how to create custom strategy.md

How to Create a Custom Strategy

Custom strategies allow you to tailor how the AI analyst interprets, investigates, and concludes on specific alert scenarios. This feature is essential for encoding your organization’s tribal knowledge, reducing false positives, and ensuring consistent outcomes for recurring situations.


1. Accessing Custom Strategies

To get started:

  1. Navigate to the Settings section of the platform.
  2. Select Custom Strategies from the menu.

Here, you’ll see a list of existing strategies as well as the option to create a new one.


2. Defining When the Strategy Applies

Each custom strategy is triggered by specific conditions. You can define these conditions using one or both of the following methods:

Scenario Description

Provide a plain-language description of the situation the strategy should apply to.

Example:

This description helps the AI analyst understand the intent and context of the strategy.

Filters

Use structured filters to target a broad or narrow set of alerts. Common filter fields include:

Examples:

You can combine scenario descriptions and filters for more precise targeting.


3. Specifying Investigative Questions (Optional)

You may require the AI analyst to ask specific questions during the investigation phase. These questions ensure the investigation aligns with your organization’s unique requirements.

Examples:

When defined, these questions are explicitly addressed as part of the investigation workflow.


4. Setting Analysis Guidance and Outcomes

Define how the AI analyst should conclude when the strategy matches.

Conclusion State

Force a specific outcome based on your policy:

Example:

Priority (If Supported)

Assign a priority level to matched alerts.

Example:

Insight Tag Rules

Use meta-analysis tags to further refine:


5. Saving and Testing Your Strategy

  1. Save the strategy. It will appear in your list of custom strategies.
  2. Enable or disable the strategy as needed.

6. Best Practices


Example Use Cases


For additional guidance or troubleshooting, consult the in-platform documentation or reach out to your technical support contact.