Triage results - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2024-07-16
Last date published
2024-12-12
Category
Administrator Guide
Retire_Doc
Retiring
Link_to_new_Doc
/r/Cortex-XDR/Cortex-XDR-Documentation
Abstract

You can drill down from the triage collection to review the results.

The Triage collection results page displays an overview of the different types of triage collections that were initiated on an endpoint.

The triage results page is divided by the following tabs:

  • Alerts: Refer to Featured fields in Overview of the Alerts page for descriptions of the fields.Overview of the Alerts page

  • Artifacts: Display all of the artifact categories collected. You can select the item to add to a timeline.

  • Host Timeline: Displays a list of normalized, per-host timelines that include multiple forensic artifacts in a single table.