AI-Assisted Search
Use AI Assisted Search to ask investigation questions in plain language and get context-rich answers and next steps.
What is AI-Assisted Search?
AI-Assisted Search helps analysts ask observability, investigation, and threat-hunting questions in plain language and turn them into useful search guidance, recommended next steps, and SQL queries.
Rather than requiring analysts to write SQL manually, AI-Assisted Search helps translate intent into searches that surface insights.
AI-Assisted Search is an additional search option alongside Basic Search and SQL Search.
AI-Assisted Search uses generative AI models and Vectra AI-built agentic workflows to generate investigation queries and recommended next steps.
Why use AI-Assisted Search?
AI-Assisted Search is designed to help security teams:
Start investigations faster without needing deep SQL expertise
Turn natural-language questions into structured searches
Explore Vectra AI metadata across supported data sources
Refine investigation paths with follow-up prompts
Generate SQL queries that analysts can review, edit, run, and save
Accelerate investigation while keeping analysts in control
How do I enable it?
AI-Assisted Search is available in the new Vectra AI experience, RUX, for customers on the Vectra AI Pro Platform or customers with 14 days of metadata retention.
An administrator must provide consent before the feature can be used.
How is data handled?
What data is involved?
AI-Assisted Search uses the analyst’s prompt to generate search guidance and SQL queries.
AI-Assisted Search does not process customer metadata records, it only processes input queries.
Will third-party generative AI models be trained on my data?
Customer query data is not used to train third-party generative AI models or stored beyond what is needed for operational purposes.
Logs related to AI-Assisted Search are retained by Vectra AI for 30 days. Vectra AI may uses these logs to troubleshoot problems, monitor quality, support reliability, and improve the product.
Where is data processed?
AI-Assisted Search maintains data within the appropriate geographic boundary (US, EU, AP), but requests may require processing in a different cloud region (AWS Region) than the region where customer data is primarily hosted. Vectra AI makes every effort to handle customer data within the appropriate geographic boundary. Some cross-region inference processing may occur as described below.
United States
May be processed across supported AWS Regions within the United States
European Union
May be processed across supported AWS Regions within the European Union
Canada
May be processed across supported AWS Regions within the United States
Switzerland
May be processed across supported AWS Regions within the European Union
Australia
May be processed across supported AWS Regions within the Asia Pacific
Vectra AI implements appropriate technical and legal safeguards and complies with applicable data protection laws. Cross-region and cross-border transfers are encrypted and logged for compliance purposes.
Usage guidance
AI-Assisted Search uses generative AI to interpret plain-language prompts and generate investigation guidance and SQL queries. Because generative AI is probabilistic, repeated prompts may not always produce the exact same response.
AI-Assisted Search supports a wide range of langauges.
For best results:
Ask specific investigation questions
Re-share edited prompts
Re-prompt for additional options
Maintain chat history of <12 exchanges
Focus each chat on a single target query
AI-Assisted Search maintains context during an active session so analysts can refine searches with follow-up prompts. Sessions time out after 10 minutes of inactivity. Analysts can manually reset a session by selecting Rest Chat.
Changing data sources starts a new AI-Assisted Search session.
AI-Assisted Search is intended to help analysts create and refine searches. It is not intended to be a general-purpose assistant for all Vectra AI product questions.
Analysts should treat AI-Assisted Search as an investigation accelerator. Generated queries, explanations, and recommendations should be reviewed and validated before they are used to make decisions.
Sample Prompts
Below are examples of how you can use AI-Assisted Search to turn questions into insights in no time.
Investigate Hybrid Threats
Modern attacks rarely stay in one domain. AI-Assisted Search helps analysts trace activity across network, identity, and cloud - from the first sign of compromise to lateral movement.
Try asking:
“Show me RDP or NTLM authentications between my domain controllers and untrusted hosts.”
“Which cloud identities accessed on-prem servers this week?”
“List all systems communicating with external IPs over uncommon ports.”
“Identify users with repeated authentication failures followed by successful logins.”
AI-Assisted Search correlates this activity automatically, surfacing suspicious behaviors that may indicate hybrid or multi-stage attacks - giving teams the full picture faster.
Validate Exposure to CVEs and New Threats
When a new vulnerability is published, the first question every analyst asks is, are we impacted?
With AI-Assisted Search, you can validate potential exposure instantly - without waiting for new signatures or building queries manually.
Try asking:
“Check if any hosts connected to domains linked to the latest Cisco CVE.”
“Show me devices running outdated versions of OpenSSL.”
“Find systems using SMBv1 or weak ciphers.”
“List all external connections made to suspicious IP ranges last week.”
AI-Assisted Search helps teams confirm exposure in minutes - saving time and providing immediate peace of mind during patch cycles or threat disclosures.
Hunt for Known Threat Actors
Threat groups like Scattered Spider, Volt Typhoon, or Qilin are constantly evolving. Their indicators change, but their behaviors don’t. AI-Assisted Search lets analysts quickly look for tactics, techniques, or infrastructure tied to specific actors - using the rich metadata already in the platform.
Try asking:
“Help me hunt for Scattered Spider activity in my network.”
“Show me any use of PowerShell with encoded commands.”
“Find lateral movement attempts using SMB shares or RDP.”
“List hosts communicating with domains containing .top or .ru.”
With built-in recommendations, you can pivot from one behavior to another seamlessly — following the trail like a seasoned threat hunter.
Ensure Compliance and Strengthen Governance
Beyond threat detection, AI-Assisted Search uncovers policy violations and compliance risks before they become audit findings.
Teams can verify proper data handling, access control, and configuration hygiene - all through simple questions.
Try asking:
“Show me any unsecured file shares containing sensitive data.”
“Find hosts using outdated browsers or unpatched systems.”
“Who accessed HR files outside business hours?”
“List all users with admin privileges on non-admin systems.”
The ability to quickly confirm compliance posture helps organizations close gaps, reduce audit findings, and maintain stronger governance.
Understand Your Modern Network Better
Visibility is clarity. From uncovering shadow IT to tracking data flows, the feature helps analysts gain deeper institutional knowledge of how their hybrid environment behaves.
Try asking:
“Which devices are consuming the most network bandwidth?”
“Are there any unmanaged hosts communicating with my domain controllers?”
“Show me new cloud identities created in the past 24 hours.”
These insights help teams baseline normal activity, detect anomalies early, and build confidence in their visibility.
Related Resources
Basic Search functionality
Last updated
Was this helpful?