investigate
Investigate any security topic—CVEs, threat actors, assets, endpoint events, or vulnerabilities—to assess exposure and gain actionable intelligence.
Instructions
[Investigation] Deep-dive investigation on any security topic — CVEs, threat actors, assets, endpoint events, vulnerability intelligence. @slow
USE WHEN: "tell me about CVE-2024-3400", "are we exposed to Lazarus Group?", "investigate this IP", "what ransomware vulns exist?", "deep dive on Log4Shell", "what's happening on 10.0.0.1?"
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tag | No | filter affected assets by tag | |
| days | No | lookback window for events/vulns (default 7) | |
| depth | No | "quick" (~10s, 2 sources) | "standard" (~20s, 4 sources) | "deep" (up to ~4 min on cold caches, all sources + summary) | standard |
| limit | No | max results per data source (default 20) | |
| scope | No | "all" | "vulns" | "threats" | "assets" | "edr" | "fim" | all |
| detail | No | "summary" | "standard" | "detailed" (includes raw aggregator output) | standard |
| target | Yes | CVE ID, threat actor/nation, hostname, IP address, or free-text topic | |
| audience | No | "technical" | "management" | "executive" (for deep investigation summaries) | technical |
| software | No | software name filter for KB search (e.g. "Apache", "OpenSSL") | |
| asset_group | No | filter by asset group | |
| threat_type | No | RTI filter — Ransomware, Active_Attacks, Cisa_Known_Exploited_Vulns, etc. | |
| prior_context | No | summary from a previous investigation for chaining |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |