Spectra Assistant
Introduction
Spectra Assistant is an AI-powered chat assistant available for both the Classic and New UI. It supports initiating a context-aware chat, dynamic analysis and interacting with specific sample details directly from within the assistant interface.
To access Spectra Assistant, click the Spectra Assistant icon at the bottom right corner or press Alt + C. Select + New Chat to start a new chat. To chat about a specific sample, go to the Search & Submissions page on Classic UI or IoC Submissions on New UI and select Spectra Assistant > Chat about this sample. On New UI, you can also select a sample and click the Ask Assistant icon at the top of the screen to open the assistant chat in a side pane.
Side pane view is only available in the New UI.
Enabling Spectra Assistant
To enable Spectra Assistant, go to Administration > Configuration > Experimental Features and select Enable AI Assistant. For more details, see Experimental Features.
Spectra Assistant requires Spectra Intelligence credentials to be configured on the appliance. If Spectra Assistant is enabled but not working, contact ReversingLabs Support.
Options and Features
Sample Analysis
To select a specific sample for analysis, go to the Search & Submissions page on Classic UI or IoC Submissions on New UI and select Spectra Assistant > Chat about this sample. To select a sample from your local machine, click the attach icon in the chat box and navigate to the sample. This option is not available in the side pane view.
File Analysis
To view the analyzed file, click the View file icon above the chat box. This opens a File viewer window with information pulled from the Content section of the sample report.
To access the Analysis Status menu, click the up arrow above the chat box. This menu shows which analysis was performed, Static, Dynamic or Auxiliary, whether the analysis is complete, indicated by a green checkmark and Done, whether it was not performed, indicated by Not yet analyzed, and the number of finished analyses (e.g. 1 of 3 done).
Conversation Options
If you navigate to another page and have an open conversation, you can continue it by clicking the Spectra Assistant icon and selecting the Continue "Conversation Title" option.
To copy or download the conversation, click the Copy conversation and Download conversation icon above the chat box.
Accessing Chat History
You can access your chat history either by clicking the Spectra Assistant icon and selecting See Chat History or selecting a chat from the chat history menu on the Spectra Assistant page.
Overview of Tools and Connectors
For an overview of built-in tools and connectors, click the connectors icon at the top right corner of the Spectra Assistant page. For a detailed overview of tools, see Available tools.
Prompts and Skills
Spectra Assistant comes with a set of pre-determined prompts and skills to help address the most common starting points.
Available Prompts
When starting a new chat, a list of prompts is displayed on the screen. Alternatively, click the Prompt template icon in the chat box to open the prompt quick-start window and select Use prompt.
| Prompt | Description |
|---|---|
| Analyze Sample | Look up a file by hash for classification and indicators of compromise. |
| Threat Report | Create a comprehensive threat report using all available analysis data for this sample. |
| Threat Hunt | Search for samples on this appliance across a wide range of criteria. |
| Incident Response | Triage a live incident from a hash or indicator and get containment and remediation guidance. |
| Threat Landscape | Summarize the malware families seen in submissions to this appliance in the last 48 hours. |
| Behavior Timeline | Show a timeline of the sample's sandbox behavior: process activity, file system changes, registry changes, and network connections, in chronological order. |
Available Skills
To access available Spectra Assistant skills, click the / icon in the chat box and select the skill from the list of available skills or click Browse skills to see a detailed description and use cases for all skills.
| Skill | Description |
|---|---|
/phishing-email-triage | Triage suspicious phishing emails by analyzing attachments, URLs, and metadata. |
/phishing-url-analysis | Analyze suspicious URLs for phishing, credential harvesting, malware delivery, and other threats. |
/smart-dynamic-reanalyzer | Diagnose why a dynamic sandbox analysis produced little to no behavioral intelligence, then recommend and execute a better reanalysis. |
/spectra-advanced-search | Use this skill to search for files, malware, IOCs or threat intel. |
Limitations
- Usage is capped at 20,000 credits per Spectra Intelligence account. Credit usage depends on the complexity of the prompt or skill. To check your usage, click the Quota Indicator (pie chart icon) in the top navigation bar.
- At 80% context capacity, the user is notified to either start a new chat or continue with summarized content.
- Sample analysis works only with ReversingLabs analyses, not with integrations.
- Password-protected files cannot be uploaded.