Aegisify AI Select: Turn Selected Security Evidence Into a Focused WordPress Risk Conversation
Aegisify AI Select lets security teams choose a small, deliberate set of stored Aegisify evidence for one authorized WordPress domain, combine it with approved log and threat-intelligence context, redact sensitive outbound data, and create a saved AI security-priority thread that stays anchored to that evidence snapshot.
AI Select is designed to narrow the question: choose the scans and supporting evidence relevant to example.com, create a bounded analysis snapshot, then ask follow-up questions about priority, impact, affected areas, remediation order, or why a risk was elevated.
AI
How AI Select Moves From Stored Evidence to a Saved Security Thread
The workflow deliberately separates evidence collection from AI analysis. Scans and logs are created elsewhere in Aegisify; AI Select assembles selected stored evidence into a new analysis snapshot.
Click a stage to expand
01Scopeexample.com
02SelectUp to 3 scans
03EnrichLogs + threat intel
04NormalizeFindings + inventory
05RedactSensitive outbound data
06DiscussSaved evidence thread
A Security Intelligence Layer Built on Evidence Aegisify Already Collected
AI Select does not run a new vulnerability scan, SAST scan, DAST scan, Agent inventory collection, log collection, or threat-intelligence lookup when the analysis starts.
The feature works on stored Aegisify evidence. A user chooses the authorized domain and then chooses which eligible scan results should be included. Aegisify can enrich that selection with the newest stored WordPress Debug Log ingestion, the newest stored WordPress Activity Log ingestion, and the newest stored Dark Web & Domain BL result when those evidence sources are selected.
The resulting payload is intentionally compact rather than an unrestricted dump of every Aegisify record. For scan evidence, it emphasizes the scan profile, completion state, report summary, finding summary, source summary, and a bounded set of Critical and High findings or results. Plugin, theme, and component inventory attached to the selected scans can also be included so AI can interpret software context alongside security findings.
Choose a Small Cross-Section of Static, Dynamic, and Advanced Security Results
The current build supports a deliberately bounded selection: no more than three stored scans in one AI analysis, with only one scan from the same profile.
Vulnerability + Static Code Analysis
Eligible defensive evidence includes the recurring Vulnerability Scan and the deeper Static Code Analysis profile. This lets the AI conversation connect software risk, WordPress posture, and code-level evidence when those scans have already been completed.
Enterprise DAST: App & Commerce
The current AI Select implementation accepts Enterprise DAST: App & Commerce as its standard dynamic-offensive scan evidence. Quick DAST is not part of the current AI Select profile list.
Authenticated, API, Front-End, and Compliance Context
Stored advanced profiles can include Deep Auth DAST, API DAST, Front-End DAST, and API DAST and Compliance evidence where those profiles exist for the selected domain.
Bring Recent WordPress Activity and External Reputation Context Into the Same Analysis
The supporting evidence switches are enabled by default in the current interface, but the user can exclude them when that context is not appropriate for the analysis.
Recent Error and Failure Context
When included, AI Select uses the newest stored WordPress Debug Log ingestion for the selected domain. It carries summary information, Critical/High error counts, recent structured entries, and a bounded excerpt of recent raw log content rather than an unlimited historical log dump.
Recent Event and Sensor Context
When included, the newest stored Activity Log ingestion can provide event counts, sensor counts, recent sanitized events, and sensor context. This can help AI distinguish a scan finding from administrative activity, repeated change, or operational behavior when the evidence supports that conclusion.
Reputation, Accessibility, and Breach Evidence
The newest stored Threat Intelligence result can add domain reputation, blocked/accessibility, and dark-web or breach-oriented evidence. Unknown or missing provider evidence remains uncertainty rather than being transformed into a clean result.
Software Context From the Selected Scans
AI Select can include component inventory already associated with the selected scan jobs, including names, versions, latest-known versions, and update-availability context. It does not perform a fresh Agent inventory fetch simply because an AI analysis was requested.
AI Select Can Use Agent-Derived Evidence Without Directly Calling the Agent
This distinction keeps the architecture clear: evidence may originate from the Agent, but AI Select itself reads the stored SaaS-side results selected for the conversation.
For example, a Vulnerability Scan or Static Code Analysis result may already contain evidence collected through the Aegisify Audit Agent. Plugin and theme inventory may have been stored as part of those scans. WordPress Activity Log data may have originated from enabled Agent sensors and an authorized ingestion workflow. AI Select can use that stored evidence when it is present and selected.
However, starting an AI Select thread does not enable sensors, change Telemetry Access Control, connect an Agent, trigger a new Agent scan, or request a fresh WordPress log ingestion. Those controls remain in their respective Agent, scan, and logging workflows.
The AI Conversation Is Deliberately Bounded
The current 1.3.5-rev1 implementation uses explicit limits to keep saved security conversations focused and manageable.
At least one scan is required, with no more than one scan from each selected profile.
The newest saved chats are retained for each user’s AI Select history.
The saved thread keeps a bounded recent user/assistant conversation window.
Each follow-up prompt is length-limited before it is submitted for analysis.
The supporting evidence is bounded too. The current payload limits the number of recent debug-log entries, raw-log excerpt size, WordPress activity events, activity sensors, priority findings, and inventory rows that enter the compact analysis package. Those implementation limits are designed to keep AI analysis focused rather than sending unbounded customer data.
Outbound AI Analysis Passes Through Aegisify’s Security Redaction Layer
The current AI configuration uses a strict redaction profile by default and treats secrets and regulated personal data as mandatory redaction categories.
Additional redaction categories cover account identifiers, domains and network identifiers, user information, filesystem/database details, configuration bodies, code excerpts, and attack-surface details depending on the selected Aegisify AI redaction profile. The current AI service is configured around Google Gemini, but the customer evidence is processed through Aegisify’s outbound redaction pipeline before the AI request is constructed.
AI Select Is Tuned for Security Triage, Not General-Purpose Chat
The current analysis instructions require the AI to stay anchored to Aegisify’s supplied evidence, separate verified facts from inference, and avoid inventing findings or remediation outcomes.
Aegisify AI Summary
The analysis begins with the most important security reality supported by the selected evidence. It is instructed to say whether live external research was available when relevant rather than pretending a real-time validation occurred.
Top 10 Biggest Threats
The analysis ranks the highest-confidence threats using severity, exploitability, exposure, recurrence across selected scans, supporting log evidence, external validation where available, and likely business impact.
Five Evidence-Based Recommendations
The current prompt requires exactly five WordPress and application hardening recommendations tied to the supplied evidence, each with a practical reason instead of generic security filler.
Plugin and Component Threat Research
When plugin, theme, or component evidence matters to a top threat, the analysis is instructed to validate relevant public vulnerability or vendor information when live research is available and to state when no verified public threat was found.
Observed Hacking Activity or External Exposure
Selected logs, DAST evidence, domain reputation, breach context, and repeated findings can be correlated to distinguish stronger evidence of abuse from routine activity, stale signals, or likely noise.
Risks, Gaps, and What Needs Verification
Missing, stale, redacted, or insufficient evidence should remain a gap. The AI instructions explicitly prohibit turning unavailable data into a confident security conclusion.
The First Analysis Becomes a Domain-Specific Evidence Thread
Saved chats make it possible to continue the investigation without rebuilding the original evidence selection for every question.
Create the Initial Snapshot
When the selected evidence is sent for analysis, Aegisify creates a saved chat tied to the authorized domain and the scan selection. The thread stores a sanitized analysis context and the initial AI response.
Ask Follow-Up Questions Against the Same Snapshot
Follow-up prompts can ask about affected areas, remediation order, why a threat was prioritized, what evidence supports a conclusion, or what should be verified next. The conversation remains tied to the same saved thread context rather than silently moving to a different domain or scan.
Use a Fresh Thread When the Security State Changes
A saved thread is a snapshot, not a live mirror of the database. If new scans run, logs change, vulnerabilities are remediated, or threat intelligence is refreshed, send a new evidence selection to create an analysis based on the updated state.
Turn Supported Follow-Ups Into AI Alerts
The current build can hand supported alert-creation requests from a chat follow-up into the Aegisify AI Alerts workflow. This lets a conversation become a monitoring instruction when the request can be safely translated into the supported alert model.
Use It When the Security Question Crosses More Than One Evidence Source
AI Select is most useful when a scan result alone does not explain the operational priority.
What Should We Fix First?
Combine a recent Vulnerability Scan with SAST or Enterprise DAST and ask which Critical/High issues have the strongest supporting evidence and business impact.
Did Activity Explain the Finding?
Add WordPress Activity Log context to determine whether an observed change aligns with a known administrative action or deserves deeper investigation.
Are Errors Increasing Security Risk?
Add recent Debug Log evidence when application failures, repeated fatal errors, broken controls, or plugin behavior may affect the interpretation of scan findings.
Does Reputation Evidence Change Priority?
Add Dark Web & Domain BL evidence when reputation, breach, blacklist, or accessibility signals may increase urgency or create a verification requirement.
Common Questions About Scan-Aware Aegisify AI Analysis
Does AI Select run a new security scan?
No. It analyzes eligible stored scan evidence for the selected authorized domain. Run or refresh the underlying security scan in its own workflow before creating a new AI Select snapshot if you need newer evidence.
How many scans can I include in one AI analysis?
The current implementation requires at least one scan and allows up to three stored scans total. Only one scan from any individual scan profile can be selected for the same analysis package.
Can Quick DAST be selected in the current AI Select build?
No. The current allowed profile list includes Vulnerability Scan, Static Code Analysis, Enterprise DAST: App & Commerce, and supported advanced-security profiles. Quick DAST is not included in the present AI Select profile set.
Does AI Select fetch new evidence from the Audit Agent?
No. It can use stored evidence that originally came from Agent-assisted scans, inventory, sensors, or log-ingestion workflows, but AI Select itself does not call the Agent to create a fresh scan or enable telemetry.
Are Debug Log, WordPress Activity Log, and Dark Web evidence included automatically?
The current interface defaults those supporting-evidence selections to enabled, but the user can exclude them. If the corresponding stored evidence does not exist, the package remains empty or unknown for that area rather than inventing data.
Does a saved chat automatically update when new scans are completed?
No. Follow-up questions use the evidence snapshot stored with that chat. Create a new AI Select thread when you want the analysis to reflect newer scans, logs, inventory, or threat-intelligence results.
How much saved chat history is retained?
The current build keeps up to 25 saved AI Select chats and retains a bounded conversation history of up to 16 recent user/assistant messages per saved thread.
Can the AI perform live external threat validation?
The current AI instructions request live internet validation when the connected AI environment supports it and the evidence makes that research relevant. If live research is unavailable, the response is instructed to say that external threat validation could not be confirmed in real time.
What happens to sensitive information before an outbound AI request?
The AI package passes through Aegisify’s configured redaction pipeline. The current default profile is strict, and secrets plus regulated personal-data categories are mandatory redaction controls. Other technical evidence may be retained or redacted according to the active redaction profile.
