Investigate host assets associated with your cases
Notice
The Host Risk View requires the Identity Threat Module add-on. Depending on your permissions, some information may be limited by your scope.
The Host Risk view provides a centralized and interactive overview of activities on the host and risk scores, enabling you to investigate host events across core data sources. It enables you to identify and prioritize high-risk endpoint, gives you immediate context for risks, helps prevent missed indicators of compromise, and accelerates triage by offering proactive mitigation strategies.
Customize the Host Risk view for your use case by dragging and dropping each widget to position it where you want in the layout. You can also collapse the widgets to hide or show content as needed.
Drilldown on a host on the Host Risk View. In this view you can see insights and profiling information about a host. When investigating issues and cases, you can view anomalies in the context of the host that can help you to make better and faster decisions about risks. In the Host Risk View you can take the following actions:
Assess the host's behavior and score.
Analyze the host's behavior over time, and compare it to peer hosts with the same asset role.
Review related cases and past issues for the host.
Star the host to be included in the watchlist.
Right-click the host that you want to investigate and select Open Host Risk View.
Tip
You can also see a list of all hosts under → → .
Select the timeframe to view the host details.
Note
Cortex XDR normalizes and displays case and issue times in your time zone. If you're in a half-hour time zone, the activity in the graphs is displayed in the whole-hour time slot preceding it. For example, if you're in a UTC +4.5 time zone, the time displayed for the activity will be UTC +4.5, however, the visualization will be in the UTC +4 slot.
Investigate the host.
(Optional) Take actions on the host.
On the top right, click Actions to see a list of available actions. Actions are context specific.