* [Blog](https://www2.paloaltonetworks.com/blog) * [Security Operations](https://www2.paloaltonetworks.com/blog/security-operations/) * [Must-Read Articles](https://www2.paloaltonetworks.com/blog/security-operations/category/must-read-articles/) * Beating Alert Fatigue wit... # Beating Alert Fatigue with Cortex XDR SmartScore Technology [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fbeating-alert-fatigue-with-cortex-xdr-smartscore-technology%2F) [](https://twitter.com/share?text=Beating+Alert+Fatigue+with+Cortex+XDR+SmartScore+Technology&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fbeating-alert-fatigue-with-cortex-xdr-smartscore-technology%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fbeating-alert-fatigue-with-cortex-xdr-smartscore-technology%2F&title=Beating+Alert+Fatigue+with+Cortex+XDR+SmartScore+Technology&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www2.paloaltonetworks.com/blog/security-operations/beating-alert-fatigue-with-cortex-xdr-smartscore-technology/&ts=markdown) \[\](mailto:?subject=Beating Alert Fatigue with Cortex XDR SmartScore Technology) Link copied By [Niv Sela](https://www.paloaltonetworks.com/blog/author/niv-sela/?ts=markdown "Posts by Niv Sela"), [Guy Mazaltrim](https://www.paloaltonetworks.com/blog/author/guy-mazaltrim/?ts=markdown "Posts by Guy Mazaltrim"), [Gal Itzhak](https://www.paloaltonetworks.com/blog/author/gal-itzhak/?ts=markdown "Posts by Gal Itzhak") and [Yinnon Meshi](https://www.paloaltonetworks.com/blog/author/yinnon-meshi/?ts=markdown "Posts by Yinnon Meshi") Aug 04, 2022 7 minutes [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown) [Analytics](https://www.paloaltonetworks.com/blog/tag/analytics/?ts=markdown) [Automation](https://www.paloaltonetworks.com/blog/tag/automation/?ts=markdown) [incident prioritization](https://www.paloaltonetworks.com/blog/tag/incident-prioritization/?ts=markdown) [Research](https://www.paloaltonetworks.com/blog/tag/research/?ts=markdown) [Risk Score](https://www.paloaltonetworks.com/blog/tag/risk-score/?ts=markdown) [Score](https://www.paloaltonetworks.com/blog/tag/score/?ts=markdown) [Scoring Rules](https://www.paloaltonetworks.com/blog/tag/scoring-rules/?ts=markdown) [security](https://www.paloaltonetworks.com/blog/tag/security/?ts=markdown) [SmartScore](https://www.paloaltonetworks.com/blog/tag/smartscore/?ts=markdown) [SOC](https://www.paloaltonetworks.com/blog/tag/soc/?ts=markdown) [SOC Platform](https://www.paloaltonetworks.com/blog/tag/soc-platform/?ts=markdown) [Triage](https://www.paloaltonetworks.com/blog/tag/triage/?ts=markdown) [XDR](https://www.paloaltonetworks.com/blog/tag/xdr/?ts=markdown) [XSIAM](https://www.paloaltonetworks.com/blog/tag/xsiam/?ts=markdown) ## Introduction to SmartScore It's no secret that today, more than ever, organizations are facing an extremely difficult mission of protecting their digital assets from sophisticated cybersecurity threats. Trends such as the migration to the cloud, the shift of software workloads to mobile devices, and an increasingly remote workforce are creating a landscape with massive volumes of security data and a vast amount of alerts that SOC teams have to contend with. Evidently, according to a recent survey conducted by Dimensional Research, 83% of the respondents stated that their security staff faces alert fatigue, and 93% of them say that they can't address all security alerts on the same day. To help our customers address alert fatigue, avoid **wasting time chasing after false threats**, and make sure no threat remains unhandled, Cortex XDR is now leveraging the power of AI and automation to deliver a top-notch automatic incident scoring engine --- and make sure SOC teams using Cortex XDR spend their precious time on incidents that matter. ## How Do Traditional Scoring Mechanisms Work? Every SOC team develops its own approach to prioritizing and triaging incidents, however, the essence behind those methods is quite the same: analysts use various manual and automatic procedures to characterize a particular threat. They may *score* a threat in order to indicate a ***severity*** *based on:* * *Tactics, techniques, and procedures (* ***TTP*** *) classification and/or stage of the attack* * ***Relevance*** to a specific use case based on common knowledge and previous experience * To reflect the potential ***impact***on the target and the entire organization. Threat intelligence is often used in parallel with those methods in order to add an additional layer of information and shed light on specific artifacts associated with the suspicious behaviors spotted to justify a deeper investigation. But such means might have inherited flaws, as they are in most cases considered to be static and time-consuming, and even if they incorporate some sort of automation, they are missing important context to reflect the real score of the threat. Additionally, such tools are not designed to evolve over time and adjust themselves according to the inputs of the analysts. This means incidents can reoccur with the same score over and over again, even if the analysts marked them as false positives in the past or gained new knowledge that would impact the incident score. ## What is SmartScore? Many SOC teams have developed their own systems to prioritize which incidents they will investigate first. Such systems consist of a bunch of handmade static rules that miss context, analytics capabilities, or even connection to the environment they are representing and need to be updated and maintained all the time, and as the number of rules increases, so does the maintenance effort. Here are some examples you likely see daily: * This alert is highly insightful but is not really precise, should I ignore it? Maybe just decrease its score? * What should we prioritize first? How do I know where to start? * I see this false positive again and again, didn't I already exclude it? Answering some of the questions above as part of your continuous prioritization workflow is not an easy task and may involve many different techniques and methods to connect the dots. With that in mind, we came up with the idea of SmartScore - \*\*A unique ML-driven scoring engine that translates security investigation methods and their associated data into a hybrid scoring system.\*\*This new disruptive system uses both ML power and contextual security rules, which are driven and built by security researchers and data scientists to generate a reliable risk score. This risk score helps in incident triaging and threat hunting and can be also used to improve another entity scoring within an organization. **![Suspicious incident found by SmartScore that received 90 score](https://www.paloaltonetworks.com/blog/wp-content/uploads/2022/07/word-image-32.png)** *Suspicious incident found by SmartScore that received a 90 score* ### **SmartScore, Hybrid and Manual Scoring Options** The SmartScore scoring engine improves upon the manual incident scoring capabilities introduced in Cortex XDR 2.7. It harnesses machine learning and behavioral analysis of incidents to automatically generate a risk score for each incident. However, if you have already defined manual incident scoring rules, you can continue to use these rules alone or in conjunction with SmartScore scoring. You can use custom incident scoring rules tailored to your environment. If you use both custom and SmartScore scoring, custom scores will override scores defined by the SmartScore engine. **![screenshot of scoring rules](https://www.paloaltonetworks.com/blog/wp-content/uploads/2022/07/word-image-33.png)** SmartScore is also adaptive to changes in your environment, not only when an incident is changed, but also when the alerts are changing their behaviors. This will allow you to invest less time in handling false positives and much more time investigating malicious cases. Moreover, you can leverage this score with your internal security orchestration and event management systems using Cortex XDR APIs to define the set of actions that you wish to take. Our end goal is to make your life easier, make it highly effective, and allow you to spot real threats in no time. ## How Does SmartScore Work? To explain how SmartScore works, let us first define its objective in a more precise manner. In essence, we are interested in assessing the risk of potential attacks and prioritizing them accordingly. First, we have to generate these potential attack stories, containing all involved events, entities, and informational context. For Cortex XDR, attack stories are equivalent to incidents that are constructed from our own XDR alerts. These alerts may originate from a variety of sources, such as the agent, analytics engine, or NGFW alerts, with each alert describing a specific detail or artifact of the attack story. Grouping them using our incident grouping approach, we can generate a complete and meaningful attack story, compared to a narrow prism of a discrete alert. SmartScore leverages incidents as its base building block. Once an incident is generated (and every time it is updated) SmartScore predicts its risk level based on its cyber-oriented features. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2022/07/word-image-34.png) *SmartScore leverages security-driven features extracted from the XDR incidents.* These include context-driven features, Incident-level features, statistical features, and model-based features. * Context-driven features typically refer to specific alerts, their unique properties, and constantly-monitored precision, which is driven by both customer resolutions and manual research conducted by our experts. * Incident-level features aim to quantify the overall threat statistics, for example: what the number of alerts in an incident is; what their corresponding severities are; where these alerts originated from, etc. * Statistical features leverage the Cortex Data Lake to generate a measure of prevalence for entities of various types (files, domains, IPs, alerts, and alert combinations), both in a tenant-based and a global manner. * Model-based features are independent ML models of their own, which focus on a specific aspect of an incident to generate a risk sub-score without being screened by any of the other artifacts. For example, we monitor the CMD process tree and assess its own risk. Once the features are calculated, they are fed to our main ML model which consists of an ensemble of [Gradient Boosting](https://en.wikipedia.org/wiki/Gradient_boosting) models, each designed to address a specific aspect of the data. Then, we combine the results of all models to generate a unified risk score, which is monitored by a set of contextual security-driven rules and incorporates customer-based rules and preferences. ## Summary SmartScore is a new ML-driven capability that will adapt to your environment very quickly. Once an incident is generated, SmartScore will automatically calculate a risk score which can be observed via the UI or the API. SmartScore can help your SOC not just fight against alert fatigue, but also remediate real threats faster, and reduce the overall mean-time-to-respond (MTTR). With SmartScore, organizations can speed up triage, prioritization, and incident response and make sure no real threat is being left unnoticed. Its unique ecosystem, as well as its ability to learn dynamically from our users' input, help us to keep improving the models behind the scenes and adjust the scores in a timely manner. ## How Do I Opt-in? Wish to join us on this journey? All you need to do is turn SmartScore on, and start working on the incidents that really matter! You can enable SmartScore from the **Incident Response \> Incident Configuration \> Incident Scoring** page in the Cortex XDR console. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2022/07/word-image-35.png) #### **To see all our latest Cortex XDR features in action, including SmartScore, attend our webinar, ["Forward Together: Cortex XDR and Unit 42 MDR"](https://register.paloaltonetworks.com/forwardtogether-global) on August 16.** [](https://register.paloaltonetworks.com/forwardtogether-global) [![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2022/07/cortex-xdr-3.4_unit-42-MDR-webinar-splash3.png)](https://register.paloaltonetworks.com/forwardtogether-global) *** ** * ** *** ## Related Blogs ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown) [#### Unlocking the Black Box: Transparency for ML-Based Incident Risk Scoring](https://www2.paloaltonetworks.com/blog/security-operations/unlocking-the-black-box-transparency-for-ml-based-incident-risk-scoring/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [#### What's New in Cortex](https://www2.paloaltonetworks.com/blog/security-operations/whats-new-in-cortex/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [#### How Cortex Defends Against Microsoft SharePoint "ToolShell" Exploits](https://www2.paloaltonetworks.com/blog/security-operations/how-cortex-defends-against-microsoft-sharepoint-toolshell-exploits/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown) [#### Defending against Phantom Taurus with Cortex](https://www2.paloaltonetworks.com/blog/security-operations/the-rise-of-phantom-taurus-unmasking-a-stealthy-new-threat-to-global-security-with-cortex/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Playbook of the Week](https://www.paloaltonetworks.com/blog/security-operations/category/playbook-of-the-week/?ts=markdown) [#### What's New for Cortex and Cortex Cloud (Apr '25)](https://www2.paloaltonetworks.com/blog/security-operations/whats-new-for-cortex-and-cortex-cloud-apr-25/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown) [#### What's New in Cortex: The Latest Innovations for the World's #1 SecOps Platform (Feb '25 Release)](https://www2.paloaltonetworks.com/blog/security-operations/whats-new-in-cortex-the-latest-innovations-for-the-worlds-1-secops-platform-feb-25-release/) ### Subscribe to Security Operations Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www2.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language