Security efficiency · Investigations and forensics
Automate repetitive investigation work
Analysts repeatedly gather the same identity, device, threat, asset, and timeline evidence before they can make an initial decision.
The record
Telemetry these decisions draw on
- Alerts and incidents
- Identity context
- Asset context
- Endpoint and network events
- Threat intelligence
- Prior incidents
- Investigation actions
- Case notes
The questions
What an agent answers
- What evidence should be collected for this alert?
- What is the likely incident timeline?
- Which identities and assets are involved?
- Does the behavior match a prior incident?
- What should the analyst investigate next?
"The alert is linked to one user, two endpoints, and a newly created cloud token. Similar activity in a prior incident resulted from token theft. Escalate and revoke the token while the endpoint is inspected."
Related use cases
Browse the full library →Security efficiency
Reconstruct a complete cyber incident
Investigators must manually collect and correlate evidence across many systems to determine how an attacker entered, moved, persisted, and accessed data.
Investigations and forensics · Chief Information Security Officer
Read the use case →Security efficiency
Recommend the safest security response
Containment decisions can protect the enterprise but also create unnecessary business disruption when the scope of compromise is not understood.
AI-driven decisions · Chief Information Security Officer
Read the use case →Security efficiency
Reduce security false positives
Analysts spend significant time reviewing alerts that lack the user, asset, change, threat, and business context required to determine whether they are dangerous.
AI-driven decisions · Chief Information Security Officer
Read the use case →