Cloud Detection and Response (CDR) Command Center - See a dynamic overview of your tenant's cloud activities in the Cloud Detection and Response (CDR) Command Center. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-04
Category
Administrator Guide
Abstract

See a dynamic overview of your tenant's cloud activities in the Cloud Detection and Response (CDR) Command Center.

The Cloud Detection and Respond (CDR) Command Center dashboard provides a dynamic overview of your cloud-based security operations. It includes details about your cloud assets and projects, related cases, risks, and vulnerabilities. From the dashboard, you can drill down to dedicated views for further investigation into your platform.

Notice

Requires Cortex XSIAM Premium, or any other XSIAM license with the Cloud Runtime Security or the Cloud Posture Security add-on.

Cloud_command_center.png

The following table describes each section on the Cloud Detection and Respond (CDR) Command Center:

Section

Details

Accounts

Displays information about your cloud accounts, the total number of assets configured per account, and the total number of cloud projects from your cloud accounts. Hover over the total number of assets to see a breakdown by category, and click on an account to drill down to the assets for the selected account.

Line colors represent the connectivity status of the assets. You can hover over the lines to see a breakdown of data ingestion or details of collection errors.

Cases

Displays the total number of cases opened in the timeframe that are associated with your cloud assets, broken down by severity. Cases are broken down into automated and manual cases, where automated cases contain at least one playbook. You can also see the top nine open cases as ranked by SmartScore.

Key performance indicators

  • Risks identified, including attack paths, configurations, and vulnerabilities.

  • Total number of assets discovered in the cloud.

  • Cloud data ingested by your cloud platforms in the timeframe, including flow logs and audit logs.