M ManySignal

AI Threat Hunter

From escalation to attack chain — and hunts that never sleep

The investigate agent assembles timelines and attack chains for every escalated case, and runs hypothesis-driven hunts against the event store on a schedule.

How it works

1

Timeline assembly

Pulls the relevant events, findings, and graph context for the case window into a single ordered timeline, with every step recorded.

2

Attack-chain reconstruction

Builds a step-by-step chain — initial access, actions taken, resources touched — grounded in observed events, and maps affected entities through the graph.

3

Hypothesis-driven hunts

Hunts carry named checks with expected outcomes plus an intel sweep; results are recorded as supporting or contradicting evidence, so hunts conclude with a position.

Key capabilities

Graph-grounded

Findings link to real entities and edges, not string matches.

Blast-radius mapping

Affected identities, assets, and data stores enumerated per case.

Scheduled or on-demand

Hunts run on the scheduler or fire immediately from the console.

What security leaders say

“Behavioural baselines cut our impossible-travel false positives to near zero. The agent knows what normal looks like per identity.”

Aisha Bello

SOC Manager, Skyfarer Air

“Month-end MDR client reports used to take my team three days. Now the report agent generates them from case data in minutes.”

Grace Whitfield

MDR Practice Director, Quillstone Legal

“Every verdict comes with the question set, the answers, and the weights. Our auditors had never seen anything like it.”

Jonas Meyer

Director of Security & Compliance, Cobalt Health

Investigate Agent agent: frequently asked questions

What does the Investigate Agent agent do?

The investigate agent assembles timelines and attack chains for every escalated case, and runs hypothesis-driven hunts against the event store on a schedule. It operates as the AI Threat Hunter inside ManySignal's agentic SOC and MDR platform.

How is the Investigate Agent agent governed?

Like every ManySignal agent, it runs under the autonomy ladder: recommend-only, approve-gated, or autonomous per action class, with dry-run previews and a tenant kill switch.

Can I audit the Investigate Agent agent's decisions?

Yes. Every question it answers, every verdict, and every action is recorded on an immutable case timeline with evidence weights.

Does it work with my existing stack?

Yes. Declarative connectors normalise telemetry from cloud, identity, endpoint, and code sources into the entity graph the agent reasons over.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.