Use the AI-powered Aurora Security Assistant to investigate alerts

You can use the AI-powered Aurora Security Assistant to provide a summary analysis of an alert group, and detailed analysis for process and script artifacts within an alert group. The Aurora Security Assistant leverages rich cybersecurity knowledge sources to provide valuable information to aid you in your threat investigations.

When you use the Aurora Security Assistant to generate an analysis of a script artifact, if your browser is set to a language that is supported by the Aurora Endpoint Security console, Aurora Security Assistant will generate the response in that language. You can change the language setting for Aurora Security Assistant by clicking the settings icon in the response panel.

Note:
  • Currently, the Aurora Security Assistant is available for Aurora Focus alerts only. Future updates will extend this functionality to other Endpoint Defense products and services.
  • Arctic Wolf does not use any customer data to train the AI that powers the Aurora Security Assistant.
  1. In the management console, on the menu bar, click Alerts.
  2. On the Product column, click The filter icon. and select Focus.
  3. Click an alert group.

    Task

    Steps

    Generate a summary analysis of the alert group.

    1. In the left pane, in the Overview section, click Alert Summary.
    2. Click The copy icon. to copy the summary.

    Generate an analysis of an instigating or target process or script for the alert group.

    1. In the left pane, scroll down to view relationships between instigating and target objects.
    2. Hover over an instigating or target process or script artifact and click The Cylance Assistant icon..
    3. Click The copy icon. to copy the analysis.

    Generate an analysis of an instigating or target process or script for a specific alert in the group.

    1. Click an individual alert in the alert group.
    2. In the right pane, scroll down to view relationships between instigating and target objects.
    3. Hover over an instigating or target process or script artifact and click The Cylance Assistant icon..
    4. Click The copy icon. to copy the analysis.