Where It Starts
You launch the wizard from the Alerts tab:From one alert
Use Investigate / Enrich on a single detection to investigate it on its
own.
From many alerts
Multi-select a cluster and use bulk investigate to open one investigation
across all of them.
What the Wizard Prepares
Before anything reaches the AI, the wizard assembles the investigation:1
Extracts indicators
It reads the selected alerts and pulls out the indicators of compromise —
IPs, domains, hashes, URLs, users, and hosts.
2
Attaches relevant context
It gathers related documents and reference material so the agent has the
background it needs.
3
Selects the assets in play
It picks the devices and integrations connected to the detection, so the
investigation can reach the right hosts and tools.
4
Composes a structured prompt
It writes a clear, SOC-shaped investigation prompt from everything it
gathered — no blank page to fill in.
What Happens Next
The composed investigation is handed to Centurion’s SOC variant in the chat. From there it runs like any other conversation: the orchestrator coordinates specialists — Orion to enrich the indicators, Perseus to inspect or act on an affected host — and you watch the reasoning and tool calls stream in live.Centurion, in SOC mode
How the orchestrator runs a detection-and-response investigation end to end.
The wizard gets an investigation moving fast, but it doesn’t act on your
environment by itself. Any response — isolating a host, blocking an indicator —
is proposed in chat for you to approve. See
AI proposes, you approve.