Use AI-powered Deep Threat Research to transform threat reports into comprehensive threat intelligence. It analyzes adversary activity and provides comprehensive insights, including threat summary, investigation and mitigation recommendations, MITRE ATT&CK mappings, related detections, malicious activity simulation, and interactive visualizations such as Attack Flow, Cyber Kill Chain, Pyramid of Pain, and Diamond Model.
Deep Threat Research helps security teams quickly understand emerging threats, analyze adversary tactics and techniques, identify relevant detection opportunities, and improve threat investigation and response workflows.
To generate a Deep Threat Research:
Open Prime Architect and go to the Agentic Threat Research mode.
Click Code Editor in the upper right corner and paste the text of a threat report.
Tip: To remove all content from the editor, click the Clear Editor button.
Select the Analyze button.
Select Deep Threat Research from the list.
Click the Enter icon to proceed.
View the Results
The results of a Deep Threat Research analysis are displayed sequentially and organized into several sections providing an overview of the analyzed threat, investigation guidance, recommended actions, and related security context.
Summary
Provides a concise overview of the analyzed threat, including key information extracted from the threat report and the main findings generated during the analysis.
Investigation
Provides recommended actions and guidance for investigating the threat.
Mitigation
Provides recommended actions for reducing the impact of the threat based on security best practices.
Response
Provides recommended response actions to help security teams address the threat, minimize risks, and take appropriate steps after identifying malicious activity.
Actors
Displays threat actors associated with the analyzed threat.
Mitre ATT&CK Techniques
Displays MITRE ATT&CK techniques associated with the threat, showing the techniques and behaviors used by adversaries during the analyzed activity.
Searched
Provides relevant detections from the SOC Prime Platform that cover the analyzed activity. Click the detection tile to view the detection on the right.
You can perform the following actions with the detection rule:
Copy the detection rule to the clipboard and paste it into your system. For this, click the Copy to Clipboard button.
Translate the detection rule into a different language. For this, select the Translate button, select the target language from the dropdown, and select Translate. For details, follow this guide.
Download a detection rule as a file by selecting Save As > File.txt or save a rule to a custom repository by selecting Save As > New Rule.
Validate detection’s syntax and structure. For details, follow this guide.
Generated
Provides AI-generated detections that cover the analyzed activity. Click the detection tile to view the detection on the right.
You can perform the following actions with the detection rule:
Copy the detection rule to the clipboard and paste it into your system. For this, click the Copy to Clipboard button.
Translate the detection rule into a different language. For this, select the Translate button, select the target language from the dropdown, and select Translate. For details, follow this guide.
Download a detection rule as a file by selecting Save As > File.txt or save a rule to a custom repository by selecting Save As > New Rule.
Validate detection’s syntax and structure. For details, follow this guide.
Simulation
Provides simulations of malicious activity associated with the threat. Click the simulation tile to view its details on the right.
Explore visualizations
Attack Flow
Attack Flow displays a visual representation of the adversary's attack sequence based on the MITRE ATT&CK framework. The diagram illustrates how the attack progresses through different stages and techniques, helping you understand the overall attack path. Select Diagram or Matrix to see the visualization of the adversary activity.
On the visualization you can drag and drop the blocks, open the visualization in full screen, change scale, or return to the starting point.
To export Attack Flow as MMD, select the Download icon.
Cyber Kill Chain
Cyber Kill Chain visualizes the seven stages of the Lockheed Martin Cyber Kill Chain and shows how the analyzed threat progresses during a successful intrusion.
The visualization helps you understand which stages of the Cyber Kill Chain the analyzed threat covers and identify potential detection opportunities.
The Cyber Kill Chain includes the following stages:
Reconnaissance
Weaponization
Delivery
Exploitation
Installation
Command & Control
Actions on Objectives
Click each stage to see its role in the chain and the typical adversary tradecraft involved.
Pyramid of Pain
The Pyramid of Pain visualizes six tiers of threat indicators based on the Pyramid of Pain threat intelligence framework.
The visualization shows indicators ranked by the level of difficulty they create for adversaries when detected and blocked. It ranges from low-pain indicators, such as Hash Values, which are easy for adversaries to change, to high-pain indicators, such as Tactics, Techniques, and Procedures (TTPs), which require significant effort to modify.
The Pyramid of Pain categorizes threat indicators into the following six levels:
Hash Values
IP Addresses
Domain Names
Network/Host Artifacts
Tools
Tactics, Techniques, and Procedures (TTPs)
The panel on the right displays the number of indicators extracted for each tier and the corresponding pain level.
In the upper-right corner, you can see a total extracted indicators count showing the overall number of indicators identified during the analysis.
To explore indicators by category, click the corresponding pyramid tier and view the list of indicators associated with that tier below the pyramid.
Diamond Model
Diamond Model visualizes the four core elements of an analyzed threat based on the Diamond Model of Intrusion Analysis and helps you understand relationships between threat entities and how adversary activity is structured.
The Diamond Model displays the following vertices:
Adversary – threat actor/organization involved in the activity
Capability – tools, malware, and techniques used by adversaries
Victim – targeted entities or organizations
Infrastructure – systems, resources, and services used to conduct the activity
Each vertex displays the number of extracted entities associated with it.
The diagram also represents connections between vertices using directional relationships, including Connects To, Uses, Exploits, Targets, Develops, and Deployed via. Hover over a vertex to highlight it and view the related connections.
Each vertex displays the number of extracted entities associated with it. An Extracted counter displays the total number of entities identified during the analysis.
Click the vertices to view the corresponding entity list below the diagram.
The diagram also includes meta-features, such as Phase, Result, Direction, Methodology, Confidence, which provide additional context about the analyzed activity.
