Investigate

In an intelligence-driven incident response, a piece of disseminated information may be the starting point for a security team to investigate the impact of a known piece of malware. The Cisco XDR Investigate feature is used to search suspicious indicators of compromise (IOCs) such as emails, log messages, domains, URLs, and IPs, and extract observables for enrichment.

Cisco XDR reaches out to all of the configured sources (configured modules) and finds the disposition for each observable, and then displays the details in the investigation results. Once an asset has been identified, you can immediately direct attention to it to gain contextual knowledge of exactly which observable(s) the asset has communicated with.

Choose Investigate in the navigation menu to begin an investigation.

Investigate