Malware hunt investigation
Correlate malware evidence across assets and produce an explainable hunt plan.
What this workflow does
Correlate malware evidence across assets and produce an explainable hunt plan. It separates observed facts from inference, surfaces conflicting evidence, and delivers a review-ready finding set instead of an opaque answer.
What you gain
Analyst-reviewed malware hunt report
What the AI agent changes
How this worked before
Traditional automation could collect records, but a person still had to compare sources, resolve conflicts, and write the conclusion.
What the AI agent changes
The agent can plan a search, inspect multiple sources, distinguish facts from inference, and return a cited report.
Agent trigger
A novel sample, indicator, or threat hypothesis is approved for investigation.
Inputs
- Process context: sample, telemetry, indicators, asset context, and prior detections
- Approved policies, ownership, and exception rules
Agent flow
- 1
Collect source material from the approved systems and record its timestamp.
- 2
Cross-check conflicting signals and separate facts from inference.
- 3
Prepare a cited hypothesis, affected scope, and hunt queries with citations, unknowns, and confidence.
- 4
Deliver the approved report and preserve its evidence set.
Human decisions
After step 3
The accountable process owner approves a cited hypothesis, affected scope, and hunt queries.
Outcome
- Analyst-reviewed malware hunt report
- Evidence, exceptions, and audit trail
Guardrails
- Label inference separately from observed facts.
- Do not close the investigation while required sources are unavailable.
Risks and mitigations
Missing or stale evidence can produce a confident but incomplete finding.
Show source coverage, conflicts, timestamps, and unanswered questions.
Sources and evidence
Sources establish feasibility or impact. Not every metric comes from an identical implementation.