Cortex XSIAM vulnerability assessment enables you to identify and quantify the security vulnerabilities on an endpoint. After evaluating the risks to which each endpoint is exposed and the vulnerability status of an installed application in your network, you can mitigate and patch these vulnerabilities on all the endpoints in your organization.
Notice
The Vulnerability Assessment feature is included with Cortex XSIAM Enterprise and with Cortex XSIAM NG SIEM with a Host Insights license. If you have a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license, use the Vulnerability Management feature. For more information, see Vulnerability management in Cortex XSIAM.
You can access the vulnerability assessment feature by navigating to → → → . Cortex XSIAM uses an advanced algorithm to collect extensive details on common vulnerabilities and exposures from comprehensive databases and to produce an in-depth analysis of endpoint vulnerabilities. Cortex XSIAM retrieves the latest information from the NIST public database to calculate the severity score.
After enabling the feature for the first time, it may take up to a week to get the updated data into the platform. Re-collecting the data from all endpoints in your network could take up to 6 hours. After that, Cortex XSIAM initiates periodical recalculations to rescan the endpoints and retrieve the updated data. If at any point you want to force data recalculation, click Recalculate. The recalculation performed by any user on a tenant updates the list displayed to every user on the same tenant.