LogoLogo
⌘Ctrlk
  • Documentation
  • Release Notes
  • API Reference
  • Help Center
AI Assistant
Good night

I'm here to help you with the docs.

⌘Ctrli
AI Based on your context
LogoLogo
  • 🏠Welcome
    • Getting started
    • IDR for Azure AD & CDR for M365
    • CDR for AWS
    • CDR for Azure
    • NDR physical appliances
    • NDR virtual / cloud appliances
    • NDR Traffic engineering and validation
    • Match
    • Stream
    • Recall (QUX only)
    • Appliance operations
    • Deprecated / Retired
    • Navigation updates in the Vectra UI
    • ACCESS
    • COVERAGE
    • RESPONSE
    • SETUP
    • TUNING
    • QUX specific
    • Response
    • SOAR
    • ITSM
    • Coverage
    • Context
    • SIEM
    • Access / Authentication
    • Notifications / Data Export
    • Analyst Guidance
      • New close workflow
      • Assignnment workflow FAQ
      • Understanding Vectra AI detections
      • Monitoring honeypot (honeytoken) identities
      • Triggering detections for testing purposes
      • TCP reset does not stop modern attacks
      • CDR (Detect) for AWS detection test guide
      • Recall best practices guide
      • Investigate Quick Start Guide (prior to SQL search)
      • Advanced search reference guide (QUX)
      • Recall custom models - how to create detections (QUX)
      • Crowdstrike EDR process correlation user guide
      • Microsoft Defender EDR process correlation user guide
      • Vectra self-detection events
      • Key asset treatment (QUX)
      • Exposure Findings - best practices guide
      • Asset Inventory getting started (private preview)
    • Updates
    • Dashboards and Reports
    • Detection specific guidance
    • Licensing
    • Backup / Restore / DR
    • Investigate
    • General
    • AI and ML terminology
    • Vectra AI prioritization and scoring factors
    • Appliance support and EOS / EOL policy
    • Bandwidth used between Sensor and Brain
    • How detection PCAPs are generated
    • In-App support
    • Metadata attributes
    • Product Security
    • RSPAN and ERSPAN support
    • Host ID best practices and functionality
    • Vectra's coverage of MITRE ATT&CK and D3FEND
    • Vectra UI supported browsers
    • Why is metadata sharing important
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Documentation
  2. Operations

Analyst Guidance

Analyst workflow guidance and quick links for investigations, testing, and reporting.

New close workflowAssignnment workflow FAQUnderstanding Vectra AI detectionsHoneypot MonitoringTriggering detections for testing purposesTCP reset does not stop modern attacksCDR (Detect) for AWS detection test guideRecall best practices guideInvestigate Quick Start Guide (prior to SQL search)Advanced search reference guide (QUX)Recall custom models - how to create detections (QUX)CrowdStrike EDR process correlationVectra self-detection eventsKey asset treatment (QUX)Exposure Findings - best practices guideAsset Inventory getting started (private preview)
PreviousNotifications / Data ExportNextNew close workflow

Last updated 1 month ago

Was this helpful?

LogoLogo
linkedinx-twitterfacebookyoutubeinstagramreddit

© 2026 Vectra AI, Inc. All rights reserved.

Was this helpful?