تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dlp_investigation_agent-3368a8b9-858a-4912-9589-903ddaf5819f/135fa726-2e66-4220-9d56-991400d13e62_cyeraicon216.png

Cyera DLP Investigation Agent

بواسطة Cyera

إصدار تجريبي مجاني

Streamline data loss prevention with Cyera's powerful investigation agent.

Cyera Omni DLP Investigation Agent

An AI-powered Security Copilot agent that helps security teams investigate and triage Data Loss Prevention incidents across email, endpoints, messaging, cloud, and GenAI platforms. Run on-demand from the Agent Management view to analyze incidents with organizational context, identify patterns, and prioritize incidents requiring immediate attention.

Agent Tasks

- Investigate DLP incidents across multiple channels (email, endpoint, messaging, cloud, GenAI)
- Analyze user behavior with organizational context (manager, department, risk status)
- Identify data leakage patterns and policy violations across channels
- Prioritize incidents by severity and business impact
- Review business justifications to distinguish legitimate use from actual data loss risks
- Generate department and user risk reports with actionable insights
- Provide direct links to provider incident URLs (Purview) for deeper investigation

Agent Workflow

**How to Use:**
1. Navigate to Agent Management view in Security Copilot
2. Select "Cyera Omni DLP Investigation Agent"
3. Click "Run one time"
4. Provide investigation parameters:
- **UserRequest** (required): Describe your investigation (e.g., "Show high severity DLP incidents from the last 7 days")
- **IngestLookbackDays** (optional): Maximum days to look back for ingested data (default: 30)
5. Review results with executive summary, incident details, and recommendations

**Inputs:**
- Data Tables: CyeraOmniDlpIncidents_CL from Microsoft Sentinel/Log Analytics
- UserRequest: Natural language investigation request parameter
- IngestLookbackDays: Time range for data ingestion filter (default: 30 days)
- Supports filtering across channels: Email, Endpoint, Messaging, Cloud, GenAI
- Analyzes user, department, severity, and policy dimensions

**Outputs:**
- Executive summary with key statistics (total incidents, high-severity count, channel breakdown)
- Incident tables with severity, channel, user, policy, and business justification
- User activity analysis with manager hierarchy and department context
- High-risk incident alerts with provider incident URLs for Purview investigation
- Pattern analysis showing common data leakage scenarios by channel and policy
- Policy violation reports with affected users and channels
- Department risk distribution showing incident concentration
- Email-specific details (subject lines, recipients) and endpoint details (device, file paths)
- Risky user identification based on identity system flags

Prerequisites

- Microsoft Security Copilot with active SCU capacity
- Microsoft Sentinel workspace with Log Analytics
- Cyera Omni DLP data ingested into CyeraOmniDlpIncidents_CL table
- Microsoft Purview DLP (recommended for incident URLs)
- Agent installed and configured with workspace connection

Key Features

- **Execution-Based**: Run on-demand from Agent Management view with specific investigation parameters
- **Cross-Channel Visibility**: Single view across email, endpoint, messaging, cloud, and GenAI channels
- **Organizational Context**: Enriches incidents with manager, department, and office location data
- **Pattern Detection**: Identifies common data leakage scenarios and policy violations
- **Risk Prioritization**: Automatically highlights high-severity incidents and risky users
- **Business Context**: Reviews justification fields to reduce false positives
- **Purview Integration**: Provides direct links to Purview incident URLs for detailed investigation
- **Flexible Investigations**: Parameterized requests for different analysis types (user, channel, severity, department)

Typical SCU Consumption

Approximately 0.5-1.5 SCU per agent execution, depending on investigation complexity and data volume.

لمحة سريعة

https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dlp_investigation_agent-3368a8b9-858a-4912-9589-903ddaf5819f/52257044-686f-496d-abc6-37f045ea76f5_trailer.png
/staticstorage/20260716.1/assets/videoOverlay_62a424ca921ff733.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dlp_investigation_agent-3368a8b9-858a-4912-9589-903ddaf5819f/9b014338-7e9c-4ad9-8f6f-9d86a5a2255b_agentmanagementview.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dlp_investigation_agent-3368a8b9-858a-4912-9589-903ddaf5819f/85b2dd9f-3512-421e-8fbd-c3ec9fde8cb0_02agentsetupconfig.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dlp_investigation_agent-3368a8b9-858a-4912-9589-903ddaf5819f/fee828c7-a446-4a9a-89fb-bcbab9d1a5d8_30dayDLPincidents.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dlp_investigation_agent-3368a8b9-858a-4912-9589-903ddaf5819f/44c8f01b-cfdf-428b-95e2-60db36a3381e_Excelviewlink.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dlp_investigation_agent-3368a8b9-858a-4912-9589-903ddaf5819f/c79a82cf-e0e1-4aaf-a8c3-cb038c8c9543_UserRequestpreexcecution.png
العربية (الإمارات العربية المتحدة)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام العلامات التجارية حول إعلاناتنا إدارة ملفات تعريف الارتباط