Endpoint Applications Groups - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide

Endpoint Applications Groups allow organizing endpoint applications into logical groups for use in Data-in-motion Rules. Instead of selecting individual applications in a rule, administrators can reference an application group, making rule management more scalable. Groups can contain custom application groups (user-defined collections of applications) and catalog web application groups (predefined web application categories).

Users access Endpoint Applications by going to ModulesData SecurityEndpoint Data-in-Motion RulesEndpoint Applications Groups.

For more information, see Create endpoint application groups.

Permission

Description

Recommended Roles

None

Users cannot access the Endpoint Applications Groups page. These users cannot see any application groups, their members, or their usage in rules.

  • SOC Tier-1 Analyst: Application group management is outside Tier-1 scope.

  • Application group management is outside the IT infrastructure administration scope.

View

Users can navigate to the Endpoint Applications Groups page and see all application groups in the grid view. They can view group names, types (Custom Application Group, Catalog Web Applications Group), member applications, and group descriptions. They cannot create groups, edit existing ones, or delete groups.

  • SOC Tier-2 and 3 Analysts: May need to review group definitions when investigating DLP issues/advanced analysis.

  • Threat Hunter: May need to understand application groupings for threat hunting context.

View/Edit

Users have full control over Endpoint Applications Groups. They can create new custom application groups and catalog web application groups, edit group membership and properties, and delete groups. All context menu actions are fully accessible.

  • Security Engineer: Responsible for organizing applications into groups for DLP rule management.

  • Security Admin: Full administrative access to all DLP configurations.