Kaspersky Next XDR Expert
Analyzing using KIRA

After configuring the integration, you can analyze commands using KIRA.

To perform an analysis:

  1. Go to the card of the event or correlation event and on the toolbar in the event card, in the Analyze using KIRA drop-down list, select the field whose value you want to analyze.

    This opens the Analyze using KIRA window.

  2. This opens the Analyze using KIRA window, displaying the command to be analyzed. You can do the following:
    • If the command is obfuscated, it is de-obfuscated automatically without spending tokens. If you want to analyze the command in obfuscated form, in the Actions drop-down list, select Revert to original string. If necessary, you can de-obfuscate the string again.
    • If you want to know in advance how many tokens will be spent on analysis, in the Actions drop-down list, select Calculate size in tokens. Number of tokens for analysis = number of tokens to send a request + number of tokens to produce a response.
    • To analyze the command, click the Analyze button.

      If you have enough tokens, the analysis and the Request to KIRA task are started.

      Processing the request may take 30 seconds or longer.

      Tokens are expended even if the request returns an error saying that the requested topic is in the deny list; the information about remaining tokens is also updated.

The command is analyzed.

The result of the analysis is available in the same Analyze using KIRA window: the output, a brief summary, and a detailed analysis. You can also view the result in a separate window by clicking View result in the pop-up notification. This opens a separate KIRA result window, from which you can also click the link to Go to event. After the analysis is completed, the Result is displayed on the KIRA analysis tab in the event card and is available for viewing by all users with access to the Analyze using KIRA functionality.

You can also view the result of the analysis in the Task manager section in the properties of the Request to KIRA task. You can click the name of the task to select one of the following commands in the context menu:

  • View result shows the results of the task from the cache to any user with access to KIRA tasks; no tokens are expended.
  • Restart performed the analysis disregarding the data of the previous analysis stored in the cache; the analysis expends tokens.