Manage effectiveness rules - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-04
Category
Administrator Guide

Effectiveness rules allow you to automate 80% of your control decisions, with senior analysts having the option to override automations on a case by case basis as needed. In order to implement them correctly, it is important to understand the underlying logic. The precedence hierarchy logic outlined below, uses clear, strict guidelines to perfectly balance automation and human expertise,

Table 7. Effectiveness value precedence

Precedence

Source

Logic

Highest

Manual Per Finding

A value set manually by an analyst on a specific finding will never be-overwritten by a rule.

Middle

Effectiveness Rule

Only applies if the current value is the default Unknown. It cannot override a Manually Defined value.

Lowest

Default Value

Unknown is applied if no manual setting or automated rule matches the finding.