AI-Generated vs. Manual PIR Process

In ThreatStream Next Gen, the Process step of a Priority Intelligence Requirement (PIR) defines the actions performed when the PIR returns matching results. These actions guide analysts through evaluation, correlation, escalation, and response.

You can build the process using:

  • Anomali AI-generated process steps, recommended by Anomali.
  • Manual process steps, defined by an analyst.

To learn more about the Process step of the PIR creation, refer to Process Step.

Anomali AI-Generated Process Steps

When you reach the Process step during PIR creation, Anomali AI analyzes the inputs provided in earlier PIR creation steps and generates recommended process steps.

Behavior

  • Process steps are generated at PIR creation time
  • The AI uses only the context provided on the Description and Inputs steps
  • Recommendations do not update automatically if description and inputs are modified after a PIR creation
  • Output quality depends on the specificity and completeness of the inputs

Usage

Anomali AI-generated process steps provide a baseline workflow based on common CTI practices. Use these steps as a draft that must be reviewed and refined.

For each recommended step, you can:

  • Accept and leave the step as is if it is relevant and actionable
  • Edit the step to align with your environment
  • Remove the step if it is not applicable

When to Use AI-generated Process

  • To quickly create an initial PIR workflow
  • When working with standard or well-defined intelligence requirements
  • To ensure common analysis steps are included
  • When building or standardizing processes across teams

Manual Process Steps

Manual process steps are analyst-defined instructions that specify what actions to take when the PIR surfaces results.

Behavior

  • Manual steps are text-based instructions
  • They are executed by analysts, not automated by the system
  • They can include references to internal procedures, tools, and teams

When to Use

  • To incorporate organization-specific procedures or policies
  • To define actions in external systems (for example, SIEM, SOAR, or ticketing platform).
  • To document escalation, notification, or reporting workflows
  • When the process requires analyst interpretation or decision-making

Writing Manual Process Steps

Manual process steps must be clear, specific, and actionable.

Guidelines for Creating Manual Process Steps

  • Start with an action verb (for example, Review, Correlate, Escalate, Notify, Document)
  • Describe what to do and what to look for
  • Reference specific tools, systems, or teams, where applicable
  • Limit each step to one action
  • Ensure the step is self-contained and can be followed without additional context

Examples

Weak Step Improved Step
Check the results Review surfaced indicators against the internal blocklist and escalate any matches
Look for threats Correlate identified threat actor TTPs with SIEM detections to identify matching activity
Tell the team Notify the incident response team via the designated escalation channel when critical indicators are identified

Best Practice

  1. Generate initial steps using Anomali AI
  2. Review and refine all recommended steps
  3. Add manual steps to address gaps and align with internal workflows

This approach ensures that the PIR process is both comprehensive and operationally relevant.