The Hexnode XDR Incidents tab centralizes threat triage, investigation, containment, and closure in one workflow.
Threats and rule-based Alerts remain separate. The Threat Inventory uses severity, status, assignee, and verdict fields to support prioritization.
Analysts can investigate process context, isolate endpoints, kill malicious processes, quarantine files, and document outcomes without leaving the incident workflow.
False positives can be classified and excluded precisely, helping teams reduce repeated benign detections.
The Hexnode XDR incidents tab centralizes threat detections, custom alerts, and endpoint context for investigation and response. Security teams can identify what happened, locate the affected endpoint, and determine the appropriate next action.
In general, Extended Detection and Response (XDR) unifies security telemetry, investigation, and response across multiple security domains. In Hexnode XDR, the Incidents tab organizes detected threats and configured alerts for investigation and response.
The Hexnode XDR Incidents tab organizes incident activity across these views:
Threats: Displays malicious activity detected through Hexnode XDR’s threat-detection mechanisms and supports investigation and remediation.
Alerts: Displays events that match administrator-defined conditions in configured Alert Profiles.
Exclusions: Lists exclusions created for files, folders, SHA-256 hashes, or file extensions during threat handling.
Meanwhile, the XDR Dashboard provides higher-level visibility into Total Incidents, Open Incidents, and Recent Incidents. The Recent Incidents view lets administrators move from dashboard-level monitoring into incident investigation.
What Is the Difference Between a Threat and an Alert in Hexnode XDR?
In Hexnode XDR, a Threat is confirmed malicious activity detected through heuristic or behavioral analysis. An administrator-defined Alert Profile triggers an Alert when configured conditions occur.
Therefore, Threats support active investigation and remediation. In contrast, the Alerts view functions as a read-only monitoring repository.
Attribute
Threat
Alert
Detection source
Hexnode XDR heuristic and behavioral detection engine
Administrator-configured Alert Profile
Examples
Ransomware, Trojan, Rootkit
Process creation, network connection, registry change, system logon
Severity labels
Low, Medium, High, Critical
No severity field documented in the Alerts inventory
Remediation available
Yes
No, view-only
Where configured
Detected automatically by XDR
Settings > Alert Profiles
Hexnode XDR classifies detected threats into eight categories:
Trojan: Malware disguised as legitimate software that executes a hidden malicious payload.
Ransomware: Malware that encrypts files or disrupts system access for extortion.
Wiper: Destructive malware that corrupts or destroys data without offering recovery.
Stealer: Malware designed to collect and exfiltrate credentials or other sensitive information.
Rootkit: A set of malicious tools or files that conceals attacker activity and helps maintain privileged access on a compromised system.
Remote Access Trojan: Malware that gives an attacker unauthorized remote control.
Backdoor: A covert access mechanism that bypasses normal security controls to provide unauthorized access.
Cryptominer: Malware that hijacks endpoint resources to mine cryptocurrency.
The distinction matters because ransomware remains a significant enterprise threat. Verizon’s 2025 DBIR reported ransomware in 51% of APAC breaches.
How Does the Hexnode XDR Incidents Tab Take You from Detection to Resolution?
The Hexnode XDR Incidents tab follows a four-step threat-response workflow: triage, investigation, containment and remediation, and closure. Analysts can investigate process context and initiate supported remediation actions without switching to separate remote-access or endpoint-management tools.
Step 1 – Triage in the Threat Inventory Table
First, analysts use the sortable Threat Inventory to prioritize incidents using these fields:
ID, Threat, User, Threat Category, Time, and Status
SHA-256, Severity, Target, Assignee, Process, and Verdict
The Process column displays the operating system PID associated with the malicious process.
Analysts can select multiple threats and use bulk actions to:
Assign an Assignee
Set a True Positive or False Positive verdict
Change Status
Add Comment
Export selected records to JSON or CSV
Consequently, teams can assign threats, update verdicts and statuses, add comments, and export threat records directly from the Threat Inventory.
Step 2 – Investigate with the Overview and Process Sub-tabs
Next, the Overview sub-tab provides the incident’s technical and identity context. Its Summary maps observed Tactics & Techniques to the MITRE ATT&CK framework.
Analysts can also inspect:
Process Metadata: command line, file path, integrity level, SHA-256, SHA-1, and publisher
User Identity Context: username and Windows SID
Endpoint Telemetry: hostname, agent version, local IP, and external IP
Canary: ransomware decoy-file details and the action that triggered detection
For deeper behavioral analysis, the Process sub-tab displays an interactive process tree. A process tree visually connects parent processes with the child processes they launch.
Analysts can inspect node attributes and review the chronological Telemetry Event Table beneath the tree. For broader investigations, the Investigate workspace supports proactive threat hunting queries across endpoint activity.
Step 3 – Contain and Remediate Without Leaving the Incident
Once analysts confirm malicious activity, Hexnode XDR provides response actions within the investigation workflow:
Isolate: cuts internet and lateral network communication while retaining the secured XDR management channel.
Quarantine File: moves the malicious file into a restricted, encrypted location.
Delete File: permanently removes the file from disk.
Kill Process: terminates one selected process.
Kill Process Tree: terminates the selected process and its child processes.
Delete Process: permanently deletes the root executable file that initiated the selected process.
Connect To Host: opens a live remote terminal session for command-line remediation.
Faster investigation and containment can also support efforts to reduce MTTD and MTTR with EDR and XDR. Importantly, Hexnode recommends stopping active execution before deleting or quarantining the underlying file. Otherwise, the process may remain active or block file removal.
Step 4 – Close the Loop and Document
After containment, analysts can move the threat through Open → In Progress → Mitigated → Closed. They can also record a True Positive or False Positive verdict.
Additionally, Add Tag creates searchable custom labels, while timestamped comments preserve investigation context. Analysts can export threat records as JSON or CSV for reporting and compliance workflows.
This workflow aligns operationally with NIST SP 800-61 Revision 3. The publication frames incident response through Detect, Respond, and Recover. Lessons learned across all CSF functions feed continuous improvement through the Improvement category within Identify.
Featured resource
Why XDR Is Stronger With UEM
See how combining endpoint management with XDR can connect security context, threat investigation and incident response in a unified security strategy.
How Does the Incidents Tab Reduce Alert Fatigue for SOC Teams?
The Hexnode XDR incidents tab reduces alert fatigue by turning endpoint telemetry into structured, assignable incidents. Hexnode XDR also separates confirmed Threats from administrator-defined Alerts, reducing reliance on an undifferentiated event stream.
Alert fatigue occurs when excessive security notifications overwhelm analysts and make meaningful detections harder to identify.
Hexnode XDR addresses that operational problem through several controls:
Incident correlation: XDR correlates localized telemetry events into a unified incident lifecycle mapped against MITRE ATT&CK.
Threat and Alert separation: Threats represent confirmed malicious activity, while Alerts track administrator-defined conditions. Adding investigation context can also turn isolated detections into more useful contextualized threat alerts for security teams.
Severity-based prioritization: Analysts can sort Threats by Low, Medium, High, or Critical severity alongside status and verdict.
Workload distribution: Analysts can assign incidents to technicians. Meanwhile, the Dashboard’s Incident Allocation panel separates Assigned from Unassigned incidents.
Controlled Alert generation: Administrators configure Alert Profiles under Settings > Alert Profiles and select which endpoint events should trigger notifications.
Together, these controls help analysts narrow the queue by threat type, severity, ownership, status, and administrator-defined alert conditions.
How Do You Handle False Positives in the Hexnode XDR Incidents Tab?
In Hexnode XDR, admins mark benign detections as False Positive and add precise exclusions to prevent repeated detections.
Follow this workflow:
Set the incident Verdict to False Positive.
Open Actions and select Add to Exclusion Policy.
Choose the required exclusion type.
Save the exclusion.
Review it later under the Exclusions sub-tab in Incidents.
Hexnode supports three exclusion types:
File/Folder: Ignores a specific file or exact path.
Hash/SHA-256: Excludes one exact file version regardless of location. Hexnode identifies this as the most precise option.
File Extension: Ignores every matching extension. Hexnode explicitly warns that broad extension exclusions are highly insecure.
For example, Hexnode documents a legitimate postgres.exe database process triggering a remote-thread detection. An analyst can mark that detection as benign and create a narrow exclusion instead of weakening broader detection coverage.
Top 7 Hexnode XDR Capabilities to Assess Before Deployment
Evaluate Hexnode XDR across threat remediation, threat hunting, MITRE ATT&CK mapping, and auditability.
Frequently Asked Questions
Can you isolate an endpoint directly from the Incidents tab?
Yes. Analysts can use Isolate from the threat’s Endpoint Telemetry section to restrict network communication. Hexnode XDR preserves a secured control channel to the console, so Connect To Host and other remediation actions remain available. However, the Alerts view remains monitoring-only and provides no isolation action.
What is the difference between True Positive and False Positive in Hexnode XDR?
A True Positive verdict confirms that Hexnode XDR detected genuinely malicious or unauthorized activity. Hexnode moves that event into history for later review. In contrast, False Positive identifies safe, expected, or authorized behavior and indicates that no further remediation is required.
Should I use Kill Process or Kill Process Tree?
Use Kill Process when you need to terminate only one rogue process. Use Kill Process Tree when an active malicious branch has spawned multiple child processes. Therefore, killing the tree stops the selected process and every child process beneath it.
Does Delete File stop a running process?
No. Deleting an executable does not necessarily terminate its running process, and file-deletion behavior varies by operating system. Terminate the process before removing its executable. Therefore, Hexnode recommends using Kill Process or Kill Process Tree first. Then, quarantine or delete the underlying file.
What is a ransomware canary in Hexnode XDR?
Hexnode XDR places monitored ransomware canary files in directories that ransomware commonly targets. It watches these files for suspicious modification or encryption. If ransomware trips a canary, analysts can investigate and isolate the affected endpoint before encryption spreads further.
Run Your Next Incident from One Screen
The Hexnode XDR Incidents tab gives analysts one workflow for triage, process investigation, endpoint response, verdict assignment, and closure. Analysts can move from Threat Inventory review to process analysis, remediation, verdict assignment, and final status without breaking context.
For teams evaluating XDR, the next step is to test that workflow against real operational requirements.
Put the Hexnode XDR Incident Workflow to the Test
Explore threat investigation, endpoint context and response workflows in Hexnode XDR.
I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.