Investigation Plan Workflow
the generate plan action creates an ai powered investigation plan organized into phases when signal context, evidence, or knowledge base guidance changes, regenerate investigation plan or regenerate remediation plan refreshes the plan without starting from an empty record the ai soc trigger analysis agent can also produce a plan and execute steps in one pass—see getting started docid\ p7qjquayekczhpxeppwcp and operations and guidance docid\ dsdgtaqeg95dseaf2iat understanding how to use each phase effectively improves investigation efficiency understanding plan phases preparation phase purpose validate observables and confirm alert context when to use first phase after generating a plan typical steps enrich observables with multiple ti providers (abuseipdb, recorded future, virustotal) get endpoint details from edr/xdr platforms validate observable types and values best practice complete preparation before moving to analysis to ensure you have accurate context analysis phase purpose verify scope, impact, and lateral movement when to use after preparation is complete typical steps search siem/edr for related activity check for similar infections across endpoints get user and asset details search for network connections and data transfers review web activity logs best practice execute analysis steps systematically to build a complete picture determination phase purpose finalize the verdict based on collected evidence when to use after analysis is complete typical step generate verdict using ai soc case hero ai analysis best practice review all evidence before generating the final verdict automation phase purpose create automation for repeatable signal patterns when to use after resolving signals that will likely recur options create a triage rule route similar signals automatically create a playbook automate investigation steps from the plan (or from an agentic investigation session) recreate playbook regenerate the associated playbook from the current investigation plan when the plan changed—see creating automation docid\ wjpjto3fjno0jio1dyv3s investigation playbooks duplicate or build in orchestration and attach on a rule record — see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi best practice create automation for patterns you see frequently remediation plan purpose generate post investigation remediation guidance when to use after confirming a malicious verdict how to use click generate remediation plan in the ai alert analysis panel updating when the verdict or investigation findings change, click regenerate remediation plan in the same section best practice review remediation steps before executing, especially those that modify systems working with plan steps before running steps review each step to understand what it will do check if required integrations are installed verify you have appropriate permissions consider the impact of steps that modify systems while running steps monitor step execution in the timeline review results as they complete add notes if steps produce unexpected results document any manual actions taken outside the system after running steps review all step results before making decisions update investigation comments with findings re run analysis if new evidence changes the context mark steps as done if completed manually managing steps add additional step insert custom steps specific to your organization delete step remove steps that are not relevant to this investigation mark as done record steps completed outside the system mark as open reopen completed steps to run again plan generation best practices before generating ensure threat intelligence enrichment has completed review evidence panels (knowledge base, threat intelligence, correlation) verify observables are present on the signal check that hero ai is enabled and available during generation wait for plan generation to complete (may take 30 60 seconds) do not navigate away from the record during generation watch progress detail messages in ai alert analysis while generate plan , regenerate investigation plan , or regenerate remediation plan runs messages update in real time (for example, reading signal details, threat intelligence, or building the plan) up to three recent status lines may appear; plan actions are disabled until the agent finishes or you cancel check browser console if generation fails after generation review the plan before executing steps understand what each step will do identify any missing integrations consider adding custom steps if needed updating investigation and remediation plans when an investigation plan already exists, regenerate investigation plan appears in ai alert analysis use it when new evidence, updated kbas, or signal field changes mean the current plan is incomplete or out of date situation recommended option threat intelligence enrichment finished after the plan was generated keep executed steps or start from beginning new observables or correlation data changed the investigation scope keep executed steps if prior step results are still valid kbas were updated with new investigation guidance start from beginning if prior steps conflict with new guidance you deleted or heavily edited plan steps and want a fresh ai proposal start from beginning steps open the signal record and scroll to ai alert analysis click regenerate investigation plan choose keep executed steps (hero ai rebuilds remaining and new steps; completed results stay on the record and timeline) or start from beginning (replaces the entire plan, same process as generate plan ) if you chose keep executed steps , enter optional guidance when prompted (for example, focus on a new observable) confirm your choice progress detail messages appear until the updated plan is shown review the regenerated plan before running new steps after a remediation plan exists, regenerate remediation plan appears in the remediation plan section choose confirm to proceed or cancel to keep the current plan review each remediation step after regeneration, especially if the manual or ai verdict changed wait for threat intelligence status to show complete before generating or regenerating a plan so hero ai has full enrichment context see troubleshooting docid\ cknuxqv85k9lu0ocqv218 if generation fails or returns unexpected steps