
概览
主要功能
- 基于自然语言的安全数据查询
- 威胁狩猎与调查支持
- 警报分拣协助
- 事件时间线重建
- 与安全遥测源集成
价格
- 模型
- Free
- 分类
- 终有吐和压免给
- 评分
- 4.3 / 5 (6)
使用场景
加速 SOC 的警报分拣
SOC 分析师以普通英语提问关于来袭警报的问题,以快速评估严重性、背景和范围,无需编写复杂查询。
无查询语言的威胁狩猎
猎手利用自然语言探索日志和遥测,发现可疑模式,降低主动调查的技术门槛。
重建事件时间线
事件响应者追踪跨安全数据源的事件,构建清晰的攻击者活动时间线,以更快地遏制并报告。
入职并提升初级分析师
新分析师通过普通英语查询安全数据,快速参与调查,而非学习厂商特定查询语法。
优点 & 缺点
优点
- 无需学习复杂的查询语言
- 加速威胁调查和分拣
- 对经验不足的分析师友好
- 降低事件期间的上下文切换
缺点
- 效果取决于基础数据质量
- 自然语言查询可能需要细化
- 在安全工作流之外的实用性有限
对决战绩
在万神殿中参与了 6 对决。
Last 5 battles
- #2
Legal, Risk & Compliance Showdown — June 17, 2026
Jun 17, 2026 · #2 of 2
- #2
Legal, Risk & Compliance Showdown — March 24, 2026
Mar 24, 2026 · #2 of 2
- #1
Legal, Risk & Compliance Showdown — August 18, 2025
Aug 18, 2025 · #1 of 2
- #2
Legal, Risk & Compliance Showdown — June 11, 2025
Jun 11, 2025 · #2 of 2
- #2
Legal, Risk & Compliance Showdown — June 9, 2025
Jun 9, 2025 · #2 of 2
评测
6 个评分的平均值。
登录以留下评测。
Skeptical, then convinced
I went in skeptical — most tools in this space overpromise. It actually delivers on natural language queries over security data, and no need to learn complex query languages caught me off guard. Limited usefulness outside security workflows is why this isn't a perfect score, still, I'd recommend giving it a real trial.
Solid for our team
We rolled this out across the team last quarter and reduces context switching during incidents. Natural language queries over security data fits neatly into how we already work, and natural language queries over security data removed a step we used to do by hand. but it has held up under daily use.
Compared a few options
Evaluated this against two competitors. Where it wins: alert triage assistance and no need to learn complex query languages. Where it lags: effectiveness depends on underlying data quality. On balance the feature set — especially alert triage assistance — justifies the 4 stars for our use case.
Compared a few options
Evaluated this against two competitors. Where it wins: integration with security telemetry sources and no need to learn complex query languages. On balance the feature set — especially threat hunting and investigation support — justifies the 5 stars for our use case.
Use it every day
Honestly didn't expect to like it this much. Incident timeline reconstruction is exactly what I needed, and speeds up threat investigation and triage. I do wish limited usefulness outside security workflows, but I reach for it almost every day now and it just clicks.
Skeptical, then convinced
I went in skeptical — most tools in this space overpromise. It actually delivers on threat hunting and investigation support, and speeds up threat investigation and triage caught me off guard. Natural language queries may need refinement is why this isn't a perfect score, still, I'd recommend giving it a real trial.
问答
What limits the accuracy of AI Investigator’s natural‑language queries?
Query effectiveness depends on the underlying data quality; ambiguous or vague prompts may need refinement, and the tool works best when users are specific (e.g., naming users or IPs) to generate precise structured queries.
Asked by Yara Mansour · Jan 29, 2026
How does AI Investigator handle multi‑tenant environments and access control?
The platform is tenant‑aware by design, enforcing strict role‑based access controls that limit each user’s view and query scope, ensuring secure and auditable investigations across multiple tenants.
Asked by Henrik Dahl · Dec 22, 2025
What data sources can AI Investigator query without writing code?
AI Investigator can pull telemetry from on‑prem and cloud sources such as network traffic, Sysmon and Windows Event Logs, Microsoft Entra ID sign‑ins, Office 365 audit trails, and EDR alerts from solutions like SentinelOne, Sophos, and Trend Micro.
Asked by Nils Johansson · Dec 13, 2025





