AI SOC Applications
ai soc includes the following applications you can find them in applications & applets after install each application defines a data model and record layout that organizes how you view and work with records for role based access control on components and orchestration (including legacy versus enhanced rbac), see rbac considerations for ai soc docid\ jl6dsw0qjbkpq iojdglp case management (case) primary application for triage and investigation with hero ai ingestion creates records here (tracking prefix case ) the case analysis tab includes controls (sla, claim , unclaim ), signal and case fields, evidence areas, and the ai analysis widget (shown as ai alert analysis on the record) the support tab includes analysis mode ( manual or autonomous ), analysis agent request id and analysis agent session tracking fields, and manual actions timelines, audit, and routing rule results live on additional tabs see case management (case) docid\ sdpesft6lsyz0zfrn hok and getting started docid\ p7qjquayekczhpxeppwcp for manual plan, re investigate , and routing rule investigation paths threat intelligence (tia) application for storing observable enrichment results (package name threat intelligence artifact ) records display with an observable panel that anchors key fields, plus enrichment results and risk scores signal routing rules (rule) application for defining routing logic that maps records to playbooks (package name routing rule ) records use a tabbed layout for rule data and configuration for compatible playbooks and manual association, see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi knowledge base articles (kb) investigation guidance with scope ( global , signal source , signal rule , signal name ) and matching value see knowledge base articles (kb) docid\ ntgnxpveszjgy llqojmf for how to create articles and kb article best practices for plan generation docid 7zdgwrtvm6yi0lunjl4jp ai ingestion (ai) application for building and tracking alert ingestion configurations (separate ai ingestion workspace ) each record represents an ingestion setup (for example, vendor product, api specification uploaded, components generated) the custom widget guides you through creating connector components and ingestion pipelines; use the audit tab to review configurations and activity for the full workflow, see ai soc ingestion these walkthroughs explain where to start in each application, which panels to prioritize when viewing records, and the actions to use for triage and investigation