---
title: "Devo DeepTrace"
canonical: "https://docs.devo.com/space/latest/248840304/Devo%20DeepTrace"
format: markdown
---
> Macro (excerpt-include)



<details>
<summary>Watch video</summary>

> Macro (widget)
</details>

> Macro (toc)

## Overview 

**Devo DeepTrace **is an autonomous alert investigation and threat-hunting capability of the Devo Platform. It allows you to perform full investigations on alerts or suspicious events. DeepTrace attack-tracing AI pieces together the activity of malicious users or external actors enabling you to quickly analyze and report results in the form of traces - artifacts that fully and chronologically document each attack chain. 

> ℹ️ **Requirements**
> ℹ️ 
> ℹ️ This is not an out-of the box feature. If you want to start using **DeepTrace**, please visit [Devo support site](https://devo.my.site.com/support/s/).

## How can DeepTrace help you? 

Devo **DeepTrace **helps security teams autonomously investigate alerts and suspicious events and perform threat hunting via:

- **Fully documented attack chains that speed investigations: **Utilising attack tracing. Building traces, which fully and chronologically document each attack chain.
- **An AI engine that augments analysts:  **Providing analysts with context and points of reference detailing the attacker’s path through an organisation’s infrastructure by asking potentially hundreds of thousands of questions. It emulates how **SOC **(Security Operations System)** **analysts investigate alerts, incidents, and suspicious behaviours.
- **Autonomous investigations that accelerate context-based decision-making:**  Autonomously traverses historical data to document an adversary’s behaviour from start to finish of an attack, providing the facts analysts need to take effective action.
- **Autonomous threat hunting to up-skill analysts:** Helps threat hunters quickly construct and configure new hunts that map to **MITRE ATT&CK **framework tactics and techniques. Once refined and validated, these can be converted to new cadence-based threat detections.

## What permissions do you need to use DeepTrace?

To access DeepTrace and use its features in Devo, you need a specific permission, as well as other satellite permissions to access the areas where these features are used:

- Feature enabler: the *DeepTrace features* permission is required to enable all the options and menus throughout the platform.
- Auto-investigate in DeepTrace: the *Finders* permissions is required to open a search and the *Alert configuration* permission is required to define a new alert, which is where auto-investigations are configured.
- Trace status: the *Triggered alerts* permission is required to access the alerts history area, which is where traces are displayed and monitored.

![image](media://ca6af72a-8b2a-4352-83da-23203d03bdaa)

## What will you find in DeepTrace?

**DeepTrace** opens showing you a dashboard with the following sections:

![image](media://33f07d49-2a0e-4acc-920d-140898bc75a5)

<details>
<summary>Click here to see the details</summary>

| **Section** | **Icon** | **Detail** |
| --- | --- | --- |
| **Dashboard** | ![image](media://b0025f31-4db0-4667-871c-0c54e86bf76f) | Main dashboard provides a general overview of:<br>- Traces
- Devices
- Triggers
- Leads |
| **Traces** | ![image](media://3cb9b589-f375-4ca0-bcbd-fddc3ffe6586) | Traces page shows all the traces generated by Devo that depict suspicious activities, attacks and campaigns prioritized in order. |
| ** Devices** | ![image](media://e7b3248b-e4a4-44fc-a9ba-dbd2b8b6e8d8) | Risky devices page shows a list of devices that were implicated in traces with additional details. |
| **Search** | ![image](media://d299f0f9-01ae-478e-9a79-430e00112638) | Smart search page allows you to search for processes exhibiting suspicious behaviour to trigger investigations. |
| **Hunt** | ![image](media://b8404354-bf9c-4270-ae82-6f57a4cdba12) | Hunt page allows you to manage hunt for suspicious behaviour, processes, network, actions, etc. to trigger investigations. |
| **Triggers** | ![image](media://7b517f26-4d7c-4d76-810f-8ce98bff8f8f) | Trigger page provides all triggers for hunting whether it was triggered from Hunt configuration or by configured external alerts. |
| **Settings** | ![image](media://6fad6f03-3ce4-4826-8a43-43bc7ee1da3d) | Settings menu allows you to access various system, administration and monitoring settings. |
| **Log out** | ![image](media://ac32d359-f161-40f0-82c5-42a8d33b315a) | Logs out the current user. |
</details>

> ℹ️ **More information**
> ℹ️ 
> ℹ️ If you want to know more about the possibilities with **Devo DeepTrace,** visit [Devo support site](https://devo.my.site.com/support/s/).

## DeepTrace in Devo Platform

**Devo DeepTrace** allows **EDR (Endpoint Detection and Response)** and other data to be brought into  DeepTrace instance. The combined deployment will be configured to enable alerts and EDR data investigations using** DeepTrace**.* *Devo customers that have activated it in their domain, will have an additional tab in their navigation pane named **DeepTrace**.

![image](media://55a1ae16-1ae0-4360-8efc-6530e5608c4d)

There are two different ways to start sending events and alerts with **Devo DeepTrace**:

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> You can activate Auto-investigation in DeepTrace when creating a new alert definition from the** Data Search** tab. Click the **alert** icon to create a new alert definition and select **Auto-investigation in DeepTrace**. 
> 
> > ℹ️ **Auto-investigate in DeepTrace**
> > ℹ️ 
> > ℹ️ DeepTrace does not allow grouping tables, when clicking on the Auto-investigate in DeepTrace the **Auto-investigation query** opens with your query without grouping, you can also modify here the query that is going to be investigated by **DeepTrace**.
> > ℹ️ 
> > ℹ️ ***rawMessage***** field required**
> > ℹ️ 
> > ℹ️ The *rawMessage* field must be included in the Auto-Investigation query definition (`select rawMessage`), even if it's not in the alert definition query. Otherwise, DeepTrace will not trigger an investigation even though the alert itself was triggered.
> 
> ![image](media://371fddb0-fafa-4b68-924a-0f2c533f0d95)
> 
> 
> > Macro (rw-tab)
> 
> It is possible to activate **DeepTrace** when opening a table in Data Search by clicking on the **engine tool button** **→ New → DeepTrace Investigation**.
> 
> ![image](media://221fcb0a-5ad7-4bc2-bd99-f8f412ded973)
> 
> You can also send a **single event** to be investigated in DeepTrace. To do that select the event and do right-click to open the options and start investigating in **DeepTrace**.
> 
> > ⚠️ **Why can’t I see that option?**
> > ⚠️ 
> > ⚠️ Be aware this option will be available when there is **no grouping** and at least **one event **is selected in the table.

Once the alert definition is created you can see the status of the alert by clicking on the **Alert **tab or **DeepTrace** tab in the navigation pane.

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> Go to **Alerts** in the navigation pane. Check the **Trace status** column to see the status of your alert. You can also click on the **DeepTrace** icon that appears in the **Actions** column to open **DeepTrace**.
> 
> ![60_ Devo DeepTrace.png](media://e39c500e-c3a8-417d-82d6-2a512ad10823)
> 
> There are different **trace statuses**:
> 
> | **Status** | **Details** |
> | --- | --- |
> | **No trace** | There have been some suspicious behaviours on the trace but no threats. |
> | **Waiting** | The investigation is being done. |
> | **Trace found** | There are some traces that need your attention. |
> | **Error** | An error occurred which prevented the investigation from proceeding. |
> 
> > Macro (rw-tab)
> 
> Go to **DeepTrace** in the navigation pane. DeepTrace opens showing you a Dashboard with the following sections:
> 
> - **Traces**: The traces generated by Devo that depict suspicious activities, attacks and campaigns prioritised in order.
> - **Devices**: Devices that are implicated in the trace.
> - **Triggers**: All the trigger information of the trace.
> - **Leads: **Investigations of the trace.
> 
> ![image](media://6c1b9430-e39b-4687-bd9d-d4a5cc72180a)

> ℹ️ **Devo Connect**
> ℹ️ 
> ℹ️ Learn more about **DeepTrace** in the the related articles:
> ℹ️ 
> ℹ️ - [Anatomy of a Trace: An all encompassing guides to “traces”, the key foundational element of Devo DeepTrace.](https://community.devo.com/guides-and-troubleshooting-82/devo-deeptrace-anatomy-of-a-trace-494)
> ℹ️ - [AI Assisted Hunting: Everything you need to know about hunting in DeepTrace.](https://community.devo.com/guides-and-troubleshooting-82/deeptrace-ai-assisted-hunting-495)
> ℹ️ - [How to Reduce Manual Investigative Processes with DeepTrace](https://community.devo.com/guides-and-troubleshooting-82/how-to-reduce-manual-investigative-processes-with-deeptrace-630).
> ℹ️ - [How to Trace Every Attack from Start to Finish with DeepTrace](https://community.devo.com/guides-and-troubleshooting-82/how-to-trace-every-attack-from-start-to-finish-with-deeptrace-644).