Security Operations
AI agents for SOC investigation and response
Cantina uses AI agents to triage alerts and investigate across your existing tools. Your team sets the response policy and decides which actions need approval.
Investigate incidents across the systems involved
An endpoint detection may need an identity check. A cloud alert may need access logs and information about the exposed data. Cantina connects these parts of the investigation so your analysts can assess the incident with the evidence in front of them.
Alert
Endpoint detection
LT-4471 · suspicious binary
Investigate across systems
-
Endpoint
process tree · persistence
-
Identity
sign-ins · session tokens
-
Cloud
access logs · exposed data
-
Logs & SIEM
correlated events
Response
Isolate host, revoke sessions
proposed action
Work with your existing security tools
Connect the sources needed for each investigation. Clarion uses alerts, live tool queries and context from the Brain to check affected accounts, devices and resources.
Your SIEM and endpoint tools keep their place in the workflow. Agents investigate the signals they produce.
-
SIEM and endpoint signals
Bring Microsoft Sentinel incidents into triage and query its data lake during an investigation. Microsoft Defender XDR supplies incidents through polling. CrowdStrike, Huntress and SentinelOne are also available integrations for endpoint investigations.
-
Identity context
Use Microsoft Entra ID for read-only identity, sign-in, group and role context. Connect Okta to investigate identity activity. What an agent can change is separate from what it can read.
-
Cloud and log queries
Connect AWS for GuardDuty alerts and CloudTrail or CloudWatch queries. Datadog supplies security events and infrastructure context. Available queries depend on the permissions granted to each connection.
-
Team input and follow-through
Use Slack or Microsoft Teams for investigation updates and human input. Jira and Linear can carry the work that needs an owner or a separate remediation task.
Event sources, available queries and response actions depend on the connector and its scopes. Review those permissions before enabling a monitor or granting an agent an action.
Follow the evidence through to the response
- 01
Connect the relevant tools
Connect the relevant sources, configure a monitor and its alert filters, then link the agent that should investigate. Review its skills and tool permissions before enabling it.
- 02
Investigate the alert
Check the affected device, account or resource using available live tools and context from the Brain. Follow the evidence to assess whether the activity represents a threat.
- 03
Apply the response policy
Let the agent take actions allowed by your tool policies, or require your team to approve the proposed response. If information is missing, the agent can ask for input.
- 04
Check the result
Review the action result and supporting evidence. Keep the investigation record and any remaining human tasks visible; closing an issue alone does not prove a fix is deployed.
Put agents to work on the investigations your team handles every day
Cloud investigations
Check the affected resource, access history and relevant cloud logs to assess exposure.
Endpoint and identity checks
Connect a device detection to the associated account, sign-ins and group context.
Response actions
Use the actions supported by your connected tools, or route the next step to the person who needs to act.
Approval controls
Decide which actions Cantina can take and which require a person. Review the proposed action before granting approval.
Demo investigation
An impossible-travel alert, investigated in context
Sign-ins from distant locations raise questions about the account, its device and the source of the activity. In this demo, Clarion worked a Microsoft Sentinel and Defender XDR alert using identity context and earlier investigation history.
-
Retrieve the identity context
The agent retrieved the user's identity, managed device and group memberships from the Brain. That gave the sign-in alert context about the account and the access associated with it.
-
Check current sign-ins
It queried recent Microsoft Entra sign-ins to check device state and authentication activity. Stored context helped direct the investigation; live queries checked what was happening now.
-
Reuse the earlier investigation
The source IP already appeared in the Brain's asset catalog from a prior investigation. The agent followed that history instead of researching the same source from scratch.
Review the evidence before the response
Analysts can follow the agent's tool calls and returned evidence in the investigation record. When a configured action needs approval, the agent asks before proceeding. The next step may be an approved action or a human task, depending on the tools and permissions available.
This example shows context retrieval and live checks in a demo environment. It is not a customer outcome or a response-time benchmark.
What security teams say about Cantina
Cantina is the first platform we have used that carries the work through from finding an issue to driving the fix, and it lets my team operate like one far larger than it is. We keep finding new uses for it across our security program.
Matt Mock
Chief Information Security Officer
See how Cantina would handle one of your alerts
Walk through the evidence, response decision, and verification with our team.