Back to workflows
Security & ITInvestigate and reportTeam

Malware hunt investigation

Correlate malware evidence across assets and produce an explainable hunt plan.

What this workflow does

Correlate malware evidence across assets and produce an explainable hunt plan. It separates observed facts from inference, surfaces conflicting evidence, and delivers a review-ready finding set instead of an opaque answer.

What you gain

Analyst-reviewed malware hunt report

What the AI agent changes

How this worked before

Traditional automation could collect records, but a person still had to compare sources, resolve conflicts, and write the conclusion.

What the AI agent changes

The agent can plan a search, inspect multiple sources, distinguish facts from inference, and return a cited report.

Agent trigger

A novel sample, indicator, or threat hypothesis is approved for investigation.

Inputs

  • Process context: sample, telemetry, indicators, asset context, and prior detections
  • Approved policies, ownership, and exception rules

Agent flow

  1. 1

    Collect source material from the approved systems and record its timestamp.

  2. 2

    Cross-check conflicting signals and separate facts from inference.

  3. 3

    Prepare a cited hypothesis, affected scope, and hunt queries with citations, unknowns, and confidence.

  4. 4

    Deliver the approved report and preserve its evidence set.

Human decisions

After step 3

The accountable process owner approves a cited hypothesis, affected scope, and hunt queries.

Outcome

  • Analyst-reviewed malware hunt report
  • Evidence, exceptions, and audit trail

Guardrails

  • Label inference separately from observed facts.
  • Do not close the investigation while required sources are unavailable.

Risks and mitigations

Missing or stale evidence can produce a confident but incomplete finding.

Show source coverage, conflicts, timestamps, and unanswered questions.

Sources and evidence