release-1-81726.png

August 17, 2026

ThreatDown AI

Feature

ThreatDown AI is available on Elite accounts. Ask questions about your environment using natural language and quickly uncover insights across endpoints, detections, vulnerabilities, audit logs, and security posture. Receive recommended actions, explore relevant data, and execute selected actions directly from the AI conversation to resolve issues faster.

Features and Improvements

  • Apply software updates to the endpoints you choose. You can target a software update by application and by endpoint in the same request while leaving others untouched.

  • Keep typing while suggested actions are on screen. The prompt box stays available when ThreatDown AI presents suggested actions, so you can pick an action or simply ask a follow-up question without dismissing the suggestions.

  • Answers reflect whether an update is actually available. Questions about vulnerable or outdated software distinguish between applications that have an update ready and those that do not.

  • Clearer answers about endpoints awaiting a restart. ThreatDown AI reports why a restart is pending on an endpoint.

  • ThreatDown AI availability setting visibility to Admin and Read-only users. The Account > Configurations > ThreatDown AI setting is visible to Admin and Read-only users, so any user can confirm whether the feature is enabled for the account. Only Super Admins can change the setting.

  • Clearer messaging for exports that run in the background. When you request an export from ThreatDown AI, the confirmation explains that the export has been initiated and that you will receive an email when the file is ready to download.

  • Endpoint name included in software asset exports. Exports of software inventory results generated from ThreatDown AI include the endpoint name, making it easier to identify which device each software entry belongs to.

  • Improved handling of questions that reference multiple endpoints. Questions that name several endpoints at once return results for each endpoint.

  • Accurate results when asking about detected files. Questions that reference a specific file or file location now match on the detection path, returning more relevant results.

  • Guidance to documentation for AI Detection and Response questions. Questions about AI usage and AI Detection and Response in your organization point to the relevant knowledge base articles.

Issues Fixed

  • NDEV-23579: Fixed an issue where asking ThreatDown AI to identify groups without a schedule returned all Nebula groups.

  • NDEV-23580: Fixed an issue where questions about the Security Advisor Endpoint Status score were interpreted as questions about endpoint state instead of the security posture score.

  • NDEV-23581: Fixed an issue where ThreatDown AI treated available operating system patches and agent updates as interchangeable.

  • NDEV-23632: Fixed an issue where questions about .NET updates returned an inaccurate response.

  • NDEV-23720: Fixed an issue where questions about endpoints requiring a restart were misinterpreted when asked immediately after a question about endpoints requiring an update.

  • NDEV-23573: Fixed an issue in ThreatDown AI where the background color did not change when hovering over an item.