Use AI-powered Deep Threat Research to transform threat reports into comprehensive threat intelligence. It analyzes adversary activity and provides comprehensive insights, including threat summary, investigation and mitigation recommendations, MITRE ATT&CK mappings, related detections, and malicious activity simulation.
Deep Threat Research helps security teams quickly understand emerging threats, analyze adversary tactics and techniques, identify relevant detection opportunities, and improve threat investigation and response workflows.
To generate a Deep Threat Research:
Open Prime Architect and go to the Agentic Threat Research mode.
Click Code Editor in the upper right corner and paste the text of a threat report.
Tip: To remove all content from the editor, click the Clear Editor button.
Select the Analyze button.
Select Deep Threat Research from the list.
Click the Enter icon to proceed.
View the Results
The results of a Deep Threat Research analysis are displayed sequentially and organized into several sections providing an overview of the analyzed threat, investigation guidance, recommended actions, and related security context.
Summary
Provides a concise overview of the analyzed threat, including key information extracted from the threat report and the main findings generated during the analysis.
Investigation
Provides recommended actions and guidance for investigating the threat.
Mitigation
Provides recommended actions for reducing the impact of the threat based on security best practices.
Response
Provides recommended response actions to help security teams address the threat, minimize risks, and take appropriate steps after identifying malicious activity.
Actors
Displays threat actors associated with the analyzed threat.
Mitre ATT&CK Techniques
Displays MITRE ATT&CK techniques associated with the threat, showing the techniques and behaviors used by adversaries during the analyzed activity.
Attack Flow
Displays a visual representation of the adversary's attack sequence based on the MITRE ATT&CK framework. The diagram illustrates how the attack progresses through different stages and techniques, helping you understand the overall attack path. Select Diagram or Matrix to see the visualization of the adversary activity.
On the visualization you can drag and drop the blocks, open the visualization in full screen, change scale, or return to the starting point.
To export Attack Flow as MMD, select the Download icon.
Searched
Provides relevant detections from the SOC Prime Platform that cover the analyzed activity. Click the detection tile to view the detection on the right.
You can perform the following actions with the detection rule:
Copy the detection rule to the clipboard and paste it into your system. For this, click the Copy to Clipboard button.
Translate the detection rule into a different language. For this, select the Translate button, select the target language from the dropdown, and select Translate. For details, follow this guide.
Download a detection rule as a file by selecting Save As > File.txt or save a rule to a custom repository by selecting Save As > New Rule.
Validate detection’s syntax and structure. For details, follow this guide.
Generated
Provides AI-generated detections that cover the analyzed activity. Click the detection tile to view the detection on the right.
You can perform the following actions with the detection rule:
Copy the detection rule to the clipboard and paste it into your system. For this, click the Copy to Clipboard button.
Translate the detection rule into a different language. For this, select the Translate button, select the target language from the dropdown, and select Translate. For details, follow this guide.
Download a detection rule as a file by selecting Save As > File.txt or save a rule to a custom repository by selecting Save As > New Rule.
Validate detection’s syntax and structure. For details, follow this guide.
Simulation
Provides simulations of malicious activity associated with the threat. Click the simulation tile to view its details on the right.
