After activity

Find the signal in your AI logs. Follow every action.

Search agent sessions, tool calls, policy decisions, and logs from agents, gateways, and model providers to reconstruct incidents and investigate suspicious behaviour.

Hunt
Hunt / AI activity
Huntsecret_access AND destination:not_approved
14 related eventssession_8fa2
  1. Component loaded

    deploy-helper / v2.4.1

  2. Secret file requested

    .env.production

  3. Outbound action blocked

    Destination did not match policy

Ask questions across the full agent activity trail.

Follow suspicious behaviour across sessions, users, agents, tools, components, and policy decisions while the original evidence stays attached.

01

Search the whole AI trail

Query sessions, tool calls, commands, file access, network destinations, approvals, and blocks from one investigation surface.

02

Explain why the action happened

Move from a runtime event to the user, agent, component, matched policy, approval, and outcome without rebuilding the evidence by hand.

03

Reconstruct the incident

Turn related activity into a defensible timeline that analysts can investigate, share, and carry into their response workflow.

From suspicious activity to an investigation-ready timeline.

  1. 01Search

    Start with an identity, session, component, command, destination, policy decision, or alert.

  2. 02Pivot

    Follow the relationships across agents, tools, repositories, gateways, and model activity.

  3. 03Explain

    Keep the original rule, component risk, approval, and runtime evidence with each event.

  4. 04Respond

    Build the investigation timeline and carry the findings into existing security operations.

Hunt / AI activity
Huntsecret_access AND destination:not_approved
14 related eventssession_8fa2
  1. Component loaded

    deploy-helper / v2.4.1

  2. Secret file requested

    .env.production

  3. Outbound action blocked

    Destination did not match policy

Trace the action back to its origin.

A suspicious outbound action becomes more useful when the analyst can see which component was loaded, who approved the session, which rule matched, and what happened next.

  • Session and cross-session timelines
  • Component and runtime evidence in one view
  • Identity, ownership, and approval details
  • Searchable policy outcomes and exceptions

Start investigations with the evidence already assembled.

AI-native search

Search agent security entities and actions directly, with raw fields available for validation.

Cross-agent pivots

Follow related activity across telemetry from coding agents, gateways, and model providers.

Session timelines

Order prompts, actions, approvals, policy decisions, and outcomes into one evidence trail.

Saved investigations

Preserve queries, pivots, notes, and evidence so analysts can resume and collaborate.

Detection handoff

Turn recurring investigative patterns into reusable detections and monitoring logic.

Response exports

Share investigation-ready evidence with SIEM, case management, and response workflows.

Reduce risk across every stage from one security platform.

Set policy, see coverage, stop high-risk actions, and investigate incidents across every agent and team from one operational view.

01Policy

Author once and adapt decisions to each control point.

02Identity

Connect users, agents, teams, tools, and repositories.

03Evidence

Keep the rule, relevant details, decision, and outcome together.

04Operations

Manage rollout, exceptions, approvals, and reporting.