Incident Investigation
Every alert enriched, reasoned, and verdicted — before it ever reaches a human.
One incident, four steps.
The Triage Agent works every alert the way a senior analyst would — just all of them, at once.
Your tools alert. So do we.
AIDR reads the raw events your tools ship — and runs its own detection on top of theirs. More of what matters gets caught, then everything related is grouped into one incident.
AIDR investigates everything the alert touches.
Assets, users, processes, IPs — each checked against AIDR’s own threat intelligence, and every answer kept as a finding. It’s the context an analyst would spend twenty minutes collecting, gathered in seconds.
Assets
Users
Processes
IPs · domains
AIDR TI
What it is, and how much it matters.
What the activity did and which entity it touched decide the verdict. How much it could hurt and whether it’s contained set the severity. Both arrive with the evidence that produced them — and if the evidence is thin, Dynamic Query goes and gets more.
The verdict decides what happens next.
Benign closes automatically. Everything else spawns tasks — investigate deeper or mitigate, human-approved — and malicious incidents escalate to the Correlation Engine.
Malicious
Becomes an attack case
Escalated immediately and handed to the Correlation Engine — the attack chain mapped end to end.
Suspicious
Kept under investigation
Evidence isn’t sufficient yet — the AI runs on-demand searches across your events and logs to close the gap, then re-verdicts.
Benign
Closed automatically
No analyst time spent — the incident is auto-closed with the reasoning documented, ready for review any time.
Inside the investigation.
How that shows up in the console — verdicts you can challenge, findings you can audit, and noise that cleans itself up.
The case is made. You decide.
The agent does the reasoning and reaches the verdict, with the evidence and its confidence laid out. All that’s left for you is the call itself — one click, recorded as yours.
The intel is ours. It’s included.
Every entity the agent touches gets looked up against AIDR’s own threat intelligence — no extra subscription, no configuration. Each answer lands in the incident as a cited finding.
What’s left is what matters.
Benign closes itself, reasoning documented — so the only incidents still on your queue are the ones worth your judgment. And every closure feeds the flywheel: the next verdict is sharper than the last.
How AIDR is different.
Plenty of tools promise AI investigation. These four are the parts that don’t come standard.
Every alert. Not a sample.
Most tools rank what looks risky and quietly drop the rest. AIDR investigates the full queue, every time — because the quiet alerts are where real attacks hide.
It never guesses.
When the evidence is thin, the verdict holds at Suspicious and the agent goes to get more — Dynamic Query searches your events and logs on demand. A call is made only when it can be defended.
Every verdict shows its work.
Findings, intel matches, MITRE mappings — the evidence rides with the verdict, cited. Your analysts and your auditors read the same trail.
It learns your environment.
Every closure — the AI’s or yours — trains the verdict model on what normal looks like for you. This week’s noise doesn’t come back next week.
Catch what your existing tools miss.
Every alert investigated — none sampled
Verdicts with the evidence attached
Analysts only make the calls that matter
We use analytics cookies to understand how the site is used. Essential cookies keep it working. Read our Cookie Policy.