Overview
Investigator lets you investigate any signal across your workspace without opening a case. Start from an alert, an observable, or a question. Investigator draws on existing cases and observables for context, and takes action across your tech stack using Socrates Tools.
For investigation inside a case, see Socrates: Transform Case Investigations.
Prerequisites
Case Management is enabled for your workspace.
Your role includes the required scopes:
socrates.investigations.read: List and read Investigator chats.socrates.investigations.write: Start and participate in Investigator chats. Available to all roles except Viewer roles.
How to use
For chat access, collaborators, and the chat list, see Socrates: Chat with AI Agents.
Start an investigation
Open Socrates: Click Socrates at the top of the left sidebar.
Select the agent: Select Investigator from the agent picker.
Describe what you need: Enter the question or task in the composer. Name the systems, time range, and entities involved.
Send the message: Click the send arrow.
To start from a common task instead, click a suggested prompt under the Response, Threat hunting, or SOC posture categories.
Specify tools for a request
Investigator selects its own tools. To point it at a specific one, add the tool to the message.
Open the tool menu: Type
/in the composer.Review the options: Hover over a tool to read its description.
Select the tools: Select each tool you want. Selected tools appear as chips in the message.
Send the message.
Selecting a tool does not guarantee Investigator uses it. Investigator may choose a different or additional tool based on the request.
Investigator uses only existing, enabled tools. It cannot run built-in tools in restricted cases. To create, edit, or disable tools, see Socrates Tools: Empower Socrates to Take Action on Cases.
Use cases
Investigate indicators: Enrich IOCs, IPs, domains, users, and endpoints across Torq observables and cases, as well as your connected threat intelligence sources. For example, check whether an indicator is linked to known threats, or look up DNS data for a domain.
Query and act on cases: Search cases and observables, break them down by criteria, and act on the results. For example, find cases matching specific criteria, assign them to an analyst, and send a Slack notification with the case details.
Take response actions: Run the tools configured in your workspace directly from a chat. For example, add an IP or domain to a blocklist, contact a compromised user, or quarantine a user or endpoint. Available actions depend on the Socrates Tools configured.
Monitoring
Every Investigator message appears in Monitor > Activity Log under the Socrates conversation message event source. Workflows run from the chat appear with Torq Socrates as the actor. To find the messages that ran a specific tool, use Search in payloads.
Investigator's actions are also recorded in the Audit Log, attributed to Socrates acting on behalf of the user who requested them. The requesting user appears under requesting_actor. To retain audit records, set up an export in Settings > Log Export with Audit as the log type. See Socrates Auditing: Monitor Your AI Analyst.
FAQ
How is Investigator different from Socrates in a case?
Investigator works across your whole workspace from the Socrates page in the left sidebar. Socrates in a case works within that case's Socrates tab, scoped to that case. See Socrates: Transform Case Investigations.
How does Torq handle the data Investigator works with?
Investigator is powered by third-party AI models and is subject to the same guardrails as Torq's other AI capabilities. See AI in Torq.
Additional documentation
Socrates: Chat with AI Agents: Select an agent, manage chats, and control access.
Socrates Tools: Empower Socrates to Take Action on Cases: Create the tools Investigator can run.
Socrates Auditing: Monitor Your AI Analyst: See how Socrates actions appear in the Audit Log.
Socrates Builder: Build Workflows and AI Agents: Build and maintain workflows and AI Agents through conversation.


