Incidents

An incident is a collection of events from one or more products that together represent an attack story. Infinity XDRClosed Extended Detection & Response/XPRClosed Extended Prevention & Response utilizes ThreatCloud's Artificial Intelligence (AI) and applies Machine Learning (ML) models to correlate between the events from on-boarded products (both benign and security events) into unified incidents. The incident's priority level is calculated based on the artifacts of the incident, including the confidence and severity levels of the detection. Incidents are actionable with prevention steps that can be taken within the Infinity XDR/XPR application.

The Incidents page shows the list of incidents and its details that includes:

  • Insights that triggered the incident and its timeline

  • Impacted assets and users

  • Indicators

  • Prevention history and recommended prevention actions. You can automate some of these actions. For more information, see Automations.

To view the Incidents page, access Infinity XDR/XPR and click IncidentsIncidents.

Legend

Item

Description

1

Time span

Select the duration for which you want to view the incidents.

  • Last 24 hours

  • Last week

  • Last two weeks

  • Last month

  • Last year

2

Sort by

Select a criterion to sort the incidents.

  • Priority

  • Creation date

  • Last update

  • Severity

3

Assign

Assign a security expert to address the incident.

4

Change status

Change the status of the incident.

  • New

  • In Progress

  • Close - Handled

  • Close - False Positive

  • Close - Known Activity

5

Follow up

Indicates that the incident requires a follow-up.

Note - Infinity XDR/XPR does not send automatic reminders for follow-up.

6

Search

Search for the an asset, incident or a user.

7

Select all

Select or clear all incidents.

8

Filters

Filter the incidents by:

  • All

  • Action required

  • Prevented

9

(Add filter)

Filter the incidents by:

  • Assignee

  • MITRE tactics

  • MITRE techniques

  • Status

  • Priority

  • News articles

10

IncidentClosed Correlation of one or more insights into a security incident potentially impacting your environment. It can be based on insights generated from one or more products.

Shows incident details.

Legend

Description

1

Priority of the incident:

  • Critical

  • High

  • Medium

  • Low

  • Informational

2

Date and time when the incident was generated.

3

View the comments added related to the incident.

4

Add or remove the follow-up flag on the incident.

5

Incident ID and title. Click the title to open the Incidents - Overview page.

6

Security Operations Center (SOC) analyst assigned to the incident. Shows Unassigned if an incident is unassigned.

7

Status of the incident. Click to set the status.

  • New

  • In Progress

  • Close - Handled

  • Close - False Positive

  • Close - Known Activity

8

Number of insights involved in triggering the incident with date and time when the first and last insight was created. Click to view Incidents - Insights & Forensics page.

An insight is anaggregation of one or more logs into valuable observations indicating the nature of the activity.

9

Number of assets involved in the incident.

10

Number of indicators and artifacts involved in the incident.

11

Opens the Incidents - Overview page.

11

Opens the incident Incidents - Overview page in a new tab.

12

Prevented

Shows that the incident is prevented without human intervention.

13

Confidence

Confidence level of the detection:

  • High

  • Medium

  • Low

14

Severity

Priority of the incident:

  • Critical

  • High

  • Medium

  • Low

  • Informational

15

Source

The source of the events correlated into the incident.

16

Personalized News

Shows the news articles related to the incident. For more information, see Personalized News.

17

MITRE ATT&CK

MITRE ATT&CK tactics and techniques involved in the incident. The numbers represent the number of insights related to each tactic.

Opens the Incidents - Insights & Forensics page that shows the related insights.

18

Top Insights

Top insights for the incident.

19

Prevention

Lists prevention actions taken and those that are recommended to be taken.

20

Insights Timeline

Shows the timeline of insights and the duration between the first and the last insight.

21

Comments

Shows the comments added for the incident. Click to add a comment.