Platform · 05 Investigate
Signals are scored, associated, and investigated before a human sees them. What reaches your team is a qualified incident: what happened, to whom, in what order, what was checked, and what to do about it.
Qvasir resolves events to the entities behind them — users, hosts, processes, services — and reasons about behavior per entity over time. This is the stage that picks up what correlation escalates: everything before it is deterministic, and everything after it is an investigation.
Investigation agents use the Model Context Protocol (MCP) to reach the tools an analyst would: threat intelligence, DNS, and your own platform data — and the framework is extensible with custom tools for your environment.
What it costs to run
An AI investigation costs real money per incident, which is the objection nobody in this category answers on their website. Two mechanisms keep that bounded, and both of them exist because the alternative was discovered the expensive way.
The platform is asked whether there is budget left before an investigation starts. When it is exhausted, the investigation is skipped rather than quietly running up a bill you find out about at the end of the month.
After a verdict, what was concluded about that entity is remembered — the decision, the severity, the tactics. A fresh alert for the same entity that is not a genuine escalation on that picture reuses the verdict instead of paying for a second opinion on the same question.
Skipping the investigation does not mean producing nothing. A lightweight verdict is still emitted, so the new activity joins the incident already open on that entity — rather than vanishing because it was judged not worth a second look.
The honest dependency. Investigation is the one stage of the pipeline that requires a model — ingest, matching and correlation are all deterministic and run without one, as does search. With no provider configured you still get scored, correlated, entity-aware alerts; what you do not get is the investigated incident this page describes. Provider support here is narrower than elsewhere in the platform: investigation runs on Anthropic or Gemini.
Fast search across your event store — pivot from any incident entity straight into the events behind it, exactly as the source emitted them.
Verdicts, escalation, and case notes are built in — and every analyst verdict feeds the detection improvement loop.
Every action on an incident — human or AI — is recorded. Handovers, reviews, and post-incident reporting come for free.
Read a full example incident report →
Policy-driven automated response — block, isolate, lock out — is on the roadmap, built on this investigation layer.