Incident Detail

The Incident Detail page provide more information about the incident to help you diagnose, contain, and remediate the threat. The page consists of the header, attack graph, and the following tabs: Overview, Detection, Response, Evidence, Worklog, and Report.

Cisco XDR incident: Malicious email, AsyncRAT activity on endpoint. Graph, assets, observables, indicators.

Click Launch new incident view in the upper right corner in incident detail to display the new AI-powered incident detail view. This view presents an overview of the AI analysis and evaluation of the incident, indicating whether it is likely a true or false positive threat. The Launch new incident view button is disabled for legacy incidents, including incidents that are directly promoted from Secure Cloud Analytics and incidents created using Cisco XDR APIs (for example, via an Automate workflow). For more information, see Incident Detail with AI Analysis. Click Return to classic view in the upper right corner to close the new view and return to the previous incident detail view.

Note: The new incident detail view is currently in Beta and subject to change.