AI-Assisted Cyber Threat Detection Query Generation
Safety & Security
What it collects
- Internal audit logs collected via Security Information and Event Management (SIEM), capturing system and network activity events used as the target corpus for executed threat hunting queries. No personal information is involved.
- Public data available on the internet used at query-generation time to inform the AI's understanding of known threat patterns, attack signatures, and Kusto Query Language syntax conventions.
- Run by
- Innovation, Science and Economic Development Canada (ISED)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Not stated by the Helpful Places.
What it is for
This system uses generative AI tools — including Anthropic Claude and Microsoft Copilot — to help cybersecurity analysts at Innovation, Science and Economic Development Canada write advanced queries for detecting threats in security logs. Analysts provide prompts; the AI generates Kusto Query Language queries that are then run against internal audit and security event data. The system processes no personal information, and its use of AI is disclosed to Government of Canada employees who interact with it.
What it collects and what happens to it
Data taken in
- Internal audit logs collected via Security Information and Event Management (SIEM), capturing system and network activity events used as the target corpus for executed threat hunting queries. No personal information is involved.
- Public data available on the internet used at query-generation time to inform the AI's understanding of known threat patterns, attack signatures, and Kusto Query Language syntax conventions.
Processing
- Generative AI foundation models — Anthropic Claude and Microsoft Copilot — process analyst prompts and public web data to produce Kusto Query Language queries for cyber threat detection.
What it does
- The AI generates Kusto Query Language queries from analyst-supplied prompts; human security analysts review and decide whether to execute each generated query against the security logs.
- The system interprets natural-language threat hunting prompts provided by analysts, drawing on public web data to understand cybersecurity concepts and translate them into structured query syntax.
Outputs
- Kusto Query Language queries generated by the AI in response to analyst prompts, intended for execution against SIEM security logs to identify potential cyber threats. Outputs are code strings, not personal data.
Run by
- The federal department that deploys and operates this AI-assisted threat hunting system to accelerate cybersecurity query development within its environment.
Government of Canada AI Register — Cyber Threat Hunting (2526-ISED-ISDE-020)
Built by
- Anthropic (Claude) and Microsoft (Copilot) supply the generative AI foundation models used to produce Kusto Query Language queries from analyst prompts.
Government of Canada AI Register — Cyber Threat Hunting (2526-ISED-ISDE-020)
Kept for
Not stated by the Helpful Places.
Shared with
Not stated by the Helpful Places.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada AI Register — Cyber Threat Hunting (2526-ISED-ISDE-020)Innovation, Science and Economic Development Canada, Government of Canada AI and Algorithmic Systems Register, entry 2526-ISED-ISDE-020.
- AI registerGovernment of Canada AI Register — Cyber Threat Hunting (2526-ISED-ISDE-020)
- AI registerGovernment of Canada AI Register — Cyber Threat Hunting (2526-ISED-ISDE-020)
- Register entryPublished by the Helpful Places. Reference 154b8dab. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseGovernment of Canada employees who interact with this system are informed that AI is being used. AI use is disclosed to users as confirmed in the official register entry.
- Right to Algorithmic TransparencyThe system is listed in the Government of Canada's public AI register, which discloses its purpose, capabilities, data sources, and the generative AI tools employed (Anthropic Claude and Microsoft Copilot).
Risks and safeguards
- Societal & cultural harmOver-reliance on AI-generated queries could introduce unverified or flawed detection logic into security operations, potentially causing missed detections or false positives at scale.Safeguard: Queries are generated as advisory outputs for human analyst review — analysts decide whether to execute each query, maintaining human oversight of security operations.