analysis guidance quick setup guide.md

Analysis Guidance Quick Setup Guide

Overview

Analysis Guidance allows you to automatically assign investigation conclusions based on predefined conditions. When alerts match your configured criteria, Dropzone applies the appropriate conclusion—such as Malicious, Suspicious, or Benign—without requiring manual review.

Analysis Guidance helps standardize investigation outcomes, reduce repetitive analyst effort, and ensure consistent handling of common alert patterns.

How Analysis Guidance Affects Investigations

With Analysis Guidance enabled:


Quick Setup

Step 1: Navigate to Custom Strategies

  1. In the Dropzone interface, open Settings from the left navigation.
  2. Select Custom Strategies.
  3. You’ll see the Custom Strategies management page with a New Strategy button.

Step 2: Create or Edit a Strategy

You’ll be taken to the strategy configuration page.


Step 3: Configure Alert Filters

Alert filters define when your Analysis Guidance rules apply.

Configure one or more of the following filters:

Example Filter Configuration:


Step 4: Configure Analysis Guidance

Scroll to the Analysis Guidance section of the strategy.

  1. Select a Guidance Type:
    • Insight Tag Rule
    • Scenario Description
  2. Click + Add Condition.
  3. Define the condition and the conclusion to apply.

Understanding Insight Tags

Insight Tags are automatically applied labels that provide additional context during investigations.

Insight Tags can:

They allow domain-specific knowledge to be embedded into the AI’s decision-making process.


Guidance Types

Insight Tag Rule

Use this guidance type when conclusions should be set based on specific insight tags.

Configuration:

You can add multiple conditions using + Add Condition.

Example:


Scenario Description

Use this guidance type when conclusions should be based on alert descriptions or behavioral patterns.

Configuration:

You can add multiple conditions using + Add Condition.

Example:


Conclusion Types

Analysis Guidance supports the following conclusions:


Common Insight Tags

Frequently used insight tags include:


Best Practices

✅ Do

❌ Don’t


Example Analysis Guidance Configurations

Insight Tag Rules

Blocked Unwanted Programs

Malware Detection


Scenario Description Rules

New Device Login

Suspicious Login Pattern


What You’ll See in Your Investigations

After configuring Analysis Guidance:


Next Steps