Using Anomali Copilot in ThreatStream
Anomali Copilot, integrated into ThreatStream, is one of the components of the Anomali Copilot suite of generative AI solutions. Acting as the embedded counterpart of the Anomali Copilot browser extension (previously known as Lens+), this onboard version streamlines accessibility within ThreatStream, eliminating the need for extension installation. When scanning a ThreatStream page, Anomali Copilot parses and highlights all cyber threat information on the current screen. It employs advanced natural language processing (NLP) to dissect the content and pinpoint crucial cyber threat entities such as Actors, Malware, or observables. Furthermore, Anomali Copilot highlights content even when the specific entity is unfamiliar to Anomali, showcasing its adaptability and effectiveness in real-time threat analysis.
Note: Anomali Copilot in ThreatStream is automatically disabled if you have the Anomali Copilot extension installed on your browser. In this case, use the extension to scan pages in ThreatStream.
To scan a page with Anomali Copilot in ThreatStream:
Click the Copilot icon from anywhere in the platform.
Page content is scanned immediately and results are displayed in the pop-out window. See Scanning Pages with Anomali Copilot for more information on how Anomali Copilot displays scanned page content.
Context at the point of use
Anomali Copilot can parse any screen in ThreatStream for cyber threat intelligence terms and provide context at the point of use. For example, you scan a Threat Bulletin and a number of observables are highlighted in the body of the Threat Bulletin. You can mouse over the highlighted observables to view metadata, such as Severity, Confidence, associated Indicator Types and Tags. If you want more context, you can click View Details to visit the Observable details page.
Thus, Anomali Copilot enables you to quickly access contextual information and provides a direct vector of entry into comprehensive detail without needing to manually run Observable or Threat Model entity searches.
ThreatStream also ensures you know which threats are trending. If you scan a page that contains reference to a threat that has appeared frequently in recent intelligence feeds and articles, a flame icon is displayed next to the term in the scan results list.
The flame icon is also displayed next to the highlighted entity on the page.
Parse new content from the web
Anomali Copilot in ThreatStream scans content within the ThreatStream user interface. However, you can leverage Anomali Copilot in ThreatStream to scan content from the web by pasting it into a text editor, such as the description of a Threat Bulletin.
Content does not need to be saved in order for Anomali Copilot to scan it. Anomali Copilot cannot scan content in the rich text or markdown editors when an entity is in edit view. However, Anomali Copilot can scan content in the markdown live preview window while in edit view.