Generate recommended actions for a security incident with Now Assist for Security Incident Response

  • Release version: Zurich
  • Updated July 31, 2025
  • 3 minutes to read
  • Automatically generate the next steps your analysts can take to help them close a security incident in the Security Incident Response Workspace. The recommended steps are based on existing security incidents and knowledge articles.

    Procedure

    1. Navigate to All > Security Incident > Security Incident Response Workspace and open a security incident that is assigned to you.
    2. Select the Recommended Actions icon in the contextual sidebar.
      Recommended actions button selected in the contextual sidebar
    3. Select Get recommendations.
    4. In the Check AI generated content modal, select I acknowledge.
      Generated recommended actions are displayed in cards. Up to four references for the actions are displayed at the top. These references can be any combination of knowledge articles (KB)s or security incidents (SIR#).
    5. In a card, choose one.
      Note:
      Click Show More button to view the recommended actions in chronological order, guiding the security analysts through the next best steps for analyzing and investigating the security incident.
    6. Optional: Select the refresh icon in the Recommended actions panel to regenerate the recommended actions.
      The recommended actions remain cached for one hour. You might choose to refresh the recommended steps if:

      You must regenerate the actions starting with step 3 to view the them after one hour.

    7. Optional: Click on the Helpful or Not helpful icons to share your feedback on the recommendations.
      Note:
      If you mark a recommendation as Not Helpful, then you’ll have the option to add detailed feedback which helps in improving the quality of future recommendations.
    8. Select Create response task on a card.
      A new tab opens in the workspace. The Short description and the Description fields are populated automatically from the details on the recommended action card you selected.
    9. Edit the form as needed and the select Save to create the response task.
      Until you change the Value on the system property, the two options on any recommended actions you generate remain View details and Create response task.
    10. Optional: Create a response task from the recommended actions.
      By default, the workflow provides you with the option to save the recommended actions to work notes from the cards. If you want to have the option to create a response task from an action card instead of saving them to work notes, you must change the Value field for the SecOps Recommended Action [sn_sec_ra.card_action_config] system property.