Getting Started
this guide walks you through your first signal investigation in ai soc follow these steps to understand the workflow and key features investigation approaches ai soc supports three complementary investigation approaches on the same case management record approach summary ai assisted investigation hero ai generates a plan; you run steps manually ( generate plan , execute steps) agentic investigation the analysis agent runs without analyst intervention during the run—via re investigate in ai alert analysis (when analysis mode is autonomous ) or a signal routing rule review after routing a routing rule already ran agentic investigation before you opened the record—review plan, verdict, and component results hands on steps for each approach are in step 4 choose how to investigate /#step 4 choose how to investigate , step 5 generate an investigation plan (ai assisted) /#step 5 generate an investigation plan ai assisted , and step 6 run agentic investigation on the record /#step 6 run agentic investigation on the record administrators who need agentic investigation to run automatically when signals arrive (for example, overnight triage) configure a routing rule after import—see enable agentic investigation after import /#enable agentic investigation after import later on this page prerequisites before starting your first investigation where to work primary triage and investigation use case management and dashboards in the ai soc workspace (for example analyst triage queue ) permissions configuration work with your organization to configure role based permissions for ai soc so users see the right actions (see permissions configuration below) platform rbac (legacy versus enhanced) also controls access to components and orchestration; see rbac considerations for ai soc docid\ jl6dsw0qjbkpq iojdglp access you have access to the case management application and ai soc workspace hero ai hero ai is enabled for your tenant (required for plan generation and agentic investigation) permissions you have appropriate permissions to view signals, generate plans, run investigation steps, and update records assets threat intelligence providers are configured (optional but recommended) permissions configuration user role permissions for ai soc control what each role can see and do in the ai alert analysis panel on case management records (that is the panel title analysts see when viewing the ai analysis widget output) widget options alone are not always enough users also need the right turbine component and orchestration permissions for your account rbac mode for enhanced rbac , analysts typically need read and execute on relevant components ; for legacy rbac , orchestrator level access is required for full ai soc behavior routing rules that invoke ai soc trigger analysis agent via routing rule also require a pat token in an asset—see rbac considerations for ai soc docid\ jl6dsw0qjbkpq iojdglp to configure widget permissions open applications & applets → case management → form layout → case analysis tab, select the ai analysis widget in the layout (it appears as ai analysis in the form; on records it displays as ai alert analysis ), then click edit widget in the widget editor you set role based access control (rbac) each option can be enabled or disabled and restricted to specific role names (use to allow all roles) there are four default permissions (create, read, update, delete) as a baseline; you can customize them or use grant full permissions to grant full access for a role the widget also exposes these ai soc–specific options (aligned with the widget configuration) option description summarysection display the ai analysis summary (verdict, threat intel, mitre att\&ck) plansection display the investigation plan section remediationplan display the remediation plan section and generate remediation plan button automationsection display the automation section (create triage rules and playbooks) generateplan ability to generate investigation and remediation plans (for example, generate plan button) modifyplan ability to modify plans (add/remove/edit steps, reorder, select components) executeplan ability to execute plans (run individual steps or run all) usemarketplace ability to search and install marketplace components when generating or editing plans how to configure in the widget editor, each option can be turned on or off and limited to specific role names use for an option to allow all roles; enter one or more role names (comma separated if supported) to restrict that option to those roles the four baseline permissions (create, read, update, delete) apply to the widget as a whole; use grant full permissions for a role if that role should have full access to the panel without per option limits example to let analysts view the summary and plan and run steps, but restrict automation and marketplace to admins enable summarysection , plansection , generateplan , modifyplan , and executeplan for analyst roles (or ), and enable automationsection and usemarketplace only for admin or automation roles adjust to match your organization's roles configure these so that analysts have the access they need without exposing actions that should be restricted (for example, automation or marketplace use) to roles that should not have them if you do not see ai features (for example, generate plan button or plan section) this is often due to hero ai not being enabled or to rbac/widget configuration in troubleshooting , see hero ai service issues (generate plan button missing or does nothing) and configuration issues (rbac features not visible or accessible) there you will find step by step checks (1) verify hero ai and the feature flag are enabled for your tenant (2) review the ai alert analysis widget configuration and confirm your role is in the allowed roles for the sections and actions you need (3) verify your role assignments and application permissions doing these checks early avoids confusion when the button or sections do not appear your first signal investigation step 1 open case management and select a record navigate to application records → case management review the signal list to find a signal to investigate tip start with a signal that has status new or in progress (avoid processing for your first run—see below) has observables (ips, domains, hashes, urls) has completed threat intelligence enrichment (check threat intelligence status ) click a record to open it about processing new signals start in processing until threat intel enrichment and signal evaluation (correlation, kb linking, hero ai analysis) complete only then does status move to new , closed , or escalated if you open a signal in processing, wait for it to leave processing before generating a plan, clicking re investigate , or expecting an ai verdict what to look for tracking id (for example, case 1234) for reference signal source to understand where the alert originated first created timestamp to see how long the signal has been open step 2 review key fields on the signal start by understanding the record's basic information and current state on the case management record, review these fields current owner is the signal assigned? if not, you may want to claim it organization which organization does this signal belong to? signal type alert, phishing, or triage (a classification value on the case management record) signal source where did this alert come from? (siem, edr, email, and similar) intelligence verdict what does threat intelligence say? (malicious, suspicious, benign, unknown) status current workflow state ( processing , new, in progress, resolved, and similar) processing means enrichment and signal evaluation are still running; the signal will move to new, closed, or escalated when done priority business priority (low, medium, high, critical) severity technical severity (informational, low, medium, high, critical) classification analyst classification (true positive, false positive, unknown) manual verdict has an analyst set a verdict? (malicious, suspicious, benign, unknown) actions to take if the signal is unclaimed and you are investigating it, click claim in the controls area update status to in progress if you are actively working on it review priority and severity to ensure they are set appropriately step 3 check evidence and context before investigating, review the evidence and context available on the record in the ui these are in the same section (not in separately labeled "panels") knowledge base articles purpose shows linked kb articles that provide investigation guidance what to look for articles that match this signal type or observable patterns action if relevant kb articles are linked, review them for standard procedures tip kb articles provide baseline context that helps hero ai generate better plans and agentic investigation runs threat intelligence purpose shows enrichment results for observables (ips, domains, hashes, urls) what to look for threat intelligence verdict overall verdict from ti providers observables list of extracted observables and their verdicts enrichment status are enrichments complete or still pending? action if enrichments are pending, wait for them to complete before generating a plan or starting investigation review observable verdicts to understand threat context click on an observable to view detailed ti information correlation purpose shows related signals and cases what to look for similar signals that may have already been investigated related cases that might contain relevant context correlation status (pending, processing, complete) action review similar signals to see how they were handled check if a case already exists for related activity use correlation to avoid duplicate work rules purpose shows routing rules that matched this signal what to look for which rules triggered and which playbooks ran (including agentic investigation via ai soc trigger analysis agent via routing rule ) action understand what automated processing has already occurred if a routing rule already ran agentic investigation overnight, the plan, verdict, and component results may be on the record when you open it step 4 choose how to investigate in ai alert analysis , you investigate in one of three ways approach when to use ai assisted investigation hero ai generates a plan; you run steps manually ( generate plan , execute steps) — continue with step 5 /#step 5 generate an investigation plan ai assisted agentic investigation the analysis agent runs without analyst intervention during the run—via re investigate in ai alert analysis (when analysis mode is autonomous on support ) or a signal routing rule — continue with step 6 /#step 6 run agentic investigation on the record review after routing a routing rule already ran agentic investigation before you opened the record—review plan, verdict, and component results, then continue with step 7 /#step 7 review and execute plan steps all approaches use the same case management record this path covers investigation only —not automated remediation step 5 generate an investigation plan (ai assisted) once you have reviewed the evidence, generate an ai powered investigation plan scroll to the ai alert analysis panel on the signal record pre plan view if no plan exists yet, you will see ai verdict summary (if available) confidence meter mitre att\&ck context guidance message generate plan button click generate plan wait for hero ai to analyze the signal and generate investigation steps progress detail messages update in the panel while generation runs (for example, reading signal details, threat intelligence, or building the plan) plan actions are disabled until generation finishes the plan appears organized into phases preparation , analysis , and determination what happens during plan generation hero ai analyzes the signal data, observables, threat intelligence, and knowledge base articles it generates investigation steps based on the signal context steps are mapped to available tools and integrations steps that require missing integrations will show an install option if plan generation fails check that hero ai is enabled (see troubleshooting) verify observables exist on the signal ensure threat intelligence enrichment has completed check browser console for errors when evidence or kbas change after a plan exists, use regenerate investigation plan instead of starting from scratch see investigation plan workflow docid\ bde8p71mmp2lbymuzuooi users without permission to install a component from a generated plan see a permissions notification ask an administrator or install the component from library → swimlane content if needed step 6 run agentic investigation on the record when analysis mode is autonomous , the analysis agent runs an end to end investigation without an analyst executing plan steps set analysis mode in the case metadata column on case analysis or on support , then click re investigate in ai alert analysis the agent reads case context, linked threat intelligence observables, knowledge base articles, correlated cases, and tenant components marked visible to hero ai it searches for relevant enrichment tools, runs them, and builds a narrative in the agent investigation panel—for example, a case summary, key observables from ti, step groups with completion counts, enrichment findings, and a final verdict with confidence and recommended actions component inputs and outputs are stored on the record (including attachments) analysis agent request id , analysis agent session , and analysis status on support track the run ( not started , in progress , completed , failed , cancelled ) open the signal after processing completes (unless your tenant allows earlier start) set analysis mode to autonomous on case analysis or support in ai alert analysis , click re investigate to start agentic investigation (which invokes ai soc trigger analysis agent ) watch the agent investigation panel until the status badge shows complete (or failed / cancelled ) review investigation summary , confidence, verdict, and recommended actions in signal summary re investigate again click re investigate after kbas or evidence change materially confirm the dialog—re investigating removes current agent progress and associated data, resets the case verdict to the initial verdict, and cannot be undone update linked knowledge base articles before you confirm if you want the agent to follow new guidance to run agentic investigation automatically when signals arrive (for example, overnight triage), complete enable agentic investigation after import /#enable agentic investigation after import after you finish this walkthrough step 7 review and execute plan steps if a routing rule analysis run or on record re investigate already completed investigation, review the plan, component inputs and outputs, and verdict on the record adjust manual verdict if needed, then continue to remediation or automation for manual investigation, work through plan phases systematically preparation phase purpose validate observables and confirm alert context typical steps enrich observables with multiple ti providers, get endpoint details action review each step before running click review to see what the step will do click run for individual steps or run all steps for the entire phase wait for steps to complete and review results analysis phase purpose verify scope, impact, and lateral movement typical steps search siem/edr for related activity, check for similar infections, get user details action execute steps to gather evidence review results in the step timeline (data from all executed steps, in any phase, is saved to the record and written to the timeline) add notes if you modify or skip steps document findings in investigation comments in the linked case (comments and evidence are added to the case record, not the signal record) determination phase purpose finalize the verdict typical step generate verdict using ai soc case hero ai analysis action run the verdict generation step (or review the verdict if agentic investigation or a routing rule analysis run already set it) review the ai verdict, confidence, and reasoning set a manual verdict if you disagree with the ai verdict add investigation comments explaining your decision in the linked case (not on the signal record) tips for executing steps steps that show install need integrations to be installed first use mark as done if you have completed a step manually outside the system use delete step to remove steps that are not relevant use add additional step to include custom investigation steps step 8 generate remediation plan in the ai alert analysis panel, find the remediation plan section click generate remediation plan when it is enabled (see note below) review the ai generated remediation steps progress detail messages appear while hero ai builds the plan execute remediation steps as appropriate (remediation remains analyst controlled even when you used agentic investigation) document any remediation actions taken in the linked case if the verdict or investigation findings change, use regenerate remediation plan in the same section see investigation plan workflow docid\ bde8p71mmp2lbymuzuooi the generate remediation plan button is disabled only when (1) the investigation plan section does not exist, (2) a plan is currently being generated, or (3) a remediation plan has already been generated in all other scenarios the button is enabled; you decide whether to generate a plan recovery steps from a generate remediation plan output (when you use that feature) are not included when you use create a playbook auto generated investigation playbooks focus on investigation and containment (for example, isolate host) adding recovery into the same automated run would often undo containment immediately (for example, rejoining a host after isolation) you should still automate recovery at scale by maintaining reusable recovery playbooks (for example, standard templates in orchestration → playbooks ) and running them after containment is verified and change management allows, rather than performing one off manual recovery for every case you can seed those playbooks from the remediation plan once, then reuse them see troubleshooting docid\ cknuxqv85k9lu0ocqv218 step 9 document and resolve after completing the investigation, document your findings and resolve the record comments and evidence cannot be added to the signal record when your workflow requires a linked case; add them in the linked case for this record document findings (in the linked case) open the case linked to this signal and add investigation comments explaining what you found why you reached your verdict any actions taken recommendations for follow up update investigation summary with key findings in the case attach any relevant evidence files in the case if needed set the verdict (on the signal) on the record, set manual verdict malicious confirmed threat requiring response suspicious needs further investigation benign false positive, no threat unknown insufficient data to determine set classification (true positive, false positive, unknown) update status set status to resolved when investigation is complete if investigation is still open, use in progress or new per your process escalated may be set automatically when the pending case resolution flow applies your tenant's verdict and confidence rules (see operations and guidance docid\ dsdgtaqeg95dseaf2iat ) you stay on the same case management record (prefix case ) for triage through resolution unless your organization uses an additional linked record step 10 create automation (optional) if this signal pattern will repeat, create automation to handle similar signals in the future create a playbook works after manual investigation or after an agentic investigation session—the suggested components come from the investigation plan or a trigger analysis agent run create a triage rule in the ai alert analysis panel, go to the automation section and click create a triage rule what gets created a record is created in the signal routing rules application (for example, rule 29) a link to the new rule record is shown—click it to open the record you can also open, edit, and enable the rule from application records → signal routing rules or from the routing rule management dashboard what you configure on the record rule name (pre populated from the signal name; edit as needed), rule application (for example, case management ), description (optional), and enabled (off by default—turn on when ready) in the if section, define conditions (for example, signal name contains "x", severity, source, observables) using the condition builder (and/group for multiple criteria) in associated playbook , select a playbook that uses rule execute , then apply the rule to the playbook see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi the new rule is assigned rule order automatically (highest existing order excluding rules associated with ai soc trigger analysis agent via routing rule , then +1), so specific triage rules stay before a correctly configured catch all save the record, then enable the rule when ready what it does when enabled the rule evaluates incoming signals when a signal meets all of the rule's conditions, the associated playbook runs to test without waiting for new signals, use run this rule against pending signals from the rule record's support tab to reorder, enable, or edit rules later, use the routing rule management dashboard (see ai soc applications) create a playbook in the automation section, click create a playbook the playbook opens in a new window (not a slider) the playbook builder opens with suggested components from your investigation plan or an agentic investigation session recovery steps from a remediation plan are not included (by design); see the note under step 8 add recovery through a separate reusable playbook or approved process review and customize the playbook, then save after you save, the associated routing rule is updated with this playbook links to the rule record and the playbook are shown so you can click to open either one enable the rule to run it on future signals to test immediately, use run this rule against pending signals from the routing rule's support tab if the investigation plan changed after you first opened the playbook builder, use recreate playbook in automation to regenerate the associated playbook from the current plan see creating automation docid\ wjpjto3fjno0jio1dyv3s to build or attach a playbook manually (duplicate, orchestration , or generate then cancel template), see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi playbook creation requires browser pop ups to be enabled for your swimlane domain if components are missing, check pop up blocker settings or see troubleshooting enable agentic investigation after import for agentic investigation at scale (for example, overnight triage), create and enable a signal routing rule after you install the solution packages the packages ship the ai soc trigger analysis agent via routing rule playbook and ai soc trigger analysis agent component, but no pre seeded signal routing rule records routing rules reference playbooks in ways that do not import reliably with the package, so you create and enable rules after import on record agentic investigation does not require a routing rule analysts can set analysis mode to autonomous and click re investigate in ai alert analysis —see step 6 run agentic investigation on the record /#step 6 run agentic investigation on the record this section is for routing rule agentic investigation at scale quick path step action 1 confirm ai soc solution and ai soc trigger analysis agent content are installed from library → swimlane content — see installing and configuring ai soc solution /installing and configuring ai soc solution md 2 in orchestration → playbooks , confirm ai soc trigger analysis agent via routing rule exists (it ships disabled ) 3 configure a pat token in the asset used by that playbook — see rbac considerations for ai soc — trigger analysis agent and routing rules docid 4 enable ai soc trigger analysis agent via routing rule in orchestration when you are ready to use it 5 create a signal routing rules record ( application records → signal routing rules , or routing rule management → add new rule ) 6 set if conditions for a catch all agentic rule, set rule order to a high value such as 99999 so more specific routing rules evaluate first associated playbook must be ai soc trigger analysis agent via routing rule (required—not any high order default rule), then apply rule to playbook optionally name the rule ai agentic investigation 7 enable the rule and test with run rule against pending signals on the rule support tab requirement the catch all for unmatched or first seen signals must associate ai soc trigger analysis agent via routing rule setting a high rule order without that playbook does not configure agentic catch all behavior, and create a triage rule may assign new rules an order after your catch all see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi for condition design, rule order, and troubleshooting, see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi and rbac considerations for ai soc docid\ jl6dsw0qjbkpq iojdglp common first time mistakes to avoid mistake 1 generating plan before enrichment completes problem plan may be incomplete without ti context solution wait for threat intelligence status to show complete before generating a plan or starting investigation mistake 1a expecting a plan or verdict while status is processing problem signals in processing have not yet completed evaluation; generate plan , re investigate , and ai verdict are not ready solution wait until status changes to new , closed , or escalated before investigating or judging readiness mistake 2 not claiming signals problem multiple analysts may work on the same signal solution always claim signals you are investigating mistake 3 skipping evidence and context problem missing important context from kb articles, threat intelligence, or correlation solution review all evidence areas (knowledge base, threat intelligence, correlation, rules) before generating a plan or clicking re investigate mistake 4 not documenting deviations problem future investigations may repeat unnecessary steps solution add notes when you skip or modify ai suggested steps mistake 5 forgetting to set manual verdict problem signals resolved without verdicts do not improve ai learning solution always set manual verdict when resolving signals next steps after completing your first investigation review the workflow understand how signals flow through your soc read best practices review operational best practices docid\ ww gfwujljt7opjduu8vg for optimization tips learn about applications see ai soc applications docid\ uosuzrpsl6hfe9d6br5az for detailed application walkthroughs understand troubleshooting bookmark troubleshooting docid\ cknuxqv85k9lu0ocqv218 for common issues