Alerts - User Guide - 2 - Cortex XPANSE - Cortex - Security Operations

Cortex Xpanse Expander User Guide

Product
Cortex XPANSE
Version
2
Creation date
2024-03-28
Last date published
2024-04-17
Category
User Guide
Solution
Cloud
Abstract

An alert is a potential security risk identified by Cortex Xpanse on your services and assets.

An alert is a potential security risk identified by Cortex Xpanse on your services and assets. Alerts are triggered by attack surface rules, which define the risks Xpanse is looking for and the severity assigned to those risks. Xpanse groups alerts into incidents, which are collections of alerts related to a single service or asset.

You can view all your alerts in a tabular format on the Alerts page. To view the Alerts page, go to Incident ResponseAlerts. See Alert Fields for descriptions of the fields in the Alerts table.

Select an alert in the table to open the alert details page on a separate tab in your browser. The alerts details page includes most of the information you need to investigate and remediate an alert, including the owner of the related incident, service and website details, relevant asset details, and remediation guidance.

You can also view alerts in the context of an incident on the Incidents page. The Alerts tab in an incident provides detailed information about each alert in the incident.