Black Hat USA 2026Startup City, Booth 5815 · Aug 4–6 · Mandalay Bay, Las VegasBook a booth demo

Incident Response

Containment as tasks — fast where it’s safe, always with a human on the gate.

Contain the attack, keep the human in control.

Every verdict becomes the right kind of task — proposed by the AI, executed only after a human says go.

Step 1 · Create

Verdicts become tasks.

A Suspicious incident spawns investigation tasks; a Malicious one spawns mitigation tasks — sometimes several from a single incident. Benign never gets here: it already closed itself. And when you need a task the AI didn’t propose, create it yourself and assign a teammate.

INC-47INC-48INC-45SuspiciousMaliciousBenignTrace key usageinvestigation · via INC-47Review sign-in historyinvestigation · via INC-47Isolate DATA-WH-01mitigation · via INC-48Rotate svc-backup keymitigation · via INC-48auto-closed — no task, no noise

A suspicious incident spawns two investigation tasks, a malicious one two mitigation tasks, and a benign one closes with no task

A suspicious incident spawns two investigation tasks, a malicious one two mitigation tasks, and a benign one closes with no task

Step 2 · Assist

Work the task with the assistant.

The assistant opens scoped to the task or incident you’re on. Ask in plain language — it writes the queries, runs them, and files what it finds.

Step 3 · Assign

Every task arrives ready to hand out.

AIDR sets the guardrails on every task — type, priority, the linked incident, and the reasoning behind them. All your team decides is who takes it. Dividing the work is the easy part now.

Step 4 · Close

Closed, documented, and learned from.

The task closes with its resolution and a full audit trail — and every closure trains the AI, so the system you run next month is sharper than the one you run today.

INC-48Incident, verdictedMalicious · from DetectionIsolate DATA-WH-01mitigationRotate svc-backup keymitigationTasks createdAI-proposed — or created by handHuman approvalapprove · modify · rejectEDR · isolateIAM · rotateFirewall · blockClosed · documentedresolution + audit trailevery closure trains the AI — sharper next month than today

A verdicted incident spawns tasks, a human approves at the gate, your tools execute, the task closes — and every closure trains the AI

A verdicted incident spawns tasks, a human approves at the gate, your tools execute, the task closes — and every closure trains the AI

Inside the response.

The assistant does the legwork; the playbook maps the mitigation.

Assistant

Ask. It queries. You decide.

Scoped to the task, the assistant writes and runs the queries you’d have hand-built — and files every answer back on the incident.

Playbook

Mitigation comes with a map.

Every mitigation task ships with its playbook — the target system, the exact items, and step-by-step instructions.

Autonomous where safe. Human where it counts.

The AI proposes — analysts approve

Actions execute through your existing tools

Every action logged on the case