Product overview
What is AI Investigator?
AI Investigator is an early-access capability within Stellar Cyber's Open XDR platform for security analysts and SOC teams. It lets analysts ask questions about security data in plain English instead of writing specialized query syntax. The system translates the request into a structured, executable security query and returns contextualized results with suggested next steps and automated pivots.
The product investigates telemetry across on-premises and cloud sources in one view. The website lists network traffic, Sysmon and Windows event logs, Microsoft Entra ID sign-ins, Office 365 audit trails, alerts from supported EDR products, and firewall logs. Multi-tenant deployments are supported with access controls based on each user's role and scope.
Follow-up questions add to a saved Notebook, preserving investigation context and an audit trail. Results include editable queries, time-range controls, and interactive visualizations. Stellar Cyber also states that security records remain in the customer's environment; only query structure and schema are sent to the AI model, not personally identifiable information.
How to Use AI Investigator
- Ask a specific security question in plain English, including a time range, user, host, or IP when relevant.
- Let AI Investigator translate the request into a structured query and run it against available telemetry.
- Review the returned context, visualizations, editable query, and suggested next steps.
- Ask clear follow-up questions to narrow the result or pivot to related activity.
- Use the saved Notebook to retain the investigation sequence and audit history.
Core Features
- Natural-language threat hunting: Accepts plain-English security questions without requiring query syntax.
- Structured query generation: Produces and executes editable queries tailored to the analyst's request.
- Hybrid telemetry access: Investigates supported on-premises and cloud security sources in one view.
- Context-preserving Notebook: Saves prompts, follow-ups, and investigation history.
- Guided investigation flows: Provides contextual results, automated pivots, and suggested next steps.
- Tenant-aware controls: Applies user role and scope restrictions in multi-tenant environments.
Use Cases
- Alert investigation: Analysts ask questions about an alert and pivot through related users, hosts, IPs, or events.
- Threat hunting: SOC teams search for suspicious behavior across network, endpoint, identity, cloud, and firewall data.
- Root-cause analysis: Investigators retain context across follow-up questions while tracing an incident.
- MSSP operations: Multi-tenant teams investigate customer environments within role- and scope-based boundaries.
Frequently Asked Questions
Is AI Investigator part of Stellar Cyber Open XDR?
Yes. The website describes it as an early-access feature within the Open XDR platform.
Does it require security query syntax?
No. Analysts ask questions in plain English, and AI Investigator generates the structured query.
Which data sources can it investigate?
The website lists network traffic, Windows and Sysmon logs, Entra ID sign-ins, Office 365 audit trails, supported EDR alerts, firewall logs, and more.
Does security data leave the Stellar Cyber environment?
Stellar Cyber states that security records stay local and only query structure and schema are sent to the AI model.

