Skip to main content

Generate Deep Threat Research

N
Written by Nataliia Pukaliak

Use AI-powered Deep Threat Research to transform threat reports into comprehensive threat intelligence. It analyzes adversary activity and provides comprehensive insights, including threat summary, investigation and mitigation recommendations, MITRE ATT&CK mappings, related detections, malicious activity simulation, and interactive visualizations such as Attack Flow, Cyber Kill Chain, Pyramid of Pain, and Diamond Model.

Deep Threat Research helps security teams quickly understand emerging threats, analyze adversary tactics and techniques, identify relevant detection opportunities, and improve threat investigation and response workflows.

To generate a Deep Threat Research:

  1. Open Prime Architect and go to the Agentic Threat Research mode.

  2. Click Code Editor in the upper right corner and paste the text of a threat report.

    Tip: To remove all content from the editor, click the Clear Editor button.

  3. Select the Analyze button.

  4. Select Deep Threat Research from the list.

  5. Click the Enter icon to proceed.

View the Results

The results of a Deep Threat Research analysis are displayed sequentially and organized into several sections providing an overview of the analyzed threat, investigation guidance, recommended actions, and related security context.

Summary

Provides a concise overview of the analyzed threat, including key information extracted from the threat report and the main findings generated during the analysis.

Investigation

Provides recommended actions and guidance for investigating the threat.

Mitigation

Provides recommended actions for reducing the impact of the threat based on security best practices.

Response

Provides recommended response actions to help security teams address the threat, minimize risks, and take appropriate steps after identifying malicious activity.

Actors

Displays threat actors associated with the analyzed threat.

Mitre ATT&CK Techniques

Displays MITRE ATT&CK techniques associated with the threat, showing the techniques and behaviors used by adversaries during the analyzed activity.

Searched

Provides relevant detections from the SOC Prime Platform that cover the analyzed activity. Click the detection tile to view the detection on the right.

You can perform the following actions with the detection rule:

  • Copy the detection rule to the clipboard and paste it into your system. For this, click the Copy to Clipboard button.

  • Translate the detection rule into a different language. For this, select the Translate button, select the target language from the dropdown, and select Translate. For details, follow this guide.

  • Download a detection rule as a file by selecting Save As > File.txt or save a rule to a custom repository by selecting Save As > New Rule.

  • Validate detection’s syntax and structure. For details, follow this guide.

Generated

Provides AI-generated detections that cover the analyzed activity. Click the detection tile to view the detection on the right.

You can perform the following actions with the detection rule:

  • Copy the detection rule to the clipboard and paste it into your system. For this, click the Copy to Clipboard button.

  • Translate the detection rule into a different language. For this, select the Translate button, select the target language from the dropdown, and select Translate. For details, follow this guide.

  • Download a detection rule as a file by selecting Save As > File.txt or save a rule to a custom repository by selecting Save As > New Rule.

  • Validate detection’s syntax and structure. For details, follow this guide.

Simulation

Provides simulations of malicious activity associated with the threat. Click the simulation tile to view its details on the right.

Explore visualizations

Attack Flow

Attack Flow displays a visual representation of the adversary's attack sequence based on the MITRE ATT&CK framework. The diagram illustrates how the attack progresses through different stages and techniques, helping you understand the overall attack path. Select Diagram or Matrix to see the visualization of the adversary activity.

On the visualization you can drag and drop the blocks, open the visualization in full screen, change scale, or return to the starting point.

To export Attack Flow as MMD, select the Download icon.

Cyber Kill Chain

Cyber Kill Chain visualizes the seven stages of the Lockheed Martin Cyber Kill Chain and shows how the analyzed threat progresses during a successful intrusion.

The visualization helps you understand which stages of the Cyber Kill Chain the analyzed threat covers and identify potential detection opportunities.

The Cyber Kill Chain includes the following stages:

  • Reconnaissance

  • Weaponization

  • Delivery

  • Exploitation

  • Installation

  • Command & Control

  • Actions on Objectives

Click each stage to see its role in the chain and the typical adversary tradecraft involved.

Pyramid of Pain

The Pyramid of Pain visualizes six tiers of threat indicators based on the Pyramid of Pain threat intelligence framework.

The visualization shows indicators ranked by the level of difficulty they create for adversaries when detected and blocked. It ranges from low-pain indicators, such as Hash Values, which are easy for adversaries to change, to high-pain indicators, such as Tactics, Techniques, and Procedures (TTPs), which require significant effort to modify.

The Pyramid of Pain categorizes threat indicators into the following six levels:

  • Hash Values

  • IP Addresses

  • Domain Names

  • Network/Host Artifacts

  • Tools

  • Tactics, Techniques, and Procedures (TTPs)

The panel on the right displays the number of indicators extracted for each tier and the corresponding pain level.

In the upper-right corner, you can see a total extracted indicators count showing the overall number of indicators identified during the analysis.

To explore indicators by category, click the corresponding pyramid tier and view the list of indicators associated with that tier below the pyramid.

Diamond Model

Diamond Model visualizes the four core elements of an analyzed threat based on the Diamond Model of Intrusion Analysis and helps you understand relationships between threat entities and how adversary activity is structured.

The Diamond Model displays the following vertices:

  • Adversary – threat actor/organization involved in the activity

  • Capability – tools, malware, and techniques used by adversaries

  • Victim – targeted entities or organizations

  • Infrastructure – systems, resources, and services used to conduct the activity

Each vertex displays the number of extracted entities associated with it.

The diagram also represents connections between vertices using directional relationships, including Connects To, Uses, Exploits, Targets, Develops, and Deployed via. Hover over a vertex to highlight it and view the related connections.

Each vertex displays the number of extracted entities associated with it. An Extracted counter displays the total number of entities identified during the analysis.

Click the vertices to view the corresponding entity list below the diagram.

The diagram also includes meta-features, such as Phase, Result, Direction, Methodology, Confidence, which provide additional context about the analyzed activity.

Did this answer your question?