Use AI to generate Attack Flow from a threat report, visualizing the adversary activity in a structured way. This feature has been inspired by the open-source Attack Flow project to help defenders move from tracking individual adversary behaviors to tracking the sequences of behaviors that adversaries employ to achieve their goals.
Key benefits:
Reduces the time required to understand the attack.
Provides visualized attack flows that directly inform detection rule logic by identifying TTP chains, enabling proactive defense without relying on IOCs.
Helps prioritize threats when linked to existing telemetry or detection rules by mapping them to known gaps or current alerts.
Provides machine-readable MMD export for easier integration with detection engineering workflows.
Gives engineers a visual depiction that aids communication with non-technical stakeholders, management, and executives.
To generate Attack Flow with AI:
Open Uncoder AI and go to the New version.
Paste the text of a threat report into the editor on the right.
Select the Attack Flow task from the task options. Alternatively, you can click the Tasks button and select Attack Flow from the list.
Click the Enter icon to proceed.
Hover over the Diagram tile and select Show to view the threat report in a diagram representation. You can do the following:
Drag and drop the blocks
Open the visualization in full screen
Change scale
Return to the starting point
Hover over the Matrix tile and select Show to view the threat report in a matrix representation. You can do the following:
Next Steps
Once the Attack Flow has been generated, you can:
Export it as MMD
Use the identified TTS to select detection content in Threat Detection Marketplace, write it on your own, or generate it with AI
