﻿---
title: Manage saved discoveries
description: Attack discoveries are automatically saved each time they're generated. Once saved, discoveries remain available for later review, reporting, and tracking...
url: https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/solutions/security/ai/attack-discovery/manage-saved-discoveries
products:
  - Elastic Cloud Serverless
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available since 9.1
---

# Manage saved discoveries
Attack discoveries are automatically saved each time they're generated. Once saved, discoveries remain available for later review, reporting, and tracking over time. This allows you to revisit discoveries to monitor trends, maintain audit trails, and support investigations as your environment evolves.
Which page you use to manage saved discoveries depends on what you're trying to do.

## Choose the right page for your goal

The **Attack Discovery** page is your primary place to generate, save, and triage discoveries.
If you'd rather split generation and triage into separate flows, you can instead:
- Go to **Attack Discovery** to run LLM analysis on demand and create new attack discoveries.
- Go to **Attacks** for day-to-day triage of all attacks (manual and scheduled), and to manage their investigation lifecycle.

<note applies-to="Elastic Cloud Serverless: Preview, Elastic Stack: Preview since 9.4">
  Splitting split generation and triage into separate flows requires turning on the [**Enable alerts and attacks alignment**](/elastic/docs-content/pull/7448/solutions/security/get-started/configure-advanced-settings#enable-alerts-and-attacks-alignment) setting to display the **Attacks** page.
</note>


## Next steps

- [Learn about Attack Discovery](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/solutions/security/ai/attack-discovery/attack-discovery)
- [Investigate threats with Timeline](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/solutions/security/investigate/timeline)
- [Manage security cases](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/solutions/security/investigate/security-cases)
- [Automate attack triage with Elastic Workflows](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/explore-analyze/workflows/use-cases/security/automate-security-operations/ai-driven-alert-triage)