Which Cortex XDR component raises an alert when suspicious activity composed of multiple events is detected and deviates from established baseline behavior?
Cortex XDR uses several engines to detect threats, but the one specifically focused on baseline deviations and behavioral anomalies is the Analytics Engine.
Behavioral Baselining: The Analytics Engine uses machine learning to observe the 'normal' behavior of users and devices (e.g., typical login times, usual data transfer volumes, common process executions).
Multi-Event Correlation: Unlike a simple IOC rule that triggers on a single malicious file hash, the Analytics Engine looks at a sequence of events---even if those individual events seem benign---and identifies them as suspicious because they deviate from the established norm.
Difference from Causality Analysis Engine (B): The CAE is used to reconstruct the chain of events (the 'how') after an alert has been triggered, whereas the Analytics Engine is the component that generates the alert based on behavioral logic.
Tarra
1 hour agoJacklyn
5 days agoTom
10 days agoJesusa
16 days agoCherri
21 days agoShelton
26 days agoShizue
1 month agoVictor
1 month agoHeike
1 month agoBrynn
2 months agoDelsie
2 months agoIlene
2 months agoLorrine
2 months agoAnthony
2 months agoFelicidad
2 months agoGarry
3 months agoFrancine
3 months agoShannan
3 months ago