diff --git a/docs/xdr/features/modules/elevate_activate.md b/docs/xdr/features/modules/elevate_activate.md new file mode 100644 index 0000000000..22a32162eb --- /dev/null +++ b/docs/xdr/features/modules/elevate_activate.md @@ -0,0 +1,41 @@ +# Activate Elevate on a workspace + +This article explains how to enable the Elevate investigation agent on your workspace so it automatically analyzes all incoming alerts. + +## Prerequisites + +- Your Sekoia plan includes the Elevate add-on. To verify, navigate to **Settings > Subscriptions** and confirm that an Elevate entry appears alongside your current plan. +- You have administrator-level access to the workspace. + +## Activate the agent + +The Elevate investigation agent is available as soon as the Elevate add-on is enabled on your workspace. The agent is disabled by default so you control when quota consumption begins. + +!!! warning "Quota consumption starts immediately" + Enabling the agent triggers analysis of all new incoming alerts across all communities in the workspace. Each analysis consumes one unit of your monthly investigation quota. Review your quota allocation before activating. + +To activate the agent: + +1. Navigate to **Settings > AI agent**. +2. Select **Investigation agent** under the **Workspace** section. +3. Toggle **Auto-analyze alerts** to enabled. + +> 📸 [SCREENSHOT SUGGESTION: Settings > AI agent panel showing the Investigation agent section with the Auto-analyze alerts toggle switched to the enabled position. | ALT TEXT: AI agent settings panel with the Auto-analyze alerts toggle enabled.] + +Once enabled, the agent analyzes every new alert that arrives across all communities in the workspace. + +## Add agent instructions + +The **Instructions** field lets you provide contextual guidance the agent takes into account when analyzing alerts. Use it to describe environment-specific context, known legitimate behaviors, or investigation priorities specific to your organization. + +[PLACEHOLDER: Confirm field format, character limit, and add 1-2 examples of effective instructions.] + +## Result + +New incoming alerts are automatically analyzed by the Elevate agent. The **Verdict** column in the alert list updates as each investigation completes. + +## Related links + +- [Limit auto-analysis to specific rules](/xdr/features/modules/elevate_rule_filter.md): How to restrict which alerts Elevate analyzes to control quota usage. +- [Override Elevate settings for a community](/xdr/features/modules/elevate_community_override.md): How to enable or disable Elevate independently for a specific community. +- [Manage your Elevate investigation quota](/xdr/features/modules/elevate_quota.md): How to monitor and optimize your monthly investigation quota. diff --git a/docs/xdr/features/modules/elevate_analysis_states.md b/docs/xdr/features/modules/elevate_analysis_states.md new file mode 100644 index 0000000000..e0e2c0b7bf --- /dev/null +++ b/docs/xdr/features/modules/elevate_analysis_states.md @@ -0,0 +1,27 @@ +# Elevate analysis states + +The **Verdict** column in the alert list displays the current state of the Elevate AI investigation for each alert. This article describes every possible state and what it means. + +> 📸 [SCREENSHOT SUGGESTION: Alert list view with the Verdict column highlighted, showing a variety of AI analysis states including "In progress", "Confirmed Attack", "AI analysis failed", "AI analysis timeout", and "AI limit reached". | ALT TEXT: Alert list showing different Elevate verdict states in the Verdict column.] + +## States reference + +| State | Description | +|---|---| +| **In progress** | The AI agent is currently analyzing the alert. Results will be available shortly. | +| **True Positive** | The agent concluded the alert represents a real threat. A confidence score and explanation are available in the AI Investigation tab. | +| **False Positive** | The agent concluded the alert is benign. A confidence score and explanation are available in the AI Investigation tab. | +| **AI analysis failed** | The analysis could not be completed due to an internal error. You can retry by reassigning the alert to Roy. | +| **AI analysis timeout** | The analysis request timed out before completing. You can retry by reassigning the alert to Roy. | +| **AI limit reached** | Your monthly investigation quota is exhausted. No new alerts will be analyzed until the next billing cycle or until your administrator upgrades your plan. | + +## AI-generated vs. analyst-set verdicts + +Verdicts set by the Elevate agent display a sparkle icon in the alert list. When an analyst validates or overrides the AI verdict manually, the sparkle icon disappears and the verdict reflects the analyst's choice. + +## Related links + +- [Elevate](/xdr/features/modules/elevate_overview.md): Concept overview of how Elevate works and its key concepts. +- [Validate or override an Elevate verdict](/xdr/features/modules/elevate_validate_verdict.md): How to confirm or change the AI verdict on an alert. +- [Trigger a manual Elevate analysis](/xdr/features/modules/elevate_manual_analysis.md): How to analyze an alert that was not processed automatically. +- [Manage your Elevate investigation quota](/xdr/features/modules/elevate_quota.md): How to monitor and optimize your monthly investigation quota. diff --git a/docs/xdr/features/modules/elevate_community_override.md b/docs/xdr/features/modules/elevate_community_override.md new file mode 100644 index 0000000000..9e09237994 --- /dev/null +++ b/docs/xdr/features/modules/elevate_community_override.md @@ -0,0 +1,34 @@ +# Override Elevate settings for a community + +When Elevate is activated at the workspace level, all communities inherit that configuration by default. This article explains how to override the agent settings for a specific community to enable or disable Elevate independently. + +## Prerequisites + +- Elevate is activated on your workspace. See [Activate Elevate on a workspace](/xdr/features/modules/elevate_activate.md). +- You have administrator-level access to the workspace. + +## Override the configuration for a community + +1. Navigate to **Settings > AI agent**. +2. Select the community you want to configure from the community list. +3. Select **Override**. +4. Toggle **Auto-analyze alerts** to the desired state for this community. + +> 📸 [SCREENSHOT SUGGESTION: AI agent settings panel for a specific community, showing the Override button and the Auto-analyze alerts toggle in a custom state with an indicator confirming that the community uses its own settings. | ALT TEXT: Community-level AI agent settings with the Override option active and a custom auto-analyze toggle state.] + +An indicator confirms that this community now uses its own settings and no longer inherits the workspace-level configuration. + +!!! note "Understanding the inherited state" + Before you select **Override**, the toggle reflects the workspace-level setting. It does not represent a choice made at the community level. Select **Override** to manage this community independently. + +## Result + +The community uses its own Elevate configuration independently of the workspace setting. Other communities are not affected. + +To revert to the workspace configuration, return to the community's AI agent settings and remove the override. + +## Related links + +- [Activate Elevate on a workspace](/xdr/features/modules/elevate_activate.md): How to enable the Elevate agent at the workspace level. +- [Limit auto-analysis to specific rules](/xdr/features/modules/elevate_rule_filter.md): How to restrict which alerts Elevate analyzes within a workspace or community. +- [Manage your Elevate investigation quota](/xdr/features/modules/elevate_quota.md): How to monitor and optimize your monthly investigation quota. diff --git a/docs/xdr/features/modules/elevate_custom_instructions.md b/docs/xdr/features/modules/elevate_custom_instructions.md new file mode 100644 index 0000000000..7bb4957167 --- /dev/null +++ b/docs/xdr/features/modules/elevate_custom_instructions.md @@ -0,0 +1,31 @@ +# Add custom instructions for Elevate agents + +If you want to refined the agent investigation results you can add custom instructions. + +## Add Contextual instructions +If you want add more context for a specific community: +1. Go to **Settings > AI agent**. +2. Select the community where you want the change to be applied. +3. Select **Agent/Alert case investigation**. +4. Open the **Instructions** tab. +5. Enter your custom instructions. +6. Select **Save**. + +!!! note "Workspace instructions" + If you want this instruction to be applied on all your communities, Select your workspace instead of a specific community. + +## Custom detection rules agent investigation + +!!! tip + - If the triggering rules comes from a runbook you have created, you can modify the Reasoning questions sections that the agent will use. + - If the triggering rules comes from a runbook build by Sekoia, you can duplicate the rule and edit the runbook but this duplicated rules won't be automatically updated by Sekoia. + + 1. If you want to change the reasoning questions, in the Triggered rule section, click on the **Runbook** button. + 2. At the bottom of the runbook panel, click on **Edit Runbook**. + 3. Modify the reasoning questions according to your preferences. + 4. Click **Save runbook**. +As soon as an alert is triggered by this detection rule the agent takes your modification into account. + +!!! note "Communities impacted" + These modifications apply to all the communities from your workspace. + diff --git a/docs/xdr/features/modules/elevate_investigate_alert.md b/docs/xdr/features/modules/elevate_investigate_alert.md new file mode 100644 index 0000000000..27cb5307cd --- /dev/null +++ b/docs/xdr/features/modules/elevate_investigate_alert.md @@ -0,0 +1,63 @@ +# Investigate an alert with Elevate + +This article explains how to access and read the AI investigation report produced by Elevate for an alert, including the verdict, confidence score, and findings. + +## Prerequisites + +- Elevate is activated on your workspace or community. See [Activate Elevate on a workspace](/xdr/features/modules/elevate_activate.md). +- The alert has been analyzed by the Elevate agent. Check the **Verdict** column in the alert list to confirm the analysis is complete. If the state is **In progress** or shows an error, see [Elevate analysis states](/xdr/features/modules/elevate_analysis_states.md). + +## Open the AI investigation report + +1. Navigate to **Investigate > Alerts**. +2. Select the alert you want to review. + +> 📸 [SCREENSHOT SUGGESTION: Alert detail view with the AI Investigation tab selected, showing the Verdict section at the top and the Findings section below. | ALT TEXT: AI Investigation tab of an alert showing the verdict and findings sections.] + +## Read the verdict + +The **Verdict** section at the top of the AI Investigation tab contains: + +- The **classification**: True Positive or False Positive +- The **confidence score**: a percentage expressing the agent's certainty in its conclusion +- A **plain-language explanation** summarizing the key evidence and reasoning behind the classification + +??? example "Example verdict: False Positive at 85% confidence" + The spike involved four distinct hosts and included an external source IP, but there were no authentication failures, new processes, data exfiltration, privileged account usage, IoC matches, or corroborating alerts from other sensors. The lack of any malicious indicators suggests the activity is benign and therefore a false positive. + +## Read the findings + +Findings are the individual evidence items the agent collected and evaluated. Each finding is a discrete, verifiable observation drawn from your telemetry. + +To review the findings from the AI Investigation tab: + +1. Scroll to the **Findings** section below the verdict. +2. Select the expand arrow on any finding card to view the underlying data that supports it. + +Findings tagged **Global** apply to the alert as a whole rather than to a specific asset or event. + +> 📸 [SCREENSHOT SUGGESTION: Findings section of the AI Investigation tab with several finding cards expanded, each displaying a "Global" tag and a plain-language observation. | ALT TEXT: Findings section showing expandable evidence cards with Global tags.] + +### Access findings from the alert timeline + +A summary of findings is also available directly from the alert detail view without opening the AI Investigation tab. + +1. In the alert detail view, locate the timeline panel. +2. Select the **Findings** tab. + +The Findings tab lists all evidence items the agent collected, allowing you to review them alongside the alert timeline. + +> 📸 [SCREENSHOT SUGGESTION: Alert detail view with the Findings tab selected in the timeline panel, showing a bulleted list of evidence items collected by the Elevate agent. | ALT TEXT: Findings tab in the alert timeline panel showing AI-collected evidence items.] + +## Discover Reasoning questions + +To go further in your understanding of the verdict and findings methodology, scroll down to **Reasoning questions** sections. + +Most of the Reasoning questions comes from our Runbooks, but Elevate agent add its own relevant investigation questions. + + +## Related links + +- [Validate or override an Elevate verdict](/xdr/features/modules/elevate_validate_verdict.md): How to confirm or change the AI verdict once you have reviewed the investigation. +- [Elevate analysis states](/xdr/features/modules/elevate_analysis_states.md): Reference table of all possible AI analysis states and their meaning. +- [Trigger a manual Elevate analysis](/xdr/features/modules/elevate_manual_analysis.md): How to analyze an alert that was not processed automatically. diff --git a/docs/xdr/features/modules/elevate_manual_analysis.md b/docs/xdr/features/modules/elevate_manual_analysis.md new file mode 100644 index 0000000000..5c4b29db82 --- /dev/null +++ b/docs/xdr/features/modules/elevate_manual_analysis.md @@ -0,0 +1,32 @@ +# Trigger a manual Elevate analysis + +This article explains how to trigger an Elevate investigation on an alert that was not analyzed automatically, for example because it was created before Elevate was activated or because it was excluded by a rule filter. + +## Prerequisites + +- Elevate is activated on your workspace or community. See [Activate Elevate on a workspace](/xdr/features/modules/elevate_activate.md). +- The alert has not yet been analyzed. The **Verdict** column shows no AI state, or the alert was excluded by the rule filter. + +## Assign the alert to Roy + +Roy is the Elevate investigation agent. Assigning an alert to Roy triggers an immediate analysis. + +1. Navigate to **Investigate > Alerts**. +2. Select the alert you want to analyze. +3. Select the **Assignee** field in the alert header. +4. Select **Roy**. + +> 📸 [SCREENSHOT SUGGESTION: Alert detail view showing the Assignee dropdown open with Roy listed as an available option. | ALT TEXT: Alert assignee dropdown with Roy as a selectable option to trigger a manual Elevate analysis.] + +## Result + +The agent begins analyzing the alert. The **Verdict** column updates to **In progress** while the analysis runs. Once complete, the verdict and findings are available in the **AI Investigation** tab. + +!!! note "Quota consumption" + A manually triggered analysis consumes one unit of your monthly investigation quota, the same as an automatic analysis. + +## Related links + +- [Investigate an alert with Elevate](/xdr/features/modules/elevate_investigate_alert.md): How to read the AI investigation report once the analysis is complete. +- [Elevate analysis states](/xdr/features/modules/elevate_analysis_states.md): Reference table of all possible AI analysis states and their meaning. +- [Manage your Elevate investigation quota](/xdr/features/modules/elevate_quota.md): How to monitor and optimize your monthly investigation quota. diff --git a/docs/xdr/features/modules/elevate_overview.md b/docs/xdr/features/modules/elevate_overview.md new file mode 100644 index 0000000000..498991c7c7 --- /dev/null +++ b/docs/xdr/features/modules/elevate_overview.md @@ -0,0 +1,42 @@ +# Elevate + +Elevate is the AI investigation layer of Sekoia, built to automatically triage and investigate alerts end-to-end. It deploys a specialized AI agent that analyzes every incoming alert, correlates evidence across your data sources, and produces a structured investigation report so your analysts focus on decisions, response, and strategy rather than manual triage. + +## How Elevate works + +When a new alert arrives in Sekoia, the Elevate investigation agent runs a full investigation autonomously without waiting for an analyst to open the alert. It is driven by detection-specific AI runbooks curated by Sekoia's research team, one per detection rule, that define the exact logic, questions, and false-positive scenarios relevant to that alert type. + +For each alert, the agent: + +- Assesses the relevance of the alert and the likelihood of a false positive +- Collects and correlates evidence across all available data sources +- Enriches findings with threat intelligence and contextual signals +- Produces a complete, audit-ready investigation report with a verdict and a confidence score + +## What makes Elevate different + +**Detection-specific AI runbooks** embed expert investigation logic directly at the rule level. Rather than applying generic playbooks across all alert types, the agent follows tailored guidance for each detection. + +**Human-in-the-loop by design** keeps analysts in full control. Every finding is reviewable, every verdict is overridable, and every automated decision is fully traceable. There are no black boxes. + +**Sovereign AI by architecture** ensures all AI computation runs on Sekoia-hosted infrastructure. No data is sent to external LLM providers, which makes Elevate suitable for regulated environments and sensitive data contexts. + +## Key concepts + +### Verdict + +The verdict is the outcome of the AI investigation. It classifies the alert as a **True Positive** or a **False Positive**, accompanied by a confidence score and a plain-language explanation of the reasoning. Analysts can validate or override any verdict at any time. + +### Findings + +Findings are the individual evidence items the agent collected during its investigation. Each finding is a discrete, verifiable observation drawn from your telemetry. They are visible in the **AI Investigation** tab and in the **Findings** panel of the alert timeline. + +### Investigation quota + +Elevate operates on a monthly investigation quota. Each alert analyzed by the agent consumes one unit. When the quota is exhausted, the agent stops analyzing new alerts until the next billing cycle. + +## Related links + +- [Elevate analysis states](/xdr/features/modules/elevate_analysis_states.md): Reference table of all possible AI analysis states and their meaning. +- [Activate Elevate on a workspace](/xdr/features/modules/elevate_activate.md): How to enable the Elevate agent and configure auto-analysis. +- [Investigate an alert with Elevate](/xdr/features/modules/elevate_investigate_alert.md): How to read an AI investigation report and interpret findings. diff --git a/docs/xdr/features/modules/elevate_quota.md b/docs/xdr/features/modules/elevate_quota.md new file mode 100644 index 0000000000..e004d8f5ff --- /dev/null +++ b/docs/xdr/features/modules/elevate_quota.md @@ -0,0 +1,46 @@ +# Manage your Elevate investigation quota + +Elevate operates on a monthly investigation quota. Each alert analyzed by the agent, whether automatically or manually triggered, consumes one unit. This article explains how to monitor your quota and how to optimize usage to avoid reaching the limit before the end of your billing cycle. + +## Prerequisites + +[PLACEHOLDER: Confirm required role to view and manage quota, e.g. administrator.] + +## Monitor your quota + +[PLACEHOLDER: Confirm the exact location of the quota view, e.g. Settings > Usage or a dedicated Elevate dashboard. Add screenshot placeholder once confirmed.] + +Your quota usage is displayed as a progress bar showing consumed units against your monthly allocation (for example, 1000/1000). When the limit is reached, the agent stops analyzing new alerts and displays the **AI limit reached** state on any alert it cannot process. + +## Optimize quota usage + +You can reduce quota consumption without disabling Elevate entirely by restricting which alerts the agent analyzes. + +**Filter by detection rule** to focus the agent on alert types where AI investigation adds the most value and skip categories already handled by playbooks. See [Limit auto-analysis to specific rules](/xdr/features/modules/elevate_rule_filter.md). + +**Disable auto-analysis for specific communities** when certain sub-tenants generate high alert volumes that do not require AI investigation. See [Override Elevate settings for a community](/xdr/features/modules/elevate_community_override.md). + +**Use manual analysis selectively** to trigger investigations only on alerts that warrant deeper review. See [Trigger a manual Elevate analysis](/xdr/features/modules/elevate_manual_analysis.md). + +## Quota management for MSSPs + +[PLACEHOLDER: Describe how MSSPs manage and distribute investigation quotas across sub-tenants. Include whether quotas are set per community or at the workspace level, and how overages are handled.] + +## What happens when the quota is exhausted + +When your monthly quota is reached: + +- The agent stops analyzing new alerts automatically. +- Alerts that cannot be analyzed display the **AI limit reached** state in the **Verdict** column. +- Manual analysis via Roy is also blocked until the quota resets. + +To resume analysis before the next billing cycle, contact your administrator to upgrade your plan. + +[PLACEHOLDER: Confirm whether self-serve quota top-up is available and add the relevant steps if so.] + +## Related links + +- [Elevate](/xdr/features/modules/elevate_overview.md): Concept overview of how Elevate works and its key concepts. +- [Elevate analysis states](/xdr/features/modules/elevate_analysis_states.md): Reference table of all possible AI analysis states including AI limit reached. +- [Limit auto-analysis to specific rules](/xdr/features/modules/elevate_rule_filter.md): How to restrict which alerts Elevate analyzes to control quota usage. +- [Override Elevate settings for a community](/xdr/features/modules/elevate_community_override.md): How to disable Elevate for specific communities to reduce consumption. diff --git a/docs/xdr/features/modules/elevate_rule_filter.md b/docs/xdr/features/modules/elevate_rule_filter.md new file mode 100644 index 0000000000..58053ec89e --- /dev/null +++ b/docs/xdr/features/modules/elevate_rule_filter.md @@ -0,0 +1,35 @@ +# Limit auto-analysis to specific rules + +By default, when auto-analysis is enabled, the Elevate agent analyzes every incoming alert regardless of the detection rule that triggered it. This article explains how to restrict analysis to a specific set of rules to focus your quota where it adds the most value. + +## Prerequisites + +- Elevate is activated on your workspace. See [Activate Elevate on a workspace](/xdr/features/modules/elevate_activate.md). +- You have administrator-level access to the workspace. + +## When to use rule filtering + +Rule filtering is useful when you already have playbooks reliably handling certain alert types and want to reserve your Elevate quota for detections where AI investigation adds the most value, such as high-volume, complex, or time-consuming alert categories. + +!!! note "Default behavior" + When no rules are selected in the filter, the agent analyzes all incoming alerts. Selecting one or more rules restricts analysis exclusively to alerts triggered by those rules. + +## Configure the rule filter + +1. Navigate to **Settings > AI agent**. +2. Select **Investigation agent** under the **Workspace** section. +3. Enable **Limit auto-analyze to specific rules**. +4. Use the search bar to find the rules you want to include. +5. Select each rule you want the agent to analyze. + +> 📸 [SCREENSHOT SUGGESTION: AI agent settings panel with the "Limit auto-analyze to specific rules" option expanded, showing a search bar and a selectable list of detection rules. | ALT TEXT: Rule filter configuration panel showing a list of detection rules that can be selected for Elevate auto-analysis.] + +## Result + +The agent analyzes only alerts triggered by the rules you selected. Alerts from all other rules are not processed automatically. You can still trigger a manual analysis on any alert at any time. + +## Related links + +- [Activate Elevate on a workspace](/xdr/features/modules/elevate_activate.md): How to enable the Elevate agent on your workspace. +- [Trigger a manual Elevate analysis](/xdr/features/modules/elevate_manual_analysis.md): How to analyze an alert that was excluded by the rule filter. +- [Manage your Elevate investigation quota](/xdr/features/modules/elevate_quota.md): How to monitor and optimize your monthly investigation quota. diff --git a/docs/xdr/features/modules/elevate_validate_verdict.md b/docs/xdr/features/modules/elevate_validate_verdict.md new file mode 100644 index 0000000000..7f5299b46f --- /dev/null +++ b/docs/xdr/features/modules/elevate_validate_verdict.md @@ -0,0 +1,29 @@ +# Validate or override an Elevate verdict + +This article explains how to confirm the AI verdict on an alert or replace it with your own judgment. + +## Prerequisites + +- The alert has an AI-generated verdict. AI verdicts are marked with a sparkle icon in the **Verdict** column of the alert list. +- You have reviewed the investigation report. See [Investigate an alert with Elevate](/xdr/features/modules/elevate_investigate_alert.md). + +## Set a verdict + +To validate or override the AI verdict, select your verdict from the **Select a verdict** dropdown in the alert header. + +- To **validate** the AI conclusion, select the same verdict the agent produced. +- To **override** the AI conclusion, select a different verdict. + +> 📸 [SCREENSHOT SUGGESTION: Alert detail view header showing the "Select a verdict" dropdown open with True Positive and False Positive options visible. | ALT TEXT: Alert header with the verdict dropdown open showing available verdict options.] + +!!! note "Your verdict always takes precedence" + Once you select a verdict, the sparkle icon disappears from the alert list. The alert reflects your analyst verdict, not the AI attribution. The original AI verdict and its reasoning remain accessible in the **AI Investigation** tab for reference. + +## Result + +The alert verdict is updated immediately. The **Verdict** column in the alert list displays your selection without the sparkle icon, indicating an analyst-confirmed verdict. + +## Related links + +- [Investigate an alert with Elevate](/xdr/features/modules/elevate_investigate_alert.md): How to read the AI investigation report before setting a verdict. +- [Elevate analysis states](/xdr/features/modules/elevate_analysis_states.md): Reference table of all possible AI analysis states and their meaning. diff --git a/mkdocs.yml b/mkdocs.yml index 39aa8a80c3..f2843818d1 100644 --- a/mkdocs.yml +++ b/mkdocs.yml @@ -202,6 +202,19 @@ nav: - FortiSOAR: xdr/features/integrations/fortisoar.md - Palo Alto Cortex XSOAR: xdr/features/integrations/interconnect_sekoia_with_xsoar.md - Swimlane Turbine: xdr/features/integrations/swimlane_turbine.md + - AI Agents (Elevate): + - Elevate overview: xdr/features/modules/elevate_overview.md + - Elevate kick start guide: + - Activate Elevate: xdr/features/modules/elevate_activate.md + - Elevate analysis states: xdr/features/modules/elevate_analysis_states.md + - Investigate with Elevate: + - Investigate an alert: xdr/features/modules/elevate_investigate_alert.md + - Validate or override a verdict: xdr/features/modules/elevate_validate_verdict.md + - Trigger an analysis: xdr/features/modules/manual_analysis.md + - Manage Elevate: + - Override community settings: xdr/features/modules/elevate_community_override.md + - Elevate Quota: xdr/features/modules/elevate_quota.md + - Limit auto-analysis: xdr/features/modules/elevate_rule_filter.md - Asset Intelligence (Reveal): - Reveal overview: xdr/features/modules/reveal_index.md - Get started with Reveal: xdr/features/modules/reveal_getting_started.md @@ -210,6 +223,7 @@ nav: - Discover Points of Interest: xdr/features/detect/points_of_interest.md - Check asset connector health: xdr/features/collect/asset_connector_health.md - Reveal enablement matrix: xdr/features/modules/reveal_feature_enablement.md + - Usecases: - Export large volumes of events: xdr/usecases/massive_export.md