Agentic Threat Research is an AI-assisted workspace within Uncoder AI that supports detection engineering and threat research tasks. It allows you to interact with AI through a chat-based interface by entering custom prompts or by selecting Agentic AI tools designed to guide the AI’s behavior for specific use cases. The AI model uses an internal knowledge base as the primary source of information for generating responses and combines it with user input and contextual data to generate relevant responses and outputs.
Workspace Layout
The Agentic Threat Research workspace consists of the following areas:
Left panel – Contains list of chats and projects. The panel can be collapsed or expanded.
Central chat interface – Used to create custom prompts and use agentic AI tools.
Code Editor – Located on the right side of the workspace and used for long inputs such as detection rules/queries or threat reports. Expand the section by clicking the Code Editor button.
Chats and Projects
Chats can be organized into projects to be grouped under a shared context. Follow this guide to learn more.
To create a new chat, click the New Chat button on the left panel.
Existing chats and projects are displayed in the left panel. Use the search bar to search for chats or projects.
Agentic AI Tools
Agentic AI tools guide the AI model in performing specific actions. Available tools are organized into three categories: Generate, Discover, and Analyze. Each category contains a set of actions that help you perform detection engineering and threat research workflows. Select a category to view available AI tools and follow the below links to learn how to use them.
Generate
Attack Flow – Visualize adversary activity from a threat report in a structured way
Behavior Sigma Rule – Generate behavior rules in Sigma format from threat intel
Discover
Active Threats Search – Search for relevant Active Threats news items
Detections Search – Search for detections on the SOC Prime Platform
MISP Search – Query your MISP instance for threat intelligence indicators
Analyze
Short Summary – Generate a concise overview of detection logic or threat descriptions
Full Summary – Get a detailed explanation of detection logic or threat descriptions
Decision Tree – Understand how a detection rule or query works step by step
AIDEFEND Framework – Gain comprehensive insights into threats, including behavior, impact, and detection
Deep Threat Research – Analyze a threat and generate a comprehensive threat intelligence, including threat summary, attack flow visualization, related detections, etc
