The Analyst Copilot is an AI-powered assistant designed to help SOC analysts streamline incident response, investigation, and remediation. Built on an advanced model, the Analyst Copilot understands the full context of each security incident, providing enriched insights and real-time recommendations. With its chat interface, analysts can quickly gather relevant information, execute enrichment tasks, and take remediation actions all without leaving their workspace. Equipped with pre-built workflows, the Analyst Copilot eliminates manual effort, accelerates decision-making, and ensures a swift, efficient, and precise response to security threats.

Safe Use of AI

It is important that Blink does not use customer data for AI training. We adhere to industry standards to ensure your data remains secure, never stored or utilized for these purposes.

Using the Analyst Copilot

For best results, check out Best Practices for Using the Analyst Copilot to create effective prompts.
1

Navigate to Case Management

Navigate to the Case Management section and select the case you want to work on.
2

Launch the Analyst Copilot

Click on the Analyst Copilot button in the top-right corner of the case interface.
3

Interact with the Chat Interface

Begin your chat with the Analyst Copilot. You can ask it to summarize case insights, identify next steps, perform investigations, or trigger specific actions based on the case data.
4

Review and Run Suggested Workflows

If the Copilot recommends executing a workflow, review the suggested action, fill in any required input fields, and then run the workflow directly from the chat interface.
Please note that, depending on the specific prompt, you might need to provide additional details in the required input fields.
5

Refine and Execute Actions

After a workflow is executed, the Analyst Copilot will automatically summarize and analyze the results. This helps you interpret key findings, uncover new leads, and determine appropriate next steps to advance the investigation helping you advance the investigation and move closer to resolving the case.
6

Enlarge Response

Next to the workflow’s execution status, you can click the icon, this will enlarge the analyst copilot’s response which connected flow it executed and to the left hand side it shows it reasoning and a button to that will direct you to the connected workflow.

7

Connected Workflows

In the top-right corner, you can find all connected workflows by clicking the icon. These are workflows the analyst copilot can utilize to help you with case investigation, enrichment, remediation, and more. Any output from these workflows will be added to the session context.

To connect more workflows to your Analyst Copilot, contact your Case Management admin.

Expose On-Demand Workflows to the Analyst Copilot

In any On Demand workflow, you can enable the ‘Analyst Copilot’ by toggling the ‘Analyst Copilot workflow’ button in the workflow’s settings or the Workflow Overview page. Enabling this setting allows the Analyst Copilot to access the workflow’s configuration and outputs, enabling deeper analysis, informed decision-making, and guided response. By gaining visibility into the workflow’s structure and data, the Copilot can more effectively support analysts throughout the investigation process. Sure! Here’s a clearer version that explains the benefit for the Analyst Copilot:
Important: To support the Analyst Copilot in conducting effective investigations, we strongly recommend adding a workflow description when setting up your workflow.
This feature is currently in its alpha stage.

Use Case Examples: Analyst Copilot in Case Management

Best Practices

Validate the copilot response, as sometimes results may be inaccurate.
  1. Be clear and precise: Providing clear and specific instructions will assist Analyst Copilot in understanding your instructions clearly.
  2. Use complete integration names: For example, instead of using generic terms like Compute Instance, specify the full name of the relevant integrations, such as AWS EC2 Compute Instance.
  3. Refrain from using unknown or unrecognized vendors in your prompt.
  4. Keep it simple and concise: To tackle complex workflows effectively, consider breaking your prompt instructions into bullet points, ensuring each bullet point prompt is concise and straightforward.