Analyze, investigate, and respond to incidents and alerts using the power of AI.
Trend Companion AI is an AI-powered cybersecurity chatbot that helps you to investigate, analyze, and
respond to Workbench alerts, generate XDR Data Explorer queries, and answer any cybersecurity questions.
Important
|
The following table outlines the available functions in Trend Companion AI.
|
Action
|
Description
|
Supported Apps
|
||
|
Open Trend Companion AI
|
Click the Trend Companion AI icon (
|
All apps and screens in Trend
Vision One™
|
||
|
Enable generative AI capabilities
|
Some features require generative AI capabilities.
To enable generative AI capabilities, open Trend Companion AI and go to .
|
- | ||
|
Explain a Workbench alert
|
During alert investigations, Trend Companion AI can explain the alert displayed on your screen.
You can use prompts such as
Provide an explanation of this Workbench alert. |
|
||
|
Add response to case
|
Click Add to Case to add a response as a case note.
|
|
||
|
Add response to a Workbench alert note
|
Click Add to Note to add a response to the alert
notes.
|
|
||
|
Generate search queries
|
When using the XDR Data Explorer app, Trend Companion AI can help you write search queries and decide what is the appropriate search method
for your query.
|
|
||
|
Add generated search query to search box
|
Click Add to Query to add the generated query to the search box.
Trend Companion AI automatically selects the suggested search method when adding queries to the search
box.
|
|
||
|
Explain CLI commands in Workbench alerts, Search results, and Observed Attack Techniques
events
|
Right-click a CLI command element (
Trend Companion AI can also provide explanations for CLI commands that include base64-encoded elements.
|
|
||
|
Explain Observed Attack Techniques events
|
To learn about an event, right-click an event or click
|
|
||
|
Create an investigation summary report for a case in Case Management
|
Do one of the following:
Trend Companion AI generates a threat investigation and remediation report for the case, which you can
preview, edit, and download by going to . This action is only available for Workbench cases with a “True positive” finding.
|
|||
|
Summarize progress notes for a case in Case Management
|
Do one of the following:
Trend Companion AI summarizes all the notes created in the case since last time a summarized progress
note was created. Summarized progress notes are helpful when transferring a case to
a new owner.
|
|||
|
Summarize Workbench insights
|
During insight investigations, Trend Companion AI can summarize the attack context of the insight displayed on the screen.
You can use prompts such as
Summarize the Workbench insight. |
Workbench (only during Workbench insights investigations)
|
||
|
Receive proactive guidance on noteworthy and false-positive Workbench insights
|
Trend Companion AI uses labeled detection data to classify Workbench alerts into noteworthy or false-positive
alerts to proactively recommend insights that may require further analysis.
|
Workbench
|
||
|
Receive guidance on threat investigation workflows
|
Trend Companion AI can suggest next steps during threat investigation and response related to a Workbench
insight.
You can use prompts such as
What should I do next? |
Workbench (only during Workbench insights investigations)
|
