Analyze, investigate, and respond to incidents and alerts using the power of AI.
TrendAI™ Companion is an AI-powered cybersecurity advisor integrated into TrendAI Vision One™ to assist in investigating, analyzing, and responding to security incidents and alerts.
Important
|
The following table outlines the available functions in TrendAI™ Companion.
|
Action
|
Description
|
Supported Apps
|
||
|
Open TrendAI™ Companion
|
Click the TrendAI™ Companion icon (
|
All apps and screens in TrendAI Vision One™
|
||
|
Explain a Workbench alert
|
During alert investigations, TrendAI™ Companion can explain the alert displayed on your screen.
You can use prompts such as
Provide an explanation of this Workbench alert. |
|
||
|
Add response to case
|
Click Add to Case to add a response as a case note.
|
|
||
|
Add response to a Workbench alert note
|
Click Add to Note to add a response to the alert
notes.
|
|
||
|
Generate search queries
|
When using the XDR Data Explorer app, TrendAI™ Companion can help you write search queries and decide what is the appropriate search method
for your query.
|
|
||
|
Add generated search query to search box
|
Click Add to Query to add the generated query to the search box.
TrendAI™ Companion automatically selects the suggested search method when adding queries to the search
box.
|
|
||
|
Explain CLI commands in Workbench alerts, Search results, and Observed Attack Techniques
events
|
Right-click a CLI command element (
TrendAI™ Companion can also provide explanations for CLI commands that include base64-encoded elements.
|
|
||
|
Explain Observed Attack Techniques events
|
To learn about an event, right-click an event or click
|
|
||
|
Create an investigation summary report for a case in Case Management
|
Do one of the following:
TrendAI™ Companion generates a threat investigation and remediation report for the case, which you can
preview, edit, and download by going to . This action is only available for Workbench cases with a “True positive” finding.
|
|||
|
Summarize progress notes for a case in Case Management
|
Do one of the following:
TrendAI™ Companion summarizes all the notes created in the case since last time a summarized progress
note was created. Summarized progress notes are helpful when transferring a case to
a new owner.
|
|||
|
Summarize Workbench insights
|
During insight investigations, TrendAI™ Companion can summarize the attack context of the insight displayed on the screen.
You can use prompts such as
Summarize the Workbench insight. |
Workbench (only during Workbench insights investigations)
|
||
|
Receive proactive guidance on noteworthy and false-positive Workbench insights
|
TrendAI™ Companion uses labeled detection data to classify Workbench alerts into noteworthy or false-positive
alerts to proactively recommend insights that may require further analysis.
|
Workbench
|
||
|
Receive guidance on threat investigation workflows
|
TrendAI™ Companion can suggest next steps during threat investigation and response related to a Workbench
insight.
You can use prompts such as
What should I do next? |
Workbench (only during Workbench insights investigations)
|
