AI Detection & Response in Cortex XSIAM (Beta) - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2025-12-29
Category
Administrator Guide

As organizations increasingly integrate AI into their operations, they become vulnerable to new threats such as model tampering or prompt injection. Traditional security tools lack the context and precision needed to detect and respond to AI-specific threats. In line with comprehensive security strategies, enterprises should incorporate a combination of preventive and responsive actions to safely enable adoption of AI technologies.

Cortex AI Detection & Response (AIDR) is a new module available in Beta that allows companies to:

  • Gain visibility into AI usage in the cloud

  • Identify AI-specific threats

  • Respond and remediate these threats

Enable AIDR

Prerequisite

To enable AIDR, you must have one of the following user roles: Instance Admin or Account Admin.

In order to use the AIDR feature, you must enable it as follows:

  1. Navigate to SettingsConfigurationsCortex - Analytics.

  2. In the AI Detection & Response box, click Beta Evaluation Agreement to read and accept the agreement.

  3. After you have accepted the agreement, enable the AIDR feature.