TL;DR
- A real investigation is more than a query. It takes planning, analysis, pivots, and a conclusion.
- Vega Agentic Search turns one question into a complete threat hunt, start to finish.
- The agent builds an investigation plan, executes searches across all connected data, analyzes findings, pivots automatically, and produces an evidence-backed conclusion.
A hunt still comes down to this: a senior analyst, a hypothesis, and query after query by hand until the evidence adds up or the shift ends. Agentic Search takes that work off their plate. It's a purpose-built agent on Vega's Security Analytics Mesh (SAM) that turns one plain-language question into a complete, evidence-backed hunt. Threat hunting is the first job we've put it on. More of the SOC's workflows will follow.
Reaching the data was only half the job
For Vega, reaching the data was never the hard part. For years it was everyone else's problem: data sat in separate legacy SIEMs, data lakes, and cloud logs, and just getting to it meant ingestion projects and pivoting across consoles. Vega closed that gap. In the Post-SIEM era, reaching the data is solved. Every source is searchable in a single query, right where it lives, without ingestion or migration. But reaching it was only ever half the job. Turning it into an answer is the expensive part, and that still takes an expert who knows which questions to ask and how to read what comes back. Agentic Search does that part. Here's what it looks like.
It starts with a question, not a query
An analyst reads a threat-intel brief on a macOS "ClickFix" campaign that tricks a user into pasting a command into Terminal. The obvious question “are we affected?” used to mean pulling ~50 indicators out of the brief by hand and running dozens of queries across every log source. With Agentic Search, they paste the brief in and write one line:
hunt this brief.
No query. No syntax. The agent reads the brief itself, pulls all ~50 indicators, and plans the hunt.

The hunt begins as one natural-language prompt, not a query. The agent reads the brief and states its plan.
Your best hunter, scaled to the whole team
Vega's agent isn't a chatbot pointed at logs. It's a hunter, trained on how threat hunting actually runs. It gets sharper with every hunt, carrying what it learns from one investigation to the next, so the expertise compounds on the platform instead of walking out the door with your senior analyst.
So it runs the hunt itself, searching every connected source (secure web gateway, firewall, EDR, and beyond) and writing and running each query as it goes.

The agent extracts indicators and fires multiple searches across every source.
Nothing it claims that you can’t check
A general agent hands you a chat box. But a hunt has a shape: a hypothesis, queries, evidence, and pivots. Agentic Search is built around that flow.
Every query the agent runs shows up two ways: as a clickable step in the agent's reasoning, and as its own cell you can open beside it. Click a step and the panel jumps to that cell: the exact query, the exact results. You can open and check everything it claims.

The agent's reasoning on the left, its query cells on the right. Click any step to jump straight to the query and results behind it.
From a single indicator to the entire picture
The moment an indicator hits, the agent pivots by itself. It pulls the activity around that host and connection into a single timeline, reconstructing what happened across all your sources at once. The source-to-source chase that used to eat an analyst's afternoon now happens automatically.

One hit triggers an automatic pivot: the agent assembles a cross-source timeline of what happened.
A conclusion you can trust and act on
The agent closes with a structured conclusion: what it found and the concrete next steps. Every claim carries a link straight to the query that produced it. On the ClickFix brief, analysts using Agentic Search closed the investigation in under 8 minutes. The same hunt, run manually, takes the better part of a shift. An answer you can't check is one you can't act on. This one you can.

A structured conclusion: what it found and what to do next, with a link back to every query cell.
When the cost of asking drops from hours to minutes, you ask more. And the hunts you used to skip become the ones that catch the breach.
See Agentic Search run on your own data. Book a demo
Frequently Asked Questions
What is Vega Agentic Search?
Vega Agentic Search is a purpose-built security agent on the Security Analytics Mesh. It takes a plain-language question or threat brief, builds an investigation plan, executes searches across every connected data source, pivots automatically on findings, and delivers a structured, evidence-backed conclusion.
How is Agentic Search different from running queries manually?
A manual hunt requires an analyst to plan each step, write each query, and interpret results one source at a time. Agentic Search runs the entire investigation autonomously. Every query it executes is visible and clickable, so analysts can review the work, not redo it.
Can I audit what the agent actually did?
Yes. Every step in the agent's reasoning links directly to the underlying query and results. Nothing is summarized away. If the agent found an indicator and pivoted, you can open the exact cell, see the exact query, and verify the exact output that drove the decision.


.png)
.png)
.png)
