AI overview

What the advisory layer does and where it appears in the console.

The principle

AI in XenXDR is advisory: it reads, compares, summarises and recommends, and people decide. Every conclusion it produces is written next to the human ones in the audit trail, attributable and reviewable. Automatic actions on the strength of an AI verdict happen only when a playbook is in auto mode, the verdict is confident-malicious, and the action is within the organization's ceiling; everything else waits for a person.

Where it appears

PlaceWhat the AI does
Alert page, AI tabThe advisory verdict: benign, malicious or needs a person, with confidence, a recommendation and an evidence grade. See Triage verdicts.
PlaybooksThe AI investigate block gathers context with bounded read-only queries; the advisory verdict block asks for the verdict. See Investigation agent.
Alert and case notesDrafts of the triage note and the shift handover. See Notes and reports.
ReportsA first draft of a section from the attached material.
Logs pageAI Hunt: plain-language questions turned into queries. See AI Hunt.
Rule pagesWhether the AI verdict tended to agree with analysts on this rule.

Your model

The platform talks to any OpenAI-compatible endpoint. Point it at a model on your own hardware and alert evidence stays inside the deployment. Optionally add a hosted fallback with your own key. Without a model, verdicts come from built-in deterministic triage. See Model setup.

Better with use

Your analysts' decisions sharpen the advice over time, while people stay in charge of every decision. See Feedback.