Gravwell Launches Environment-Aware AI Agents for Security Operations

Gravwell has launched a new set of environment-aware AI agents designed to help security teams investigate alerts, hunt threats and manage security infrastructure without giving AI unrestricted control over the environment.

Introduced with Gravwell 5.10, the agents can gather context directly from a customer’s deployment, including live telemetry, searches, detections, system state, flows and playbooks. This allows them to investigate activity and collect supporting evidence using information from the actual security environment rather than relying solely on preassembled context from individual alerts or cases.

The release targets a persistent challenge for security operations teams: analysts are often presented with alerts that still require significant manual investigation before they can determine what happened, how serious it is and what to do next.

Gravwell’s Alert Triage Agent is designed to perform some of that initial work automatically, running supporting queries and gathering relevant context before delivering an investigation report to an analyst. Its Case Agent works alongside analysts and threat hunters to write queries, interpret results and recommend the next investigative pivot while maintaining context throughout an investigation.

The company has also introduced agents focused on security platform operations. The Admin Agent can answer questions about deployment configuration and platform health, while the Audit Agent checks automations, alerts, queries, infrastructure and data flows for issues including stalled searches, unused alerts, missing ingesters and dead data feeds.

A Daily Summary Agent reviews telemetry from the previous day to identify activity that may require additional investigation and provides queries analysts can use to explore its findings.

Adding Guardrails to Agentic Security

As security teams experiment with increasingly autonomous AI, Gravwell is also emphasizing controls around what its agents can access and do.

The agents are delivered through the company’s AI Agent Preview kit, with predefined tools, permissions and workflows governing their behavior. Gravwell 5.10 also provides an in-product view of agent workflows, allowing users to see what information an agent accessed, which tools it used and the steps it took to reach a conclusion.

“Autonomy without context or boundaries can create more problems than it solves,” said Corey Thuen, CEO and co-founder of Gravwell. “Gravwell agents can gather the context they need from the customer’s actual environment while operating within defined tools, permissions and procedures.”

Rather than removing analysts from the process, the approach is designed to automate repetitive evidence gathering, initial analysis and platform checks while leaving decisions requiring human judgment with security teams.

The AI Agent Preview kit is available across Gravwell editions, including its free Community Edition.

Join our LinkedIn group Information Security Community!

No posts to display