-unit-management-for-ip-ranges.md): Learn about business unit assignments for user-defined and system-defined IPv4 ranges.
- [Create a user-defined IPv4 range](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/manage-business-units/create-a-user-defined-ipv4-range.md): Create a new IPv4 address range and modify the business unit assignment.
- [Modify the Business Unit for an IPv4 Range](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/manage-business-units/modify-the-business-unit-for-an-ipv4-range.md): Update the BU assignment for an IPv4 address range.
- [Modify the Business Unit for an Asset](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/manage-business-units/modify-the-business-unit-for-an-asset.md): Update the business unit assignment for an asset in the context of an incident or in the Inventory.
- [Bulk business unit management](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/manage-business-units/bulk-business-unit-management.md): Bulk update business unit assignments for domains and IP ranges using a CSV file.
- [Asset Attribution](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-attribution.md): Learn about the attribution information Cortex Xpanse provides about your assets, so you know why each asset was attributed to your organization.
- [Asset Tagging](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-tagging.md): Learn about how Cortex Xpanse uses tags to support advanced data filtering, customized data, and to restrict or permit access to data.
- [Create a New Tag](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-tagging/create-a-new-tag.md): Create asset or IP range tags and optionally assign them to users and groups for scoped access.
- [Add an Existing Tag to an Asset](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-tagging/add-an-existing-tag-to-an-asset.md): Add an existing tag to one or more assets in your Inventory.
- [Remove Tags from Assets](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-tagging/remove-tags-from-assets.md): Remove tags from one or more assets.
- [Create Inventory Tag Rules](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-tagging/create-inventory-tag-rules.md): Define inventory tag rules to apply tags automatically to assets that match your rule criteria, including any new assets that are attributed to your organization.
- [Asset Notes](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/asset-notes.md): Add and manage notes for individual assets from the Inventory or an incident.
- [Upload or remove assets](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/upload-or-remove-assets.md): Adjust your inventory by adding or removing assets yourself through the Cortex Xpanse UI.
- [Upload assets](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/upload-or-remove-assets/upload-assets.md): Add assets to your inventory through the UI.
- [Remove assets](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/upload-or-remove-assets/remove-assets.md): Remove assets from your inventory through the UI.
- [Undo an asset removal](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/upload-or-remove-assets/undo-an-asset-removal.md): Restore a previously removed asset to the Cortex Xpanse inventory.
- [Investigating Assets](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/inventory/investigating-assets.md): Use filters to monitor and find potentially vulnerable assets in your Inventory
- [Incidents and alerts](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts.md): Learn about workflows and playbook-driven automation for monitoring, prioritizing, investigating, and remediating incidents and alerts.
- [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/incidents.md): Cortex Xpanse provides an Incidents table that you can use to view all the incidents reported to and surfaced from your Cortex Xpanse instance.
- [Export an incident as a PDF](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/incidents/export-an-incident-as-a-pdf.md): Export incident details as a PDF report from the Incidents page.
- [Incident Status](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/incidents/incident-status.md): Learn about each incident status.
- [Incident Starring](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/incidents/incident-starring.md): Create an incident starring configuration that categorizes and stars incidents when alerts contain attributes that you decide are important.
- [Incidents Fields](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/incidents/incidents-fields.md): You can sort, filter, and configure the fields to display in the Incidents table.
- [Risk Scoring](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/risk-scoring.md): Learn about Cortex Xpanse risk scores and how they are calculated.
- [Incident Risk Details](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/risk-scoring/incident-risk-details.md): Understand how inferred CVEs, exploit data, and risk factors contribute to an incident’s risk score.
- [Risk Factors](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/risk-scoring/risk-factors.md): Cortex Xpanse uses a set of Risk Factors when calculating incident risk scores.
- [Alerts](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/alerts.md): An alert is a potential security risk identified by Cortex Xpanse on your services and assets.
- [Alert Status](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/alerts/alert-status.md): Learn about the alert lifecycle and definition of each alert status.
- [Alert Fields](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/alerts/alert-fields.md): Review the descriptions of the fields in the Alerts table.
- [Alert exclusions](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/alerts/alert-exclusions.md): Create a rule to exclude certain criteria from raising or reopening alerts in Cortex Xpanse.
- [Export an alert as a PDF](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/incidents-and-alerts/alerts/export-an-alert-as-a-pdf.md)
- [Threat Response Center](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/threat-response-center.md): Research and respond to zero-day exploits and global threat events in the Threat Response Center.
- [Review the list of threat events](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/threat-response-center/review-the-list-of-threat-events.md): Review a curated list of zero-day exploits and global threat events on the Emerging Vulnerabilities page.
- [Research a threat event](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/threat-response-center/research-a-threat-event.md): Review detailed information about a threat event, including related alerts and incidents, in the Threat Response Center.
- [Active Response](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response.md): Automate ASM alert investigation and remediation with the Cortex Xpanse Active Response add-on module.
- [How Active Response Works](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/how-active-response-works.md): Learn how Active Response automates alert investigation, remediation, and resolution validation.
- [Active Response License](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/active-response-license.md): Review Active Response licensing options and start a 60-day free trial.
- [Set Up Active Response](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/set-up-active-response.md): Configure automation integrations and remediation path rules for Active Response.
- [Automation Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/set-up-active-response/automation-integrations.md): Automation integrations enable Active Response to enrich an alert or respond to an alert with an action, such as sending notifications or directly modifying the configuration of an asset, service, or
- [Remediation Path Rules](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/set-up-active-response/remediation-path-rules.md): Create remediation path rules to customize Active Response to automatically respond to alerts with actions that meet your business requirements.
- [Playbook Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/set-up-active-response/playbook-configuration.md): Customize the email and ticket notifications generated by the Active Response playbook.
- [Resolve Incidents with Active Response](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/resolve-incidents-with-active-response.md): Use Active Response to automate the investigation and resolution of alerts and incidents in Expander.
- [Troubleshoot Active Response](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/troubleshoot-active-response.md)
- [Automated Remediation Capabilities Matrix](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/automated-remediation-capabilities-matrix.md): Learn about the specific ASM automated remediation and enrichment capabilities and criteria.
- [Active Response FAQ](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/active-response-faq.md)
- [Engines](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines.md): Install, manage, configure, and troubleshoot engines.
- [Engines Use Case](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/engines-use-case.md): Understand engine architecture and load balancing groups.
- [Engine Installation](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/engine-installation.md): Install, deploy and configure Cortex Xpanse engines.
- [Docker](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/docker.md): Cortex Xpanse Docker installation, configuration, security, and troubleshooting guides.
- [Podman](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/podman.md): Run Podman containers instead of Docker for RHEL v8.
- [Configure Engines](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/configure-engines.md): Configure Cortex Xpanse engines to use custom certificates and notify users if engine disconnects
- [Manage Engines](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/manage-engines.md): Manage engines and load balancing groups.
- [Use an Engine in an Integration](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/use-an-engine-in-an-integration.md): Use an engine or load-balancing group of engines to fetch alerts and run commands for an integration.
- [Run a Script Using an Engine](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/run-a-script-using-an-engine.md): Run a script on an engine or load-balancing group to distribute the workload and improve performance.
- [Remove an Engine](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/remove-an-engine.md): Remove an engine by running the relevant command, depending on your operating system.
- [Troubleshoot Engines](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/engines/troubleshoot-engines.md): Troubleshoot engines by accessing logs and viewing errors.
- [Attack Surface Testing](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing.md): Attack Surface Testing runs benign exploits against your externally facing assets to confirm the presence of vulnerabilities.
- [Attack surface tests](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/attack-surface-tests.md): Attack surface tests are designed to minimize the potential impact to scanned and tested services.
- [Attack surface tests for default credentials](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/attack-surface-tests/attack-surface-tests-for-default-credentials.md): Identify default-credential attack surface tests and their non-invasive login checks.
- [Attack Surface Testing intrusivity](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/attack-surface-testing-intrusivity.md): Attack surface tests are categorized by their intrusiveness, enabling you to choose more intrusive methods to confirm specific vulnerabilities.
- [Set up Attack Surface Testing](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/set-up-attack-surface-testing.md): Set up Attack Surface Testing by verifying permissions, accepting the EULA, and selecting targets.
- [Select targets for Attack Surface Testing](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/select-targets-for-attack-surface-testing.md): Choose specific or all directly-discovered services for Attack Surface Testing.
- [View attack surface test results](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/view-attack-surface-test-results.md): Find, filter, and review Attack Surface Testing results in the Services inventory.
- [Alerts for positive attack surface test results](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/alerts-for-positive-attack-surface-test-results.md): Confirmed positive Attack Surface Testing (AST) results automatically generate alerts.
- [AST Scan Now](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/ast-scan-now.md): Trigger on-demand AST rescans from alerts to verify vulnerabilities and automatically update alert status.
- [Enable new attack surface tests by default](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/enable-new-attack-surface-tests-by-default.md): Configure which new attack surface tests will be enabled by default.
- [View attack surface tests](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/view-attack-surface-tests.md)
- [View source IP addresses for Attack Surface Testing scans](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/attack-surface-testing/view-source-ip-addresses-for-attack-surface-testing-scans.md): Locate Attack Surface Testing scan source IPs and apply recommended allow-list guidance.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference.md)
- [Cortex Xpanse Expander FedRAMP support](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/cortex-xpanse-expander-fedramp-support.md): Cortex Xpanse Expander supports features for FedRAMP Moderate and High environments.
- [Scanning activity](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/scanning-activity.md): Cortex Xpanse scanning activity on listed ranges is CFAA-compliant
- [Cortex Xpanse Product Policies](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/cortex-xpanse-product-policies.md)
- [Data Privacy](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/cortex-xpanse-product-policies/data-privacy.md): Learn where Cortex Xpanse processes and hosts data, and how long it retains it.
- [Data Retention Policy](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/cortex-xpanse-product-policies/data-retention-policy.md): Cortex Xpanse data retention policy.
- [API Use Policy](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/cortex-xpanse-product-policies/api-use-policy.md): Cortex Xpanse API Use Policy.
- [Cortex Xpanse Product Security](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/cortex-xpanse-product-policies/cortex-xpanse-product-security.md): Cortex Xpanse product security
- [Browser Support Policy](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/cortex-xpanse-product-policies/browser-support-policy.md): Cortex Xpanse Browser Support Policy
- [Management Audit Logs](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/management-audit-logs.md): View and export management audit logs in Cortex Xpanse.
- [Monitor Compliance Violations](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/monitor-compliance-violations.md): The Attack Surface Compliance Violations Dashboard helps customers better understand how the issues on their external network impact compliance controls.
- [CMMC L1-L5 Unevaluated Controls](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/monitor-compliance-violations/cmmc-l1-l5-unevaluated-controls.md): Cortex Xpanse does not make a determination regarding compliance with the listed CMMC L1-L5 controls.
- [NIST 800-53 Unevaluated Controls](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/monitor-compliance-violations/nist-800-53-unevaluated-controls.md): Cortex Xpanse does not make a determination regarding compliance with the listed NIST 800-53 controls.
- [NIST 800-171 Unevaluated Controls](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/monitor-compliance-violations/nist-800-171-unevaluated-controls.md): Cortex Xpanse does not make a determination regarding compliance with the listed NIST 800-171 controls.
- [Navigation Cheat Sheet](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/navigation-cheat-sheet.md): Cortex Xpanse provides an easy-to-use interface.
- [List View Options](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/list-view-options.md): In the Cortex Xpanse Expander, you can filter page results, manage columns and rows, and save or share the filters.
- [Search Page Results](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/list-view-options/search-page-results.md): You can search the content in the Alerts and Incidents tables.
- [Filter Page Results](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/list-view-options/filter-page-results.md)
- [Save and Share Filters](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/list-view-options/save-and-share-filters.md)
- [Manage Columns and Rows](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/list-view-options/manage-columns-and-rows.md)
- [Show or Hide Results](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/list-view-options/show-or-hide-results.md): Temporarily show or hide table results by pivoting on field values or empty values.
- [Export Results to File](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/list-view-options/export-results-to-file.md)

## Cortex XSIAM

- [Cortex XSIAM Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information.md)
- [Features introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/july-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/july-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/july-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/july-2026/changed-features.md)
- [Cortex Cloud Posture Management and Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/july-2026/cortex-cloud-posture-management-and-cortex-cloud-runtime-security.md)
- [July 20, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/july-20-2026.md)
- [May 17, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-17-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026/changed-features.md)
- [Marketplace content changes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026/marketplace-content-changes.md)
- [Cortex Cloud Posture Management and Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026/cortex-cloud-posture-management-and-cortex-cloud-runtime-security.md)
- [February 22, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-22-2026.md)
- [February 8, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-08-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-2026/changed-features.md)
- [Cortex Cloud Posture Management and Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-2026/cortex-cloud-posture-management-and-cortex-cloud-runtime-security.md)
- [Features Introduced in 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam.md)
- [December 22, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/december-22-2025.md)
- [November 23, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-23-2025.md)
- [November 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-2025/changed-features.md)
- [Marketplace content changes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-2025/marketplace-content-changes.md)
- [July 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/july-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/july-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/july-2025/feature-enhancements.md)
- [Changed features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/july-2025/changed-features.md)
- [April 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/april-2025.md)
- [Release highlights](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/april-2025/release-highlights.md)
- [Feature enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/april-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/april-2025/changed-features.md)
- [Known Issues](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/known-issues-xsiam.md)
- [Maintenance releases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases.md)
- [Broker VM 32.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases/broker-vm-32052-major.md)
- [Broker VM 31.100.2](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases/broker-vm-311002.md)
- [Broker VM 32.0.51 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases/broker-vm-32051-major.md)
- [XDR Collectors 1.5.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases/xdr-collectors-153-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases/xdr-collectors-143-major.md)
- [Cortex XDR Agent Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/cortex-xdr-agent-release-information.md)
- [Previous maintenance releases](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm.md)
- [Broker VM 31.0.58 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-31058-major.md)
- [Broker VM 31.0.57 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-31057-major.md)
- [Broker VM 30.0.63 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-30063-major.md)
- [Broker VM 30.0.61 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-30061-major.md)
- [Broker VM 30.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-30052-major.md)
- [Broker VM 29.0.77 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-29077-major.md)
- [Broker VM 29.0.71 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-29071-major.md)
- [Broker VM 28.0.99 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-28099-major.md)
- [Broker VM 28.0.96](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-28096-major.md)
- [Broker VM 27.100.18](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-2710018.md)
- [Broker VM 27.100.17](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-2710017.md)
- [Broker VM 27.0.47](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-27047-major.md)
- [Broker VM 26.100.10](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-2610010.md)
- [Broker VM 26.100.3](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-261003.md)
- [Broker VM 26.0.119](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/broker-vm/broker-vm-260119-major.md)
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-35.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-35.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-34.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-34.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-34.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-33.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-33.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major.md)
- [XDR Collectors 1.5.0 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-150-major.md)
- [Compliance standards updates](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/compliance-standards-updates.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/compliance-standards-updates/july-2026.md)
- [June 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/compliance-standards-updates/june-2026.md)
- [April 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/compliance-standards-updates/april-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/compliance-standards-updates/february-2026.md)
- [API Ingestions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/api-ingestions.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/api-ingestions/july-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/api-ingestions/may-2026.md)

## Cortex XDR 5.x

- [Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information.md)
- [Features introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/july-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/july-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/july-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/july-2026/changed-features.md)
- [Cortex Cloud Posture Management and Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/july-2026/cortex-cloud-posture-management-and-cortex-cloud-runtime-security.md)
- [July 20, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/july-20-2026.md)
- [May 17, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-17-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-2026/changed-features.md)
- [Cortex Cloud Posture Management and Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-2026/cortex-cloud-posture-management-and-cortex-cloud-runtime-security.md)
- [February 22, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/february-22-2026.md)
- [February 8, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/february-08-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/february-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/february-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/february-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/february-2026/changed-features.md)
- [Cortex Cloud Posture Management and Cortex Cloud Runtime Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/february-2026/cortex-cloud-posture-management-and-cortex-cloud-runtime-security.md)
- [Features Introduced in 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x.md)
- [December 22, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/december-22-2025.md)
- [November 23, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/november-23-2025.md)
- [November 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/november-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/november-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/november-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/november-2025/changed-features.md)
- [July 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025/changed-features.md)
- [April 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/april-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/april-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/april-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/april-2025/changed-features.md)
- [Known Issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/known-issues-xdr.md)
- [Maintenance releases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/maintenance-releases.md)
- [Broker VM 32.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/maintenance-releases/broker-vm-32052-major.md)
- [Broker VM 31.100.2](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/maintenance-releases/broker-vm-311002.md)
- [Broker VM 32.0.51 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/maintenance-releases/broker-vm-32051-major.md)
- [XDR Collectors 1.5.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/maintenance-releases/xdr-collectors-153-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/maintenance-releases/xdr-collectors-143-major.md)
- [Associated Software and Content Versions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/associated-software-and-content-versions.md)
- [Cortex XDR Agent Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/cortex-xdr-agent-release-information.md)
- [Previous maintenance releases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm.md)
- [Broker VM 31.0.58 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-31058-major.md)
- [Broker VM 31.0.57 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-31057-major.md)
- [Broker VM 30.0.63 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-30063-major.md)
- [Broker VM 30.0.61 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-30061-major.md)
- [Broker VM 30.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-30052-major.md)
- [Broker VM 29.0.77 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-29077-major.md)
- [Broker VM 29.0.71 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-29071-major.md)
- [Broker VM 28.0.99 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-28099-major.md)
- [Broker VM 28.0.96](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-28096-major.md)
- [Broker VM 27.100.18](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-2710018.md)
- [Broker VM 27.100.17](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-2710017.md)
- [Broker VM 27.0.47](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-27047-major.md)
- [Broker VM 26.100.10](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-2610010.md)
- [Broker VM 26.100.3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-261003.md)
- [Broker VM 26.0.119](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/broker-vm/broker-vm-260119-major.md)
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-51.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-51.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-50.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-50.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-50.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-43.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-43.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major.md)
- [XDR Collectors 1.5.0 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-150-major.md)
- [Compliance standards updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/compliance-standards-updates.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/compliance-standards-updates/july-2026.md)
- [June 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/compliance-standards-updates/june-2026.md)
- [April 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/compliance-standards-updates/april-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/compliance-standards-updates/february-2026.md)

## Cortex XDR 3.x

- [Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information.md)
- [Features introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/july-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/july-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/july-2026/feature-enhancements.md)
- [July 20, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/july-20-2026.md)
- [May 17, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/may-17-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/may-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/may-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/may-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/may-2026/changed-features.md)
- [February 22, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/february-22-2026.md)
- [February 8, 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/february-08-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/february-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/february-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/february-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/february-2026/changed-features.md)
- [Features Introduced in 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr.md)
- [December 22, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/december-22-2025.md)
- [November 23, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/november-23-2025.md)
- [November 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/november-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/november-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/november-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/november-2025/changed-features.md)
- [July 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/july-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/july-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/july-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/july-2025/changed-features.md)
- [April 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/april-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/april-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/april-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/april-2025/changed-features.md)
- [March 16, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/march-16-2025.md)
- [March 9, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/march-9-2025.md)
- [February 16, 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/february-16-2025.md)
- [February 2025](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/february-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/february-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/february-2025/feature-enhancements.md)
- [Features Introduced in 2024](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr.md)
- [September 2024](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/september-2024.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/september-2024/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/september-2024/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/september-2024/changed-features.md)
- [July 2024](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/july-2024.md)
- [June 2024](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/june-2024.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/june-2024/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/june-2024/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/june-2024/changed-features.md)
- [May 2024](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/may-2024.md)
- [April 2024](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/april-2024.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/april-2024/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/april-2024/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/april-2024/changed-features.md)
- [February 2024](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/february-2024.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/february-2024/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/february-2024/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/february-2024/changed-features.md)
- [Features Introduced in 2023](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2023-xdr.md)
- [October 2023](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2023-xdr/october-2023.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2023-xdr/october-2023/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2023-xdr/october-2023/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2023-xdr/october-2023/changed-features.md)
- [Maintenance Releases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)
- [Broker VM 32.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases/broker-vm-32052-major.md)
- [Broker VM 31.100.2](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases/broker-vm-311002.md)
- [Broker VM 32.0.51 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases/broker-vm-32051-major.md)
- [XDR Collectors 1.5.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases/xdr-collectors-153-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases/xdr-collectors-143-major.md)
- [Hotfix Releases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/hot-fix-releases.md)
- [Associated Software and Content Versions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/associated-software-and-content-versions.md)
- [Cortex XDR Agent Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/cortex-xdr-agent-release-information.md)
- [Known Issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/known-issues-xdr.md)
- [Previous Maintenance Releases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm.md)
- [Broker VM 31.0.58 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-31058-major.md)
- [Broker VM 31.0.57 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-31057-major.md)
- [Broker VM 30.0.63 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-30063-major.md)
- [Broker VM 30.0.61 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-30061-major.md)
- [Broker VM 30.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-30052-major.md)
- [Broker VM 29.0.77 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-29077-major.md)
- [Broker VM 29.0.71 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-29071-major.md)
- [Broker VM 28.0.99 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-28099-major.md)
- [Broker VM 28.0.96 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-28096-major.md)
- [Broker VM 27.100.18](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-2710018.md)
- [Broker VM 27.100.17](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-2710017.md)
- [Broker VM 27.0.47 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-27047-major.md)
- [Broker VM 26.100.10](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-2610010.md)
- [Broker VM 26.100.3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-261003.md)
- [Broker VM 26.0.119](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-260119.md)
- [Broker VM 26.0.116 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-260116-major.md)
- [Broker VM 25.100.4](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/broker-vm/broker-vm-251004.md)
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-318.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-318.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-317.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-317.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-317.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-316.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-316.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major.md)
- [XDR Collectors 1.5.0 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-150-major.md)
- [XDR Collectors 1.4.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-142-major.md)
- [XDR Collectors 1.4.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-141.md)

## Cortex XDR Agent Release Notes

- [Cortex XDR Agent Releases](https://cortex-docs.paloaltonetworks.com/agent-release-notes/cortex-xdr-agent-releases/readme.md)
- [Cortex XDR Hotfix Releases](https://cortex-docs.paloaltonetworks.com/agent-release-notes/cortex-xdr-agent-releases/cortex-xdr-hotfix-releases.md)
- [Cortex XDR Mobile Patch Releases](https://cortex-docs.paloaltonetworks.com/agent-release-notes/cortex-xdr-agent-releases/cortex-xdr-mobile-patch-releases.md): View the list of Cortex XDR agent releases for iOS and Android devices.
- [Cortex XDR Agent Past Releases Archive](https://cortex-docs.paloaltonetworks.com/agent-release-notes/cortex-xdr-agent-releases/cortex-xdr-agent-past-releases-archive.md)

## Cortex XDR Agent 9.x

- [Cortex XDR Agent 9.3 Release Information](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/release-information.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/release-information/feature-enhancements.md)
- [Addressed Issues](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/release-information/addressed-issues.md)
- [Known Limitations](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/release-information/known-issues.md)

* [Cortex XDR Agent 9.2 Release Information](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.2/release-information.md)
* [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.2/release-information/feature-enhancements.md)
* [Addressed Issues](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.2/release-information/addressed-issues.md)
* [Cortex XDR agent known limitations](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.2/release-information/known-issues.md)

- [Cortex XDR Agent 9.1-CE Release Information](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1-ce/cortex-xdr-agent-release-information.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1-ce/cortex-xdr-agent-release-information/feature-enhancements.md)
- [Addressed issues in Cortex XDR agent 9.1-CE](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1-ce/cortex-xdr-agent-release-information/addressed-issues-title-in-cortex-xdr-agent.md)
- [Cortex XDR agent known limitations](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1-ce/cortex-xdr-agent-release-information/cortex-xdr-agent-known-issues-91.md)

* [Cortex XDR Agent 9.1 Release Information](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1/cortex-xdr-agent-release-information.md)
* [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1/cortex-xdr-agent-release-information/feature-enhancements.md)
* [Addressed Issues](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1/cortex-xdr-agent-release-information/addressed-issues.md)
* [Addressed issues in Cortex XDR agent 9.1.1](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1/cortex-xdr-agent-release-information/addressed-issues/addressed-issues-911.md)
* [Addressed issues in Cortex XDR agent 9.1](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1/cortex-xdr-agent-release-information/addressed-issues/addressed-issues-91.md)
* [Cortex XDR agent known limitations](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1/cortex-xdr-agent-release-information/cortex-xdr-agent-known-issues-91.md)

- [Agent 9.0 Release Information](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information.md): New features, default behavior changes, and known issues in agent 9.0 release
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/feature-enhancements.md)
- [Addressed issues in agent 9.0](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/addressed-issues-in-agent-9.0.md): Addressed issues in agent 9.0 release for Windows, macOS, and Linux.
- [Addressed issues in Cortex XDR agent 9.0.1](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/addressed-issues-in-agent-9.0/addressed-issues-in-cortex-xdr-agent-9.0.1.md)
- [Addressed issues in Cortex XDR agent 9.0](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/addressed-issues-in-agent-9.0/addressed-issues-in-cortex-xdr-agent-9.0.1-1.md)
- [Cortex XDR agent known limitations](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/cortex-xdr-agent-known-limitations.md): See the list of the known limitations in Cortex XDR agent 9.0

## Cortex XDR Agent 8.x

- [Cortex XDR Agent 8.9 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/cortex-xdr-agent-8.9-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.9 release
- [Features introduced in Cortex XDR agent 8.9](https://cortex-docs.paloaltonetworks.com/8.x/cortex-xdr-agent-8.9-release-information/features-introduced-in-cortex-xdr-agent-8.9.md): Describes the new features introduced in Cortex XDR agent 8.9 releases
- [Addressed issues in Cortex XDR agent 8.9](https://cortex-docs.paloaltonetworks.com/8.x/cortex-xdr-agent-8.9-release-information/addressed-issues-in-cortex-xdr-agent-8.9.md): Addressed issues in Cortex XDR agent 8.9 release for Windows, macOS, and Linux.
- [Addressed issues in Cortex XDR agent 8.9.1](https://cortex-docs.paloaltonetworks.com/8.x/cortex-xdr-agent-8.9-release-information/addressed-issues-in-cortex-xdr-agent-8.9/addressed-issues-in-cortex-xdr-agent-8.9.1.md)
- [Addressed issues in Cortex XDR agent 8.9.0](https://cortex-docs.paloaltonetworks.com/8.x/cortex-xdr-agent-8.9-release-information/addressed-issues-in-cortex-xdr-agent-8.9/addressed-issues-in-cortex-xdr-agent-8.9.0.md): Addressed issues in Cortex XDR agent 8.9.0
- [Cortex XDR agent known limitations](https://cortex-docs.paloaltonetworks.com/8.x/cortex-xdr-agent-8.9-release-information/cortex-xdr-agent-known-limitations.md): See the list of the known limitations in Cortex XDR agent 8.9.

* [Cortex XDR Agent 8.8 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.8-eol/cortex-xdr-agent-8.8-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.8 release
* [Features introduced in Cortex XDR agent 8.8](https://cortex-docs.paloaltonetworks.com/8.x/8.8-eol/cortex-xdr-agent-8.8-release-information/features-introduced-in-cortex-xdr-agent-8.8.md): Describes the new features introduced in Cortex XDR agent 8.8 releases.
* [Addressed issues in Cortex XDR agent 8.8](https://cortex-docs.paloaltonetworks.com/8.x/8.8-eol/cortex-xdr-agent-8.8-release-information/addressed-issues-in-cortex-xdr-agent-8.8.md): Addressed issues in Cortex XDR agent 8.8 release for Windows, macOS, and Linux.
* [Addressed issues in Cortex XDR agent 8.8.1](https://cortex-docs.paloaltonetworks.com/8.x/8.8-eol/cortex-xdr-agent-8.8-release-information/addressed-issues-in-cortex-xdr-agent-8.8/addressed-issues-in-cortex-xdr-agent-8.8.1.md)
* [Addressed issues in Cortex XDR agent 8.8.0](https://cortex-docs.paloaltonetworks.com/8.x/8.8-eol/cortex-xdr-agent-8.8-release-information/addressed-issues-in-cortex-xdr-agent-8.8/addressed-issues-in-cortex-xdr-agent-8.8.0.md): Addressed issues in Cortex XDR agent 8.8 release for Windows, macOS, and Linux.
* [Cortex XDR agent known issues](https://cortex-docs.paloaltonetworks.com/8.x/8.8-eol/cortex-xdr-agent-8.8-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.8.

- [Cortex XDR agent 8.7-CE release information](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.7-CE release
- [Features introduced in Cortex XDR agent 8.7](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information/features-introduced-in-cortex-xdr-agent-8.7.md): Describes the new features introduced in Cortex XDR agent 8.7 release.
- [Windows Features](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information/features-introduced-in-cortex-xdr-agent-8.7/windows-features.md): Describes the new features introduced in Cortex XDR agent 8.7 release.
- [Addressed issues in Cortex XDR agent 8.7-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.7-ce.md): Addressed issues in Cortex XDR agent 8.7-CE release for Windows, macOS, and Linux.
- [Addressed issues in Cortex XDR agent 8.7.101-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.7-ce/addressed-issues-in-cortex-xdr-agent-8.7.101-ce.md)
- [Addressed issues in Cortex XDR agent 8.7.100-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.7-ce/addressed-issues-in-cortex-xdr-agent-8.7.100-ce.md)
- [Cortex XDR agent known issues](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.7-CE.

* [Cortex XDR agent 8.7 release information](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.7-CE release
* [Features introduced in Cortex XDR agent 8.7](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information/features-introduced-in-cortex-xdr-agent-8.7.md): Describes the new features introduced in Cortex XDR agent 8.7 releases.
* [Windows Features](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information/features-introduced-in-cortex-xdr-agent-8.7/windows-features.md): Describes the new features introduced in Cortex XDR agent 8.7 releases.
* [Addressed issues in Cortex XDR agent 8.7](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information/addressed-issues-in-cortex-xdr-agent-8.7.md): Addressed issues in Cortex XDR agent 8.7 release for Windows, macOS, and Linux.
* [Cortex XDR agent 8.7.1 HF (8.7.1.135865)](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information/addressed-issues-in-cortex-xdr-agent-8.7/cortex-xdr-agent-8.7.1-hf-8.7.1.135865.md)
* [Addressed issues in Cortex XDR agent 8.7.1](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information/addressed-issues-in-cortex-xdr-agent-8.7/addressed-issues-in-cortex-xdr-agent-8.7.1.md)
* [Addressed issues in Cortex XDR agent 8.7.0](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information/addressed-issues-in-cortex-xdr-agent-8.7/addressed-issues-in-cortex-xdr-agent-8.7.0.md)
* [Cortex XDR agent known issues](https://cortex-docs.paloaltonetworks.com/8.x/8.7-eol/cortex-xdr-agent-8.7-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.7-CE.

- [Cortex XDR agent 8.6 release information](https://cortex-docs.paloaltonetworks.com/8.x/8.6-eol/cortex-xdr-agent-8.6-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.6 release
- [Features Introduced in Cortex XDR agent 8.6](https://cortex-docs.paloaltonetworks.com/8.x/8.6-eol/cortex-xdr-agent-8.6-release-information/features-introduced-in-cortex-xdr-agent-8.6.md): Describes the new features introduced in Cortex XDR agent 8.6 release.
- [Addressed issues in Cortex XDR agent 8.6](https://cortex-docs.paloaltonetworks.com/8.x/8.6-eol/cortex-xdr-agent-8.6-release-information/addressed-issues-in-cortex-xdr-agent-8.6.md): Addressed issues in Cortex XDR agent 8.6 release for Windows, macOS, and Linux.
- [Addressed issues in Cortex XDR agent 8.6.2](https://cortex-docs.paloaltonetworks.com/8.x/8.6-eol/cortex-xdr-agent-8.6-release-information/addressed-issues-in-cortex-xdr-agent-8.6/addressed-issues-in-cortex-xdr-agent-8.6.2.md): Addressed issues in Cortex XDR agent 8.6.2 release for Windows, macOS, and Linux.
- [Addressed issues in Cortex XDR agent 8.6.1](https://cortex-docs.paloaltonetworks.com/8.x/8.6-eol/cortex-xdr-agent-8.6-release-information/addressed-issues-in-cortex-xdr-agent-8.6/addressed-issues-in-cortex-xdr-agent-8.6.1.md)
- [Addressed issues in Cortex XDR agent 8.6.0](https://cortex-docs.paloaltonetworks.com/8.x/8.6-eol/cortex-xdr-agent-8.6-release-information/addressed-issues-in-cortex-xdr-agent-8.6/addressed-issues-in-cortex-xdr-agent-8.6.0.md): Addressed issues in Cortex XDR agent 8.6 release for Windows, macOS, and Linux.
- [Cortex XDR agent known issues](https://cortex-docs.paloaltonetworks.com/8.x/8.6-eol/cortex-xdr-agent-8.6-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.6.

* [Cortex XDR Agent 8.5 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.5 release
* [Features Introduced in Cortex XDR Agent 8.5](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information/features-introduced-in-cortex-xdr-agent-8.5.md): Describes the new features introduced in Cortex XDR agent 8.5 release.
* [Addressed Issues in Cortex XDR Agent 8.5](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information/addressed-issues-in-cortex-xdr-agent-8.5.md): Addressed issues in Cortex XDR agent 8.5 release for Windows, macOS, and Linux.
* [Addressed issues in Cortex XDR agent 8.5.2](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information/addressed-issues-in-cortex-xdr-agent-8.5/addressed-issues-in-cortex-xdr-agent-8.5.2.md)
* [Addressed issues in Cortex XDR agent 8.5.1](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information/addressed-issues-in-cortex-xdr-agent-8.5/addressed-issues-in-cortex-xdr-agent-8.5.1.md): Addressed issues in Cortex XDR agent 8.5.1
* [Cortex XDR agent 8.5.0 HF (8.5.0.3639)](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information/addressed-issues-in-cortex-xdr-agent-8.5/cortex-xdr-agent-8.5.0-hf-8.5.0.3639.md)
* [Addressed issues in Cortex XDR agent 8.5.0](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information/addressed-issues-in-cortex-xdr-agent-8.5/addressed-issues-in-cortex-xdr-agent-8.5.0.md): Addressed issues in Cortex XDR agent 8.5.0
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.5-eol/cortex-xdr-agent-8.5-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.5.

- [Cortex XDR Agent 8.4 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.4-eol/cortex-xdr-agent-8.4-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.4 release
- [Features Introduced in Cortex XDR Agent 8.4](https://cortex-docs.paloaltonetworks.com/8.x/8.4-eol/cortex-xdr-agent-8.4-release-information/features-introduced-in-cortex-xdr-agent-8.4.md): Describes the new features introduced in Cortex XDR agent 8.4 releases.
- [Addressed Issues in Cortex XDR Agent 8.4](https://cortex-docs.paloaltonetworks.com/8.x/8.4-eol/cortex-xdr-agent-8.4-release-information/addressed-issues-in-cortex-xdr-agent-8.4.md): Addressed issues in Cortex XDR agent 8.4 release for Windows, macOS, and Linux.
- [Cortex XDR agent 8.4.1 HF (8.4.1.53455)](https://cortex-docs.paloaltonetworks.com/8.x/8.4-eol/cortex-xdr-agent-8.4-release-information/addressed-issues-in-cortex-xdr-agent-8.4/cortex-xdr-agent-8.4.1-hf-8.4.1.53455.md)
- [Cortex XDR agent 8.4.1 addressed issues](https://cortex-docs.paloaltonetworks.com/8.x/8.4-eol/cortex-xdr-agent-8.4-release-information/addressed-issues-in-cortex-xdr-agent-8.4/cortex-xdr-agent-8.4.1-addressed-issues.md)
- [Cortex XDR agent 8.4.0 addressed issues](https://cortex-docs.paloaltonetworks.com/8.x/8.4-eol/cortex-xdr-agent-8.4-release-information/addressed-issues-in-cortex-xdr-agent-8.4/cortex-xdr-agent-8.4.0-addressed-issues.md)
- [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.4-eol/cortex-xdr-agent-8.4-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.4.

* [Cortex XDR Agent 8.3-CE Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.3.100-CE release
* [Features Introduced in Cortex XDR Agent 8.3](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/features-introduced-in-cortex-xdr-agent-8.3.md): Describes the new features introduced in Cortex XDR agent 8.3 releases.
* [Features introduced in Cortex XDR agent 8.3](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/features-introduced-in-cortex-xdr-agent-8.3/features-introduced-in-cortex-xdr-agent-8.3.md): Describes the new features introduced in Cortex XDR agent 8.3 releases.
* [Changes to Default Behavior in Cortex XDR Agent 8.3](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/changes-to-default-behavior-in-cortex-xdr-agent-8.3.md): Changes to default behavior in Cortex XDR agent 8.3 for Windows, macOS, and Linux endpoints.
* [Addressed Issues in Cortex XDR Agent 8.3-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce.md): Addressed issues in Cortex XDR agent 8.3-CE release for Windows, macOS, and Linux.
* [Cortex XDR agent 8.3.102-CE addressed issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.102-ce-addressed-issues.md)
* [Cortex XDR agent 8.3.101-CE addressed issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.101-ce-addressed-issues.md)
* [Cortex XDR agent 8.3.100-CE HF (8.3.100.53457)](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.100-ce-hf-8.3.100.53457.md)
* [Cortex XDR agent 8.3.100-CE addressed issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.100-ce-addressed-issues.md)
* [Cortex XDR agent 8.3.0 addressed issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.0-addressed-issues.md)
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.3-CE.

- [Cortex XDR Agent 8.3 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.3 release
- [Features Introduced in Cortex XDR Agent 8.3](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/features-introduced-in-cortex-xdr-agent-8.3.md): Describes the new features introduced in Cortex XDR agent 8.3 releases.
- [Features introduced in Cortex XDR agent 8.3](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/features-introduced-in-cortex-xdr-agent-8.3/features-introduced-in-cortex-xdr-agent-8.3.md): Describes the new features introduced in Cortex XDR agent 8.3 releases.
- [Changes to Default Behavior in Cortex XDR Agent 8.3](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/changes-to-default-behavior-in-cortex-xdr-agent-8.3.md): Changes to default behavior in Cortex XDR agent 8.3 for Windows, macOS, and Linux endpoints.
- [Addressed Issues in Cortex XDR Agent 8.3](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/addressed-issues-in-cortex-xdr-agent-8.3.md): Addressed issues in Cortex XDR agent 8.3 release for Windows, macOS, and Linux.
- [Cortex XDR Agent 8.3.2 Addressed Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/addressed-issues-in-cortex-xdr-agent-8.3/cortex-xdr-agent-8.3.2-addressed-issues.md)
- [Cortex XDR Agent 8.3.1 Addressed Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/addressed-issues-in-cortex-xdr-agent-8.3/cortex-xdr-agent-8.3.1-addressed-issues.md)
- [Cortex XDR agent 8.3.0 addressed issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/addressed-issues-in-cortex-xdr-agent-8.3/cortex-xdr-agent-8.3.0-addressed-issues.md)
- [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.3-eol/cortex-xdr-agent-8.3-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.3.

* [Cortex XDR Agent 8.2 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.2-eol/cortex-xdr-agent-8.2-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.2 release.
* [Features Introduced in Cortex XDR Agent 8.2](https://cortex-docs.paloaltonetworks.com/8.x/8.2-eol/cortex-xdr-agent-8.2-release-information/features-introduced-in-cortex-xdr-agent-8.2.md): Describes the new features introduced in Cortex XDR agent 8.2 releases.
* [Features Introduced in Cortex XDR Agent 8.2.0](https://cortex-docs.paloaltonetworks.com/8.x/8.2-eol/cortex-xdr-agent-8.2-release-information/features-introduced-in-cortex-xdr-agent-8.2/features-introduced-in-cortex-xdr-agent-8.2.0.md): Describes the new features introduced in Cortex XDR agent 8.2 releases.
* [Addressed Issues in Cortex XDR Agent 8.2](https://cortex-docs.paloaltonetworks.com/8.x/8.2-eol/cortex-xdr-agent-8.2-release-information/addressed-issues-in-cortex-xdr-agent-8.2.md)
* [Changes to Default Behavior in Cortex XDR Agent 8.2](https://cortex-docs.paloaltonetworks.com/8.x/8.2-eol/cortex-xdr-agent-8.2-release-information/changes-to-default-behavior-in-cortex-xdr-agent-8.2.md): Changes to default behavior in Cortex XDR agent 8.2 for Windows, macOS, and Linux endpoints.
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.2-eol/cortex-xdr-agent-8.2-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.2.

- [Cortex XDR Agent 8.1 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.1-eol/cortex-xdr-agent-8.1-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.1 release.
- [Features Introduced in Cortex XDR Agent 8.1](https://cortex-docs.paloaltonetworks.com/8.x/8.1-eol/cortex-xdr-agent-8.1-release-information/features-introduced-in-cortex-xdr-agent-8.1.md): Describes the new features introduced in Cortex XDR agent 8.1 releases.
- [Addressed Issues in Cortex XDR Agent 8.1.x](https://cortex-docs.paloaltonetworks.com/8.x/8.1-eol/cortex-xdr-agent-8.1-release-information/addressed-issues-in-cortex-xdr-agent-8.1.x.md): Addressed issues in Cortex XDR agent 8.1 release for Windows, macOS, Linux, and iOS.
- [Changes to Default Behavior in Cortex XDR Agent 8.1](https://cortex-docs.paloaltonetworks.com/8.x/8.1-eol/cortex-xdr-agent-8.1-release-information/changes-to-default-behavior-in-cortex-xdr-agent-8.1.md): Changes to default behavior in Cortex XDR agent 8.1.
- [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.1-eol/cortex-xdr-agent-8.1-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.1.

* [Cortex XDR Agent 8.0 Release Information](https://cortex-docs.paloaltonetworks.com/8.x/8.0-eol/cortex-xdr-agent-8.0-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 8.0 release.
* [Features Introduced in Cortex XDR Agent 8.0](https://cortex-docs.paloaltonetworks.com/8.x/8.0-eol/cortex-xdr-agent-8.0-release-information/features-introduced-in-cortex-xdr-agent-8.0.md): Describes the new features introduced in Cortex XDR agent 8.0 releases.
* [Addressed Issues in Cortex XDR Agent 8.0](https://cortex-docs.paloaltonetworks.com/8.x/8.0-eol/cortex-xdr-agent-8.0-release-information/addressed-issues-in-cortex-xdr-agent-8.0.md): Addressed issues in Cortex XDR agent 8.0 release for Windows, macOS, and Linux.
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/8.x/8.0-eol/cortex-xdr-agent-8.0-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 8.0.

## Cortex XDR Agent 7.x

- [Cortex XDR Agent 7.9-CE Release Information](https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information.md): New features, default behavior changes, and known issues in Cortex XDR Agent 7.9-CE release.
- [Features Introduced in Cortex XDR Agent 7.9](https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information/features-introduced-in-cortex-xdr-agent-7.9.md)
- [Addressed Issues in Cortex XDR Agent 7.9-CE](https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information/addressed-issues-in-cortex-xdr-agent-7.9-ce.md): Addressed issues in Cortex XDR agent 7.9-CE release for Windows, macOS, iOS, and Linux.
- [Changes to Default Behavior in Cortex XDR Agent 7.9-CE](https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.9-ce.md): Changes to default behavior in Cortex XDR agent 7.9-CE for Windows, macOS, and Linux endpoints.
- [Changes to Default Behavior in Cortex XDR Agent 7.9-CE](https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.9-ce/changes-to-default-behavior-in-cortex-xdr-agent-7.9-ce.md): Changes to default behavior in Cortex XDR agent 7.9-CE for Windows, macOS, and Linux endpoints.
- [Known Issues in Cortex XDR Agent 7.9-CE](https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information/known-issues-in-cortex-xdr-agent-7.9-ce.md)

* [Cortex XDR Agent 7.9 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 7.9 release
* [Features Introduced in Cortex XDR Agent 7.9](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/features-introduced-in-cortex-xdr-agent-7.9.md)
* [Changes to Default Behavior in Cortex XDR Agent 7.9](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.9.md): Changes to default behavior in Cortex XDR agent 7.9 for Windows, macOS, and Linux endpoints.
* [Changes to Default Behavior in Cortex XDR Agent 7.9](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.9/changes-to-default-behavior-in-cortex-xdr-agent-7.9.md): Changes to default behavior in Cortex XDR agent 7.9 for Windows, macOS, and Linux endpoints.
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 7.9.
* [Addressed Issues in Cortex XDR Agent 7.9](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-in-cortex-xdr-agent-7.9.md): Addressed issues in Cortex XDR agent 7.9 release for Windows, macOS, iOS, and Linux.
* [Addressed Issues in Cortex XDR Agent 7.9.3](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-in-cortex-xdr-agent-7.9/addressed-issues-in-cortex-xdr-agent-7.9.3.md)
* [Addressed Issues in Cortex XDR Agent 7.9.2](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-in-cortex-xdr-agent-7.9/addressed-issues-in-cortex-xdr-agent-7.9.2.md)
* [Addressed Issues in Cortex XDR Agent 7.9.1](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-in-cortex-xdr-agent-7.9/addressed-issues-in-cortex-xdr-agent-7.9.1.md): Addressed issues in Cortex XDR agent 7.9.1 release for Windows, macOS, iOS, and Linux.
* [Addressed Issue in Cortex XDR 7.9.0-hotfix (7.9.0.20664)](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-in-cortex-xdr-agent-7.9/addressed-issue-in-cortex-xdr-7.9.0-hotfix-7.9.0.20664.md)
* [Addressed Issue in Cortex XDR 7.9.0-HF1](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-in-cortex-xdr-agent-7.9/addressed-issue-in-cortex-xdr-7.9.0-hf1.md)
* [Addressed Issues in Cortex XDR Agent 7.9.0](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-in-cortex-xdr-agent-7.9/addressed-issues-in-cortex-xdr-agent-7.9.0.md)
* [Addressed Issues for Cortex XDR Collectors](https://cortex-docs.paloaltonetworks.com/7.x/7.9-eol/cortex-xdr-agent-7.9-release-information/addressed-issues-for-cortex-xdr-collectors.md)

- [Cortex XDR Agent 7.8 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 7.8 release
- [Features Introduced in Cortex XDR Agent 7.8](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/features-introduced-in-cortex-xdr-agent-7.8.md): Describes the new features introduced in Cortex XDR agent 7.8 releases.
- [Features Introduced in Cortex XDR Agent 7.8](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/features-introduced-in-cortex-xdr-agent-7.8/features-introduced-in-cortex-xdr-agent-7.8.md): Describes the new features introduced in Cortex XDR agent 7.8 releases.
- [Changes to Default Behavior in Cortex XDR Agent 7.8](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.8.md): Changes to default behavior in Cortex XDR agent 7.9 for Windows, macOS, and Linux endpoints.
- [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 7.8.
- [Addressed Issues in Cortex XDR Agent 7.8](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8.md): Addressed issues in Cortex XDR agent 7.8 release for Windows, macOS, and Linux.
- [Addressed Issue in Cortex XDR Agent 7.8.2-HF2](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8/addressed-issue-in-cortex-xdr-agent-7.8.2-hf2.md)
- [Addressed Issue in Cortex XDR Agent 7.8.2-hotfix (7.8.0.20663)](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8/addressed-issue-in-cortex-xdr-agent-7.8.2-hotfix-7.8.0.20663.md)
- [Addressed Issues in Cortex XDR Agent 7.8.2](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8/addressed-issues-in-cortex-xdr-agent-7.8.2.md)
- [Addressed Issues in Cortex XDR Agent 7.8.1](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8/addressed-issues-in-cortex-xdr-agent-7.8.1.md)
- [Addressed Issue in Cortex XDR Agent 7.8-hotfix](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8/addressed-issue-in-cortex-xdr-agent-7.8-hotfix.md)
- [Addressed Issue in Cortex XDR Agent 7.8-hotfix (7.8.0.64264)](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8/addressed-issue-in-cortex-xdr-agent-7.8-hotfix-7.8.0.64264.md)
- [Addressed Issues in Cortex XDR Agent 7.8](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/addressed-issues-in-cortex-xdr-agent-7.8/addressed-issues-in-cortex-xdr-agent-7.8.md)

* [Cortex XDR Agent 7.7 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.7-eol/cortex-xdr-agent-7.7-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent \\\<x.x\\> release
* [Features Introduced in Cortex XDR Agent 7.7](https://cortex-docs.paloaltonetworks.com/7.x/7.7-eol/cortex-xdr-agent-7.7-release-information/features-introduced-in-cortex-xdr-agent-7.7.md): Describes the new features introduced in Cortex XDR agent 7.7 releases.
* [Changes to Default Behavior in Cortex XDR Agent 7.7](https://cortex-docs.paloaltonetworks.com/7.x/7.7-eol/cortex-xdr-agent-7.7-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.7.md): Changes to default behavior in Cortex XDR agent 7.7 for Windows, macOS, and Linux endpoints.
* [Changes to Default Behavior in Cortex XDR Agent 7.7](https://cortex-docs.paloaltonetworks.com/7.x/7.7-eol/cortex-xdr-agent-7.7-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.7/changes-to-default-behavior-in-cortex-xdr-agent-7.7.md): Changes to default behavior in Cortex XDR agent 7.7 for Windows, macOS, and Linux endpoints.
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.7-eol/cortex-xdr-agent-7.7-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 7.7.
* [Addressed Issues in Cortex XDR Agent 7.7](https://cortex-docs.paloaltonetworks.com/7.x/7.7-eol/cortex-xdr-agent-7.7-release-information/addressed-issues-in-cortex-xdr-agent-7.7.md): Addressed issues in Cortex XDR agent 7.7 release for Windows, macOS, and Linux.

- [Cortex XDR Agent 7.6 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/cortex-xdr-agent-7.6-release-information.md)
- [Features Introduced in Cortex XDR Agent 7.6](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/features-introduced-in-cortex-xdr-agent-7.6.md)
- [Microsoft Exchange Vulnerability Protection](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/features-introduced-in-cortex-xdr-agent-7.6/microsoft-exchange-vulnerability-protection.md)
- [Mac Features](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/features-introduced-in-cortex-xdr-agent-7.6/mac-features.md)
- [Linux Features](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/features-introduced-in-cortex-xdr-agent-7.6/linux-features.md)
- [Changes to Default Behavior in Cortex XDR Agent 7.6](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/changes-to-default-behavior-in-cortex-xdr-agent-7.6.md)
- [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/cortex-xdr-agent-known-issues.md)
- [Addressed Issues in Cortex XDR Agent 7.6](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/addressed-issues-in-cortex-xdr-agent-7.6.md)
- [Addressed Issues in Cortex XDR Agent 7.6](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/addressed-issues-in-cortex-xdr-agent-7.6/addressed-issues-in-cortex-xdr-agent-7.6.md)
- [Addressed Issues in Cortex XDR Agent 7.6.0-hotfix](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/addressed-issues-in-cortex-xdr-agent-7.6/addressed-issues-in-cortex-xdr-agent-7.6.0-hotfix.md)

* [Cortex XDR Agent 7.5 CE Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.5ce-eol/cortex-xdr-agent-7.5-ce-release-information.md): New features, default behavior changes, and known issues in Cortex XDR agent 7.5 CE release
* [Features Introduced in Cortex XDR Agent 7.5 CE](https://cortex-docs.paloaltonetworks.com/7.x/7.5ce-eol/cortex-xdr-agent-7.5-ce-release-information/features-introduced-in-cortex-xdr-agent-7.5-ce.md): Describes the new features introduced in Cortex XDR agent 7.5 CE releases.
* [Features Introduced in Cortex XDR Agent 7.5.102](https://cortex-docs.paloaltonetworks.com/7.x/7.5ce-eol/cortex-xdr-agent-7.5-ce-release-information/features-introduced-in-cortex-xdr-agent-7.5-ce/features-introduced-in-cortex-xdr-agent-7.5.102.md): Describes the new features introduced in Cortex XDR agent 7.5 CE releases.
* [Changes to Default Behavior in Cortex XDR Agent 7.5 CE](https://cortex-docs.paloaltonetworks.com/7.x/7.5ce-eol/cortex-xdr-agent-7.5-ce-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.5-ce.md): Changes to default behavior in Cortex XDR agent 7.5 CE for Windows, macOS, and Linux endpoints.
* [Changes to Default Behavior in Cortex XDR Agent 7.5.100](https://cortex-docs.paloaltonetworks.com/7.x/7.5ce-eol/cortex-xdr-agent-7.5-ce-release-information/changes-to-default-behavior-in-cortex-xdr-agent-7.5-ce/changes-to-default-behavior-in-cortex-xdr-agent-7.5.100.md): Changes to default behavior in Cortex XDR agent 7.5 CE for Windows, macOS, and Linux endpoints.
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.5ce-eol/cortex-xdr-agent-7.5-ce-release-information/cortex-xdr-agent-known-issues.md): See the list of the known issues in Cortex XDR agent 7.5 CE.
* [Addressed Issues in Cortex XDR Agent 7.5 CE](https://cortex-docs.paloaltonetworks.com/7.x/7.5ce-eol/cortex-xdr-agent-7.5-ce-release-information/addressed-issues-in-cortex-xdr-agent-7.5-ce.md): Addressed issues in Cortex XDR agent 7.5 CE release for Windows, macOS, and Linux.

- [Cortex XDR Agent 7.5 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.5-eol/cortex-xdr-agent-7.5-release-information.md)
- [Features Introduced in Cortex XDR Agent 7.5](https://cortex-docs.paloaltonetworks.com/7.x/7.5-eol/features-introduced-in-cortex-xdr-agent-7.5.md)
- [Changes to Default Behavior in Cortex XDR Agent 7.5](https://cortex-docs.paloaltonetworks.com/7.x/7.5-eol/changes-to-default-behavior-in-cortex-xdr-agent-7.5.md)
- [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.5-eol/cortex-xdr-agent-known-issues.md)
- [Addressed Issues in Cortex® XDR™ Agent 7.5](https://cortex-docs.paloaltonetworks.com/7.x/7.5-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.5.md)

* [Cortex XDR Agent 7.4 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.4-eol/cortex-xdr-agent-7.4-release-information.md)
* [Features Introduced in Cortex XDR Agent 7.4](https://cortex-docs.paloaltonetworks.com/7.x/7.4-eol/features-introduced-in-cortex-xdr-agent-7.4.md)
* [Changes to Default Behavior in Cortex XDR Agent 7.4](https://cortex-docs.paloaltonetworks.com/7.x/7.4-eol/changes-to-default-behavior-in-cortex-xdr-agent-7.4.md)
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.4-eol/cortex-xdr-agent-known-issues.md)
* [Addressed Issues in Cortex® XDR™ Agent 7.4](https://cortex-docs.paloaltonetworks.com/7.x/7.4-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.4.md)

- [Cortex® XDR™ Agent 7.3 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.3-eol/cortex-r-xdr-tm-agent-7.3-release-information.md): Release 7.3 (EoL)
- [Features Introduced in Cortex® XDR™ Agent 7.3](https://cortex-docs.paloaltonetworks.com/7.x/7.3-eol/features-introduced-in-cortex-r-xdr-tm-agent-7.3.md)
- [Changes to Default Behavior in Cortex® XDR™ Agent 7.3](https://cortex-docs.paloaltonetworks.com/7.x/7.3-eol/changes-to-default-behavior-in-cortex-r-xdr-tm-agent-7.3.md)
- [Known Issues in Cortex® XDR™ Agent 7.3](https://cortex-docs.paloaltonetworks.com/7.x/7.3-eol/known-issues-in-cortex-r-xdr-tm-agent-7.3.md)
- [Addressed Issues in Cortex® XDR™ Agent 7.3](https://cortex-docs.paloaltonetworks.com/7.x/7.3-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.3.md)

* [Cortex® XDR™ Agent 7.2 Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.2-eol/cortex-r-xdr-tm-agent-7.2-release-information.md)
* [Features Introduced in Cortex® XDR™ Agent 7.2](https://cortex-docs.paloaltonetworks.com/7.x/7.2-eol/features-introduced-in-cortex-r-xdr-tm-agent-7.2.md)
* [Changes to Default Behavior](https://cortex-docs.paloaltonetworks.com/7.x/7.2-eol/changes-to-default-behavior.md)
* [Compatibility](https://cortex-docs.paloaltonetworks.com/7.x/7.2-eol/compatibility.md)
* [Known Issues in Cortex® XDR™ Agent 7.2](https://cortex-docs.paloaltonetworks.com/7.x/7.2-eol/known-issues-in-cortex-r-xdr-tm-agent-7.2.md)
* [Addressed Issues in Cortex® XDR™ Agent 7.2](https://cortex-docs.paloaltonetworks.com/7.x/7.2-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.2.md)

- [Cortex XDR Agent Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.1-eol/cortex-xdr-agent-release-information.md)
- [Features Introduced in Cortex XDR Agent 7.1](https://cortex-docs.paloaltonetworks.com/7.x/7.1-eol/features-introduced-in-cortex-xdr-agent-7.1.md)
- [Associated Software and Content Versions](https://cortex-docs.paloaltonetworks.com/7.x/7.1-eol/associated-software-and-content-versions.md)
- [Changes to Default Behavior](https://cortex-docs.paloaltonetworks.com/7.x/7.1-eol/changes-to-default-behavior.md)
- [Limitations](https://cortex-docs.paloaltonetworks.com/7.x/7.1-eol/limitations.md)
- [Cortex XDR Agent Addressed Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.1-eol/cortex-xdr-agent-addressed-issues.md)
- [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.1-eol/cortex-xdr-agent-known-issues.md)

* [Cortex XDR Agent Release Information](https://cortex-docs.paloaltonetworks.com/7.x/7.0-eol/cortex-xdr-agent-release-information.md)
* [Features Introduced in Cortex XDR Agent 7.0](https://cortex-docs.paloaltonetworks.com/7.x/7.0-eol/features-introduced-in-cortex-xdr-agent-7.0.md)
* [Changes to Default Behavior](https://cortex-docs.paloaltonetworks.com/7.x/7.0-eol/changes-to-default-behavior.md)
* [Associated Software and Content Versions](https://cortex-docs.paloaltonetworks.com/7.x/7.0-eol/associated-software-and-content-versions.md)
* [Limitations](https://cortex-docs.paloaltonetworks.com/7.x/7.0-eol/limitations.md)
* [Cortex XDR Agent Known Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.0-eol/cortex-xdr-agent-known-issues.md)
* [Cortex XDR Agent Addressed Issues](https://cortex-docs.paloaltonetworks.com/7.x/7.0-eol/cortex-xdr-agent-addressed-issues.md)

## Cortex XDR Agent 6.x

- [Traps™ Agent Release Information](https://cortex-docs.paloaltonetworks.com/6.1-eol/traps-tm-agent-release-information.md)
- [Features Introduced in Traps Agent 6.1.0](https://cortex-docs.paloaltonetworks.com/6.1-eol/features-introduced-in-traps-agent-6.1.0.md)
- [Changes to Default Behavior](https://cortex-docs.paloaltonetworks.com/6.1-eol/changes-to-default-behavior.md)
- [Associated Software and Content Versions](https://cortex-docs.paloaltonetworks.com/6.1-eol/associated-software-and-content-versions.md)
- [Limitations](https://cortex-docs.paloaltonetworks.com/6.1-eol/limitations.md)
- [Known Issues in Traps Agent 6.1](https://cortex-docs.paloaltonetworks.com/6.1-eol/known-issues-in-traps-agent-6.1.md)
- [Addressed Issues in Traps Agent 6.1.9-hotfix (Windows)](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.9-hotfix-windows.md)
- [Addressed Issues in Traps Agent 6.1.9](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.9.md)
- [Addressed Issues in Traps Agent 6.1.7/8-hotfix](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.7-8-hotfix.md)
- [Addressed Issues in Traps Agent 6.1.8](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.8.md)
- [Addressed Issues for Traps Agent 6.1.7-hotfix (Mac & Linux)](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-for-traps-agent-6.1.7-hotfix-mac-and-linux.md)
- [Addressed Issues in Traps Agent 6.1.7](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.7.md)
- [Addressed Issues in Traps Agent 6.1.6](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.6.md)
- [Addressed Issues in Traps Agent 6.1.5-h1](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.5-h1.md)
- [Addressed Issues in Traps Agent 6.1.5](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.5.md)
- [Addressed Issues in Traps Agent 6.1.4-h1](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.4-h1.md)
- [Addressed Issues in Traps Agent 6.1.3](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.3.md)
- [Addressed Issues in Traps Agent 6.1.2](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.2.md)
- [Addressed Issues in Traps Agent 6.1.1](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.1.md)
- [Addressed Issues in Traps Agent 6.1.0](https://cortex-docs.paloaltonetworks.com/6.1-eol/addressed-issues-in-traps-agent-6.1.0.md)

## Cortex XDR Agent 5.x

- [Features Introduced in Traps Agent 5.0 (EoL)](https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/features-introduced-in-traps-agent-5.0.md): The following topics describe the new features introduced in Traps agent 5.0 releases.
- [Changes to Default Behavior](https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/changes-to-default-behavior.md): Changes to Default Behavior in Traps agent 5.0 releases.
- [Associated Software and Content Versions](https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/associated-software-and-content-versions.md)
- [Compatibility](https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/compatibility.md): Trap agent 5.0 releases are compatible only with specific platforms.
- [Known Issues in Traps Agent 5.0](https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/known-issues-in-traps-agent-5.0.md): Known issues in Traps agent 5.0 releases.
- [Addressed Issues in Traps Agent 5.0](https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/addressed-issues-in-traps-agent-5.0.md): List of addressed issues in Traps agent 5.0 releases.

## Cortex Cloud Runtime Security

- [Cortex Cloud Runtime Security Release Information](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information.md)
- [Features introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/july-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/july-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/july-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/july-2026/changed-features.md)
- [July 20, 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/july-20-2026.md)
- [May 17, 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/may-17-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/may-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/may-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/may-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/may-2026/changed-features.md)
- [February 22, 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/february-22-2026.md)
- [February 8, 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/february-08-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/february-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/february-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/february-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2026-cloud/february-2026/changed-features.md)
- [Features introduced in 2025](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud.md)
- [December 22, 2025](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/december-22-2025.md)
- [November 23, 2025](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/november-23-2025.md)
- [November 2025](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/november-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/november-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/november-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/november-2025/changed-features.md)
- [July 2025](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/july-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/july-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/july-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/july-2025/changed-features.md)
- [April 2025](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/april-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/april-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/april-2025/feature-enhancements.md)
- [Maintenance releases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases.md)
- [Broker VM 32.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases/broker-vm-32052-major.md)
- [Broker VM 31.100.2](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases/broker-vm-311002.md)
- [Broker VM 32.0.51 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases/broker-vm-32051-major.md)
- [XDR Collectors 1.5.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases/xdr-collectors-153-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases/xdr-collectors-143-major.md)
- [Previous maintenance releases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm.md)
- [Broker VM 31.0.58 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-31058-major.md)
- [Broker VM 31.0.57 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-31057-major.md)
- [Broker VM 30.0.63 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-30063-major.md)
- [Broker VM 30.0.61 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-30061-major.md)
- [Broker VM 30.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-30052-major.md)
- [Broker VM 29.0.77 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-29077-major.md)
- [Broker VM 29.0.71 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-29071-major.md)
- [Broker VM 28.0.99 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-28099-major.md)
- [Broker VM 28.0.96](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-28096-major.md)
- [Broker VM 27.100.18](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-2710018.md)
- [Broker VM 27.100.17](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-2710017.md)
- [Broker VM 27.0.47](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-27047-major.md)
- [Broker VM 26.100.10](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-2610010.md)
- [Broker VM 26.100.3](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-261003.md)
- [Broker VM 26.0.119](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/broker-vm/broker-vm-260119-major.md)
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-21.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-21.md)
- [XDR Collectors 1.5.2 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-20.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-20.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-20.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major-13.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major-13.md)
- [XDR Collectors 1.5.1 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-151-major.md)
- [XDR Collectors 1.4.3 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-143-major.md)
- [XDR Collectors 1.5.0 (Major)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-150-major.md)
- [Compliance standards updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/compliance-standards-updates.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/compliance-standards-updates/july-2026.md)
- [June 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/compliance-standards-updates/june-2026.md)
- [April 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/compliance-standards-updates/april-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/compliance-standards-updates/february-2026.md)
- [API Ingestions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/api-ingestions.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/api-ingestions/july-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/api-ingestions/may-2026.md)

## Cortex Cloud Posture Management

- [Cortex Cloud Posture Management Release Information](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information.md)
- [Features introduced in 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/july-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/july-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/july-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/july-2026/changed-features.md)
- [May 17, 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/may-17-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/may-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/may-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/may-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/may-2026/changed-features.md)
- [February 22, 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/february-22-2026.md)
- [February 8, 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/february-08-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/february-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/february-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/february-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/february-2026/changed-features.md)
- [Features introduced in 2025](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud.md)
- [November 23, 2025](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/november-23-2025.md)
- [November 2025](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/november-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/november-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/november-2025/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/november-2025/changed-features.md)
- [July 2025](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/july-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/july-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/july-2025/feature-enhancements.md)
- [April 2025](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/april-2025.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/april-2025/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2025-cloud/april-2025/feature-enhancements.md)
- [Maintenance releases](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/maintenance-releases.md)
- [Broker VM 32.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/maintenance-releases/broker-vm-32052-major.md)
- [Broker VM 31.100.2](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/maintenance-releases/broker-vm-311002.md)
- [Broker VM 32.0.51 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/maintenance-releases/broker-vm-32051-major.md)
- [Previous maintenance releases](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm.md)
- [Broker VM 31.0.58 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-31058-major.md)
- [Broker VM 31.0.57 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-31057-major.md)
- [Broker VM 30.0.63 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-30063-major.md)
- [Broker VM 30.0.61 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-30061-major.md)
- [Broker VM 30.0.52 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-30052-major.md)
- [Broker VM 29.0.77 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-29077-major.md)
- [Broker VM 29.0.71 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-29071-major.md)
- [Broker VM 28.0.99 (Major)](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-28099-major.md)
- [Broker VM 28.0.96](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/previous-maintenance-releases/broker-vm/broker-vm-28096-major.md)
- [Compliance standards updates](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/compliance-standards-updates.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/compliance-standards-updates/july-2026.md)
- [June 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/compliance-standards-updates/june-2026.md)
- [April 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/compliance-standards-updates/april-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/compliance-standards-updates/february-2026.md)
- [API Ingestions](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/api-ingestions.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/api-ingestions/july-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/api-ingestions/may-2026.md)

## Cortex AgentiX

- [Cortex AgentiX Release Information](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/cortex-agentix-release-information.md)
- [Features Introduced in This Release](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/july-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/july-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/july-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/july-2026/changed-features.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/may-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/may-2026/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/may-2026/feature-enhancements.md)
- [Changed Features](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/may-2026/changed-features.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/february-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/february-2026/release-highlights.md)
- [November 2025](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/november-2025.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/november-2025/feature-enhancements.md)
- [Marketplace content changes](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/features-introduced-in-this-release/november-2025/marketplace-content-changes.md)

## Cortex XSOAR 8 SaaS Release Notes

- [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/cortex-xsoar-release-information.md)
- [Features Introduced in This Release](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-this-release.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-this-release/july-2026.md)
- [Features introduced in previous releases](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases.md)
- [Features Introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2026.md)
- [May 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2026/may-2026.md)
- [February 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2026/february-2026.md)
- [Features Introduced in 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025.md)
- [November 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/november-2025.md)
- [July 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/july-2025.md)
- [April 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/april-2025.md)
- [February 2025](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/february-2025.md)
- [Features Introduced in 2024](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2024.md)
- [September 2024](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2024/september-2024.md)
- [June 2024](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2024/june-2024.md)
- [April 2024](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2024/april-2024.md)
- [February 2024](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2024/february-2024.md)
- [Features Introduced in 2023](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2023.md)
- [October 2023](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2023/october-2023.md)
- [July 2023](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2023/july-2023.md)
- [April 2023](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2023/april-2023.md)
- [January 2023](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2023/january-2023.md)
- [Known Issues](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/known-issues.md)

## Cortex XSOAR 8 On-prem Release Notes

- [Cortex XSOAR 8 On-prem Releases](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/cortex-xsoar-8-on-prem-releases.md): Major general availability and maintenance releases for Cortex XSOAR 8 On-prem

* [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/xsoar-opp-release-notes-8.14/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR 8.14 On-prem.
* [Features Introduced in this Release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/xsoar-opp-release-notes-8.14/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.14 On-prem, including release highlights and feature enhancements.
* [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/xsoar-opp-release-notes-8.14/features-introduced-in-this-release/release-highlights.md)
* [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/xsoar-opp-release-notes-8.14/features-introduced-in-this-release/feature-enhancements.md)
* [Marketplace Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/xsoar-opp-release-notes-8.14/features-introduced-in-this-release/marketplace-changes.md)
* [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/xsoar-opp-release-notes-8.14/known-issues.md)

- [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR 8.13 On-prem.
- [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.13.
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/features-introduced-in-this-release/release-highlights.md)
- [Feature enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/features-introduced-in-this-release/feature-enhancements.md)
- [Marketplace Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/features-introduced-in-this-release/marketplace-changes.md)
- [Changed features](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/features-introduced-in-this-release/changed-features.md)
- [Maintenance releases in Cortex XSOAR 8.13](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/maintenance-releases-in-cortex-xsoar-8.13.md)
- [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.13/known-issues.md): Cortex XSOAR 8 known issues.

* [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
* [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.12.
* [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/features-introduced-in-this-release/release-highlights.md)
* [Feature enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/features-introduced-in-this-release/feature-enhancements.md)
* [Changed features](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/features-introduced-in-this-release/changed-features.md)
* [Marketplace Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/features-introduced-in-this-release/marketplace-changes.md)
* [Maintenance Releases in Cortex XSOAR 8.12](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/maintenance-releases-in-cortex-xsoar-8.12.md): Maintenance Releases for Cortex XSOAR 8.12 On-prem.
* [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.12/known-issues.md): Cortex XSOAR 8 known issues.

- [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
- [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/features-introduced-in-this-release.md): New features are available in Cortex XSOAR On-prem 8.11.
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/features-introduced-in-this-release/release-highlights.md)
- [Feature enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/features-introduced-in-this-release/feature-enhancements.md)
- [Changed features](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/features-introduced-in-this-release/changed-features.md)
- [Marketplace Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/features-introduced-in-this-release/marketplace-changes.md)
- [Maintenance Releases in Cortex XSOAR 8.11](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/maintenance-releases-in-cortex-xsoar-8.11.md): Maintenance Releases for Cortex XSOAR 8.11 On-prem.
- [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.11/known-issues.md): Cortex XSOAR 8 known issues.

* [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.10/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
* [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.10/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.10.
* [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.10/features-introduced-in-this-release/release-highlights.md)
* [Marketplace Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.10/features-introduced-in-this-release/marketplace-changes.md)
* [Addressed Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.10/features-introduced-in-this-release/addressed-issues.md)
* [Maintenance Releases in Cortex XSOAR 8.10](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.10/maintenance-releases-in-cortex-xsoar-8.10.md): Maintenance Releases for Cortex XSOAR 8x On-prem.
* [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.10/known-issues.md): Cortex XSOAR 8 known issues.

- [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.9/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
- [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.9/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.9/features-introduced-in-this-release/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.9/features-introduced-in-this-release/feature-enhancements.md)
- [Marketplace Content Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.9/features-introduced-in-this-release/marketplace-content-changes.md)
- [Maintenance Releases in Cortex XSOAR 8.9](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.9/maintenance-releases-in-cortex-xsoar-8.9.md): Maintenance Releases for Cortex XSOAR 8x On-prem.
- [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.9/known-issues.md): Cortex XSOAR 8 known issues.

* [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.8/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
* [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.8/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.8
* [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.8/features-introduced-in-this-release/release-highlights.md)
* [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.8/features-introduced-in-this-release/feature-enhancements.md)
* [Marketplace Content Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.8/features-introduced-in-this-release/marketplace-content-changes.md)
* [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.8/known-issues.md): Cortex XSOAR 8 known issues.

- [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.7/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
- [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.7/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.7/features-introduced-in-this-release/release-highlights.md)
- [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.7/features-introduced-in-this-release/feature-enhancements.md)
- [Marketplace content changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.7/features-introduced-in-this-release/marketplace-content-changes.md)
- [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.7/known-issues.md): Cortex XSOAR 8 known issues.

* [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.6/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
* [Features introduced in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.6/features-introduced-in-this-release.md): New features are available in Cortex XSOAR 8.
* [Release Highlights](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.6/features-introduced-in-this-release/release-highlights.md)
* [Feature Enhancements](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.6/features-introduced-in-this-release/feature-enhancements.md)
* [Marketplace Content Changes](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.6/features-introduced-in-this-release/marketplace-content-changes.md)
* [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.6/known-issues.md): Cortex XSOAR 8 known issues.

- [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.5/cortex-xsoar-release-information.md): New features, addressed issues, and breaking changes in Cortex XSOAR On-prem.
- [Features Introduced in This Release](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.5/features-introduced-in-this-release.md): New features introduced in Cortex XSOAR 8 SaaS per year.
- [Cortex XSOAR 8 On-prem](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.5/features-introduced-in-this-release/cortex-xsoar-8-on-prem.md)
- [Cortex XSOAR On-prem features](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.5/features-introduced-in-this-release/cortex-xsoar-on-prem-features.md)
- [Cortex XSOAR 8.5 features](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.5/features-introduced-in-this-release/cortex-xsoar-8.5-features.md)
- [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes/8.5/known-issues.md): Cortex XSOAR 8 known issues.

## Cortex XSOAR 6 Release Notes

- [Cortex XSOAR 6 Release Notes](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/cortex-xsoar-6-release-notes.md)

* [Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.14/release-information.md): Cortex XSOAR 6.14 release information.
* [New Features](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.14/new-features.md): New features are available in Cortex XSOAR 6.14.
* [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.14/known-issues.md): Cortex XSOAR known issues.
* [Minor Releases](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.14/minor-releases.md): Cortex XSOAR 6.14 minor release, maintenance release.

- [Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.13/release-information.md): Cortex XSOAR 6.13 release information.
- [New Features](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.13/new-features.md): New features are available in Cortex XSOAR 6.13.
- [Addressed Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.13/addressed-issues.md): Cortex XSOAR 6.13 addressed issues.
- [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.13/known-issues.md): Cortex XSOAR known issues.

* [Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.12/release-information.md): Cortex XSOAR v6.12 release information.
* [New Features](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.12/release-information/new-features.md): New features are available in Cortex XSOAR 6.12.
* [Addressed Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.12/release-information/addressed-issues.md): Cortex XSOAR 6.12 addressed issues.
* [Known Issues](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.12/release-information/known-issues.md): Cortex XSOAR known issues.
* [Minor Releases](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.12/release-information/minor-releases.md): Cortex XSOAR 6.12 minor release, maintenance release.

## Cortex Xpanse Expander

- [Cortex Xpanse Expander Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/expander-release-information.md)
- [Features introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases.md)
- [Release 2.14 (July 2026)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/july-2026.md)
- [Release 2.13 (May 2026)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/may-2026.md)
- [Release 2.12 (February 2026)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/february-2026.md)
- [Features introduced before 2026](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026.md)
- [Features introduced in 2025](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2025-releases.md)
- [Release 2.11 (November 2025)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2025-releases/release-211-november-2025.md)
- [Release 2.10 (July 2025)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2025-releases/release-210-july-2025.md)
- [Release 2.9 (April 2025)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2025-releases/release-29-april-2025.md)
- [Release 2.8 (February 2025)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2025-releases/release-28-february-2025.md)
- [Features introduced in 2024](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases.md)
- [Expander Release 2.7 (Minor Releases)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-27-minor-releases.md)
- [Expander Release 2.7 (September 2024)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-27-september-2024.md)
- [Expander Release 2.6 (June 2024)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-26-june-2024.md)
- [Expander Release 2.5 (Minor Releases)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-25-minor-releases.md)
- [Expander Release 2.5 (April 2024)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-25-april-2024.md)
- [Expander Release 2.4 (Minor Releases)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-24-minor-releases.md)
- [Expander Release 2.4 (February 2024)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-24-february-2024.md)
- [Features introduced in 2023](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases.md)
- [Expander Release 2.3 (Minor Releases)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-23-minor-releases.md)
- [Expander Release 2.3 (October 2023)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-23-october.md)
- [Expander Release 2.2 (Minor Releases)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-22-minor-releases.md)
- [Expander Release 2.2 (June 2023)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-22-june.md)
- [Expander Release 2.1 (March 2023)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-21-march.md)
- [Features introduced in 2022](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2022-releases.md)
- [Expander Release 2.0 (December 2022)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2022-releases/expander-release-20-december-2022.md)
- [Hotfix Releases](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases.md)
- [January 2025](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases/january-2025.md)
- [November 2024](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases/november-2024.md)
- [October 2024](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases/october-2024.md)
- [August 2024](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases/august-2024.md)
- [July 2024](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases/july-2024.md)
- [June 2024](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases/june-2024.md)
- [May 2024](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/hotfix-releases/may-2024.md)

## Cortex Analytics Content Releases

- [Cortex Analytics Content Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes.md)
- [2026.08.05](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-08-05.md)
- [2026.07.29](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-29.md)
- [2026.07.22](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-22.md)
- [2026.07.15](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-15.md)
- [2026.07.08](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-08.md)
- [2026.07.01](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-01.md)
- [2026.06.10](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-06-10.md)
- [2026.05.28](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-05-28.md)
- [2026.05.06](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-05-06.md)
- [2026.04.29](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-04-29.md)
- [2026.04.22](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-04-22.md)
- [2026.04.15](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-04-15.md)
- [2026.03.18](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-03-18.md)
- [2026.03.04](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-03-04.md)
- [2026.02.25](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-25.md)
- [2026.02.18](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-18.md)
- [2026.02.11](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-11.md)
- [2026.02.04](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-04.md)
- [2026.01.28](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-01-28.md)
- [2026.01.21](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-01-21.md)
- [2026.01.07](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-01-07.md)
- [2025.12.31](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-12-31.md)
- [2025.12.03](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-12-03.md)
- [2025.11.26](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-11-26.md)
- [2025.11.19](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-11-19.md)
- [2025.11.12](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-11-12.md)
- [2025.11.05](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-11-05.md)
- [2025.10.22](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-10-22.md)
- [2025.10.08](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-10-08.md)
- [2025.09.03](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-09-03.md)
- [2025.08.20](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-08-20.md)
- [2025.08.13](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-08-13.md)
- [2025.07.23](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-07-23.md)
- [2025.07.16](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-07-16.md)
- [2025.07.09](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-07-09.md)
- [2025.06.11](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-06-11.md)
- [2025.06.04](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-06-04.md)
- [2025.05.28](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-05-28.md)
- [2025.05.21](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-05-21.md)
- [2025.04.23](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-04-23.md)
- [2025.04.16](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-04-16.md)
- [2025.03.26](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-03-26.md)
- [2025.03.12](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-03-12.md)
- [2025.03.05](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-03-05.md)
- [2025.02.26](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-02-26.md)
- [2025.02.19](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-02-19.md)
- [2025.02.05](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-02-05.md)
- [2025.01.29](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-01-29.md)
- [2025.01.15](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-01-15.md)
- [2024.12.25](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-12-25.md)
- [2024.11.20](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-11-20.md)
- [2024.11.06](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-11-06.md)
- [2024.10.09](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-10-09.md)
- [2024.09.25](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-09-25.md)
- [2024.09.18](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-09-18.md)
- [2024.09.04](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-09-04.md)
- [2024.08.28](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-08-28.md)
- [2024.08.14](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-08-14.md)
- [2024.07.31](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-07-31.md)
- [2024.07.24](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-07-24.md)
- [2024.07.17](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-07-17.md)
- [2024.07.10](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-07-10.md)
- [2024.06.05](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-06-05.md)
- [2024.05.22](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-05-22.md)
- [2024.05.15](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-05-15.md)
- [2024.05.08](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-05-08.md)
- [2024.05.01](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-05-01.md)
- [2024.04.03](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-04-03.md)
- [2024.03.27](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-03-27.md)
- [2024.03.20](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-03-20.md)
- [2024.03.06](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-03-06.md)
- [2024.02.28](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2024-02-28.md)

## Cortex XDR Content Update Releases

- [Cortex XDR Content Releases](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases.md)
- [2390](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2390.md)
- [2380](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2380.md)
- [2370](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2370.md)
- [2360](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2360.md)
- [2350](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2350.md)
- [2340](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2340.md)
- [2330](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2330.md)
- [2320](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2320.md)
- [2310](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2310.md)
- [2300](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2300.md)
- [2290](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2290.md)
- [2280](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2280.md)
- [2270](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2270.md)
- [2260](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2260.md)
- [2250](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2250.md)
- [2240](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2240.md)
- [2230](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2230.md)
- [2220](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2220.md)
- [2210](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2210.md)
- [2200](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2200.md)
- [2190](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2190.md)
- [2180](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2180.md)
- [2170](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2170.md)
- [2160](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2160.md)
- [2150](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2150.md)
- [2140](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2140.md)
- [2130](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2130.md)
- [2120](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2120.md)
- [2110](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2110.md)
- [2100](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2100.md)
- [2090](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2090.md)
- [2080](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2080.md)
- [2070](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2070.md)
- [2060](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2060.md)
- [2050](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2050.md)
- [2040](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2040.md)
- [2030](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2030.md)
- [2020](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2020.md)
- [2010](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2010.md)
- [2000](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/2000.md)
- [1990](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1990.md)
- [1980](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1980.md)
- [1970](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1970.md)
- [1960](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1960.md)
- [1950](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1950.md)
- [1940](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1940.md)
- [1930](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1930.md)
- [1920](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1920.md)
- [1910](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1910.md)
- [1900](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1900.md)
- [1890](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1890.md)
- [1880](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1880.md)
- [1870](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1870.md)
- [1860](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1860.md)
- [1850](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1850.md)
- [1840](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1840.md)
- [1830](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1830.md)
- [1820](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1820.md)
- [1810](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1810.md)
- [1800](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1800.md)
- [1790](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1790.md)
- [1780](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1780.md)
- [1770](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1770.md)
- [1760](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1760.md)
- [1750](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1750.md)
- [1740](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1740.md)
- [1730](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1730.md)
- [1720](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1720.md)
- [1710](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1710.md)
- [1700](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1700.md)
- [1690](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1690.md)
- [1680](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1680.md)
- [1670](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1670.md)
- [1660](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1660.md)
- [1650](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1650.md)
- [1640](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1640.md)
- [1630](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1630.md)
- [1620](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1620.md)
- [1610](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases/cortex-xdr-content-releases/1610.md)

## Cortex XSPM Content Releases



## Cortex Attack Path Content Releases



## Cortex Data Security

- [Release Information](https://cortex-docs.paloaltonetworks.com/cortex-data-security/release-information.md)
- [Features introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-data-security/release-information/features-2026.md)
- [July 2026](https://cortex-docs.paloaltonetworks.com/cortex-data-security/release-information/features-2026/july-2026.md)
- [Release Highlights](https://cortex-docs.paloaltonetworks.com/cortex-data-security/release-information/features-2026/july-2026/release-highlights.md)

## Overview

- [Cortex API Documentation](https://cortex-docs.paloaltonetworks.com/cortex-api-overview/readme.md): Explore and integrate with the Cortex platform APIs

## Cortex Cloud APIs

- [Get started with Cortex Cloud APIs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/get-started-with-cortex-apis.md)
- [What's new in this release](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/api-release-notes.md)
- [Create a new API key](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/create-a-new-api-key.md)
- [Get your Cortex Cloud API key ID](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/get-your-cortex-api-key-id.md)
- [Get your FQDN](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/get-your-fqdn.md)
- [Make your first API call](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/make-your-first-api-call.md)
- [Understand Cortex Cloud licenses](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/understand-cortex-cloud-licenses.md)
- [Cortex Cloud Platform Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/cortex-cloud-platform-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/api-keys.md)
- [Asset Groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/asset-groups.md)
- [Asset Inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/asset-inventory.md)
- [Attack Surface Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/attack-surface-management.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/audit-log.md)
- [Authentication Settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/authentication-settings.md)
- [BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/biocs.md)
- [Correlation Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/correlation-rules.md)
- [Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/cortex-cli.md)
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/dashboards.md)
- [Dataset Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/dataset-management.md)
- [Endpoint Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/endpoint-management.md)
- [IOCs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/iocs.md)
- [Lookup Datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/lookup-datasets.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/playbooks.md)
- [Query Library](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/query-library.md)
- [Response Action](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/response-action.md)
- [Scheduled Queries](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/scheduled-queries.md)
- [Script Execution](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/script-execution.md)
- [Scripts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/scripts.md)
- [Syslog Servers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/syslog-servers.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/system-management.md)
- [Widgets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/widgets.md)
- [XQL Query](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/xql-query.md)
- [XQL User Datasets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/xql-user-datasets.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/models.md)
- [Run XQL query APIs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/run-xql-query-apis.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform/cortex-cloud-platform-papi-tables.md)
- [Agent Configuration Settings overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/agent-configuration-settings/agent-configuration-settings-overview.md)
- [Agent Configurations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/agent-configuration-settings/agent-configurations.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/agent-configuration-settings/models.md)
- [ASPM, CI/CD, and Application Security Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/application-security-overview.md)
- [Billing](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/billing.md)
- [Applications](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/applications.md)
- [Criteria](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/criteria.md)
- [Data Sources](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/data-sources.md)
- [Policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/policies.md)
- [Package Explorer](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/package-explorer.md)
- [Repositories](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/repositories.md)
- [Remediations](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/remediations.md)
- [Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/rules.md)
- [SBOM Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/sbom-management.md)
- [Scan Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/scan-management.md)
- [Cloud Coverage](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/cloud-coverage.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/aspm-cicd-and-application-security/appsec-papi-tables.md)
- [Asset Compliance overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/asset-compliance/asset-compliance-overview.md)
- [Control Findings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/asset-compliance/control-findings.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/asset-compliance/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/asset-compliance/asset-compliance-papi-tables.md)
- [Broker VM (On-Appliance) overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-on-appliance/broker-vm-appliance-overview.md)
- [Auth (bootstrap)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-on-appliance/auth-bootstrap.md)
- [Registration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-on-appliance/registration.md)
- [Network configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-on-appliance/network-configuration.md)
- [Local log bundle](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-on-appliance/local-log-bundle.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-on-appliance/models.md)
- [Broker VM (Tenant-Side) overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/broker-vm-tenant-overview.md)
- [Brokers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/brokers.md)
- [Actions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/actions.md)
- [Install images](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/install-images.md)
- [Applets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/applets.md)
- [Remote log bundle](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/remote-log-bundle.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/broker-vm-tenant-side/broker-papi-tables.md)
- [Cases APIs overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cases-apis/cases-apis-overview.md)
- [Cases](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cases-apis/cases.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cases-apis/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cases-apis/cases-papi-tables.md)
- [Cloud Infrastructure Entitlement Management (CIEM) overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-infrastructure-entitlement-management-ciem/cloud-infrastructure-entitlement-management-ciem-overview.md)
- [CIEM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-infrastructure-entitlement-management-ciem/ciem.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-infrastructure-entitlement-management-ciem/models.md)
- [Cloud Onboarding API overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-onboarding/cloud-onboarding-overview.md)
- [Cloud Instance Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-onboarding/cloud-instance-management.md)
- [Cloud Account Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-onboarding/cloud-account-management.md)
- [Outpost Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-onboarding/outpost-management.md)
- [General](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-onboarding/general.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-onboarding/models.md)
- [Cloud Workload Protection Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-workload-protection/cloud-workload-protection-overview.md)
- [Policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-workload-protection/policies.md)
- [SBOM](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-workload-protection/sbom.md)
- [Registry Onboarding](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-workload-protection/registry-onboarding.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-workload-protection/models.md)
- [Compliance Controls Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/compliance-controls-overview.md)
- [Pagination](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/pagination.md)
- [Rule Association](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/rule-association.md)
- [Assessment Profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/assessment-profiles.md)
- [Assessment Results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/assessment-results.md)
- [Categories](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/categories.md)
- [Compliance Assets](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/compliance-assets.md)
- [Controls](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/controls.md)
- [Export](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/export.md)
- [Import](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/import.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/reports.md)
- [Results](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/results.md)
- [Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/rules.md)
- [Standards](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/standards.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/compliance-controls/models.md)
- [Cortex Cloud Alert Notification Rules overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-alert-notification-rules/cortex-cloud-alert-notification-rules-overview.md)
- [Alert Notification Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-alert-notification-rules/alert-notification-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-alert-notification-rules/models.md)
- [Cortex Cloud External Application Management overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-external-application-management/cortex-cloud-external-application-management-overview.md)
- [External Applications](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-external-application-management/external-applications.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-external-application-management/models.md)
- [Cortex Cloud Logging and Collection Service Management overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-logging-and-collection-service-management/cortex-cloud-logging-and-collection-service-management-overview.md)
- [CLCS Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-logging-and-collection-service-management/clcs-management.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-cloud-logging-and-collection-service-management/models.md)
- [Cortex Platform IAM Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform-identity-and-access-management-iam/iam-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform-identity-and-access-management-iam/api-keys.md)
- [Roles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform-identity-and-access-management-iam/roles.md)
- [Scopes](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform-identity-and-access-management-iam/scopes.md)
- [User](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform-identity-and-access-management-iam/user.md)
- [User Groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform-identity-and-access-management-iam/user-groups.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cortex-platform-identity-and-access-management-iam/models.md)
- [Restore Distributions overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/restore-distributions/restore-distributions-overview.md)
- [Restore Distributions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/restore-distributions/restore-distributions.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/restore-distributions/models.md)
- [Data Security Posture Management overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/data-security-posture-management/data-security-posture-management-overview.md)
- [Inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/data-security-posture-management/inventory.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/data-security-posture-management/models.md)
- [Detection Rules Management overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/detection-rules-management/detection-rules-management-overview.md)
- [Detection Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/detection-rules-management/detection-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/detection-rules-management/models.md)
- [Disable Injection and Prevention Rules overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/disable-injection-and-prevention-rules/disable-injection-and-prevention-rules-overview.md)
- [Disable Injection and Prevention Rules Public API](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/disable-injection-and-prevention-rules/disable-injection-and-prevention-rules-public-api.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/disable-injection-and-prevention-rules/models.md)
- [Disable Prevention Rule overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/disable-prevention-rule/disable-prevention-rule-overview.md)
- [Disable Prevention Rule Public APIs](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/disable-prevention-rule/disable-prevention-rule-public-apis.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/disable-prevention-rule/models.md)
- [Forensics overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/forensics/forensics-overview.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/forensics/forensics.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/forensics/models.md)
- [Issues APIs overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/issues-apis/issues-apis-overview.md)
- [Issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/issues-apis/issues.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/issues-apis/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/issues-apis/issues-papi-tables.md)
- [Managed Services Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/managed-services/managed-services-overview.md)
- [Assignment](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/managed-services/assignment.md)
- [Comments](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/managed-services/comments.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/managed-services/reports.md)
- [Status](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/managed-services/status.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/managed-services/models.md)
- [Netscan overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/netscan/netscan-overview.md)
- [Vulnerability Network Scan Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/netscan/vulnerability-network-scan-management.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/netscan/models.md)
- [Policies overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/policies/policies-overview.md)
- [Cloud Security Policies](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/policies/cloud-security-policies.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/policies/models.md)
- [Unified Rules overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/unified-rules/unified-rules-overview.md)
- [Unified Rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/unified-rules/unified-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/unified-rules/models.md)
- [Vulnerability Intelligence Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-intelligence/vulnerability-intelligence-overview.md)
- [Affected Software](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-intelligence/affected-software.md)
- [Vulnerabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-intelligence/vulnerabilities.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-intelligence/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-intelligence/vulnerability-intelligence-papi-tables.md)
- [Vulnerability Management Overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-management/vulnerability-management-overview.md)
- [Vulnerability Management](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-management/vulnerability-management.md)
- [Vulnerability Findings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-management/vulnerability-findings.md)
- [Vulnerability Findings Snapshot](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-management/vulnerability-findings-snapshot.md)
- [Bring Your Own Scanner](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-management/bring-your-own-scanner.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/vulnerability-management/models.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/forensics-1/forensics.md)
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/forensics-1/models.md)
- [Cloud Consumption Dashboard API overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-consumption-dashboard/cloud-consumption-overview.md)
- [Cloud Consumption Dashboard](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-consumption-dashboard/cloud-consumption-dashboard.md): Retrieve workload consumption data per asset type, over time, and in a paginated details grid.
- [Licensing](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-consumption-dashboard/licensing.md): Retrieve tenant license entitlements and add-on information.
- [Models](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/cloud-consumption-dashboard/models.md)

## XDR 5.x APIs

- [Get started with Cortex XDR 5.x APIs](https://cortex-docs.paloaltonetworks.com/xdr-5-api/get-started-with-cortex-apis.md)
- [What's new in this release](https://cortex-docs.paloaltonetworks.com/xdr-5-api/api-release-notes.md)
- [Create a new API key](https://cortex-docs.paloaltonetworks.com/xdr-5-api/create-a-new-api-key.md)
- [Get your Cortex XDR API key ID](https://cortex-docs.paloaltonetworks.com/xdr-5-api/get-your-cortex-api-key-id.md)
- [Get your FQDN](https://cortex-docs.paloaltonetworks.com/xdr-5-api/get-your-fqdn.md)
- [Make your first API call](https://cortex-docs.paloaltonetworks.com/xdr-5-api/make-your-first-api-call.md)
- [Understand Cortex XDR licenses](https://cortex-docs.paloaltonetworks.com/xdr-5-api/understand-cortex-xdr-licenses.md)
- [Cortex XDR Platform Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/cortex-xdr-platform-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/api-keys.md)
- [Asset Groups](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/asset-groups.md)
- [Asset Inventory](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/asset-inventory.md)
- [Attack Surface Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/attack-surface-management.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/audit-log.md)
- [Authentication Settings](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/authentication-settings.md)
- [BIOCs](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/biocs.md)
- [Correlation Rules](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/correlation-rules.md)
- [Cortex CLI](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/cortex-cli.md)
- [Dashboards](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/dashboards.md)
- [Dataset Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/dataset-management.md)
- [Endpoint Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/endpoint-management.md)
- [Indicator Rules](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/indicator-rules.md)
- [IOCs](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/iocs.md)
- [Lookup Datasets](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/lookup-datasets.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/playbooks.md)
- [Query Library](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/query-library.md)
- [Response Action](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/response-action.md)
- [Scheduled Queries](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/scheduled-queries.md)
- [Script Execution](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/script-execution.md)
- [Scripts](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/scripts.md)
- [Syslog Servers](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/syslog-servers.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/system-management.md)
- [Widgets](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/widgets.md)
- [XQL Query](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/xql-query.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/models.md)
- [Run XQL query APIs](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/run-xql-query-apis.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cortex-platform/cortex-platform-papi-tables.md)
- [Agent Configuration Settings overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/agent-configuration-settings/agent-configuration-settings-overview.md)
- [Agent Configurations](https://cortex-docs.paloaltonetworks.com/xdr-5-api/agent-configuration-settings/agent-configurations.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/agent-configuration-settings/models.md)
- [Alert Notification Rules overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/alert-notification-rules/alert-notification-rules-overview.md)
- [Alert Notification Rules](https://cortex-docs.paloaltonetworks.com/xdr-5-api/alert-notification-rules/alert-notification-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/alert-notification-rules/models.md)
- [ASPM, CI/CD, and Application Security Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/aspm-cicd-and-application-security-overview.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/appsec-papi-tables.md)
- [Billing](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/billing.md)
- [Applications](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/applications.md)
- [Criteria](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/criteria.md)
- [Data Sources](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/data-sources.md)
- [Policies](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/policies.md)
- [Package Explorer](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/package-explorer.md)
- [Repositories](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/repositories.md)
- [Remediations](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/remediations.md)
- [Rules](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/rules.md)
- [SBOM Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/sbom-management.md)
- [Scan Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/scan-management.md)
- [Cloud Coverage](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/cloud-coverage.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/aspm-cicd-and-application-security/models.md)
- [Asset Compliance overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/asset-compliance/asset-compliance-overview.md)
- [Control Findings](https://cortex-docs.paloaltonetworks.com/xdr-5-api/asset-compliance/control-findings.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/asset-compliance/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-5-api/asset-compliance/asset-compliance-papi-tables.md)
- [Broker VM (On-Appliance) overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-on-appliance/broker-vm-appliance-overview.md)
- [Auth (bootstrap)](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-on-appliance/auth-bootstrap.md)
- [Registration](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-on-appliance/registration.md)
- [Network configuration](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-on-appliance/network-configuration.md)
- [Local log bundle](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-on-appliance/local-log-bundle.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-on-appliance/models.md)
- [Broker VM (Tenant-Side) overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/broker-vm-tenant-overview.md)
- [Brokers](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/brokers.md)
- [Actions](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/actions.md)
- [Install images](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/install-images.md)
- [Applets](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/applets.md)
- [Remote log bundle](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/remote-log-bundle.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-5-api/broker-vm-tenant-side/broker-papi-tables.md)
- [Cases APIs overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cases-apis/cases-apis-overview.md)
- [Cases](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cases-apis/cases.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cases-apis/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cases-apis/cases-papi-tables.md)
- [Cloud Infrastructure Entitlement Management (CIEM) overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-infrastructure-entitlement-management-ciem/cloud-infrastructure-entitlement-management-ciem-overview.md)
- [CIEM](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-infrastructure-entitlement-management-ciem/ciem.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-infrastructure-entitlement-management-ciem/models.md)
- [Cloud Onboarding API overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-onboarding/cloud-onboarding-overview.md)
- [Cloud Instance Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-onboarding/cloud-instance-management.md)
- [Cloud Account Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-onboarding/cloud-account-management.md)
- [Outpost Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-onboarding/outpost-management.md)
- [General](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-onboarding/general.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-onboarding/models.md)
- [Cloud Workload Protection Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-workload-protection/cloud-workload-protection-overview.md)
- [Policies](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-workload-protection/policies.md)
- [SBOM](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-workload-protection/sbom.md)
- [Registry Onboarding](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-workload-protection/registry-onboarding.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/cloud-workload-protection/models.md)
- [Compliance Controls Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/compliance-controls-overview.md)
- [Assessment Profiles](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/assessment-profiles.md)
- [Assessment Results](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/assessment-results.md)
- [Categories](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/categories.md)
- [Compliance Assets](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/compliance-assets.md)
- [Controls](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/controls.md)
- [Export](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/export.md)
- [Import](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/import.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/reports.md)
- [Results](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/results.md)
- [Rules](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/rules.md)
- [Standards](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/standards.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/compliance-controls/models.md)
- [Data Security Posture Management overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/data-security-posture-management/data-security-posture-management-overview.md)
- [Inventory](https://cortex-docs.paloaltonetworks.com/xdr-5-api/data-security-posture-management/inventory.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/data-security-posture-management/models.md)
- [Detection Rules Management overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/detection-rules-management/detection-rules-management-overview.md)
- [Detection Rules](https://cortex-docs.paloaltonetworks.com/xdr-5-api/detection-rules-management/detection-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/detection-rules-management/models.md)
- [Disable Injection and Prevention Rules overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/disable-injection-and-prevention-rules/disable-injection-and-prevention-rules-overview.md)
- [Disable Injection and Prevention Rules Public API](https://cortex-docs.paloaltonetworks.com/xdr-5-api/disable-injection-and-prevention-rules/disable-injection-and-prevention-rules-public-api.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/disable-injection-and-prevention-rules/models.md)
- [Disable Prevention Rule overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/disable-prevention-rule/disable-prevention-rule-overview.md)
- [Disable Prevention Rule Public APIs](https://cortex-docs.paloaltonetworks.com/xdr-5-api/disable-prevention-rule/disable-prevention-rule-public-apis.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/disable-prevention-rule/models.md)
- [External Application Management overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/external-application-management/external-application-management-overview.md)
- [External Applications](https://cortex-docs.paloaltonetworks.com/xdr-5-api/external-application-management/external-applications.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/external-application-management/models.md)
- [Forensics overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/forensics/forensics-overview.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/xdr-5-api/forensics/forensics.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/forensics/models.md)
- [Cortex Platform IAM Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/identity-and-access-management-iam/cortex-platform-iam-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/xdr-5-api/identity-and-access-management-iam/api-keys.md)
- [Roles](https://cortex-docs.paloaltonetworks.com/xdr-5-api/identity-and-access-management-iam/roles.md)
- [Scopes](https://cortex-docs.paloaltonetworks.com/xdr-5-api/identity-and-access-management-iam/scopes.md)
- [User](https://cortex-docs.paloaltonetworks.com/xdr-5-api/identity-and-access-management-iam/user.md)
- [User Groups](https://cortex-docs.paloaltonetworks.com/xdr-5-api/identity-and-access-management-iam/user-groups.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/identity-and-access-management-iam/models.md)
- [Issues APIs overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/issues-apis/issues-apis-overview.md)
- [Issues](https://cortex-docs.paloaltonetworks.com/xdr-5-api/issues-apis/issues.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/issues-apis/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-5-api/issues-apis/issues-papi-tables.md)
- [Logging and Collection Service Management overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/logging-and-collection-service-management/logging-and-collection-service-management-overview.md)
- [CLCS Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/logging-and-collection-service-management/clcs-management.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/logging-and-collection-service-management/models.md)
- [Managed Services Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/managed-services/managed-services-overview.md)
- [Assignment](https://cortex-docs.paloaltonetworks.com/xdr-5-api/managed-services/assignment.md)
- [Comments](https://cortex-docs.paloaltonetworks.com/xdr-5-api/managed-services/comments.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/xdr-5-api/managed-services/reports.md)
- [Status](https://cortex-docs.paloaltonetworks.com/xdr-5-api/managed-services/status.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/managed-services/models.md)
- [Netscan overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/netscan/netscan-overview.md)
- [Vulnerability Network Scan Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/netscan/vulnerability-network-scan-management.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/netscan/models.md)
- [Policies overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/policies/policies-overview.md)
- [Cloud Security Policies](https://cortex-docs.paloaltonetworks.com/xdr-5-api/policies/cloud-security-policies.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/policies/models.md)
- [Restore Distributions overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/restore-distributions/restore-distributions-overview.md)
- [Restore Distributions](https://cortex-docs.paloaltonetworks.com/xdr-5-api/restore-distributions/restore-distributions.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/restore-distributions/models.md)
- [Unified Rules overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/unified-rules/unified-rules-overview.md)
- [Unified Rules](https://cortex-docs.paloaltonetworks.com/xdr-5-api/unified-rules/unified-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/unified-rules/models.md)
- [Vulnerability Intelligence Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-intelligence/vulnerability-intelligence-overview.md)
- [Affected Software](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-intelligence/affected-software.md)
- [Vulnerabilities](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-intelligence/vulnerabilities.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-intelligence/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-intelligence/vulnerability-intelligence-papi-tables.md)
- [Vulnerability Management Overview](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-management/vulnerability-management-overview.md)
- [Vulnerability Management](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-management/vulnerability-management.md)
- [Vulnerability Findings](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-management/vulnerability-findings.md)
- [Vulnerability Findings Snapshot](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-management/vulnerability-findings-snapshot.md)
- [Bring Your Own Scanner](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-management/bring-your-own-scanner.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-5-api/vulnerability-management/models.md)

## XDR 3.x APIs

- [Get started with Cortex XDR 3.x APIs](https://cortex-docs.paloaltonetworks.com/xdr-3-api/get-started-with-cortex-xdr-apis.md)
- [Run XQL Query APIs](https://cortex-docs.paloaltonetworks.com/xdr-3-api/run-xql-query-apis.md)
- [Cortex XDR APIs Overview](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/cortex-xdr-apis-overview.md)
- [Authentication Settings](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/authentication-settings.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/audit-log.md)
- [Dataset Management](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/dataset-management.md)
- [Endpoint Management](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/endpoint-management.md)
- [Incident Management](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/incident-management.md)
- [Lookup Datasets](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/lookup-datasets.md)
- [Response Action](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/response-action.md)
- [Rule Management](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/rule-management.md)
- [Script Execution](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/script-execution.md)
- [Syslog Servers](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/syslog-servers.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/system-management.md)
- [XQL Query](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/xql-query.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-3-api/cortex-xdr-3.x-apis/cortex-xdr-tables.md)
- [Broker VM (Tenant-Side) overview](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/broker-vm-tenant-overview.md)
- [Brokers](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/brokers.md)
- [Actions](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/actions.md)
- [Install images](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/install-images.md)
- [Applets](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/applets.md)
- [Remote log bundle](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/remote-log-bundle.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xdr-3-api/broker-vm-tenant-side/broker-papi-tables.md)

## XSIAM APIs

- [Get started with Cortex XSIAM APIs](https://cortex-docs.paloaltonetworks.com/xsiam-api/get-started-with-cortex-apis.md)
- [What's new in this release](https://cortex-docs.paloaltonetworks.com/xsiam-api/api-release-notes.md)
- [Create a new API key](https://cortex-docs.paloaltonetworks.com/xsiam-api/create-a-new-api-key.md)
- [Get your Cortex XSIAM API key ID](https://cortex-docs.paloaltonetworks.com/xsiam-api/get-your-cortex-api-key-id.md)
- [Get your FQDN](https://cortex-docs.paloaltonetworks.com/xsiam-api/get-your-fqdn.md)
- [Make your first API call](https://cortex-docs.paloaltonetworks.com/xsiam-api/make-your-first-api-call.md)
- [Understand Cortex XSIAM licenses](https://cortex-docs.paloaltonetworks.com/xsiam-api/understand-cortex-xsiam-licenses.md)
- [Cortex XSIAM Platform Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/cortex-xsiam-platform-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/api-keys.md)
- [Asset Groups](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/asset-groups.md)
- [Asset Inventory](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/asset-inventory.md)
- [Attack Surface Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/attack-surface-management.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/audit-log.md)
- [Authentication Settings](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/authentication-settings.md)
- [BIOCs](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/biocs.md)
- [Correlation Rules](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/correlation-rules.md)
- [Cortex CLI](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/cortex-cli.md)
- [Dashboards](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/dashboards.md)
- [Dataset Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/dataset-management.md)
- [Endpoint Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/endpoint-management.md)
- [IOCs](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/iocs.md)
- [Lookup Datasets](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/lookup-datasets.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/playbooks.md)
- [Query Library](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/query-library.md)
- [Response Action](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/response-action.md)
- [Scheduled Queries](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/scheduled-queries.md)
- [Script Execution](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/script-execution.md)
- [Scripts](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/scripts.md)
- [Syslog Servers](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/syslog-servers.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/system-management.md)
- [Widgets](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/widgets.md)
- [XQL Query](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/xql-query.md)
- [XQL User Datasets](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/xql-user-datasets.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/models.md)
- [Run XQL query APIs](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/run-xql-query-apis.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xsiam-api/cortex-platform/cortex-platform-papi-tables.md)
- [Agent Configuration Settings overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/agent-configuration-settings/agent-configuration-settings-overview.md)
- [Agent Configurations](https://cortex-docs.paloaltonetworks.com/xsiam-api/agent-configuration-settings/agent-configurations.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/agent-configuration-settings/models.md)
- [Alert Notification Rules overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/alert-notification-rules/alert-notification-rules-overview.md)
- [Alert Notification Rules](https://cortex-docs.paloaltonetworks.com/xsiam-api/alert-notification-rules/alert-notification-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/alert-notification-rules/models.md)
- [ASPM, CI/CD, and Application Security Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/aspm-cicd-and-application-security-overview.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/appsec-papi-tables.md)
- [Billing](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/billing.md)
- [Applications](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/applications.md)
- [Criteria](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/criteria.md)
- [Data Sources](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/data-sources.md)
- [Policies](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/policies.md)
- [Package Explorer](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/package-explorer.md)
- [Repositories](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/repositories.md)
- [Remediations](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/remediations.md)
- [Rules](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/rules.md)
- [SBOM Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/sbom-management.md)
- [Scan Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/scan-management.md)
- [Cloud Coverage](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/cloud-coverage.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/aspm-cicd-and-application-security/models.md)
- [Asset Compliance overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/asset-compliance/asset-compliance-overview.md)
- [Control Findings](https://cortex-docs.paloaltonetworks.com/xsiam-api/asset-compliance/control-findings.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/asset-compliance/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xsiam-api/asset-compliance/asset-compliance-papi-tables.md)
- [Broker VM (On-Appliance) overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-on-appliance/broker-vm-appliance-overview.md)
- [Auth (bootstrap)](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-on-appliance/auth-bootstrap.md)
- [Registration](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-on-appliance/registration.md)
- [Network configuration](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-on-appliance/network-configuration.md)
- [Local log bundle](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-on-appliance/local-log-bundle.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-on-appliance/models.md)
- [Broker VM (Tenant-Side) overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/broker-vm-tenant-overview.md)
- [Brokers](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/brokers.md)
- [Actions](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/actions.md)
- [Install images](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/install-images.md)
- [Applets](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/applets.md)
- [Remote log bundle](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/remote-log-bundle.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xsiam-api/broker-vm-tenant-side/broker-papi-tables.md)
- [Cases APIs overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/cases-apis/cases-apis-overview.md)
- [Cases](https://cortex-docs.paloaltonetworks.com/xsiam-api/cases-apis/cases.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/cases-apis/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xsiam-api/cases-apis/cases-papi-tables.md)
- [Cloud Infrastructure Entitlement Management (CIEM) overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-infrastructure-entitlement-management-ciem/cloud-infrastructure-entitlement-management-ciem-overview.md)
- [CIEM](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-infrastructure-entitlement-management-ciem/ciem.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-infrastructure-entitlement-management-ciem/models.md)
- [Cloud Onboarding API overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-onboarding/cloud-onboarding-overview.md)
- [Cloud Instance Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-onboarding/cloud-instance-management.md)
- [Cloud Account Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-onboarding/cloud-account-management.md)
- [Outpost Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-onboarding/outpost-management.md)
- [General](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-onboarding/general.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-onboarding/models.md)
- [Cloud Workload Protection Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-workload-protection/cloud-workload-protection-overview.md)
- [Policies](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-workload-protection/policies.md)
- [SBOM](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-workload-protection/sbom.md)
- [Registry Onboarding](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-workload-protection/registry-onboarding.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-workload-protection/models.md)
- [Compliance Controls Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/compliance-controls-overview.md)
- [Assessment Profiles](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/assessment-profiles.md)
- [Assessment Results](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/assessment-results.md)
- [Categories](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/categories.md)
- [Compliance Assets](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/compliance-assets.md)
- [Controls](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/controls.md)
- [Export](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/export.md)
- [Import](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/import.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/reports.md)
- [Results](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/results.md)
- [Rules](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/rules.md)
- [Standards](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/standards.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/compliance-controls/models.md)
- [Data Security Posture Management overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/data-security-posture-management/data-security-posture-management-overview.md)
- [Data Security Posture Management APIs](https://cortex-docs.paloaltonetworks.com/xsiam-api/data-security-posture-management/data-security-posture-management-apis.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/data-security-posture-management/models.md)
- [Disable Injection and Prevention Rules overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/disable-injection-and-prevention-rules/disable-injection-and-prevention-rules-overview.md)
- [Disable Injection and Prevention Rules Public API](https://cortex-docs.paloaltonetworks.com/xsiam-api/disable-injection-and-prevention-rules/disable-injection-and-prevention-rules-public-api.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/disable-injection-and-prevention-rules/models.md)
- [Disable Prevention Rule overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/disable-prevention-rule/disable-prevention-rule-overview.md)
- [Disable Prevention Rule Public APIs](https://cortex-docs.paloaltonetworks.com/xsiam-api/disable-prevention-rule/disable-prevention-rule-public-apis.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/disable-prevention-rule/models.md)
- [External Application Management overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/external-application-management/external-application-management-overview.md)
- [External Applications](https://cortex-docs.paloaltonetworks.com/xsiam-api/external-application-management/external-applications.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/external-application-management/models.md)
- [Forensics overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/forensics/forensics-overview.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/xsiam-api/forensics/forensics.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/forensics/models.md)
- [Cortex Platform IAM Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/identity-and-access-management-iam/cortex-platform-iam-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/xsiam-api/identity-and-access-management-iam/api-keys.md)
- [Roles](https://cortex-docs.paloaltonetworks.com/xsiam-api/identity-and-access-management-iam/roles.md)
- [Scopes](https://cortex-docs.paloaltonetworks.com/xsiam-api/identity-and-access-management-iam/scopes.md)
- [User](https://cortex-docs.paloaltonetworks.com/xsiam-api/identity-and-access-management-iam/user.md)
- [User Groups](https://cortex-docs.paloaltonetworks.com/xsiam-api/identity-and-access-management-iam/user-groups.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/identity-and-access-management-iam/models.md)
- [Integrations overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/integrations/integrations-overview.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/xsiam-api/integrations/integrations.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/integrations/models.md)
- [Issues APIs overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/issues-apis/issues-apis-overview.md)
- [Issues](https://cortex-docs.paloaltonetworks.com/xsiam-api/issues-apis/issues.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/issues-apis/models.md)
- [Logging and Collection Service Management overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/logging-and-collection-service-management/logging-and-collection-service-management-overview.md)
- [CLCS Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/logging-and-collection-service-management/clcs-management.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/logging-and-collection-service-management/models.md)
- [Managed Services Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/managed-services/managed-services-overview.md)
- [Assignment](https://cortex-docs.paloaltonetworks.com/xsiam-api/managed-services/assignment.md)
- [Comments](https://cortex-docs.paloaltonetworks.com/xsiam-api/managed-services/comments.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/xsiam-api/managed-services/reports.md)
- [Status](https://cortex-docs.paloaltonetworks.com/xsiam-api/managed-services/status.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/managed-services/models.md)
- [Netscan overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/netscan/netscan-overview.md)
- [Vulnerability Network Scan Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/netscan/vulnerability-network-scan-management.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/netscan/models.md)
- [Policies overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/policies/policies-overview.md)
- [Cloud Security Policies](https://cortex-docs.paloaltonetworks.com/xsiam-api/policies/cloud-security-policies.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/policies/models.md)
- [Restore Distributions overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/restore-distributions/restore-distributions-overview.md)
- [Restore Distributions](https://cortex-docs.paloaltonetworks.com/xsiam-api/restore-distributions/restore-distributions.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/restore-distributions/models.md)
- [Unified Rules overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/unified-rules/unified-rules-overview.md)
- [Unified Rules](https://cortex-docs.paloaltonetworks.com/xsiam-api/unified-rules/unified-rules.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/unified-rules/models.md)
- [Vulnerability Intelligence Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-intelligence/vulnerability-intelligence-overview.md)
- [Affected Software](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-intelligence/affected-software.md)
- [Vulnerabilities](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-intelligence/vulnerabilities.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-intelligence/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-intelligence/vulnerability-intelligence-papi-tables.md)
- [Vulnerability Management Overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-management/vulnerability-management-overview.md)
- [Vulnerability Management](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-management/vulnerability-management.md)
- [Vulnerability Findings](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-management/vulnerability-findings.md)
- [Vulnerability Findings Snapshot](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-management/vulnerability-findings-snapshot.md)
- [Bring Your Own Scanner](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-management/bring-your-own-scanner.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/vulnerability-management/models.md)
- [Forensics](https://cortex-docs.paloaltonetworks.com/xsiam-api/forensics-1/forensics.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/forensics-1/models.md)
- [Cloud Consumption Dashboard API overview](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-consumption-dashboard/cloud-consumption-overview.md)
- [Cloud Consumption Dashboard](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-consumption-dashboard/cloud-consumption-dashboard.md): Retrieve workload consumption data per asset type, over time, and in a paginated details grid.
- [Licensing](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-consumption-dashboard/licensing.md): Retrieve tenant license entitlements and add-on information.
- [Models](https://cortex-docs.paloaltonetworks.com/xsiam-api/cloud-consumption-dashboard/models.md)

## XSOAR 8.x APIs

- [Get started with Cortex XSOAR 8.x APIs](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/get-started-with-cortex-xsoar-8-apis.md)
- [Changes in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/changes-in-this-release.md)
- [Create a new API key](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/create-a-new-api-key.md)
- [Get your Cortex XSOAR API key ID](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/get-your-cortex-xsoar-api-key-id.md)
- [Get your FQDN](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/get-your-fqdn.md)
- [Make your first API call](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/make-your-first-api-call.md)
- [Optimistic locking and versioning](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/optimistic-locking-and-versioning.md)
- [Cortex XSOAR 8 APIs Overview](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/cortex-xsoar-8-apis-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/api-keys.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/audit-log.md)
- [Authentication Settings](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/authentication-settings.md)
- [Content Packs](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/content-packs.md)
- [Dashboards](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/dashboards.md)
- [Engines](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/engines.md)
- [Entry](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/entry.md)
- [Evidence](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/evidence.md)
- [Incident Fields](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/incident-fields.md)
- [Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/incidents.md)
- [Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/indicators.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/integrations.md)
- [Investigations](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/investigations.md)
- [Jobs](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/jobs.md)
- [Lists](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/lists.md)
- [Multi Tenant](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/multi-tenant.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/playbooks.md)
- [Remote Repository](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/remote-repository.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/reports.md)
- [Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/scripts.md)
- [Syslog Servers](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/syslog-servers.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/system-management.md)
- [Widgets](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/widgets.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/models.md)
- [Additional References](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/cortex-xsoar-8.x-apis/xsoar-8-tables.md)

## XSOAR 6.x APIs

- [Get started with Cortex XSOAR 6.x APIs](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/get-started-with-cortex-xsoar-6-apis.md)
- [Create a new API key](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/create-a-new-api-key.md)
- [Make your first API call](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/make-your-first-api-call.md)
- [Optimistic locking and versioning](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/optimistic-locking-and-versioning.md)
- [Cortex XSOAR 6 APIs Overview](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/cortex-xsoar-6-apis-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/api-keys.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/audit-log.md)
- [Authentication](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/authentication.md)
- [Content Packs](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/content-packs.md)
- [Dashboards](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/dashboards.md)
- [Entry](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/entry.md)
- [Evidence](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/evidence.md)
- [Incident Fields](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/incident-fields.md)
- [Incidents](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/incidents.md)
- [Indicators](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/indicators.md)
- [Integrations](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/integrations.md)
- [Investigations](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/investigations.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/playbooks.md)
- [Reports](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/reports.md)
- [Scripts](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/scripts.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/system-management.md)
- [Widgets](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/widgets.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/cortex-xsoar-6.x-apis/models.md)

## AgentiX APIs

- [Get started with Cortex AgentiX APIs](https://cortex-docs.paloaltonetworks.com/agentix-api/get-started-with-cortex-apis.md)
- [Create a new API key](https://cortex-docs.paloaltonetworks.com/agentix-api/readme.md)
- [Get your Cortex AgentiX API key ID](https://cortex-docs.paloaltonetworks.com/agentix-api/get-your-cortex-api-key-id.md)
- [Get your FQDN](https://cortex-docs.paloaltonetworks.com/agentix-api/get-your-fqdn.md)
- [Make your first API call](https://cortex-docs.paloaltonetworks.com/agentix-api/make-your-first-api-call.md)
- [Run XQL query APIs](https://cortex-docs.paloaltonetworks.com/agentix-api/run-xql-query-apis.md)
- [Understand Cortex AgentiX licenses](https://cortex-docs.paloaltonetworks.com/agentix-api/understand-cortex-agentix-licenses.md)
- [Cortex AgentiX Platform Overview](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/cortex-agentix-platform-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/api-keys.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/audit-log.md)
- [Authentication Settings](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/authentication-settings.md)
- [Cases](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/cases.md)
- [Correlation Rules](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/correlation-rules.md)
- [Dashboards](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/dashboards.md)
- [Dataset Management](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/dataset-management.md)
- [Issues](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/issues.md)
- [Lookup Datasets](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/lookup-datasets.md)
- [Playbooks](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/playbooks.md)
- [Query Library](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/query-library.md)
- [Scheduled Queries](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/scheduled-queries.md)
- [Script Execution](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/script-execution.md)
- [Scripts](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/scripts.md)
- [Syslog Servers](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/syslog-servers.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/system-management.md)
- [Widgets](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/widgets.md)
- [XQL Query](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/xql-query.md)
- [Models](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-agentix/models.md)
- [Cortex Platform IAM Overview](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-platform-iam/cortex-platform-iam-overview.md)
- [API Keys](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-platform-iam/api-keys.md)
- [Roles](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-platform-iam/roles.md)
- [Scopes](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-platform-iam/scopes.md)
- [User](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-platform-iam/user.md)
- [User Groups](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-platform-iam/user-groups.md)
- [Models](https://cortex-docs.paloaltonetworks.com/agentix-api/cortex-platform-iam/models.md)

## Xpanse APIs

- [Get Started with Xpanse APIs](https://cortex-docs.paloaltonetworks.com/xpanse-api/get-started-with-cortex-xpanse-apis.md)
- [What's new in this release](https://cortex-docs.paloaltonetworks.com/xpanse-api/changes-to-the-api-in-this-release.md)
- [Cortex Xpanse API Overview](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/cortex-xpanse-api-overview.md)
- [Asset Management](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/asset-management.md)
- [Attack Surface Rules](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/attack-surface-rules.md)
- [Audit Log](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/audit-log.md)
- [Incident Management](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/incident-management.md)
- [Remediation Path Rules](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/remediation-path-rules.md)
- [Remediation Scanning](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/remediation-scanning.md)
- [System Management](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/system-management.md)
- [Tag Management](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/tag-management.md)
- [Vulnerability Testing](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/vulnerability-testing.md)
- [Models](https://cortex-docs.paloaltonetworks.com/xpanse-api/xpanse-public-api/models.md)

## XQL Schema Reference

- [Cortex XQL Schema Reference Guide](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/readme.md)
- [XDR\_DATA Fields by Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor.md)
- [Action Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor/action-actor.md)
- [Actor Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor/actor-actor.md)
- [Causality Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor/causality-actor.md)
- [DST Action Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor/dst-action-actor.md)
- [DST Causality Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor/dst-causality-actor.md)
- [DST OS Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor/dst-os-actor.md)
- [OS Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor/os-actor.md)
- [XDR\_DATA Fields](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields.md)

## XSIAM Data Model Schema

- [XSIAM Data Model Schema](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/readme.md)
- [XDM Aliases](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases.md)
- [XDM\_ALIAS.ipv4](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/ipv4.md)
- [XDM\_ALIAS.ipv6](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/ipv6.md)
- [XDM\_ALIAS.ip](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/ip.md)
- [XDM\_ALIAS.user](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/user.md)
- [XDM\_ALIAS.identity\_type](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/identity-type.md)
- [XDM\_ALIAS.file](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/file.md)
- [XDM\_ALIAS.file\_hash](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/file-hash.md)
- [XDM\_ALIAS.domain](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/domain.md)
- [XDM\_ALIAS.hostname](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/hostname.md)
- [XDM\_ALIAS.country](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/country.md)
- [XDM\_ALIAS.resource](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/resource.md)
- [XDM\_ALIAS.cloud\_project](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/cloud-project.md)
- [XDM\_ALIAS.cloud\_provider](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/cloud-provider.md)
- [XDM\_ALIAS.cloud\_zone](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases/cloud-zone.md)
- [XDM Consts](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts.md)
- [XDM\_CONST.DEPLOYMENT\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/deployment-status.md)
- [XDM\_CONST.DEPLOYMENT\_PROVISIONING\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/deployment-provisioning-status.md)
- [XDM\_CONST.DEPLOYMENT\_LAUNCH\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/deployment-launch-type.md)
- [XDM\_CONST.EVENT\_TAG](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/event-tag.md)
- [XDM\_CONST.OUTCOME](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/outcome.md)
- [XDM\_CONST.PRIVILEGE\_LEVEL](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/privilege-level.md)
- [XDM\_CONST.USER\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/user-type.md)
- [XDM\_CONST.FORMAT\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/format-type.md)
- [XDM\_CONST.KUBERNETES\_RESOURCE\_CATEGORY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kubernetes-resource-category.md)
- [XDM\_CONST.KUBERNETES\_CONNECTOR\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kubernetes-connector-status.md)
- [XDM\_CONST.KUBERNETES\_PROFILE\_CAPABILITY\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kubernetes-profile-capability-status.md)
- [XDM\_CONST.KUBERNETES\_POD\_CONTAINER\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kubernetes-pod-container-type.md)
- [XDM\_CONST.KUBERNETES\_DISTRIBUTION](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kubernetes-distribution.md)
- [XDM\_CONST.KUBERNETES\_SETTINGS\_AUTO\_UPGRADE\_POLICY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kubernetes-settings-auto-upgrade-policy.md)
- [XDM\_CONST.IP\_PROTOCOL](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/ip-protocol.md)
- [XDM\_CONST.PROVIDER](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/provider.md)
- [XDM\_CONST.CLOUD\_PROVIDER](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/cloud-provider.md)
- [XDM\_CONST.DEVELOPMENT\_CYCLE\_STAGE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/development-cycle-stage.md)
- [XDM\_CONST.OS\_FAMILY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/os-family.md)
- [XDM\_CONST.AGENT\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/agent-type.md)
- [XDM\_CONST.SIGNATURE\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/signature-status.md)
- [XDM\_CONST.SECRET\_VALIDATION](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/secret-validation.md)
- [XDM\_CONST.APPSEC\_IMPACT](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/appsec-impact.md)
- [XDM\_CONST.IMAGE\_SPECIFICATION\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/image-specification-type.md)
- [XDM\_CONST.HOST\_STATE\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/host-state-type.md)
- [XDM\_CONST.REGISTRY\_VALUE\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/registry-value-type.md)
- [XDM\_CONST.IMAGE\_VISIBILITY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/image-visibility.md)
- [XDM\_CONST.HTTP\_METHOD](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/http-method.md)
- [XDM\_CONST.HTTP\_RSP\_CODE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/http-rsp-code.md)
- [XDM\_CONST.DHCP\_MESSAGE\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/dhcp-message-type.md)
- [XDM\_CONST.DCERPC\_OPERATION](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/dcerpc-operation.md)
- [XDM\_CONST.KERBEROS\_MSG\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kerberos-msg-type.md)
- [XDM\_CONST.KERBEROS\_PRINCIPAL\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kerberos-principal-type.md)
- [XDM\_CONST.KERBEROS\_KDC\_OPTION](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kerberos-kdc-option.md)
- [XDM\_CONST.KERBEROS\_ENCRYPTION\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kerberos-encryption-type.md)
- [XDM\_CONST.KERBEROS\_PA\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kerberos-pa-type.md)
- [XDM\_CONST.KERBEROS\_ERROR\_CODE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/kerberos-error-code.md)
- [XDM\_CONST.LDAP\_OPERATION](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/ldap-operation.md)
- [XDM\_CONST.LDAP\_SCOPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/ldap-scope.md)
- [XDM\_CONST.LDAP\_BIND\_AUTH\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/ldap-bind-auth-type.md)
- [XDM\_CONST.LOGON\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/logon-type.md)
- [XDM\_CONST.LOGON\_IMPERSONATION\_LEVEL](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/logon-impersonation-level.md)
- [XDM\_CONST.LOGON\_ASSIGNED\_RIGHT](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/logon-assigned-right.md)
- [XDM\_CONST.DB\_OPERATION](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/db-operation.md)
- [XDM\_CONST.MITRE\_TACTIC](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/mitre-tactic.md)
- [XDM\_CONST.MITRE\_TECHNIQUE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/mitre-technique.md)
- [XDM\_CONST.THREAT\_CATEGORY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/threat-category.md)
- [XDM\_CONST.URL\_CATEGORY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/url-category.md)
- [XDM\_CONST.DNS\_RESPONSE\_CODE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/dns-response-code.md)
- [XDM\_CONST.DNS\_RECORD\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/dns-record-type.md)
- [XDM\_CONST.OPERATION\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/operation-type.md)
- [XDM\_CONST.IDENTITY\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/identity-type.md)
- [XDM\_CONST.SCOPE\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/scope-type.md)
- [XDM\_CONST.LOG\_LEVEL](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/log-level.md)
- [XDM\_CONST.BACKUP\_ASSET\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/backup-asset-type.md)
- [XDM\_CONST.PACKAGE\_INSTALLATION\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/package-installation-type.md)
- [XDM\_CONST.IDENTITY\_PROVIDER](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/identity-provider.md)
- [XDM\_CONST.IDENTITY\_SECRET\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/identity-secret-status.md)
- [XDM\_CONST.IDENTITY\_ACCOUNT\_ACCESS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/identity-account-access.md)
- [XDM\_CONST.IDENTITY\_SECRET\_SERVICE\_SCOPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/identity-secret-service-scope.md)
- [XDM\_CONST.IDENTITY\_ACCESS\_LEVEL](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/identity-access-level.md)
- [XDM\_CONST.LICENSE\_CATEGORY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/license-category.md)
- [XDM\_CONST.ASSET\_GROUP\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/asset-group-type.md)
- [XDM\_CONST.OPERATIONAL\_RISK](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/operational-risk.md)
- [XDM\_CONST.MODEL\_ENDPOINT\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/model-endpoint-type.md)
- [XDM\_CONST.MODEL\_KIND](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/model-kind.md)
- [XDM\_CONST.MODEL\_FAMILY](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/model-family.md)
- [XDM\_CONST.SCAN\_SOURCE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/scan-source.md)
- [XDM\_CONST.ARCH](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/arch.md)
- [XDM\_CONST.DATABASE\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/database-type.md)
- [XDM\_CONST.BACKLOG\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/backlog-status.md)
- [XDM\_CONST.FINDING\_SOURCE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/finding-source.md)
- [XDM\_CONST.PARTITION\_ID\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/partition-id-type.md)
- [XDM\_CONST.ALERT\_STATUS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/alert-status.md)
- [XDM\_CONST.SECURITY\_CONTROL\_EFFECTIVENESS](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/security-control-effectiveness.md)
- [XDM\_CONST.DOMAIN\_MODES](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/domain-modes.md)
- [XDM\_CONST.TRUST\_DIRECTION](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/trust-direction.md)
- [XDM\_CONST.ENCRYPTION\_TYPE](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/encryption-type.md)
- [XDM Fieldsets](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fieldsets.md)
- [fieldset.xdm\_core](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fieldsets/xdm-core.md)
- [fieldset.xdm\_cloud](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fieldsets/xdm-cloud.md)
- [fieldset.xdm\_endpoint](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fieldsets/xdm-endpoint.md)
- [fieldset.xdm\_identity](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fieldsets/xdm-identity.md)
- [fieldset.xdm\_network](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fieldsets/xdm-network.md)
- [XDM Fields](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields.md)
- [xdm.session\_context\_id](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/session-context-id.md)
- [xdm.event](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/event.md)
- [xdm.source](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source.md)
- [xdm.source.host](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/host.md)
- [xdm.source.agent](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/agent.md)
- [xdm.source.identity](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity.md)
- [xdm.source.identity.idp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/idp.md)
- [xdm.source.identity.app\_registration](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/app-registration.md)
- [xdm.source.identity.app\_registration.owners](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/app-registration/owners.md)
- [xdm.source.identity.group](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/group.md)
- [xdm.source.identity.policy](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/policy.md)
- [xdm.source.identity.policy.security\_properties](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/policy/security-properties.md)
- [xdm.source.identity.secret](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/secret.md)
- [xdm.source.identity.access\_keys](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/access-keys.md)
- [xdm.source.identity.access\_statistics](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/access-statistics.md)
- [xdm.source.identity.key\_management](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/identity/key-management.md)
- [xdm.source.user](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user.md)
- [xdm.source.user.idp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/idp.md)
- [xdm.source.user.app\_registration](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/app-registration.md)
- [xdm.source.user.app\_registration.owners](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/app-registration/owners.md)
- [xdm.source.user.group](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/group.md)
- [xdm.source.user.policy](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/policy.md)
- [xdm.source.user.policy.security\_properties](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/policy/security-properties.md)
- [xdm.source.user.secret](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/secret.md)
- [xdm.source.user.access\_keys](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/access-keys.md)
- [xdm.source.user.access\_statistics](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/access-statistics.md)
- [xdm.source.user.key\_management](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/user/key-management.md)
- [xdm.source.location](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/location.md)
- [xdm.source.process](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/process.md)
- [xdm.source.process.executable](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/process/executable.md)
- [xdm.source.process.executable.permissions](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/process/executable/permissions.md)
- [xdm.source.process.executable.position](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/process/executable/position.md)
- [xdm.source.process.executable.position.start](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/process/executable/position/start.md)
- [xdm.source.process.executable.position.end](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/process/executable/position/end.md)
- [xdm.source.application](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/application.md)
- [xdm.source.asn](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/asn.md)
- [xdm.source.cloud](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/cloud.md)
- [xdm.source.cloud.function](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/cloud/function.md)
- [xdm.source.virtualization](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/virtualization.md)
- [xdm.source.virtualization.data\_center](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/virtualization/data-center.md)
- [xdm.source.virtualization.data\_store](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/virtualization/data-store.md)
- [xdm.source.virtualization.task](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/virtualization/task.md)
- [xdm.source.virtualization.vm](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/source/virtualization/vm.md)
- [xdm.intermediate](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate.md)
- [xdm.intermediate.host](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/host.md)
- [xdm.intermediate.location](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/location.md)
- [xdm.intermediate.agent](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/agent.md)
- [xdm.intermediate.identity](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity.md)
- [xdm.intermediate.identity.idp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/idp.md)
- [xdm.intermediate.identity.app\_registration](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/app-registration.md)
- [xdm.intermediate.identity.app\_registration.owners](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/app-registration/owners.md)
- [xdm.intermediate.identity.group](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/group.md)
- [xdm.intermediate.identity.policy](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/policy.md)
- [xdm.intermediate.identity.policy.security\_properties](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/policy/security-properties.md)
- [xdm.intermediate.identity.secret](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/secret.md)
- [xdm.intermediate.identity.access\_keys](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/access-keys.md)
- [xdm.intermediate.identity.access\_statistics](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/access-statistics.md)
- [xdm.intermediate.identity.key\_management](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/identity/key-management.md)
- [xdm.intermediate.user](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user.md)
- [xdm.intermediate.user.idp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/idp.md)
- [xdm.intermediate.user.app\_registration](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/app-registration.md)
- [xdm.intermediate.user.app\_registration.owners](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/app-registration/owners.md)
- [xdm.intermediate.user.group](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/group.md)
- [xdm.intermediate.user.policy](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/policy.md)
- [xdm.intermediate.user.policy.security\_properties](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/policy/security-properties.md)
- [xdm.intermediate.user.secret](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/secret.md)
- [xdm.intermediate.user.access\_keys](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/access-keys.md)
- [xdm.intermediate.user.access\_statistics](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/access-statistics.md)
- [xdm.intermediate.user.key\_management](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/user/key-management.md)
- [xdm.intermediate.process](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/process.md)
- [xdm.intermediate.process.executable](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/process/executable.md)
- [xdm.intermediate.process.executable.permissions](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/process/executable/permissions.md)
- [xdm.intermediate.process.executable.position](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/process/executable/position.md)
- [xdm.intermediate.process.executable.position.start](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/process/executable/position/start.md)
- [xdm.intermediate.process.executable.position.end](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/process/executable/position/end.md)
- [xdm.intermediate.application](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/application.md)
- [xdm.intermediate.asn](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/asn.md)
- [xdm.intermediate.cloud](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/cloud.md)
- [xdm.intermediate.cloud.function](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/intermediate/cloud/function.md)
- [xdm.target](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target.md)
- [xdm.target.host](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/host.md)
- [xdm.target.agent](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/agent.md)
- [xdm.target.identity](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity.md)
- [xdm.target.identity.idp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/idp.md)
- [xdm.target.identity.app\_registration](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/app-registration.md)
- [xdm.target.identity.app\_registration.owners](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/app-registration/owners.md)
- [xdm.target.identity.group](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/group.md)
- [xdm.target.identity.policy](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/policy.md)
- [xdm.target.identity.policy.security\_properties](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/policy/security-properties.md)
- [xdm.target.identity.secret](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/secret.md)
- [xdm.target.identity.access\_keys](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/access-keys.md)
- [xdm.target.identity.access\_statistics](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/access-statistics.md)
- [xdm.target.identity.key\_management](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/identity/key-management.md)
- [xdm.target.user](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user.md)
- [xdm.target.user.idp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/idp.md)
- [xdm.target.user.app\_registration](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/app-registration.md)
- [xdm.target.user.app\_registration.owners](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/app-registration/owners.md)
- [xdm.target.user.group](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/group.md)
- [xdm.target.user.policy](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/policy.md)
- [xdm.target.user.policy.security\_properties](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/policy/security-properties.md)
- [xdm.target.user.secret](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/secret.md)
- [xdm.target.user.access\_keys](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/access-keys.md)
- [xdm.target.user.access\_statistics](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/access-statistics.md)
- [xdm.target.user.key\_management](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/user/key-management.md)
- [xdm.target.location](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/location.md)
- [xdm.target.process](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/process.md)
- [xdm.target.process.executable](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/process/executable.md)
- [xdm.target.process.executable.permissions](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/process/executable/permissions.md)
- [xdm.target.process.executable.position](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/process/executable/position.md)
- [xdm.target.process.executable.position.start](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/process/executable/position/start.md)
- [xdm.target.process.executable.position.end](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/process/executable/position/end.md)
- [xdm.target.application](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/application.md)
- [xdm.target.asn](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/asn.md)
- [xdm.target.cloud](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/cloud.md)
- [xdm.target.cloud.function](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/cloud/function.md)
- [xdm.target.module](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/module.md)
- [xdm.target.module.permissions](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/module/permissions.md)
- [xdm.target.module.position](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/module/position.md)
- [xdm.target.module.position.start](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/module/position/start.md)
- [xdm.target.module.position.end](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/module/position/end.md)
- [xdm.target.registry](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/registry.md)
- [xdm.target.registry\_before](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/registry-before.md)
- [xdm.target.file](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file.md)
- [xdm.target.file.permissions](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file/permissions.md)
- [xdm.target.file.position](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file/position.md)
- [xdm.target.file.position.start](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file/position/start.md)
- [xdm.target.file.position.end](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file/position/end.md)
- [xdm.target.file\_before](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file-before.md)
- [xdm.target.file\_before.permissions](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file-before/permissions.md)
- [xdm.target.file\_before.position](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file-before/position.md)
- [xdm.target.file\_before.position.start](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file-before/position/start.md)
- [xdm.target.file\_before.position.end](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/file-before/position/end.md)
- [xdm.target.resource](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/resource.md)
- [xdm.target.resource\_before](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/resource-before.md)
- [xdm.target.virtualization](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/virtualization.md)
- [xdm.target.virtualization.data\_center](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/virtualization/data-center.md)
- [xdm.target.virtualization.data\_store](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/virtualization/data-store.md)
- [xdm.target.virtualization.task](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/virtualization/task.md)
- [xdm.target.virtualization.vm](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/target/virtualization/vm.md)
- [xdm.observer](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/observer.md)
- [xdm.alert](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/alert.md)
- [xdm.network](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network.md)
- [xdm.network.icmp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/icmp.md)
- [xdm.network.dhcp](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/dhcp.md)
- [xdm.network.dns](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/dns.md)
- [xdm.network.dns.dns\_question](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/dns/dns-question.md)
- [xdm.network.dns.dns\_resource\_record](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/dns/dns-resource-record.md)
- [xdm.network.http](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/http.md)
- [xdm.network.http.request](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/http/request.md)
- [xdm.network.http.request.headers](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/http/request/headers.md)
- [xdm.network.http.request.query\_params](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/http/request/query-params.md)
- [xdm.network.http.response](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/http/response.md)
- [xdm.network.http.response.headers](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/http/response/headers.md)
- [xdm.network.http.http\_header](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/http/http-header.md)
- [xdm.network.tls](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/tls.md)
- [xdm.network.tls.client\_certificate](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/tls/client-certificate.md)
- [xdm.network.tls.client\_certificate.subject\_details](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/tls/client-certificate/subject-details.md)
- [xdm.network.tls.client\_certificate.issuer\_details](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/tls/client-certificate/issuer-details.md)
- [xdm.network.tls.server\_certificate](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/tls/server-certificate.md)
- [xdm.network.tls.server\_certificate.subject\_details](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/tls/server-certificate/subject-details.md)
- [xdm.network.tls.server\_certificate.issuer\_details](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/tls/server-certificate/issuer-details.md)
- [xdm.network.dcerpc](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/dcerpc.md)
- [xdm.network.ldap](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/ldap.md)
- [xdm.network.vpn](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/network/vpn.md)
- [xdm.auth](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/auth.md)
- [xdm.auth.kerberos\_tgt](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/auth/kerberos-tgt.md)
- [xdm.auth.kerberos\_tgs](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/auth/kerberos-tgs.md)
- [xdm.auth.ntlm](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/auth/ntlm.md)
- [xdm.auth.mfa](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/auth/mfa.md)
- [xdm.logon](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/logon.md)
- [xdm.database](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/database.md)
- [xdm.email](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/email.md)
- [xdm.email.attachment](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/email/attachment.md)
- [xdm.email.attachment.permissions](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/email/attachment/permissions.md)
- [xdm.email.attachment.position](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/email/attachment/position.md)
- [xdm.email.attachment.position.start](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/email/attachment/position/start.md)
- [xdm.email.attachment.position.end](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields/email/attachment/position/end.md)
- [XDM System Fields](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/system-fields.md)
- [\_insert\_time](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/system-fields/insert-time.md)
- [\_time](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/system-fields/time.md)
- [\_vendor](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/system-fields/vendor.md)
- [\_product](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/system-fields/product.md)
- [\_reception\_time](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/system-fields/reception-time.md)

## Linux Kernel Versions

- [Linux Kernel Versions](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/readme.md)
- [AlmaLinux](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/almalinux.md)
- [AlmaLinux \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/almalinux/x86_64.md)
- [AlmaLinux 8 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/almalinux/x86_64/8.md)
- [AlmaLinux 9 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/almalinux/x86_64/9.md)
- [AlmaLinux 10 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/almalinux/x86_64/10.md)
- [Amazon Linux](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux.md)
- [Amazon Linux \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux/x86_64.md)
- [Amazon Linux 2018 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux/x86_64/2018.md)
- [Amazon Linux 2](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2.md)
- [Amazon Linux 2 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/x86_64.md)
- [Amazon Linux 2 2017 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/x86_64/2017.md)
- [Amazon Linux 2 2018 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/x86_64/2018.md)
- [Amazon Linux 2 2019 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/x86_64/2019.md)
- [Amazon Linux 2 2020 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/x86_64/2020.md)
- [Amazon Linux 2 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/aarch64.md)
- [Amazon Linux 2 2017 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/aarch64/2017.md)
- [Amazon Linux 2 2018 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/aarch64/2018.md)
- [Amazon Linux 2 2019 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/aarch64/2019.md)
- [Amazon Linux 2 2020 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2/aarch64/2020.md)
- [Amazon Linux 2023](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2023.md)
- [Amazon Linux 2023 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2023/x86_64.md)
- [Amazon Linux 2023 2023 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2023/x86_64/2023.md)
- [Amazon Linux 2023 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2023/aarch64.md)
- [Amazon Linux 2023 2023 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/amazon-linux-2023/aarch64/2023.md)
- [CentOS](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos.md)
- [CentOS \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos/x86_64.md)
- [CentOS 6 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos/x86_64/6.md)
- [CentOS 7 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos/x86_64/7.md)
- [CentOS 8 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos/x86_64/8.md)
- [CentOS \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos/aarch64.md)
- [CentOS 7 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos/aarch64/7.md)
- [CentOS 8 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos/aarch64/8.md)
- [CentOS Stream](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos-stream.md)
- [CentOS Stream \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos-stream/x86_64.md)
- [CentOS Stream 8 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos-stream/x86_64/8.md)
- [CentOS Stream 9 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos-stream/x86_64/9.md)
- [CentOS Stream \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos-stream/aarch64.md)
- [CentOS Stream 8 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/centos-stream/aarch64/8.md)
- [Debian](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian.md)
- [Debian \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/x86_64.md)
- [Debian 9 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/x86_64/9.md)
- [Debian 10 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/x86_64/10.md)
- [Debian 11 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/x86_64/11.md)
- [Debian 12 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/x86_64/12.md)
- [Debian 13 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/x86_64/13.md)
- [Debian \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/aarch64.md)
- [Debian 10 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/debian/aarch64/10.md)
- [OpenSUSE](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/opensuse.md)
- [OpenSUSE \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/opensuse/x86_64.md)
- [OpenSUSE 15 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/opensuse/x86_64/15.md)
- [Oracle Linux](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux.md)
- [Oracle Linux \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/x86_64.md)
- [Oracle Linux 6 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/x86_64/6.md)
- [Oracle Linux 7 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/x86_64/7.md)
- [Oracle Linux 8 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/x86_64/8.md)
- [Oracle Linux 9 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/x86_64/9.md)
- [Oracle Linux 10 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/x86_64/10.md)
- [Oracle Linux \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/aarch64.md)
- [Oracle Linux 8 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/aarch64/8.md)
- [Oracle Linux 9 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/aarch64/9.md)
- [Oracle Linux 10 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/oracle-linux/aarch64/10.md)
- [Red Hat Enterprise Linux (RHEL)](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel.md)
- [Red Hat Enterprise Linux (RHEL) \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/x86_64.md)
- [Red Hat Enterprise Linux (RHEL) 6 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/x86_64/6.md)
- [Red Hat Enterprise Linux (RHEL) 7 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/x86_64/7.md)
- [Red Hat Enterprise Linux (RHEL) 8 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/x86_64/8.md)
- [Red Hat Enterprise Linux (RHEL) 9 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/x86_64/9.md)
- [Red Hat Enterprise Linux (RHEL) 10 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/x86_64/10.md)
- [Red Hat Enterprise Linux (RHEL) \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/aarch64.md)
- [Red Hat Enterprise Linux (RHEL) 8 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/aarch64/8.md)
- [Red Hat Enterprise Linux (RHEL) 9 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/aarch64/9.md)
- [Red Hat Enterprise Linux (RHEL) 10 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/red-hat-enterprise-linux-rhel/aarch64/10.md)
- [Rocky Linux](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/rocky-linux.md)
- [Rocky Linux \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/rocky-linux/x86_64.md)
- [Rocky Linux 8 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/rocky-linux/x86_64/8.md)
- [Rocky Linux 9 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/rocky-linux/x86_64/9.md)
- [Rocky Linux 10 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/rocky-linux/x86_64/10.md)
- [Rocky Linux \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/rocky-linux/aarch64.md)
- [Rocky Linux 9 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/rocky-linux/aarch64/9.md)
- [SUSE Linux Enterprise Server](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/suse-linux-enterprise-server.md)
- [SUSE Linux Enterprise Server \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/suse-linux-enterprise-server/x86_64.md)
- [SUSE Linux Enterprise Server 11 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/suse-linux-enterprise-server/x86_64/11.md)
- [SUSE Linux Enterprise Server 12 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/suse-linux-enterprise-server/x86_64/12.md)
- [SUSE Linux Enterprise Server 15 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/suse-linux-enterprise-server/x86_64/15.md)
- [SUSE Linux Enterprise Server 16 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/suse-linux-enterprise-server/x86_64/16.md)
- [Ubuntu](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu.md)
- [Ubuntu \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64.md)
- [Ubuntu 12 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64/12.md)
- [Ubuntu 14 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64/14.md)
- [Ubuntu 16 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64/16.md)
- [Ubuntu 18 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64/18.md)
- [Ubuntu 20 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64/20.md)
- [Ubuntu 22 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64/22.md)
- [Ubuntu 24 \[x86\_64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/x86_64/24.md)
- [Ubuntu \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/aarch64.md)
- [Ubuntu 18 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/aarch64/18.md)
- [Ubuntu 20 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/aarch64/20.md)
- [Ubuntu 22 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/aarch64/22.md)
- [Ubuntu 24 \[aarch64\]](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/ubuntu/aarch64/24.md)

## Compatibility Matrix&#x20;

- [Where can I install the Cortex XDR agent?](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent.md)
- [Endpoint operating systems supported](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported.md)
- [Mac](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported/mac.md)
- [Windows](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported/windows.md)
- [Linux](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported/linux.md)
- [Cloud platforms supported with Cortex XDR agent](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/cloud-platforms-supported-with-cortex-xdr-agent.md)
- [Kubernetes platforms supported](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/kubernetes-platforms-supported.md)
- [Virtual applications supported](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/virtual-applications-supported.md)
- [Mobile operating systems supported with Cortex XDR](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/mobile-operating-systems-supported-with-cortex-xdr.md)
- [Cortex XDR agent compatibility with third-party security products](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr-agent-compatibility-with-third-party-security-products.md)
- [Third-party Windows security applications](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr-agent-compatibility-with-third-party-security-products/third-party-windows-security-applications.md)
- [Third-party Mac security applications](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr-agent-compatibility-with-third-party-security-products/third-party-mac-security-applications.md)
- [Third-party Linux security applications](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr-agent-compatibility-with-third-party-security-products/third-party-linux-security-applications.md)

## Cortex XSIAM Developer Guide

- [Getting Started](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme.md): Get started developing content for Cortex XSIAM.
- [Design](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/design.md): Plan out the content items you want to create for your own use or content packs that can be contributed to Marketplace.
- [Use Case Design for Cortex XSIAM](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/design/use-case-design-for-cortex-xsiam.md): Define your use case, how to improve your incident workflow and decrease the time and resources required for investigation.
- [Development scope](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/design/development-scope.md): Determine which content items to create based on your use case design.
- [Integration design](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/design/integration-design.md): Considerations for defining your integration so it functions correctly, is properly documented, and works well with other related content.
- [Design best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/design/design-best-practices.md): Design best practices for building an integration.
- [Content development environments](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments.md): Development environments and tools to help develop various content items.
- [IDE for script development](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/ide-for-script-development.md): Cortex XSIAM UI development environment for content development.
- [Set up a local development environment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/set-up-a-local-development-environment.md): How to set up an external dev environment to contribute a full integration.
- [Set up a GitHub Codespace environment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/set-up-a-github-codespace-environment.md)
- [Set up a containerized development environment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/set-up-a-containerized-development-environment.md)
- [Demisto SDK](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/demisto-sdk.md): Use the Demisto SDK Python library to facilitate the Cortex XSIAM content development process.
- [Visual Studio Code extension](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/visual-studio-code-extension.md): Use Visual Studio Code extension to design and author scripts and integrations for Cortex XSIAM directly from VS Code.
- [Frequently asked questions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/frequently-asked-questions.md): FAQs for Cortex XSIAM development.
- [Integrations and scripts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts.md): Learn about integration and script components, developing, and testing.
- [Components](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/components.md): Learn about integration and script directory structure, metadata YAML file, parameter types, integration description file, integration logo standards, and README file.
- [Integration directory structure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/components/integration-directory-structure.md): Integrations are stored in the Integrations directory and contain a specific set of files.
- [Integration metadata YAML file](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/components/integration-metadata-yaml-file.md): The YAML file includes all the metadata for integrations and scripts.
- [Integration and script parameter types](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/components/integration-and-script-parameter-types.md): Available parameter types for configuring integration instances and scripts.
- [Integration description file](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/components/integration-description-file.md): The integration description file includes use case and integration instance configuration information.
- [Integration Logo Requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/components/integration-logo-requirements.md): Requirements for applying a logo to an integration, including size, dimensions, and background.
- [Developing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing.md): Code conventions for Cortex XSIAM.
- [Python code conventions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/python-code-conventions.md): Python code conventions for Cortex XSIAM.
- [PowerShell](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/powershell.md)
- [General naming conventions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/general-naming-conventions.md): Naming conventions for integrations, commands, arguments, and outputs.
- [Integration Parameters](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/integration-parameters.md): Integration parameter types that are configurable in integration instances.
- [Context and outputs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/context-and-outputs.md): The context map stores results from integration commands and scripts and is used to pass data between playbook tasks.
- [Context standards](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/context-standards.md): How incident data is structured when it is extracted into the incident Context tree of objects.
- [Generic commands](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/generic-commands.md): Commands generalized across similar integrations to enable combining data from various sources or running integrations in parallel.
- [Reputation and DBot score](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/reputation-and-dbot-score.md): Format indicator data for DBot to ingest information about indicators to determine if they are malicious.
- [Integration commands](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/integration-commands.md): Integration commands used in playbooks and in the CLI. Command design, arguments, and outputs.
- [Using Docker](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/developing/using-docker.md): Use Docker to run Python scripts and integrations in a controlled environment.
- [Advanced topics](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics.md): Advanced information for content development in Cortex XSIAM.
- [Fetching credentials](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/fetching-credentials.md): Integrate with third-party credential vaults for Cortex XSIAM to authenticate with integrations.
- [Event collector integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/event-collector-integrations.md): Develop event collector integrations to fetch events and logs from external products to Cortex XSIAM.
- [Feed Integrations](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/feed-integrations.md)
- [Long Running Containers](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/long-running-containers.md): Use long running containers to make integrations long running. Develop long running integrations in Python.
- [Transform Language (DT)](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/transform-language-dt.md): Use DT for various context related functions in Cortex XSIAM. DT is a query language for JSON objects, similar to JSONQuery.
- [Integration cache](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/integration-cache.md): Store objects in the database per integration instance using the integrationContext command to store data between integration command runs.
- [OpenAPI (Swagger) Codegen](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/openapi-swagger-codegen.md): Use the openapi-codegen command in the Demisto SDK to generate a Cortex XSIAM integration package (YAML and Python files).
- [Postman code generator](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/postman-code-generator.md): Use the demisto-sdk postman-codegen command to generate an integration (YAML file) from a Postman Collection v2.1.
- [Generate Integration Python Code from JSON](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/generate-integration-python-code-from-json.md): use the demisto-sdk generate-integration  command to generate a Cortex XSIAM integration from an integration config JSON file.
- [Generate YAML from Python](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/generate-yaml-from-python.md): Generate a YAML file from Python code that includes special syntax. Currently for integrations only.
- [Scheduled Commands](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/scheduled-commands.md): Use commands to schedule the future execution of other commands in playbook tasks.
- [Fetch missing incidents with generic lookback methods](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/advanced-topics/fetch-missing-incidents-with-generic-lookback-methods.md): To retrieve missing incidents, configure how far back in time (in minutes) to get incidents that were created a while ago but indexed a few minutes ago. In addition, store the fields to be used by the
- [Create a sample integration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/create-a-sample-integration.md): Create a sample integration for Cortex XSIAM.
- [Define sample integration settings](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/create-a-sample-integration/define-sample-integration-settings.md): Define integration settings for a sample integration in Cortex XSIAM.
- [Write integration code](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/create-a-sample-integration/write-integration-code.md): Write integration code for a sample integration.
- [Test the integration](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/integrations-and-scripts/create-a-sample-integration/test-the-integration.md): Check the integration you created works.
- [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/playbooks.md): Create playbooks in the UI with the Playbook Editor to automate complex workflows in Cortex XSIAM without requiring complicated coding. Add the playbook to a content pack.
- [Add a Playbook to a Content Pack](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/playbooks/add-a-playbook-to-a-content-pack.md)
- [Playbook conventions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/playbooks/playbook-conventions.md): Recommendations for playbook and task naming, as well as playbook design tips.
- [Generic playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/playbooks/generic-playbooks.md): Use the out of the box installed Common Playbooks content back for common tasks that are part of many analyst workflows.
- [Lists](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/lists.md): Create a list and add it to your content pack.
- [Alerts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/alerts.md): Create a content pack for Cortex XSIAM with custom content for alerts.
- [Data modeling rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/data-modeling-rules.md): Map your Cortex XSIAM logs into a single, unified data model with a consolidated schema.
- [Create data model rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/data-modeling-rules/create-data-model-rules.md): Once events are ingested in the data set, create data model rules in the repository and then map the ingested raw events to Cortex XSIAM system fields.
- [Test Data Model Rules](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/data-modeling-rules/create-data-model-rules/test-data-model-rules.md): Test data model rules to verify they work as expected.
- [Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/indicators.md): Learn about indicator fields, relationships, and URL and domain indicator extraction.
- [URL extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/indicators/url-extraction.md): Extract a URL indicator from text that is recognized from a regular expression and then formatted with a formatting script.
- [Domain extraction](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/indicators/domain-extraction.md): Extract a domain indicator from text that is recognized from a regular expression and then formatted with a formatting script.
- [Relationships](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/indicators/relationships.md): Use the create\_relationships parameter in an integration to create relationships between indicators as part of enrichment.
- [Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation.md): Content documentation best practices for content pack metadata files, release notes, README files, and documentation contributions.
- [Documentation best practices](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/documentation-best-practices.md)
- [Content pack metadata file](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/content-pack-metadata-file.md): Information about the pack\_metadata.json used to display a description of the content pack in the Marketplace, and apply tags, use cases and categories to a content pack.
- [Content pack release notes](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/content-pack-release-notes.md): Best practices for naming, writing, and generating content pack release notes. Troubleshooting for release notes files.
- [Content Pack README](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/content-pack-readme.md)
- [README files for content entities](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/readme-files-for-content-entities.md): Create and deploy entity README files that include images and videos.
- [Images in documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/images-in-documentation.md)
- [Videos in documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/videos-in-documentation.md)
- [Documentation Contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/documentation/documentation-contributions.md): Edit an xsoar.pan.dev doc page or report an issue.
- [Testing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/testing.md): Methods for testing code, including linting, unit testing, playbook testing and debugging.
- [Linting](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/testing/linting.md): Run linters to catch common programming errors, stylistic errors, and possible security issues
- [Unit testing](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/testing/unit-testing.md): Write and run unit tests with VS Code to test small units of code in an isolated and deterministic fashion.
- [Test playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/testing/test-playbooks.md): Create test playbooks to check integration commands and scripts.
- [Debugging](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/testing/debugging.md): Use print to War Room, logs, and the IDE debugging resources to understand unexpected code behavior.
- [Contributing content](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content.md): How to contribute content for Cortex XSIAM.
- [Contribution requirements](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content/contribution-requirements.md): Prerequisite tools and environments for developing content for contributions to Cortex XSIAM.
- [File checklist](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content/file-checklist.md): A checklist of all the files you need to contribute to the Cortex XSIAM content repository.
- [Content pack structure](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content/content-pack-structure.md): File structure for files included in the Cortex XSIAM content pack.
- [Content pack dependencies](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content/content-pack-dependencies.md): Find and and fix content pack dependencies.
- [Pull request conventions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content/pull-request-conventions.md): Pull request best practices. A description of the pull request build process.
- [Contribution demo preparation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content/contribution-demo-preparation.md): How to prepare for a demo and how the demo is conducted as the last stage of the contribution before it is merged into the content internal repo.
- [Contribution SLA](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content/contribution-sla.md): An SLA detailing the required services and the expected level of services when contributing content to the Cortex XSIAM Marketplace

## Cortex CLI

- [Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli.md): The Cortex CLI is a unified command-line tool integrating Cloud Workload Protection, API Security, and Code Security scans into a single executable.
- [Connect Cortex CLI](https://cortex-docs.paloaltonetworks.com/cortex-cli/connect-cortex-cli.md)
- [Authenticate credentials](https://cortex-docs.paloaltonetworks.com/cortex-cli/authenticate-credentials.md)
- [Cortex CLI usage](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-usage.md)
- [Self-service API keys for CLI scans](https://cortex-docs.paloaltonetworks.com/cortex-cli/self-service-api-keys-for-cli-scans.md)
- [Cortex CLI common command line reference guide](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-common-command-line-reference-guide.md)
- [Cortex CLI for API Security](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-api-security.md)
- [Cortex CLI for Cloud Workload Protection](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-cloud-workload-protection.md)
- [Cortex CLI for Code Security](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-code-security.md)
- [Cortex CLI usage for Application Security](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-code-security/cortex-cli-usage-for-application-security.md)
- [Cortex CLI Application Security command line reference](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-code-security/cortex-cli-application-security-command-line-reference.md)
- [Cortex CLI pre-commit hooks](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-commit-hooks.md)
- [Pre-commit hook usage](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-code-security/pre-commit-hook-usage.md)
- [Cortex CLI pre-receive hooks](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-code-security/cortex-cli-pre-receive-hooks.md)
- [Pre-receive hook usage](https://cortex-docs.paloaltonetworks.com/cortex-cli/cortex-cli-for-code-security/pre-receive-hook-usage.md)

## XQL Command Reference Guide

- [Cortex XQL Command Reference](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme.md)
- [Reference overview](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/introduction.md)
- [Browse the reference](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/summary.md)
- [Functions](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions.md)
- [Functions overview](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/index.md)
- [Functions list](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/functions-list.md)
- [acos](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/acos.md)
- [add](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/add.md)
- [approx\_count](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/approx_count.md)
- [approx\_quantiles](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/approx_quantiles.md)
- [approx\_top](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/approx_top.md)
- [array\_all](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/array_all.md)
- [array\_any](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/array_any.md)
- [array\_length](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/array_length.md)
- [arrayconcat](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arrayconcat.md)
- [arraycreate](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arraycreate.md)
- [arraydistinct](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arraydistinct.md)
- [arrayfilter](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arrayfilter.md)
- [arrayindex](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arrayindex.md)
- [arrayindexof](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arrayindexof.md)
- [arraymap](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arraymap.md)
- [arraymerge](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arraymerge.md)
- [arrayrange](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arrayrange.md)
- [arraystring](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/arraystring.md)
- [asin](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/asin.md)
- [avg (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/avg_with_comp_stage.md)
- [avg (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/avg_with_windowcomp_stage.md)
- [bitwise\_and](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/bitwise_and.md)
- [bitwise\_or](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/bitwise_or.md)
- [bitwise\_sleft](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/bitwise_sleft.md)
- [bitwise\_sright](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/bitwise_sright.md)
- [bitwise\_xor](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/bitwise_xor.md)
- [cbrt](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/cbrt.md)
- [ceil](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/ceil.md)
- [coalesce](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/coalesce.md)
- [concat](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/concat.md)
- [convert\_from\_base\_64](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/convert_from_base_64.md)
- [convert\_to\_base\_64](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/convert_to_base_64.md)
- [cos](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/cos.md)
- [cosine\_distance](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/cosine_distance.md)
- [cot](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/cot.md)
- [count\_distinct](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/count_distinct.md)
- [count (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/count_with_comp_stage.md)
- [count (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/count_with_windowcomp_stage.md)
- [csc](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/csc.md)
- [current\_time](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/current_time.md)
- [date\_floor](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/date_floor.md)
- [div](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/div.md)
- [divide](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/divide.md)
- [earliest](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/earliest.md)
- [euclidean\_distance](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/euclidean_distance.md)
- [exp](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/exp.md)
- [extract\_time](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/extract_time.md)
- [extract\_url\_host](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/extract_url_host.md)
- [extract\_url\_pub\_suffix](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/extract_url_pub_suffix.md)
- [extract\_url\_registered\_domain](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/extract_url_registered_domain.md)
- [first](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/first.md)
- [first\_value](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/first_value.md)
- [floor](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/floor.md)
- [format\_string](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/format_string.md)
- [format\_timestamp](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/format_timestamp.md)
- [greatest](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/greatest.md)
- [hierarchy\_match](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/hierarchy_match.md)
- [if](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/if.md)
- [incidr](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/incidr.md)
- [incidr6](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/incidr6.md)
- [incidrlist](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/incidrlist.md)
- [int\_to\_ip](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/int_to_ip.md)
- [ip\_to\_int](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/ip_to_int.md)
- [is\_ipv4](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/is_ipv4.md)
- [is\_ipv6](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/is_ipv6.md)
- [is\_known\_private\_ipv4](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/is_known_private_ipv4.md)
- [is\_known\_private\_ipv6](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/is_known_private_ipv6.md)
- [json\_extract](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/json_extract.md)
- [json\_extract\_array](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/json_extract_array.md)
- [json\_extract\_scalar](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/json_extract_scalar.md)
- [json\_extract\_scalar\_array](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/json_extract_scalar_array.md)
- [XQL JSON Functions Reference](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/json_functions_reference.md)
- [json\_path\_extract](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/json_path_extract.md)
- [lag](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/lag.md)
- [last](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/last.md)
- [last\_value](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/last_value.md)
- [latest](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/latest.md)
- [least](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/least.md)
- [len](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/len.md)
- [list (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/list_with_comp_stage.md)
- [ln](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/ln.md)
- [log](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/log.md)
- [log10](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/log10.md)
- [lowercase](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/lowercase.md)
- [ltrim](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/ltrim.md)
- [max (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/max_with_comp_stage.md)
- [max (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/max_with_windowcomp_stage.md)
- [md5](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/md5.md)
- [median (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/median_with_comp_stage.md)
- [median (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/median_with_windowcomp_stage.md)
- [min (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/min_with_comp_stage.md)
- [min (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/min_with_windowcomp_stage.md)
- [mod](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/mod.md)
- [multiply](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/multiply.md)
- [object\_create](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/object_create.md)
- [object\_merge](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/object_merge.md)
- [parse\_epoch](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/parse_epoch.md)
- [parse\_timestamp](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/parse_timestamp.md)
- [pow](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/pow.md)
- [power](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/power.md)
- [rand](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/rand.md)
- [range\_bucket](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/range_bucket.md)
- [rank (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/rank_with_windowcomp_stage.md)
- [regexcapture](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/regexcapture.md)
- [regextract](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/regextract.md)
- [replace](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/replace.md)
- [replex](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/replex.md)
- [round](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/round.md)
- [row\_number (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/row_number_with_windowcomp_stage.md)
- [rtrim](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/rtrim.md)
- [safe\_add](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/safe_add.md)
- [safe\_divide](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/safe_divide.md)
- [safe\_multiply](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/safe_multiply.md)
- [safe\_negate](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/safe_negate.md)
- [safe\_subtract](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/safe_subtract.md)
- [sec](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sec.md)
- [sha1](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sha1.md)
- [sha256](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sha256.md)
- [sha512](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sha512.md)
- [sign](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sign.md)
- [sin](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sin.md)
- [split](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/split.md)
- [sqrt](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sqrt.md)
- [stddev\_population (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/stddev_population_with_comp_stage.md)
- [stddev\_population (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/stddev_population_with_windowcomp_stage.md)
- [stddev\_sample (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/stddev_sample_with_comp_stage.md)
- [stddev\_sample (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/stddev_sample_with_windowcomp_stage.md)
- [string\_count](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/string_count.md)
- [subtract](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/subtract.md)
- [sum (comp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sum_with_comp_stage.md)
- [sum (windowcomp)](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/sum_with_windowcomp_stage.md)
- [tan](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/tan.md)
- [time\_frame\_end](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/time_frame_end.md)
- [timestamp\_diff](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/timestamp_diff.md)
- [timestamp\_seconds](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/timestamp_seconds.md)
- [to\_boolean](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_boolean.md)
- [to\_epoch](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_epoch.md)
- [to\_float](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_float.md)
- [to\_integer](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_integer.md)
- [to\_json\_string](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_json_string.md)
- [to\_number](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_number.md)
- [to\_string](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_string.md)
- [to\_timestamp](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/to_timestamp.md)
- [trim](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/trim.md)
- [trunc](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/trunc.md)
- [uppercase](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/uppercase.md)
- [values](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/values.md)
- [var](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/var.md)
- [wildcard\_match](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/wildcard_match.md)
- [Stages](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages.md)
- [Stages overview](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/index.md)
- [Stages list](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/stages-list.md)
- [alter](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/alter.md)
- [arrayexpand](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/arrayexpand.md)
- [bin](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/bin.md)
- [call](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/call.md)
- [comp](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/comp.md)
- [config](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/config.md)
- [dataset](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/dataset.md)
- [dedup](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/dedup.md)
- [fields](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/fields.md)
- [filter](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/filter.md)
- [iploc](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/iploc.md)
- [join](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/join.md)
- [limit](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/limit.md)
- [pivot](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/pivot.md)
- [preset](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/presets.md)
- [replacenull](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/replacenull.md)
- [search](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/search.md)
- [sort](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/sort.md)
- [tag](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/tag.md)
- [target](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/target.md)
- [top](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/top.md)
- [transaction](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/transaction.md)
- [transpose](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/transpose.md)
- [union](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/union.md)
- [view](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/view.md)
- [windowcomp](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/stages/windowcomp.md)

## Analytics Alerts

- [Cortex Analytics Alert Reference](https://cortex-docs.paloaltonetworks.com/analytics-alerts/cortex-analytics-alert-reference.md)
- [Alerts by name](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name.md)
- [A Backup vault policy was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-backup-vault-policy-was-modified.md)
- [A browser extension was installed or loaded in an uncommon way](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-browser-extension-was-installed-or-loaded-in-an-uncommon-way.md)
- [A browser was opened in private mode](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-browser-was-opened-in-private-mode.md)
- [A Cloud DB instance was exported to an unknown destination](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-db-instance-was-exported-to-an-unknown-destination.md)
- [A cloud function was created with an unusual runtime](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-function-was-created-with-an-unusual-runtime.md)
- [A cloud identity created or modified a security group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-identity-created-or-modified-a-security-group.md)
- [A cloud identity executed an API call from an unusual country](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country.md)
- [A cloud identity had escalated its permissions](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-identity-had-escalated-its-permissions.md)
- [A cloud identity invoked IAM related persistence operations](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-identity-invoked-iam-related-persistence-operations.md)
- [A cloud identity performed multiple unusual activities](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-identity-performed-multiple-unusual-activities.md)
- [A cloud identity started a Cloud Shell session](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-identity-started-a-cloud-shell-session.md)
- [A cloud instance was stopped](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-instance-was-stopped.md)
- [A cloud snapshot of AWS database or storage was modified or shared](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-snapshot-of-aws-database-or-storage-was-modified-or-shared.md)
- [A cloud storage configuration was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-storage-configuration-was-modified.md)
- [A cloud storage object was copied to a foreign cloud account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-cloud-storage-object-was-copied-to-a-foreign-cloud-account.md)
- [A Command Line Interface (CLI) command was executed from a GCP serverless compute service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-command-line-interface-cli-command-was-executed-from-a-gcp-serverless-compute-service.md)
- [A Command Line Interface (CLI) command was executed from an AWS serverless compute service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-command-line-interface-cli-command-was-executed-from-an-aws-serverless-compute-service.md)
- [A commonly abused process connected to a rare cloud resource](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-cloud-resource.md)
- [A commonly abused process connected to a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-external-host.md)
- [A compiled HTML help file wrote a script file to the disk](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-compiled-html-help-file-wrote-a-script-file-to-the-disk.md)
- [A compressed file was exfiltrated over SSH](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-compressed-file-was-exfiltrated-over-ssh.md)
- [A compromised process accessed a rare cloud resource](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-compromised-process-accessed-a-rare-cloud-resource.md)
- [A compromised process accessed a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-compromised-process-accessed-a-rare-external-host.md)
- [A compute-attached identity executed API calls outside the instance's region](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-compute-attached-identity-executed-api-calls-outside-the-instance-s-region.md)
- [A computer account was promoted to DC](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-computer-account-was-promoted-to-dc.md)
- [A contained executable from a mounted share initiated a suspicious outbound network connection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-contained-executable-from-a-mounted-share-initiated-a-suspicious-outbound-network-connection.md)
- [A contained executable was executed by an unusual process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-contained-executable-was-executed-by-an-unusual-process.md)
- [A contained process attempted to escape using the 'notify on release' feature](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-contained-process-attempted-to-escape-using-the-notify-on-release-feature.md)
- [A container registry was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-container-registry-was-created-or-deleted.md)
- [A disabled user attempted to authenticate via SSO](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-disabled-user-attempted-to-authenticate-via-sso.md)
- [A disabled user attempted to log in to a VPN](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-disabled-user-attempted-to-log-in-to-a-vpn.md)
- [A disabled user attempted to log in](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-disabled-user-attempted-to-log-in.md)
- [A domain was added to the trusted domains list](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-domain-was-added-to-the-trusted-domains-list.md)
- [A GCP Cloud SQL DB instance was exported from a production account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-gcp-cloud-sql-db-instance-was-exported-from-a-production-account.md)
- [A GCP service account was delegated domain-wide authority in Google Workspace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-gcp-service-account-was-delegated-domain-wide-authority-in-google-workspace.md)
- [A Google Workspace identity created, assigned or modified a role](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-google-workspace-identity-created-assigned-or-modified-a-role.md)
- [A Google Workspace identity performed an unusual admin console activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-google-workspace-identity-performed-an-unusual-admin-console-activity.md)
- [A Google Workspace identity used the security investigation tool](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-google-workspace-identity-used-the-security-investigation-tool.md)
- [A Google Workspace Role privilege was deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-google-workspace-role-privilege-was-deleted.md)
- [A Google Workspace service was configured as unrestricted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-google-workspace-service-was-configured-as-unrestricted.md)
- [A Google Workspace user was added to a group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-google-workspace-user-was-added-to-a-group.md)
- [A Google Workspace user was removed from a group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-google-workspace-user-was-removed-from-a-group.md)
- [A Kubernetes API operation was successfully invoked by an anonymous user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-api-operation-was-successfully-invoked-by-an-anonymous-user.md)
- [A Kubernetes cluster role binding was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-cluster-role-binding-was-created-or-deleted.md)
- [A Kubernetes cluster role was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-cluster-role-was-created.md)
- [A Kubernetes cluster was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-cluster-was-created-or-deleted.md)
- [A Kubernetes ConfigMap was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-configmap-was-created-or-deleted.md)
- [A Kubernetes Cronjob was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-cronjob-was-created.md)
- [A Kubernetes DaemonSet was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-daemonset-was-created.md)
- [A Kubernetes dashboard service account was used outside the cluster](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-dashboard-service-account-was-used-outside-the-cluster.md)
- [A Kubernetes deployment was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-deployment-was-created.md)
- [A Kubernetes ephemeral container was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-ephemeral-container-was-created.md)
- [A Kubernetes namespace was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-namespace-was-created-or-deleted.md)
- [A Kubernetes node service account activity from external IP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-node-service-account-activity-from-external-ip.md)
- [A Kubernetes Pod was created with a sidecar container](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-pod-was-created-with-a-sidecar-container.md)
- [A Kubernetes Pod was deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-pod-was-deleted.md)
- [A Kubernetes ReplicaSet was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-replicaset-was-created.md)
- [A Kubernetes role binding was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-role-binding-was-created-or-deleted.md)
- [A Kubernetes secret was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-secret-was-created-or-deleted.md)
- [A Kubernetes service account executed an unusual API call](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-service-account-executed-an-unusual-api-call.md)
- [A Kubernetes service account has enumerated its permissions](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-service-account-has-enumerated-its-permissions.md)
- [A Kubernetes service account was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-service-account-was-created-or-deleted.md)
- [A Kubernetes service was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-service-was-created-or-deleted.md)
- [A Kubernetes StatefulSet was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-kubernetes-statefulset-was-created.md)
- [A LOLBIN was copied to a different location](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-lolbin-was-copied-to-a-different-location.md)
- [A machine certificate was issued with a mismatch](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-machine-certificate-was-issued-with-a-mismatch.md)
- [A mail forwarding rule was configured in Google Workspace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-mail-forwarding-rule-was-configured-in-google-workspace.md)
- [A Microsoft Teams application was installed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-microsoft-teams-application-was-installed.md)
- [A Microsoft Teams bot was added to a team](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-microsoft-teams-bot-was-added-to-a-team.md)
- [A new Azure email domain verification was requested](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-new-azure-email-domain-verification-was-requested.md)
- [A new machine attempted Kerberos delegation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-new-machine-attempted-kerberos-delegation.md)
- [A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-new-server-was-added-to-an-azure-active-directory-hybrid-health-adfs-environment.md)
- [A non-browser process accessed a website UI](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-non-browser-process-accessed-a-website-ui.md)
- [A Possible crypto miner was detected on a host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-possible-crypto-miner-was-detected-on-a-host.md)
- [A possible risky login to Azure](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-possible-risky-login-to-azure.md)
- [A process connected to a rare cloud resource](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-process-connected-to-a-rare-cloud-resource.md)
- [A process connected to a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-process-connected-to-a-rare-external-host.md)
- [A process connected to rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-process-connected-to-rare-external-host.md)
- [A process is masquerading as a common Microsoft product](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-process-is-masquerading-as-a-common-microsoft-product.md)
- [A process modified an SSH authorized\_keys file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-process-modified-an-ssh-authorized-keys-file.md)
- [A process queried the ADFS database decryption key via LDAP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-process-queried-the-adfs-database-decryption-key-via-ldap.md)
- [A process was executed with a command line obfuscated by Unicode character substitution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-process-was-executed-with-a-command-line-obfuscated-by-unicode-character-substitution.md)
- [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-process.md)
- [A rare file path was added to the AppInit\_DLLs registry value](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-rare-file-path-was-added-to-the-appinit-dlls-registry-value.md)
- [A rare FTP user has been detected on an existing FTP server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-rare-ftp-user-has-been-detected-on-an-existing-ftp-server.md)
- [A rare local administrator login](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-rare-local-administrator-login.md)
- [A remote service was created via RPC over SMB](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-remote-service-was-created-via-rpc-over-smb.md)
- [A Service Principal was created in Azure](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-service-principal-was-created-in-azure.md)
- [A Service Principal was removed from Azure](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-service-principal-was-removed-from-azure.md)
- [A service was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-service-was-disabled.md)
- [A Successful login from TOR](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-successful-login-from-tor.md)
- [A successful SSO sign-in from TOR](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-successful-sso-sign-in-from-tor.md)
- [A Successful VPN connection from TOR](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-successful-vpn-connection-from-tor.md)
- [A suspicious direct syscall was executed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-suspicious-direct-syscall-was-executed.md)
- [A suspicious executable with multiple file extensions was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-suspicious-executable-with-multiple-file-extensions-was-created.md)
- [A suspicious process enrolled for a certificate](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-suspicious-process-enrolled-for-a-certificate.md)
- [A suspicious process queried AD CS objects via LDAP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-suspicious-process-queried-ad-cs-objects-via-ldap.md)
- [A TCP stream was created directly in a shell](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-tcp-stream-was-created-directly-in-a-shell.md)
- [A third-party application's access to the Google Workspace domain's resources was revoked](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-third-party-application-s-access-to-the-google-workspace-domain-s-resources-was-revoked.md)
- [A third-party application was authorized to access the Google Workspace APIs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-third-party-application-was-authorized-to-access-the-google-workspace-apis.md)
- [A third-party utility was copied to a different location](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-third-party-utility-was-copied-to-a-different-location.md)
- [A Torrent client was detected on a host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-torrent-client-was-detected-on-a-host.md)
- [A user accessed an abnormal number of files on a remote shared folder](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-accessed-an-abnormal-number-of-files-on-a-remote-shared-folder.md)
- [A user accessed an abnormal number of remote shared folders](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-accessed-an-abnormal-number-of-remote-shared-folders.md)
- [A user accessed an uncommon AppID](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-accessed-an-uncommon-appid.md)
- [A user accessed multiple time-consuming websites](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-accessed-multiple-time-consuming-websites.md)
- [A user accessed multiple unusual resources via SSO](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-accessed-multiple-unusual-resources-via-sso.md)
- [A user accessed Okta's admin application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-accessed-okta-s-admin-application.md)
- [A user account was modified to password never expires](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-account-was-modified-to-password-never-expires.md)
- [A user added a Windows firewall rule](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-added-a-windows-firewall-rule.md)
- [A user attempted to bypass Okta MFA](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-attempted-to-bypass-okta-mfa.md)
- [A user authenticated with weak NTLM to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-authenticated-with-weak-ntlm-to-multiple-hosts.md)
- [A user certificate was issued with a mismatch](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-certificate-was-issued-with-a-mismatch.md)
- [A user changed the Windows system time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-changed-the-windows-system-time.md)
- [A user connected a new USB storage device to a host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-a-host.md)
- [A user connected a new USB storage device to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-multiple-hosts.md)
- [A user connected a USB storage device for the first time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-connected-a-usb-storage-device-for-the-first-time.md)
- [A user connected from a new country](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-connected-from-a-new-country.md)
- [A user connected to a VPN from a new country](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-connected-to-a-vpn-from-a-new-country.md)
- [A user created a pfx file for the first time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-created-a-pfx-file-for-the-first-time.md)
- [A user created an abnormal password-protected archive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-created-an-abnormal-password-protected-archive.md)
- [A user enabled a default local account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-enabled-a-default-local-account.md)
- [A user established an SMB connection to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-established-an-smb-connection-to-multiple-hosts.md)
- [A user executed multiple LDAP enumeration queries](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-executed-multiple-ldap-enumeration-queries.md)
- [A user logged in at an unusual time via SSO](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-sso.md)
- [A user logged in at an unusual time via VPN](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-vpn.md)
- [A user logged in from an abnormal country or ASN](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-logged-in-from-an-abnormal-country-or-asn.md)
- [A user logged in to the AWS console for the first time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-logged-in-to-the-aws-console-for-the-first-time.md)
- [A user logged on to multiple workstations via Schannel](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-logged-on-to-multiple-workstations-via-schannel.md)
- [A user modified an Okta MFA factor](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-modified-an-okta-mfa-factor.md)
- [A user modified an Okta network zone](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-modified-an-okta-network-zone.md)
- [A user modified an Okta policy rule](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-modified-an-okta-policy-rule.md)
- [A user modified the CA audit policy](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-modified-the-ca-audit-policy.md)
- [A user observed and reported unusual activity in Okta](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-observed-and-reported-unusual-activity-in-okta.md)
- [A user performed suspiciously massive file activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-performed-suspiciously-massive-file-activity.md)
- [A user printed an unusual number of files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-printed-an-unusual-number-of-files.md)
- [A user queried AD CS objects via LDAP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-queried-ad-cs-objects-via-ldap.md)
- [A user received multiple weakly encrypted service tickets](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-received-multiple-weakly-encrypted-service-tickets.md)
- [A user rejected an SSO request from an unusual country](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-rejected-an-sso-request-from-an-unusual-country.md)
- [A user requested multiple service tickets](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-requested-multiple-service-tickets.md)
- [A user sent multiple TGT requests to irregular service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-sent-multiple-tgt-requests-to-irregular-service.md)
- [A user took numerous screenshots](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-took-numerous-screenshots.md)
- [A user uploaded malware to SharePoint or OneDrive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-uploaded-malware-to-sharepoint-or-onedrive.md)
- [A user was added to a Windows security group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-user-was-added-to-a-windows-security-group.md)
- [A WMI subscriber was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/a-wmi-subscriber-was-created.md)
- [Abnormal Allocation of compute resources in multiple regions](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-allocation-of-compute-resources-in-multiple-regions.md)
- [Abnormal Communication to a Rare Domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-communication-to-a-rare-domain.md)
- [Abnormal communication with a rare combination of TLS and HTTP User Agent](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-communication-with-a-rare-combination-of-tls-and-http-user-agent.md)
- [Abnormal connections to a dormant host from a newly seen endpoint](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-connections-to-a-dormant-host-from-a-newly-seen-endpoint.md)
- [Abnormal File Activity in SCCMContentLib Shared Folder by user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-file-activity-in-sccmcontentlib-shared-folder-by-user.md)
- [Abnormal ICMP echo (PING) to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-icmp-echo-ping-to-multiple-hosts.md)
- [Abnormal increase in network-related alerts on the same host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-increase-in-network-related-alerts-on-the-same-host.md)
- [Abnormal network communication through TOR using an uncommon port](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-network-communication-through-tor-using-an-uncommon-port.md)
- [Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-network-communication-with-a-rare-combination-of-http-user-agent-and-http-server.md)
- [Abnormal process connection to default Meterpreter port](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-process-connection-to-default-meterpreter-port.md)
- [Abnormal RDP connections to multiple hosts from a rarely seen host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-rdp-connections-to-multiple-hosts-from-a-rarely-seen-host.md)
- [Abnormal RDP connections to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-rdp-connections-to-multiple-hosts.md)
- [Abnormal RDP session to a remote host from a rarely seen host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-rdp-session-to-a-remote-host-from-a-rarely-seen-host.md)
- [Abnormal Recurring Communications to a Rare Domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-recurring-communications-to-a-rare-domain.md)
- [Abnormal RPC traffic to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-rpc-traffic-to-multiple-hosts.md)
- [Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts-from-a-rarely-seen-host.md)
- [Abnormal sensitive RPC traffic to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts.md)
- [Abnormal SMB activity to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-smb-activity-to-multiple-hosts.md)
- [Abnormal SMB scanning activity to multiple hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-smb-scanning-activity-to-multiple-hosts.md)
- [Abnormal User Login to Domain Controller](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-user-login-to-domain-controller.md)
- [Access to kubelet credentials file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/access-to-kubelet-credentials-file.md)
- [Access to Kubernetes CA certificate file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/access-to-kubernetes-ca-certificate-file.md)
- [Access to Kubernetes configuration file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/access-to-kubernetes-configuration-file.md)
- [Access to sensitive host files from within a Kubernetes pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/access-to-sensitive-host-files-from-within-a-kubernetes-pod.md)
- [Account probing](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/account-probing.md)
- [Adding execution privileges](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/adding-execution-privileges.md)
- [ADFS DKM Key Access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/adfs-dkm-key-access.md)
- [Admin privileges were granted to a Google Workspace user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/admin-privileges-were-granted-to-a-google-workspace-user.md)
- [Administrator groups enumerated via LDAP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/administrator-groups-enumerated-via-ldap.md)
- [AI-determined combination of risky alerts under the same actor process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-actor-process.md)
- [AI-determined combination of risky alerts under the same causality](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-causality.md)
- [AI model discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ai-model-discovery.md)
- [AI safeguards deletion attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ai-safeguards-deletion-attempt.md)
- [AI safeguards were modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ai-safeguards-were-modified.md)
- [Allocation of multiple cloud compute resources](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/allocation-of-multiple-cloud-compute-resources.md)
- [An app was added to Google Marketplace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-app-was-added-to-google-marketplace.md)
- [An app was added to the Google Workspace trusted OAuth apps list](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-app-was-added-to-the-google-workspace-trusted-oauth-apps-list.md)
- [An app was removed from a blocked list in Google Workspace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-app-was-removed-from-a-blocked-list-in-google-workspace.md)
- [An AWS database service master user password was changed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-database-service-master-user-password-was-changed.md)
- [An AWS EC2 instance containing sensitive data was exported](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-ec2-instance-containing-sensitive-data-was-exported.md)
- [An AWS EC2 instance was exported from a production account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-ec2-instance-was-exported-from-a-production-account.md)
- [An AWS EC2 instance was exported into an unknown S3 bucket](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-ec2-instance-was-exported-into-an-unknown-s3-bucket.md)
- [An AWS EFS File-share mount was deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-efs-file-share-mount-was-deleted.md)
- [An AWS EFS file-share was deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-efs-file-share-was-deleted.md)
- [An AWS EKS cluster was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-eks-cluster-was-created-or-deleted.md)
- [An AWS GuardDuty IP set was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-guardduty-ip-set-was-created.md)
- [An AWS Lambda Function was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-lambda-function-was-created.md)
- [An AWS Lambda function was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-lambda-function-was-modified.md)
- [An AWS RDS Global Cluster Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-rds-global-cluster-deletion.md)
- [An AWS RDS instance was created from a snapshot](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-rds-instance-was-created-from-a-snapshot.md)
- [An AWS Route 53 domain was transferred to another AWS account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-route-53-domain-was-transferred-to-another-aws-account.md)
- [An AWS S3 bucket configuration was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-s3-bucket-configuration-was-modified.md)
- [An AWS SAML provider was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-saml-provider-was-modified.md)
- [An AWS SES identity was deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-aws-ses-identity-was-deleted.md)
- [An Azure application reached a throttling API rate](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-application-reached-a-throttling-api-rate.md)
- [An Azure DNS Zone was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-dns-zone-was-modified.md)
- [An Azure Firewall policy deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-firewall-policy-deletion.md)
- [An Azure Firewall rule collection group was modified or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-firewall-rule-collection-group-was-modified-or-deleted.md)
- [An Azure firewall rule group was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-firewall-rule-group-was-modified.md)
- [An Azure Firewall was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-firewall-was-modified.md)
- [An Azure identity performed multiple actions that were denied](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-identity-performed-multiple-actions-that-were-denied.md)
- [An Azure Key Vault key was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-key-vault-key-was-modified.md)
- [An Azure Key Vault was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-key-vault-was-modified.md)
- [An Azure Kubernetes Cluster was created or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-kubernetes-cluster-was-created-or-deleted.md)
- [An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-kubernetes-role-binding-or-cluster-role-binding-was-modified-or-deleted.md)
- [An Azure Kubernetes Role or Cluster-Role was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-kubernetes-role-or-cluster-role-was-modified.md)
- [An Azure Kubernetes Service Account was modified or deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-kubernetes-service-account-was-modified-or-deleted.md)
- [An Azure Network Security Group was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-network-security-group-was-modified.md)
- [An Azure Point-to-Site VPN was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-point-to-site-vpn-was-modified.md)
- [An Azure SQL database was exported from a production subscription](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-sql-database-was-exported-from-a-production-subscription.md)
- [An Azure Suppression Rule was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-suppression-rule-was-created.md)
- [An Azure virtual network Device was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-virtual-network-device-was-modified.md)
- [An Azure virtual network was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-virtual-network-was-modified.md)
- [An Azure VM snapshot SAS URL was generated for export from a production subscription](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-vm-snapshot-sas-url-was-generated-for-export-from-a-production-subscription.md)
- [An Azure VM snapshot SAS URL was generated](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-vm-snapshot-sas-url-was-generated.md)
- [An Azure VPN Connection was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-azure-vpn-connection-was-modified.md)
- [An EBS snapshot block was downloaded](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-ebs-snapshot-block-was-downloaded.md)
- [An Email address was added to AWS SES](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-email-address-was-added-to-aws-ses.md)
- [An executable was written and executed by a web server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-executable-was-written-and-executed-by-a-web-server.md)
- [An IAM group was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-iam-group-was-created.md)
- [An identity accessed a backup cloud storage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-accessed-a-backup-cloud-storage.md)
- [An identity accessed a cloud storage for the first time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-accessed-a-cloud-storage-for-the-first-time.md)
- [An identity accessed Azure Kubernetes Secrets](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-accessed-azure-kubernetes-secrets.md)
- [An identity attached an administrative policy to an IAM user or role](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-attached-an-administrative-policy-to-an-iam-user-or-role.md)
- [An identity created or updated password for an IAM user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-created-or-updated-password-for-an-iam-user.md)
- [An identity disabled bucket logging](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-disabled-bucket-logging.md)
- [An identity initiated a download of multiple cloud objects](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-initiated-a-download-of-multiple-cloud-objects.md)
- [An identity performed a suspicious download of multiple cloud storage objects](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-performed-a-suspicious-download-of-multiple-cloud-storage-objects.md)
- [An identity started an AWS SSM session](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-started-an-aws-ssm-session.md)
- [An identity successfully extracted multiple secrets within the organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-successfully-extracted-multiple-secrets-within-the-organization.md)
- [An identity was granted permissions to manage user access to Azure resources](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-identity-was-granted-permissions-to-manage-user-access-to-azure-resources.md)
- [An internal Cloud resource performed port scan on external networks](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-internal-cloud-resource-performed-port-scan-on-external-networks.md)
- [An operation was performed by an identity from a domain that was not seen in the organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-operation-was-performed-by-an-identity-from-a-domain-that-was-not-seen-in-the-organization.md)
- [An RDS snapshot containing sensitive data was exported](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-rds-snapshot-containing-sensitive-data-was-exported.md)
- [An RDS snapshot was exported from a production account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-rds-snapshot-was-exported-from-a-production-account.md)
- [An RDS snapshot was exported to an unknown bucket](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-bucket.md)
- [An RDS snapshot was exported to an unknown S3 bucket](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-s3-bucket.md)
- [An S3 replication policy to an unknown bucket was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-s3-replication-policy-to-an-unknown-bucket-was-created.md)
- [An uncommon executable was remotely written over SMB to an uncommon destination](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-uncommon-executable-was-remotely-written-over-smb-to-an-uncommon-destination.md)
- [An uncommon file added to startup-related Registry keys](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-uncommon-file-added-to-startup-related-registry-keys.md)
- [An uncommon file was created in the startup folder](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-uncommon-file-was-created-in-the-startup-folder.md)
- [An uncommon lolbin execution by scheduled task](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-uncommon-lolbin-execution-by-scheduled-task.md)
- [An uncommon RDP session from a managed host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-uncommon-rdp-session-from-a-managed-host.md)
- [An uncommon RDP session was established](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-uncommon-rdp-session-was-established.md)
- [An uncommon service was started](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-uncommon-service-was-started.md)
- [An unknown account was invited to the AWS organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-unknown-account-was-invited-to-the-aws-organization.md)
- [An unpopular process accessed the microphone on the host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-unpopular-process-accessed-the-microphone-on-the-host.md)
- [An unsigned process created scheduled task and performed an injection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-unsigned-process-created-scheduled-task-and-performed-an-injection.md)
- [An unusual archive file creation by a user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-unusual-archive-file-creation-by-a-user.md)
- [An unusual cloud identity was granted permissions to a BigQuery resource](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-unusual-cloud-identity-was-granted-permissions-to-a-bigquery-resource.md)
- [An unusual process in ingress-nginx has accessed a service-account token file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-unusual-process-in-ingress-nginx-has-accessed-a-service-account-token-file.md)
- [An unusual read activity of cloud object](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/an-unusual-read-activity-of-cloud-object.md)
- [Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/analytics-enhanced-rare-internal-firewall-vulnerability-threat-alert.md)
- [AppleScript executed a shell script](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/applescript-executed-a-shell-script.md)
- [AppleScript interpreter dynamic library loaded into a process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/applescript-interpreter-dynamic-library-loaded-into-a-process.md)
- [AppleScript process executed with a rare command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/applescript-process-executed-with-a-rare-command-line.md)
- [Attempt to execute a command on a remote host using PsExec.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/attempt-to-execute-a-command-on-a-remote-host-using-psexec-exe.md)
- [Attempted Azure application access from unknown tenant](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/attempted-azure-application-access-from-unknown-tenant.md)
- [Aurora DB cluster stopped](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aurora-db-cluster-stopped.md)
- [Authentication attempt by a honey user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/authentication-attempt-by-a-honey-user.md)
- [Authentication Attempt From a Dormant Account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/authentication-attempt-from-a-dormant-account.md)
- [Authentication method added to an Azure account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/authentication-method-added-to-an-azure-account.md)
- [Authentication method was added to Azure account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/authentication-method-was-added-to-azure-account.md)
- [Autorun.inf created in root C drive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/autorun-inf-created-in-root-c-drive.md)
- [AWS Backup recovery point deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-backup-recovery-point-deletion.md)
- [AWS Backup vault was deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-backup-vault-was-deleted.md)
- [AWS Bedrock AI infrastructure enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-bedrock-ai-infrastructure-enumeration-activity.md)
- [AWS Bedrock model invocation logging deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-bedrock-model-invocation-logging-deletion.md)
- [AWS CloudTrail has been stopped](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-cloudtrail-has-been-stopped.md)
- [AWS CloudTrail modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-cloudtrail-modification.md)
- [AWS CloudWatch log group deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-cloudwatch-log-group-deletion.md)
- [AWS CloudWatch log stream deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-cloudwatch-log-stream-deletion.md)
- [AWS Config Recorder stopped](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-config-recorder-stopped.md)
- [AWS config resource deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-config-resource-deletion.md)
- [AWS console login without MFA](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-console-login-without-mfa.md)
- [AWS data asset shared public](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-data-asset-shared-public.md)
- [AWS EBS enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ebs-enumeration-activity.md)
- [AWS EBS snapshot deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ebs-snapshot-deletion.md)
- [AWS EC2 infrastructure enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ec2-infrastructure-enumeration-activity.md)
- [AWS EC2 instance exported into S3](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ec2-instance-exported-into-s3.md)
- [AWS Flow Logs deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-flow-logs-deletion.md)
- [AWS Guard-Duty detector deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-guard-duty-detector-deletion.md)
- [AWS IAM resource group deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-iam-resource-group-deletion.md)
- [AWS IAM Role Created with Cross-Account Access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-iam-role-created-with-cross-account-access.md)
- [AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-iam-role-s-trusted-policy-modification-allows-cross-account-access.md)
- [AWS Lambda Cross-Account sensitive permissions configured](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-lambda-cross-account-sensitive-permissions-configured.md)
- [AWS Lambda infrastructure enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-lambda-infrastructure-enumeration-activity.md)
- [AWS network ACL rule creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-network-acl-rule-creation.md)
- [AWS network ACL rule deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-network-acl-rule-deletion.md)
- [AWS Password Policy Discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-password-policy-discovery.md)
- [AWS principals discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-principals-discovery.md)
- [AWS RDS cluster deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-rds-cluster-deletion.md)
- [AWS resource discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-resource-discovery.md)
- [AWS root account activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-root-account-activity.md)
- [AWS S3 bucket data retention policy change through S3 Lifecycle rule](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-s3-bucket-data-retention-policy-change-through-s3-lifecycle-rule.md)
- [AWS S3 bucket was exposed to public access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-s3-bucket-was-exposed-to-public-access.md)
- [AWS S3 Buckets enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-s3-buckets-enumeration-activity.md)
- [AWS Secrets Manager discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-secrets-manager-discovery.md)
- [AWS Security Group remote access allowed from an unknown external IP address](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-security-group-remote-access-allowed-from-an-unknown-external-ip-address.md)
- [AWS Security Service Enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-security-service-enumeration.md)
- [AWS SecurityHub findings were modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-securityhub-findings-were-modified.md)
- [AWS SES account sending settings modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ses-account-sending-settings-modified.md)
- [AWS SSM association created with inventory collection document](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ssm-association-created-with-inventory-collection-document.md)
- [AWS SSM parameters discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ssm-parameters-discovery.md)
- [AWS SSM parameters retrieval](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ssm-parameters-retrieval.md)
- [AWS SSM send command attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-ssm-send-command-attempt.md)
- [AWS Storage Gateway enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-storage-gateway-enumeration.md)
- [AWS Storage Gateway file share enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-storage-gateway-file-share-enumeration.md)
- [AWS STS temporary credentials were generated](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-sts-temporary-credentials-were-generated.md)
- [AWS support case creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-support-case-creation.md)
- [AWS Systems Manager hosts enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-systems-manager-hosts-enumeration.md)
- [AWS Transfer Family server created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-transfer-family-server-created.md)
- [AWS user creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-user-creation.md)
- [AWS web ACL deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/aws-web-acl-deletion.md)
- [Azure account creation by a non-standard account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-account-creation-by-a-non-standard-account.md)
- [Azure account deletion by a non-standard account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-account-deletion-by-a-non-standard-account.md)
- [Azure AD account unlock/password reset attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-ad-account-unlock-password-reset-attempt.md)
- [Azure AD PIM alert disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-ad-pim-alert-disabled.md)
- [Azure AD PIM elevation request](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-ad-pim-elevation-request.md)
- [Azure AD PIM role settings change](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-ad-pim-role-settings-change.md)
- [Azure application consent](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-application-consent.md)
- [Azure application credentials added](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-application-credentials-added.md)
- [Azure application removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-application-removed.md)
- [Azure application URI modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-application-uri-modification.md)
- [Azure Automation Account Creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-automation-account-creation.md)
- [Azure Automation Runbook Creation/Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-automation-runbook-creation-modification.md)
- [Azure Automation Runbook Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-automation-runbook-deletion.md)
- [Azure Automation Webhook creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-automation-webhook-creation.md)
- [Azure Blob Container Access Level Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-blob-container-access-level-modification.md)
- [Azure conditional access policy creation or modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-conditional-access-policy-creation-or-modification.md)
- [Azure device code authentication flow used](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-device-code-authentication-flow-used.md)
- [Azure diagnostic configuration deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-diagnostic-configuration-deletion.md)
- [Azure domain federation settings modification attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-domain-federation-settings-modification-attempt.md)
- [Azure enumeration activity using Microsoft Graph API](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-enumeration-activity-using-microsoft-graph-api.md)
- [Azure Event Hub Authorization rule creation/modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-event-hub-authorization-rule-creation-modification.md)
- [Azure Event Hub Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-event-hub-deletion.md)
- [Azure group creation/deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-group-creation-deletion.md)
- [Azure Key Vault modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-key-vault-modification.md)
- [Azure Key Vault Secrets were modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-key-vault-secrets-were-modified.md)
- [Azure Kubernetes events were deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-kubernetes-events-were-deleted.md)
- [Azure mailbox rule creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-mailbox-rule-creation.md)
- [Azure Monitor alert rule deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-monitor-alert-rule-deleted.md)
- [Azure Network Watcher Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-network-watcher-deletion.md)
- [Azure permission delegation granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-permission-delegation-granted.md)
- [Azure Privilege Escalation Using an Application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-privilege-escalation-using-an-application.md)
- [Azure Resource Group Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-resource-group-deletion.md)
- [Azure route table creation or modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-route-table-creation-or-modification.md)
- [Azure Service principal/Application creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-service-principal-application-creation.md)
- [Azure service principal assigned app role](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-service-principal-assigned-app-role.md)
- [Azure storage account blob anonymous access is enabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-storage-account-blob-anonymous-access-is-enabled.md)
- [Azure storage account cross-tenant object replication was enabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-storage-account-cross-tenant-object-replication-was-enabled.md)
- [Azure Storage Account key generated](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-storage-account-key-generated.md)
- [Azure storage account was publicly shared](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-storage-account-was-publicly-shared.md)
- [Azure Temporary Access Pass (TAP) registered to an account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-temporary-access-pass-tap-registered-to-an-account.md)
- [Azure user creation/deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-user-creation-deletion.md)
- [Azure user password reset](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-user-password-reset.md)
- [Azure virtual machine commands execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-virtual-machine-commands-execution.md)
- [Azure VM extension abuse attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/azure-vm-extension-abuse-attempt.md)
- [Bedrock model shared with a foreign account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/bedrock-model-shared-with-a-foreign-account.md)
- [BigQuery table or query results exfiltrated to a foreign project](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/bigquery-table-or-query-results-exfiltrated-to-a-foreign-project.md)
- [Billing admin role was removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/billing-admin-role-was-removed.md)
- [BitLocker key retrieval](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/bitlocker-key-retrieval.md)
- [Bitsadmin.exe persistence using command-line callback](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/bitsadmin-exe-persistence-using-command-line-callback.md)
- [Broker Collection Error](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/broker-collection-error.md)
- [Bronze-Bit exploit](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/bronze-bit-exploit.md)
- [Browser bookmark files accessed by a rare non-browser process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/browser-bookmark-files-accessed-by-a-rare-non-browser-process.md)
- [Browser Extension Installed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/browser-extension-installed.md)
- [Brute-force attempt on a local account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/brute-force-attempt-on-a-local-account.md)
- [Bucket's block public access setting turned off](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/bucket-s-block-public-access-setting-turned-off.md)
- [Bucket's object ownership controls were modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/bucket-s-object-ownership-controls-were-modified.md)
- [Cached credentials discovery with cmdkey](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cached-credentials-discovery-with-cmdkey.md)
- [Certutil pfx parsing](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/certutil-pfx-parsing.md)
- [Change of sudo caching configuration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/change-of-sudo-caching-configuration.md)
- [Chrome Extension Installed By User](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/chrome-extension-installed-by-user.md)
- [Chrome OS Remote Access policy was modified in Google Workspace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/chrome-os-remote-access-policy-was-modified-in-google-workspace.md)
- [ClickFix - PowerShell executed through the run application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/clickfix-powershell-executed-through-the-run-application.md)
- [Cloud access key creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-access-key-creation.md)
- [Cloud activity from a high-risk IP address](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-activity-from-a-high-risk-ip-address.md)
- [Cloud AI agent was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-ai-agent-was-modified.md)
- [Cloud compute instance user data script modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-compute-instance-user-data-script-modification.md)
- [Cloud compute serial console access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-compute-serial-console-access.md)
- [Cloud compute volume creation attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-compute-volume-creation-attempt.md)
- [Cloud email infrastructure enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-email-infrastructure-enumeration-activity.md)
- [Cloud email sending was enabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-email-sending-was-enabled.md)
- [Cloud email service activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-email-service-activity.md)
- [Cloud identity reached a throttling API rate](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-identity-reached-a-throttling-api-rate.md)
- [Cloud IMDS access followed by remote token usage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-imds-access-followed-by-remote-token-usage.md)
- [Cloud impersonation attempt by unusual identity type](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-impersonation-attempt-by-unusual-identity-type.md)
- [Cloud infrastructure discovery across multiple regions](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-infrastructure-discovery-across-multiple-regions.md)
- [Cloud infrastructure enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-infrastructure-enumeration-activity.md)
- [Cloud instance creation attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-instance-creation-attempt.md)
- [Cloud instance deletion attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-instance-deletion-attempt.md)
- [Cloud Organizational policy was created or modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-organizational-policy-was-created-or-modified.md)
- [Cloud penetration testing tool activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-penetration-testing-tool-activity.md)
- [Cloud resource logging was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-resource-logging-was-disabled.md)
- [Cloud snapshot created or modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-snapshot-created-or-modified.md)
- [Cloud snapshot of a database or storage instance was publicly shared](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-snapshot-of-a-database-or-storage-instance-was-publicly-shared.md)
- [Cloud storage automatic backup disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-storage-automatic-backup-disabled.md)
- [Cloud storage delete protection disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-storage-delete-protection-disabled.md)
- [Cloud user performed multiple actions that were denied](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-user-performed-multiple-actions-that-were-denied.md)
- [Cloud Watch alarm deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloud-watch-alarm-deletion.md)
- [CloudTrail logging deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/cloudtrail-logging-deletion.md)
- [Collection error](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/collection-error.md)
- [Command execution in a Kubernetes pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/command-execution-in-a-kubernetes-pod.md)
- [Command execution via AWS SSM](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/command-execution-via-aws-ssm.md)
- [Command execution via wmiexec](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/command-execution-via-wmiexec.md)
- [Command running with COMSPEC in the command line argument](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/command-running-with-comspec-in-the-command-line-argument.md)
- [Common third-party software name masquerading](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/common-third-party-software-name-masquerading.md)
- [Commonly abused AutoIT script connects to an external domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/commonly-abused-autoit-script-connects-to-an-external-domain.md)
- [Commonly abused AutoIT script drops an executable file to disk](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/commonly-abused-autoit-script-drops-an-executable-file-to-disk.md)
- [Commonly abused process launched as a system service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/commonly-abused-process-launched-as-a-system-service.md)
- [Compressing data using python](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/compressing-data-using-python.md)
- [Compute activity in dormant cloud region](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/compute-activity-in-dormant-cloud-region.md)
- [Conditional Access policy removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/conditional-access-policy-removed.md)
- [Conhost.exe spawned a suspicious cmd process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/conhost-exe-spawned-a-suspicious-cmd-process.md)
- [Contained process execution with a rare GitHub URL](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/contained-process-execution-with-a-rare-github-url.md)
- [Copy a process memory file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/copy-a-process-memory-file.md)
- [Copy a user's GnuPG directory with rsync](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/copy-a-user-s-gnupg-directory-with-rsync.md)
- [Correlation rule error](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/correlation-rule-error.md)
- [Creation or modification of the default command executed when opening an application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/creation-or-modification-of-the-default-command-executed-when-opening-an-application.md)
- [Credentials were added to Azure application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/credentials-were-added-to-azure-application.md)
- [Data encryption was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/data-encryption-was-disabled.md)
- [Data exfiltration from cloud database](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/data-exfiltration-from-cloud-database.md)
- [Data Sharing between GCP and Google Workspace was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/data-sharing-between-gcp-and-google-workspace-was-disabled.md)
- [Delayed Deletion of Files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/delayed-deletion-of-files.md)
- [Deletion of AD CS certificate database entries](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/deletion-of-ad-cs-certificate-database-entries.md)
- [Deletion of multiple cloud resources](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/deletion-of-multiple-cloud-resources.md)
- [Denied API call by a Kubernetes service account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/denied-api-call-by-a-kubernetes-service-account.md)
- [Device Registration Policy modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/device-registration-policy-modification.md)
- [Disable AWS audit logs through Event Selectors](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/disable-aws-audit-logs-through-event-selectors.md)
- [Disable encryption operations](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/disable-encryption-operations.md)
- [Disable Microsoft Defender Antivirus via registry](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/disable-microsoft-defender-antivirus-via-registry.md)
- [Discovery of accounts with pre-authentication disabled via LDAP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/discovery-of-accounts-with-pre-authentication-disabled-via-ldap.md)
- [Discovery of host users via WMIC](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/discovery-of-host-users-via-wmic.md)
- [Discovery of misconfigured certificate templates using LDAP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/discovery-of-misconfigured-certificate-templates-using-ldap.md)
- [Display text URL differs from actual URL](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/display-text-url-differs-from-actual-url.md)
- [DLP sensitive data exposed to external users](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/dlp-sensitive-data-exposed-to-external-users.md)
- [DNS Tunneling](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/dns-tunneling.md)
- [Download a script using the python requests module](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/download-a-script-using-the-python-requests-module.md)
- [Download pattern that resembles Peer to Peer traffic](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/download-pattern-that-resembles-peer-to-peer-traffic.md)
- [DSC (Desired State Configuration) lateral movement using PowerShell](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/dsc-desired-state-configuration-lateral-movement-using-powershell.md)
- [EBS snapshots were created from an EC2 instance](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ebs-snapshots-were-created-from-an-ec2-instance.md)
- [EBS volume attachment attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ebs-volume-attachment-attempt.md)
- [EBS volume detachment attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ebs-volume-detachment-attempt.md)
- [EC2 backdoor created with newly added external SSH or RDP access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ec2-backdoor-created-with-newly-added-external-ssh-or-rdp-access.md)
- [EC2 instance Amazon machine image was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ec2-instance-amazon-machine-image-was-created.md)
- [Elevation to SYSTEM via services](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/elevation-to-system-via-services.md)
- [Email attachment(s) with potentially malicious MIME type](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type.md)
- [Email attachment with a potentially malicious file extension](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension.md)
- [Email attachment with multiple extensions](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-attachment-with-multiple-extensions.md)
- [Email attachment with Right-to-Left Override Unicode character](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character.md)
- [Email containing a link with an IP address convention was detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected.md)
- [Email containing a redirected link](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-containing-a-redirected-link.md)
- [Email contains URL delivering high-risk file type](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-contains-url-delivering-high-risk-file-type.md)
- [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values.md)
- [Email mimics replies or forwards without an actual ongoing conversation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation.md)
- [Email sent using an automated system or script detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-sent-using-an-automated-system-or-script-detected.md)
- [Email was received from an unknown address using a public provider domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain.md)
- [Email was received from an unknown sender using a disposable domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain.md)
- [Email with file-sharing link containing auto-download parameter](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter.md)
- [Email with URL shortener detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/email-with-url-shortener-detected.md)
- [Encoded information using Windows certificate management tool](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/encoded-information-using-windows-certificate-management-tool.md)
- [Error in event forwarding](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/error-in-event-forwarding.md)
- [Excessive user account lockouts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/excessive-user-account-lockouts.md)
- [Exchange anti-phish policy disabled or removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-anti-phish-policy-disabled-or-removed.md)
- [Exchange audit log disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-audit-log-disabled.md)
- [Exchange compliance search created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-compliance-search-created.md)
- [Exchange DKIM signing configuration disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-dkim-signing-configuration-disabled.md)
- [Exchange email-hiding inbox rule](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-email-hiding-inbox-rule.md)
- [Exchange email-hiding transport rule](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-email-hiding-transport-rule.md)
- [Exchange inbox forwarding rule configured](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-inbox-forwarding-rule-configured.md)
- [Exchange mailbox audit bypass](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-mailbox-audit-bypass.md)
- [Exchange mailbox delegation permissions added](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-mailbox-delegation-permissions-added.md)
- [Exchange mailbox folder permission modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-mailbox-folder-permission-modification.md)
- [Exchange malware filter policy removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-malware-filter-policy-removed.md)
- [Exchange Safe Attachment policy disabled or removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-safe-attachment-policy-disabled-or-removed.md)
- [Exchange Safe Link policy disabled or removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-safe-link-policy-disabled-or-removed.md)
- [Exchange transport forwarding rule configured](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-transport-forwarding-rule-configured.md)
- [Exchange user mailbox forwarding](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/exchange-user-mailbox-forwarding.md)
- [Executable created to disk by lsass.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/executable-created-to-disk-by-lsass-exe.md)
- [Executable moved to Windows system folder](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/executable-moved-to-windows-system-folder.md)
- [Executable or Script file written by a web server process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/executable-or-script-file-written-by-a-web-server-process.md)
- [Execution of an uncommon process at an early startup stage by Windows system binary](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage-by-windows-system-binary.md)
- [Execution of an uncommon process at an early startup stage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage.md)
- [Execution of an uncommon process with a local/domain user SID at an early startup stage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage.md)
- [Execution of command from within a Kubernetes pod using kubelet credentials](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/execution-of-command-from-within-a-kubernetes-pod-using-kubelet-credentials.md)
- [Execution of dllhost.exe with an empty command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/execution-of-dllhost-exe-with-an-empty-command-line.md)
- [Execution of masqueraded third-party utility](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/execution-of-masqueraded-third-party-utility.md)
- [Execution of renamed lolbin](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/execution-of-renamed-lolbin.md)
- [External email display name impersonation of internal personnel](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel.md)
- [External email with a single internal recipient hidden in BCC](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc.md)
- [External Login Password Spray](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-login-password-spray.md)
- [External SaaS file-sharing activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-saas-file-sharing-activity.md)
- [External Sharing was turned on for Google Drive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-sharing-was-turned-on-for-google-drive.md)
- [External user added a link to a Microsoft Teams chat](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-user-added-a-link-to-a-microsoft-teams-chat.md)
- [External user call via Microsoft Teams](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-user-call-via-microsoft-teams.md)
- [External user created a Microsoft Teams conversation with suspicious operations](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-user-created-a-microsoft-teams-conversation-with-suspicious-operations.md)
- [External user invitation to Azure tenant](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-user-invitation-to-azure-tenant.md)
- [External user started a Microsoft Teams conversation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/external-user-started-a-microsoft-teams-conversation.md)
- [Extracting credentials from Unix files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/extracting-credentials-from-unix-files.md)
- [Failed Connections](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/failed-connections.md)
- [Failed DNS](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/failed-dns.md)
- [Failed Login For a Long Username With Special Characters](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/failed-login-for-a-long-username-with-special-characters.md)
- [Failed Login For Locked-Out Account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/failed-login-for-locked-out-account.md)
- [File transfer from unusual IP using known tools](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/file-transfer-from-unusual-ip-using-known-tools.md)
- [First Azure AD PowerShell operation for a user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-azure-ad-powershell-operation-for-a-user.md)
- [First connection from a country in organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-connection-from-a-country-in-organization.md)
- [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days.md)
- [First SSO access from ASN for user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-sso-access-from-asn-for-user.md)
- [First SSO access from ASN in organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-sso-access-from-asn-in-organization.md)
- [First SSO Resource Access in the Organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-sso-resource-access-in-the-organization.md)
- [First-time attachment exchange](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-time-attachment-exchange.md)
- [First-time directory sync of an on-premises domain user to an existing cloud account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-time-directory-sync-of-an-on-premises-domain-user-to-an-existing-cloud-account.md)
- [First VPN access attempt from a country in organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-vpn-access-attempt-from-a-country-in-organization.md)
- [First VPN access from ASN for user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-vpn-access-from-asn-for-user.md)
- [First VPN access from ASN in organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/first-vpn-access-from-asn-in-organization.md)
- [Fodhelper.exe UAC bypass](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/fodhelper-exe-uac-bypass.md)
- [Foreign account was granted permissions to S3 bucket via resource-based policy](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/foreign-account-was-granted-permissions-to-s3-bucket-via-resource-based-policy.md)
- [FTP Connection Using an Anonymous Login or Default Credentials](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ftp-connection-using-an-anonymous-login-or-default-credentials.md)
- [GCP administrative role granted to a cloud identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-administrative-role-granted-to-a-cloud-identity.md)
- [GCP data asset shared public](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-data-asset-shared-public.md)
- [GCP Firewall Rule creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-firewall-rule-creation.md)
- [GCP Firewall Rule Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-firewall-rule-modification.md)
- [GCP IAM deny policy creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-iam-deny-policy-creation.md)
- [GCP IAM Role Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-iam-role-deletion.md)
- [GCP IAM Service Account Key Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-iam-service-account-key-deletion.md)
- [GCP Logging Bucket Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-logging-bucket-deletion.md)
- [GCP logging sink deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-logging-sink-deletion.md)
- [GCP logging sink modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-logging-sink-modification.md)
- [GCP Pub/Sub Subscription Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-pub-sub-subscription-deletion.md)
- [GCP Pub/Sub Topic Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-pub-sub-topic-deletion.md)
- [GCP sensitive Cloud Run role granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-cloud-run-role-granted.md)
- [GCP sensitive compute role granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-compute-role-granted.md)
- [GCP sensitive Deployment Manager role granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-deployment-manager-role-granted.md)
- [GCP sensitive Functions role granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-functions-role-granted.md)
- [GCP sensitive IAM role granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-iam-role-granted.md)
- [GCP sensitive role granted to group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-role-granted-to-group.md)
- [GCP sensitive Secret Manager role granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-secret-manager-role-granted.md)
- [GCP sensitive storage role granted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-sensitive-storage-role-granted.md)
- [GCP Service Account creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-service-account-creation.md)
- [GCP Service Account Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-service-account-deletion.md)
- [GCP Service Account Disable](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-service-account-disable.md)
- [GCP service account impersonation attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-service-account-impersonation-attempt.md)
- [GCP Service Account key creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-service-account-key-creation.md)
- [GCP set IAM policy activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-set-iam-policy-activity.md)
- [GCP Storage Bucket Configuration Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-storage-bucket-configuration-modification.md)
- [GCP Storage Bucket deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-storage-bucket-deletion.md)
- [GCP Storage Bucket Permissions Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-storage-bucket-permissions-modification.md)
- [GCP Virtual Private Cloud (VPC) Network Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-virtual-private-cloud-vpc-network-deletion.md)
- [GCP Virtual Private Network Route Creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-virtual-private-network-route-creation.md)
- [GCP Virtual Private Network Route Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-virtual-private-network-route-deletion.md)
- [GCP VPC Firewall Rule Deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gcp-vpc-firewall-rule-deletion.md)
- [Globally uncommon high entropy module was loaded](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-high-entropy-module-was-loaded.md)
- [Globally uncommon high entropy process was executed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-high-entropy-process-was-executed.md)
- [Globally uncommon image load from a signed process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-image-load-from-a-signed-process.md)
- [Globally uncommon injection from a signed process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-injection-from-a-signed-process.md)
- [Globally uncommon IP address by a common process (sha256)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-ip-address-by-a-common-process-sha256.md)
- [Globally uncommon IP address connection from a signed process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-ip-address-connection-from-a-signed-process.md)
- [Globally uncommon process execution from a signed process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-process-execution-from-a-signed-process.md)
- [Globally uncommon root domain from a signed process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-root-domain-from-a-signed-process.md)
- [Globally uncommon root-domain port combination by a common process (sha256)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-root-domain-port-combination-by-a-common-process-sha256.md)
- [Globally uncommon root-domain port combination from a signed process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/globally-uncommon-root-domain-port-combination-from-a-signed-process.md)
- [Gmail delegation was turned on for the organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gmail-delegation-was-turned-on-for-the-organization.md)
- [Gmail routing settings changed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/gmail-routing-settings-changed.md)
- [Google Marketplace restrictions were modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/google-marketplace-restrictions-were-modified.md)
- [Google Workspace automation was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/google-workspace-automation-was-created.md)
- [Google Workspace organizational unit was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/google-workspace-organizational-unit-was-modified.md)
- [Google Workspace third-party application's security settings were changed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/google-workspace-third-party-application-s-security-settings-were-changed.md)
- [Google Workspace user authentication information changed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/google-workspace-user-authentication-information-changed.md)
- [Granting Access to an Account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/granting-access-to-an-account.md)
- [Hidden Attribute was added to a file using attrib.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/hidden-attribute-was-added-to-a-file-using-attrib-exe.md)
- [HTTP with suspicious characteristics](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/http-with-suspicious-characteristics.md)
- [Hydra Password Brute-Force Tool Execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/hydra-password-brute-force-tool-execution.md)
- [IAM Enumeration sequence](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-enumeration-sequence.md)
- [IAM inline policy was added to group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-inline-policy-was-added-to-group.md)
- [IAM inline policy was added to role](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-inline-policy-was-added-to-role.md)
- [IAM inline policy was added to user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-inline-policy-was-added-to-user.md)
- [IAM instance profile associations were described](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-instance-profile-associations-were-described.md)
- [IAM instance profile was associated with EC2 instance](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-instance-profile-was-associated-with-ec2-instance.md)
- [IAM instance profile was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-instance-profile-was-created.md)
- [IAM instance profile was replaced for EC2 instance](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-instance-profile-was-replaced-for-ec2-instance.md)
- [IAM policy default version was changed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-policy-default-version-was-changed.md)
- [IAM policy version was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-policy-version-was-created.md)
- [IAM policy was attached to group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-policy-was-attached-to-group.md)
- [IAM policy was attached to role](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-policy-was-attached-to-role.md)
- [IAM role-attached managed policies were listed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-role-attached-managed-policies-were-listed.md)
- [IAM role trust policy modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-role-trust-policy-modification.md)
- [IAM role was created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-role-was-created.md)
- [IAM User added to an IAM group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iam-user-added-to-an-iam-group.md)
- [Identity assigned an Azure AD Administrator Role](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/identity-assigned-an-azure-ad-administrator-role.md)
- [Image file execution options (IFEO) registry key set](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/image-file-execution-options-ifeo-registry-key-set.md)
- [Impossible travel by a cloud identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/impossible-travel-by-a-cloud-identity.md)
- [Impossible traveler - SSO](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/impossible-traveler-sso.md)
- [Impossible traveler - VPN](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/impossible-traveler-vpn.md)
- [Increase in Job-Related Site Visits](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/increase-in-job-related-site-visits.md)
- [Indicator blocking](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/indicator-blocking.md)
- [Indirect command execution using the Program Compatibility Assistant](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/indirect-command-execution-using-the-program-compatibility-assistant.md)
- [Initial person-to-person email contact](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/initial-person-to-person-email-contact.md)
- [Injection into rundll32.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/injection-into-rundll32-exe.md)
- [Installation of a new System-V service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/installation-of-a-new-system-v-service.md)
- [Intense SSO failures](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/intense-sso-failures.md)
- [Interactive at.exe privilege escalation method](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/interactive-at-exe-privilege-escalation-method.md)
- [Interactive local account enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/interactive-local-account-enumeration.md)
- [Interactive login by a machine account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/interactive-login-by-a-machine-account.md)
- [Interactive login by a service account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/interactive-login-by-a-service-account.md)
- [Interactive login from a shared user account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/interactive-login-from-a-shared-user-account.md)
- [Internal Login Password Spray](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/internal-login-password-spray.md)
- [Invalid SAML Detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/invalid-saml-detected.md)
- [IP Rotation Pattern in SSO Spray](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ip-rotation-pattern-in-sso-spray.md)
- [Iptables configuration command was executed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/iptables-configuration-command-was-executed.md)
- [Kerberos Pre-Auth Failures by Host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kerberos-pre-auth-failures-by-host.md)
- [Kerberos Pre-Auth Failures by User and Host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kerberos-pre-auth-failures-by-user-and-host.md)
- [Kerberos Traffic from Non-Standard Process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kerberos-traffic-from-non-standard-process.md)
- [Kerberos User Enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kerberos-user-enumeration.md)
- [Key credential attribute modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/key-credential-attribute-modification.md)
- [Keylogging using system commands](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/keylogging-using-system-commands.md)
- [Known service display name with uncommon image-path](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/known-service-display-name-with-uncommon-image-path.md)
- [Known service name with an uncommon image-path](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/known-service-name-with-an-uncommon-image-path.md)
- [Kubelet server communication from a pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubelet-server-communication-from-a-pod.md)
- [Kubernetes admission controller activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-admission-controller-activity.md)
- [Kubernetes API server communication from within a pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-api-server-communication-from-within-a-pod.md)
- [Kubernetes cluster events deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-cluster-events-deletion.md)
- [Kubernetes enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-enumeration-activity.md)
- [Kubernetes environment enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-environment-enumeration-activity.md)
- [Kubernetes network policy modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-network-policy-modification.md)
- [Kubernetes nsenter container escape](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-nsenter-container-escape.md)
- [Kubernetes Pod Created with host Inter Process Communications (IPC) namespace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-pod-created-with-host-inter-process-communications-ipc-namespace.md)
- [Kubernetes Pod created with host process ID (PID) namespace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-pod-created-with-host-process-id-pid-namespace.md)
- [Kubernetes Pod Created With Sensitive Volume](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-pod-created-with-sensitive-volume.md)
- [Kubernetes pod creation from unknown container image registry](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-pod-creation-from-unknown-container-image-registry.md)
- [Kubernetes pod creation with host network](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-pod-creation-with-host-network.md)
- [Kubernetes Privileged Pod Creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-privileged-pod-creation.md)
- [Kubernetes secret enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-secret-enumeration-activity.md)
- [Kubernetes secrets enumeration for the first time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-secrets-enumeration-for-the-first-time.md)
- [Kubernetes service account activity outside the cluster](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-service-account-activity-outside-the-cluster.md)
- [Kubernetes version disclosure](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-version-disclosure.md)
- [Kubernetes vulnerability scanner activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-vulnerability-scanner-activity.md)
- [Kubernetes vulnerability scanning tool usage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kubernetes-vulnerability-scanning-tool-usage.md)
- [Large Upload (FTP)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/large-upload-ftp.md)
- [Large Upload (Generic)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/large-upload-generic.md)
- [Large Upload (HTTPS)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/large-upload-https.md)
- [Large Upload (SMTP)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/large-upload-smtp.md)
- [Large volume of files potentially containing credentials accessed in Google Drive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/large-volume-of-files-potentially-containing-credentials-accessed-in-google-drive.md)
- [LDAP AD CS Enumeration via Attack Tool](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ldap-ad-cs-enumeration-via-attack-tool.md)
- [LDAP search query from an unpopular and unsigned process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ldap-search-query-from-an-unpopular-and-unsigned-process.md)
- [LDAP traffic from non-standard process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ldap-traffic-from-non-standard-process.md)
- [Linux local user account creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/linux-local-user-account-creation.md)
- [Linux network share discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/linux-network-share-discovery.md)
- [Linux process execution with a rare GitHub URL](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/linux-process-execution-with-a-rare-github-url.md)
- [Linux system firewall was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/linux-system-firewall-was-modified.md)
- [Local account discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/local-account-discovery.md)
- [Local group enumeration via RPC](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/local-group-enumeration-via-rpc.md)
- [Local group enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/local-group-enumeration.md)
- [Local user account creation by a machine account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/local-user-account-creation-by-a-machine-account.md)
- [Local user account creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/local-user-account-creation.md)
- [Local user enumeration via SAMR](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/local-user-enumeration-via-samr.md)
- [Log enumeration via cloud native logging service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/log-enumeration-via-cloud-native-logging-service.md)
- [Logging was impaired via external encryption key](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/logging-was-impaired-via-external-encryption-key.md)
- [Login attempt by a honey user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/login-attempt-by-a-honey-user.md)
- [Login by a dormant user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/login-by-a-dormant-user.md)
- [Logs were not collected from a data source for an abnormally long time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/logs-were-not-collected-from-a-data-source-for-an-abnormally-long-time.md)
- [LOLBAS executable injects into another process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/lolbas-executable-injects-into-another-process.md)
- [LOLBIN created a PSScriptPolicyTest PowerShell script file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/lolbin-created-a-psscriptpolicytest-powershell-script-file.md)
- [LOLBIN process executed with a high integrity level](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/lolbin-process-executed-with-a-high-integrity-level.md)
- [LSASS dump file written to disk](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/lsass-dump-file-written-to-disk.md)
- [Machine Account NTLM Relay](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/machine-account-ntlm-relay.md)
- [Machine account was added to a domain admins group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/machine-account-was-added-to-a-domain-admins-group.md)
- [Mailbox Client Access Setting (CAS) changed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mailbox-client-access-setting-cas-changed.md)
- [Mailbox enumeration activity by Azure application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mailbox-enumeration-activity-by-azure-application.md)
- [Manipulation of netsh helper DLLs Registry keys](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/manipulation-of-netsh-helper-dlls-registry-keys.md)
- [Masquerading as a default local account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/masquerading-as-a-default-local-account.md)
- [Masquerading as the Linux crond process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/masquerading-as-the-linux-crond-process.md)
- [Massive file activity abnormal to process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-file-activity-abnormal-to-process.md)
- [Massive file compression by user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-file-compression-by-user.md)
- [Massive file downloads from SaaS service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-file-downloads-from-saas-service.md)
- [Massive files deletion in Box](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-files-deletion-in-box.md)
- [Massive files deletion in Dropbox](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-files-deletion-in-dropbox.md)
- [Massive files deletion in Google Drive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-files-deletion-in-google-drive.md)
- [Massive files deletion in Microsoft SharePoint or OneDrive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-files-deletion-in-microsoft-sharepoint-or-onedrive.md)
- [Massive upload to a rare storage or mail domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-upload-to-a-rare-storage-or-mail-domain.md)
- [Massive upload to SaaS service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/massive-upload-to-saas-service.md)
- [Member added to a Windows local security group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/member-added-to-a-windows-local-security-group.md)
- [Memory dumping with comsvcs.dll](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/memory-dumping-with-comsvcs-dll.md)
- [MFA device was removed/deactivated from an IAM user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mfa-device-was-removed-deactivated-from-an-iam-user.md)
- [MFA Disabled for Google Workspace](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mfa-disabled-for-google-workspace.md)
- [MFA was disabled for a Google Workspace user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mfa-was-disabled-for-a-google-workspace-user.md)
- [MFA was disabled for an Azure identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mfa-was-disabled-for-an-azure-identity.md)
- [Microsoft 365 DLP policy disabled or removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-365-dlp-policy-disabled-or-removed.md)
- [Microsoft 365 storage services exfiltration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-365-storage-services-exfiltration-activity.md)
- [Microsoft Configuration Manager device registration and policy request](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-configuration-manager-device-registration-and-policy-request.md)
- [Microsoft Office adds a value to autostart Registry key](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-office-adds-a-value-to-autostart-registry-key.md)
- [Microsoft Office injects code into a process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-office-injects-code-into-a-process.md)
- [Microsoft Office Process Spawning a Suspicious One-Liner](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-office-process-spawning-a-suspicious-one-liner.md)
- [Microsoft Office process spawns a commonly abused process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-office-process-spawns-a-commonly-abused-process.md)
- [Microsoft Office process spawns conhost.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-office-process-spawns-conhost-exe.md)
- [Microsoft OneDrive enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-onedrive-enumeration-activity.md)
- [Microsoft OneNote enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-onenote-enumeration-activity.md)
- [Microsoft SharePoint enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-sharepoint-enumeration-activity.md)
- [Microsoft Teams application setup policy was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-teams-application-setup-policy-was-modified.md)
- [Microsoft Teams enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-teams-enumeration-activity.md)
- [Microsoft Teams external communication policy was modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-teams-external-communication-policy-was-modified.md)
- [Microsoft Teams messages were exported from conversation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/microsoft-teams-messages-were-exported-from-conversation.md)
- [Mimikatz command-line arguments](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mimikatz-command-line-arguments.md)
- [ML artifacts destruction](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ml-artifacts-destruction.md)
- [Modification of NTLM restrictions in the Registry](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/modification-of-ntlm-restrictions-in-the-registry.md)
- [Modification of PAM](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/modification-of-pam.md)
- [Modification of the AD FS IdentityServer configuration file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/modification-of-the-ad-fs-identityserver-configuration-file.md)
- [Modification or Deletion of an Azure Application Gateway Detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/modification-or-deletion-of-an-azure-application-gateway-detected.md)
- [Moniker link detected in URL(s)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/moniker-link-detected-in-url-s.md)
- [Mount command was executed from within a Kubernetes pod to list all the attached filesystems](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mount-command-was-executed-from-within-a-kubernetes-pod-to-list-all-the-attached-filesystems.md)
- [MpCmdRun.exe was used to download files into the system](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mpcmdrun-exe-was-used-to-download-files-into-the-system.md)
- [Mshta.exe launched with suspicious arguments](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mshta-exe-launched-with-suspicious-arguments.md)
- [Mshta.exe spawns from a browser process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/mshta-exe-spawns-from-a-browser-process.md)
- [MSI accessed a web page running a server-side script](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/msi-accessed-a-web-page-running-a-server-side-script.md)
- [Msiexec execution of an executable from an uncommon remote location](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/msiexec-execution-of-an-executable-from-an-uncommon-remote-location.md)
- [Multi region enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multi-region-enumeration-activity.md)
- [Multiple alerts associated with a single RDP connection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-alerts-associated-with-a-single-rdp-connection.md)
- [Multiple alerts of different MITRE tactics were seen](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-alerts-of-different-mitre-tactics-were-seen.md)
- [Multiple Azure AD admin role removals](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-azure-ad-admin-role-removals.md)
- [Multiple cloud snapshots export](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-cloud-snapshots-export.md)
- [Multiple discovery commands on a Linux host by the same process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-discovery-commands-on-a-linux-host-by-the-same-process.md)
- [Multiple discovery commands on a Windows host by the same process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-discovery-commands-on-a-windows-host-by-the-same-process.md)
- [Multiple discovery commands](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-discovery-commands.md)
- [Multiple discovery-like commands](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-discovery-like-commands.md)
- [Multiple failed AWS assume role attempts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-failed-aws-assume-role-attempts.md)
- [Multiple failed logins from a single IP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-failed-logins-from-a-single-ip.md)
- [Multiple network-related alerts of different MITRE tactics on the same host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-network-related-alerts-of-different-mitre-tactics-on-the-same-host.md)
- [Multiple network-related alerts produced by different detectors on the same host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-network-related-alerts-produced-by-different-detectors-on-the-same-host.md)
- [Multiple Okta MFA requests sent to a user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-okta-mfa-requests-sent-to-a-user.md)
- [Multiple Rare LOLBIN Process Executions by User](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-rare-lolbin-process-executions-by-user.md)
- [Multiple Rare Process Executions in Organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-rare-process-executions-in-organization.md)
- [Multiple risk indicators for a cloud identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-risk-indicators-for-a-cloud-identity.md)
- [Multiple Suspicious FTP Login Attempts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-suspicious-ftp-login-attempts.md)
- [Multiple suspicious user accounts were created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-suspicious-user-accounts-were-created.md)
- [Multiple TGT requests for users without Kerberos pre-authentication](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-tgt-requests-for-users-without-kerberos-pre-authentication.md)
- [Multiple uncommon SSH Servers with the same Server host key](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-uncommon-ssh-servers-with-the-same-server-host-key.md)
- [Multiple user accounts failed login due to account lockouts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-user-accounts-failed-login-due-to-account-lockouts.md)
- [Multiple user accounts were deleted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-user-accounts-were-deleted.md)
- [Multiple users authenticated with weak NTLM to a host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-users-authenticated-with-weak-ntlm-to-a-host.md)
- [Multiple Weakly-Encrypted Kerberos Tickets Received](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/multiple-weakly-encrypted-kerberos-tickets-received.md)
- [Near-empty email from an external sender](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/near-empty-email-from-an-external-sender.md)
- [Netcat makes or gets connections](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/netcat-makes-or-gets-connections.md)
- [Network sniffing detected in Cloud environment](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/network-sniffing-detected-in-cloud-environment.md)
- [New addition to Windows Defender exclusion list](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/new-addition-to-windows-defender-exclusion-list.md)
- [New Administrative Behavior](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/new-administrative-behavior.md)
- [New cloud identity created with administrative policy](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/new-cloud-identity-created-with-administrative-policy.md)
- [New FTP Server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/new-ftp-server.md)
- [New Shared User Account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/new-shared-user-account.md)
- [New Teams application published to the organization catalog](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/new-teams-application-published-to-the-organization-catalog.md)
- [Non-browser access to a pastebin-like site](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/non-browser-access-to-a-pastebin-like-site.md)
- [NTDS.dit file written by an uncommon executable](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ntds-dit-file-written-by-an-uncommon-executable.md)
- [NTLM Brute Force on a Service Account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ntlm-brute-force-on-a-service-account.md)
- [NTLM Brute Force on an Administrator Account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ntlm-brute-force-on-an-administrator-account.md)
- [NTLM Brute Force](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ntlm-brute-force.md)
- [NTLM Hash Harvesting](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ntlm-hash-harvesting.md)
- [NTLM Password Spray](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ntlm-password-spray.md)
- [NTLM Relay](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ntlm-relay.md)
- [Numerous emails sent by a single sender to multiple internal recipients](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients.md)
- [Object versioning was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/object-versioning-was-disabled.md)
- [Office process accessed an unusual .LNK file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/office-process-accessed-an-unusual-lnk-file.md)
- [Office process spawned with suspicious command-line arguments](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/office-process-spawned-with-suspicious-command-line-arguments.md)
- [Okta account reset password attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-account-reset-password-attempt.md)
- [Okta account unlock by admin](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-account-unlock-by-admin.md)
- [Okta account unlock](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-account-unlock.md)
- [Okta admin privilege assignment](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-admin-privilege-assignment.md)
- [Okta API Token Created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-api-token-created.md)
- [Okta device assignment](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-device-assignment.md)
- [Okta FastPass reported phishing attack suspected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-fastpass-reported-phishing-attack-suspected.md)
- [Okta Reported Attack Suspected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-reported-attack-suspected.md)
- [Okta Reported Threat Detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-reported-threat-detected.md)
- [Okta User Session Impersonation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/okta-user-session-impersonation.md)
- [OneDrive file download](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/onedrive-file-download.md)
- [OneDrive file upload](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/onedrive-file-upload.md)
- [OneDrive folder creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/onedrive-folder-creation.md)
- [Outbound email contains file-sharing service link sent to external recipient](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient.md)
- [Outbound email includes an external BCC recipient observed for the first time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time.md)
- [Outbound email to an address hosted by a public email service provider](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider.md)
- [Outlook files accessed by an unsigned process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/outlook-files-accessed-by-an-unsigned-process.md)
- [Owner added to Azure application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/owner-added-to-azure-application.md)
- [Owner was added to Azure application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/owner-was-added-to-azure-application.md)
- [Parsing Rule Error](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/parsing-rule-error.md)
- [Penetration testing tool activity attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/penetration-testing-tool-activity-attempt.md)
- [Permission Groups discovery commands](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/permission-groups-discovery-commands.md)
- [Phantom DLL Loading](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/phantom-dll-loading.md)
- [PIM privilege member removal](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/pim-privilege-member-removal.md)
- [Ping to localhost from an uncommon, unsigned parent process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ping-to-localhost-from-an-uncommon-unsigned-parent-process.md)
- [PKINIT TGT authentication request](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/pkinit-tgt-authentication-request.md)
- [Port Scan](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/port-scan.md)
- [Port Sweep](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/port-sweep.md)
- [Possible AS-REP Roasting Attack](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-as-rep-roasting-attack.md)
- [Possible authentication coercion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-authentication-coercion.md)
- [Possible binary padding using dd](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-binary-padding-using-dd.md)
- [Possible Brute-Force attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-brute-force-attempt.md)
- [Possible brute force on sudo user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-brute-force-on-sudo-user.md)
- [Possible brute force or configuration change attempt on cytool](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-brute-force-or-configuration-change-attempt-on-cytool.md)
- [Possible code downloading from a remote host by Regsvr32](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-code-downloading-from-a-remote-host-by-regsvr32.md)
- [Possible collection of screen captures with Windows Problem Steps Recorder](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-collection-of-screen-captures-with-windows-problem-steps-recorder.md)
- [Possible compromised machine account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-compromised-machine-account.md)
- [Possible ConsentFix - OAuth Token Theft Detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-consentfix-oauth-token-theft-detected.md)
- [Possible data exfiltration over a USB storage device](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-data-exfiltration-over-a-usb-storage-device.md)
- [Possible data obfuscation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-data-obfuscation.md)
- [Possible DCSync from a non domain controller](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-dcsync-from-a-non-domain-controller.md)
- [Possible Distributed File System Namespace Management (DFSNM) abuse](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-distributed-file-system-namespace-management-dfsnm-abuse.md)
- [Possible DLL Hijack into a Microsoft process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-dll-hijack-into-a-microsoft-process.md)
- [Possible DLL Search Order Hijacking](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-dll-search-order-hijacking.md)
- [Possible Email collection using Outlook RPC](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-email-collection-using-outlook-rpc.md)
- [Possible external RDP Brute-Force](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-external-rdp-brute-force.md)
- [Possible GPO Enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-gpo-enumeration.md)
- [Possible Impossible Travel Pattern - SSO](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-impossible-travel-pattern-sso.md)
- [Possible Insider Threat Activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-insider-threat-activity.md)
- [Possible internal data exfiltration over a USB storage device](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-internal-data-exfiltration-over-a-usb-storage-device.md)
- [Possible IPFS traffic was detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-ipfs-traffic-was-detected.md)
- [Possible Kerberoasting attack](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-kerberoasting-attack.md)
- [Possible Kerberoasting without SPNs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-kerberoasting-without-spns.md)
- [Possible Kerberos relay attack](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-kerberos-relay-attack.md)
- [Possible Kerberos User Enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-kerberos-user-enumeration.md)
- [Possible LDAP enumeration by unsigned process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-ldap-enumeration-by-unsigned-process.md)
- [Possible LDAP Enumeration of Microsoft Configuration Manager](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-ldap-enumeration-of-microsoft-configuration-manager.md)
- [Possible LDAP Enumeration Tool Usage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-ldap-enumeration-tool-usage.md)
- [Possible malicious .NET compilation started by a commonly abused process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-malicious-net-compilation-started-by-a-commonly-abused-process.md)
- [Possible multistage attack in Microsoft Teams](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-multistage-attack-in-microsoft-teams.md)
- [Possible network service discovery via command-line tool](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-network-service-discovery-via-command-line-tool.md)
- [Possible network sniffing attempt via tcpdump or tshark](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-network-sniffing-attempt-via-tcpdump-or-tshark.md)
- [Possible new DHCP server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-new-dhcp-server.md)
- [Possible Pass-the-Hash](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-pass-the-hash.md)
- [Possible path traversal via HTTP request](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-path-traversal-via-http-request.md)
- [Possible Persistence via group policy Registry keys](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-persistence-via-group-policy-registry-keys.md)
- [Possible phishing attack via Microsoft Teams](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-phishing-attack-via-microsoft-teams.md)
- [Possible Privilege Escalation using Delegated MSA account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-privilege-escalation-using-delegated-msa-account.md)
- [Possible RDP session hijacking using tscon.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-rdp-session-hijacking-using-tscon-exe.md)
- [Possible Search For Password Files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-search-for-password-files.md)
- [Possible SPN enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-spn-enumeration.md)
- [Possible TGT reuse from different hosts (pass the ticket)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-tgt-reuse-from-different-hosts-pass-the-ticket.md)
- [Possible use of a networking driver for network sniffing](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-use-of-a-networking-driver-for-network-sniffing.md)
- [Possible use of IPFS was detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-use-of-ipfs-was-detected.md)
- [Possible webshell file written by a web server process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/possible-webshell-file-written-by-a-web-server-process.md)
- [Potential creation of persistent cloud credentials](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-creation-of-persistent-cloud-credentials.md)
- [Potential DCSync by an unusual user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-dcsync-by-an-unusual-user.md)
- [Potential denial of wallet abusing AI services](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-denial-of-wallet-abusing-ai-services.md)
- [Potential extraction of NAA Account Credentials in Microsoft Configuration Manager](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-extraction-of-naa-account-credentials-in-microsoft-configuration-manager.md)
- [Potential kubelet impersonation attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-kubelet-impersonation-attempt.md)
- [Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-ntlm-relay-attack-against-a-microsoft-configuration-manager-site-server.md)
- [Potential NTLM Relay Attack](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-ntlm-relay-attack.md)
- [Potential Okta access limit breach](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-okta-access-limit-breach.md)
- [Potential Phishing has been detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-phishing-has-been-detected.md)
- [Potential SCCM credential harvesting using WMI detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-sccm-credential-harvesting-using-wmi-detected.md)
- [Potential spoofing of internal domain spotted](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/potential-spoofing-of-internal-domain-spotted.md)
- [PowerShell Initiates a Network Connection to GitHub](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/powershell-initiates-a-network-connection-to-github.md)
- [PowerShell pfx certificate extraction](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/powershell-pfx-certificate-extraction.md)
- [PowerShell runs suspicious base64-encoded commands](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/powershell-runs-suspicious-base64-encoded-commands.md)
- [PowerShell suspicious flags](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/powershell-suspicious-flags.md)
- [PowerShell used to export mailbox contents](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/powershell-used-to-export-mailbox-contents.md)
- [PowerShell used to remove mailbox export request logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/powershell-used-to-remove-mailbox-export-request-logs.md)
- [Privileged certificate request via certificate template](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/privileged-certificate-request-via-certificate-template.md)
- [Privileged role used by Azure application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/privileged-role-used-by-azure-application.md)
- [Procdump executed from an atypical directory](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/procdump-executed-from-an-atypical-directory.md)
- [PsExec was executed with a suspicious command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/psexec-was-executed-with-a-suspicious-command-line.md)
- [Punycode characters detected in URL(s)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/punycode-characters-detected-in-url-s.md)
- [Python HTTP server started](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/python-http-server-started.md)
- [Quarantined email released to recipients](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/quarantined-email-released-to-recipients.md)
- [Random-Looking Domain Names](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/random-looking-domain-names.md)
- [Rare access to known advertising domains](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-access-to-known-advertising-domains.md)
- [Rare AppID usage to a rare destination](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-appid-usage-to-a-rare-destination.md)
- [Rare binary connected to a rare cloud resource](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-binary-connected-to-a-rare-cloud-resource.md)
- [Rare binary connected to a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-binary-connected-to-a-rare-external-host.md)
- [Rare communication over email ports to external email server by unsigned process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-communication-over-email-ports-to-external-email-server-by-unsigned-process.md)
- [Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-connection-to-external-ip-address-or-host-by-an-application-using-rmi-iiop-or-ldap-protocol.md)
- [Rare DCOM RPC activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-dcom-rpc-activity.md)
- [Rare DLP rule match by user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-dlp-rule-match-by-user.md)
- [Rare file transfer over SMB protocol](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-file-transfer-over-smb-protocol.md)
- [Rare LDAP enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-ldap-enumeration.md)
- [Rare LOLBIN Process Execution by User](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-lolbin-process-execution-by-user.md)
- [Rare machine account creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-machine-account-creation.md)
- [Rare MS-Update Server was detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-ms-update-server-was-detected.md)
- [Rare MS-Update traffic over HTTP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-ms-update-traffic-over-http.md)
- [Rare NTLM Access By User To Host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-ntlm-access-by-user-to-host.md)
- [Rare NTLM Usage by User](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-ntlm-usage-by-user.md)
- [Rare process accessed a Keychain file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-accessed-a-keychain-file.md)
- [Rare process created an SSH session to an uncommon cloud resource](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-cloud-resource.md)
- [Rare process created an SSH session to an uncommon external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-external-host.md)
- [Rare process executed by an AppleScript](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-executed-by-an-applescript.md)
- [Rare process execution by user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-execution-by-user.md)
- [Rare process execution in organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-execution-in-organization.md)
- [Rare process spawned by srvany.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-spawned-by-srvany-exe.md)
- [Rare process with VNC server capabilities started](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-process-with-vnc-server-capabilities-started.md)
- [Rare RDP session to a remote host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-rdp-session-to-a-remote-host.md)
- [Rare Remote Service (SVCCTL) RPC activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-remote-service-svcctl-rpc-activity.md)
- [Rare scheduled task created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-scheduled-task-created.md)
- [Rare Scheduled Task RPC activity from a rarely seen host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-scheduled-task-rpc-activity-from-a-rarely-seen-host.md)
- [Rare Scheduled Task RPC activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-scheduled-task-rpc-activity.md)
- [Rare security product signed executable executed in the network](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-security-product-signed-executable-executed-in-the-network.md)
- [Rare service DLL was added to the registry](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-service-dll-was-added-to-the-registry.md)
- [Rare signature signed executable executed in the network](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-signature-signed-executable-executed-in-the-network.md)
- [Rare SMB session to a remote host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-smb-session-to-a-remote-host.md)
- [Rare SMTP/S Session](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-smtp-s-session.md)
- [Rare SSH Session](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-ssh-session.md)
- [Rare Unix process divided files by size](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-unix-process-divided-files-by-size.md)
- [Rare unsigned process execution by scheduled task](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-unsigned-process-execution-by-scheduled-task.md)
- [Rare Unsigned Process Spawned by Office Process Under Suspicious Directory](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-unsigned-process-spawned-by-office-process-under-suspicious-directory.md)
- [Rare Windows Remote Management (WinRM) HTTP Activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-windows-remote-management-winrm-http-activity.md)
- [Rare WinRM Session](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rare-winrm-session.md)
- [Rarely seen sender address in the organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rarely-seen-sender-address-in-the-organization.md)
- [Rarely seen sender domain in the organization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rarely-seen-sender-domain-in-the-organization.md)
- [RDP Connection to localhost](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rdp-connection-to-localhost.md)
- [RDP connections enabled remotely via Registry](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rdp-connections-enabled-remotely-via-registry.md)
- [RDP from an unmanaged endpoint in a typically managed subnet](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rdp-from-an-unmanaged-endpoint-in-a-typically-managed-subnet.md)
- [Reading bash command history file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/reading-bash-command-history-file.md)
- [Recurring access to rare domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/recurring-access-to-rare-domain.md)
- [Recurring access to rare IP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/recurring-access-to-rare-ip.md)
- [Recurring rare domain access from an unsigned process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/recurring-rare-domain-access-from-an-unsigned-process.md)
- [Recurring rare domain access to dynamic DNS domain](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/recurring-rare-domain-access-to-dynamic-dns-domain.md)
- [Registration of Uncommon .NET Services and/or Assemblies](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/registration-of-uncommon-net-services-and-or-assemblies.md)
- [Remote account enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-account-enumeration.md)
- [Remote code execution into Kubernetes Pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-code-execution-into-kubernetes-pod.md)
- [Remote command execution via wmic.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-command-execution-via-wmic-exe.md)
- [Remote DCOM command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-dcom-command-execution.md)
- [Remote PsExec-like command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-psexec-like-command-execution.md)
- [Remote service command execution from an uncommon source](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-service-command-execution-from-an-uncommon-source.md)
- [Remote service start from an uncommon source](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-service-start-from-an-uncommon-source.md)
- [Remote usage of an App engine Service Account token](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-usage-of-an-app-engine-service-account-token.md)
- [Remote usage of an AWS service token](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-usage-of-an-aws-service-token.md)
- [Remote usage of an Azure Managed Identity token](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-usage-of-an-azure-managed-identity-token.md)
- [Remote usage of an Azure Service Principal token](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-usage-of-an-azure-service-principal-token.md)
- [Remote usage of AWS Lambda's role](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-usage-of-aws-lambda-s-role.md)
- [Remote usage of VM Service Account token](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-usage-of-vm-service-account-token.md)
- [Remote WMI process execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/remote-wmi-process-execution.md)
- [Removal of an Azure Owner from an Application or Service Principal](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/removal-of-an-azure-owner-from-an-application-or-service-principal.md)
- [Retrieval of cloud compute EC2 instance user data](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/retrieval-of-cloud-compute-ec2-instance-user-data.md)
- [Retrieval of kubelet credentials](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/retrieval-of-kubelet-credentials.md)
- [Run downloaded script using pipe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/run-downloaded-script-using-pipe.md)
- [Rundll32.exe executes a rare unsigned module](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rundll32-exe-executes-a-rare-unsigned-module.md)
- [Rundll32.exe running with no command-line arguments](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rundll32-exe-running-with-no-command-line-arguments.md)
- [Rundll32.exe spawns conhost.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/rundll32-exe-spawns-conhost-exe.md)
- [S3 configuration deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/s3-configuration-deletion.md)
- [SAAS - Email was reported by the user or administrator as a phishing attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/saas-email-was-reported-by-the-user-or-administrator-as-a-phishing-attempt.md)
- [SaaS suspicious external domain user activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/saas-suspicious-external-domain-user-activity.md)
- [SCCM log files enumeration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sccm-log-files-enumeration.md)
- [Scheduled Task hidden by registry modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/scheduled-task-hidden-by-registry-modification.md)
- [Scrcons.exe Rare Child Process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/scrcons-exe-rare-child-process.md)
- [Screensaver process executed from Users or temporary folder](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/screensaver-process-executed-from-users-or-temporary-folder.md)
- [Script file added to startup-related Registry keys](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/script-file-added-to-startup-related-registry-keys.md)
- [Scripting engine connected to a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/scripting-engine-connected-to-a-rare-external-host.md)
- [SecureBoot was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/secureboot-was-disabled.md)
- [Security object deletion in Google Workspace Admin Console](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/security-object-deletion-in-google-workspace-admin-console.md)
- [Security tools detection attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/security-tools-detection-attempt.md)
- [Sending unusual file(s) to an external address](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sending-unusual-file-s-to-an-external-address.md)
- [Sensitive account password reset attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sensitive-account-password-reset-attempt.md)
- [Sensitive browser credential files accessed by a rare non browser process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sensitive-browser-credential-files-accessed-by-a-rare-non-browser-process.md)
- [Sensitive Exchange mail sent to external users](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sensitive-exchange-mail-sent-to-external-users.md)
- [Serial console access was enabled in AWS account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/serial-console-access-was-enabled-in-aws-account.md)
- [Service execution via sc.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/service-execution-via-sc-exe.md)
- [Service ticket request with a spoofed sAMAccountName](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/service-ticket-request-with-a-spoofed-samaccountname.md)
- [SES Production Access Requested](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ses-production-access-requested.md)
- [Setting Windows Auto Logon by uncommon process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/setting-windows-auto-logon-by-uncommon-process.md)
- [Setuid and Setgid file bit manipulation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/setuid-and-setgid-file-bit-manipulation.md)
- [SharePoint Site Collection admin group addition](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sharepoint-site-collection-admin-group-addition.md)
- [Short-lived Azure AD user account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/short-lived-azure-ad-user-account.md)
- [Short-lived user account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/short-lived-user-account.md)
- [Signed process creates a scheduled task via file access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/signed-process-creates-a-scheduled-task-via-file-access.md)
- [Signed process performed an unpopular DLL injection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/signed-process-performed-an-unpopular-dll-injection.md)
- [Signed process performed an unpopular injection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/signed-process-performed-an-unpopular-injection.md)
- [Single account excessively locked out](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/single-account-excessively-locked-out.md)
- [SMB Traffic from Non-Standard Process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/smb-traffic-from-non-standard-process.md)
- [Soft delete of cloud storage configuration was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/soft-delete-of-cloud-storage-configuration-was-disabled.md)
- [Space after filename](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/space-after-filename.md)
- [Spam Bot Traffic](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/spam-bot-traffic.md)
- [SPNs cleared from a machine account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/spns-cleared-from-a-machine-account.md)
- [SSH authentication brute force attempts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ssh-authentication-brute-force-attempts.md)
- [SSO authentication attempt by a honey user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-authentication-attempt-by-a-honey-user.md)
- [SSO authentication by a machine account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-authentication-by-a-machine-account.md)
- [SSO authentication by a service account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-authentication-by-a-service-account.md)
- [SSO Brute Force](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-brute-force.md)
- [SSO Password Spray](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-password-spray.md)
- [SSO with abnormal operating system](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-with-abnormal-operating-system.md)
- [SSO with abnormal user agent](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-with-abnormal-user-agent.md)
- [SSO with new operating system](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sso-with-new-operating-system.md)
- [Storage enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/storage-enumeration-activity.md)
- [Stored credentials exported using credwiz.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/stored-credentials-exported-using-credwiz-exe.md)
- [Subdomain Fuzzing](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/subdomain-fuzzing.md)
- [Successful unusual guest user invitation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/successful-unusual-guest-user-invitation.md)
- [Sudden spike in outbound email volume](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sudden-spike-in-outbound-email-volume.md)
- [Sudoedit Brute force attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/sudoedit-brute-force-attempt.md)
- [SUID/GUID permission discovery](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suid-guid-permission-discovery.md)
- [Suspicious access of the System Management Container](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-access-of-the-system-management-container.md)
- [Suspicious access to cloud credential files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-access-to-cloud-credential-files.md)
- [Suspicious access to Kubernetes API with kubelet credentials](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-access-to-kubernetes-api-with-kubelet-credentials.md)
- [Suspicious access to shadow file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-access-to-shadow-file.md)
- [Suspicious account attribute modification that matches that of another account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-account-attribute-modification-that-matches-that-of-another-account.md)
- [Suspicious active setup registered](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-active-setup-registered.md)
- [Suspicious activity indicating a potential abuse of a cloud-native email service](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-activity-indicating-a-potential-abuse-of-a-cloud-native-email-service.md)
- [Suspicious activity on logging bucket](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-activity-on-logging-bucket.md)
- [Suspicious AI Dataset Download](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ai-dataset-download.md)
- [Suspicious AI Dataset Label Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ai-dataset-label-modification.md)
- [Suspicious AI model usage from a Tor exit node](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ai-model-usage-from-a-tor-exit-node.md)
- [Suspicious AMSI decode attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-amsi-decode-attempt.md)
- [Suspicious API call from a Tor exit node](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-api-call-from-a-tor-exit-node.md)
- [Suspicious authentication package registered](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-authentication-package-registered.md)
- [Suspicious authentication with Azure Password Hash Sync user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-authentication-with-azure-password-hash-sync-user.md)
- [Suspicious AWS SSM parameters retrieval activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-aws-ssm-parameters-retrieval-activity.md)
- [Suspicious Azure AD interactive sign-in using PowerShell](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-azure-ad-interactive-sign-in-using-powershell.md)
- [Suspicious Azure enumeration activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-azure-enumeration-activity.md)
- [Suspicious brand affiliation detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-brand-affiliation-detected.md)
- [Suspicious certificate template modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-certificate-template-modification.md)
- [Suspicious Certutil AD CS contact](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-certutil-ad-cs-contact.md)
- [Suspicious certutil command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-certutil-command-line.md)
- [Suspicious cloud compute instance SSH keys modification attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-cloud-compute-instance-ssh-keys-modification-attempt.md)
- [Suspicious cloud user data modification attempt followed by VM restart](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-cloud-user-data-modification-attempt-followed-by-vm-restart.md)
- [Suspicious container orchestration job](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-container-orchestration-job.md)
- [Suspicious container reconnaissance activity in a Kubernetes pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-container-reconnaissance-activity-in-a-kubernetes-pod.md)
- [Suspicious container runtime connection from within a Kubernetes Pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-container-runtime-connection-from-within-a-kubernetes-pod.md)
- [Suspicious curl user agent](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-curl-user-agent.md)
- [Suspicious data encryption](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-data-encryption.md)
- [Suspicious disablement of the Windows Firewall using PowerShell commands](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-disablement-of-the-windows-firewall-using-powershell-commands.md)
- [Suspicious disablement of the Windows Firewall](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-disablement-of-the-windows-firewall.md)
- [Suspicious DKIM Result](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-dkim-result.md)
- [Suspicious DMARC result](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-dmarc-result.md)
- [Suspicious DNS traffic](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-dns-traffic.md)
- [Suspicious dNSHostName attribute change to DC name](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-dnshostname-attribute-change-to-dc-name.md)
- [Suspicious docker image download from an unusual repository](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-docker-image-download-from-an-unusual-repository.md)
- [Suspicious domain user account creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-domain-user-account-creation.md)
- [Suspicious DotNet log file created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-dotnet-log-file-created.md)
- [Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-dump-of-ntds-dit-using-shadow-copy-with-ntdsutil-vssadmin.md)
- [Suspicious EBS snapshots deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ebs-snapshots-deletion.md)
- [Suspicious Encrypting File System Remote call (EFSRPC) to domain controller](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-encrypting-file-system-remote-call-efsrpc-to-domain-controller.md)
- [Suspicious External RDP Login](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-external-rdp-login.md)
- [Suspicious failed HTTP request - potential Spring4Shell exploit](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-failed-http-request-potential-spring4shell-exploit.md)
- [Suspicious heavy allocation of compute resources - possible mining activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-heavy-allocation-of-compute-resources-possible-mining-activity.md)
- [Suspicious hidden user created](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-hidden-user-created.md)
- [Suspicious HTTP parameters detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-http-parameters-detected.md)
- [Suspicious ICMP packet](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-icmp-packet.md)
- [Suspicious ICMP traffic that resembles smurf attack](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-icmp-traffic-that-resembles-smurf-attack.md)
- [Suspicious identity downloaded multiple objects from a bucket](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-identity-downloaded-multiple-objects-from-a-bucket.md)
- [Suspicious Kerberos Pre-Auth Failures by Host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-kerberos-pre-auth-failures-by-host.md)
- [Suspicious Kubernetes pod token access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-kubernetes-pod-token-access.md)
- [Suspicious LDAP queries followed by shared folder access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ldap-queries-followed-by-shared-folder-access.md)
- [Suspicious LDAP search query executed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ldap-search-query-executed.md)
- [Suspicious MFA request reported by user in Entra ID](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-mfa-request-reported-by-user-in-entra-id.md)
- [Suspicious ML Model Download](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ml-model-download.md)
- [Suspicious modification of the AdminSDHolder's ACL](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-modification-of-the-adminsdholder-s-acl.md)
- [Suspicious module load using direct syscall](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-module-load-using-direct-syscall.md)
- [Suspicious .NET process loads an MSBuild DLL](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-net-process-loads-an-msbuild-dll.md)
- [Suspicious Network Connection Originating from AWS SSM Agent](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-network-connection-originating-from-aws-ssm-agent.md)
- [Suspicious NTLM authentication with machine account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ntlm-authentication-with-machine-account.md)
- [Suspicious objects encryption in an AWS bucket](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-objects-encryption-in-an-aws-bucket.md)
- [Suspicious PowerShell Command Line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-powershell-command-line.md)
- [Suspicious PowerShell Enumeration of Running Processes](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-powershell-enumeration-of-running-processes.md)
- [Suspicious PowerSploit's recon module (PowerView) net function was executed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-net-function-was-executed.md)
- [Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-used-to-search-for-exposed-hosts.md)
- [Suspicious print processor registered](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-print-processor-registered.md)
- [Suspicious Print System Remote Protocol usage by a process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-print-system-remote-protocol-usage-by-a-process.md)
- [Suspicious process accessed a site masquerading as Google](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-accessed-a-site-masquerading-as-google.md)
- [Suspicious process accessed certificate files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-accessed-certificate-files.md)
- [Suspicious process executed with a high integrity level](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-executed-with-a-high-integrity-level.md)
- [Suspicious process execution from tmp folder](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-execution-from-tmp-folder.md)
- [Suspicious process execution in a privileged container](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-execution-in-a-privileged-container.md)
- [Suspicious process loads a known PowerShell module](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-loads-a-known-powershell-module.md)
- [Suspicious process modified RC script file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-modified-rc-script-file.md)
- [Suspicious Process Spawned by Adobe Reader](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-spawned-by-adobe-reader.md)
- [Suspicious Process Spawned by wininit.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-process-spawned-by-wininit-exe.md)
- [Suspicious proxy environment variable setting](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-proxy-environment-variable-setting.md)
- [Suspicious reconnaissance using LDAP](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-reconnaissance-using-ldap.md)
- [Suspicious runonce.exe parent process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-runonce-exe-parent-process.md)
- [Suspicious RunOnce Parent Process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-runonce-parent-process.md)
- [Suspicious SaaS API call from a Tor exit node](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-saas-api-call-from-a-tor-exit-node.md)
- [Suspicious sAMAccountName change](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-samaccountname-change.md)
- [Suspicious SearchProtocolHost.exe parent process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-searchprotocolhost-exe-parent-process.md)
- [Suspicious secrets dump activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-secrets-dump-activity.md)
- [Suspicious sender exhibiting automated sending patterns](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-sender-exhibiting-automated-sending-patterns.md)
- [Suspicious sending domain with sender address randomization](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-sending-domain-with-sender-address-randomization.md)
- [Suspicious setspn.exe execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-setspn-exe-execution.md)
- [Suspicious SMB connection from domain controller](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-smb-connection-from-domain-controller.md)
- [Suspicious SPF Result](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-spf-result.md)
- [Suspicious SSH Downgrade](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-ssh-downgrade.md)
- [Suspicious sshpass command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-sshpass-command-execution.md)
- [Suspicious SSO access from ASN](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-sso-access-from-asn.md)
- [Suspicious SSO authentication](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-sso-authentication.md)
- [Suspicious successful RDP connection to localhost](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-successful-rdp-connection-to-localhost.md)
- [Suspicious systemd timer activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-systemd-timer-activity.md)
- [Suspicious theme and sentiment in email](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-theme-and-sentiment-in-email.md)
- [Suspicious time provider registered](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-time-provider-registered.md)
- [Suspicious Udev driver rule execution manipulation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-udev-driver-rule-execution-manipulation.md)
- [Suspicious Unicode character detected in email](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-unicode-character-detected-in-email.md)
- [Suspicious usage of EC2 token](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-usage-of-ec2-token.md)
- [Suspicious usage of File Server Remote VSS Protocol (FSRVP)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-usage-of-file-server-remote-vss-protocol-fsrvp.md)
- [Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/suspicious-usage-of-microsoft-s-active-directory-powershell-module-remote-discovery-cmdlet.md)
- [Svchost.exe loads a rare unsigned module](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/svchost-exe-loads-a-rare-unsigned-module.md)
- [System information discovery via psinfo.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/system-information-discovery-via-psinfo-exe.md)
- [System profiling WMI query execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/system-profiling-wmi-query-execution.md)
- [System shutdown or reboot](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/system-shutdown-or-reboot.md)
- [Tampering with Internet Explorer Protected Mode configuration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/tampering-with-internet-explorer-protected-mode-configuration.md)
- [Tampering with the Windows User Account Controls (UAC) configuration](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/tampering-with-the-windows-user-account-controls-uac-configuration.md)
- [TGT request with a spoofed sAMAccountName - Event log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-event-log.md)
- [TGT request with a spoofed sAMAccountName - Network](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-network.md)
- [The CA policy EditFlags was queried](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/the-ca-policy-editflags-was-queried.md)
- [The Linux system firewall was disabled](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/the-linux-system-firewall-was-disabled.md)
- [Training simulation email detected](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/training-simulation-email-detected.md)
- [Uncommon access to cloud platforms' sensitive files by a scripting engine](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-access-to-cloud-platforms-sensitive-files-by-a-scripting-engine.md)
- [Uncommon access to /etc/passwd](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-access-to-etc-passwd.md)
- [Uncommon access to Microsoft Teams cookies files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-access-to-microsoft-teams-cookies-files.md)
- [Uncommon access to Microsoft Teams credential files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-access-to-microsoft-teams-credential-files.md)
- [Uncommon AppleScript containing a potential obfuscation technique was executed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-containing-a-potential-obfuscation-technique-was-executed.md)
- [Uncommon AppleScript containing a potential persistence command was executed via the command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-containing-a-potential-persistence-command-was-executed-via-the-command-line.md)
- [Uncommon AppleScript designed to access credential files was executed via the command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-access-credential-files-was-executed-via-the-command-line.md)
- [Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-access-cryptocurrency-wallet-data-was-executed-via-the-command-line.md)
- [Uncommon AppleScript designed to access sensitive application data was executed via the command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-access-sensitive-application-data-was-executed-via-the-command-line.md)
- [Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-capture-screen-or-clipboard-data-was-executed-via-the-command-line.md)
- [Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-potentially-utilizes-credential-grabbing-techniques-to-steal-user-passwords.md)
- [Uncommon AppleScript was executed via the command line to contact an external server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-applescript-was-executed-via-the-command-line-to-contact-an-external-server.md)
- [Uncommon ARP cache listing via arp.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-arp-cache-listing-via-arp-exe.md)
- [Uncommon AT task-job creation by user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-at-task-job-creation-by-user.md)
- [Uncommon attempt at discovering a sensitive file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file.md)
- [Uncommon attempt at grabbing credentials from a sensitive file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file.md)
- [Uncommon attempt to clear shell history](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-attempt-to-clear-shell-history.md)
- [Uncommon Azure Cosmos DB master key read by identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-azure-cosmos-db-master-key-read-by-identity.md)
- [Uncommon browser extension loaded](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-browser-extension-loaded.md)
- [Uncommon cloud CLI tool usage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-cloud-cli-tool-usage.md)
- [Uncommon communication to an instant messaging server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-communication-to-an-instant-messaging-server.md)
- [Uncommon creation or access operation of sensitive shadow copy](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-creation-or-access-operation-of-sensitive-shadow-copy.md)
- [Uncommon DLL-sideloading from a logical CD-ROM (ISO) device](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-dll-sideloading-from-a-logical-cd-rom-iso-device.md)
- [Uncommon DotNet module load relationship](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-dotnet-module-load-relationship.md)
- [Uncommon driver loaded](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-driver-loaded.md)
- [Uncommon execution of ODBCConf](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-execution-of-odbcconf.md)
- [Uncommon file access over WebDAV](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-file-access-over-webdav.md)
- [Uncommon GetClipboardData API function invocation of a possible information stealer](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-getclipboarddata-api-function-invocation-of-a-possible-information-stealer.md)
- [Uncommon increase in Azure Microsoft Graph API request sizes](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-increase-in-azure-microsoft-graph-api-request-sizes.md)
- [Uncommon IP Configuration Listing via ipconfig.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-ip-configuration-listing-via-ipconfig-exe.md)
- [Uncommon jsp file write by a Java process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-jsp-file-write-by-a-java-process.md)
- [Uncommon kernel module load](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-kernel-module-load.md)
- [Uncommon Launch Agent persistency was registered or modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-launch-agent-persistency-was-registered-or-modified.md)
- [Uncommon Launch Daemon persistency was registered or modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-launch-daemon-persistency-was-registered-or-modified.md)
- [Uncommon Linux process communication to a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-linux-process-communication-to-a-rare-external-host.md)
- [Uncommon Linux remote shell command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-linux-remote-shell-command-execution.md)
- [Uncommon Linux shell command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-linux-shell-command-execution.md)
- [Uncommon local scheduled task creation via schtasks.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-local-scheduled-task-creation-via-schtasks-exe.md)
- [Uncommon login item persistency was registered or modified](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-login-item-persistency-was-registered-or-modified.md)
- [Uncommon macOS process communication to a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-macos-process-communication-to-a-rare-external-host.md)
- [Uncommon macOS shell command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-macos-shell-command-execution.md)
- [Uncommon Managed Object Format (MOF) compiler usage](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-managed-object-format-mof-compiler-usage.md)
- [Uncommon msiexec execution of an arbitrary file from a remote location](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-msiexec-execution-of-an-arbitrary-file-from-a-remote-location.md)
- [Uncommon net group command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-net-group-command-execution.md)
- [Uncommon net localgroup command execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-net-localgroup-command-execution.md)
- [Uncommon network tunnel creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-network-tunnel-creation.md)
- [Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-ntwritevirtualmemoryremote-api-invocation-with-a-pe-header-buffer.md)
- [Uncommon PowerShell commands used to create or alter scheduled task parameters](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-powershell-commands-used-to-create-or-alter-scheduled-task-parameters.md)
- [Uncommon RDP connection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-rdp-connection.md)
- [Uncommon recurring rare external host access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-recurring-rare-external-host-access.md)
- [Uncommon remote monitoring and management tool](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-remote-monitoring-and-management-tool.md)
- [Uncommon remote scheduled task creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-remote-scheduled-task-creation.md)
- [Uncommon remote service start via sc.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-remote-service-start-via-sc-exe.md)
- [Uncommon reverse SSH tunnel to external domain/ip](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-reverse-ssh-tunnel-to-external-domain-ip.md)
- [Uncommon routing table listing via route.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-routing-table-listing-via-route-exe.md)
- [Uncommon Security Support Provider (SSP) registered via a registry key](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-security-support-provider-ssp-registered-via-a-registry-key.md)
- [Uncommon sensitive filesystem registry hive access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-sensitive-filesystem-registry-hive-access.md)
- [Uncommon sensitive registry hive dump](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-sensitive-registry-hive-dump.md)
- [Uncommon Service Create/Config](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-service-create-config.md)
- [Uncommon service stop operation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-service-stop-operation.md)
- [Uncommon SetWindowsHookEx API invocation of a possible keylogger](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-setwindowshookex-api-invocation-of-a-possible-keylogger.md)
- [Uncommon signed process execution by scheduled task](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-signed-process-execution-by-scheduled-task.md)
- [Uncommon SQL like command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-sql-like-command-line.md)
- [Uncommon SSH session was established](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-ssh-session-was-established.md)
- [Uncommon URL domain(s) in your organization detected in email](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email.md)
- [Uncommon user management via net.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-user-management-via-net-exe.md)
- [Uncommon VNC server communication](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-vnc-server-communication.md)
- [Uncommon WPAD queries](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/uncommon-wpad-queries.md)
- [Unicode RTL Override Character](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unicode-rtl-override-character.md)
- [Unique client computer model was detected via MS-Update protocol](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unique-client-computer-model-was-detected-via-ms-update-protocol.md)
- [Unknown DLL was added to the AD FS Global Assembly Cache path](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unknown-dll-was-added-to-the-ad-fs-global-assembly-cache-path.md)
- [Unpopular rsync process execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unpopular-rsync-process-execution.md)
- [Unprivileged process opened a registry hive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unprivileged-process-opened-a-registry-hive.md)
- [Unrecognized internal address (AAD mismatch)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unrecognized-internal-address-aad-mismatch.md)
- [Unsigned and unpopular process performed a DLL injection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unsigned-and-unpopular-process-performed-a-dll-injection.md)
- [Unsigned and unpopular process performed an injection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unsigned-and-unpopular-process-performed-an-injection.md)
- [Unsigned DLL Hijack into a Microsoft process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unsigned-dll-hijack-into-a-microsoft-process.md)
- [Unsigned DLL Side-Loading](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unsigned-dll-side-loading.md)
- [Unsigned process creates a scheduled task via file access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unsigned-process-creates-a-scheduled-task-via-file-access.md)
- [Unsigned process injecting into a Windows system binary with no command line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unsigned-process-injecting-into-a-windows-system-binary-with-no-command-line.md)
- [Untrusted process contacted LLM API](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/untrusted-process-contacted-llm-api.md)
- [Unusual access to Microsoft 365 storage services](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-access-to-microsoft-365-storage-services.md)
- [Unusual access to the AD Sync credential files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-access-to-the-ad-sync-credential-files.md)
- [Unusual access to the Windows Internal Database on an ADFS server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-access-to-the-windows-internal-database-on-an-adfs-server.md)
- [Unusual ADConnect database file access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-adconnect-database-file-access.md)
- [Unusual ADFS Remote Synchronization network connections from non-ADFS server](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-adfs-remote-synchronization-network-connections-from-non-adfs-server.md)
- [Unusual AI dataset modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-ai-dataset-modification.md)
- [Unusual AI Knowledge Base Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-ai-knowledge-base-modification.md)
- [Unusual AI model invocation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-ai-model-invocation.md)
- [Unusual AI RAG Knowledge Base Modification](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-ai-rag-knowledge-base-modification.md)
- [Unusual attachment volume in outbound emails](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-attachment-volume-in-outbound-emails.md)
- [Unusual AWS Bedrock model access request](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-aws-bedrock-model-access-request.md)
- [Unusual AWS CLI/SDK activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-aws-cli-sdk-activity.md)
- [Unusual AWS credentials creation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-aws-credentials-creation.md)
- [Unusual AWS S3 objects deletion](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-aws-s3-objects-deletion.md)
- [Unusual AWS SageMaker notebook access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-aws-sagemaker-notebook-access.md)
- [Unusual AWS systems manager activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-aws-systems-manager-activity.md)
- [Unusual AWS user added to group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-aws-user-added-to-group.md)
- [Unusual Azure AD sync module load](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-azure-ad-sync-module-load.md)
- [Unusual certificate management activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-certificate-management-activity.md)
- [Unusual CertLog Remote File Write](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-certlog-remote-file-write.md)
- [Unusual CIM repository file access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-cim-repository-file-access.md)
- [Unusual cloud identity impersonation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-cloud-identity-impersonation.md)
- [Unusual cloud Instance Metadata Service (IMDS) access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access.md)
- [Unusual compressed file password protection](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-compressed-file-password-protection.md)
- [Unusual Conditional Access operation for an identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-conditional-access-operation-for-an-identity.md)
- [Unusual cross projects activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-cross-projects-activity.md)
- [Unusual DB process spawning a shell](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-db-process-spawning-a-shell.md)
- [Unusual display name in From header](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-display-name-in-from-header.md)
- [Unusual Encrypting File System Remote call (EFSRPC) to domain controller](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-encrypting-file-system-remote-call-efsrpc-to-domain-controller.md)
- [Unusual exec into a Kubernetes Pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-exec-into-a-kubernetes-pod.md)
- [Unusual file-sharing links for mailbox owner](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-file-sharing-links-for-mailbox-owner.md)
- [Unusual hostname for the sending mail server in the email headers](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers.md)
- [Unusual IAM enumeration activity by a non-user Identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-iam-enumeration-activity-by-a-non-user-identity.md)
- [Unusual Identity and Access Management (IAM) activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-identity-and-access-management-iam-activity.md)
- [Unusual internal access to network device management interface](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-internal-access-to-network-device-management-interface.md)
- [Unusual key management activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-key-management-activity.md)
- [Unusual Kubernetes dashboard communication from a pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-kubernetes-dashboard-communication-from-a-pod.md)
- [Unusual Kubernetes secret access](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-kubernetes-secret-access.md)
- [Unusual Kubernetes service account file read](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-kubernetes-service-account-file-read.md)
- [Unusual Lolbins Process Spawned by InstallUtil.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-lolbins-process-spawned-by-installutil-exe.md)
- [Unusual multi-region AWS Resource Explorer searches](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-multi-region-aws-resource-explorer-searches.md)
- [Unusual Netsh PortProxy rule](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-netsh-portproxy-rule.md)
- [Unusual process access to ld.so.preload file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-access-to-ld-so-preload-file.md)
- [Unusual process accessed a crypto wallet's files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-a-crypto-wallet-s-files.md)
- [Unusual process accessed a macOS notes DB file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-a-macos-notes-db-file.md)
- [Unusual process accessed a messaging app's files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-a-messaging-app-s-files.md)
- [Unusual process accessed a web browser history file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-a-web-browser-history-file.md)
- [Unusual process accessed FTP Client credentials](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-ftp-client-credentials.md)
- [Unusual process accessed the PowerShell history file](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-the-powershell-history-file.md)
- [Unusual process accessed web browser cookies](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-web-browser-cookies.md)
- [Unusual process accessed web browser credentials](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-accessed-web-browser-credentials.md)
- [Unusual process executed by AWS Systems Manager](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-executed-by-aws-systems-manager.md)
- [Unusual Process Spawned by Nginx in Ingress-Nginx pod](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-process-spawned-by-nginx-in-ingress-nginx-pod.md)
- [Unusual resource access by Azure application](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-resource-access-by-azure-application.md)
- [Unusual resource modification by newly seen IAM user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-resource-modification-by-newly-seen-iam-user.md)
- [Unusual secret management activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-secret-management-activity.md)
- [Unusual sender IP subnet](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-sender-ip-subnet.md)
- [Unusual SSH activity that resembles SSH proxy](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-ssh-activity-that-resembles-ssh-proxy.md)
- [Unusual SSH Activity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-ssh-activity.md)
- [Unusual URL(s) sent by a brand were observed in the email](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-url-s-sent-by-a-brand-were-observed-in-the-email.md)
- [Unusual use of a 'SysInternals' tool](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-use-of-a-sysinternals-tool.md)
- [Unusual user account enablement](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-user-account-enablement.md)
- [Unusual user account unlock](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-user-account-unlock.md)
- [Unusual user-agent for a cloud identity](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-user-agent-for-a-cloud-identity.md)
- [Unusual weak authentication by user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unusual-weak-authentication-by-user.md)
- [Unverified domain added to Azure AD](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/unverified-domain-added-to-azure-ad.md)
- [Upload pattern that resembles Peer to Peer traffic](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/upload-pattern-that-resembles-peer-to-peer-traffic.md)
- [Usage of homograph characters detected in an email attachment(s) name](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name.md)
- [Usage of homograph characters detected in an email's from header](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header.md)
- [Usage of homograph characters detected in an email](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/usage-of-homograph-characters-detected-in-an-email.md)
- [User accessed multiple O365 AIP sensitive files](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-accessed-multiple-o365-aip-sensitive-files.md)
- [User accessed SaaS resource via anonymous link](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-accessed-saas-resource-via-anonymous-link.md)
- [User account delegation change](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-account-delegation-change.md)
- [User added a new device to Okta Verify instance](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-added-a-new-device-to-okta-verify-instance.md)
- [User added SID History to an account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-added-sid-history-to-an-account.md)
- [User added to a group and removed](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-added-to-a-group-and-removed.md)
- [User added to the SMS Admins local group](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-added-to-the-sms-admins-local-group.md)
- [User and Group Enumeration via SAMR](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-and-group-enumeration-via-samr.md)
- [User attempted to connect from a suspicious country](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-attempted-to-connect-from-a-suspicious-country.md)
- [User collected remote shared files in an archive](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-collected-remote-shared-files-in-an-archive.md)
- [User discovery via WMI query execution](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-discovery-via-wmi-query-execution.md)
- [User exported multiple messages in Microsoft Teams via Graph API](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-exported-multiple-messages-in-microsoft-teams-via-graph-api.md)
- [User installed an application in Microsoft Teams via Graph API](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-installed-an-application-in-microsoft-teams-via-graph-api.md)
- [User moved Exchange sent messages to deleted items](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-moved-exchange-sent-messages-to-deleted-items.md)
- [User sent messages in Microsoft Teams to multiple conversations via Graph API](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-sent-messages-in-microsoft-teams-to-multiple-conversations-via-graph-api.md)
- [User set insecure CA registry setting for global SANs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-set-insecure-ca-registry-setting-for-global-sans.md)
- [User signed in to an application via Power Automate for the first time](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-signed-in-to-an-application-via-power-automate-for-the-first-time.md)
- [VM Detection attempt on Linux](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vm-detection-attempt-on-linux.md)
- [VM Detection attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vm-detection-attempt.md)
- [VPN access with an abnormal operating system](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vpn-access-with-an-abnormal-operating-system.md)
- [VPN login attempt by a honey user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vpn-login-attempt-by-a-honey-user.md)
- [VPN login Brute-Force attempt](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vpn-login-brute-force-attempt.md)
- [VPN login by a dormant user](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vpn-login-by-a-dormant-user.md)
- [VPN login by a service account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vpn-login-by-a-service-account.md)
- [VPN Login Password Spray](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vpn-login-password-spray.md)
- [VPN login with a machine account](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vpn-login-with-a-machine-account.md)
- [Vulnerable certificate template loaded](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/vulnerable-certificate-template-loaded.md)
- [Wbadmin deleted files in quiet mode](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/wbadmin-deleted-files-in-quiet-mode.md)
- [Weakly-Encrypted Kerberos TGT Response](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/weakly-encrypted-kerberos-tgt-response.md)
- [Weakly-Encrypted Kerberos Ticket Requested](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/weakly-encrypted-kerberos-ticket-requested.md)
- [Web server CGO executed a process following a potential Webshell dropped](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/web-server-cgo-executed-a-process-following-a-potential-webshell-dropped.md)
- [Web server CGO executed an uncommon process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/web-server-cgo-executed-an-uncommon-process.md)
- [WebDAV drive mounted from net.exe over HTTPS](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/webdav-drive-mounted-from-net-exe-over-https.md)
- [Well-known brand in sender headers with header inconsistencies](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies.md)
- [Windows CGO, actor and action processes with anomalous characteristics](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/windows-cgo-actor-and-action-processes-with-anomalous-characteristics.md)
- [Windows CGO, actor process and action module with anomalous characteristics](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/windows-cgo-actor-process-and-action-module-with-anomalous-characteristics.md)
- [Windows Event Log was cleared using wevtutil.exe](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/windows-event-log-was-cleared-using-wevtutil-exe.md)
- [Windows event logs were cleared with PowerShell](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/windows-event-logs-were-cleared-with-powershell.md)
- [Windows Installer exploitation for local privilege escalation](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/windows-installer-exploitation-for-local-privilege-escalation.md)
- [Windows LOLBIN executable connected to a rare external host](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/windows-lolbin-executable-connected-to-a-rare-external-host.md)
- [WmiPrvSe.exe Rare Child Command Line](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/wmiprvse-exe-rare-child-command-line.md)
- [Wscript/Cscript loads .NET DLLs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/wscript-cscript-loads-net-dlls.md)
- [Wsmprovhost.exe Rare Child Process](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/wsmprovhost-exe-rare-child-process.md)
- [X-Forefront-Antispam-Report has flagged this email as a potential threat](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat.md)
- [Alerts by data source](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source.md)
- [AWS Audit Log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/aws-audit-log.md)
- [Azure Audit Log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/azure-audit-log.md)
- [Azure SignIn Log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/azure-signin-log.md)
- [AzureAD Audit Log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/azuread-audit-log.md)
- [AzureAD](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/azuread.md)
- [Box Audit Log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/box-audit-log.md)
- [DropBox](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/dropbox.md)
- [Duo](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/duo.md)
- [Gcp Audit Log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/gcp-audit-log.md)
- [Google Workspace Audit Logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/google-workspace-audit-logs.md)
- [Google Workspace Authentication](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/google-workspace-authentication.md)
- [Health Monitoring Data](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/health-monitoring-data.md)
- [Idira](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/idira.md)
- [Kubernetes Audit Logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/kubernetes-audit-logs.md)
- [Microsoft 365 Emails](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/microsoft-365-emails.md)
- [Microsoft Graph Logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/microsoft-graph-logs.md)
- [Office 365 Audit](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/office-365-audit.md)
- [Okta Audit Log](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/okta-audit-log.md)
- [Okta](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/okta.md)
- [OneLogin](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/onelogin.md)
- [Palo Alto Networks Firewall EAL Logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-firewall-eal-logs.md)
- [Palo Alto Networks Firewall threat Logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-firewall-threat-logs.md)
- [Palo Alto Networks Firewall traffic Logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-firewall-traffic-logs.md)
- [Palo Alto Networks Global Protect](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-global-protect.md)
- [Palo Alto Networks Platform Alerts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-platform-alerts.md)
- [Palo Alto Networks Url Logs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-url-logs.md)
- [PingOne](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/pingone.md)
- [Third-Party Alerts](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/third-party-alerts.md)
- [Third-Party Firewalls](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/third-party-firewalls.md)
- [Third-Party VPNs](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/third-party-vpns.md)
- [Windows Event Collector](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/windows-event-collector.md)
- [XDR Agent with eXtended Threat Hunting (XTH)](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/xdr-agent-with-extended-threat-hunting-xth.md)
- [XDR Agent](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/xdr-agent.md)

## AppSec Rules

- [AppSec Rules](https://cortex-docs.paloaltonetworks.com/appsec-rules/readme.md)
- [IaC Security](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security.md)
- [AI And Machine Learning](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning.md)
- [AWS SageMaker notebook instance not configured with data encryption at rest using KMS key misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-22.md)
- [AWS SageMaker endpoint data encryption at rest not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-98.md)
- [AWS SageMaker notebook instance configured with direct internet access feature misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-122.md)
- [AWS Sagemaker domain not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-187.md)
- [AWS Kendra index Server side encryption does not use Customer Managed Keys (CMKs) misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-262.md)
- [AWS SageMaker notebook instance with root access enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-307.md)
- [AWS Sagemaker data quality job not encrypting model artifacts with KMS misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-367.md)
- [AWS Sagemaker data quality job not using KMS to encrypt data on attached storage volume misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-368.md)
- [AWS Sagemaker data quality job not encrypting communications between instances used for monitoring j](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-369.md)
- [AWS SageMaker model does not use network isolation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-370.md)
- [AWS SageMaker notebook instance allows for IMDSv1 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-371.md)
- [AWS SageMaker Flow Definition does not use KMS for output configurations misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-372.md)
- [AWS Bedrock agent is not associated with Bedrock guardrails misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-383.md)
- [Azure Synapse Workspaces do not enable managed virtual networks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-58.md)
- [Azure Cognitive Services account configured with public network access misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-134.md)
- [Azure Machine Learning Compute Cluster Local Authentication is enabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-142.md)
- [Azure Machine Learning Workspace is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-144.md)
- [Azure Machine Learning Compute Cluster Minimum Nodes is not set to 0 misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-150.md)
- [Azure Data exfiltration protection for Azure Synapse workspace is disabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-157.md)
- [Azure Databricks workspace is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-158.md)
- [Azure Cognitive Services account configured with local authentication misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-236.md)
- [Azure Cognitive Services account is not configured with managed identity misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-238.md)
- [Azure Synapse workspace administrator login password exposed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-239.md)
- [Azure Synapse Workspace not encrypted with a Customer Managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-240.md)
- [Azure Synapse SQL pool not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-241.md)
- [Azure Synapse Spark Pool not using isolated compute misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-242.md)
- [Azure Machine learning workspace is not configured with private endpoint misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-243.md)
- [Azure Cognitive Services account hosted with OpenAI is not configured with data loss prevention misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-247.md)
- [GCP Vertex AI datasets do not use a Customer Manager Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-92.md)
- [GCP Vertex AI Metadata Store does not use a Customer Manager Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-96.md)
- [GCP Dataproc Clusters have public IPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-103.md)
- [GCP DataFusion does not have stack driver logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-104.md)
- [GCP DataFusion does not have stack driver monitoring enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-105.md)
- [GCP Vertex AI Workbench user-managed notebook has vTPM disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-126.md)
- [GCP Vertex AI Workbench user-managed notebook has Integrity monitoring disabled misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-127.md)
- [AWS SageMaker notebook instance IAM policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-aws-68.md)
- [Azure Synapse workspaces have IP firewall rules attached misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-19.md)
- [Azure Cognitive Services does not Customer Managed Keys (CMKs) for encryption misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-22.md)
- [Azure Synapse Workspace vulnerability assessment is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-46.md)
- [Azure Databricks Workspaces not using customer-managed key for root DBFS encryption misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-48.md)
- [Azure Machine learning workspace configured with overly permissive network access misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-49.md)
- [Azure Storage Account storing Machine Learning workspace high business impact data is publicly acces](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-50.md)
- [Azure Synapse SQL Pool does not have a security alert policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-51.md)
- [Azure Synapse SQL Pool vulnerability assessment disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-52.md)
- [Azure Synapse Workspace does not have extended audit logs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-53.md)
- [Log monitoring disabled for Azure Synapse SQL Pool misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-54.md)
- [Vertex AI endpoint is not using a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-24.md)
- [Vertex AI featurestore is not configured to use a Customer Managed Key (CMK) misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-25.md)
- [Vertex AI tensorboard does not use a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-26.md)
- [Vertex AI endpoint is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-33.md)
- [Vertex AI index endpoint is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-34.md)
- [Vertex AI runtime is not encrypted with a Customer Managed Key (CMK) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-35.md)
- [Vertex AI runtime is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-36.md)
- [Compute](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute.md)
- [Alibaba Cloud RDS instance is not set to perform auto upgrades for minor versions misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ali-30.md)
- [Disabled Ansible URI certificate validation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-1.md)
- [Certificate validation disabled with Ansible get\_url module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-2.md)
- [SSL certificate validation disabled with Ansible Yum misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-3.md)
- [SSL validation is disabled with yum misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-4.md)
- [Usage of packages with unauthenticated or missing signatures allowed misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-5.md)
- [Usage of the force parameter disabling signature validation allowed misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-6.md)
- [AWS Lambda functions with tracing not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-50.md)
- [API Gateway does not have X-Ray tracing enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-73.md)
- [AWS EC2 instance not configured with Instance Metadata Service v2 (IMDSv2) misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-79.md)
- [AWS EMR cluster is not configured with Kerberos Authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-114.md)
- [AWS Lambda function is not configured for function-level concurrent execution Limit misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-115.md)
- [AWS Lambda function is not configured for a DLQ misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-116.md)
- [AWS Lambda Function is not assigned to access within VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-117.md)
- [AWS API Gateway caching is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-120.md)
- [Autoscaling groups did not supply tags to launch configurations misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-153.md)
- [ECR image scan on push is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-163.md)
- [AWS MQBroker's minor version updates are disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-207.md)
- [AWS MQBroker version is not up to date misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-208.md)
- [AWS Batch Job is defined as a privileged container misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-210.md)
- [AWS API deployments do not enable Create before Destroy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-217.md)
- [AWS DMS replication instance automatic version upgrade disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-222.md)
- [AWS API Gateway method settings do not enable caching misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-225.md)
- [AWS DB instance does not get all minor upgrades automatically misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-226.md)
- [AWS ACM certificate does not enable Create before Destroy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-233.md)
- [Ensure AWS API gateway enables Create before Destroy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-237.md)
- [AWS HTTP and HTTPS target groups do not define health check misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-261.md)
- [AWS Lambda function is not configured to validate code-signing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-272.md)
- [API Gateway method setting is not set to encrypted caching misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-308.md)
- [RDS cluster is not configured to copy tags to snapshots misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-313.md)
- [EC2 Auto Scaling groups are not utilizing EC2 launch templates misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-315.md)
- [AWS CodeBuild project environment privileged mode is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-316.md)
- [Elasticsearch domains are not configured with a minimum of three dedicated master nodes misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-318.md)
- [Redshift clusters are not using the default database name. misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-320.md)
- [Redshift clusters are not using enhanced VPC routing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-321.md)
- [AWS ElastiCache Redis cluster automatic version upgrade disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-322.md)
- [ECS Fargate services are not ensured to run on the latest Fargate platform version misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-332.md)
- [AWS ECS task definition elevated privileges enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-334.md)
- [ECS task definitions have their own unique process namespace or share the host's process namespace m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-335.md)
- [AWS ECS task definition is not configured with read-only access to container root filesystems miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-336.md)
- [AWS Elastic Beanstalk environment managed platform updates are not enabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-340.md)
- [AWS Auto Scaling group launch configuration configured with Instance Metadata Service hop count grea](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-341.md)
- [Runtime of Lambda is deprecated misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-363.md)
- [Hard-coded secrets found in Parameter Store values misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-384.md)
- [Potential WhoAMI name confusion attack exposure misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-386.md)
- [AWS SQS queue access policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-387.md)
- [Secrets are exposed in Azure VM customData misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-45.md)
- [Azure Linux scale set does not use an SSH key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-49.md)
- [Virtual Machine extensions are installed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-50.md)
- [Azure App Service Web app doesn't use latest .Net framework version misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-80.md)
- [Azure App Service Web app does not use latest PHP version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-81.md)
- [Azure App Service Web app does not use latest Python version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-82.md)
- [Azure App Service Web app does not use latest Java version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-83.md)
- [Azure Linux and Windows Virtual Machines does not utilize Managed Disks misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-92.md)
- [Automatic OS image patching is disabled for Virtual Machine scale sets misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-95.md)
- [Azure Data Factory does not use Git repository for source control misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-103.md)
- [Azure Service Fabric cluster not configured with cluster protection level security misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-126.md)
- [Azure Container Registry (ACR) Isn't Configured to Use Signed/Trusted Images misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-164.md)
- [Azure Kubernetes Cluster (AKS) Nodes Don't Limit the Maximum Pods to Greater than 50 misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-168.md)
- [Azure Kubernetes Cluster (AKS) Nodes Do Not Use Scale Sets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-169.md)
- [AKS Doesn't Use the Paid SKU for its SLA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-170.md)
- [AKS Cluster Without Upgrade Channel misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-171.md)
- [Windows VM Without Automatic Updates misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-177.md)
- [VM Without Azure VM Agent Installed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-179.md)
- [App Configuration Not Using Standard SKU misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-188.md)
- [Azure App Service Plan is Not Suitable for Production misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-211.md)
- [Azure App Service Not Always On misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-214.md)
- [Operating system disks are not ephemeral disks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-226.md)
- [Non-Critical System Pods Run on System Nodes misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-232.md)
- [Healthcheck instructions have not been added to container images misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-2.md)
- [A user for the container has not been created misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-3.md)
- [Copy is not used instead of Add in Dockerfiles misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-4.md)
- [Update instructions are used alone in a Dockerfile misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-5.md)
- [LABEL maintainer is used instead of MAINTAINER (deprecated) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-6.md)
- [Base image uses a latest version tag misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-7.md)
- [Last USER is root misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-8.md)
- [Docker APT is used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-9.md)
- [Docker WORKDIR values are not absolute paths misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-10.md)
- [Docker From alias is not unique for multistage builds misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-11.md)
- [GCP Kubernetes Engine Clusters not using Container-Optimized OS for Node image misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-22.md)
- [GCP Kubernetes Engine Clusters have legacy compute engine metadata endpoints enabled misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-67.md)
- [GCP Kubernetes cluster shielded GKE node with Secure Boot disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-68.md)
- [GCP Kubernetes cluster Shielded GKE Nodes feature disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-71.md)
- [GCP SQL database does not use the latest Major version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-79.md)
- [GKE NodePool configuration managed at cluster level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-123.md)
- [Containers wishing to share host process ID namespace admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-1.md)
- [Privileged containers are admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-2.md)
- [Containers wishing to share host IPC namespace admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-3.md)
- [Root containers admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-6.md)
- [Containers with NET\_RAW capability admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-7.md)
- [CPU request is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-10.md)
- [CPU limits are not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-11.md)
- [Memory requests are not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-12.md)
- [Memory limits are not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-13.md)
- [Image tag is not set to Fixed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-14.md)
- [Image pull policy is not set to Always misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-15.md)
- [Container is privileged misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-16.md)
- [Containers share host process ID namespace misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-17.md)
- [Containers share host IPC namespace misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-18.md)
- [Containers run with AllowPrivilegeEscalation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-20.md)
- [Default namespace is used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-21.md)
- [Read-Only filesystem for containers is not used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-22.md)
- [Admission of root containers not minimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-23.md)
- [Containers with added capability are allowed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-24.md)
- [Admission of containers with added capability is not minimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-25.md)
- [Mounting Docker socket daemon in a container is not limited misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-27.md)
- [Admission of containers with NET\_RAW capability is not minimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-28.md)
- [securityContext is not applied to pods and containers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-29.md)
- [securityContext is not applied to pods and containers in container context misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-30.md)
- [seccomp is not set to Docker/Default or Runtime/Default misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-31.md)
- [seccomp profile is not set to Docker/Default or Runtime/Default misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-32.md)
- [Kubernetes dashboard is deployed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-33.md)
- [Tiller (Helm V2) is deployed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-34.md)
- [Admission of containers with capabilities assigned is not minimised misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-36.md)
- [Admission of containers with capabilities assigned is not limited misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-37.md)
- [CAP\_SYS\_ADMIN Linux capability is used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-39.md)
- [Containers do not run with a high UID misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-40.md)
- [Images are not selected using a digest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-43.md)
- [Tiller (Helm v2) service is not deleted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-44.md)
- [The admission control plugin EventRateLimit is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-78.md)
- [The admission control plugin AlwaysAdmit is set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-79.md)
- [The admission control plugin AlwaysPullImages is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-80.md)
- [The admission control plugin NamespaceLifecycle is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-83.md)
- [The --terminated-pod-gc-threshold argument for controller managers is not set appropriately misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-106.md)
- [The --streaming-connection-idle-timeout argument is set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-143.md)
- [The --protect-kernel-defaults argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-144.md)
- [The --hostname-override argument is set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-146.md)
- [OCI Compute Instance boot volume has in-transit data encryption is disabled misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-oci-4.md)
- [OCI Compute Instance has Legacy MetaData service endpoint enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-oci-5.md)
- [Operation objects do not have the 'produces' field defined for GET operations misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-16.md)
- [Operation objects for PUT, POST, and PATCH operations do not have a 'consumes' field defined misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-17.md)
- [Array does not have a maximum number of items misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-21.md)
- [DNF usage of packages with untrusted or missing GPG signatures allowed misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-ansible-4.md)
- [SSL validation disabled within Ansible DNF module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-ansible-5.md)
- [Certificate validation disabled within Ansible DNF module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-ansible-6.md)
- [AWS Elasticsearch domain has Dedicated master set to disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-aws-59.md)
- [Azure Virtual Machines does not utilise Managed Disks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-azure-9.md)
- [Microsoft Antimalware is not configured to automatically update Virtual Machines misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-azure-10.md)
- [Dockerfile contains the use of 'sudo' misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-1.md)
- [Dockerfile certificate validation is disabled with curl misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-2.md)
- [Dockerfile certificate validation is disabled with wget misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-3.md)
- [Dockerfile certificate validation is disabled with the pip '--trusted-host' option misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-4.md)
- [Dockerfile certificate validation is disabled with the PYTHONHTTPSVERIFY environment variable miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-5.md)
- [Dockerfile Node.js certificate validation is disabled with the NODE\_TLS\_REJECT\_UNAUTHORIZED environm](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-6.md)
- [Dockerfile APK package manager is configured to allow untrusted repositories misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-7.md)
- [Dockerfile APT package manager is configured to allow unauthenticated packages misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-8.md)
- [Dockerfile YUM package manager is configured to skip GPG signature checks misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-9.md)
- [Dockerfile RPM package manager is configured to skip package signature checks misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-10.md)
- [Dockerfile APT package manager is configured to force package installations without prompts or verif](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-11.md)
- [Dockerfile configuration disables strict SSL for NPM misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-12.md)
- [Dockerfile sets NPM configuration to disable strict SSL misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-13.md)
- [Dockerfile configures GIT to disable SSL verification misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-14.md)
- [Dockerfile sets YUM configuration to disable SSL verification misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-15.md)
- [Dockerfile uses a trusted host with pip misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-16.md)
- [GCP Kubernetes Engine Clusters have Alpha cluster feature enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-gcp-19.md)
- [IAM](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam.md)
- [Alibaba Cloud RAM password policy does not have a minimum of 14 characters misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-13.md)
- [Alibaba Cloud RAM password policy does not have a number misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-14.md)
- [Alibaba Cloud RAM password policy does not have a symbol misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-15.md)
- [Alibaba Cloud RAM password policy does not expire in 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-16.md)
- [Alibaba Cloud RAM password policy does not have a lowercase character misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-17.md)
- [Alibaba Cloud RAM password policy does not prevent password reuse misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-18.md)
- [Alibaba Cloud RAM password policy does not have an uppercase character misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-19.md)
- [Alibaba Cloud RAM password policy maximal login attempts is more than 4 misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-23.md)
- [Alibaba Cloud RAM does not enforce MFA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-24.md)
- [Alibaba Cloud KMS Key Rotation is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-27.md)
- [Alibaba Cloud KMS Key is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-28.md)
- [AWS IAM policies that allow full administrative privileges are created misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-1.md)
- [AWS Customer Master Key (CMK) rotation is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-7.md)
- [AWS IAM password policy does not expire in 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-9.md)
- [AWS IAM password policy does not have a minimum of 14 characters misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-10.md)
- [AWS IAM password policy does not have a lowercase character misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-11.md)
- [AWS IAM password policy does not have a number misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-12.md)
- [AWS IAM password policy does allow password reuse misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-13.md)
- [AWS IAM password policy does not have a symbol misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-14.md)
- [AWS IAM password policy does not have an uppercase character misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-15.md)
- [AWS Private ECR repository policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-32.md)
- [AWS KMS Key policy overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-33.md)
- [AWS IAM policy attached to users misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-40.md)
- [AWS IAM policy documents do not allow \* (asterisk) as a statement's action misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-49.md)
- [AWS IAM role allows all services or principals to be assumed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-60.md)
- [AWS IAM policy allows all principals used by any AWS service from target account to assume role misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-61.md)
- [AWS IAM policies that allow full "-" administrative privileges are created misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-62.md)
- [AWS IAM policy documents allow \* (asterisk) as a statement's action misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-63.md)
- [SQS policy allows all actions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-72.md)
- [Credentials exposure actions return credentials in an API response misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-107.md)
- [Data exfiltration allowed without resource constraints misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-108.md)
- [Resource exposure allows modification of policies and exposes resources misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-109.md)
- [IAM policies allow privilege escalation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-110.md)
- [Write access allowed without constraint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-111.md)
- [Respective logs of Amazon RDS are disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-129.md)
- [RDS database does not have IAM authentication enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-161.md)
- [AWS RDS cluster not configured with IAM authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-162.md)
- [Glacier Vault access policy is public and not restricted to specific services or principals misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-167.md)
- [SQS queue policy is public and access is not restricted to specific services or principals misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-168.md)
- [SNS topic policy is public and access is not restricted to specific services or principals misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-169.md)
- [AWS AMI launch permissions are not limited misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-205.md)
- [AWS Key Management Service (KMS) key is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-227.md)
- [AWS Execution Role ARN and Task Role ARN are different in ECS Task definitions misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-249.md)
- [AWS Codecommit branch changes has less than 2 approvals misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-257.md)
- [AWS Lambda function URL AuthType set to NONE misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-258.md)
- [Access is not controlled through Single Sign-On (SSO) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-273.md)
- [AWS AdministratorAccess policy is used by IAM roles, users, or groups misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-274.md)
- [IAM policy uses the AWS AdministratorAccess policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-275.md)
- [IAM Policy Document Allows All or Any AWS Principal Permissions to Resources misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-283.md)
- [AWS IAM Policy permission may cause privilege escalation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-286.md)
- [IAM policies allow exposure of credentials misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-287.md)
- [IAM policies allow data exfiltration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-288.md)
- [IAM policies allow permissions management or resource exposure without constraints misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-289.md)
- [IAM policies allow write access without constraints misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-290.md)
- [AWS Lambda Function resource-based policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-301.md)
- [Authorization type for API GatewayV2 routes is not specified misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-309.md)
- [AWS Access key enabled on root account misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-348.md)
- [IAM policy document allows all resources with restricted actions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-355.md)
- [Data source IAM policy document allows all resources with restricted actions misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-356.md)
- [AWS GitHub Actions OIDC authorization policies allow for unsafe claims or claim order misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-358.md)
- [AWS Neptune Cluster not configured with IAM authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-359.md)
- [Permissions delegated to AWS services for AWS Lambda functions are not limited by SourceArn or Sourc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-364.md)
- [AWS Cognito identity pool allows unauthenticated guest access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-366.md)
- [AWS Security Group allows unrestricted egress traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-382.md)
- [AWS GitHub Actions OIDC authorization policies allow for unsafe claims or claim order on IAM role mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-393.md)
- [Azure AKS enable role-based access control (RBAC) not enforced misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-5.md)
- [Azure AKS cluster configured with overly permissive API server access misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-6.md)
- [Azure App Service Web app authentication is off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-13.md)
- [App Service is not registered with an Azure Active Directory account misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-16.md)
- [Azure subscriptions with custom roles does not have minimum permissions misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-39.md)
- [Azure Function App authentication is off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-56.md)
- [Azure App Service Web app doesn't have a Managed Service Identity misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-71.md)
- [AKS does not use Azure policies add-on misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-116.md)
- [Active Directory is not used for authentication for Service Fabric misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-125.md)
- [Azure ACR admin account is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-137.md)
- [Azure ACR enables anonymous image pulling misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-138.md)
- [Azure CosmosDB does not have Local Authentication disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-140.md)
- [Azure Kubernetes Service (AKS) local admin account is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-141.md)
- [Azure SQL on Virtual Machine (Linux) with basic authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-149.md)
- [Web PubSub Without Managed Identities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-176.md)
- [Linux VM Without SSH Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-178.md)
- [Data Explorer Not Using Managed Identities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-181.md)
- [App Configuration Using Local Authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-184.md)
- [Azure Event Grid Topic Managed Identity Provider misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-191.md)
- [Azure Event Grid Topic Local Authentication Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-192.md)
- [Azure Event Grid Domain Managed Identity Provider is Disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-194.md)
- [Azure Event Grid Domain Local Authentication Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-195.md)
- [Azure Service Bus Without Managed Identity Provider misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-202.md)
- [Azure Service Bus with Local Authentication Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-203.md)
- [Azure Cognitive Search Without Managed Identities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-207.md)
- [Local users used for Azure Storage misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-244.md)
- [Azure GitHub Actions OIDC trust policy is insecurely configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-249.md)
- [GCP Kubernetes Engine Clusters have Legacy Authorization enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-7.md)
- [GCP Kubernetes engine clusters have client certificate disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-13.md)
- [GCP Kubernetes Engine Clusters have pod security policy disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-24.md)
- [GCP VM instance configured with default service account misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-30.md)
- [GCP VM instance using a default service account with Cloud Platform access scope misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-31.md)
- [GCP IAM user are assigned Service Account User or Service Account Token creator roles at project lev](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-41.md)
- [GCP IAM Service account does have admin privileges misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-42.md)
- [Roles impersonate or manage Service Accounts used at folder level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-44.md)
- [Roles impersonate or manage Service Accounts used at organizational level misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-45.md)
- [Default Service Account is used at project level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-46.md)
- [Default Service Account is used at organization level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-47.md)
- [Default Service Account is used at folder level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-48.md)
- [GCP IAM primitive roles are in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-49.md)
- [Kubernetes RBAC users are not managed with Google Groups for GKE misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-65.md)
- [GCP Kubernetes Engine Clusters have binary authorization disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-66.md)
- [GCP Memorystore for Redis has AUTH disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-95.md)
- [KMS policy allows public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-112.md)
- [IAM policy defines public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-113.md)
- [Basic roles utilized at the organization level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-115.md)
- [Basic roles used at the folder level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-116.md)
- [Project level utilization of basic roles misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-117.md)
- [IAM workload identity pool provider is not restricted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-118.md)
- [GCP GitHub Actions OIDC trust policy is insecurely configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-125.md)
- [GitHub pull request configurations defined in Terraform have less than 2 approvals misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-git-5.md)
- [GitHub repository defined in Terraform does not have GPG signatures for all commits misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-git-6.md)
- [Gitlab project defined in Terraform requires fewer than 2 approvals misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-glb-1.md)
- [Gitlab branch protection rules defined in Terraform allow force push misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-glb-2.md)
- [Gitlab project defined in Terraform does not require signed commits misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-glb-4.md)
- [Containers run with AllowPrivilegeEscalation based on Pod Security Policy setting misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-5.md)
- [Secrets used as environment variables misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-35.md)
- [Service account tokens are not mounted where necessary misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-38.md)
- [Default service accounts are actively used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-41.md)
- [Default Kubernetes service accounts are actively used by bounding to a role or cluster role misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-42.md)
- [Wildcard use is not minimized in Roles and ClusterRoles misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-49.md)
- [The --anonymous-auth argument is not set to False for API server misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-68.md)
- [The --basic-auth-file argument is Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-69.md)
- [The --token-auth-file argument is Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-70.md)
- [The --kubelet-client-certificate and --kubelet-client-key arguments are not set appropriately miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-72.md)
- [The --kubelet-certificate-authority argument is not set appropriately misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-73.md)
- [The --authorization-mode argument is set to AlwaysAllow for Kubelet misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-74.md)
- [The --authorization-mode argument does not include node misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-75.md)
- [The --authorization-mode argument does not include RBAC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-77.md)
- [The admission control plugin SecurityContextDeny is set if PodSecurityPolicy is used misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-81.md)
- [The admission control plugin ServiceAccount is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-82.md)
- [The admission control plugin PodSecurityPolicy is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-84.md)
- [The admission control plugin NodeRestriction is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-85.md)
- [The --service-account-lookup argument is not set to true misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-96.md)
- [The --service-account-key-file argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-97.md)
- [The --etcd-cafile argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-102.md)
- [The --use-service-account-credentials argument for controller managers is not set to True misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-108.md)
- [The --service-account-private-key-file argument for controller managers is not set appropriately mis](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-110.md)
- [The --root-ca-file argument for controller managers is not set appropriately misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-111.md)
- [The RotateKubeletServerCertificate argument for controller managers is not set to True misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-112.md)
- [The --client-cert-auth argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-117.md)
- [The --peer-client-cert-auth argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-121.md)
- [The --anonymous-auth argument is not set to False for Kubelet misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-138.md)
- [The --authorization-mode argument is set to AlwaysAllow for API server misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-139.md)
- [The --client-ca-file argument for API Servers is not set appropriately misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-140.md)
- [The --rotate-certificates argument is set to false misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-149.md)
- [Kubernetes ClusterRoles that grant control over validating or mutating admission webhook configurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-155.md)
- [Kubernetes ClusterRoles that grant permissions to approve CertificateSigningRequests are not minimiz](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-156.md)
- [Kubernetes Roles and ClusterRoles that grant permissions to bind RoleBindings or ClusterRoleBindings](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-157.md)
- [Kubernetes Roles and ClusterRoles that grant permissions to escalate Roles or ClusterRole are not mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-158.md)
- [OCI private keys are hard coded in the provider misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-1.md)
- [OCI IAM password policy for local (non-federated) users does not have a lowercase character misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-11.md)
- [OCI IAM password policy for local (non-federated) users does not have a number misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-12.md)
- [OCI IAM password policy for local (non-federated) users does not have a symbol misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-13.md)
- [OCI IAM password policy for local (non-federated) users does not have an uppercase character misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-14.md)
- [OCI IAM password policy for local (non-federated) users does not have minimum 14 characters misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-18.md)
- [OpenAPI Security object needs to have defined rules in its array and rules should be defined in the](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-4.md)
- [OpenAPI Security object for operations, if defined, must define a security scheme, otherwise it shou](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-5.md)
- [OpenAPI Security requirement not defined in the security definitions misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-6.md)
- [API spec includes a 'password' flow in OAuth2 authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-8.md)
- [Security scopes of operations are not defined in securityDefinition misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-9.md)
- [OAuth2 security definitions includes password flow in OpenAPI 2.0 file misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-10.md)
- [OAuth2 password flow in security definitions for OpenAPI 2.0 file misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-11.md)
- [Security definition uses the deprecated implicit flow on OAuth2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-12.md)
- [Security definitions uses basic auth misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-13.md)
- [Operation Objects Uses 'Implicit' Flow misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-14.md)
- [Operation Objects Uses Basic Auth misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-15.md)
- [The global security scope is not defined in the securityDefinitions misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-19.md)
- [OpenStack hard coded password, token, or application\_credential\_secret exists in provider misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openstack-1.md)
- [OpenStack instance use basic credentials misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openstack-4.md)
- [AWS IAM group not in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-14.md)
- [Not all IAM users are members of at least one IAM group misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-21.md)
- [IAM User has access to the console misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-22.md)
- [AWS IAM policy allows full administrative privileges misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-40.md)
- [AWS EC2 Instance IAM Role not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-41.md)
- [AWS S3 buckets are accessible to any authenticated user misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-43.md)
- [AWS Cloudfront Distribution with S3 have Origin Access set to disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-46.md)
- [AWS OpenSearch Fine-grained access control is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-52.md)
- [The AWS Managed IAMFullAccess IAM policy should not be used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-56.md)
- [A Policy is not Defined for KMS Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-64.md)
- [AWS API Gateway method lacking authorization or API keys misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-70.md)
- [Azure SQL servers which doesn't have Azure Active Directory admin configured misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-7.md)
- [Azure SQL server not configured with Active Directory admin authentication misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-27.md)
- [Azure Container Instance not configured with the managed identity misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-30.md)
- [Azure Recovery Services vault is not configured with managed identity misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-35.md)
- [Azure Automation account is not configured with managed identity misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-36.md)
- [Azure Storage account configured with Shared Key authorization misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-40.md)
- [Azure Storage account not configured with SAS expiration policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-41.md)
- [Anonymous blob access configured in Azure storage account misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-47.md)
- ['chpasswd' is used to set or remove passwords misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-docker-17.md)
- [GCP Kubernetes Engine Cluster Nodes have default Service account for Project access misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-gcp-1.md)
- [There are not only GCP-managed service account keys for each service account misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-gcp-3.md)
- [A MySQL database instance allows anyone to connect with administrative privileges misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-gcp-7.md)
- [IBM Cloud API key creation is not restricted in account settings in Terraform misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-ibm-3.md)
- [IBM Cloud Multi-Factor Authentication (MFA) not enabled at the account level in Terraform misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-ibm-4.md)
- [IBM Cloud Service ID creation is not restricted in account settings in Terraform misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-ibm-5.md)
- [RoleBinding should not allow privilege escalation to a ServiceAccount or Node on other RoleBinding m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-1.md)
- [Granting create permissions to nodes/proxy or pods/exec sub resources allows potential privilege esc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-2.md)
- [No ServiceAccount/Node should have impersonate permissions for groups/users/service-accounts misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-3.md)
- [ServiceAccounts and nodes that can modify services/status may set the status.loadBalancer.ingress.ip](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-4.md)
- [No ServiceAccount/Node should be able to read all secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-5.md)
- [OCI tenancy administrator users are associated with API keys misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-oci-1.md)
- [Logging](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging.md)
- [Alibaba Cloud Action Trail Logging is not enabled for all regions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-4.md)
- [Alibaba Cloud Action Trail Logging is not enabled for all events misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-5.md)
- [Alibaba Cloud OSS bucket has access logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-12.md)
- [Alibaba Cloud RDS Instance SQL Collector Retention Period is less than 180 misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-25.md)
- [Alibaba Cloud RDS instance does not have log\_duration enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-35.md)
- [Alibaba Cloud RDS instance has log\_disconnections disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-36.md)
- [Alibaba Cloud RDS log audit is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-38.md)
- [AWS CloudTrail log validation is not enabled in all regions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-36.md)
- [AWS EKS control plane logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-37.md)
- [Amazon MQ Broker logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-48.md)
- [AWS CloudWatch Log groups not configured with definite retention days misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-66.md)
- [AWS CloudTrail is not enabled with multi trail and not capturing all management events misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-67.md)
- [AWS Redshift database does not have audit logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-71.md)
- [Global Accelerator does not have Flow logs enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-75.md)
- [API Gateway does not have access logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-76.md)
- [Amazon MSK cluster logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-80.md)
- [AWS Elasticsearch domain logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-84.md)
- [AWS DocumentDB logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-85.md)
- [AWS CloudFront distribution with access logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-86.md)
- [AWS Elastic Load Balancer v2 (ELBv2) with access log disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-91.md)
- [AWS Elastic Load Balancer (Classic) with access log disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-92.md)
- [AWS API Gateway V2 has Access Logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-95.md)
- [Neptune logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-101.md)
- [AWS config is not enabled in all regions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-121.md)
- [AWS CloudWatch Log groups encrypted using default encryption key instead of KMS CMK misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-158.md)
- [AWS WAF Web Access Control Lists logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-176.md)
- [AWS AppSync's logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-193.md)
- [AWS AppSync has field-level logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-194.md)
- [AWS MQBroker audit logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-197.md)
- [AWS ECS Cluster does not enable logging of ECS Exec misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-223.md)
- [AWS cluster logging is not enabled or client to container communication not encrypted using a Custom](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-224.md)
- [AWS ACM certificates does not have logging preference misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-234.md)
- [AWS MWAA environment has scheduler logs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-242.md)
- [AWS MWAA environment has worker logs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-243.md)
- [AWS MWAA environment has webserver logs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-244.md)
- [AWS CloudTrail logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-251.md)
- [AWS CloudTrail does not define an SNS Topic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-252.md)
- [Data Trace is not enabled in the API Gateway Method Settings misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-276.md)
- [State machine does not have X-ray tracing enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-284.md)
- [Execution history logging is not enabled on the State Machine misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-285.md)
- [AWS CodeBuild project not configured with logging configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-314.md)
- [Elasticsearch Domain Audit Logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-317.md)
- [RDS Cluster log capture is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-324.md)
- [RDS Cluster audit logging for MySQL engine is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-325.md)
- [AWS ECS services have automatic public IP address assignment enabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-333.md)
- [AWS CloudWatch log groups retention set to less than 365 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-338.md)
- [RDS instances have performance insights disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-353.md)
- [Azure Network Watcher Network Security Group (NSG) flow logs retention is less than 90 days misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-12.md)
- [Azure SQL Server auditing policy is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-23.md)
- [Azure SQL Server audit log retention is not greater than 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-24.md)
- [Azure SQL server send alerts to field value is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-26.md)
- [Azure storage account logging for queues is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-33.md)
- [Azure Activity Log retention should not be set to less than 365 days misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-37.md)
- [Azure Monitor log profile does not capture all activities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-38.md)
- [Azure App service HTTP logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-63.md)
- [App service disables detailed error messages misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-65.md)
- [App service does not enable failed request tracing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-66.md)
- [Server Parameter 'log\_retention' is Set to 'OFF' for PostgreSQL Database Server misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-146.md)
- [Azure SQL Server does not have default auditing policy configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-156.md)
- [Azure Built-in logging for Azure function app is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-159.md)
- [Ledger feature is disabled on the database misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-224.md)
- [GCP Kubernetes Engine Clusters have Cloud Logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-1.md)
- [GCP VPC Flow logs for the subnet is set to Off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-26.md)
- [GCP PostgreSQL instance with log\_checkpoints database flag is disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-51.md)
- [GCP PostgreSQL instance database flag log\_connections is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-52.md)
- [GCP PostgreSQL instance database flag log\_disconnections is disabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-53.md)
- [GCP PostgreSQL instance database flag log\_lock\_waits is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-54.md)
- [GCP PostgreSQL instance database flag log\_min\_messages is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-55.md)
- [GCP PostgreSQL instance database flag log\_temp\_files is not set to 0 misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-56.md)
- [GCP PostgreSQL instance database flag log\_min\_duration\_statement is not set to -1 misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-57.md)
- [GCP PostgreSQL instance database flag log\_hostname is not set to off misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-108.md)
- [Log levels of the GCP PostgreSQL database are not set to ERROR or lower misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-109.md)
- [pgAudit is disabled for your GCP PostgreSQL database misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-110.md)
- [SQL statements of GCP PostgreSQL are not logged misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-111.md)
- [The --audit-log-path argument is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-91.md)
- [The --audit-log-maxage argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-92.md)
- [The --audit-log-maxbackup argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-93.md)
- [The --audit-log-maxsize argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-94.md)
- [Security policies missing descriptions in Palo Alto Networks devices misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-8.md)
- [Log Forwarding Profile not selected for a Palo Alto Networks device security policy rule misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-9.md)
- [End-of-session logging disabled on Palo Alto Networks security policies misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-10.md)
- [Logging at session start enabled on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-16.md)
- [API Gateway stage does not have logging level defined appropriately misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-4.md)
- [AWS CloudTrail trail logs is not integrated with CloudWatch Log misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-10.md)
- [AWS VPC Flow Logs not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-11.md)
- [AWS RDS Postgres Cluster does not have query logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-27.md)
- [AWS Postgres RDS have Query Logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-30.md)
- [AWS WAF2 does not have a Logging Configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-31.md)
- [AWS Codecommit is not associated with an approval rule misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-37.md)
- [Domain Name System (DNS) query logging is not enabled for Amazon Route 53 hosted zones misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-39.md)
- [AWS Config Recording is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-45.md)
- [AWS Config must record all possible resources misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-48.md)
- [An S3 bucket must have a lifecycle configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-61.md)
- [S3 buckets do not have event notifications enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-62.md)
- [AWS Network Firewall is not configured with logging configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-63.md)
- [Azure storage account logging setting for tables is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-azure-20.md)
- [Azure storage account logging setting for blobs is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-azure-21.md)
- [GCP Log bucket retention policy is not configured using bucket lock misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-4.md)
- [GCP Project audit logging is not configured properly across all services and all users in a project](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-5.md)
- [GCP PostgreSQL instance database flag log\_duration is not set to on misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-13.md)
- [GCP PostgreSQL instance database flag log\_executor\_stats is not set to off misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-14.md)
- [GCP PostgreSQL instance database flag log\_parser\_stats is not set to off misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-15.md)
- [GCP PostgreSQL instance database flag log\_planner\_stats is not set to off misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-16.md)
- [GCP PostgreSQL instance database flag log\_statement\_stats is not set to off misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-17.md)
- [Logging is disabled for Dialogflow agents misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-29.md)
- [Logging for Dialogflow CX agents is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-30.md)
- [Logging for Dialogflow CX webhooks is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-31.md)
- [Monitoring](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring.md)
- [Alibaba Cloud Kubernetes node pools are not set to auto repair misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-ali-31.md)
- [Alibaba RDS instance has log\_connections disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-ali-37.md)
- [AWS ECS cluster with container insights feature disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-65.md)
- [AWS Amazon RDS instances Enhanced Monitoring is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-118.md)
- [AWS CloudFormation stack configured without SNS topic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-124.md)
- [AWS EC2 instance detailed monitoring disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-126.md)
- [AWS WAF does not have associated rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-175.md)
- [AWS GuardDuty detector is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-238.md)
- [Elastic Beanstalk environments do not have enhanced health reporting enabled misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-312.md)
- [CloudWatch alarm actions are not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-319.md)
- [EKS clusters are not running on a supported Kubernetes version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-339.md)
- [AWS resources that support tags do not have Tags misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-custom-1.md)
- [Azure AKS cluster monitoring not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-4.md)
- [Azure Microsoft Defender for Cloud Defender plans is set to Off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-19.md)
- [Azure Microsoft Defender for Cloud security contact phone number is not set misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-20.md)
- [Azure Microsoft Defender for Cloud security alert email notification is not set misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-21.md)
- [Azure Microsoft Defender for Cloud email notification for subscription owner is not set misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-22.md)
- [Azure SQL Server threat detection alerts are not enabled for all threat types misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-25.md)
- [Azure SQL Databases with disabled Email service and co-administrators for Threat Detection misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-27.md)
- [Azure Microsoft Defender for Cloud is set to Off for Servers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-55.md)
- [Azure Microsoft Defender for Cloud is set to Off for App Service misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-61.md)
- [Azure Microsoft Defender for Cloud is set to Off for Azure SQL Databases misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-69.md)
- [Azure Microsoft Defender for Cloud is set to Off for SQL servers on machines misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-79.md)
- [Azure Microsoft Defender for Cloud is set to Off for Storage misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-84.md)
- [Azure Security Center Defender set to Off for Kubernetes misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-85.md)
- [Azure Microsoft Defender for Cloud is set to Off for Container Registries misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-86.md)
- [Azure Microsoft Defender for Cloud is set to Off for Key Vault misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-87.md)
- [My SQL server does not enable Threat Detection policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-127.md)
- [PostgreSQL server does not enable Threat Detection policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-128.md)
- [Azure Microsoft Defender for Cloud security alert email notifications is not set misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-131.md)
- [Vulnerability Scanning not enabled for Azure Container Registry misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-163.md)
- [Azure App Service Health Check Missing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-213.md)
- [Azure Microsoft Defender for Cloud set to Off for Resource Manager misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-234.md)
- [Azure resources that support tags do not have tags misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-custom-1.md)
- [GCP Kubernetes Engine Clusters have Cloud Monitoring disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-8.md)
- [GCP Kubernetes cluster node auto-repair configuration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-9.md)
- [GCP Kubernetes cluster node auto-upgrade configuration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-10.md)
- [GCP Kubernetes Engine Clusters without any label information misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-21.md)
- [The GKE metadata server is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-69.md)
- [GCP Kubernetes Engine cluster not using Release Channel for version management misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-70.md)
- [GCP Kubernetes cluster shielded GKE node with integrity monitoring disabled misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-72.md)
- [GCP Cloud Armor policy not configured with cve-canary rule misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-73.md)
- [GCP resources that support labels do not have labels misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-custom-1.md)
- [GitHub Repository defined in Terraform doesn't have vulnerability alerts enabled misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-git-3.md)
- [Liveness probe is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-8.md)
- [Readiness probe is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-9.md)
- [The --profiling argument is not set to false for API server misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-90.md)
- [The --request-timeout argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-95.md)
- [The --profiling argument for controller managers is not set to False misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-107.md)
- [The --profiling argument is not set to False for scheduler misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-114.md)
- [The --event-qps argument is not set to a level that ensures appropriate event capture misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-147.md)
- [OCI Compute Instance has monitoring disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-oci-6.md)
- [Terraform module sources do not use a git url with a commit hash revision misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-tf-1.md)
- [Terraform module sources do not use a git url with a tag or commit hash revision misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-tf-2.md)
- [GuardDuty is not enabled to specific org/region misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-aws-3.md)
- [AWS CloudFront attached WAFv2 WebACL is not configured with AMR for Log4j Vulnerability misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-aws-47.md)
- [AWS RDS instance with copy tags to snapshots disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-aws-60.md)
- [Azure SQL Server ADS Vulnerability Assessment is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-2.md)
- [Azure SQL Server ADS Vulnerability Assessment (VA) Periodic recurring scans is disabled misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-3.md)
- [Azure SQL Server ADS Vulnerability Assessment (VA) 'Send scan reports to' is not configured misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-4.md)
- [Azure SQL Server ADS Vulnerability Assessment (VA) 'Also send email notifications to admins and subs](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-5.md)
- [Azure SQL server Defender setting is set to Off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-13.md)
- [GCP GCR Container Vulnerability Scanning is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-gcp-11.md)
- [Networking](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking.md)
- [Alibaba Cloud Kubernetes does not install plugin Terway or Flannel to support standard policies misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-ali-26.md)
- [Alibaba Cloud Cypher Policy is not secured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-ali-33.md)
- [Alibaba Cloud MongoDB is not deployed inside a VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-ali-41.md)
- [AWS EKS cluster security group overly permissive to all traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-38.md)
- [AWS CloudFront web distribution with AWS Web Application Firewall (AWS WAF) service disabled misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-68.md)
- [AWS EKS node group have implicit SSH access from 0.0.0.0/0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-100.md)
- [Deletion protection disabled for load balancer misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-113.md)
- [VPC endpoint service is not configured for manual acceptance misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-123.md)
- [Elastic load balancers do not use SSL Certificates provided by AWS Certificate Manager misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-127.md)
- [ALB does not drop HTTP headers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-131.md)
- [AWS Elastic Load Balancer (Classic) with cross-zone load balancing disabled misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-138.md)
- [Default VPC is planned to be provisioned misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-148.md)
- [AWS Elastic Load Balancer v2 with deletion protection feature disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-150.md)
- [AWS Elastic Load Balancer v2 (ELBv2) with cross-zone load balancing disabled misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-152.md)
- [WAF enables message lookup in Log4j2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-192.md)
- [AWS RDS security groups are not defined misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-198.md)
- [AWS ELB Policy uses some unsecure protocols misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-213.md)
- [AWS Cloudfront distribution is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-216.md)
- [AWS Elasticsearch uses the default security group misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-248.md)
- [ALB is not configured with the defensive or strictest desync mitigation mode misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-328.md)
- [Network firewalls do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-344.md)
- [Transfer server does not force secure protocols. misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-357.md)
- [AWS CloudFront web distribution with geo restriction disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-374.md)
- [Route 53 domains do not have transfer lock protection misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-377.md)
- [Azure AKS cluster network policies are not enforced misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-7.md)
- [Azure RDP Internet access is not restricted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-9.md)
- [CORS allows resources to access function apps misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-62.md)
- [Azure Function App doesn't use HTTP 2.0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-67.md)
- [Azure App Services Remote debugging is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-72.md)
- [Azure container container group is not deployed into a virtual network misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-98.md)
- [API management services do not use virtual networks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-107.md)
- [Key vault does not allow firewall rules settings misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-109.md)
- [AKS is not enabled for private clusters misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-115.md)
- [Azure application gateway does not have WAF enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-120.md)
- [Azure Front Door does not have the Azure Web application firewall (WAF) enabled misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-121.md)
- [Application gateway does not use WAF in Detection or Prevention modes misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-122.md)
- [Azure front door does not use WAF in Detection or Prevention modes misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-123.md)
- [Azure Front Door Web application firewall (WAF) policy rule for Remote Command Execution is disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-133.md)
- [Azure Application Gateway Web application firewall (WAF) policy rule for Remote Command Execution is](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-135.md)
- [Firewall policy does not have IDPS mode set to deny misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-220.md)
- [Azure Container Registry dedicated data endpoint is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-237.md)
- [Azure Batch Account configured with overly permissive network access misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-248.md)
- [Azure Storage Sync Service configured with overly permissive network access misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-250.md)
- [Azure VM disk configured with public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-251.md)
- [GCP Kubernetes Engine Clusters have Network policy disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-12.md)
- [GCP Kubernetes Engine Clusters have Master authorized networks disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-20.md)
- [GCP Kubernetes Engine Clusters have Alias IP disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-23.md)
- [GCP Kubernetes Engine private cluster has private endpoint disabled misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-25.md)
- [GCP Kubernetes cluster intra-node visibility disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-61.md)
- [GCP Kubernetes Engine Clusters not configured with private nodes feature misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-64.md)
- [Containers wishing to share host network namespace admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-4.md)
- [Containers share the host network namespace misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-19.md)
- [hostPort is specified misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-26.md)
- [The --kubelet-https argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-71.md)
- [The API server does not make use of strong cryptographic ciphers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-105.md)
- [The --bind-address argument for controller managers is not set to 127.0.0.1 misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-113.md)
- [The --bind-address argument is not set to 127.0.0.1 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-115.md)
- [The --auto-tls argument is set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-118.md)
- [The --make-iptables-util-chains argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-145.md)
- [The --tls-cert-file and --tls-private-key-file arguments for Kubelet are not set appropriately misco](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-148.md)
- [Kubelet does not use strong cryptographic ciphers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-151.md)
- [NGINX Ingress annotation snippets contains LUA code execution misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-152.md)
- [NGINX Ingress has annotation snippets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-153.md)
- [NGINX Ingress has annotation snippets which contain alias statements misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-154.md)
- [OCI Network Security Groups (NSG) has stateful security rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-oci-21.md)
- [OCI Data Catalog configured with overly permissive network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-oci-23.md)
- [OpenStack firewall rule does not have destination IP configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-openstack-5.md)
- [Plain-text management HTTP enabled for Interface Management Profile in Palo Alto Networks devices mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-2.md)
- [Plain-text management Telnet enabled for Interface Management Profile in Palo Alto Networks devices](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-3.md)
- [Disable Server Response Inspection (DSRI) enabled in security policies for Palo Alto Networks device](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-4.md)
- [Security rule allows any application on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-5.md)
- [Security rule permits any service on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-6.md)
- [Security Rule in Palo Alto Networks devices with overly broad Source and Destination IPs misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-7.md)
- [IPsec profile uses insecure authentication algorithms on Palo Alto Networks devices misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-12.md)
- [IPsec profile uses insecure authentication protocols on Palo Alto Networks devices misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-13.md)
- [Security zone on Palo Alto Networks devices does not have an associated Zone Protection Profile misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-14.md)
- [Include ACL (Access Control List) not defined for a security zone in Palo Alto Networks devices with](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-15.md)
- [Security rules apply to all zones on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-17.md)
- [AWS AppSync is not protected by WAF misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-33.md)
- [AWS NAT Gateways are not utilized for the default route misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-35.md)
- [AWS ACM Certificate with wildcard domain name misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-71.md)
- [AWS Load Balancers do not use strong ciphers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-74.md)
- [AWS Lambda function URL having overly permissive cross-origin resource sharing permissions misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-75.md)
- [Azure Automation account configured with overly permissive network access misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-azure-24.md)
- [Azure MySQL Flexible Server not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-azure-56.md)
- [PostgreSQL Flexible Server not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-azure-57.md)
- [GCP project is configured with legacy network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-2.md)
- [Vertex AI workbench instances are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-28.md)
- [GCP public-facing (external) regional load balancer using HTTP protocol misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-37.md)
- [GCP public-facing (external) global load balancer using HTTP protocol misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-38.md)
- [IBM Cloud Virtual Private Cloud (VPC) classic access is enabled in Terraform misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-ibm-2.md)
- [Public Exposure](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure.md)
- [Alibaba Cloud OSS bucket accessible to public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-1.md)
- [Alibaba Cloud Security group allow internet traffic to SSH port (22) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-2.md)
- [Alibaba Cloud Security group allow internet traffic to RDP port (3389) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-3.md)
- [Alibaba Cloud database instance accessible to public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-9.md)
- [Alibaba Cloud RDS instance does not use SSL misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-20.md)
- [Alibaba Cloud API Gateway API Protocol does not use HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-21.md)
- [Alibaba cloud ALB ACL does not restrict public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-29.md)
- [Alibaba Cloud Mongodb instance does not use SSL misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-42.md)
- [Alibaba Cloud MongoDB instance is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-43.md)
- [AWS Elastic Load Balancer v2 (ELBv2) listener that allow connection requests over HTTP misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-2.md)
- [AWS Elasticsearch does not have node-to-node encryption enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-6.md)
- [AWS RDS database instance is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-17.md)
- [Not every Security Group rule has a description misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-23.md)
- [AWS Security Group allows all traffic on SSH port (22) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-24.md)
- [AWS Security Group allows all traffic on RDP port (3389) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-25.md)
- [AWS ElastiCache Redis cluster with in-transit encryption disabled (Replication group) misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-30.md)
- [AWS ElastiCache Redis cluster with Redis AUTH feature disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-31.md)
- [AWS CloudFront viewer protocol policy is not configured with HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-34.md)
- [AWS EKS cluster endpoint access publicly enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-39.md)
- [AWS access keys and secrets are hard coded in infrastructure misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-41.md)
- [Lambda function's environment variables expose secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-45.md)
- [EC2 user data exposes secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-46.md)
- [AWS API gateway methods are publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-59.md)
- [AWS MQ is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-69.md)
- [AWS Elasticsearch domain is not configured with HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-83.md)
- [AWS Redshift cluster instance with public access setting enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-87.md)
- [AWS EC2 instances with public IP and associated with security groups have Internet access misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-88.md)
- [AWS DMS replication instance is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-89.md)
- [Neptune cluster instance is publicly available misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-102.md)
- [AWS Load Balancer is not using TLS 1.2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-103.md)
- [AWS VPC subnets should not allow automatic public IP assignment misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-130.md)
- [AWS Elasticsearch is not configured inside a VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-137.md)
- [Redshift is deployed outside of a VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-154.md)
- [AWS Transfer Server is publicly exposed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-164.md)
- [AWS CloudFront web distribution using insecure TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-174.md)
- [AWS Elasticache security groups are not defined misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-196.md)
- [AWS API Gateway Domain does not use a modern security policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-206.md)
- [AWS Cloudsearch does not use the latest (Transport Layer Security) TLS misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-218.md)
- [AWS Cloudsearch does not use HTTPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-220.md)
- [AWS Elasticsearch domain does not use an updated TLS policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-228.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 21 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-229.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 20 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-230.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 3389 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-231.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 22 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-232.md)
- [AWS DAX cluster endpoint does not use TLS (Transport Layer Security) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-239.md)
- [AWS CloudFront response header policy does not enforce Strict Transport Security misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-259.md)
- [AWS security groups allow ingress from 0.0.0.0/0 to port 80 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-260.md)
- [AWS Security Group allows all traffic on all ports misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-277.md)
- [MSK nodes are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-291.md)
- [AWS RDS snapshots are accessible to public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-302.md)
- [AWS SSM documents are public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-303.md)
- [AWS CloudFront distributions does not have a default root object configured misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-305.md)
- [AWS SageMaker notebook instance is not placed in VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-306.md)
- [CloudFront distributions do not have origin failover configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-310.md)
- [ElastiCache cluster is using the default subnet group misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-323.md)
- [AWS Transit Gateway auto accept vpc attachment is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-331.md)
- [WAF rule does not have any actions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-342.md)
- [NACL ingress allows all ports misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-352.md)
- [TLS not enforced in SES configuration set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-365.md)
- [AWS Elastic Load Balancer with listener TLS/SSL is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-376.md)
- [AWS Load Balancer uses HTTP protocol misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-378.md)
- [AWS S3 bucket not configured with secure data transport policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-379.md)
- [AWS Transfer Server not using latest Security Policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-380.md)
- [Azure Virtual Machine (Linux) does not authenticate using SSH keys misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-1.md)
- [Kubernetes dashboard is not disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-8.md)
- [Azure Network Security Group allows all traffic on SSH port 22 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-10.md)
- [Azure SQL Servers Firewall rule allow ingress access from 0.0.0.0/0 misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-11.md)
- [Azure App Service Web app doesn't redirect HTTP to HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-14.md)
- [Azure App Service Web app doesn't use latest TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-15.md)
- [Azure App Service Web app client certificate is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-17.md)
- [Azure App Service Web app doesn't use HTTP 2.0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-18.md)
- [Azure MySQL Database Server SSL connection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-28.md)
- [Azure PostgreSQL database server with SSL connection disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-29.md)
- [Azure storage account has a blob container that is publicly accessible misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-34.md)
- [Azure Storage Account default network access is set to 'Allow' misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-35.md)
- [Azure MariaDB database server with SSL connection disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-47.md)
- [MariaDB servers do not have public network access enabled set to False misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-48.md)
- ['public network access enabled' is not set to 'False' for mySQL servers misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-53.md)
- [MySQL is not using the latest version of TLS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-54.md)
- [CORS allows resource to access app services misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-57.md)
- [Azure storage account does allow public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-59.md)
- [Azure file sync enables public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-64.md)
- [PostgreSQL server does not disable public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-68.md)
- [Azure Function App doesn't redirect HTTP to HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-70.md)
- [Azure Network Security Group having Inbound rule overly permissive to all traffic on UDP protocol mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-77.md)
- [Azure App Services FTP deployment is All allowed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-78.md)
- [Azure cache for Redis has public network access enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-89.md)
- [Cosmos DB accounts do not have restricted access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-99.md)
- [Azure Cosmos DB enables public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-101.md)
- [Azure Data Factory (V2) configured with overly permissive network access misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-104.md)
- [Azure Event Grid domain public network access is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-106.md)
- [Azure IoT Hub enables public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-108.md)
- [SQL Server is enabled for public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-113.md)
- [Azure Virtual machine NIC has IP forwarding enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-118.md)
- [Network interfaces use public IPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-119.md)
- [Azure cognitive search does not disable public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-124.md)
- [Azure Container registries Public access to All networks is enabled misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-139.md)
- [Azure AKS cluster nodes have public IP addresses misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-143.md)
- [Azure Function App doesn't use latest TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-145.md)
- [Azure Redis Cache does not use the latest version of TLS encryption misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-148.md)
- [Azure Client Certificates are not enforced for API management misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-152.md)
- [Azure web app does not redirect all HTTP traffic to HTTPS in Azure App Service Slot misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-153.md)
- [Azure App's service slot does not use the latest version of TLS encryption misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-154.md)
- [Azure App service slot does not have debugging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-155.md)
- [Azure HTTP (port 80) access from the internet is not restricted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-160.md)
- [Azure Spring Cloud API Portal is not enabled for HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-161.md)
- [Azure Spring Cloud API Portal Public Access Is Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-162.md)
- [API Management Without Minimum TLS 1.2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-173.md)
- [API Management with Public Access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-174.md)
- [Web PubSub Without SLA SKU misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-175.md)
- [VNET With Only One DNS Endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-182.md)
- [VNET Using External DNS Addresses misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-183.md)
- [App Configuration Public Access Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-185.md)
- [Azure Key Vault Public Network Access Control misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-189.md)
- [Azure storage account has a blob container with public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-190.md)
- [Azure Event Grid Topic Public Network Access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-193.md)
- [Azure SignalR Service not Using Paid SKU for its SLA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-196.md)
- [Azure CDN Doesn't Disable HTTP Endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-197.md)
- [Azure CDN Endpoint Custom domains is not configured with HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-198.md)
- [Azure CDN Using Outdated TLS Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-200.md)
- [Azure Service Bus with Public Network Access Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-204.md)
- [Azure Service Bus Without Latest TLS Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-205.md)
- [Azure Cognitive Search With Global IP Allowance misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-210.md)
- [Azure App Service Instance Lacks Redundancy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-212.md)
- [Backend of the API management system does not utilize HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-215.md)
- [DenyIntelMode for Azure Firewalls is not set to Deny misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-216.md)
- [Azure Application gateways listener that allow connection requests over HTTP misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-217.md)
- [Azure Application Gateway is configured with SSL policy having TLS version 1.1 or lower misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-218.md)
- [Azure Firewall does not define a firewall policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-219.md)
- [Azure Function app configured with public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-221.md)
- [Azure App Service web apps with public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-222.md)
- [Event Hub Namespace not using TLS 1.2 or greater misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-223.md)
- [Azure Container Instance environment variable with regular value type misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-235.md)
- [Azure Container Instance is not configured with virtual network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-245.md)
- [Azure AKS cluster HTTP application routing enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-246.md)
- [Port 22 is exposed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-docker-1.md)
- [GCP Firewall rule allows all traffic on SSH port (22) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-2.md)
- [GCP Firewall rule allows all traffic on RDP port (3389) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-3.md)
- [GCP HTTPS Load balancer is set with SSL policy having TLS version 1.1 or lower misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-4.md)
- [GCP SQL Instances do not have SSL configured for incoming connections misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-6.md)
- [GCP SQL database is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-11.md)
- [GCP BigQuery dataset is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-15.md)
- [GCP Cloud DNS has DNSSEC disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-16.md)
- [RSASHA1 is used for Zone-Signing and Key-Signing Keys in Cloud DNS DNSSEC misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-17.md)
- [GKE control plane is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-18.md)
- [GCP project is using the default network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-27.md)
- [GCP Storage bucket is anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-28.md)
- [GCP VM instances do have block project-wide SSH keys feature disabled misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-32.md)
- [GCP Projects do have OS Login disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-33.md)
- [GCP Projects have OS Login disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-34.md)
- [GCP VM instances have serial port access enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-35.md)
- [GCP VM instances have IP Forwarding enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-36.md)
- [GCP VM instance with Shielded VM features disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-39.md)
- [GCP VM instance with the external IP address misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-40.md)
- [GCP Cloud SQL database instances have public IPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-60.md)
- [GCP VPC Network subnets have Private Google access disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-74.md)
- [GCP Firewall rule allows all traffic on FTP port (21) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-75.md)
- [GCP VPC Network subnets have Private Google access for IPv6 disabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-76.md)
- [GCP Google compute firewall ingress allow FTP port (20) access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-77.md)
- [GCP cloud build workers are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-86.md)
- [GCP data fusion instances are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-87.md)
- [GCP Firewall rule allows all traffic on MySQL DB port (3306) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-88.md)
- [GCP Vertex AI instances are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-89.md)
- [GCP Dataflow jobs are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-94.md)
- [GCP Dataproc clusters are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-98.md)
- [GCP Pub/Sub Topics are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-99.md)
- [GCP BigQuery Tables are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-100.md)
- [GCP Artifact Registry repositories are anonymously or publicly accessible misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-101.md)
- [GCP Cloud Run services are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-102.md)
- [GCP Firewall rule allows all traffic on HTTP port (80) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-106.md)
- [GCP Cloud Function is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-107.md)
- [GCP Storage buckets are publicly accessible to all users misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-114.md)
- [GCP Cloud Function configured with overly permissive Ingress setting misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-124.md)
- [GitHub repository webhook defined in Terraform does not use a secure SSL misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-git-2.md)
- [Tiller (Helm V2) deployment is accessible from within the cluster misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-45.md)
- [The --insecure-bind-address argument is set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-86.md)
- [The --insecure-port argument is not set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-88.md)
- [The --secure-port argument is set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-89.md)
- [The --tls-cert-file and --tls-private-key-file arguments for API server are not set appropriately mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-100.md)
- [The --read-only-port argument is not set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-141.md)
- [OCI VCN has no inbound security list misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-16.md)
- [OCI VCN Security list has stateful security rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-17.md)
- [OCI Security List allows all traffic on SSH port (22) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-19.md)
- [OCI security lists allows unrestricted ingress access to port 3389 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-20.md)
- [OCI security group allows unrestricted ingress access to port 22 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-22.md)
- [OpenAPI Security Definitions Object should be set and not empty misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-1.md)
- [OpenAPI If the security scheme is not of type 'oauth2', the array value must be empty misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-2.md)
- [Cleartext credentials over unencrypted channel should not be accepted for the operation misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-3.md)
- [The path scheme is supports unencrypted HTTP connections misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-7.md)
- [Global schemes use 'httpa' protocol instead of 'https' misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-18.md)
- [API keys transmitted over cleartext misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-20.md)
- [OpenStack Security groups allow ingress from 0.0.0.0:0 to port 22 (tcp / udp) misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openstack-2.md)
- [OpenStack Security groups allow ingress from 0.0.0.0:0 to port 3389 (tcp / udp) misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openstack-3.md)
- [HTTPS url not used with Ansible uri misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ansible-1.md)
- [HTTPS url not used with Ansible get\_url module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ansible-2.md)
- [AWS Network ACL is not in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-1.md)
- [Security Groups are not attached to EC2 instances or ENIs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-5.md)
- [S3 Bucket does not have public access blocks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-6.md)
- [Amazon EMR clusters' security groups are open to the world misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-7.md)
- [AWS Default Security Group does not restrict all traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-12.md)
- [Auto scaling groups associated with a load balancer do not use elastic load balancing health checks](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-15.md)
- [Not all EIP addresses allocated to a VPC are attached to EC2 instances misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-19.md)
- [ALB does not redirect HTTP requests into HTTPS ones misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-20.md)
- [Route53 A Record does not have Attached Resource misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-23.md)
- [AWS Application Load Balancer (ALB) not configured with AWS Web Application Firewall v2 (AWS WAFv2)](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-28.md)
- [Public API gateway not configured with AWS Web Application Firewall v2 (AWS WAFv2) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-29.md)
- [AWS CloudFront distribution does not have a strict security headers policy attached misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-32.md)
- [AWS Terraform sends SSM secrets to untrusted domains over HTTP misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-36.md)
- [Domain Name System Security Extensions (DNSSEC) signing is not enabled for Amazon Route 53 public ho](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-38.md)
- [AWS CloudFront web distribution with default SSL certificate misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-42.md)
- [AWS route table with VPC peering overly permissive to all traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-44.md)
- [AWS Database Migration Service endpoint do not have SSL configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-49.md)
- [AWS API Gateway endpoints without client certificate authentication misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-51.md)
- [AWS API gateway request parameter is not validated misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-53.md)
- [AWS CloudFront distribution is using insecure SSL protocols for HTTPS communication misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-54.md)
- [MWAA environment is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-66.md)
- [AWS CloudFront origin protocol policy does not enforce HTTPS-only misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-72.md)
- [Azure PostgreSQL Database Server 'Allow access to Azure services' enabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-6.md)
- [Azure Storage account container storing activity logs is publicly accessible misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-8.md)
- [Azure Spring Cloud service is not configured with virtual network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-23.md)
- [Azure PostgreSQL database flexible server configured with overly permissive network access misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-26.md)
- [Azure ACR HTTPS not enabled for webhook misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-28.md)
- [Azure AKS cluster Azure CNI networking not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-29.md)
- [Azure Virtual Network subnet is not configured with a Network Security Group misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-31.md)
- [Azure Key vault Private endpoint connection is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-32.md)
- [Azure Storage account is not configured with private endpoint connection misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-33.md)
- [Azure SQL Server allow access to any Azure internal resources misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-34.md)
- [Azure Virtual machine configured with public IP and serial console access misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-39.md)
- [Azure PostgreSQL servers not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-42.md)
- [Azure Database for MariaDB not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-43.md)
- [Azure Database for MySQL server not configured with private endpoint misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-44.md)
- [Azure SQL Database server not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-45.md)
- [Azure Spring Cloud app end-to-end TLS is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-55.md)
- [GCP KMS crypto key is anonymously accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-6.md)
- [GCP Cloud KMS Key Rings are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-8.md)
- [GCP Container Registry repositories are anonymously or publicly accessible misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-9.md)
- [GCP Cloud Function HTTP trigger is not secured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-10.md)
- [GCP Firewall with Inbound rule overly permissive to All Traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-12.md)
- [Google Cloud Platform network is not ensured to define a firewall misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-18.md)
- [TPU v2 VM is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-32.md)
- [IBM Cloud Application Load Balancer for VPC has public access enabled in Terraform misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ibm-1.md)
- [IBM Cloud Kubernetes clusters are accessible by using public endpoint in Terraform misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ibm-7.md)
- [OCI Network Security Group allows all traffic on RDP port (3389) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-oci-2.md)
- [OCI Kubernetes Engine Cluster endpoint is not configured with Network Security Groups misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-oci-3.md)
- [OCI Kubernetes Engine Cluster pod security policy not enforced misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-oci-6.md)
- [Storage](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage.md)
- [Alibaba Cloud OSS bucket is not encrypted with Customer Master Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-6.md)
- [Alibaba Cloud disk encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-7.md)
- [Alibaba Cloud Disk is not encrypted with Customer Master Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-8.md)
- [Alibaba Cloud OSS bucket has versioning disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-10.md)
- [Alibaba Cloud OSS bucket has transfer Acceleration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-11.md)
- [Alibaba Cloud Transparent Data Encryption is disabled on instance misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-22.md)
- [Alibaba Cloud launch template data disks are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-32.md)
- [Alibaba Cloud MongoDB does not have transparent data encryption enabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-44.md)
- [AWS EBS volumes are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-3.md)
- [AWS Elasticsearch domain Encryption for data at rest is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-5.md)
- [AWS EC2 Auto Scaling Launch Configuration is not using encrypted EBS volumes misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-8.md)
- [AWS RDS DB cluster encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-16.md)
- [AWS Access logging not enabled on S3 buckets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-18.md)
- [AWS S3 buckets do not have server side encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-19.md)
- [AWS S3 bucket ACL grants READ permission to everyone misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-20.md)
- [AWS S3 Object Versioning is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-21.md)
- [AWS SNS topic has SSE disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-26.md)
- [AWS SQS Queue not configured with server side encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-27.md)
- [DynamoDB PITR is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-28.md)
- [AWS ElastiCache Redis cluster with encryption for data at rest disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-29.md)
- [AWS CloudTrail logs are not encrypted using Customer Master Keys (CMKs) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-35.md)
- [AWS Elastic File System (EFS) with encryption for data at rest is disabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-42.md)
- [AWS Kinesis streams are not encrypted using Server Side Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-43.md)
- [Neptune storage is not securely encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-44.md)
- [AWS DAX cluster not configured with encryption at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-47.md)
- [ECR image tags are not immutable misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-51.md)
- [AWS S3 Bucket has the block public ACLs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-53.md)
- [AWS S3 Bucket BlockPublicPolicy is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-54.md)
- [AWS S3 bucket IgnorePublicAcls is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-55.md)
- [AWS S3 bucket RestrictPublicBucket is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-56.md)
- [AWS S3 Bucket has an ACL defined which allows public WRITE access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-57.md)
- [AWS EKS cluster does not have secrets encryption enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-58.md)
- [AWS Redshift instances are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-64.md)
- [AWS S3 bucket policy overly permissive to any principal misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-70.md)
- [DocumentDB is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-74.md)
- [Athena Database is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-77.md)
- [CodeBuild project encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-78.md)
- [AWS MSK cluster encryption in transit is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-81.md)
- [Athena workgroup does not prevent disabling encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-82.md)
- [DocDB TLS is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-90.md)
- [S3 bucket policy allows lockout all but root user misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-93.md)
- [Glue Data Catalog encryption is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-94.md)
- [Not all data stored in Aurora is securely encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-96.md)
- [EFS volumes in ECS task definitions do not have encryption in transit enabled misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-97.md)
- [AWS Glue security configuration encryption is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-99.md)
- [DocDB does not have audit logs enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-104.md)
- [AWS Redshift does not have require\_ssl configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-105.md)
- [AWS EBS volume region with encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-106.md)
- [Session Manager data is not encrypted in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-112.md)
- [AWS DynamoDB encrypted using AWS owned CMK instead of AWS managed CMK misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-119.md)
- [AWS RDS instance without Automatic Backup setting misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-133.md)
- [AWS ElastiCache Redis cluster is not configured with automatic backup misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-134.md)
- [EC2 EBS is not optimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-135.md)
- [Unencrypted ECR repositories misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-136.md)
- [AWS RDS cluster delete protection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-139.md)
- [Unencrypted RDS global clusters misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-140.md)
- [Redshift clusters version upgrade is not default misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-141.md)
- [AWS Redshift Cluster not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-142.md)
- [S3 bucket lock configuration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-143.md)
- [S3 bucket cross-region replication disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-144.md)
- [S3 buckets are not encrypted with KMS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-145.md)
- [AWS RDS DB snapshot is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-146.md)
- [CodeBuild projects are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-147.md)
- [AWS Secrets Manager secret not encrypted by Customer Managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-149.md)
- [Workspace user volumes are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-155.md)
- [Workspace root volumes are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-156.md)
- [RDS instances do not have Multi-AZ enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-157.md)
- [Athena Workgroup is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-159.md)
- [Timestream database is not encrypted with KMS CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-160.md)
- [Dynamodb point in time recovery is not enabled for global tables misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-165.md)
- [Backup Vault is not encrypted at rest using KMS CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-166.md)
- [QLDB ledger permissions mode is not set to STANDARD misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-170.md)
- [AWS EMR cluster is not configured with SSE KMS for data at rest encryption (Amazon S3 with EMRFS) mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-171.md)
- [AWS QLDB ledger has deletion protection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-172.md)
- [AWS Lambda encryption settings environmental variable is not set properly misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-173.md)
- [AWS Kinesis Video Stream not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-177.md)
- [AWS fx ontap file system not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-178.md)
- [AWS FSX Windows filesystem not encrypted using Customer Managed Key misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-179.md)
- [AWS Image Builder component not encrypted using Customer Managed Key misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-180.md)
- [AWS S3 Object Copy not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-181.md)
- [AWS Doc DB not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-182.md)
- [AWS EBS Snapshot Copy not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-183.md)
- [AWS Elastic File System (EFS) is not encrypted using Customer Managed Key misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-184.md)
- [AWS Kinesis streams encryption is using default KMS keys instead of Customer's Managed Master Keys m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-185.md)
- [AWS S3 bucket Object not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-186.md)
- [AWS EBS Volume not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-189.md)
- [AWS lustre file system not configured with CMK key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-190.md)
- [AWS Elasticache replication group not configured with CMK key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-191.md)
- [AWS Glue component is not associated with a security configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-195.md)
- [AWS Image Builder Distribution Configuration is not encrypting AMI by Key Management Service (KMS) u](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-199.md)
- [AWS Image Recipe EBS Disk are not encrypted using a Customer Managed Key (CMK) misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-200.md)
- [AWS MemoryDB is not encrypted at rest by AWS' Key Management Service KMS using CMKs misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-201.md)
- [AWS MemoryDB data is not encrypted in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-202.md)
- [AWS FSX openzfs is not encrypted by AWS' Key Management Service (KMS) using a Customer Managed Key (](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-203.md)
- [AWS AMIs are not encrypted by Key Management Service (KMS) using Customer Managed Keys (CMKs) miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-204.md)
- [AWS MQ Broker is not encrypted by Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-209.md)
- [AWS RDS does not use a modern CaCert misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-211.md)
- [AWS EBS Volume is not encrypted by Key Management Service (KMS) using a Customer Managed Key (CMK) m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-212.md)
- [AWS Appsync API Cache is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-214.md)
- [AWS Appsync API Cache is not encrypted in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-215.md)
- [AWS CodePipeline artifactStore is not encrypted by Key Management Service (KMS) using a Customer Man](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-219.md)
- [AWS Code Artifact Domain is not encrypted by KMS using a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-221.md)
- [AWS copied AMIs are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-235.md)
- [AWS AMI copying does not use a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-236.md)
- [AWS Kinesis Firehose's delivery stream is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-240.md)
- [AWS Kinesis Firehose Delivery Streams are not encrypted with CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-241.md)
- [AWS replicated backups are not encrypted at rest by Key Management Service (KMS) using a Customer Ma](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-245.md)
- [AWS RDS Cluster activity streams are not encrypted by Key Management Service (KMS) using Customer Ma](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-246.md)
- [AWS all data stored in the Elasticsearch domain is not encrypted using a Customer Managed Key (CMK)](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-247.md)
- [AWS RDS PostgreSQL exposed to local file read vulnerability misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-250.md)
- [AWS DLM cross-region events are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-253.md)
- [AWS DLM cross-region events are not encrypted with a Customer Managed Key (CMK) misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-254.md)
- [AWS DLM-cross region schedules are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-255.md)
- [AWS DLM cross-region schedules are not encrypted using a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-256.md)
- [AWS App Flow flow does not use Customer Managed Keys (CMKs) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-263.md)
- [AWS App Flow connector profile does not use Customer Managed Keys (CMKs) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-264.md)
- [AWS Keyspace Table does not use Customer Managed Keys (CMKs) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-265.md)
- [AWS RDS DB snapshot does not use Customer Managed Keys (CMKs) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-266.md)
- [Comprehend Entity Recognizer's model is not encrypted by KMS using a customer managed Key (CMK) misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-267.md)
- [Comprehend Entity Recognizer's volume is not encrypted by KMS using a customer managed Key (CMK) mis](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-268.md)
- [Connect Instance Kinesis Video Stream Storage Config is not using CMK for encryption misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-269.md)
- [The Connect Instance S3 Storage Configuration utilizes Customer Managed Key. misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-270.md)
- [DynamoDB table replica does not use CMK KMS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-271.md)
- [MemoryDB snapshot is not encrypted by KMS using a customer managed Key (CMK) misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-278.md)
- [Neptune snapshot is not securely encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-279.md)
- [Neptune snapshot is encrypted by KMS using a customer managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-280.md)
- [RedShift snapshot copy is not encrypted by KMS using a customer managed Key (CMK). misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-281.md)
- [Redshift Serverless namespace is not encrypted by KMS using a customer managed key (CMK) misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-282.md)
- [DocDB Global Cluster is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-292.md)
- [AWS database instances do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-293.md)
- [CloudTrail Event Data Store does not use Customer Managed Keys (CMKs) misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-294.md)
- [DataSync Location Object Storage exposes secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-295.md)
- [DMS endpoint is not using a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-296.md)
- [EventBridge Scheduler Schedule is not using a Customer Managed Key (CMK) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-297.md)
- [The DMS S3 does not use a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-298.md)
- [S3 lifecycle configuration does not set a period for aborting failed uploads misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-300.md)
- [Secrets Manager secrets are not rotated within 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-304.md)
- [CodeBuild S3 logs are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-311.md)
- [RDS Aurora Clusters do not have backtracking enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-326.md)
- [AWS RDS DB cluster is encrypted using default KMS key instead of CMK misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-327.md)
- [EFS Access Points are not enforcing a root directory misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-329.md)
- [User identity should be enforced by EFS access points misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-330.md)
- [SSM parameters are not utilizing KMS CMK. misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-337.md)
- [Amazon Redshift clusters do not have automatic snapshots enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-343.md)
- [Network firewall encryption does not use a CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-345.md)
- [Network Firewall Policy does not define an encryption configuration that uses a CMK misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-346.md)
- [Neptune is not encrypted with KMS using a customer managed Key (CMK) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-347.md)
- [AWS EMR cluster is not enabled with local disk encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-349.md)
- [Security configuration of the EMR Cluster does not ensure the encryption of EBS disks misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-350.md)
- [AWS EMR cluster is not enabled with data encryption in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-351.md)
- [RDS Performance Insights are not encrypted using KMS CMKs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-354.md)
- [AWS DocumentDB clusters have backup retention period less than 7 days misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-360.md)
- [AWS Neptune DB clusters have backup retention period less than 7 days misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-361.md)
- [Clusters of Neptune DB do not replicate tags to snapshots misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-362.md)
- [Bedrock Agent not encrypted with Customer Master Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-373.md)
- [AWS S3 bucket has global view ACL permissions enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-375.md)
- [AWS CodeGuru Reviewer repository association does not use a Customer Managed Key (CMK) misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-381.md)
- [Not all data stored in the EBS snapshot is securely encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-custom-3.md)
- [Azure VM data disk is not encrypted with ADE/CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-2.md)
- [Azure Storage Account without Secure transfer enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-3.md)
- [Azure PostgreSQL database server with log checkpoints parameter disabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-30.md)
- [Azure PostgreSQL database server with log connections parameter disabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-31.md)
- [Azure PostgreSQL database server with connection throttling parameter is disabled misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-32.md)
- [Azure Storage Account 'Trusted Microsoft Services' access not enabled misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-36.md)
- [Azure Key Vault Keys does not have expiration date misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-40.md)
- [Azure Key Vault secrets does not have expiration date misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-41.md)
- [Azure Key Vault is not recoverable misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-42.md)
- [Storage Account name does not follow naming rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-43.md)
- [Azure Storage Account using insecure TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-44.md)
- [MSSQL is not using the latest version of TLS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-52.md)
- [Azure Automation account variables are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-73.md)
- [Azure Data Explorer cluster disk encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-74.md)
- [Azure Data Explorer cluster double encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-75.md)
- [Azure Batch account does not use key vault to encrypt data misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-76.md)
- [App services do not use Azure files misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-88.md)
- [Not only SSL are enabled for cache for Redis misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-91.md)
- [Managed disks do not use a specific set of disk encryption sets for customer-managed key encryption](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-93.md)
- [My SQL server disables geo-redundant backups misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-94.md)
- [MySQL server disables infrastructure encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-96.md)
- [Virtual machine scale sets do not have encryption at host enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-97.md)
- [Cosmos DB Accounts do not have CMKs encrypting data at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-100.md)
- [PostgreSQL server enables geo-redundant backups misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-102.md)
- [Unencrypted Data Lake Store accounts misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-105.md)
- [Azure Key Vault Purge protection is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-110.md)
- [Key vault does not enable soft-delete misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-111.md)
- [Key vault key is not backed by HSM misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-112.md)
- [Key vault secrets do not have content\_type set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-114.md)
- [Azure AKS cluster is not configured with disk encryption set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-117.md)
- [MariaDB server does not enable geo-redundant backups misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-129.md)
- [PostgreSQL server does not enable infrastructure encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-130.md)
- [Azure Cosmos DB key based authentication is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-132.md)
- [Azure PostgreSQL Flexible Server does not enable geo-redundant backups misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-136.md)
- [Azure PostgreSQL does not use the latest version of TLS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-147.md)
- [Azure Windows VM does not enable encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-151.md)
- [Geo-Replicated Not Enabled for Azure Container Registry (ACR) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-165.md)
- [Azure Container Registry (ACR) Does Not Have a Quarantine Policy Enabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-166.md)
- [Azure Container Registry (ACR) Doesn't Have a Retention Policy Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-167.md)
- [AKS Secrets Store Without Auto-Rotation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-172.md)
- [Azure Data Explorer without SLA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-180.md)
- [App Configuration Encryption Block Not Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-186.md)
- [App Configuration Without Purge Protection Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-187.md)
- [Azure Service Bus Doesn't Use Double Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-199.md)
- [Azure Service Bus Doesn't Use Customer-Managed Key Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-201.md)
- [Azure Storage Accounts Without Proper Replication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-206.md)
- [Azure Cognitive Search Without SLA Index Updates misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-208.md)
- [Azure Cognitive Search Without SLA for Search Index Queries misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-209.md)
- [App Service Plan is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-225.md)
- [AKS cluster not encrypting temp disks, caches, and data flows misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-227.md)
- [Azure Event Hub Namespace is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-228.md)
- [Azure SQL Database Namespace is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-229.md)
- [Standard Replication is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-230.md)
- [App Service Environment is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-231.md)
- [Azure Container Registry (ACR) not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-233.md)
- [GCP SQL database instance does not have backup configuration enabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-14.md)
- [GCP cloud storage bucket with uniform bucket-level access disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-29.md)
- [GCP VM disks not encrypted with Customer-Supplied Encryption Keys (CSEK) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-37.md)
- [Boot disks for instances do not use CSEKs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-38.md)
- [GCP KMS Symmetric key not rotating in every 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-43.md)
- [GCP MySQL instance with local\_infile database flag is not disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-50.md)
- [GCP SQL Server instance database flag 'cross db ownership chaining' is enabled misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-58.md)
- [GCP SQL Server instance database flag 'contained database authentication' is enabled misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-59.md)
- [GCP Storage Bucket does not have Access and Storage Logging enabled misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-62.md)
- [GCP storage bucket is logging to itself misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-63.md)
- [GCP Cloud storage does not have versioning enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-78.md)
- [GCP Big Query Tables are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-80.md)
- [GCP Big Query Datasets are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-81.md)
- [GCP KMS keys are not protected from deletion misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-82.md)
- [GCP Pub/Sub Topics are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-83.md)
- [GCP Artifact Registry repositories are not encrypted with Customer Supplied Encryption Keys (CSEK) m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-84.md)
- [GCP Big Table Instances are not encrypted with Customer Supplied Encryption Keys (CSEKs) misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-85.md)
- [GCP data flow jobs are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-90.md)
- [GCP Dataproc Cluster not configured with Customer-Managed Encryption Key (CMEK) misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-91.md)
- [GCP Spanner Database is not encrypted with Customer Supplied Encryption Keys (CSEKs) misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-93.md)
- [GCP Memorystore for Redis does not use intransit encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-97.md)
- [Deletion protection for Spanner Database is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-119.md)
- [Spanner Database does not have drop protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-120.md)
- [BigQuery tables do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-121.md)
- [Big Table Instances do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-122.md)
- [GitHub Actions Environment Secrets defined in Terraform are not encrypted misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-git-4.md)
- [Gitlab project defined in Terraform does not prevent secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-glb-3.md)
- [The --etcd-certfile and --etcd-keyfile arguments are not set appropriately misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-99.md)
- [Encryption providers are not appropriately configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-104.md)
- [The --cert-file and --key-file arguments are not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-116.md)
- [The --peer-cert-file and --peer-key-file arguments are not set appropriately misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-119.md)
- [OCI Block Storage Block Volume does not have backup enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-2.md)
- [OCI Block Storage Block Volumes are not encrypted with a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-3.md)
- [OCI Object Storage bucket does not emit object events misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-7.md)
- [OCI Object Storage Bucket has object Versioning disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-8.md)
- [OCI Object Storage Bucket is not encrypted with a Customer Managed Key (CMK) misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-9.md)
- [OCI Object Storage bucket is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-10.md)
- [OCI File Storage File Systems are not encrypted with a Customer Managed Key (CMK) misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-15.md)
- [Not only encrypted EBS volumes are attached to EC2 instances misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-2.md)
- [RDS clusters do not have an AWS Backup backup plan misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-8.md)
- [EBS does not have an AWS Backup backup plan misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-9.md)
- [AWS DynamoDB table Auto Scaling not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-16.md)
- [Amazon EFS does not have an AWS Backup backup plan misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-18.md)
- [AWS SSM Parameter is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-34.md)
- [AWS ElastiCache Redis cluster with Multi-AZ Automatic Failover feature set to disabled misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-50.md)
- [AWS EMR cluster is not configured with security configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-55.md)
- [AWS Secret Manager Automatic Key Rotation is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-57.md)
- [AWS Neptune cluster deletion protection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-58.md)
- [AWS S3 bucket access control lists (ACLs) in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-65.md)
- [AWS RDS database instance not configured with encryption in transit misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-69.md)
- [AWS SQS queue encryption using default KMS key instead of CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-73.md)
- [Storage for critical data are not encrypted with Customer Managed Key misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-1.md)
- [Azure Data Explorer encryption at rest does not use a customer-managed key misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-11.md)
- [Virtual Machines are not backed up using Azure Backup misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-12.md)
- [Unattached disks are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-14.md)
- [Azure data factories are not encrypted with a customer-managed key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-15.md)
- [MySQL server does not enable customer-managed key for encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-16.md)
- [PostgreSQL server does not enable customer-managed key for encryption misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-17.md)
- [Azure Storage account Encryption CMKs Disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-18.md)
- [Azure SQL database Transparent Data Encryption (TDE) encryption disabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-25.md)
- [Azure MariaDB database server not using latest TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-37.md)
- [Azure Storage account soft delete is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-38.md)
- [GCP SQL MySQL DB instance point-in-time recovery backup (Binary logs) is not enabled misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-20.md)
- [Vertex AI instance disks not encrypted with a Customer Managed Key (CMK) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-21.md)
- [Document AI Processors not encrypted with a Customer Managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-22.md)
- [Document AI Warehouse Location is not configured to use a Customer Managed Key (CMK) misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-23.md)
- [Vertex AI workbench instance disks not encrypted with a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-27.md)
- [OCI File Storage File System access is not restricted to root users misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-oci-4.md)
- [OCI Kubernetes Engine Cluster boot volume is not configured with in-transit data encryption misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-oci-5.md)
- [CI/CD Security](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security.md)
- [Artifact Integrity Validation](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation.md)
- [Missing integrity check for downloaded executable in pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-106.md)
- [Missing integrity check for downloaded executable in CircleCI pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-107.md)
- [Missing integrity check for downloaded executable in GitHub Actions pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-108.md)
- [Auto-merge configured in pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-118.md)
- [Missing integrity check for downloaded executable in GitLab CI pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-123.md)
- [Unpinned GitHub actions](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-125.md)
- [Missing integrity check for downloaded executable in Azure Pipelines pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-189.md)
- [Pipeline uses an unpinned container image](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-253.md)
- [CircleCI pipeline uses an unpinned container image](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-cicd-254.md)
- [Artifact signing operation failure detected in pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-1.md)
- [Signed image without a prior build scan found](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-2.md)
- [Image signature verification failed due to untrusted public key in pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-3.md)
- [Image signature verification failed due to invalid signature in pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-4.md)
- [Unsigned artifact push to registry detected in pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-5.md)
- [Invalid artifact signature detected in registry](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-6.md)
- [Unsigned image detected in registry](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-7.md)
- [Image signed by an untrusted public key found](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-8.md)
- [Image signed by a recently removed trusted public key found](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-9.md)
- [Expired signing key found](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-10.md)
- [Key has not been rotated within the required period](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/artifact-integrity-validation/appsec-attest-11.md)
- [Credential Hygiene](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene.md)
- [Jenkins credentials stored with global scope](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-38.md)
- [Variable is not scoped to an environment](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-74.md)
- [Accesses to cloud providers using insecure long-term credentials](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-75.md)
- [GitLab CI/CD accesses cloud provider using insecure long-term credentials](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-78.md)
- [Secrets detected in pipeline's console output](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-84.md)
- [Secrets found in console output of a CircleCI pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-85.md)
- [CircleCI accesses cloud provider using insecure long-term credentials](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-87.md)
- [Jenkins environment variables exposed when printed to log](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-132.md)
- [Secrets found in console output of a GitHub Actions pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-133.md)
- [Environment variables exposed when printed to log](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-134.md)
- [CircleCI environment variables exposed when printed to log](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-135.md)
- [GitLab CI environment variables exposed when printed to log](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-136.md)
- [Secrets found in webhook URL](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-148.md)
- [Secrets found in GitLab webhook URL](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-149.md)
- [Secrets found in BitBucket webhook URL](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-150.md)
- [GitHub Organization secret not scoped](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-178.md)
- [Insecure definition of secret variable in pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-192.md)
- [Environment variables exposed when printed to log in Azure Pipelines](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-193.md)
- [Secrets found in console output of an Azure pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-242.md)
- [Unrotated GitHub Organization secrets](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-247.md)
- [Unrotated repository secrets](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-248.md)
- [Secrets found in logs of a GitLab CI pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-256.md)
- [Pipeline uploads the GITHUB\_TOKEN in an artifact](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-340.md)
- [Data Protection](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection.md)
- [Webhooks sent over unencrypted channel detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-12.md)
- [GitLab Webhooks sent over unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-13.md)
- [BitBucket webhooks sent over unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-14.md)
- [Forking of a private repository is allowed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-19.md)
- [Forking of BitBucket private repository is allowed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-20.md)
- [Organization webhook SSL verification is disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-30.md)
- [Force push to default branch is allowed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-31.md)
- [BitBucket repository webhook SSL verification is disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-37.md)
- [Repository webhook SSL verification is disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-39.md)
- [Organization members can create public repositories](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-44.md)
- [Project webhook SSL verification disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-72.md)
- [Force push to default branch is allowed in GitLab](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-82.md)
- [Private repository made public](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-88.md)
- [Certificate not verified by pipeline command](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-92.md)
- [Pipeline commands transmit data over an unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-93.md)
- [Certificate not verified by GitHub Actions pipeline command](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-109.md)
- [Certificate not verified by CircleCI pipeline command](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-110.md)
- [GitHub Actions pipeline commands transmit data over an unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-111.md)
- [CircleCI pipeline commands transmit data over an unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-112.md)
- [Certificate not verified by GitLab CI pipeline command](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-121.md)
- [GitLab CI pipeline commands transmit data over an unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-122.md)
- [Forking of private repositories in the organization is allowed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-153.md)
- [Forking of a private GitHub repository is allowed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-154.md)
- [Private repository forks can lead to code leakage](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-157.md)
- [Project service hook SSL verification is disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-182.md)
- [Project service hook sent over unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-183.md)
- [Forking of a private Azure repository is allowed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-191.md)
- [Certificate not verified by Azure Pipelines pipeline command](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-194.md)
- [Azure Pipelines commands transmit data over an unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-195.md)
- [Public repository created](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-239.md)
- [BitBucket private repository made public](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/data-protection/appsec-cicd-245.md)
- [Dependency Chains](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains.md)
- [Packages insecurely installed through “npm install” command in GitHub Actions pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-137.md)
- [Packages insecurely installed through “npm install” command in GitLab CI pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-139.md)
- [Packages insecurely installed through "npm install" command](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-140.md)
- [Packages insecurely installed through “npm install” command in Circle CI pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-141.md)
- [Repository missing NPM lock file package-lock.json](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-158.md)
- [Unencrypted channel used to download dependencies from NPM registry](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-159.md)
- [Internal NPM package is not scoped](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-160.md)
- [Secrets found in NPM dependency download URL](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-161.md)
- [GitLab repository missing NPM lock file](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-162.md)
- [Unencrypted channel used in GitLab repository to download dependencies from NPM registry](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-163.md)
- [Internal NPM package is not scoped in GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-164.md)
- [Secrets found in NPM dependency download URL in GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-165.md)
- [BitBucket repository missing NPM lock file](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-166.md)
- [Unencrypted channel used in BitBucket repository to download dependencies from NPM registry](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-167.md)
- [Internal NPM package is not scoped in BitBucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-168.md)
- [Secrets found in NPM dependency download URL in BitBucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-169.md)
- [Azure repository missing NPM lock file](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-170.md)
- [Unencrypted channel used in Azure repository to download dependencies from NPM registry](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-171.md)
- [Internal NPM package is not scoped in Azure repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-172.md)
- [Secrets found in NPM dependency download URL in Azure repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-173.md)
- [NPM package lock file verifies integrity with weak hash algorithm](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-174.md)
- [NPM package lock file verifies integrity with weak hash algorithm (Gitlab)](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-175.md)
- [NPM package lock file verifies integrity with weak hash algorithm (BitBucket)](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-176.md)
- [NPM package lock file verifies in Azure repository integrity with weak hash algorithm](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-177.md)
- [Packages insecurely installed through “npm install” command in Azure Pipelines pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-190.md)
- [Possible Python typosquatting detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-200.md)
- [Possible Python typosquatting detected in a GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-201.md)
- [Possible Python typosquatting detected in a Bitbucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-202.md)
- [Possible Python typosquatting detected in an Azure repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-203.md)
- [Missing '.npmrc' file in repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-265.md)
- [Secret exposed in proxy URL within '.npmrc' file](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-266.md)
- [Secret exposed in registry URL within '.npmrc' file](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-267.md)
- [Deprecated package used in NPM project](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-268.md)
- [Potential dependency confusion due to package name or scope available in registry](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-269.md)
- [Unencrypted channel used by '.npmrc' file to download dependencies from proxy](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-270.md)
- [Unencrypted channel used by '.npmrc' file of a GitHub repository to download dependencies from regis](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-271.md)
- [Missing '.npmrc' file in GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-272.md)
- [Secret exposed in proxy URL within '.npmrc' file of a Gitlab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-273.md)
- [Secret exposed in registry URL within '.npmrc' file of a GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-274.md)
- [Deprecated package used in NPM project of a GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-275.md)
- [Potential dependency confusion in a GitLab repository due to package name or scope available in regi](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-276.md)
- [Unencrypted channel used by '.npmrc' file of a GitLab repository to download dependencies from proxy](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-277.md)
- [Unencrypted channel used by '.npmrc' file of a GitLab repository to download dependencies from regis](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-278.md)
- [Missing '.npmrc' file in Bitbucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-279.md)
- [Secret exposed in proxy URL within '.npmrc' file of a Bitbucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-280.md)
- [Secret exposed in registry URL within '.npmrc' file of a Bitbucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-281.md)
- [Deprecated package used in NPM project of a Bitbucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-282.md)
- [Potential dependency confusion in a Bitbucket repository due to package name or scope available in r](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-283.md)
- [Unencrypted channel used by '.npmrc' file of a Bitbucket repository to download dependencies from pr](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-284.md)
- [Unencrypted channel used by '.npmrc' file of a bitbucket repository to download dependencies from re](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-285.md)
- [Missing '.npmrc' file in Azure repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-286.md)
- [Secret exposed in proxy URL within '.npmrc' file of an Azure repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-287.md)
- [Secret exposed in registry URL within '.npmrc' file of an Azure repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-288.md)
- [Deprecated package used in NPM project of an Azure repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-289.md)
- [Potential dependency confusion in an Azure repository due to package name or scope available in regi](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-290.md)
- [Unencrypted channel used by '.npmrc' file of an Azure repository to download dependencies from proxy](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-291.md)
- [Unencrypted channel used by '.npmrc' file of an Azure repository to download dependencies from regis](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-292.md)
- [NPM project contains unused dependencies](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-301.md)
- [NPM project contains unused dependencies in a GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-302.md)
- [NPM project contains unused dependencies in a Bitbucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-303.md)
- [NPM project contains unused dependencies in an Azure Repos repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-304.md)
- [NPM package downloaded from git without commit hash reference](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-313.md)
- [NPM package downloaded from git without commit hash reference in a GitLab repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-314.md)
- [NPM package downloaded from git without commit hash reference in a Bitbucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-315.md)
- [NPM package downloaded from git without commit hash reference in an Azure Repos repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/dependency-chains/appsec-cicd-316.md)
- [Flow Control Mechanism](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism.md)
- [Actively used repository lacks branch protection rules](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-2.md)
- [Actively used GitLab repository lacks branch protection rules](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-3.md)
- [Actively used BitBucket repository lacks branch protection rules](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-4.md)
- [Branch protection not enforced on administrators](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-33.md)
- [Pull request reviews not required before merging to the default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-34.md)
- [Required reviews can be bypassed using GitHub Actions](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-53.md)
- [Pull request reviews in BitBucket not required before merging code to default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-68.md)
- [Push restrictions not enforced on the default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-69.md)
- [Merge request approvals not required for default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-79.md)
- [GitLab branch protection rule allows push to default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-83.md)
- ["Require review from Code Owners" Branch Protection rule was disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-116.md)
- [Reviews may no longer be required before merging](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-142.md)
- [Repository does not dismiss pull request approvals on the default branch when new commits are pushed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-152.md)
- [Pull request reviews are not required in Azure Repos before merging to the default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-179.md)
- [Requestors allowed to self-approve pull requests on default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-180.md)
- [Code owners reviews not required before merging to the default branch](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-187.md)
- [Merging to default branch with outdated code allowed](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-197.md)
- [Azure repository does not dismiss pull request approvals on the default branch when new commits are](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/flow-control-mechanism/appsec-cicd-262.md)
- [Identity Access Management](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management.md)
- [2FA is not enforced in SCM](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-1.md)
- [Unrotated deploy keys](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-6.md)
- [Unrotated GitLab deploy keys](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-7.md)
- [Unrotated access keys detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-8.md)
- [Inactive SCM user accounts](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-16.md)
- [Jenkins provides full access to anonymous visitors](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-17.md)
- [Jenkins provides full access to authenticated user accounts](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-18.md)
- [User account is missing 2FA](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-22.md)
- [Permissive organization base permissions](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-29.md)
- [Outside collaborators have admin access to a repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-35.md)
- [Deploy key has a weak SSH signature](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-36.md)
- [Weak authentication service in use](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-49.md)
- [Jenkins provides read access to anonymous visitors](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-50.md)
- [No authentication is configured](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-51.md)
- [Access key with a weak SSH signature was detected in SCM](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-70.md)
- [Excessive user permissions to a repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-89.md)
- [Excessive user permissions to a project](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-95.md)
- [Excessive user permissions to a BitBucket repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-96.md)
- [User account credentials (access token and/or SSH Keys) are inactive in GitHub](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-105.md)
- [Any organization member can create internal repositories](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-184.md)
- [Any organization member can create private repositories](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-185.md)
- [Default branch does not require signed commits](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/identity-access-management/appsec-cicd-206.md)
- [Input Validation](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/input-validation.md)
- [Pipeline vulnerable to command injection](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/input-validation/appsec-cicd-138.md)
- [Possible command injection detected in user event](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/input-validation/appsec-cicd-146.md)
- [Workflow allows command execution through the standard output stream](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/input-validation/appsec-cicd-186.md)
- [CirceCI pipeline vulnerable to command injection](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/input-validation/appsec-cicd-207.md)
- [Logging And Visibility](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/logging-and-visibility.md)
- [Audit log not installed on Jenkins](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/logging-and-visibility/appsec-cicd-9.md)
- [Pipeline Based Access Controls](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls.md)
- [Deploy keys assigned with write permissions](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-26.md)
- [GitLab deploy keys assigned with write permissions](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-27.md)
- [All instance jobs run with high privileges](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-46.md)
- [Jobs are allowed to run on the Jenkins Controller](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-52.md)
- [Jenkins jobs are executed with high privileges by default](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-54.md)
- [Jenkins jobs can be executed with high privileges](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-55.md)
- [GitLab project job token authorized to access other projects](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-71.md)
- [Default workflow permissions in the repository set to 'read and write'](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-127.md)
- [Default workflow permissions in the organization set to 'read and write'](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-128.md)
- [Excessive pipeline permissions on the repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-156.md)
- [Project configured for group-wide access using job token](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-238.md)
- [Pipeline Configuration](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration.md)
- [An archived GitHub action is used](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-343.md)
- [A GitHub workflow is using action with CRITICAL severity CVE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-344.md)
- [A pipeline is using rejected Supply Chain Tool](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-345.md)
- [A pipeline is using an unapproved Supply Chain Tool](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-346.md)
- [Jenkins instance is using rejected plugin](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-347.md)
- [Jenkins instance is using an unapproved plugin](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-348.md)
- [A deprecated Jenkins plugin is used on a Jenkins Instance](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-349.md)
- [A Jenkins plugin with CRITICAL severity CVE is installed on a Jenkins Instance](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-350.md)
- [A pipeline is using a rejected tool within a Remote Script](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-351.md)
- [A pipeline is using an unapproved tool within a Remote Script](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-352.md)
- [A GitHub workflow is using action with HIGH severity CVE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-355.md)
- [A Jenkins plugin with HIGH severity CVE is installed on a Jenkins Instance](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-356.md)
- [Unverified MCP Server Vendor is detected in an SCM Repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-357.md)
- [Non-Containerized MCP Server is detected in an SCM Repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-358.md)
- [Unmaintained MCP Server is detected in an SCM Repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-359.md)
- [Archived or Deprecated MCP Server in use, detected in SCM repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-360.md)
- [MCP Server with Dangerous Capability Request is detected in SCM Repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-361.md)
- [A Rejected MCP Server is in-use (recognized in SCM Repository config file)](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-362.md)
- [An Unapproved MCP Server is in-use (recognized in SCM Repository config file)](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-363.md)
- [Unverified MCP Server Vendor is detected in a Pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-364.md)
- [Non-Containerized MCP Server is detected in a Pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-365.md)
- [Unmaintained MCP Server is detected in a Pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-366.md)
- [Archived or Deprecated MCP Server is detected in a Pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-367.md)
- [MCP Server with Dangerous Capability Request is detected in a Pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-368.md)
- [Rejected MCP Server in Use in the Pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-369.md)
- [Unapproved MCP Server in Use in the Pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-370.md)
- [Unverified MCP Server Vendor is detected in IDE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-371.md)
- [Non-Containerized MCP Server is detected in IDE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-372.md)
- [Unmaintained MCP Server is detected in IDE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-373.md)
- [Archived or Deprecated MCP Server in Use is detected in IDE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-374.md)
- [MCP Server with Dangerous Capability Request is detected in IDE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-375.md)
- [Contributor is using Rejected MCP Server in their IDE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-376.md)
- [Contributor is using an Unapproved MCP Server in their IDE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-configuration/appsec-cicd-377.md)
- [PPE](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/ppe.md)
- [Direct Poisoned Pipeline Execution](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/ppe/appsec-cicd-40.md)
- [Direct Poisoned Pipeline Execution by outside collaborators](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/ppe/appsec-cicd-144.md)
- [SCM System Configuration](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/scm-system-configuration.md)
- [GitHub is using rejected Application](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/scm-system-configuration/appsec-cicd-341.md)
- [GitHub is using an unapproved Application](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/scm-system-configuration/appsec-cicd-342.md)
- [SCM is using a rejected Webhook](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/scm-system-configuration/appsec-cicd-353.md)
- [SCM is using an unapproved Webhook](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/scm-system-configuration/appsec-cicd-354.md)
- [System Configurations](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations.md)
- [Vulnerable Jenkins plugins](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-10.md)
- [Vulnerable Jenkins version in use](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-11.md)
- [Throttling is not enabled in SCM](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-15.md)
- [Access to resources on the GitLab server from GitLab services is not restricted](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-25.md)
- [LDAP is configured to use an unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-47.md)
- [Jenkins instance traffic sent over an unencrypted channel](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-48.md)
- [GitHub Actions is enabled and not used in a repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-60.md)
- [Self-hosted runner group allows public repositories](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-181.md)
- [Organization's identity not confirmed with a verified badge](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-188.md)
- [Push restrictions are not enforced on the default branch in GitHub](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/system-configurations/appsec-cicd-208.md)
- [Third Party Services](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/third-party-services.md)
- [Excessive GitHub App permissions](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/third-party-services/appsec-cicd-97.md)
- [Unrestricted usage of GitHub Actions allowed in the repository](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/third-party-services/appsec-cicd-129.md)
- [Unrestricted usage of GitHub Actions allowed across the organization](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/third-party-services/appsec-cicd-130.md)
- [Mutable orb used in the pipeline](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/third-party-services/appsec-cicd-196.md)
- [Secrets Security](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security.md)
- [GitHub repository defined in Terraform is not Private](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-git-1.md)
- [Artifactory Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-1.md)
- [AWS Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-2.md)
- [Azure Storage Account Access Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-3.md)
- [Basic Auth Credential detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-4.md)
- [Cloudant Credential detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-5.md)
- [Base64 High Entropy String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-6.md)
- [IBM Cloud IAM Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-7.md)
- [IBM COS HMAC credential detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-8.md)
- [JSON Web Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-9.md)
- [Mailchimp Access Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-11.md)
- [NPM Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-12.md)
- [Private Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-13.md)
- [Slack Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-14.md)
- [SoftLayer Credential detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-15.md)
- [Square OAuth Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-16.md)
- [Stripe Access Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-17.md)
- [Twilio Access Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-18.md)
- [Hex High Entropy String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-19.md)
- [Airtable API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-21.md)
- [Algolia Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-22.md)
- [Alibaba Cloud Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-23.md)
- [Asana Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-24.md)
- [Atlassian Oauth2 Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-25.md)
- [Auth0 Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-26.md)
- [Bitbucket Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-27.md)
- [Buildkite Agent Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-28.md)
- [CircleCI Personal Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-29.md)
- [Codecov API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-30.md)
- [Coinbase Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-31.md)
- [Confluent Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-32.md)
- [Databricks Authentication Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-33.md)
- [DigitalOcean Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-34.md)
- [Discord Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-35.md)
- [Doppler API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-36.md)
- [DroneCI Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-37.md)
- [Dropbox App Credential detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-38.md)
- [Dynatrace token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-39.md)
- [Elastic Email Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-40.md)
- [Fastly Personal Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-41.md)
- [FullStory API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-42.md)
- [GitHub Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-43.md)
- [GitLab Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-44.md)
- [Google API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-45.md)
- [Grafana Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-46.md)
- [Terraform Cloud API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-47.md)
- [Heroku Platform Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-48.md)
- [HubSpot API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-49.md)
- [Intercom Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-50.md)
- [Jira Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-51.md)
- [LaunchDarkly Personal Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-52.md)
- [Netlify Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-53.md)
- [New Relic Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-54.md)
- [Notion Integration Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-55.md)
- [Okta Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-56.md)
- [PagerDuty Authorization Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-57.md)
- [PlanetScale Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-58.md)
- [Postman API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-59.md)
- [Pulumi Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-60.md)
- [Python Package Index Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-61.md)
- [RapidAPI Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-62.md)
- [Readme API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-63.md)
- [RubyGems API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-64.md)
- [Sentry Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-65.md)
- [Splunk User Credential detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-66.md)
- [Sumo Logic Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-67.md)
- [Telegram Bot Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-68.md)
- [Travis Personal Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-69.md)
- [Typeform API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-70.md)
- [Vault Unseal Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-71.md)
- [Yandex Predictor API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-72.md)
- [Cloudflare API Credential detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-73.md)
- [Vercel API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-74.md)
- [Webflow API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-75.md)
- [Scalr API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-76.md)
- [MongoDB Connection String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-77.md)
- [Braintree Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-78.md)
- [GCP Service Account Auth Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-79.md)
- [Random High Entropy String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-80.md)
- [Braintree Payments Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-81.md)
- [AWS MWS Auth Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-82.md)
- [PayPal Token ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-83.md)
- [PayPal Token Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-84.md)
- [Braintree Payments Id detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-85.md)
- [SonarQube Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-86.md)
- [SendGrid Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-87.md)
- [Firebase Cloud Messaging API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-88.md)
- [Docker Swarm Join Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-89.md)
- [Shopify Generic App Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-90.md)
- [Mapbox Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-91.md)
- [PubNub Subscription Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-92.md)
- [PubNub Publish Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-93.md)
- [Mailgun Primary Account API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-94.md)
- [SendinBlue Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-95.md)
- [Crates API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-96.md)
- [Shopify Private App Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-97.md)
- [Flutterwave API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-98.md)
- [NuGet API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-99.md)
- [Checkout.com API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-100.md)
- [Square Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-101.md)
- [Square Access Token V2 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-102.md)
- [Typeform Personal Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-103.md)
- [Mailgun Domain Sending Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-104.md)
- [Frame IO Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-105.md)
- [Clojars Deploy Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-106.md)
- [OpenAI API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-107.md)
- [Samsara API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-108.md)
- [Anthropic API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-109.md)
- [Hugging Face token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-110.md)
- [Microsoft Teams webhook detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-111.md)
- [Azure Functions HTTP Trigger Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-112.md)
- [MonkeyLearn API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-113.md)
- [Clarifai API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-114.md)
- [Azure Machine Learning web service API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-115.md)
- [MongoDB Atlas Keys Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-116.md)
- [MongoDB Atlas Keys ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-117.md)
- [Customer.io Track Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-118.md)
- [Databricks Authentication Token With Hostname detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-119.md)
- [GitGuardian Public Monitoring API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-121.md)
- [Mandrill API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-122.md)
- [Elastic Cloud Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-123.md)
- [OpenWeatherMap Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-124.md)
- [Mailjet Keys ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-125.md)
- [Mailjet Keys Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-126.md)
- [Pusher Channels Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-127.md)
- [Pusher Channels Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-128.md)
- [LinkedIn OAuth2 Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-129.md)
- [LinkedIn OAuth2 Secrets detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-130.md)
- [WeChat App User ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-131.md)
- [WeChat App Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-132.md)
- [Webex App Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-133.md)
- [Webex App Secrets detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-134.md)
- [Lacework API Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-135.md)
- [Lacework API Secrets detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-136.md)
- [Zendesk Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-137.md)
- [Zoom API JWT Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-138.md)
- [Zoom API JWT Secrets detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-139.md)
- [Zoom API Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-141.md)
- [Zoom API Secrets detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-142.md)
- [Contentful Content Delivery API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-143.md)
- [MariaDB Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-144.md)
- [AWS SES client secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-145.md)
- [reCAPTCHA key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-146.md)
- [Adobe API ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-147.md)
- [Adobe API Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-148.md)
- [DB2 Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-149.md)
- [Pingdom Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-150.md)
- [Redis Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-151.md)
- [Coveralls Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-152.md)
- [Azure Active Directory Client Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-153.md)
- [DataDog Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-154.md)
- [GitHub OAuth App Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-155.md)
- [GitHub OAuth App Client ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-156.md)
- [LDAP Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-157.md)
- [MySQL User Name detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-158.md)
- [MySQL Password detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-159.md)
- [FTP User Name detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-162.md)
- [FTP Password detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-163.md)
- [AMQP User Name detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-164.md)
- [AMQP Password detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-165.md)
- [Stripe Webhook Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-166.md)
- [Rails Secret Key Base detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-167.md)
- [Salesforce Refresh Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-168.md)
- [Azure Service Management Certificate detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-169.md)
- [Codeclimate key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-170.md)
- [Docker Swarm Unlock Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-171.md)
- [Facebook Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-172.md)
- [Putty Private Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-173.md)
- [Tableau Personal Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-174.md)
- [Zillow Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-175.md)
- [Line Messaging OAuth2 Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-176.md)
- [Google Bard API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-177.md)
- [Azure Subscription Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-178.md)
- [Authentication Tuple detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-179.md)
- [Okta Keys Client Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-180.md)
- [Generic Terraform Variable Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-181.md)
- [SMTP credentials Password detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-182.md)
- [SMTP credentials - Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-183.md)
- [Yahoo OAuth2 Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-184.md)
- [Eventbrite OAuth2 Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-185.md)
- [Octopus Deploy API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-191.md)
- [Bearer token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-192.md)
- [Django secret key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-194.md)
- [Salesforce OAuth2 ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-195.md)
- [Salesforce OAuth2 secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-196.md)
- [Azure DevOps personal access token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-197.md)
- [Splunk authentication token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-198.md)
- [HashiCorp Vault token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-199.md)
- [Kubernetes cluster credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-200.md)
- [Jira basic authentication credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-201.md)
- [Neo4j credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-202.md)
- [Keycloak API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-203.md)
- [Oracle credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-204.md)
- [Thycotic Secret Server credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-205.md)
- [Gemfury access token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-206.md)
- [Zoho OAuth2 keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-207.md)
- [Zoom SDK keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-208.md)
- [Cloudera model key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-209.md)
- [Akamai API client secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-210.md)
- [Generic database assignment detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-211.md)
- [Generic CLI key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-212.md)
- [Akamai API client token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-213.md)
- [ODBC connection string detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-214.md)
- [Sauce Labs keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-215.md)
- [OVH keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-216.md)
- [PingIdentity keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-217.md)
- [Slack Application secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-218.md)
- [Slack Application ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-219.md)
- [Grafana service account token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-220.md)
- [Redis server password detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-221.md)
- [Slack signing secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-222.md)
- [SSH Password detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-223.md)
- [Encrypted Private Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-224.md)
- [Duo key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-225.md)
- [Slack bot token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-226.md)
- [Slack application credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-227.md)
- [Base64 AWS SES keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-228.md)
- [Base64 AWS IAM Secret Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-229.md)
- [Slack app token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-230.md)
- [Razorpay API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-231.md)
- [PGP Private Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-232.md)
- [Twitter access keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-233.md)
- [Base64 basic authentication detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-234.md)
- [GitHub App Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-235.md)
- [Snowflake credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-236.md)
- [Azure OpenAI API endpoint detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-237.md)
- [Azure OpenAI API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-238.md)
- [Fernet key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-239.md)
- [New Relic APM license key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-240.md)
- [NX Cloud token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-241.md)
- [Plaid access token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-242.md)
- [Redshift credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-243.md)
- [Replicate user access token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-244.md)
- [Solr credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-245.md)
- [Discord OAuth2 secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-246.md)
- [Kubernetes Docker secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-247.md)
- [Sourcegraph access token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-248.md)
- [Workato API key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-249.md)
- [Google OAuth2 secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-250.md)
- [DigitalOcean Spaces secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-251.md)
- [DigitalOcean Spaces connection string detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-252.md)
- [LaunchDarkly SDK key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-253.md)
- [Zapier webhook url detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-254.md)
- [GitLab enterprise server key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-255.md)
- [Rails Master Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-256.md)
- [PubNub Secret Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-257.md)
- [Shopify Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-258.md)
- [New Relic Agent Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-259.md)
- [New Relic API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-260.md)
- [HashiCorp Vault Unseal Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-261.md)
- [Slack Webhook URL detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-262.md)
- [Samsara API token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-263.md)
- [Dropbox Key token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-264.md)
- [Figma Personal Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-265.md)
- [Azure Functions App Key Header detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-266.md)
- [Azure Functions App Key Query Parameter detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-267.md)
- [Jenkins API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-268.md)
- [Nessus Agent Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-269.md)
- [VISA Basic Authentication Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-270.md)
- [OpenAI Project API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-271.md)
- [Midtrans API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-272.md)
- [Base64 Midtrans API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-273.md)
- [Atlassian Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-274.md)
- [New Relic Insights Query Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-275.md)
- [ASPNet Validation Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-276.md)
- [ASPNet Decryption Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-277.md)
- [InfluxDB Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-278.md)
- [New Relic Insights Insert Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-279.md)
- [Prefixed New Relic Insights Insert Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-280.md)
- [MSSQL Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-281.md)
- [MSSQL Connection String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-282.md)
- [Cloudinary API Key URL detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-283.md)
- [Cloudinary API Key Config detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-284.md)
- [Google OAuth2 token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-285.md)
- [Freshdesk API Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-286.md)
- [Grafana Cloud API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-287.md)
- [Base64 AWS IAM Access Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-288.md)
- [Aiven API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-289.md)
- [Anthropic Admin Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-290.md)
- [CircleCI Project Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-291.md)
- [Tencent Cloud Secret ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-292.md)
- [Azure API Management Repository Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-293.md)
- [Azure API Management Subscription Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-294.md)
- [Azure App Configuration Connection String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-295.md)
- [Azure Communication Services Connection String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-296.md)
- [Azure Batch Key Identifiable detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-297.md)
- [Azure Cosmosdb Key Identifiable detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-298.md)
- [Azure SignalR Connection String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-299.md)
- [Azure Entra ID Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-300.md)
- [Azure Search Admin Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-301.md)
- [EasyPost API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-303.md)
- [MongoDB credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-304.md)
- [Trendmicro Cloudone Apikey v2 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-305.md)
- [Slack Configuration Refresh Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-306.md)
- [DigitalOcean OAuth Application Token v1 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-307.md)
- [DigitalOcean Personal Access Token v1 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-308.md)
- [DigitalOcean Refresh Token v1 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-309.md)
- [FTP Credentials Assignment detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-310.md)
- [Amqp Assignment detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-311.md)
- [Sourcegraph Access Token v1 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-312.md)
- [Sourcegraph Access Token v3 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-313.md)
- [Dropbox Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-314.md)
- [PostgreSQL Connection String detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-315.md)
- [Slack Workflow Webhook URL detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-316.md)
- [Google OAuth2 ID detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-317.md)
- [HashiCorp Vault Batch Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-318.md)
- [HashiCorp Vault Recovery token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-319.md)
- [Groq API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-320.md)
- [Artifactory Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-321.md)
- [Google OAuth Refresh token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-322.md)
- [GitLab Deploy Token was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-323.md)
- [GitLab Runner Authentication Token was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-324.md)
- [GitGuardian Internal Monitoring Key was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-325.md)
- [Shippo API token was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-326.md)
- [Infracost API Key was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-327.md)
- [Vapi API Key was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-328.md)
- [Brave Search API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-329.md)
- [Dify API Key was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-330.md)
- [Linear Personal API key was detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-331.md)
- [Trendmicro Cloudone Apikey v1 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-332.md)
- [Airtable API Key v1 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-333.md)
- [Gitlab Personal Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-334.md)
- [Artifactory Reference Token With Host detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-336.md)
- [New Relic API Service Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-337.md)
- [Artifactory Basic Auth Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-338.md)
- [Datadog Secret detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-339.md)
- [Hashicorp Vault AppRole Authentication detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-340.md)
- [Snowflake Connector Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-341.md)
- [Artifactory Reference Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-342.md)
- [Azure Logic App Shared Access Signature detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-343.md)
- [Gitlab Trigger Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-344.md)
- [Laravel App Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-345.md)
- [Langfuse Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-346.md)
- [Alchemy API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-347.md)
- [Alchemy API Key V2 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-348.md)
- [Azure DevOps Personal Access Token with Organization detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-349.md)
- [Azure Event Grid Access Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-350.md)
- [ASP.NET Decryption Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-351.md)
- [Firecrawl API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-352.md)
- [GitLab Feature Flags Client Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-353.md)
- [IBM API Connect credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-354.md)
- [IBM COS HMAC credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-355.md)
- [Checkout.com Sandbox API Secret Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-356.md)
- [Contributed Systems Sidekiq API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-357.md)
- [Duffel API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-358.md)
- [Elliptic Curve Private Key Base64 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-359.md)
- [Elliptic Curve Private Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-360.md)
- [Okta OAuth 2.0 Client Credentials with Host detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-361.md)
- [Llama Cloud API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-362.md)
- [OpenAI Project API Key V2 detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-363.md)
- [OpenRouter API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-364.md)
- [PayPal OAuth2 Keys detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-365.md)
- [VirusTotal API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-366.md)
- [Ubidots API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-367.md)
- [Resend API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-368.md)
- [Cursor API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-369.md)
- [E2B API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-370.md)
- [GitLab Runner Registration Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-371.md)
- [PostHog Private API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-372.md)
- [PostHog Public API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-373.md)
- [Clerk Secret Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-374.md)
- [Mercado Pago Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-375.md)
- [Discord Webhook URL detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-376.md)
- [GitHub Fine-Grained Personal Access Token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-377.md)
- [Anthropic API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-378.md)
- [Oracle Credentials detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-379.md)
- [Azure SAS URL detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-382.md)
- [Coveo API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-383.md)
- [Elasticsearch API Key detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-384.md)
- [Zoho OAuth token detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-385.md)
- [SAST](https://cortex-docs.paloaltonetworks.com/appsec-rules/sast.md)
- [3rd party security weakness found in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/sast/appsec-sast-1.md)
- [Vulnerabilities](https://cortex-docs.paloaltonetworks.com/appsec-rules/vulnerabilities.md)
- [Vulnerability found in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/vulnerabilities/appsec-vul-1.md)
- [Vulnerability found in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/vulnerabilities/appsec-vul-2.md)
- [License Compliance](https://cortex-docs.paloaltonetworks.com/appsec-rules/license-compliance.md)
- [Weak copyleft license found in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/license-compliance/appsec-lic-3.md)
- [Strong copyleft license found in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/license-compliance/appsec-lic-4.md)
- [Non permissive license found in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/license-compliance/appsec-lic-5.md)
- [Malicious Packages](https://cortex-docs.paloaltonetworks.com/appsec-rules/malicious-packages.md)
- [Malicious open-source package detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/malicious-packages/appsec-mal-1.md)

## XSPM Rules



## Attack Path Rules



## Discovery Catalog

- [Cortex Cloud discovery catalog](https://cortex-docs.paloaltonetworks.com/discovery-catalog/cortex-cloud-discovery-catalog.md)
- [Alibaba Cloud Services](https://cortex-docs.paloaltonetworks.com/discovery-catalog/cortex-cloud-discovery-catalog/alibaba-cloud-services.md)
- [AWS Services](https://cortex-docs.paloaltonetworks.com/discovery-catalog/cortex-cloud-discovery-catalog/aws-services.md)
- [Azure Services](https://cortex-docs.paloaltonetworks.com/discovery-catalog/cortex-cloud-discovery-catalog/azure-services.md)
- [GCP Services](https://cortex-docs.paloaltonetworks.com/discovery-catalog/cortex-cloud-discovery-catalog/gcp-services.md)
- [OCI Services](https://cortex-docs.paloaltonetworks.com/discovery-catalog/cortex-cloud-discovery-catalog/oci-services.md)
- [Event-based Asset Ingestion (EAI) Resource Ingestion Templates (RITs)](https://cortex-docs.paloaltonetworks.com/discovery-catalog/cortex-cloud-discovery-catalog/event-based-asset-ingestion-eai-resource-ingestion-templates-rits.md)

## Compliance

- [Cortex Compliance](https://cortex-docs.paloaltonetworks.com/compliance/cortex-compliance.md): Access compliance dashboards, reports, certifications, and marketplace content packs.

## Gateway Guide

- [About the Cortex Gateway](https://cortex-docs.paloaltonetworks.com/gateway-guide/cortex-gateway.md)
- [Activate a tenant](https://cortex-docs.paloaltonetworks.com/gateway-guide/activate-a-tenant.md): Learn how to activate your Cortex tenant.
- [Activate Cortex XDR tenant](https://cortex-docs.paloaltonetworks.com/gateway-guide/activate-a-tenant/activate-cortex-xdr-tenant.md): Learn how to activate your Cortex XDR tenant.
- [Activate Cortex XSIAM tenant](https://cortex-docs.paloaltonetworks.com/gateway-guide/activate-a-tenant/activate-cortex-xsiam-tenant.md): Learn how to activate your Cortex XSIAM tenant.
- [Activate Cortex XSOAR tenant](https://cortex-docs.paloaltonetworks.com/gateway-guide/activate-a-tenant/activate-cortex-xsoar-tenant.md): Learn how to activate your Cortex XSOAR tenant.
- [Users and roles in Cortex](https://cortex-docs.paloaltonetworks.com/gateway-guide/users-and-roles-in-cortex.md): Set up and configure roles and user groups in the Cortex tenant and Cortex Gateway. Configure authentication and manage users.
- [User management](https://cortex-docs.paloaltonetworks.com/gateway-guide/user-management.md): Manage users in Cortex Gateway or the Cortex tenant.
- [Manage users in Cortex Gateway](https://cortex-docs.paloaltonetworks.com/gateway-guide/user-management/manage-users-in-cortex-gateway.md): Add user roles, disable users, hide users, and deactivate users in Cortex Gateway.
- [FedRAMP security configuration for top-level admin accounts](https://cortex-docs.paloaltonetworks.com/gateway-guide/fedramp-security-configuration-for-top-level-admin-accounts.md)
- [Roles management](https://cortex-docs.paloaltonetworks.com/gateway-guide/roles-management.md): Configure roles in the Cortex tenant or Cortex Gateway.
- [Next steps](https://cortex-docs.paloaltonetworks.com/gateway-guide/roles-management/next-steps.md): Configure roles in the Cortex tenant or Cortex Gateway.
- [Predefined roles in Cortex Gateway](https://cortex-docs.paloaltonetworks.com/gateway-guide/roles-management/predefined-roles-in-cortex-gateway.md): Review the predefined roles in the Cortex Gateway.
- [Manage roles in Cortex Gateway](https://cortex-docs.paloaltonetworks.com/gateway-guide/roles-management/manage-roles-in-cortex-gateway.md): View, create, edit, and delete roles in Cortex Gateway.
- [User group management](https://cortex-docs.paloaltonetworks.com/gateway-guide/user-group-management.md): Create user groups, and assign roles and users to further refine your requirements,
- [Egress configurations](https://cortex-docs.paloaltonetworks.com/gateway-guide/egress-configurations.md)

## Cortex Commands Guide

- [Cortex Commands Overview](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/cortex-commands-overview.md): Use Cortex commands to investigate, respond, and manage Cortex platform data.
- [Action Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/action-commands.md)
- [Analytics Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/analytics-commands.md)
- [API Keys Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/api-keys-commands.md)
- [AppSec Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/appsec-commands.md)
- [Asset Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/asset-commands.md)
- [Audit Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/audit-commands.md)
- [BIOC Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/bioc-commands.md)
- [Case Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/case-commands.md)
- [Correlation Rule Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/correlation-rule-commands.md)
- [Coverage Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/coverage-commands.md)
- [Distribution Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/distribution-commands.md)
- [Endpoint Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/endpoint-commands.md)
- [Exceptions Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/exceptions-commands.md)
- [Exclusions Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/exclusions-commands.md)
- [File Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/file-commands.md)
- [Groups Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/groups-commands.md)
- [Hash Exceptions Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/hash-exceptions-commands.md)
- [Indicators Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/indicators-commands.md)
- [Issues Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/issues-commands.md)
- [Playbooks Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/playbooks-commands.md)
- [RCS Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/rcs-commands.md)
- [Risk Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/risk-commands.md)
- [Scanner Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/scanner-commands.md)
- [Script Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/script-commands.md)
- [System Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/system-commands.md)
- [Timeline Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/timeline-commands.md)
- [Triage Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/triage-commands.md)
- [User Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/user-commands.md)
- [Vulnerability Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/vulnerability-commands.md)
- [War Room Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/war-room-commands.md)
- [XQL Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/xql-commands.md)
- [XQL Library Commands](https://cortex-docs.paloaltonetworks.com/cortex-commands-guide/xql-library-commands.md)

## MCP Integration Contributor Guide

- [Get started with MCP integration development](https://cortex-docs.paloaltonetworks.com/mcp-integration-contributor-guide/get-started-with-mcp-integration-development.md)
- [Required MCP commands](https://cortex-docs.paloaltonetworks.com/mcp-integration-contributor-guide/required-mcp-commands.md)
- [MCPApiModule](https://cortex-docs.paloaltonetworks.com/mcp-integration-contributor-guide/mcpapimodule.md)
- [Python implementation](https://cortex-docs.paloaltonetworks.com/mcp-integration-contributor-guide/python-implementation.md)
- [Authentication patterns](https://cortex-docs.paloaltonetworks.com/mcp-integration-contributor-guide/authentication-patterns.md)
- [Vendor-specific customizations](https://cortex-docs.paloaltonetworks.com/mcp-integration-contributor-guide/vendor-specific-customizations.md)
- [Test your integration](https://cortex-docs.paloaltonetworks.com/mcp-integration-contributor-guide/test-your-integration.md)

## Manual Cloud Onboarding



## ADS Support for LVM



## Outposts: Bring Your Own Network (BYON)



---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information, you can query the documentation dynamically by asking a question.
Perform an HTTP GET request on a page URL with the `ask` query parameter:
```
GET https://cortex-docs.paloaltonetworks.com/readme.md?ask=<question>
```
The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.
Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
