zerofox logo
Blog

Meet Scout AI Assistant: Ask Your Threat Data a Question, Get an Answer

by ZeroFox Team
Meet Scout AI Assistant: Ask Your Threat Data a Question, Get an Answer
8 minute read

Say hello to Scout AI.

Your data knows which alert types spiked this week. It knows your takedown acceptance rate this quarter, and exactly why escalations jumped between two dates last month. It knows all of this, right now. It just won't tell you without effort: write the query, pull the export, or file a request and wait your turn behind everyone else who needed a number this week. Sound familiar?

Scout is the new conversational analytics assistant inside ZeroFox, and it’s a game changer for your data. It lets you ask your threat data a question in plain English and get the answer straight back, as a chart, a table, or a single number. You type it the way you'd say it to a coworker, and Scout does the rest. No query language, no export, no waiting on someone else to pull it.

The data was always yours. Now it works the way you do. Anyone on AI Analytics Core or Premium, you already have Scout. It's live now.

Read on for why we built it, what it looks like in practice, and why your SOC and intel teams are going to stop dreading the reporting ask.

Why We Built It

Security teams have never had a data problem. They've had an access problem. The intelligence you need is already in the platform: every alert, escalation, takedown, and trend. Getting it out has been the slow part.

Consider how data pulls go today. You want last quarter's takedown numbers, so you export the data, drop it in a spreadsheet, build a pivot, format a chart, and double-check your math. All that time, gone, for a number you'll need again in three months. And that's a good day. On a bad day, you don't write SQL, so you file a ticket and wait for the one person who does to get to it.

Now multiply that by every question a security team asks in a week. That's the tax: hours spent assembling answers instead of acting on them, reporting shaped by what's easy to pull instead of what you really want to know, and questions bottlenecked behind the one analyst who knows how to get them answered.

So we got rid of the bottleneck. Scout puts the question and the answer in the same place, in plain language.

What Scout AI Assistant Is

Scout is ZeroFox's conversational analytics assistant, built right into the Data Analytics section of the platform. Ask a question about your threat intelligence data in plain English, and Scout reads your intent, runs the query, and hands back a visual answer. No query language or field names to memorize. No schema to learn. Anyone on AI Analytics Core or Premium has Scout and it's live now.

It works like asking a specialist who knows your data cold and never gets tired of the question. Type "Show me alerts by type this month," and Scout figures out the request, picks the right chart, and shows you. First answer not quite it? Say so in the next message. No starting over.

What It Looks Like in Practice

The fastest way to understand Scout is to watch real questions land.

Open Scout from the main Data Analytics page and start typing the way you'd say it to a colleague.

Ask a status question: "Show me all escalated alerts from the last 30 days." Scout returns the full set, grouped, charted, and ready to read with a plain-language summary on request. A complete picture of where analyst attention is going today, no export, no pivot table.

Ask a performance question: "How many takedown requests were accepted in the last 90 days?" The number lands as a single metric tile. That's your protection value story: acceptance rate, one question, done. It went from an afternoon of assembly to a single line.

Now open the Alert Insights dashboard. The alert volume trend chart shows a spike in the third week of March. You can see it, but you just can't explain it yet. That's when you use in-dashboard Scout: "Why did alert volume spike between March 10 and March 17?" Scout has the dashboard's full context. It names the rule group that drove it, identifies the network it hit hardest, and surfaces the assets that accounted for most of the volume. Two-analyst debug session, compressed to two minutes.

That's the two modes working together: Scout from the main Data Analytics page for questions you already know how to ask, dashboard Scout for the follow-up your data just handed you.

Following the Thread

One-shot answers are handy. Scout's real range shows up when you keep pulling.

Start wide: "Show me alert volume by rule group for the last 90 days." Full breakdown, every category. Narrow it, no need to repeat yourself: "Now filter that to phishing alerts only." Done, same result set. Reshape it: "Break that down by month and show it as a line chart." Reconfigured on the spot. Then make it think: "Which month had the highest volume? Summarize what you see." Scout names the peak and tells you what stands out.

Four questions and about two minutes. A fully scoped, chart-ready phishing trend analysis that used to mean building a workbook by hand. Scout holds the thread of your conversation within a session, so every follow-up stacks on the last one. 

Two Ways to Use Scout

Scout shows up in two places, and knowing which one to use saves you a frustrating dead end.

The purple button Scout, accessible from the main Data Analytics page, is scoped to Alert Base data like general alert trends and disruption activity. It's the right tool when your question is about alert volume, escalations, takedown counts, or how those numbers are moving over time.

The in-dashboard Scout lives inside a specific report and works against that dashboard's full data model, which means it can answer questions the purple button can't. Two examples worth knowing:

  • Configuration and operational questions: Open one of the Admin dashboards (Policy & Rule Configuration Overview, Asset Inventory, Alert Action Logs & Assignments) and use Scout from there. Ask about rule coverage gaps, asset configuration, or team assignment patterns. That context doesn't exist in the alert base.
  • Deep-dive alert metadata: For domains, botnets, credentials, and payment cards go to the Data Exports dashboard and use Scout there. That dashboard surfaces the full enrichment layer: registration details, botnet infrastructure, CAC context, and disruption timelines. It's the place to go when you need to understand what an alert is, not just that it happened.

Same engine with same plain-language prompts, but the dashboard you're standing in defines what Scout knows. When results feel thin, you're probably asking the wrong front door.

Why It Matters for SOC and Intel Teams

It comes down to time, and where that time goes. The fifteen-minute spreadsheet pull becomes one line. The ticket you'd have filed never gets filed. And the analyst who doesn't write SQL can now dig through exactly the same data as the one who does, so your questions stop piling up behind a single person.

Picture the weekly report. Nobody loses Thursday morning to assembling charts. Anyone on the team asks Scout for volume, escalations, and takedown numbers, has them in minutes, and spends the hour they just got back on the spike that needs a human staring at it. The report stops being a chore you look backward to finish and starts being a live read on where the threats are.

It's just as useful one level up. The Executive Risk & Value Briefing is the monthly snapshot leadership opens: alert volume, severity trends, top targeted assets, takedown pipeline status, and remediation rates, built to benchmark month-over-month risk posture and show the program is working. The numbers that prove value are now a question away. Ask Scout for takedown acceptance or volume trends and the briefing stops being a once-a-month assembly job.

Built to Be Trusted

Fast is good, but trustworthy is non-negotiable. So a few things are true about Scout by design.

Scout is read-only. It surfaces and summarizes your data, but it can't initiate takedowns, change alert statuses, or take any action in the platform. It answers questions; it doesn't pull triggers.

Scout only surfaces data you're cleared to see. Your organization's data stays scoped to your account, and access controls run on every query, no matter how you phrase it.

And your data isn't training the AI. The engine behind ZeroFox Data Analytics does not train on your data. Full stop.

That's the point of building this inside the platform instead of bolting a chatbot onto the side. Scout works against your real intelligence, under your real permissions, with none of the guesswork about where your data goes.

Go Ask It Something

The intelligence was always there. Scout makes it answer in the language you already use. Ask it what spiked, what got taken down, what's trending, and get something back you can act on, not a ticket in someone else's queue and not a spreadsheet you'll rebuild next week.

Anyone on AI Analytics Core or Premium has Scout, and it's live now. Open the Data Analytics section, type a question, and watch your data answer.

Want to see it against live data before you commit? Request a demo and bring your hardest reporting question. 

Meet Scout AI Assistant: Ask Your Data a Question, Get an Answer