AI-Generated vs. Manual PIR Process
In ThreatStream Next Gen, the Process step of a Priority Intelligence Requirement (PIR) defines the actions performed when the PIR returns matching results. These actions guide analysts through evaluation, correlation, escalation, and response.
You can build the process using:
- Anomali AI-generated process steps, recommended by Anomali.
- Manual process steps, defined by an analyst.
To learn more about the Process step of the PIR creation, refer to Process Step.
Anomali AI-Generated Process Steps
When you reach the Process step during PIR creation, Anomali AI analyzes the inputs provided in earlier PIR creation steps and generates recommended process steps.
Behavior
- Process steps are generated at PIR creation time
- The AI uses only the context provided on the Description and Inputs steps
- Recommendations do not update automatically if description and inputs are modified after a PIR creation
- Output quality depends on the specificity and completeness of the inputs
Usage
Anomali AI-generated process steps provide a baseline workflow based on common CTI practices. Use these steps as a draft that must be reviewed and refined.
For each recommended step, you can:
- Accept and leave the step as is if it is relevant and actionable
- Edit the step to align with your environment
- Remove the step if it is not applicable
When to Use AI-generated Process
- To quickly create an initial PIR workflow
- When working with standard or well-defined intelligence requirements
- To ensure common analysis steps are included
- When building or standardizing processes across teams
Manual Process Steps
Manual process steps are analyst-defined instructions that specify what actions to take when the PIR surfaces results.
Behavior
- Manual steps are text-based instructions
- They are executed by analysts, not automated by the system
- They can include references to internal procedures, tools, and teams
When to Use
- To incorporate organization-specific procedures or policies
- To define actions in external systems (for example, SIEM, SOAR, or ticketing platform).
- To document escalation, notification, or reporting workflows
- When the process requires analyst interpretation or decision-making
Writing Manual Process Steps
Manual process steps must be clear, specific, and actionable.
Guidelines for Creating Manual Process Steps
- Start with an action verb (for example, Review, Correlate, Escalate, Notify, Document)
- Describe what to do and what to look for
- Reference specific tools, systems, or teams, where applicable
- Limit each step to one action
- Ensure the step is self-contained and can be followed without additional context
Examples
| Weak Step | Improved Step |
|---|---|
| Check the results | Review surfaced indicators against the internal blocklist and escalate any matches |
| Look for threats | Correlate identified threat actor TTPs with SIEM detections to identify matching activity |
| Tell the team | Notify the incident response team via the designated escalation channel when critical indicators are identified |
Best Practice
- Generate initial steps using Anomali AI
- Review and refine all recommended steps
- Add manual steps to address gaps and align with internal workflows
This approach ensures that the PIR process is both comprehensive and operationally relevant.