AI triage
Advice with evidence. People decide.
The model reads the alert, the related events and the history of similar alerts, then writes what it thinks and why. A person confirms, or a policy you wrote does, when the verdict is clear-cut.
The verdict
Three things, every time.
A verdict and confidence
Benign, malicious or needs a person, with a confidence you can set thresholds on per workflow.
A recommendation
What to do next, in the vocabulary of the platform: escalate, isolate, close, ask.
An evidence grade
How much of the cited evidence is actually about this alert. A confident verdict on thin evidence is flagged as exactly that.
Where it helps
Grunt work, done for you.
Investigation agent
Runs a bounded number of guarded, read-only queries to gather context, and shows every query it ran.
Triage notes and handovers
Drafts the note for the case and the summary for the next shift from what actually happened.
Report first drafts
Turns a closed case into the first draft of the customer write-up, in the template you defined.
AI Hunt
Plain-language questions over your logs, answered with the queries it used.
Your model
Any OpenAI-compatible endpoint.
Point XenXDR at a model on your own hardware and alert evidence stays inside the deployment. Add a hosted fallback with the provider you choose.
- Self-hosted first: Ollama, vLLM, llama.cpp, LM Studio or anything else that speaks the OpenAI API.
- Optional hosted fallback with your own key, to whichever provider you allow.
- Running without a model? Built-in deterministic triage keeps every workflow running.
- Advice improves with every analyst accept and reject decision, while people keep the final say.
- Your data is used only to protect your organization.
In the docs
See XenXDR on your own telemetry.
A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.