AI Investigator logo

AI Investigator脆弱性データをご自身の言葉で問い合わせて、脅威を迅速に調べます。

4.3 (6)
Daniel Nikulshynレビュー: Daniel Nikulshyn·更新 2026年7月

概要

セキュリティ分析者を支援してデータをご自身の言葉で問い合わせることができます。特殊な記法や遅いパヴィティングを使わずに、構造されたクエリを自動生成および実行して、オンプレミスおよびクラウドソースを通じた脅威の調査に力を付けます。自然言語を通じて、分析者はセキュリティの質問をすると、次のアクションへの提案と連続した洞察を得ることができます。従来は数時間でしたが、調査時間を数分以下に短縮します。このツールはハイブリッドインフラストラクチャからテレメトリへの平易なアクセスを提供し、ネットワークトラフィック、Sysmon、Windows Event Logs、および人気セキュリティソリューションからEDRアラートなどのさまざまなデータソースへの瞬間的なアクセスと完全な視認性を提供します。AI Investigatorは、複数のテナント環境に対応するための組み込みアクセス制御を備えています。これにより、セキュアで審査可能な調査を実行することが可能になります。

主な機能

  • セキュリティデータに自然言語クエリを掛ける
  • 脅威狩りおよび調査サポート
  • エラート処理の助言
  • インシデント時系列再構築
  • セキュリティテレメトリソースと統合する

料金

モデル
Free
評価
4.3 / 5 (6)

ユースケース

SOC上でのエラート処理を高速化する

SOC分析者はincomingアルラートについてのご自身の言葉で質問して、脅威の重さ、背景、および範囲を簡単に理解し、複雑なクエリを書かなくても、迅速に評価することができます。

クエリ言語なしで脅威狩りをする

ハンタはロッグおよびテレメトリに自然言語を使用して、不審なパターンを表面化するために、主導的な調査に役立つ可能性があります。

インシデント時系列を再構築する

インシデント処理者はセキュリティデータソースを通じて、迅速には抑留およびレポートを高速化するための侵入者の活動と連続した時系列を表すための、起こり得る事件の連鎖を辿ることができます。

ジュニア分析者を導入して向上させる

新しい分析者はvendor特有のクエリ記法を学習しなくても、セキュリティデータに自然言語で質問することで、インシデントに貢献する時間を短縮できます。

メリット & デメリット

メリット

  • 複雑なクエリ言語を学識を得る必要がなく
  • 脅威の調査およびエラート処理を高速化する
  • 経験不足な分析者にもアクセス
  • インシデント中のコンテキストスイッチングを削減する
  • 効果性はデータの品質に依存
  • 自然言語クエリの改良が必要になる場合
  • セキュリティフローの外では有用性が限られる

デメリット

  • アンダーリング データの質に依存するため、効果は低い可能性があります。
  • 自然言語のクエリを精度よく設定する必要がある場合があります。
  • セキュリティワークフロー以外では、有用性が制限される可能性があります。

バトル戦績

パンテオンで6バトルに出場。

2
1位
4
2位
0
3位

Last 5 battles

レビュー

4.3

6件の評価の平均。

5
2
4
4
3
0
2
0
1
0

レビューを投稿するにはログインしてください。

Pierre Dubois

Pierre Dubois

Feb 27, 2026

Skeptical, then convinced

I went in skeptical — most tools in this space overpromise. It actually delivers on natural language queries over security data, and no need to learn complex query languages caught me off guard. Limited usefulness outside security workflows is why this isn't a perfect score, still, I'd recommend giving it a real trial.

VN

Victor Nguyen

Feb 18, 2026

Solid for our team

We rolled this out across the team last quarter and reduces context switching during incidents. Natural language queries over security data fits neatly into how we already work, and natural language queries over security data removed a step we used to do by hand. but it has held up under daily use.

GE

Gunnar Eriksson

Jan 28, 2026

Compared a few options

Evaluated this against two competitors. Where it wins: alert triage assistance and no need to learn complex query languages. Where it lags: effectiveness depends on underlying data quality. On balance the feature set — especially alert triage assistance — justifies the 4 stars for our use case.

Frank Müller

Frank Müller

Jul 25, 2025

Compared a few options

Evaluated this against two competitors. Where it wins: integration with security telemetry sources and no need to learn complex query languages. On balance the feature set — especially threat hunting and investigation support — justifies the 5 stars for our use case.

Tomáš Novák

Tomáš Novák

Jul 24, 2025

Use it every day

Honestly didn't expect to like it this much. Incident timeline reconstruction is exactly what I needed, and speeds up threat investigation and triage. I do wish limited usefulness outside security workflows, but I reach for it almost every day now and it just clicks.

Liam O’Connor

Liam O’Connor

Jun 1, 2025

Skeptical, then convinced

I went in skeptical — most tools in this space overpromise. It actually delivers on threat hunting and investigation support, and speeds up threat investigation and triage caught me off guard. Natural language queries may need refinement is why this isn't a perfect score, still, I'd recommend giving it a real trial.

Q&A

AI Investigatorの自然言語クエリの正確性を制限する要因は何ですか?

クエリの効果は基盤となるデータの品質に依存します。曖昧または漠然としたプロンプトは改良が必要で、ツールはユーザーが具体的(例:ユーザー名やIPを指定)に入力すると最も正確な構造化クエリを生成できるように設計されています。

Asked by Yara Mansour · Jan 29, 2026

AI Investigatorはマルチテナント環境とアクセス制御をどのように処理しますか?

AI Investigatorは設計上テナントに対して認識があり、厳格なロールベースのアクセス制御を施行して各ユーザーの閲覧範囲とクエリ範囲を制限します。これにより、複数テナントにわたる調査を安全かつ監査可能に実行できます。

Asked by Henrik Dahl · Dec 22, 2025

What data sources can AI Investigator query without writing code?

AI Investigatorは、オンプレミスやクラウドソースからテレメトリを取得できます。例えば、ネットワークトラフィック、SysmonおよびWindows Event Logs、Microsoft Entra IDのサインイン、Office 365監査トレイル、SentinelOne、Sophos、Trend MicroなどのEDRアラートがあります。

Asked by Nils Johansson · Dec 13, 2025

質問する

東起と合通にブソルを工私だの代替