Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Assisted Cyber Threat Detection Query Generation

Safety & Security

What it collects

About behaviour
Anonymized data
  • Internal audit logs collected via Security Information and Event Management (SIEM), capturing system and network activity events used as the target corpus for executed threat hunting queries. No personal information is involved.
Operational data
Anonymized data
  • Public data available on the internet used at query-generation time to inform the AI's understanding of known threat patterns, attack signatures, and Kusto Query Language syntax conventions.
Run by
Innovation, Science and Economic Development Canada (ISED)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Not stated by the Helpful Places.

What it is for

This system uses generative AI tools — including Anthropic Claude and Microsoft Copilot — to help cybersecurity analysts at Innovation, Science and Economic Development Canada write advanced queries for detecting threats in security logs. Analysts provide prompts; the AI generates Kusto Query Language queries that are then run against internal audit and security event data. The system processes no personal information, and its use of AI is disclosed to Government of Canada employees who interact with it.

What it collects and what happens to it

Data taken in

About behaviour
Anonymized data
  • Internal audit logs collected via Security Information and Event Management (SIEM), capturing system and network activity events used as the target corpus for executed threat hunting queries. No personal information is involved.
Operational data
Anonymized data
  • Public data available on the internet used at query-generation time to inform the AI's understanding of known threat patterns, attack signatures, and Kusto Query Language syntax conventions.

Processing

Language Models
  • Generative AI foundation models — Anthropic Claude and Microsoft Copilot — process analyst prompts and public web data to produce Kusto Query Language queries for cyber threat detection.

What it does

Creating (Generative AI)
Human decides
  • The AI generates Kusto Query Language queries from analyst-supplied prompts; human security analysts review and decide whether to execute each generated query against the security logs.
Understanding (Semantic AI)
Human decides
  • The system interprets natural-language threat hunting prompts provided by analysts, drawing on public web data to understand cybersecurity concepts and translate them into structured query syntax.

Outputs

Generated content
Anonymized data
  • Kusto Query Language queries generated by the AI in response to analyst prompts, intended for execution against SIEM security logs to identify potential cyber threats. Outputs are code strings, not personal data.

Run by

Innovation, Science and Economic Development Canada (ISED)
  • The federal department that deploys and operates this AI-assisted threat hunting system to accelerate cybersecurity query development within its environment.

Government of Canada AI Register — Cyber Threat Hunting (2526-ISED-ISDE-020)

Built by

Anthropic and Microsoft
  • Anthropic (Claude) and Microsoft (Copilot) supply the generative AI foundation models used to produce Kusto Query Language queries from analyst prompts.

Government of Canada AI Register — Cyber Threat Hunting (2526-ISED-ISDE-020)

Kept for

Not stated by the Helpful Places.

Shared with

Not stated by the Helpful Places.

Stored

Not stated by the Helpful Places.

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UseGovernment of Canada employees who interact with this system are informed that AI is being used. AI use is disclosed to users as confirmed in the official register entry.
  • Right to Algorithmic TransparencyThe system is listed in the Government of Canada's public AI register, which discloses its purpose, capabilities, data sources, and the generative AI tools employed (Anthropic Claude and Microsoft Copilot).

Risks and safeguards

  • Societal & cultural harmOver-reliance on AI-generated queries could introduce unverified or flawed detection logic into security operations, potentially causing missed detections or false positives at scale.Safeguard: Queries are generated as advisory outputs for human analyst review — analysts decide whether to execute each query, maintaining human oversight of security operations.