For the complete documentation index, see llms.txt. This page is also available as Markdown.

Understanding Vectra AI detections

Understand Vectra AI detection models and the behaviors they identify.

This KB article serves as the replacement for all other KB articles that contained various prior versions of this document. There is also a JSON version which can be used as metadata to enrich Vectra Detections in third-party tools like Tines that are ingesting Vectra detections via API or Syslog.

For scoring guidance:

  • RUX users: individual detections are no longer scored; instead, Vectra prioritizes host and account entities for analysts with AI-driven Prioritization

  • QUX users: individual one-pager detection explanations with Threat and Certainty ranges are available in each individual detection in the UI

If you are uncertain of which UX you are using, please see Vectra Analyst User Experiences (Respond vs Quadrant).

Last updated

Was this helpful?