Dropzone AI Documentation
WebsiteTest Drive
  • Dropzone Documentation
  • Overview
    • Alert Sources
    • Data Sources
    • Communicators
    • On-prem Support - Dropzone Connector
    • Interactive Chat
    • Metrics Guide
  • Dropzone Administraton
    • Team Admin
      • Google Workspace SAML
      • Okta SAML
  • Dropzone Integrations
    • Alert + Data Source Integrations
      • Amazon Web Services (AWS)
        • Cross-Account Access via CloudFormation
        • Cross-Account Access via Console
      • CrowdStrike
      • Datadog
      • Elasticsearch
      • Google Workspace
      • Google GCP
      • Jira
      • Microsoft 365 / Microsoft Defender
      • Palo Alto Networks Firewall
      • Panther
      • SentinelOne
      • Splunk
      • Sumo Logic
    • Alert Integrations
      • Gem
    • Communicators
      • Slack Communicator
    • Data Source Integrations
      • AbuseIPDB
      • Active Directory (LDAP)
      • Archive Inspector
      • Blocklist.de
      • CAPA
      • Censys
      • Crowdstrike Falcon Intelligence
      • DNSResolver
      • File
      • GreyNoise
      • Hybrid Analysis
      • Host.io
      • IPInfo.io
      • IPQualityScore
      • MalwareBazaar
      • Nuclei
      • NVD
      • Okta
      • oletools
      • OpenSSL Sign Code
      • PDF Analysis
      • Perplexity AI
      • PhishTank
      • Shodan
      • TShark
      • QRadar
      • UnshortenMe
      • URLhaus
      • Urlscan.io
      • VirusTotal
      • Vision
      • WHOIS
      • YARAify
Powered by GitBook
On this page
  • Omni Chat
  • Chat Page
  • Investigation Chat

Was this helpful?

  1. Overview

Interactive Chat

PreviousOn-prem Support - Dropzone ConnectorNextMetrics Guide

Last updated 8 months ago

Was this helpful?

The Dropzone platform allows you to interact directly with the Dropzone AI Agent. Some notable features:

  • It has access to all the same sources that are available during investigations

  • It shows you what sources it's using as it queries them

  • All evidence it gathers can be viewed

You can engage the chat in several ways as described below.

Omni Chat

The Omni Chat is present on most pages, allowing you to chat with the Dropzone AI agent anywhere you see this chat logo in the bottom right:

In the example below, we're looking at investigations of recent phishing emails. Without leaving this screen you can easily ask information about the the recipient, bucky.bennett, and learn that they're one of the company's accountants, which was determined by Dropzone querying the corporate directory.

Chat Page

You can reach the chat page via the "Chat" button in the top menu. From here you can create new chat sessions or access the Omni chat.

Each chat session has its own context, much like a chat session with LLMs like ChatGPT.

As you can see in the above screenshot, the Dropzone user wendell is currently asking questions about user activities, and Dropzone has automatically queried their Google Workspace environment (activity logs and directory information) to find answers.

On the left you can see a previous session, as well as the persistent "Omni Chat", and switch to any of these to continue those conversations.

Chat sessions can be deleted by hitting the trash can icon.

Investigation Chat

Each investigation has its own chat that has access to all the investigation context. This can be found on the right in the "Chat" tab.

Here our analyst wendell has determined that they need to reach out to Bucky, the recipient of the phishing email. They can quickly look up contact info without leaving the page.

Chat icon
Omni chat: answers where you need them
Chat Menu
Chat Session Example
Deleting a chat session
Investigation Chat