Analyst Guidance
Analyst workflow guidance and quick links for investigations, testing, and reporting.
New close workflowUnderstanding Vectra AI detectionsAssignnment workflow FAQ (prior to New close workflow)Monitoring honeypot (honeytoken) identitiesTriggering detections for testing purposesTCP reset does not stop modern attacksCDR (Detect) for AWS detection test guideRecall best practices guideInvestigate Quick Start Guide (prior to SQL search)Advanced search reference guide (QUX)Recall custom models - how to create detections (QUX)Crowdstrike EDR process correlation user guide
Last updated
Was this helpful?