LogoLogo
search
⌘Ctrlk
  • book-blankDocumentation
  • file-linesRelease Notes
  • terminalAPI Reference
  • life-ringHelp Center
sparkle
AI Assistant
Working...Thinking...
sparkle
Good evening

I'm here to help you with the docs.

⌘Ctrli
AI Based on your contextquestion-circle
LogoLogo
  • 🏠Welcome
  • Deployment
    • Getting started
    • IDR for Azure AD & CDR for M365
    • CDR for AWS
    • CDR for Azure
    • NDR physical appliances
    • NDR virtual / cloud appliances
    • NDR Traffic engineering and validation
    • Match
    • Stream
    • Recall (QUX only)
    • Appliance operations
    • Deprecated / Retired
  • Configuration
    • Navigation updates (RUX)
    • ACCESS
    • COVERAGE
    • RESPONSE
    • SETUP
    • TUNING
    • QUX specific
  • Operations
    • Analyst Guidance
      • New close workflow
      • Understanding Vectra AI detections
      • Assignnment workflow FAQ (prior to New close workflow)
      • Monitoring honeypot (honeytoken) identities
      • Triggering detections for testing purposes
      • TCP reset does not stop modern attacks
      • CDR (Detect) for AWS detection test guide
      • Recall best practices guide
      • Investigate Quick Start Guide (prior to SQL search)
      • Advanced search reference guide (QUX)
      • Recall custom models - how to create detections (QUX)
      • Crowdstrike EDR process correlation user guide
      • Vectra self-detection events
      • Key asset treatment (QUX)
    • Updates
    • Dashboards and Reports
    • Detection Specific Guidance
    • Licensing
    • Backup / Restore / DR
    • Investigate
    • General
  • Reference
    • Appliance EOS / EOL policy
    • Metadata attributes
    • Vectra's coverage of MITRE ATT&CK and D3FEND
    • Understanding Vectra host naming
    • How detection PCAPs are generated
    • RSPAN and ERSPAN support
    • AI-driven priortization FAQ
    • Bandwidth used between Sensor and Brain
    • AI and ML terminology
    • In-App support
    • Why is metadata sharing important
    • Product Security
    • Vectra UI supported browsers
block-quoteOn this pagechevron-down
  1. Operations

Analyst Guidance

Analyst workflow guidance and quick links for investigations, testing, and reporting.

New close workflowchevron-rightUnderstanding Vectra AI detectionschevron-rightAssignnment workflow FAQ (prior to New close workflow)chevron-rightMonitoring honeypot (honeytoken) identitieschevron-rightTriggering detections for testing purposeschevron-rightTCP reset does not stop modern attackschevron-rightCDR (Detect) for AWS detection test guidechevron-rightRecall best practices guidechevron-rightInvestigate Quick Start Guide (prior to SQL search)chevron-rightAdvanced search reference guide (QUX)chevron-rightRecall custom models - how to create detections (QUX)chevron-rightCrowdstrike EDR process correlation user guidechevron-right
PreviousSMTP configuration (QUX)chevron-leftNextNew close workflowchevron-right

Last updated 1 day ago

Was this helpful?

LogoLogo
linkedinx-twitterfacebookyoutubeinstagramredditgithub

© 2026 Vectra AI, Inc. All rights reserved.

Was this helpful?