@cryptotaxi247 / CoPilot / commits / bf4eff8e

Add CoPilot Searches documentation and navigation entry (#756)

taylor_socfortress committed Mar 9, 2026 at 09:54 UTC bf4eff8ee120e5f379e8056b02073b3c0a0e4254
3 files changed +160 -1
docs/docs.json
+2 -1
@@ -185,7 +185,8 @@
185 "power-features/github-audit",
186 "power-features/ai-analyst",
187 "power-features/atomic-red-team",
188 - "power-features/report-creation"
188 + "power-features/report-creation",
189 + "power-features/copilot-searches"
190 ]
191 }
192 ]
docs/power-features/copilot-searches.mdx new
+157
@@ -0,0 +1,157 @@
1 +---
2 +title: CoPilot Searches (threat hunting)
3 +description: Pre-built detection queries for proactive threat hunting across your Wazuh Indexer data — filterable by platform, severity, MITRE ATT&CK technique, and CVE.
4 +---
5 +
6 +CoPilot Searches is a library of ready-to-run detection queries designed for threat hunting in your Wazuh Indexer. Instead of writing queries from scratch, you browse a curated catalog, pick a rule, fill in a few parameters, and execute — all without leaving CoPilot.
7 +
8 +The detection rules are maintained in a public GitHub repository:
9 +- https://github.com/socfortress/CoPilot-Search-Queries
10 +
11 +CoPilot automatically fetches and caches the latest rules from this repository so your catalog stays up to date.
12 +
13 +---
14 +
15 +## What it is
16 +
17 +A searchable, filterable catalog of detection rules that you can:
18 +
19 +- **Browse** by platform (Linux, Windows, PowerShell), severity, status, or MITRE ATT&CK technique
20 +- **Filter by CVE** to find rules that detect exploitation of specific vulnerabilities
21 +- **Search** by keyword across rule names and descriptions
22 +- **Execute** directly against your Wazuh Indexer to hunt for matching activity
23 +- **Generate Graylog queries** for rules that include a Graylog query template
24 +- **Provision as Graylog alerts** to turn any rule into a recurring, automated alert
25 +
26 +Each rule includes:
27 +- A description of what the rule detects
28 +- The MITRE ATT&CK mapping
29 +- Required parameters (customer code, agent name, time range, etc.)
30 +- The underlying search query
31 +- Severity and risk score
32 +- References and known false positives
33 +
34 +---
35 +
36 +## Why this is a power feature
37 +
38 +Threat hunting is most effective once your core stack is stable — alerts are flowing, agents are reporting, and your indexer contains meaningful data. CoPilot Searches builds on that foundation by giving operators a structured way to proactively look for threats rather than waiting for alerts to fire.
39 +
40 +It's especially valuable when:
41 +- you want to investigate a specific CVE across your fleet
42 +- you need to validate whether a MITRE technique is visible in your environment
43 +- you're responding to a new threat advisory and want to check historical data
44 +- you want to turn a hunt into a recurring Graylog alert
45 +
46 +---
47 +
48 +## Where it lives in the UI
49 +
50 +**Menu path:** Agents → CoPilot Searches
51 +
52 +The page shows the full rule catalog with:
53 +- A **search bar** for free-text search across rule names and descriptions
54 +- A **filter panel** with dropdowns for Platform, Severity, Status, and a Graylog-only toggle
55 +- **Rule cards** showing the name, description, severity badge, platform, MITRE mappings, and CVE tags
56 +
57 +Clicking a rule card opens the full detail view where you can review the query and execute it.
58 +
59 +---
60 +
61 +## Operator workflows
62 +
63 +### Hunt for a specific threat
64 +
65 +1. Navigate to **Agents → CoPilot Searches**
66 +2. Use the search bar or filters to find a relevant rule (e.g., search for "brute force" or filter by MITRE technique T1110)
67 +3. Click the rule to open its details
68 +4. Fill in the required parameters:
69 + - **Index pattern** (e.g., `wazuh-alerts-*`)
70 + - **Customer code** and/or **agent name** to scope the search
71 + - **Time range** (start/end)
72 +5. Click **Execute** to run the query against your Wazuh Indexer
73 +6. Review the results — each hit links back to the original indexed event
74 +
75 +### Find rules related to a CVE
76 +
77 +1. Open the filter panel and select **CVE** from the Platform dropdown
78 +2. The list narrows to rules that detect exploitation of specific CVEs
79 +3. Each CVE rule card shows the associated CVE IDs (e.g., CVE-2024-1234)
80 +4. Click a rule and execute it to check whether any matching activity exists in your environment
81 +
82 +### Filter by platform
83 +
84 +Use the Platform filter to narrow rules to:
85 +- **Linux** — rules targeting Linux-specific telemetry (auditd, syslog, etc.)
86 +- **Windows** — rules targeting Windows event logs, Sysmon, etc.
87 +- **PowerShell** — rules focused on PowerShell script block logging, command-line activity, etc.
88 +
89 +### Generate a Graylog query
90 +
91 +Some rules include a pre-built Graylog query template. These are marked with a Graylog indicator in the rule list.
92 +
93 +1. Filter for Graylog-compatible rules using the **Graylog Only** checkbox
94 +2. Open a rule and use the **Graylog query** section to generate a query with your parameters substituted
95 +3. Copy the query into Graylog search, or provision it as an alert directly from CoPilot
96 +
97 +### Provision a Graylog alert from a rule
98 +
99 +Turn any Graylog-compatible rule into a recurring alert:
100 +
101 +1. Open a rule that has a Graylog query
102 +2. Click **Provision Graylog Alert**
103 +3. Configure:
104 + - **Search window** — how far back each execution looks (default: 5 minutes)
105 + - **Execution interval** — how often the alert runs (default: 5 minutes)
106 + - **Priority** — Low, Normal, or High
107 + - **Streams** — optionally limit to specific Graylog streams
108 +4. Submit — CoPilot creates the Graylog event definition for you
109 +
110 +Once provisioned, the alert runs automatically in Graylog and routes matches into your normal incident pipeline.
111 +
112 +---
113 +
114 +## Rule details
115 +
116 +When you open a rule, you'll see:
117 +
118 +| Field | Description |
119 +|-------|-------------|
120 +| **Name** | Human-readable rule name |
121 +| **Status** | `production`, `experimental`, or `deprecated` |
122 +| **Severity** | `low`, `medium`, `high`, or `critical` |
123 +| **Risk score** | Numeric risk score (0–100) |
124 +| **Platform** | Linux, Windows, or PowerShell |
125 +| **MITRE ATT&CK** | Mapped technique IDs (e.g., T1136.001) |
126 +| **CVE** | Associated CVE IDs, if any |
127 +| **Description** | What the rule detects and why it matters |
128 +| **How to implement** | Any prerequisites or data source requirements |
129 +| **Known false positives** | When this rule might fire on benign activity |
130 +| **References** | Links to related advisories or documentation |
131 +
132 +---
133 +
134 +## Setup checklist
135 +
136 +CoPilot Searches works out of the box with no additional configuration:
137 +
138 +- [x] CoPilot is running (the rules are fetched automatically from GitHub)
139 +- [x] Your Wazuh Indexer is connected (required to execute searches)
140 +- [ ] Optionally, Graylog is connected (required for Graylog query generation and alert provisioning)
141 +
142 +The rule catalog refreshes automatically every 30 minutes. You can also manually refresh from the UI to pull the latest rules immediately.
143 +
144 +---
145 +
146 +## Safety / guardrails
147 +
148 +- Searches run **read-only queries** against your Wazuh Indexer — they do not modify any data.
149 +- Graylog alert provisioning creates event definitions in Graylog. Review the query and parameters before provisioning.
150 +- Rules are community-maintained. Treat results as indicators for investigation, not definitive verdicts — always validate before acting.
151 +- Scope searches to specific customers/agents when possible to reduce noise and execution time.
152 +
153 +---
154 +
155 +## Related resources
156 +
157 +- Rule repository: https://github.com/socfortress/CoPilot-Search-Queries
docs/power-features/index.mdx
+1
@@ -32,3 +32,4 @@ They typically have additional inputs (connectors, permissions, targets) and sho
32 - [AI analyst / AI-assisted investigation](/power-features/ai-analyst)
33 - [Atomic Red Team (detection simulation)](/power-features/atomic-red-team)
34 - [Report creation](/power-features/report-creation)
35 +- [CoPilot Searches (threat hunting)](/power-features/copilot-searches)