> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/ko/ai/examples.md).

# Panther AI 워크플로 예시

## 개요

이 페이지의 동영상들은 일반적인 [Panther AI](/ko/ai.md) 워크플로를 보여줍니다. 최상의 시청 경험을 위해서는 다음을 클릭하는 것이 좋습니다. **YouTube에서 보기** 각 동영상의 왼쪽 아래 모서리에 있는 버튼을 클릭하거나 전체 화면 모드로 보세요.

## 알러트와 함께 Panther AI 사용하기

### AI 알러트 분류 실행

다음 예시에서 [알러트 트리아지](/ko/alerts.md#panther-ai-alert-triage), Panther AI:

* 알러트, 관련된 디택션(파이썬 코드 포함), 지난 7일 동안 해당 디택션으로 생성된 알러트, 그리고 지난 24시간 동안의 모든 알러트를 읽어 문맥을 수집합니다
* 데이터를 분석합니다
* 다른 도구(예: [`panther_ai_enrichments_lookup`](/ko/ai.md#enrichment-and-context))를 사용하고 데이터 레이크 쿼리를 실행하여 추가 문맥을 수집할 수 있습니다

{% embed url="<https://youtu.be/d7Kvturpbrg>" %}

### AI가 제안한 후속 프롬프트를 실행하여 알러트 분류하기

* 이 예시에서는, 다음 이후 [AI 알러트 트리아지](/ko/alerts.md#panther-ai-alert-triage) 가 실행되면 사용자가 다음의 옵션 중 하나를 클릭합니다: **추천 후속 AI 프롬프트** 섹션.

{% embed url="<https://youtu.be/LfzTJn0rUFw>" %}

### 전체 보고서를 위해 여러 AI 응답을 집계하기

다음의 [AI가 제안한 후속 프롬프트를 실행하여 알러트 분류하기](#running-an-ai-suggested-follow-up-prompt-to-alert-triage) 위의 예시에서 초기 AI 알러트 분류가 생성된 후, 우리는 인접한 우려 사항을 살펴보기 위해 제안된 후속 프롬프트를 클릭합니다. 두 번째 응답은 첫 번째 응답과 "하위" 응답으로 관련되어 있습니다.

제안된 후속 프롬프트를 클릭하거나 직접 입력하면, 응답들(초기 분류와 후속 응답)은 서로를 인식합니다. 이를 통해 응답 자체에 대해 질문할 수 있으며, 예를 들어 이를 종합 보고서로 결합할 수 있습니다.

예를 들어, 다음 초기 AI 알러트 분류를 살펴보세요:

<figure><img src="/files/df5c6daae3e36fd65b37e76cf19ae98f9b16c729" alt="Under an &#x22;ALB Web Scanning&#x22; header is a Panther AI prompt box, followed by Summary and Key Findings sections."><figcaption></figcaption></figure>

제안된 프롬프트를 탐색하고 사용자 지정 후속 질문을 한 뒤, [응답 기록 목록](/ko/ai/using-panther-ai/managing-ai-response-history.md#viewing-ai-response-history) 은 다음과 같습니다:

<figure><img src="/files/35afa1698aeb55a01ab2a848112c301ba5daa539" alt="Under an &#x22;AI Triage History&#x22; header, there is a sub-header labeled &#x22;Today.&#x22; Under it is a table with six entries."><figcaption></figcaption></figure>

초기 알러트 분류 응답(부모 응답)을 클릭하고 다음을 입력하면:

> 관련된 모든 AI 응답을 짧은 보고서로 요약하세요.

<figure><img src="/files/219abac57e3321f45ebdb4527d78f72b14b85db7" alt="Under an &#x22;ALB Web Scanning&#x22; header is a Panther AI prompt bar and sections titled &#x22;Summary&#x22; and &#x22;Key Findings.&#x22;"><figcaption></figcaption></figure>

다음과 같은 결과를 볼 수 있습니다 **ALB 웹 스캐닝 조사 요약**:

<figure><img src="/files/ba2fc014cc0794c529c9bbbb50d97425ed68b583" alt="Under an &#x22;ALB Web Scanning Investigation Summary&#x22; header are various sub-headers, including &#x22;Overview,&#x22; &#x22;Key Findings,&#x22; and &#x22;Risk Assessment.&#x22;"><figcaption></figcaption></figure>

다음 항목을 열면 **분석** 요약에 포함된 내용을 통해 Panther AI가 모든 관련 응답을 읽고 있음을 보여줍니다:

<figure><img src="/files/57ebed0adc811b8efa18c6d594b99f5e590c9f2c" alt="There is an &#x22;Analysis&#x22; header with a &#x22;Thinking steps&#x22; sub-header."><figcaption></figcaption></figure>

### 디택션 런북을 사용하여 AI 알러트 분류를 지시하기

동안 [알러트 트리아지](/ko/alerts.md#panther-ai-alert-triage), Panther AI는 다음의 지침을 읽도록 지시됩니다 [알러트 런북](/ko/alerts/alert-runbooks.md). 이를 활용하면 알러트 분류 시 Panther AI에게 특정 작업을 수행하도록 지시할 수 있습니다.

예를 들어, `런북` 값으로 다음을 입력할 수 있습니다:

* "이벤트의 사용자에 대해 \\"Okta Historical Profile\\"라는 저장된 쿼리를 컨텍스트로 실행하세요."
* "모든 로그에서 다음의 활동을 검색하세요: `clientIP` 지난 일주일 동안을 컨텍스트로."
* "알러트에 항상 요약이 포함된 댓글을 추가하세요."

{% hint style="info" %}
[Panther AI에 적합한 작성 방법에 대해 더 알아보세요 `런북` 여기](/ko/alerts/alert-runbooks.md#tips-for-writing-an-effective-runbook).
{% endhint %}

아래 예시에서는 Panther AI가 디택션의 `런북` 내용을 알러트 분류 중 고려한다는 것을 보여주기 위해 다음 내용을 `런북`:

> 분석 보고서 전에 리머릭 형식의 요약을 추가하세요.

응답에서 리머릭을 볼 수 있습니다:

<figure><img src="/files/2ff1de2d5b8caecaaa3f6ca1fce480b572db83e9" alt="Under an &#x22;ALB Web Scanning Analysis&#x22; title are various sections with text under them, such as &#x22;Summary&#x22; and &#x22;Key Findings.&#x22;"><figcaption></figcaption></figure>

### 알러트 목록의 AI 요약 생성

* 아래 예시에서 Panther AI는 [최근 알러트를 요약합니다](/ko/alerts.md#panther-ai-summary-of-alerts-list) 알러트 목록 페이지에서.

{% hint style="warning" %}
이 동영상은 오래된 Panther Console을 보여줍니다. 알러트 목록 페이지에는 더 이상 프롬프트 바가 없으며, 대신 다음이 있습니다: **AI로 요약** 버튼이 있으며, [이를 클릭하면 알러트 요약을 생성할 수 있습니다](/ko/alerts.md#panther-ai-alert-triage).
{% endhint %}

{% embed url="<https://youtu.be/thB5TlsfG2g>" %}

### 알러트 목록에서 공격 시각화하기

아래 예시에서는 특정 공격과 관련된 알러트(다음을 통해 생성된 [적대자 에뮬레이션](https://github.com/panther-labs/stratus-red-team))가 알러트 목록 페이지에서 선택된 뒤, [AI 요약이 생성되었습니다](/ko/alerts.md#panther-ai-summary-of-alerts-list).

생성된 AI 요약의 프롬프트 바에 다음을 입력했습니다, `흐름도로 공격을 시각화하세요. 이 알러트에 대한 모든 지원 데이터를 분석하세요.`:

<figure><img src="/files/5784b3f50fa2e48c081650361ace4d13cd86f7ed" alt="A prompt bar is shown above a block of text output containing Summary and Key Finding sections."><figcaption></figcaption></figure>

그 결과 Panther AI는 공격 체인의 다이어그램을 생성합니다:

<figure><img src="/files/59a2826230b2e08b03116951839803b50e4a935e" alt="A diagram of an attack chain in shown, with a number of boxes and arrows. Boxes contain text such as &#x22;Defense Evasion&#x22; and &#x22;Impact &#x26; Exfiltration.&#x22;"><figcaption></figcaption></figure>

## 지표 검색에 Panther AI 사용하기

위협 인텔리전스 보고서에서 악성 IP 주소와 같은 침해 지표(IoC)를 받고 "내 로그에서 이 값들 중 일부를 본 적이 있는가?"라고 묻는 것은 흔한 일입니다.

IoC에 대한 위협 헌팅은 검색 결과가 없으면 간단합니다. 그러나 IoC가 발견되면 해당 활동을 검증해야 하므로 과정이 오래 걸릴 수 있습니다. 데이터 레이크를 수동으로 검색하는 대신 Panther AI에게 최근 활동을 요약해 달라고 요청할 수 있습니다.

{% embed url="<https://www.youtube.com/watch?v=CfjVmKq8N5w>" %}

## Search 및 디택션과 함께 Panther AI 사용하기

### 검색 결과 AI 요약

* 아래 예시에서 Panther AI는 다음을 수행합니다 [검색 결과 요약](/ko/search/search-tool.md#panther-ai-search-results-summary) 최근 [AWS Application Load Balancer (ALB)](/ko/data-onboarding/supported-logs/aws/alb.md) 이벤트.

{% embed url="<https://youtu.be/u4vRGPvMT6c>" %}

## 저장된 검색과 함께 Panther AI 사용하기

### 재사용을 위해 SQL 쿼리 작성 및 저장

아래 예시에서는 Panther AI에게 SQL 쿼리(또는 [저장된 검색](/ko/search/scheduled-searches.md))를 작성하고 이름을 붙여 향후(사람과 Panther AI가) 사용할 수 있도록 요청합니다. 프롬프트는 다음과 같습니다:

> ALB 로그의 일주일치 데이터에서 상위 10개 IP 주소를 계산하는 SQL 쿼리를 작성해 주세요.\
> 쿼리를 "Top 10 IP Addresses in ALB."라는 이름으로 저장하세요. 쿼리를 실행할 때 결과를 시각화하도록 설명란에 Panther AI용 메모를 추가하세요.

{% embed url="<https://www.youtube.com/watch?v=vwPorDpuVVY>" %}

### 저장된 SQL 쿼리 실행 및 편집

* 이 예시에서는 Panther AI에게 이름이 지정된 [저장된 검색](/ko/search/scheduled-searches.md) (하지만 SQL 변경이 필요한 수정이 적용된) 쿼리를 실행하고, 각 IP 주소를 보강한 다음, 결과를 시각화하도록 요청합니다.

{% embed url="<https://www.youtube.com/watch?v=46XUZMi0q_Q>" %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/ko/ai/examples.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
