Using Scout with Intelligence
When Intelligence is on for your organization, Scout can read the same intel you see in the Intelligence tabs: your shared and private feeds, your watch lists, your detections and your coverage. Ask it in plain language, for example "Have we seen 185.220.101.4?" or "Which threats matter most to us, and what don't we cover?".
Scout's Intelligence tools are part of Intelligence, which is in beta. Access is by request, so they may not be enabled for your organization. When Intelligence is off, Scout doesn't have them.
What Scout can look up
| Ask about | What Scout does |
|---|---|
| Indicators | Looks up IPs, domains, URLs, hashes and emails (up to 50 at a time) in your intel and in public sources, and says whether each was sighted in your environment. It can also search your indicators by actor, malware, feed or type, and list where they were seen. |
| Threat context | Explains a threat actor, malware family or campaign: what it is, its ATT&CK techniques, and your known exploited vulnerabilities. |
| Relevance | Lists the threats most relevant to your organization, with the reasons behind each score and the techniques you don't cover yet. |
| Detections and coverage | Finds the rules that cover a technique, reports a rule's health, and summarizes your ATT&CK coverage. |
| Feeds | Reports feed health and the Intelligence overview. |
Answers show as compact cards in the chat. Each card links to the matching Intelligence page, such as the indicator or the threat.
Scout only reads intel your organization can see. It follows your TLP markings: TLP:RED values are never sent to outside services such as web search or external enrichment. Text that comes from a feed is treated as data, never as instructions.
What Scout can propose
Scout can suggest a change, but it can't make one. When it proposes one of these, the chat shows a card with Confirm and Cancel, and nothing happens until someone selects Confirm:
- Create watch list or Add to watch list: watch for a set of values from now on. See Watch lists.
- Start retro-hunt: search your stored telemetry for indicators over a past window. See Hunt back over your data.
- Save detection rule: keep a Sigma rule Scout drafted and tested. It's created in Shadow and enters its rollout. It's never switched straight to On.
- Propose response action: a response action on a managed endpoint where an indicator was sighted. As with Respond… on a sighting, it still needs a second person to approve it in the hunt. See Respond to a sighting.
Confirming needs permission to manage watchers in the organization.
Threat briefings
When a threat becomes relevant to your organization, Scout can write you a short briefing: what the threat is, why it matters to you (the products it targets, the vulnerabilities you own, sighted indicators and uncovered techniques) and what to do next.
Briefings need the Threat relevant to your environment watcher to be on for your organization. You get at most one briefing for each threat each week. Briefings appear in the Activity Feed and the daily digest. On Pulse, add the Threat briefings widget from the Intelligence group.