CTP247PRE-LAUNCH

Coming soon.

CTP247 is cyber threat protection that never clocks out — autonomous agents watching your attack surface, brand, and the dark web 24/7. Leave your email and we'll let you know when it's live.

One email at launch. No newsletters, no marketing dripfeed.

CTP247
All agents

Investigation Agent

The agent that asks the questions a junior analyst forgets.

Iterates through actor → asset → IOC → prior cases. Shows its work.

When an alert needs more than a glance, the Investigation agent picks it up. Up to six iterations, each a tool call against your live data — alert lookups, IOC pivots, actor lookups, related-alert search, asset-exposure checks — ending with a final assessment that cites every decision. The dashboard shows the full trace. So can your auditor.

Iteration trace

run · 019d-…-aa28
iter 1lookup_alert(alert_id="ALERT-9817")
Read the alert before anything else.
Critical · C2 indicator 185.101.94.215 · source=feodo_tracker
iter 2search_iocs(value="185.101.94.215")
How widely is this indicator corroborated?
Seen in 3 feeds · first_seen 22d ago · tags: c2, botnet
iter 3lookup_threat_actor(indicator="185.101.94.215")
Does it map to a known actor?
Match: APT28 (Fancy Bear) · GRU Unit 26165 · risk 95
iter 4related_alerts(same IOC cluster, 90d)
Has this cluster touched us before?
2 prior alerts · linked case CASE-018 · status=remediated

Final assessment

Criticalconf 91%

APT28-linked C2 indicator corroborated across three feeds. Two prior alerts touch the same IOC cluster and CASE-018 covered the same TTP — recommend reopening it, not duplicating.

Re-open CASE-018 (don't duplicate)
Block 185.101.94.215 at egress
Hunt 10.4.18.99 for T1078 evidence

Inputs

  • A single alert (with linked IOCs and matched entities)
  • Your asset inventory and DNS/log data
  • Org-wide IOC and case history
  • Threat-actor catalogue with TTP coverage

Outputs

  • Final assessment (severity, confidence, attribution)
  • Tool-call trace per iteration (auditable, JSON)
  • Linked findings ready to promote into a case
  • Recommended next steps with citations

Runtime

  • Iterations≤ 6 tool calls
  • Tools available5 read-only
  • Plan-then-actoptional gate
  • Cost ceilingper-run cap
  • Traceevery step persisted
6
Max tool calls before forced finalise
100%
Tool calls logged with thought, args, and result
5
Read-only tools — the agent can look, never touch