Flint
12 min
this is an alpha release and is available to a small group of organizations capabilities, limits, and the interface will change during the alpha program if you are part of the alpha program and something does not work as expected, please reach out to your csm flint is flare's ai assistant, built directly into the platform it works inside your tenant, using the same data, identifiers, and permissions you already have in flare ask a question in plain language and flint searches flare's collection, reads your events, follows leads across actors, credentials, and infrastructure, then explains what it found and where it found it flint supports the work analysts already do in flare triaging events, confirming whether an exposure is real, and identifying who is behind an activity, among other tasks during the alpha program, flint can read your data and recommend what to look at next, but it cannot change anything in your tenant key features plain language search ask for what you want instead of building a query flint translates your question into a flare search, runs it, and returns the results matching events appear inline you can refine your question in the next message, or run the same search yourself in global search event explanation point flint at an event and ask what it means flint reads the event, the identifier that matched it, and the source it came from, then explains what was found, why it matched your organization, and what to look at next the explanation stays on the record flint tells you what is in the event and separates that from what it infers investigation ask flint to look into a finding flint pivots from the starting point to related data the actor behind a post, other credentials from the same source, or infrastructure that appears alongside a domain each pivot is one step, and flint reports what it checked and what came back, including when a pivot returns nothing scoped to your tenant flint sees what you see your identifiers, your events, your module entitlements, and your role permissions apply to every flint conversation exactly as they apply everywhere else in flare flint cannot show you data your account cannot access, and it cannot reach into another tenant read only during the alpha flint can read your identifiers and severity rules, tell you what you are monitoring, and suggest coverage you may be missing it does not change anything it does not create, edit, or delete identifiers or severity rules, and it does not take actions on events when you ask it to make a change, it tells you where to make the change yourself what flint can see flint works with the following parts of your tenant events the event itself, its type, and the identifier that matched it identifiers the list of what your organization monitors and the details of each identifier severity rules the rules that set severity on your events actor profiles the profiles available in the intelligence browser tenant search searches across the data already collected for your organization global search searches across flare's full collection, run with your approval flint does not run module specific workflows it does not have identity exposure management or cyber threat intelligence (cti) module tooling beyond the identifiers, events, and actor profiles listed above module entitlements still apply flint cannot show you data from a module your organization does not have using flint follow these steps to use flint open flint from the left navigation menu, click flint alpha a new conversation starts empty, and your previous conversations are listed so you can return to them ask a question type what you want to know be specific flint works best when you name the thing you are looking at see the example questions below review the answer flint responds with what it found, where it found it, and what it did to get there events appear inline in the conversation, so you can review them without leaving flint when flint is not sure, it says so follow up ask your next question in the same conversation flint keeps the context of what you have already discussed, so you can narrow the scope, ask for a different angle, or ask flint to pivot on something it surfaced continue investigation in flare events that flint surfaces open in flare directly from the conversation for anything else, such as an actor profile or a search you want to extend, take the name or query flint gave you into the intelligence browser or global search and continue there example questions these are the kinds of questions flint handles today topic questions exposures is any of our data being sold on forums right now? any leaks for acmecorp com? any stealer logs mentioning acmecorp com? what are people saying about us on telegram? any leaks about acme supplies? they're a supplier of ours but we don't monitor them events feed show me events in our feed from the last 7 days show me only the low severity events in our feed explain this event (followed by the event link or id) actors threats topics what do you know about the threat actor intelbroker? find forum posts written by intelbroker find mentions of cve 2026 70724 any recent ransomware activity i should know about? search the entire flare dataset for mentions of lockbit i want to search chat messages and blog posts that talk about ai abuse coverage what identifiers are we monitoring right now? looking at what we monitor today, what related assets might we be missing? what flint does not do yet the alpha covers search, event explanation, and investigation the following are not available yet configuration changes flint does not create, edit, or delete identifiers or severity rules it can tell you what you monitor and what to consider adding, but making the change is up to you background tasks flint does not run on a schedule, react to new events on its own, or keep working after you close the conversation report generation as a dedicated capability you can ask flint to write up what it found, and it will, but there is no report skill behind it yet, so the output is a conversation answer, not a formatted, saved report threat flow remains the reporting engine actions flint does not change event status, trigger takedowns, or push data to integrations several of these are in progress see what we are working on for the current list flint and the rest of flare global search flint searches your tenant's data directly when a question needs a global search across flare's full collection, flint asks before running it an approved search runs as a global search, the same as one you run yourself you can copy any query flint used into global search and keep working there events flint reads the same events you see in the events feed and the event details panel to ask about an event, paste its link or id into the conversation there is no flint button on events during the alpha usage and limits flint is free during the alpha global searches that flint runs with your approval count the same as global searches you run yourself giving feedback feedback during the alpha will help us improve the feature before the final release we are specifically looking for feedback on the following something flint got wrong, with a link to the conversation something you asked flint to do that it could not something you expected to find and did not please share any feedback with your customer success manager