Skip to main content

Generate Attack Flow with AI

N
Written by Nataliia Pukaliak

Use AI to generate Attack Flow from a threat report, visualizing the adversary activity in a structured way. This feature has been inspired by the open-source Attack Flow project to help defenders move from tracking individual adversary behaviors to tracking the sequences of behaviors that adversaries employ to achieve their goals.

Key benefits:

  • Reduces the time required to understand the attack.

  • Provides visualized attack flows that directly inform detection rule logic by identifying TTP chains, enabling proactive defense without relying on IOCs.

  • Helps prioritize threats when linked to existing telemetry or detection rules by mapping them to known gaps or current alerts.

  • Provides machine-readable MMD export for easier integration with detection engineering workflows.

  • Gives engineers a visual depiction that aids communication with non-technical stakeholders, management, and executives.

To generate Attack Flow with AI:

  1. Open Uncoder AI and go to the New version.

  2. Paste the text of a threat report into the editor on the right.

  3. Select the Attack Flow task from the task options. Alternatively, you can click the Tasks button and select Attack Flow from the list.

  4. Click the Enter icon to proceed.

  5. Hover over the Diagram tile and select Show to view the threat report in a diagram representation. You can do the following:

    • Drag and drop the blocks

    • Open the visualization in full screen

    • Change scale

    • Return to the starting point

  6. Hover over the Matrix tile and select Show to view the threat report in a matrix representation. You can do the following:

    • Open the visualization in full screen

    • Return to the starting point

Next Steps


Once the Attack Flow has been generated, you can:

Did this answer your question?