Extending the Power of Forensics with Cortex
Built as part of the Cortex platform, Forensics provides an end-to-end solution, enhancing your security operations by seamlessly integrating forensic data with real-time detection and response. This converged platform allows you to unify detection, response, and forensic analysis in a single console, providing faster threat containment and deeper investigative insights.
- Causality Chain: - The forensic data can be viewed across the Cortex platform, including the causality chain, providing a comprehensive understanding of an attack. 
- Alerts and Detection:- Continuously monitor events to detect ongoing attacks. Unlike siloed forensic tools, your analysts can monitor activity and verify threats from one console, including activity from unmanaged endpoints and IoT devices. 
- Smart Grouping:- Alerts and events from forensics can be grouped together into unified cases, providing a single view for investigation and response.