Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

Security Operations

AI agents for SOC investigation and response

Cantina uses AI agents to triage alerts and investigate across your existing tools. Your team sets the response policy and decides which actions need approval.

Investigate incidents across the systems involved

An endpoint detection may need an identity check. A cloud alert may need access logs and information about the exposed data. Cantina connects these parts of the investigation so your analysts can assess the incident with the evidence in front of them.

Alert

Endpoint detection

LT-4471 · suspicious binary

Investigate across systems

  • Endpoint

    process tree · persistence

  • Identity

    sign-ins · session tokens

  • Cloud

    access logs · exposed data

  • Logs & SIEM

    correlated events

Response

Isolate host, revoke sessions

proposed action

Awaiting your approval
Illustrative workflow. Available checks and response actions depend on your integrations and permissions.

Work with your existing security tools

Connect the sources needed for each investigation. Clarion uses alerts, live tool queries and context from the Brain to check affected accounts, devices and resources.

Your SIEM and endpoint tools keep their place in the workflow. Agents investigate the signals they produce.

Explore integrations and connection options

  • SIEM and endpoint signals

    Bring Microsoft Sentinel incidents into triage and query its data lake during an investigation. Microsoft Defender XDR supplies incidents through polling. CrowdStrike, Huntress and SentinelOne are also available integrations for endpoint investigations.

  • Identity context

    Use Microsoft Entra ID for read-only identity, sign-in, group and role context. Connect Okta to investigate identity activity. What an agent can change is separate from what it can read.

  • Cloud and log queries

    Connect AWS for GuardDuty alerts and CloudTrail or CloudWatch queries. Datadog supplies security events and infrastructure context. Available queries depend on the permissions granted to each connection.

  • Team input and follow-through

    Use Slack or Microsoft Teams for investigation updates and human input. Jira and Linear can carry the work that needs an owner or a separate remediation task.

Event sources, available queries and response actions depend on the connector and its scopes. Review those permissions before enabling a monitor or granting an agent an action.

Follow the evidence through to the response

  1. 01

    Connect the relevant tools

    Connect the relevant sources, configure a monitor and its alert filters, then link the agent that should investigate. Review its skills and tool permissions before enabling it.

  2. 02

    Investigate the alert

    Check the affected device, account or resource using available live tools and context from the Brain. Follow the evidence to assess whether the activity represents a threat.

  3. 03

    Apply the response policy

    Let the agent take actions allowed by your tool policies, or require your team to approve the proposed response. If information is missing, the agent can ask for input.

  4. 04

    Check the result

    Review the action result and supporting evidence. Keep the investigation record and any remaining human tasks visible; closing an issue alone does not prove a fix is deployed.

Put agents to work on the investigations your team handles every day

Cloud investigations

Check the affected resource, access history and relevant cloud logs to assess exposure.

Endpoint and identity checks

Connect a device detection to the associated account, sign-ins and group context.

Response actions

Use the actions supported by your connected tools, or route the next step to the person who needs to act.

Approval controls

Decide which actions Cantina can take and which require a person. Review the proposed action before granting approval.

Demo investigation

An impossible-travel alert, investigated in context

Sign-ins from distant locations raise questions about the account, its device and the source of the activity. In this demo, Clarion worked a Microsoft Sentinel and Defender XDR alert using identity context and earlier investigation history.

  1. Retrieve the identity context

    The agent retrieved the user's identity, managed device and group memberships from the Brain. That gave the sign-in alert context about the account and the access associated with it.

  2. Check current sign-ins

    It queried recent Microsoft Entra sign-ins to check device state and authentication activity. Stored context helped direct the investigation; live queries checked what was happening now.

  3. Reuse the earlier investigation

    The source IP already appeared in the Brain's asset catalog from a prior investigation. The agent followed that history instead of researching the same source from scratch.

Review the evidence before the response

Analysts can follow the agent's tool calls and returned evidence in the investigation record. When a configured action needs approval, the agent asks before proceeding. The next step may be an approved action or a human task, depending on the tools and permissions available.

This example shows context retrieval and live checks in a demo environment. It is not a customer outcome or a response-time benchmark.

What security teams say about Cantina

Trend Health Partners Security leadership
Cantina is the first platform we have used that carries the work through from finding an issue to driving the fix, and it lets my team operate like one far larger than it is. We keep finding new uses for it across our security program.

Matt Mock

Chief Information Security Officer

See how Cantina would handle one of your alerts

Walk through the evidence, response decision, and verification with our team.