Detections

The Detections tab in the incident detail with AI analysis displays a list of detection groups associated with the incident that are derived from security events analyzed by agentic AI.

Security events generated by integrated products are analyzed by agentic AI in Cisco XDR to determine the relationships between detections, such as shared observables, overlapping timelines, and related attack patterns. When events are determined to be part of the same threat, they are grouped to create incidents in Cisco XDR. The resulting data is displayed in the Detections tab. For details on security events, see Detections.

Each row in the table includes data from a group of detections that were initially involved with the incident.