Close the ticket like a senior would.
VerdictIQ AI explains the verdict in plain language and stays for the follow-up, so a tier-1 analyst sees why it scored high and acts on it, block or escalate, without waiting on a senior tap.
It isn't a one-and-done report. It's your own analyst on call: talk to it in plain language, ask follow-ups, and go deeper signal by signal until the picture is clear. The deterministic verdict ships either way; this conversation lives in the portal, on top of it.
A static write-up explains the score once and stops. Real triage is the second and third question, the follow-up the paragraph didn't cover. With no one to ask, the IOC sits in the queue or rides on a guess.
Every verdict already ships with the signals, the score and the recommended action. VerdictIQ AI turns those signals into plain language you can question, so your most junior analyst acts without escalating.
Turns the score, signals and recommended action into a plain-language read your most junior analyst can act on.
Ask why it scored, what a signal means, or what to do next, in plain language, and go deeper one question at a time.
Talk to it like a senior colleague. Ask whatever is on your mind and get a precise, evidence-backed answer, deepening one turn at a time.
Open VerdictIQ AI from the Analysis sidebar, or click the AI hotspot next to a verdict you are already reading. Either way the assistant works from what the deterministic engine just produced and answers alongside the same verdict.
Inside the portal, the left nav has an Analysis section with three actions: VerdictIQ AI, IOC Verdict and Bulk Replay. Open VerdictIQ AI for a full-screen conversation, or click the AI hotspot on a verdict to open the same assistant in the side panel with the question already put to it.
The assistant works from the signals and evidence VerdictIQ's own engine just produced. The model does not browse the web or call a third party, and a new thread starts with no carry-over from the last one.
The read arrives alongside the verdict, and you keep going: ask why a signal fired, what to do next, or bring a file into the full-screen conversation. Score, risk level and recommended action don't move; the conversation is added on top.
Skip VerdictIQ AI and the deterministic verdict still ships: through the API, through IOC Verdict in the portal, or through Bulk Replay. The AI layer only runs when you open it.
Tier 1 closes the ticket without a senior tap. MSSP analysts speak the same language across tenants. CTI triages at first sight. Detection engineers turn a verdict into a hunt hypothesis.
VerdictIQ AI explains the verdict in plain language and stays for the follow-up, so a tier-1 analyst sees why it scored high and acts on it, block or escalate, without waiting on a senior tap.
Every tenant gets the same senior-level write-up from the same signals, so the rationale reads consistently across analysts and shifts, with no drift as you add tenants.
The narrative tells you why an IOC matters and which relational signals tie it to known infrastructure, so you triage before committing a full investigation.
The write-up spells out which behavioral signals fired and why, so an engineer turns a single verdict into a detection rule or a hunt hypothesis instead of reverse-engineering a score.
VerdictIQ AI has a single, narrow job: turn a deterministic verdict into an answer an analyst can act on, and stay for the follow-ups. Anything beyond that lives on a different surface.
No narrative key, no explain flag, no SDK call. Your SIEM and SOAR see the deterministic verdict only.
A deterministic signal engine computes the verdict before the model writes a word. Take the engine away and there is nothing to narrate.
It answers from what VerdictIQ's own engine produced. The model doesn't browse the web or reach a third party on its own.
Answers are bound to the exact signals and evidence of the verdict in front of you. It can only restate what the engine proved, never invent a reason that didn't fire.
Grounded in VerdictIQ's own signal taxonomy, not a stock model guessing about IOCs. Every line traces back to a named signal.
VerdictIQ AI reasons like a senior analyst and runs on fresh data every call: live DNS, WHOIS, relational and behavioral signals, not a cached summary. You get a read that reflects the infrastructure as it stands right now, explained in plain language.
It is a conversation, but not a general-purpose one: a full-screen page in the portal and a side panel next to any verdict, holding the thread across follow-ups. What separates it from a stock chatbot is grounding: it answers from VerdictIQ's own signals, and none of it moves the verdict.
There is no per-IOC surcharge and no separate subscription. Every plan, free tier included, comes with an AI token budget that refreshes daily and is sized by plan. If your team needs more than the included budget, extra tokens are arranged with sales and land in a pool the whole team draws from.
No. The score, risk level and recommended action are functions of the signals, not the model. VerdictIQ AI explains the verdict and answers questions about it; it does not adjust the deterministic output.
The verdict path is fully LLM-free: score, signals and recommended action come from deterministic fusion, with no model in the loop. VerdictIQ AI is the one part that uses an LLM, and that is what the AI token budget covers. It runs only when an analyst opens it.
No. VerdictIQ AI is portal-only. API and SDK clients always receive the deterministic verdict, no narrative field, no explain flag.
An internally-managed LLM, not a public third-party API. Sub-processors and model provenance are disclosed at /trust.
No. Your inputs are not retained for model training, and sub-processor contracts forbid training on customer data. A thread stays in your own session; it is never carried into anyone else's.
The verdict is computed before the assistant reads a word, so text carried by an IOC cannot move the score, the risk level or the recommended action. The assistant answers from the structured signals and evidence the engine produced, and it has no write path back into the verdict.
The deterministic verdict ships unchanged through the API and the portal. VerdictIQ AI simply doesn't answer that round; the score, risk level and recommended action remain identical.
The narrative is plain text for analyst consumption. The structured fields (risk_level, recommended_action, signals[]) are designed for SIEM ingestion. Every signal maps to MITRE ATT&CK techniques.
No. It cites what already fired, not what it imagined. Every sentence is anchored to a signal or evidence the deterministic engine already produced for that IOC. If a signal didn't fire, the answer doesn't mention it; nothing is invented to fill a gap.
Sign in to the VerdictIQ portal and open VerdictIQ AI on any IOC. The deterministic verdict ships either way; the senior-analyst read, and every follow-up you ask, comes on top. Free tier, no credit card.