How to perform advanced AI Security investigations using XQL - Working with datasets in Cortex Cloud AI Security. - Administrator Guide - Cortex CLOUD

Cortex Cloud Posture Management Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Posture Management
Creation date
2025-01-22
Last date published
2026-06-10
Category
Administrator Guide
Abstract

Working with datasets in Cortex Cloud AI Security.

Overview

Cortex Cloud AI Security centralizes information about your AI ecosystem into a list of datasets, providing the foundation for comprehensive security investigations. Using Cortex Query Language (XQL) , security practitioners can create custom queries to extract valuable insights from these data sources within their appliance. For more information, see Get started with XQL.

You can use the following AI-related datasets:

Dataset

Description

asset_inventory

Provides a normalized, structured inventory of all digital assets across your AI environment, including detailed metadata for each asset, such as type, cloud provider, region, and security configurations. The dataset also maps relationships between assets, enabling the identification of complex AI and cloud dependencies for a comprehensive AI security posture.

classification_mgmt_data_profile

Provides administrative insights into the data classification policies and profiles configured within the Cortex Cloud Data Classification service.This dataset is primarily used for monitoring and managing the data classification rules in the Cortex Cloud environment.

findings

Contains the findings that are associated with the assets that are found in your environments. For more information, see Findings and events.

issues

Consolidates all AI security vulnerabilities, misconfigurations, and threats detected by Cortex Cloud AI Security. Each entry includes detailed context, such as the affected asset ID, a risk score, a description of the issue, and suggested remediation steps. This dataset provides a unified, actionable view of all security risks for your organization.

Investigate Cortex Cloud AI Security

To run queries on your Cortex Cloud AI Security datasets:

  1. In Cortex Cloud, in the navigation pane on the left, click Investigation & Response, then under Search, click Query Builder.

  2. Click XQL.

  3. You can start typing your query in the box at the top of the screen, or search for existing queries on the Query Library tab.

  4. Click Run. The results of the query appear on the Query Results tab.

Note

For more information, see Build XQL queries.

Examples

Here are some examples of AI-related queries you can run in Cortex Cloud to investigate your AI Security posture: