Skip to main content

Agentic Threat Research Overview

N
Written by Nataliia Pukaliak

Agentic Threat Research is an AI-assisted workspace within Uncoder AI that supports detection engineering and threat research tasks. It allows you to interact with AI through a chat-based interface by entering custom prompts or by selecting Agentic AI tools designed to guide the AI’s behavior for specific use cases. The AI model uses an internal knowledge base as the primary source of information for generating responses and combines it with user input and contextual data to generate relevant responses and outputs.

Workspace Layout

The Agentic Threat Research workspace consists of the following areas:

  • Left panel – Contains list of chats and projects. The panel can be collapsed or expanded.

  • Central chat interface – Used to create custom prompts and use agentic AI tools.

  • Code Editor – Located on the right side of the workspace and used for long inputs such as detection rules/queries or threat reports. Expand the section by clicking the Code Editor button.

Chats and Projects

Chats can be organized into projects to be grouped under a shared context. Follow this guide to learn more.

To create a new chat, click the New Chat button on the left panel.

Existing chats and projects are displayed in the left panel. Use the search bar to search for chats or projects.

Agentic AI Tools

Agentic AI tools guide the AI model in performing specific actions. Available tools are organized into three categories: Generate, Discover, and Analyze. Each category contains a set of actions that help you perform detection engineering and threat research workflows. Select a category to view available AI tools and follow the below links to learn how to use them.

Generate

  • Attack Flow – Visualize adversary activity from a threat report in a structured way

  • Behavior Sigma Rule – Generate behavior rules in Sigma format from threat intel

Discover

Analyze

  • Short Summary – Generate a concise overview of detection logic or threat descriptions

  • Full Summary – Get a detailed explanation of detection logic or threat descriptions

  • Decision Tree – Understand how a detection rule or query works step by step

  • AIDEFEND Framework – Gain comprehensive insights into threats, including behavior, impact, and detection

  • Deep Threat Research – Analyze a threat and generate a comprehensive threat intelligence, including threat summary, attack flow visualization, related detections, etc

Did this answer your question?