﻿---
title: Run Attack Discovery
description: Choose how to run Attack Discovery: from the Attacks view, a workflow, Agent Builder chat, or the Attack Discovery page.
url: https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7588/solutions/security/ai/attack-discovery/run-attack-discovery
products:
  - Elastic Cloud Serverless
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Run Attack Discovery
Pick the path that fits how you work and the Elastic Stack version you have. Every option uses the same analysis steps.

| When to use this                                                                        | Available in                                                                                                                  | Go to                                                                                                                                                                               |
|-----------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Choose which alerts to analyze, then run Attack Discovery immediately or on a schedule. | <applies-to>Elastic Stack: Preview in 9.4</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to> | [Run from the Attacks view](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7588/solutions/security/ai/attack-discovery/run-from-attacks-page)                        |
| Include Attack Discovery as one step in a larger workflow.                              | <applies-to>Elastic Stack: Planned</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to>        | [Run from a workflow](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7588/solutions/security/ai/attack-discovery/run-attack-discovery-in-a-workflow)                 |
| Ask Elastic Agent Builder to investigate in chat.                                       | <applies-to>Elastic Stack: Planned</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to>        | [Run from Elastic Agent Builder](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7588/solutions/security/ai/attack-discovery/run-attack-discovery-from-agent-builder) |
| Work from the standalone Attack Discovery experience                                    | <applies-to>Elastic Stack: Generally available from 9.0 to 9.4</applies-to>                                                   | [Run from the Attack Discovery page](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/7588/solutions/security/ai/attack-discovery/run-from-attack-discovery-page)      |