Understanding Vectra AI detections
Understand Vectra AI detection models and the behaviors they identify.
Last updated
Was this helpful?
Understand Vectra AI detection models and the behaviors they identify.
This KB article serves as the replacement for all other KB articles that contained various prior versions of this document. There is also a JSON version which can be used as metadata to enrich Vectra Detections in third-party tools like Tines that are ingesting Vectra detections via API or Syslog.
For scoring guidance:
RUX users: individual detections are no longer scored; instead, Vectra prioritizes host and account entities for analysts with AI-driven Prioritization
QUX users: individual one-pager detection explanations with Threat and Certainty ranges are available in each individual detection in the UI
Please Note:
We’ve updated the JSON file that accompanies the formal .pdf file.
As part of this update, the content of the info section has changed. If you rely on automated parsing of this JSON, you should review and validate your parsing logic to ensure everything continues to function as expected.
We recommend testing your integrations against the updated structure to avoid any potential disruptions.
If you are uncertain of which UX you are using, please see Vectra Analyst User Experiences (Respond vs Quadrant).
Last updated
Was this helpful?
Was this helpful?