AI Agents

Your autonomous AI investigation team

Eleven specialised AI agents work in concert — each an expert in their domain — to investigate every alert from triage through to resolution.

01

Report Agent

Receives alerts & delivers reports

The front door. Receives the alert, kicks off the investigation, and sends the finished report to your inbox when it is done.

Alert received and acknowledged in under 1 second
Final investigation report emailed automatically
Nothing sits in a queue
Learn more

02

Orchestrator

Watches your Sentinel workspace

Checks your Microsoft Sentinel workspace on a regular schedule and picks up any new incidents — even if no webhook is configured.

Checks every 5, 15, or 30 minutes — you choose
Never processes the same alert twice
Handles high-volume periods without slowing down
Learn more

03

Triage Agent

Real vs false alarm — decided in seconds

Reads the alert and decides immediately whether it is a genuine threat or a false alarm — with a confidence score so you know how certain it is.

False alarms closed automatically with documented reasoning
Real threats escalated to full investigation instantly
Your team only sees what genuinely matters
Learn more

04

Entity Enrichment

Who is involved and what are they?

Looks up every IP address, user account, and device mentioned in the alert — building a full picture of who is involved before a human even opens the report.

IP addresses: location, internet provider, who owns it
User accounts: job role, admin access, login history
Devices: what it is, who uses it, is it managed by your IT team
Learn more

05

Threat Intelligence

Is this a known threat actor?

Checks every suspicious IP, website, and file hash against global threat databases — the same databases professional threat analysts use.

Checks VirusTotal, URLhaus, and open threat feeds automatically
Tells you if an IP is linked to ransomware gangs or nation-state groups
Turns an unknown IP address into "known Qakbot command server"
Learn more

06

Hunting Agent

Looks for what the attacker left behind

Goes looking for signs of more activity beyond the original alert — like checking whether an attacker who got in through one door also tried others.

Searches for movement to other machines on your network
Looks for attempts to create new admin accounts
Finds malware that hid itself after the initial alert fired
Learn more

07

Investigation Agent

Puts the whole story together

Takes everything the other agents found and writes a clear, complete account of what happened — in plain English — with a full timeline and recommendations.

Full incident narrative: what happened, when, and how
Maps attack steps to known hacker playbooks (MITRE ATT&CK)
Specific, actionable recommendations — not generic advice
Learn more

08

Detection Engineering

Makes sure it cannot happen again

Every investigation teaches the system something new. After each incident, this agent writes a new detection rule so the same attack gets caught faster next time.

New Sentinel detection rules written after every investigation
Automatically avoids duplicating rules you already have
Your security posture improves with every incident handled
Learn more

09

Data Agent

Checks your security visibility is working

Runs a daily health check on your security data feeds — because you cannot detect a threat if your logs have silently stopped working.

Checks 50+ log sources every day
Alerts you if a data feed goes silent before you miss a real attack
Tells you if your coverage has gaps in critical areas
Learn more

10

Firewall Agent

Blocks the attacker at the door

When a confirmed malicious IP is found, this agent automatically blocks it at your firewall — before the attacker can move further into your network.

Blocks happen in under 60 seconds from confirmation
Works with Cisco and Fortinet firewalls out of the box
You can require human approval first, or let it act automatically
Learn more

11

Vulnerability Agent

Flags what the attacker might exploit next

When an incident involves one of your machines, this agent checks whether that machine has any known security weaknesses — and flags them so you can patch before the attacker uses them.

Cross-references active incidents with unpatched vulnerabilities
Prioritises by real risk — not just theoretical severity scores
Connects your patch backlog to live attack context
Learn more

Ready to transform your security operations?

See how urgentic's autonomous AI analysts can cut investigation time by 90% and reduce alert fatigue.