Cortex XDR enables you to investigate any threat, also
referred to as a lead, which has been detected.
This topic
describes what steps you can take to investigate a lead. A lead
can be:
An alert from a non-Palo Alto Networks system
with information relevant to endpoints or firewalls.
Information from online articles or other external threat
intelligence that provides well-defined characteristics about the
threat.
Users or hosts that have been reported as acting abnormally.