Projects allow you to group multiple chats in the Agentic Threat Search mode and define a shared context that is automatically applied to all chats within the project. You can define this context by entering instructions as prompts or by attaching files, providing additional knowledge and reference material.
For example, you can provide your data schema, log sources, guidance on detection structure and expected output, specify key rules such as clarifying assumptions, using precise technical language, provide tuning ideas, etc. Additionally, you can upload files such as internal playbooks, incident reports, environment documentation, or other security-related reference materials.
Create a project
Navigate to Projects in the left sidebar and select Create Project.
In the modal, provide a name for your project.
Define the project context using one of the following methods:
Click the pencil icon in the Instructions section, enter a prompt that defines how the AI should behave within the project, and select Save.
You can edit these instructions using the pencil icon.
Click the plus (+) icon in the Resources section, select Upload Files, and choose the file you want to use as additional context for the project. You can upload up to 5 files each with a maximum size of 15 MB and up to 500k tokens. Supported file formats include PDF, TXT, CSV, JSON, PNG, JPG/JPEG. A PDF cannot have more than 1000 pages.
To remove an uploaded file, click the cross (×) icon next to it.
Note: The instructions and resources you add are applied to all chats within the project.
Manage Chats in a Project
To add chats to a project, open the project and start a new interaction there. All chats within the project are available under the chat panel.
To rename or delete the chats within the project, click the three-dot menu and select one of the options.
Manage Projects
To rename a project, go to Projects in the sidebar, click the three-dot menu and select Rename.
To delete a project, go to Projects in the sidebar, click the three-dot menu and select Delete.
