Skip to main content

How to Generate Attack Flow with AI

S
Written by Sergey Bayrachny

Use AI to generate Attack Flow from a threat report, visualizing the adversary activity in a structured way. This feature has been inspired by the open-source Attack Flow project to help defenders move from tracking individual adversary behaviors to tracking the sequences of behaviors that adversaries employ to move towards their goals:

  • Reduces the time to understand the attack

  • Visualized attack flows can directly inform detection rule logic by identifying TTP chains, enabling proactive defense without relying on IOCs

  • When linked to existing telemetry or detection rules, it helps prioritize threats that map to known gaps or current alerts

  • Machine-readable MMD export for easier integration with detection engineering workflows

  • Gives engineers a visual depiction that aids communication with non-technical stakeholders, management, and executives

  1. Go to the Generate mode in Uncoder AI.

  2. Select Threat Report/IOCs as the input type.

  3. Paste or upload the threat report and select Attack Flow as the output.

  4. Click Generate.

  5. The output panel shows the Attack Flow visualization of the threat report. You can do the following:

    1. Drag and drop the blocks

    2. Open the visualization in full screen

    3. Change scale

    4. Return to the starting point

    5. Export the Attack Flow as MMD

Next Steps


Once the Attack Flow has been generated, you can:

  • Export it as MMD

  • Use the identified TTS to select detection content in Threat Detection Marketplace, write it on your own, or generate it with AI

  • Generate a short or full summary for your threat report

  • Generate a rule/query from your threat report

  • Make custom actions on your threat report with AI

Did this answer your question?