Skip to main content

How to Generate Behavior Rules and Queries with AI

S
Written by Sergey Bayrachny

Generate a behavior rule/query from a threat report or any other description of malicious activity with AI.

  1. Go to the Generate mode in Uncoder AI.

  2. Select Threat Report/IOCs as the input type.

  3. Select Behavior Rule/Query as the output

  4. Select the platform (language) of the output rule/query (start typing the platform name in the dropdown to filter the options).

  5. Optionally, customize the rule:

    1. Set a different data schema.

    2. Set additional customization profiles (note that configuring these profiles is available only with the Enterprise subscription):

  6. Paste the text of a threat report or any other description of a malicious activity into the input panel and click Generate.

  7. Wait for the AI to generate a rule/query. Once the output is ready, check it and make modifications if needed.

Next Steps


After you've ensured that the generated rule/query fits your needs and preferences, you can:

  • Save it to a custom repository

  • Copy it to the clipboard and paste it into your system or download the rule/query as a file

  • Deploy it to a SIEM or push it to a Git repository

  • Translate it into a different language

  • Validate its syntax and structure

  • Optimize the query

  • Group query results

  • Get its short summary, full summary, or decision tree

  • Make custom modifications with AI

Supported Platforms


To find out what platforms (languages) are supported, see this article.

Did this answer your question?