Skip to main content

Socrates: Investigate Outside a Case

Ask Socrates Investigator anything - investigate, review, and take action at a workspace level.

Socrates is Torq's in-platform conversational AI surface for its AI agents. This article covers Investigator (Socrates working as an autonomous SOC analyst outside a case), which you select with the Investigator/Builder toggle at the top. (Builder, the other agent at launch, can perform workspace-level actions; see Socrates Builder: Getting Started.)

Investigator is always available across your workspace. For Socrates working on a specific case, see Socrates: Transform Case Investigations.

As a SOC analyst, Socrates works in three ways:

  • In-case chats: Inside a case, in the case's Socrates tab.

  • Autonomous case investigation: Socrates runs a predefined Actionplan on an assigned case.

  • Investigation outside a case: As Socrates' Investigator agent.

Outside a case, a chat operates across your entire workspace. Any signal (an alert, an observable, or any other finding or query) can serve as the starting point. Socrates draws on full workspace context, including existing cases and observables, to help you investigate, operate, and take action across your tech stack.

Where to find it

  • Open Socrates from the Socrates entry at the top of the left sidebar, then select Investigator using the Investigator/Builder toggle.

Start a chat

  1. Navigate to the Socrates tab.

  2. Enter a prompt in the message field describing what you want to investigate or do.

Use tools in a chat

To see which tools are available or ask Socrates to use a specific one, open the tool menu and select a tool. The selected tool is embedded in your message as a chip.

  • In Socrates: type / to open the tool menu.

Socrates only uses existing, enabled tools, and it cannot execute built-in tools in restricted cases. Explicitly selecting a tool does not guarantee that Socrates will use it. It may choose a different or additional tool based on your message. See Socrates Tools.

Collaboration and history

Chats are saved and shared across the workspace. You can filter to All chats or My chats. Multiple analysts can view, contribute, and take action, with full visibility into Socrates' responses and executions. You can rename or delete a chat from its three-dot menu.

Monitoring

Activity logs: Each message in a Socrates chat is recorded in the Activity Log (event source: Socrates conversation message), whether or not Socrates performs an action.

Audit logs: When Socrates performs an action, the Audit Log attributes it to Socrates, acting on your behalf. See Socrates Auditing: Monitor Your AI Analyst.

Permissions

  • socrates.investigations.read: List and read the content of chats.

  • socrates.investigations.write: Start and participate in chats. Available to all roles except Viewer roles.

For more on scopes and permissions, see Torq Roles and Scopes.

Use cases

Investigate indicators: Enrich and investigate IOCs, IPs, domains, users, and endpoints across Torq observables and cases, as well as the threat intelligence feeds and platforms you are integrated with. For example, check whether an indicator is linked to known threats, or look up DNS data for a domain.

Query and act on cases: Search cases and observables, break them down by criteria, and take action. For example, find cases matching specific criteria, assign them to an analyst, and send a Slack notification with case details.

Take response actions: Run the tools set up in your workspace to respond directly from a chat, such as adding an IP or domain to a blocklist, contacting a compromised user, or quarantining a user or endpoint. Available actions depend on the Socrates Tools you have configured.

FAQ

What permissions do I need for workspace-level investigations with Socrates?
The socrates.investigations.write scope to start or participate; socrates.investigations.read to view only.

Do I need Case Management to start a Socrates chat?
Yes. Socrates Investigator is available to Case Management customers.

Does Socrates store or share workspace data?
No. All data remains private within your workspace. Socrates processes context within the workspace and does not expose data beyond it.

Explore related resources

Did this answer your question?