Investigate a host - Investigate host assets associated with your cases - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-04
Category
Administrator Guide
Abstract

Investigate host assets associated with your cases

Notice

The Host Risk View requires the Identity Threat Module add-on. Depending on your permissions, some information may be limited by your scope.

The Host Risk view provides a centralized and interactive overview of activities on the host and risk scores, enabling you to investigate host events across core data sources. It enables you to identify and prioritize high-risk endpoint, gives you immediate context for risks, helps prevent missed indicators of compromise, and accelerates triage by offering proactive mitigation strategies.

Customize the Host Risk view for your use case by dragging and dropping each widget to position it where you want in the layout. You can also collapse the widgets to hide or show content as needed.

Drilldown on a host on the Host Risk View. In this view you can see insights and profiling information about a host. When investigating issues and cases, you can view anomalies in the context of the host that can help you to make better and faster decisions about risks. In the Host Risk View you can take the following actions:

  • Assess the host's behavior and score.

  • Analyze the host's behavior over time, and compare it to peer hosts with the same asset role.

  • Review related cases and past issues for the host.

  • Star the host to be included in the watchlist.

How to investigate a host
  1. Right-click the host that you want to investigate and select Open Host Risk View.

    Tip

    You can also see a list of all hosts under InventoryAssetsAsset Scores.

  2. Select the timeframe to view the host details.

    Note

    Cortex XDR normalizes and displays case and issue times in your time zone. If you're in a half-hour time zone, the activity in the graphs is displayed in the whole-hour time slot preceding it. For example, if you're in a UTC +4.5 time zone, the time displayed for the activity will be UTC +4.5, however, the visualization will be in the UTC +4 slot.

  3. Investigate the host.

  4. (Optional) Take actions on the host.

    On the top right, click Actions to see a list of available actions. Actions are context specific.