Black Hat USA 2026Startup City, Booth 5815 · Aug 4–6 · Mandalay Bay, Las VegasBook a booth demo

Incident Investigation

Every alert enriched, reasoned, and verdicted — before it ever reaches a human.

One incident, four steps.

The Triage Agent works every alert the way a senior analyst would — just all of them, at once.

Step 1 · Detect

Your tools alert. So do we.

AIDR reads the raw events your tools ship — and runs its own detection on top of theirs. More of what matters gets caught, then everything related is grouped into one incident.

Events from four sources become 12,384 alerts, correlated down to 62 incidents — a 200:1 noise cut.

Step 2 · Enrich

AIDR investigates everything the alert touches.

Assets, users, processes, IPs — each checked against AIDR’s own threat intelligence, and every answer kept as a finding. It’s the context an analyst would spend twenty minutes collecting, gathered in seconds.

Assets

Users

Processes

IPs · domains

AIDR TI

Step 3 · Reason

What it is, and how much it matters.

What the activity did and which entity it touched decide the verdict. How much it could hurt and whether it’s contained set the severity. Both arrive with the evidence that produced them — and if the evidence is thin, Dynamic Query goes and gets more.

AssessmentINC-48
VerdictSuspicious
Silent install pattern plus a role mismatch — a paralegal installing a remote-access tool. The outbound connection meets every precondition for unattended remote access.
SeverityS3
Moderate-impact active threat, or contained high-impact threat. Investigate and contain within the shift.
Impact levelModerate
Evidence
LEGAL-WS-05 ran the signed TeamViewer installerTeamViewer_Setup.exe /silent — a tool that isn’t in the approved catalogue for Legal endpoints.
TacticSupporting indicators
Command and ControlInstall outside the corporate software catalogue, with an outbound connection to *.teamviewer.com.
Modifiers
Asset criticalityNo asset in scope is registered as critical.
ScopeNo scope threshold set in policy. Observed scope: 1 host.
Step 4 · Verdict

The verdict decides what happens next.

Benign closes automatically. Everything else spawns tasks — investigate deeper or mitigate, human-approved — and malicious incidents escalate to the Correlation Engine.

Every incident lands an AI verdict — malicious escalates, suspicious gathers more evidence, benign auto-closes.

Every incident lands an AI verdict — malicious escalates, suspicious gathers more evidence, benign auto-closes.

Malicious

Becomes an attack case

Escalated immediately and handed to the Correlation Engine — the attack chain mapped end to end.

Suspicious

Kept under investigation

Evidence isn’t sufficient yet — the AI runs on-demand searches across your events and logs to close the gap, then re-verdicts.

Benign

Closed automatically

No analyst time spent — the incident is auto-closed with the reasoning documented, ready for review any time.

Inside the investigation.

How that shows up in the console — verdicts you can challenge, findings you can audit, and noise that cleans itself up.

Assessment

The case is made. You decide.

The agent does the reasoning and reaches the verdict, with the evidence and its confidence laid out. All that’s left for you is the call itself — one click, recorded as yours.

Findings

The intel is ours. It’s included.

Every entity the agent touches gets looked up against AIDR’s own threat intelligence — no extra subscription, no configuration. Each answer lands in the incident as a cited finding.

Auto-close

What’s left is what matters.

Benign closes itself, reasoning documented — so the only incidents still on your queue are the ones worth your judgment. And every closure feeds the flywheel: the next verdict is sharper than the last.

How AIDR is different.

Plenty of tools promise AI investigation. These four are the parts that don’t come standard.

Typical tools — a sampleAIDR — all of it

Typical tools investigate a sample of alerts — AIDR investigates all of them

Typical tools investigate a sample of alerts — AIDR investigates all of them

Every alert. Not a sample.

Most tools rank what looks risky and quietly drop the rest. AIDR investigates the full queue, every time — because the quiet alerts are where real attacks hide.

SuspiciousHeld — not enough evidenceDynamic QueryPulls the missing events

A thin-evidence verdict stays Suspicious while Dynamic Query gathers more

A thin-evidence verdict stays Suspicious while Dynamic Query gathers more

It never guesses.

When the evidence is thin, the verdict holds at Suspicious and the agent goes to get more — Dynamic Query searches your events and logs on demand. A call is made only when it can be defended.

MaliciousAIDR TImatch in 3 sourcesDynamic Query1,850 probes foundMITRE T1595Active Scanning

A Malicious verdict connected to the findings that support it

A Malicious verdict connected to the findings that support it

Every verdict shows its work.

Findings, intel matches, MITRE mappings — the evidence rides with the verdict, cited. Your analysts and your auditors read the same trail.

Repeat noise, per weekW1W2W3W4W5W6

Recurring benign noise shrinks week over week as closures train the model

Recurring benign noise shrinks week over week as closures train the model

It learns your environment.

Every closure — the AI’s or yours — trains the verdict model on what normal looks like for you. This week’s noise doesn’t come back next week.

Catch what your existing tools miss.

Every alert investigated — none sampled

Verdicts with the evidence attached

Analysts only make the calls that matter