Book a demo

Use case · Investigation

Investigations

An escalation is not an answer. It is a question that now needs a timeline built from four or five sources, a judgement about how far the thing spread, a root cause, and a write up that a responder, a manager and eventually an auditor can all use.

Runs on

SIEM · EDR · identity · cloud · ITSM

Autonomy

levels 1 to 3

The problem today

The investigation is the expensive part, and it is where depth quietly gets traded for speed

A proper investigation takes a senior analyst several hours: pulling telemetry from each system, aligning timestamps, working out which accounts and hosts were involved, and separating what happened from what was merely present.

Under load, that work gets shortened rather than skipped. The incident is closed on the first plausible explanation, the scope is assumed rather than established, and the write up is a paragraph. Six months later nobody can tell whether it was handled properly.

What CloudPeek does

As many passes as the evidence demands.

CloudPeek // flow · escalation to write upflow 02 · INC-2418
EDR telemetrysign in historycloud auditprior incidentsnew lead · another passOPENescalated from triageTIMELINE412 events · 38 keptCORRELATE4 sources · 3 passesROOT CAUSEconsent grant · 11 AugWRITE UPevidence linkedHANDOVERentity pages updated
iterative by design · pivots on what it finds · the operator can steer at any pointEvery step recorded
swipe to see the full flow
CloudPeek // action trail · illustrative entriesautonomy level 2
09:27:01OPENEscalation from triage. Suspected credential abuse, 1 identity, 2 hosts.
09:27:04TIMELINEEvents aligned across SIEM, EDR, identity and cloud audit. 412 events, 38 relevant.
09:27:39SCOPEBlast radius established: 2 hosts, 1 service account, 1 shared mailbox. No lateral movement found.
09:28:02ROOT CAUSEToken issued to an unmanaged device following a consent grant on 11 August.
09:28:15WRITE UPNarrative, timeline, scope, root cause and recommended actions produced with evidence linked.
09:28:16HANDOVEREntity pages updated. Findings available to the next investigation touching these assets.
read only by default · policy bounded · kill switch with the operatorAll actions traced
At level 1The full investigation and write up are prepared. Your analyst reviews, amends and signs it off.
At level 2Recommended actions arising from the investigation are staged and held for approval.
At level 3Investigation and the actions it recommends run inside declared guardrails, fully recorded.

What you get

Outcomes, not activity.

DepthScope established, not assumedHow far it spread is answered with evidence rather than a judgement made under time pressure.
SpeedMinutes rather than a dayThe senior analyst reviews an investigation instead of assembling one.
ReuseFindings that compoundEvery conclusion is written back, so the next investigation on the same assets starts further along.

Get started

Bring a week of alerts nobody got to.

Book a demo