Skip to main content
SentrySurface
Platform Capability 03 — Investigate

Security Copilot AI Analyst

One conversational AI. Two modes of power. Instantly explain any individual scan in plain English — or investigate entire enterprise threat campaigns across your full scan history. Every response is grounded in real scan evidence, not hallucination.

Report generated in

< 5s

MITRE techniques mapped

Auto

Scans investigable

Unlimited

Security Copilot
Enterprise Investigation Mode

You

Show me all scans from the last 30 days that share infrastructure with the recent Microsoft phishing campaign.

Security Copilot

Found 14 related scans. They share 3 common hosting providers (Hostinger BVI, Fastly edge node 185.220.x.x, OVH DE), 2 TLS fingerprint clusters (JARM: 29d3fd...), and a favicon MMH3 hash match — indicating coordinated campaign infrastructure. I've grouped them by hosting cluster for your review.

You

Generate a takedown evidence package for all 14.

Security Copilot

Generating... 14 evidence packages created. Each includes: screenshot comparison, redirect chain, certificate details, WHOIS data, and pre-formatted abuse contact emails for each registrar. Ready to download.

Full Capability Suite

Everything a Security Analyst Needs — In One Conversation

Interactive Threat Querying

Ask in plain English: 'Did this scan load external scripts?' or 'Was credential data exfiltrated?' — get instant, natural-language answers grounded in the raw scan evidence.

Automated MITRE ATT&CK Mapping

Every sandbox execution path is automatically mapped to standardized MITRE ATT&CK tactics (T1566 Phishing, T1204 User Execution, etc.) for streamlined SOC logging and compliance.

Plain-English Executive Summary

Security Copilot translates cryptic sandboxing logs and network captures into a clear executive summary that legal, brand protection, or PR teams can act on directly.

Enterprise Campaign Investigation

Go beyond a single scan — query your entire threat dataset to investigate multi-domain phishing campaigns, identify shared infrastructure clusters, and surface campaign patterns.

Cross-Scan Pattern Recognition

Security Copilot correlates behavioral signals across hundreds of scans to identify adversary tooling, reuse of infrastructure, and campaign pivots at enterprise scale.

Automated Threat Report Generation

Generate analyst-ready reports with ATT&CK technique references, confidence scores, and recommended remediation steps — ready to attach to a ticket or email to your CISO.

Two AI Approaches, One Goal: Clarity

AI Verdict Report vs. SentryGenie: Know the Difference

Both are powered by AI, but they serve different purposes. Understand when to use each one for maximum security intelligence.

AI Verdict Report

Per-Scan Analysis
Primary Focus

Individual Threat Investigation

Automatically generates a comprehensive report for each submitted URL or scan.

Key Capabilities
  • Executive summary for each threat
  • Plain-English verdict & confidence score
  • MITRE ATT&CK technique mapping
  • PDF export for legal/compliance
  • Recommendations per finding
  • Step-by-step screenshots & evidence
Per-Scan Report
› URL: malicious-portal.icu/login
› Verdict: Credential Harvester
› Confidence: 99.8%
› Techniques: T1566 (Phishing), T1110 (Brute Force)
When to Use This

When you need an instant, actionable report on ONE specific threat to share with legal, compliance, or your security team.

See AI Verdict Report

SentryGenie

Security Research AI
Primary Focus

Historical Threat Pattern Analysis

Deep-dive AI analyst across your entire scan history for exploration, research, and discovery.

Key Capabilities
  • Query across all historical scans & threat data
  • Ask plain-English research questions
  • Identify trends & campaign patterns
  • Slice-and-dice threat intelligence
  • Cross-scan correlation & analytics
  • Fraud intel & emerging threat discovery
Historical Research
› Q: "Show me all phishing campaigns targeting finance in Q2"
› Q: "Which hosting provider hosts most malware?"
› Q: "Correlate 50+ related domains from past scans"
When to Use This

When you need to RESEARCH patterns, investigate trends, explore relationships across multiple threats, or perform forensic analysis on historical data.

Explore SentryGenie
AspectAI Verdict ReportSentryGenie
Data ScopeOne scan at a timeAll historical scans
Report TypeAutomated threat analysis & verdictExploratory research & pattern discovery
Question TypeN/A - Auto-generated per scanPlain-English queries across data
Export FormatPDF (legal/compliance ready)JSON, CSV, custom analytics
Use CaseImmediate threat verdict sharingForensic analysis & pattern research
SpeedInstant (per-scan detonation)On-demand (sub-second)
Ready for Enterprise

Stop parsing cryptic logs.
Let Security Copilot do it.

From a single suspicious URL to a coordinated multi-domain phishing campaign — Security Copilot compiles, maps, and explains it all in seconds.