Performing Remedial Actions on Messages in Cisco XDR

Before you begin

In Cisco XDR, you can now investigate and apply the following remedial actions on messages processed by your Secure Email and Web Manager:

  • Delete

  • Forward

  • Forward and Delete

Make sure you have met the following prerequisites before you perform remedial actions on messages in Cisco XDR:

Procedure


Step 1

Log in to Cisco XDR with your user credentials.

Step 2

Perform an investigation for threat analysis by entering required IOCs (for example, URLs, Email Message ID and so on) in the Investigate panel and click Investigate. For more information, see the Investigate topic in the Help section at https://docs.xdr.security.cisco.com/Content/Investigate/investigate.htm.

Step 3

Click the pivot menu button next to the Cisco Message ID or Email Message ID and select the required remedial action (for example, ‘Forward’). For more information, see the Pivot Menu topic in the Help section at https://visibility.amp.cisco.com/help/investigate.