Gravwell adds five AI agents that gather their own investigation context
Security data platform company Gravwell Inc. today released Gravwell 5.10, an update that puts five artificial intelligence agents inside a customer’s deployment. The agents collect the context an investigation needs on their own. A Model Context Protocol server gets them there. An agent can pull live telemetry, detections, system state and saved searches, then call the […] The post Gravwell adds…
Gravwell Inc., a security data platform company, has released an update to its software, Gravwell 5.10, incorporating five artificial intelligence agents designed to independently gather investigation context within a customer's deployment. According to Gravwell, these agents utilize the Model Context Protocol server to access live telemetry, detections, system state, and saved searches. By leveraging the platform's own tools, the agents can run queries and collect evidence until it becomes valuable for analysts.
Three of the five AI agents collaborate with analysts. The Case Agent continually works with an investigation, from its inception, generating and validating Gravwell queries, running them, and recommending the next pivot. It operates in read-only mode unless instructed to save information. The Alert Triage Agent intervenes between a detection and the receiving analyst, generating supporting queries and preparing an initial report, avoiding alerts without context from reaching analysts.
The Daily Summary Agent handles overnight tasks, analyzing the previous day's telemetry and supplying analysts with queries to run against its findings.
The remaining two agents serve administrators. The Admin Agent responds to configuration queries about deployments, including ingesters, access controls, storage, and replication. The Audit Agent performs a read-only review of automations, alerts, query content, and data flows, identifying issues such as stalled searches, duplicate extractors, and dead data feeds, compiling them into a prioritized report.
All five agents operate within a controlled environment defined by Gravwell, specifying the tools, portions of the Model Context Protocol environment, actions, and procedures each agent can access.
Gravwell emphasizes that this update offers a controlled approach to AI autonomy, ensuring security teams can benefit from more autonomy without exposing their systems to unrestricted AI access. The preview kit, featuring these agents, is available across all Gravwell editions, including the free Community Edition. Founded in 2017, Gravwell replaces legacy security information and event management systems, ingesting data in full fidelity and structuring it only at query time.
The company raised $15.4 million in its Series A round led by Bear Capital in October last year, with participation from Gula Tech Adventures Inc., Next Frontier Capital, and Kickstart.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.