> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/operations.md).

# Operations

- [Analyst Guidance](https://docs.vectra.ai/operations/analyst-guidance.md): Analyst workflow guidance and quick links for investigations, testing, and reporting.
- [New close workflow](https://docs.vectra.ai/operations/analyst-guidance/new-close-workflow.md): The New Close Workflow is used to close, resolve, assign, and provide report data for detections and entities.
- [Assignnment workflow FAQ](https://docs.vectra.ai/operations/analyst-guidance/assignnment-workflow-faq-prior-to-new-close-workflow.md): FAQ for legacy and new assignment/close workflows, including creating, changing, deleting, and closing assignments.
- [Understanding Vectra AI detections](https://docs.vectra.ai/operations/analyst-guidance/understanding-vectra-ai-detections.md): Understand Vectra AI detection models and the behaviors they identify.
- [Triggering detections for testing purposes](https://docs.vectra.ai/operations/analyst-guidance/triggering-detections-for-testing-purposes.md): This article shows some ways to trigger a Cyptocurrency Mining (like Bitcoin mining for example) or Brute-Force Detection to quickly see if your system is working properly.
- [TCP reset does not stop modern attacks](https://docs.vectra.ai/operations/analyst-guidance/tcp-reset-does-not-stop-modern-attacks.md): Understand why TCP reset is unreliable for modern attacks and review Vectra response and containment options.
- [CDR (Detect) for AWS detection test guide](https://docs.vectra.ai/operations/analyst-guidance/cdr-detect-for-aws-detection-test-guide.md): Run an AWS detection test lab with CloudGoat and Pacu to validate CDR for AWS detections in Vectra.
- [Recall best practices guide](https://docs.vectra.ai/operations/analyst-guidance/recall-best-practices-guide.md): A guide to understand best practices & recommendations to get the most out of Recall in a fast and efficient way.
- [Investigate Quick Start Guide (prior to SQL search)](https://docs.vectra.ai/operations/analyst-guidance/investigate-quick-start-guide-prior-to-sql-search.md): Use the pre-SQL Investigate quick start to build queries, adjust filters, modify columns, and review cloud activity examples.
- [Advanced search reference guide (QUX)](https://docs.vectra.ai/operations/analyst-guidance/advanced-search-reference-guide-qux.md): Use Advanced Search in QUX to investigate activity and build effective queries.
- [Recall custom models - how to create detections (QUX)](https://docs.vectra.ai/operations/analyst-guidance/recall-custom-models-how-to-create-detections-qux.md): Create Recall custom models in QUX to generate detections from saved searches, signatures, indicators, and policy checks.
- [Vectra self-detection events](https://docs.vectra.ai/operations/analyst-guidance/vectra-self-detection-events.md): Explains expected Vectra cloud/update/metadata-sharing traffic and why it may trigger Hidden HTTPS Tunnel, Multi-home fronted tunnel, or Smash and Grab detections.
- [Key asset treatment (QUX)](https://docs.vectra.ai/operations/analyst-guidance/key-asset-treatment-qux.md): Mark and monitor key assets in QUX so high-value hosts stand out in filters, detections, dashboards, and notifications.
- [Exposure Findings - best practices guide](https://docs.vectra.ai/operations/analyst-guidance/exposure-findings-best-practices-guide.md): Use Exposure Findings to identify, prioritize, and reduce attack surface risk from exposed assets and risky communications.
- [Asset Inventory getting started (private preview)](https://docs.vectra.ai/operations/analyst-guidance/asset-inventory-getting-started-private-preview.md): Getting Started with Asset Inventory: Understanding What's On Your Network - Private Preview
- [Updates](https://docs.vectra.ai/operations/readme-1.md): Update guidance for Vectra appliances, including offline updates and troubleshooting upgrade status.
- [Offline updates (v8.9+)](https://docs.vectra.ai/operations/readme-1/offline-updates-v89.md): Use offline update packages for air-gapped QUX deployments running version 8.9 or later.
- [Offline updates (prior to v8.9)](https://docs.vectra.ai/operations/readme-1/offline-updates-prior-to-v89.md): Use legacy offline update procedures for QUX deployments running Vectra software earlier than version 8.9.
- [Troubleshooting updates](https://docs.vectra.ai/operations/readme-1/troubleshooting-updates.md): Troubleshoot Vectra appliance upgrades by checking versions, upgrade status, sensor versions, and version pinning.
- [Dashboards and Reports](https://docs.vectra.ai/operations/dashboards-and-reports.md): Dashboard and report guidance for operational, executive, Recall, and custom reporting views.
- [Operational Overview report guidance](https://docs.vectra.ai/operations/dashboards-and-reports/operational-overview-report-guidance.md): Use the Operational Overview report to communicate detection trends, team performance, and operational value.
- [Executive Overview report guidance](https://docs.vectra.ai/operations/dashboards-and-reports/executive-overview-report-guidance.md): Use the Executive Overview report to brief security leaders on alert noise reduction, threat trends, and business-level outcomes.
- [Recall](https://docs.vectra.ai/operations/dashboards-and-reports/recall.md): Recall dashboard guides for certificate expiry, Netlogon exploit visibility, host activity, and related metadata views.
- [Recall certificate expiry dashboard](https://docs.vectra.ai/operations/dashboards-and-reports/recall/recall-certificate-expiry-dashboard.md): Use the Recall certificate expiry dashboard to track certificates expiring in the next 7, 30, and 60 days.
- [Recall Netlogon exploit visibility dashboard](https://docs.vectra.ai/operations/dashboards-and-reports/recall/recall-netlogon-exploit-visibility-dashboard.md): Use the Recall Netlogon exploit visibility dashboard to investigate traffic related to the Netlogon vulnerability.
- [Recall host dashboard](https://docs.vectra.ai/operations/dashboards-and-reports/recall/recall-host-dashboard.md): Use the Recall host dashboard to review historical metadata and activity for a selected host.
- [Detection specific guidance](https://docs.vectra.ai/operations/detection-specific-guidance.md): Detection-specific guidance for interpreting selected Vectra detections, behaviors, and investigation context.
- [Suspicious Remote Desktop](https://docs.vectra.ai/operations/detection-specific-guidance/suspicious-remote-desktop.md): Understand the Suspicious Remote Desktop detection model and the RDP behavior patterns it identifies.
- [Hidden HTTPS Tunnel - detection showing proxy IP as target](https://docs.vectra.ai/operations/detection-specific-guidance/hidden-https-tunnel-detection-showing-proxy-ip-as-target.md): Understand why Hidden HTTPS Tunnel detections may show a proxy IP as the target and where to find the destination domain.
- [Data Gathering - detected between Brain and Sensor](https://docs.vectra.ai/operations/detection-specific-guidance/data-gathering-detected-between-brain-and-sensor.md): Vectra detected data gathering between the brain and the sensor, triggering an alert.
- [Suspect Protocol Activity detection descriptions](https://docs.vectra.ai/operations/detection-specific-guidance/suspect-protocol-activity-detection-descriptions.md): This page will explain the different Suspect Protocol Activity (SPA) detections which can appear in the platform and serves as one pager content for the SPA detections.
- [Turla and Snake malware](https://docs.vectra.ai/operations/detection-specific-guidance/turla-and-snake-malware.md): Vectra Notice: Turla and Snake Malware
- [Suspicious Remote Execution](https://docs.vectra.ai/operations/detection-specific-guidance/suspicious-remote-execution.md): Understand the Suspicious Remote Execution detection model and how it identifies suspicious RPC-based remote execution.
- [Intel AMT (Active Management Technology) detections](https://docs.vectra.ai/operations/detection-specific-guidance/intel-amt-active-management-technology-detections.md): Review Vectra coverage for Intel AMT CVE-2017-5689 activity and related detection behavior.
- [Licensing](https://docs.vectra.ai/operations/licensing.md): Licensing guidance for Vectra products, including metrics and license-related reference information.
- [Vectra licensing metrics (all products)](https://docs.vectra.ai/operations/licensing/vectra-licensing-metrics-all-products.md): Review the licensing metrics used across Vectra products.
- [Backup / Restore / DR](https://docs.vectra.ai/operations/backup-restore-dr.md): Backup, restore, disaster recovery, and migration guidance for Vectra Brain appliances.
- [Backup and restore (v8.5+)](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85.md): Backup and restore guidance for Vectra Brain appliances running version 8.5 or later.
- [Introduction and changes](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/introduction-and-changes.md): Backup and Restore introduction and changes from earlier versions.
- [Backup and restore FAQ](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/backup-and-restore-faq.md): Frequently asked questions about backup and restore.
- [Migration from earlier versions](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/migration-from-earlier-versions.md): Guidance for customers migrating from earlier versions of backup and restore.
- [Scheduling backups and running manual backups](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/scheduling-and-manual-backups.md): How to schedule backups and run backups manually.
- [Configuring external targets](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/configuring-external-targets.md): How to configure external targets including SCP, SFTP, and S3. Brain to Brain backups. Rotating old backups. Testing, renaming, and removing external backup targets.
- [Restoring backups](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/restoring-backups.md): Guidance for restoring backups and deleting older backup versions.
- [Troubleshooting and additional commands](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/troubleshooting-and-additional-commands.md): Additional backup and restore related commands and troubleshooting advice.
- [All commands (syntax examples)](https://docs.vectra.ai/operations/backup-restore-dr/backup-and-restore-v85/all-commands-syntax-examples.md): Examples of all backup and restore related commands.
- [Disaster recovery and migration (v8.5+)](https://docs.vectra.ai/operations/backup-restore-dr/disaster-recovery-and-migration-v85.md): Plan disaster recovery and Brain migration for Vectra deployments running version 8.5 or later.
- [DR (Disaster Recover) process](https://docs.vectra.ai/operations/backup-restore-dr/disaster-recovery-and-migration-v85/dr-disaster-recover-process.md): Follow the disaster recovery process for restoring a Brain backup to a target appliance during failover.
- [Migration process](https://docs.vectra.ai/operations/backup-restore-dr/disaster-recovery-and-migration-v85/migration-process.md): Follow the migration process for moving from an existing Brain to a replacement or upgraded Brain appliance.
- [Legacy details prior to v8.5](https://docs.vectra.ai/operations/backup-restore-dr/legacy-details-prior-to-v8.5.md): Legacy backup, restore, disaster recovery, and migration guidance for Vectra versions prior to 8.5.
- [Backup / Restore (prior to v8.5)](https://docs.vectra.ai/operations/backup-restore-dr/legacy-details-prior-to-v8.5/backup-restore-prior-to-v85.md): Restore backups in Vectra versions prior to 8.5.
- [Disaster recovery process (prior to v8.5)](https://docs.vectra.ai/operations/backup-restore-dr/legacy-details-prior-to-v8.5/disaster-recovery-process-prior-to-v85.md): Plan disaster recovery for Cognito deployments running versions prior to 8.5.
- [Migrating to new Brain (prior to v8.5)](https://docs.vectra.ai/operations/backup-restore-dr/legacy-details-prior-to-v8.5/migrating-to-new-brain-prior-to-v85.md): Migrate to a new Brain appliance in Vectra versions prior to 8.5.
- [Investigate](https://docs.vectra.ai/operations/investigate.md): Investigate guides for AI-assisted search, SQL search, API usage, metadata, and investigation workflows.
- [AI-Assisted Search](https://docs.vectra.ai/operations/investigate/ai-assisted-search.md): Use AI Assisted Search to ask investigation questions in plain language and get context-rich answers and next steps.
- [SQL search](https://docs.vectra.ai/operations/investigate/sql-search.md): Accessing SQL Search, examples, syntax, fields, tables, operators, and functions supported.
- [Vectra AI Platform Metadata Retention FAQ](https://docs.vectra.ai/operations/investigate/vectra-ai-platform-investigate-faq.md): FAQ for Vectra AI metadata retention for observability, hunting, and investigations.
- [Investigate API user guide](https://docs.vectra.ai/operations/investigate/investigate-api-user-guide.md): Using the RUX Investigate (Metadata) API Manually (e.g., with Postman)
- [Investigate API metadata schema reference](https://docs.vectra.ai/operations/investigate/investigate-api-metadata-schema-reference.md): Available Tables and Fields for RUX Investigate (Metadata) API Queries
- [Agentic Investigations](https://docs.vectra.ai/operations/investigate/agentic-investigations.md): Understand and respond to active security incidents faster with the help an integrated SOC Investigation Agent
- [General](https://docs.vectra.ai/operations/general.md): General operations guidance for attack graphs, AI Triage, suspect protocol activity, and RUX portal links.
- [Attack Graph FAQ](https://docs.vectra.ai/operations/general/attack-graph-faq.md): This article details the Attack Graph feature for entities in the Vectra UI.
- [AI-Triage in Detail](https://docs.vectra.ai/operations/general/ai-triage-in-detail.md): Learn how AI Triage reviews detections, how it is enabled, and how behavior differs between RUX and QUX.
- [Suspect Protocol Activity detections (feature overview)](https://docs.vectra.ai/operations/general/suspect-protocol-activity-detections-feature-overview.md): Understand Suspect Protocol Activity detections, how they differ from Match, and how to manage SPA settings.
- [Using generic portal links (RUX)](https://docs.vectra.ai/operations/general/using-generic-portal-links-rux.md): Generic Portal Links take you to specific pages in your RUX UI after inputting your RUX URL or tenant ID.  You might find these links in Docs, KBs, blogs, or training materials.
- [Dark mode support for UI](https://docs.vectra.ai/operations/general/dark-mode-support-for-ui.md): How to enable dark mode and switch between light and dark modes.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/operations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
