The Netskope DLP AISecOps Agent is built for one purpose: to give data security analysts their time back.
The agent transforms raw data into a streamlined incident-to-resolution pipeline through five key stages:
- Signal Ingestion: Collects millions of DLP signals across cloud, web, email, and endpoints to eliminate blind spots.
- Analysis & Clustering: Filters noise and groups related incidents into a single case centered around specific users, data, applications, or devices.
- Enrichment: Automatically enriches the cases with context around identity, application, device & data.
- Recommendation: Provides a clear verdict and risk score based on business context, suggesting the best next steps.
- Resolution: Analysts can execute actions such as revoking sharing or muting benign activity directly from the Netskope One Orchestrator.
For more details:
Overview
Pour commencer à utiliser le Netskop DLP AISecOps Agent, connectez-vous à la console d’administration Netskope et cliquez sur AISecOps.

L'interface utilisateur vous permettra d'accéder aux pages Total New Cases, Critical Risk Cases, Average Case Age, et Total Views. Les « Overview » peuvent être filtrées par période à l'aide du menu déroulant situé en haut à droite.
The Incident-to-Resolution Pipeline provides the complete case lifecycle from detection to close. Your Alerts will flow into Incidents which are then grouped into cases and can be further filtered based on severity.
Cases

Cases are a construct of one or more incidents that have been grouped based on customizable rules.
Vous pouvez filtrer ces cas dans la barre supérieure en fonction de l'Name, Status, Risk Level, Assigned Analyst, Recency,, et Timeframe.

Clicking on a case will take you to the case details where you can view all the incidents which comprise the case. From here, you can:
- Re-investigate – Re-investigate an already investigated case.
- Assign – Assign a case to an analyst
- Download –
- Close case – Close the case out.
- Investigate – Launch an investigation to dig into the incidents. The Agent will gather all the evidence across the Netskope platform and provide a risk assessment and recommendation for remediation.
You can also perform bulk actions like Assign Cases or Close Cases when you select multiple cases.

En haut, vous verrez Similar Cases, Analysis, Incidentset Investigation Trail.
The Incidents tab will let you click on an Incident and get additional details on the Incident. You can also click View in Incident Management to get even more detail.

The Similar Cases tab will list cases which are similar in nature.

L'onglet « Investigation Trail » (Enquête) vous fournira des informations sur l'enquête et permettra également de renommer le dossier en fonction des conclusions.

Toutes ces informations seront remplies dans l’onglet Overview après le lancement d’une enquête, accompagnées d’une Executive Summary et d’une série de Recommended Actions.
Vous pouvez également voir Suggested Remediations.

For information on creating cases, see Case Creation.
Views

L’onglet Vues contient deux sections, Data Loss et Insider Threat.
Data Loss
The Data Loss sub-tab allows you to filter incidents by Sanctioned Instances, Critical Severity, PCI Data, and PII Data. These views provide additional granularity and allow analysts to monitor for any fluctuations in behavior across the organization.

Clicking on an insight will provide the analysts with more detail on any spikes in Incidents generated by specific user actions.

Menace d'initié

The Insider Threat page allows you create user watchlists for specific users or groups in order to monitor for malicious activity or active malware infections.
Clicking on a user will allow you to get analytics on their behavior and see cases associated with their activity

Pour plus d'informations, consultez la rubrique « Vues ».

