Investigate an Asset

Investigate host insights, such as users, groups, services, drivers, hardware, and network shares.
The
Asset View
provides a powerful way to investigate assets by reducing the number of steps it takes to collect and research hosts. Cortex XDR automatically aggregates information on hosts and displays the host insights and a list of related incidents.
asset-view.png
To investigate an asset:
  1. Open the Asset View for an asset.
    You can access the view from:
    • Every host in Cortex XDR console by right-click >
      Open Asset View
      .
    • The
      IP View
      of an internal IP address with a Cortex XDR Agent by selecting
      Host Insights
      from the navigation bar.
    • The Quick Launcher, by searching for a specific Host Name or Agent ID.
  2. Review the Asset overview.
    The overview displays the host name and any related incidents.
    1. Review the Host name.
    2. Add an
      Alias
      or
      Comment
      to the host name.
    3. Review any related incidents:
      Related Incidents
      lists the last 3 incidents which contain the host as part of the incident
      Key Artifacts
      according to the
      Last Updated
      timestamp. To dive deeper into specific incidents, you can select the Incident ID. If more than three incidents are displayed, select
      View All
      .
  3. Filter the host information you want to display.
    Select from the following criteria to refine the scope of the host information you want to display. Each selection aggregates the displayed data.
    Filter
    Description
    Type
    The type of information you want to display.
    • Host Insights
      —A list of the host artifacts.
    • Network Inventory
      —Pivot to the IP view of the IP addresses associated with the host.
    Primary
    List of host artifacts you want to display.
    • Users
    • Groups
    • Users to Groups
    • Services
    • Drivers
    • Autorun
    • System Information
    • Shares
    • Disks
    Compare
    Compare host insights collected by Cortex XDR over the last 30 days.
    Select ip-view-cluster-enter.png to apply your selections and update the information displayed in the visualization pane.
  4. Review the host insights.

Recommended For You