Incident & Investigation Agent
The Incident & Investigation Agent performs a deeper, hypothesis-driven investigation in the SOC Operations workflow. It evaluates all alerts associated with the incident, identifies the entities involved, and develops an investigation hypothesis using available context such as MITRE ATT&CK enrichment and Anomali ThreatStream threat intelligence.
The agent then evaluates the available evidence and records its investigation findings and supporting evidence.
Based on the findings, the agent recommends one of two incident outcomes:
-
Escalate—when broader case-level investigation, response, or coordination is required.
-
Close—when no further case-level handling is required. A Close recommendation includes a closure reason. If the available evidence remains inconclusive, the incident remains under investigation according to the re-investigation workflow rather than being closed automatically
While the Incident & Investigation Agent performs its investigation, you do not need to monitor each step. When findings or recommended actions require your attention, you must review the recommendation in the Approval Queue. See Using Approval Queue.
If you approve an escalation recommendation, the agent creates a case and the Case Management Agent enriches and manages the case from that point on. See Case Management Agent for more information.
For details on monitoring and managing the Incident & Investigation Agent, refer to Monitoring Status and Activity of Individual Agents.