RedCarbon

AI Virtual Analyst L1

The Next Gen Analyst

Virtual Analyst is an AI instance with specialized cybersecurity algorithms that turns human resource-intensive monitoring and initial triage into consistent and deep computational investigations.

The L1 RedCarbon Virtual Analyst is an AI instance that intervenes immediately after ingesting an alert from a data source system.

Its job is to conduct an in-depth analysis of the alert (Triage) to correctly classify any anomaly detected and build and produce a complete report with all the information helpful in managing a single event. During the Triage phase, the Virtual Analyst plays a critical role in quickly assessing and prioritizing security incidents based on their severity and potential impact.
The three steps process

Primary tasks it undertakes during this phase include three main steps to describe the information in this process:

The AI of the Virtual Analyst L1, during the process of elevation from “Alert” to “Case,” always enriches the original information generated by the data source system; in some situations, it is responsible for carrying out a “Retrospective Analysis” looking for any comparisons with information relating to the hours preceding the ingestion phase of the Alert.

Once all the operations described above have been completed, the AI of the Virtual Analyst L1 makes the “case” available to the SOC operator in the console dedicated to him in the form of a “Human Readable” report; this is because despite being complex information, the AI strives to write it in a language as familiar and congenial as possible to a human operator, not necessarily to an experienced operator.

While in these phases, RedCarbon's AI creates new value, generates and adds new information to the original ones:

Virtual Analyst L1 does a considerable job.

Once all the operations described above have been completed, the AI of the Virtual Analyst L1 makes the “case” available to the SOC operator in the console dedicated to him in the form of a “Human Readable” report; this is because despite being complex information, the AI strives to write it in a language as familiar and congenial as possible to a human operator, not necessarily to an experienced operator.

A full report is usually generated in about 1 second, compared to the 15 or 20 minutes a human operator takes. That means a RedCarbon Virtual Analyst during the triage phase could be from 700 to 900 times faster than a senior human operator.

In essence, it allows the future subsequent reuse of information for these different purposes:

** Contextual Rules in RedCarbon are information related to each customer’s unique infrastructure. In RedCarbon, panels are very easy to set up and permit to the assignment of Priority and Risk Value Scores with great precision. More details are available here