Loading

Manage discoveries from the Attacks view

The Attacks view brings Attack Discovery findings together with their related alerts. Open it at DetectionsViewsAttacks.

This page covers how to filter and search attacks, tell manually generated and scheduled attacks apart, review linked alerts, and take triage actions.

At the top of the Attacks view, overview visualizations summarize activity. The Summary tab shows the total number of attacks detected and attack volume over time. The Trends, Count, and Treemap tabs describe alerts associated with those attacks.

Overview of the Attacks view showing the Summary tab

Below the summary, the Attacks table lists individual attacks. Expand an attack to see involved entities and steps in the attack chain.

The Generations control center in the Attacks view header lists recent Attack Discovery runs. Open it to check run status. When a run finishes, refresh the Attacks view to see new results.

Select a run to open Workflow execution details. That view shows alert retrieval, generation, and validation, with timing and counts for each step. Use Inspect on a step to review its data. For manual, scheduled, and workflow-triggered runs, select Open conversation to view the run in Elastic Agent Builder.

If a run fails, is canceled or dismissed, or an analysis step fails, troubleshoot it with AI.

The Attacks table lists both manually generated and scheduled discoveries. Both types share the same details flyout and triage actions. To start a manual run, refer to Manually run Attack Discovery.

Type What it is How to recognize it
Scheduled Created by a recurring Attack Discovery schedule. A calendar icon appears in the attack title column and in the Attack flyout header. Hover for the Scheduled Attack discovery tooltip. Select the icon to open schedule details, including execution history and configuration.
Manually generated Created when you select Run on the Attacks view or the Attack Discovery page. The attack subtitle shows who ran it: detected time, Run by with the user's avatar, and the attack summary. The same Run by details appear in the Attack flyout summary.

In 9.4, the Attacks view lists scheduled discoveries. Manual runs appear after you start them from the Attack Discovery page.

Use the controls at the top of the Attacks table to narrow results:

Filter method Description
KQL search Enter queries in the search bar. Autocomplete includes fields from both attacks and alerts.
Date/time picker Set a specific time range.
Status filter Filter by status: Open, Acknowledged, or Closed.
Type filter Show Scheduled attacks, Manually generated attacks, or both.
Connector filter Filter attacks by the LLM connector that generated them.
Assignees filter Click Filter by assignees to show only attacks or alerts assigned to specific users.
Sort Use the Sort by menu to sort by Most recent, Least recent, Most alerts, or Least alerts.
Note

Type, Connector, and Assignees filter selections persist across page reloads. The Attacks volume over time summary graph updates to match the filters you apply.

Open the View options ( ) menu for these toggles:

  • Show attacks only (on by default): Hides standalone alerts that don't belong to any attack. Turn it off to see all alerts, including unlinked ones. Unlinked alerts appear in a group labeled - (dash).
  • Show anonymized values: Replaces attack titles and summaries with anonymized placeholders. Turn this off if you are searching for specific entities such as hostnames or IP addresses.

Filters on the Attacks view apply to both attacks and their related alerts at once.

When you open an attack's details, the Alerts tab shows the alerts linked to that attack.

By default, the tab shows all linked alerts, even when page filters are active. Alerts outside the current filters stay visible but greyed out, so the list still matches the attack's total alert count.

A callout above the alerts table explains this behavior and includes a Show matching alerts only toggle. Turn the toggle on if you want to hide non-matching alerts. Your toggle choice persists across attacks.

Attack group statistics in the Attacks table, such as the total alert count, continue to reflect the full set of linked alerts, not only the filtered subset.

Access actions from the Take actions menu on an attack's row in the Attacks table.

Note

When you change an attack's status, assign or unassign it, or apply attack tags, a modal lets you apply the action to the attack only, or to both the attack and its associated alerts. This is the same choice available when changing a discovery's status.

Action How to do it Notes
Change status Take actionsMark as acknowledged or Mark as closed Status lifecycle matches discoveries: Open (default), Acknowledged, or Closed.
Run workflow Take actionsRun workflow → select a workflow → Run workflow Requires workflows prerequisites. You can select only enabled workflows.
Assign or unassign Take actionsAssign attack or Unassign attack Users are not notified when assigned or unassigned.
Apply attack tags Take actionsApply attack tags Use tags to categorize attacks for filtering.
Investigate in timeline Take actionsInvestigate in timeline Includes all alerts originally correlated when the attack was created. It does not reflect your current page filters or time range.
Add to case Take actionsAdd to new case or Add to existing case Attaches the attack to a case.
View in AI Chat Take actionsView in AI Chat Continue investigating with an AI agent. Ask follow-up questions about the attack or its alerts.