Skip to main content

Use Case: Post-Verdict Investigation with AI Agents

Learn how to investigate security alerts after Auto Triage verdict, confirm compromise, and map blast radius using AI Agents.

Scenario

A Security Operations Center (SOC) team uses Auto Triage to process incoming alerts and reduce noise. When Auto Triage produces a verdict on a true positive, analysts still need to confirm the finding in raw data, understand who the affected entity is, contact the user if needed, and determine how far the compromise can spread. Each of these steps requires pivoting between tools, and the results vary depending on who runs the investigation.

To address this, the team built a post-verdict workflow powered by three AI Agents: Splunk Investigation Agent, Interview Agent, and Hunt-and-Map Agent. Each agent handles a distinct phase of the investigation, passing findings to the next. The result is a coordinated pipeline that picks up where Auto Triage left off and delivers a complete investigation in a single workflow run.

Challenge

The SOC team needed to:

  • Bridge the gap between an Auto Triage verdict and a full investigation without manual pivoting between tools.

  • Confirm compromise with specific, evidence-backed conclusions drawn from raw Splunk data.

  • Identify post-compromise activity to scope the threat before it spreads.

  • Contact affected users to gather context and determine whether flagged activity was intentional.

  • Map every entity the compromise can reach and translate that into business impact an incident lead can act on.

Prerequisites

Before implementing this workflow, configure the following:

  • Splunk integration: Required for the Splunk Investigation Agent and Hunt-and-Map Agent. The integration must have access to the indexes relevant to the environment, including authentication logs, EDR data, firewall and proxy traffic, cloud audit logs, and directory events.

  • Slack integration: Required for the Interview Agent to contact end users and analysts with multiple-choice and open-text questions.

  • Context Graph: Required for the Hunt-and-Map Agent. At least one context connector must be configured and actively ingesting data. The agent uses the graph to map entity connections, ownership, group memberships, and reachable applications.

  • Case Management: Required for the Interview Agent to log interview transcripts, add tags, and escalate severity. The relevant case must exist before the agent runs.

  • Alert and case payload: The workflow must pass a structured alert or incident payload to each agent at runtime, including the anchor entity, detection details, timestamps, and case ID.

  • Initial entity input: Required for the Hunt-and-Map Agent. The workflow must supply the initial Context Graph entity used to seed the first query.

  • Tool descriptions: Each tool added to an agent requires a clear, natural-language description that explains what the tool does, when to use it, and what it returns. Accurate descriptions reduce tool selection errors and improve investigation consistency.

Workflow overview

This workflow automates post-verdict investigation of security alerts using three coordinated AI Agents:

  • Splunk Investigation Agent: Queries the Splunk environment to confirm compromise with specific evidence and identify one post-compromise activity, such as data exfiltration, lateral movement, privilege escalation, or a persistence action.

  • Interview Agent: Contacts the affected end user or analyst via Slack to gather context, determine whether the flagged activity was intentional, and log the full interview transcript to the case.

  • Hunt-and-Map Agent: Queries Splunk and the Context Graph in a single coordinated pass to confirm compromise and map the full blast radius, delivering a structured investigation report with verdict, evidence, reachable entities, and business impact.

Set up the workflow trigger

Add a trigger based on a verdict received from Auto Triage. When Auto Triage produces a verdict on an incoming alert, this workflow starts automatically, passing the alert payload and anchor entity to the agents for deeper investigation.

Create and configure AI Agents

All three agents are created and managed on the AI Agents page. To open it, go to Build > AI Agents.

Each agent starts in Draft state after creation. Draft agents are not available to workflows or other platform components until published. After configuring and testing each agent, click Save, then Publish to make it available.

Configure Splunk Investigation Agent

The Splunk Investigation Agent investigates security alerts by discovering and querying data directly in a Splunk environment. Its objective on every investigation is twofold: establish concrete evidence of compromise, then confirm at least one post-compromise activity. Once both are confirmed, it stops and delivers a structured verdict.

Instructions

  • Role: Security investigation agent operating inside a Torq workflow. Answers security questions by discovering and querying data in a Splunk environment.

  • Supported scenario: Triage incoming alerts by confirming compromise and identifying one post-compromise activity (data exfiltration, lateral movement, privilege escalation, or persistence actions).

  • Behavior guidelines:

    • Always begin by calling Get active indexes to discover available data sources.

    • Map alert entities to relevant index and sourcetype pairs before querying.

    • Confirm compromise first, then pivot to confirm one post-compromise activity.

    • Stop investigating the moment both objectives are satisfied. Do not continue querying.

    • Always include time bounds in every query.

    • Never guess field names. Use Get a Splunk field summary to verify field formats before querying.

    • Deliver a structured report with verdict, evidence table, post-compromise activity, investigation reasoning, and recommended next steps.

Setup

Field

Value

Name

Splunk Investigation Agent

Subscription

Torq

AI model

Select from available models

Tools

Search for active indexes, Get a Splunk field summary, Run a Splunk Query.

Configure Interview Agent

The Interview Agent contacts end users or analysts about security alerts, collects their responses, and logs the outcome to the case. It follows a structured conversation: introduce the alert, ask whether the user recognizes the activity, follow up for context, and escalate if the answers are evasive, contradictory, or the user is unreachable.

Instructions

  • Role: SOC Interview Agent. Contacts end users about security alerts, determines whether they recognize the flagged activity, and logs the full transcript to the case.

  • Supported scenario: Interview the affected user when an alert requires human context to confirm or dismiss. Escalate when denial, evasion, or unreachability criteria are met.

  • Behavior guidelines:

    • Open every conversation by identifying as the security team and explaining the alert in plain, non-technical language. Always include the relevant details: timestamp, location, resource name, or action flagged.

    • Follow immediately with a multiple-choice question asking whether the user recognizes the activity.

    • Ask one open-text follow-up based on the response: justification if they confirm, context if they deny, clarification if they are unsure.

    • Close with: "Is there anything else you'd like the security team to know about this?"

    • Add the full transcript to the case as a note at the end of every conversation, regardless of outcome.

    • Escalate if the user denies and has no explanation, answers are contradictory or evasive, the incident poses an organizational risk, or the user is unreachable. Include the escalation reason in the case note.

    • Never expose raw logs, detection logic, or internal policy names.

    • Never ask the user what they would like to do. Run the interview and log the result.

Setup

Field

Value

Name

Interview Agent

Subscription

Torq

AI model

Select from available models

Tools

Ask User a Multiple Choice Question in Slack, Ask User an Open Text Question in Slack, Add a new note to a case, Add tags to an existing case, Change case severity.

Configure Hunt-and-Map Agent

The Hunt-and-Map Agent performs compromise triage and blast radius mapping in a single pass. It queries Splunk to confirm compromise and identify post-compromise activity, while simultaneously walking the Context Graph to map every entity the compromise can reach and what each one means for the business. The two data sources feed each other: the graph supplies pivot values for Splunk queries, and Splunk findings direct the next graph expansion. The agent delivers a structured Markdown report ready to drop into a ticket or incident channel.

Instructions

  • Role: Security investigation agent operating inside a Torq workflow. Confirms compromise via Splunk and maps blast radius via the Context Graph in a single coordinated pass.

  • Supported scenario: Triage a security alert involving an identity or device anchor. Confirm compromise with specific Splunk evidence, confirm one post-compromise activity, and produce a complete map of reachable accounts, devices, applications, groups, and their business significance.

  • Behavior guidelines:

    • Begin every investigation by running the provided Context Graph query exactly once to establish the anchor entity and its first-hop connections. Extract all pivot values (usernames, logins, hostnames, IPs) for use in Splunk.

    • Alternate between Splunk calls (building the compromise verdict) and Context Graph expansions (mapping connections and business significance) until the verdict is settled and the graph mapping is thorough, or the 18-call budget is reached.

    • Stop Splunk querying once compromise and one post-compromise activity are confirmed. Continue graph mapping until every significant connection is enumerated.

    • Expand applications, security and privileged groups, and owned devices to second hop. Never expand accounts, distribution groups, oversized groups (over 200 members), the manager, or subordinates beyond first hop. Never take a third hop. Never re-expand the anchor or the same entity twice.

    • Report bundle nodes by count only. Never fabricate members.

    • If the graph returns truncated: true, expand further to fill the neighborhood within the remaining budget.

    • Always include time bounds in every Splunk query. Never guess field names, verify with Get a Splunk field summary first.

    • The final output is a Markdown report only, beginning with # Entity Compromise. No preamble, no trailing text.

    • Report affirmatively from what the tools returned. Never state that something is missing, unavailable, or not found.

Setup

Field

Value

Name

Hunt-and-Map Agent

Subscription

Torq

AI model

Select from available models

Tools

Query Context Graph Neighbors, Search for active indexes, Get a Splunk field summary, Run a Splunk Query.

Add agents to the workflow

Once an agent is published, it appears in the Published Agents panel in the workflow builder. To add an agent to the workflow:

  1. Open the workflow: Go to Build > Workflows and open the workflow.

  2. Locate the agent: In the step panel, go to AI Agents, select the agent from the Published Agents list, and drag it onto the canvas.

  3. Repeat: Add each of the three agents in sequence: Splunk Investigation Agent, Interview Agent, and Hunt-and-Map Agent.

Review the execution

After the workflow runs, open the Log tab in the agent to inspect the execution in detail.

The Activity log lists all past executions with date, duration, and the user or component that triggered each run. Click any entry to open its Action flow.

The Action flow provides a step-by-step breakdown of a single execution:

  • Input: The instructions and parameters passed to the agent at the start of execution.

  • Reasoning: The agent's internal decision-making, including what it assessed and why it chose each action.

  • Step: The inputs and outputs of each tool call.

  • Output: The final result returned by the agent.

The Action flow also supports live streaming during execution. Open the view while an agent is running to watch decisions, tool calls, and outputs in real time.

Outcome

This workflow produces:

  • Faster time from Auto Triage verdict to confirmed investigation, without manual tool pivoting.

  • Compromise verdicts backed by specific Splunk evidence, building on the verdict Auto Triage already produced.

  • A mapped blast radius showing every reachable account, device, application, and group, with business impact stated in plain language for incident leads.

  • User context gathered directly from the affected employee, reducing false positive escalations.

  • A structured, auditable investigation report ready to drop into a ticket or incident channel.

  • Recommended next steps prioritized by what the graph and Splunk evidence surfaced.

Did this answer your question?