AI Agent Scope
AI Triage Agents were built for Malicious Site Monitoring and Dark Web Brand Monitoring use cases to produce higher quality alerts. Currently, the agents do not review all detections for the use case, but rather a subset. For Malicious Sites, the agent will review all domains in your enterprise with more than one moderate risk assessment (phishing/scam, login form, high interest logo detection). For Dark Web, the agent will review all telegram and dark web forum mentions in your enterprise.
We will look to expand the scope of agent-reviewed detections over time.
AI Agent Assessments
For Malicious Site Monitoring, the agent can make one of three assessments:
- Suggested Takedown (high priority): the agent validated the clear use of your brand and believes the domain is abusive and should be taken down.
- Review Recommended (moderate priority): the agent validated the clear use of your brand but is not able to decide if the domain is abusive and recommends your security team validate the domain and either request a takedown or resolve the alert.
- AI Rejected (informational priority): the agent reviewed the domain but did not see any risk or did not see clear use of your brand
These assessments are informed by key evidence, such as the most relevant screenshot, whois information, redirect chain, domain name, and more.
The Suggested Takedown and Review Recommended assessments will be set to trigger alerts by default. The AI Triage Agent is now the only way that Suggested Takedown assessments are created (no longer using rule-based combinations).
For Dark Web Brand Monitoring, the AI Triage agents reviews all brand mentions on Telegram and Dark Web Forums, using the reference information to determine the risk level.
The Malicious Dark Web Forum Mention and Malicious Telegram Mention assessments will be set to trigger alerts by default.
Note: Any suggested takedown assessments generated prior to September 26 were not reviewed by the AI Triage Agent. Any future updates to the alert will be reviewed by the AI agent, but the priority will not be changed. This could lead to informational agent verdicts that remain an open high priority alert. If you'd like us to fully reprocess any open alerts that were created prior to September 26, please reach out to the Support team.
AI Agent Verdict & Reasoning
The AI Triage Agent’s verdict and reasoning will be added to all detections and alerts that the agent reviewed.
Custom Instructions
You can provide custom instructions to the agent for each supported use case. This is performed via a new panel in the use case configuration slideout called AI Triage Agent. In the panel, you will see a summary of the standard instructions and a field where you can add instructions. Your instructions can help the agent prioritize or de-prioritize based on the conditions you outline, but it cannot increase the scope of its coverage.
Feedback
In the AI Agent Verdict and Reasoning section of each detection and alert, there is a thumbs up/down button for feedback. If you choose to provide negative feedback, there is a form for additional information. This feedback is critical for improving the agents, so please let us know how it is performing.