Hunting - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2024-05-15
Category
Administrator Guide
Abstract

Hunting refers to searching for specific data across a large number of hosts.

Hunting allow investigators to search for specific data across a large number of hosts. Hunt collections provide more details about where something occurred. Such examples would be, finding which endpoints executed a piece of malware, which users accessed a particular file, or which endpoints were accessed by a specific user.