Getting Started with Incident Response

Cisco XDR Incidents is where security analysts and incident responders manage the incidents that have been promoted from security events. Through advanced analytics and correlation, Cisco XDR takes raw telemetry and uses detection logic to create meaningful security events which are shown as incidents.

Incidents

The incidents are prioritized using an overall priority score calculated from detection risk (including incident severity and TTP-based risk of financial loss) and asset value at risk (based on the value of assets involved in the incident). This ensures that the most critical detections are surfaced at the top of the list, allowing your team to spend time on what really matters.

Priority Score

Select an incident in the list to open the Incident drawer for visibility into additional high-level details, including a breakdown of the priority score, MITRE TTPs, and the assets associated with the incident and number of events where the asset was seen.

Incident Drawer

Select View Incident Detail in the lower portion of the Incident drawer to open the full incident. The Incident Detail page provides more information about the incident to help you diagnose, contain, and remediate the threat.