Incident Detail with AI Analysis

Note: The new incident detail view is currently in Beta and subject to change.

The new Incident Detail page presents an overview of the AI analysis and evaluation of the incident, indicating whether it is likely a true or false positive threat. The AI assesses incidents in a manner similar to a human analyst, systematically forming and validating hypotheses. It analyzes individual detections, observables, indicators, and their combination, to identify a threat narrative consistent with the incident data. The final classification, along with reasoning, supporting evidence, and recommended response steps, is displayed in the incident detail view.

Note: The incident detail view with AI analysis is not available for legacy incidents, including incidents that are directly promoted from Secure Cloud Analytics and incidents created using Cisco XDR APIs (for example, via an Automate workflow). If possible, we recommend that you use the Custom Security Events feature instead of creating incidents directly via API. These events will generate detection findings in Cisco XDR, which are considered for incident correlation and the incidents are analyzed by AI.

On the Incident Detail page, click Launch new incident view in the upper right corner in incident detail to open the new incident detail view. To close the new incident detail view and return to the previous incident detail view, click Return to classic view in the upper right corner.