AI Investigator logo

AI Investigatorשאל את הנתוני הביטחון בשפה פשוטה כדי לחקור איומים מהר

4.3 (6)
Daniel Nikulshynנבדק על ידי Daniel Nikulshyn·עודכן יולי 2026

סקירה

AI Investigator מאמנת את חוקרי ביטחון לשאול את נתוניהם בשפה פשוטה, ללא תאור שפיות או תפנית איטית. היא מוציאה באופן אוטומטי ומריצה שאלות מבנות, ואפשרה לחוקרים לחקור איומים על פני מקורות מס וצל. על ידי שימוש בלשון טבעית, החוקרים יוכלו לשאול שאלות על ביטחון ולקבל תצפיות בתפיל-צעד, עם הצעות לצעדי פעולה, וזאת במטרה להוריד את זמן החיפושים משעות לדקות. הכלי נעשה לצורך של שמשכור בלתי-אחיד, עם ראות טוטלית וגישה הזמינה כל הזמן למספר מקורות התגליות, כולל תעבורת רשת, Sysmon ו- Windows Event Logs, ואזערטי EDR מפשכונייטאת עבור פתרונות-ביטחון פופולארים. AI Investigator כוללת גם גישה גשרונית-טכונית עבור סביבתי-בטלעטנט, שומר על חקי-ביטחון נגיש ותאבע-צאפ.

תכונות עיקריות

  • שאילתות בשפה טבעית על נתוני אבטחה
  • תמיכה בחיפוש איומים ובחקירה
  • סיוע בסינון התראות
  • בנייה מחדש של ציר הזמן של אירוע
  • שילוב עם מקורות טלמטריה של אבטחה

תמחור

מודל
Free
דירוג
4.3 / 5 (6)

מקרי שימוש

מה-ב-צ-ב-ק

ח-ק-ב-ב-ם- ת-

ז-ב-

ח-ק-ב-ח- (.

-

- -

- -

יתרונות וחסרונות

יתרונות

  • אין צורך ללמוד שפות שאילתה מורכבות
  • מאיץ חקירת איומים וסינון התראות
  • ניתן לשימוש על ידי אנליסטים עם פחות ניסיון
  • מקטין את המעבר בין קונטקסטים במהלך אירועים

חסרונות

  • יעילותו תלויה באיכות הנתונים הבסיסיים
  • שאילתות בשפה הטבעית עלולות לדרוש תיקונים
  • שימושיות מוגבלת מחוץ לזרימות עבודה של אבטחה

שיא קרבות

ב-6 קרבות בפנתאון.

2
1
4
2
0
3

Last 5 battles

ביקורות

4.3

ממוצע מ-6 דירוגים.

5
2
4
4
3
0
2
0
1
0

התחבר כדי להשאיר ביקורת.

Pierre Dubois

Pierre Dubois

Feb 27, 2026

Skeptical, then convinced

I went in skeptical — most tools in this space overpromise. It actually delivers on natural language queries over security data, and no need to learn complex query languages caught me off guard. Limited usefulness outside security workflows is why this isn't a perfect score, still, I'd recommend giving it a real trial.

VN

Victor Nguyen

Feb 18, 2026

Solid for our team

We rolled this out across the team last quarter and reduces context switching during incidents. Natural language queries over security data fits neatly into how we already work, and natural language queries over security data removed a step we used to do by hand. but it has held up under daily use.

GE

Gunnar Eriksson

Jan 28, 2026

Compared a few options

Evaluated this against two competitors. Where it wins: alert triage assistance and no need to learn complex query languages. Where it lags: effectiveness depends on underlying data quality. On balance the feature set — especially alert triage assistance — justifies the 4 stars for our use case.

Frank Müller

Frank Müller

Jul 25, 2025

Compared a few options

Evaluated this against two competitors. Where it wins: integration with security telemetry sources and no need to learn complex query languages. On balance the feature set — especially threat hunting and investigation support — justifies the 5 stars for our use case.

Tomáš Novák

Tomáš Novák

Jul 24, 2025

Use it every day

Honestly didn't expect to like it this much. Incident timeline reconstruction is exactly what I needed, and speeds up threat investigation and triage. I do wish limited usefulness outside security workflows, but I reach for it almost every day now and it just clicks.

Liam O’Connor

Liam O’Connor

Jun 1, 2025

Skeptical, then convinced

I went in skeptical — most tools in this space overpromise. It actually delivers on threat hunting and investigation support, and speeds up threat investigation and triage caught me off guard. Natural language queries may need refinement is why this isn't a perfect score, still, I'd recommend giving it a real trial.

שאלות ותשובות

What limits the accuracy of AI Investigator’s natural‑language queries?

Query effectiveness depends on the underlying data quality; ambiguous or vague prompts may need refinement, and the tool works best when users are specific (e.g., naming users or IPs) to generate precise structured queries.

Asked by Yara Mansour · Jan 29, 2026

How does AI Investigator handle multi‑tenant environments and access control?

The platform is tenant‑aware by design, enforcing strict role‑based access controls that limit each user’s view and query scope, ensuring secure and auditable investigations across multiple tenants.

Asked by Henrik Dahl · Dec 22, 2025

What data sources can AI Investigator query without writing code?

AI Investigator can pull telemetry from on‑prem and cloud sources such as network traffic, Sysmon and Windows Event Logs, Microsoft Entra ID sign‑ins, Office 365 audit trails, and EDR alerts from solutions like SentinelOne, Sophos, and Trend Micro.

Asked by Nils Johansson · Dec 13, 2025

שאל שאלה

חלופות למשפט, סיכון וצייתנות