
概要
主な機能
- セキュリティデータに自然言語クエリを掛ける
- 脅威狩りおよび調査サポート
- エラート処理の助言
- インシデント時系列再構築
- セキュリティテレメトリソースと統合する
料金
- モデル
- Free
- カテゴリー
- 東起と合通にブソルを工私だ
- 評価
- 4.3 / 5 (6)
ユースケース
SOC上でのエラート処理を高速化する
SOC分析者はincomingアルラートについてのご自身の言葉で質問して、脅威の重さ、背景、および範囲を簡単に理解し、複雑なクエリを書かなくても、迅速に評価することができます。
クエリ言語なしで脅威狩りをする
ハンタはロッグおよびテレメトリに自然言語を使用して、不審なパターンを表面化するために、主導的な調査に役立つ可能性があります。
インシデント時系列を再構築する
インシデント処理者はセキュリティデータソースを通じて、迅速には抑留およびレポートを高速化するための侵入者の活動と連続した時系列を表すための、起こり得る事件の連鎖を辿ることができます。
ジュニア分析者を導入して向上させる
新しい分析者はvendor特有のクエリ記法を学習しなくても、セキュリティデータに自然言語で質問することで、インシデントに貢献する時間を短縮できます。
メリット & デメリット
メリット
- 複雑なクエリ言語を学識を得る必要がなく
- 脅威の調査およびエラート処理を高速化する
- 経験不足な分析者にもアクセス
- インシデント中のコンテキストスイッチングを削減する
- 効果性はデータの品質に依存
- 自然言語クエリの改良が必要になる場合
- セキュリティフローの外では有用性が限られる
デメリット
- アンダーリング データの質に依存するため、効果は低い可能性があります。
- 自然言語のクエリを精度よく設定する必要がある場合があります。
- セキュリティワークフロー以外では、有用性が制限される可能性があります。
バトル戦績
パンテオンで6バトルに出場。
Last 5 battles
- #2
Legal, Risk & Compliance Showdown — June 17, 2026
Jun 17, 2026 · #2 of 2
- #2
Legal, Risk & Compliance Showdown — March 24, 2026
Mar 24, 2026 · #2 of 2
- #1
Legal, Risk & Compliance Showdown — August 18, 2025
Aug 18, 2025 · #1 of 2
- #2
Legal, Risk & Compliance Showdown — June 11, 2025
Jun 11, 2025 · #2 of 2
- #2
Legal, Risk & Compliance Showdown — June 9, 2025
Jun 9, 2025 · #2 of 2
レビュー
6件の評価の平均。
レビューを投稿するにはログインしてください。
Skeptical, then convinced
I went in skeptical — most tools in this space overpromise. It actually delivers on natural language queries over security data, and no need to learn complex query languages caught me off guard. Limited usefulness outside security workflows is why this isn't a perfect score, still, I'd recommend giving it a real trial.
Solid for our team
We rolled this out across the team last quarter and reduces context switching during incidents. Natural language queries over security data fits neatly into how we already work, and natural language queries over security data removed a step we used to do by hand. but it has held up under daily use.
Compared a few options
Evaluated this against two competitors. Where it wins: alert triage assistance and no need to learn complex query languages. Where it lags: effectiveness depends on underlying data quality. On balance the feature set — especially alert triage assistance — justifies the 4 stars for our use case.
Compared a few options
Evaluated this against two competitors. Where it wins: integration with security telemetry sources and no need to learn complex query languages. On balance the feature set — especially threat hunting and investigation support — justifies the 5 stars for our use case.
Use it every day
Honestly didn't expect to like it this much. Incident timeline reconstruction is exactly what I needed, and speeds up threat investigation and triage. I do wish limited usefulness outside security workflows, but I reach for it almost every day now and it just clicks.
Skeptical, then convinced
I went in skeptical — most tools in this space overpromise. It actually delivers on threat hunting and investigation support, and speeds up threat investigation and triage caught me off guard. Natural language queries may need refinement is why this isn't a perfect score, still, I'd recommend giving it a real trial.
Q&A
AI Investigatorの自然言語クエリの正確性を制限する要因は何ですか?
クエリの効果は基盤となるデータの品質に依存します。曖昧または漠然としたプロンプトは改良が必要で、ツールはユーザーが具体的(例:ユーザー名やIPを指定)に入力すると最も正確な構造化クエリを生成できるように設計されています。
Asked by Yara Mansour · Jan 29, 2026
AI Investigatorはマルチテナント環境とアクセス制御をどのように処理しますか?
AI Investigatorは設計上テナントに対して認識があり、厳格なロールベースのアクセス制御を施行して各ユーザーの閲覧範囲とクエリ範囲を制限します。これにより、複数テナントにわたる調査を安全かつ監査可能に実行できます。
Asked by Henrik Dahl · Dec 22, 2025
What data sources can AI Investigator query without writing code?
AI Investigatorは、オンプレミスやクラウドソースからテレメトリを取得できます。例えば、ネットワークトラフィック、SysmonおよびWindows Event Logs、Microsoft Entra IDのサインイン、Office 365監査トレイル、SentinelOne、Sophos、Trend MicroなどのEDRアラートがあります。
Asked by Nils Johansson · Dec 13, 2025
質問する
東起と合通にブソルを工私だの代替
Trending now

正確な宿題の助けとなる説明がある

複雑なPDF、スライド、スプレッドシートを.parse、分割、OCR、構造化データを抽出するドキュメント インテリジェンス API。

オープンマルチモーダル 12B モデルが、128K コンテキストウィンドウでインターリーブ画像とテキストを処理する。

スポンサード回答、クリックごとに収益

