﻿---
title: Run Attack Discovery
description: The different ways to trigger Attack Discovery analysis, from a manual run to a fully automated, always-on pipeline.
url: https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/solutions/security/ai/attack-discovery/run-attack-discovery
products:
  - Elastic Cloud Serverless
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Run Attack Discovery
You can run Attack Discovery on demand or on a recurring schedule. Use the following table to find the right entry point for your needs.

| Best for                                                                                                                                                                                                                                                                                                                    | Available in                                                                                                                       | Go to                                                                                                                                                             |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Creating or managing schedules without leaving the unified attack-triage view. Only supports scheduled runs, and requires turning on the [**Enable alerts and attacks alignment**](/elastic/docs-content/pull/7448/solutions/security/get-started/configure-advanced-settings#enable-alerts-and-attacks-alignment) setting. | <applies-to>Elastic Stack: Preview since 9.4</applies-to> <applies-to>Elastic Cloud Serverless: Preview</applies-to>               | [Attacks page](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/solutions/security/ai/attack-discovery/run-from-attacks-page)                   |
| Triggering an on-demand run, or setting up a schedule. The only entry point that supports on-demand runs.                                                                                                                                                                                                                   | <applies-to>Elastic Stack: Generally available</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to> | [Attack Discovery page](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7448/solutions/security/ai/attack-discovery/run-from-attack-discovery-page) |

<note>
  Schedules created on either page appear on both, so you can switch between them without losing track of what's running.
</note>