QUERY WORKERS

Your security team, multiplied.

Query Workers automate security operations across every source in the mesh. Engineered with evidence and transparency you can verify.

Query Workers

Mission-specific agents with complete coverage and context.

Analysts spend more time pulling data than analyzing it. Each Worker automates a security operations job across every connected source, builds the evidence chain, and flags what it couldn’t verify. Your analysts make the call.

INVESTIGATE

Every case, worked to a verdict.

A Worker triages the alert, enriches it across every source in the mesh, and recommends a disposition. Your analysts review the work instead of rebuilding it.

HUNT

Test a hypothesis against your real data.

Drop in a threat advisory, a hypothesis, or a MITRE technique. The Worker searches every source and chases the leads across identity, endpoint, and cloud, without you switching tools.

DETECT

Find what your detections are missing.

The Worker finds what your current detections miss and writes back a coverage-gap report: proposed rules, and the data each one fires on.

Use Workers in
Query UI · Claude Code plugin
Integrate with
MCP tools · API
Notifications
Slack · Teams · Jira · more
Query Workers in action

Automated from first query
to final recommendation.

A proactive hunt, an identity assessment, overnight alert triage at scale, and a cross-investigation catch. Engineered to keep your analysts in the loop.

Malicious · No detection fired CASE-2026-0515-E
HUNT8.9 / 10 · HIGH

Cross-Boundary Living-off-the-Land Hunt

A 7-day hypothesis-driven hunt across endpoint, identity, cloud, and network. Found WMI execution, rundll32 DLL proxying, and cron task abuse running below the detection threshold across Windows and Linux. Three techniques active, no SIEM rule had fired.

21
queries
9
hosts
36m
Agent time
24-40h
Effort saved
edr.crowdstrikeidentity.oktacloud.cloudtrailnetwork.zeek
Artifacts shipped · hunt pack
report.mdqueries.mdhypothesis.mdfindings.mddetections.md
Read the hunt →
Malicious · Confirmed CASE-2026-0317-B
CRITICALHIGH

120 alerts → 5 confirmed threats + cross-environment spread

120 overnight alerts. One intrusion. 5 compromised users, plus a cloud EC2 host that corporate-only triage would miss every time.

20
queries
50+
hosts
23m
Agent time
6-10h
Effort saved
edr.crowdstrikeidentity.oktacloud.aws
Artifacts shipped
report.mdqueries.mdiocs.mdreview.md
Read the work →
Suspicious · No alert fired CASE-2026-0317-C
PROACTIVEESCALATED · DAY 8

Finding the insider risk no alert would catch

A service account logging in through Chrome from a regular user’s laptop. Every day. No SIEM rule fires on this. We tested 8 identity techniques across Okta and Entra, found it, and tracked it unremediated for 8 days.

27
queries/run
8
patterns
3 runs
Agent time
12-18h
Effort saved
identity.oktaidentity.entradlpnetwork.zeek
Artifacts shipped · ITDR pack
report.mdqueries.mdiocs.mdscorecard.mdidentity-data-map.md
Read the work →
Malicious · Upgraded in review CASE-2026-0313-D
3.64.0HIGH

Two routine alerts → confirmed 57-host C2 compromise

Two more phishing victims. Routine, until the review pulled up a 3-day-old C2 investigation and found both hosts in the 57-host backdoor, with the prior fix orders sitting unactioned.

38
queries
2
investigations
27m
Agent time
the case
Effort saved
emailedr.crowdstrikeidentity.oktanetwork.zeek
Artifacts shipped · plus cross-investigation link
report.mdqueries.mdiocs.mdreview.md
Read the work →

Every Worker investigation produces the same artifact pack:
findings, every FSQL query executed, every source queried, gaps the agent couldn’t close, and confidence per finding.

Query Workers in 2 minutes
Query Workers running on the mesh changes what my team can actually do. Issues that used to take hours to investigate are pre-packaged in minutes, and my analysts are making decisions instead of chasing data.
Rudy Ristich · CISO & CPO, Avant
Beyond investigation

AI-powered security operations.

Query Workers let you go broader and deeper than you’ve ever had the capacity to go.

Each Worker automates a specific job with specialist skills, from access reviews to vulnerability prioritization to threat hunting and more.

Threat Hunting

Drop in a hypothesis or a threat advisory. The Worker searches every source, chases the leads, and writes back detections for what it finds.

Identity Threat Detection & Response

Sweeps 8 identity attack patterns across every connected identity provider in a single pass. One scorecard, not eight vendor consoles.

Vulnerability Prioritization

Cross-references findings with exploit intelligence, asset criticality, and network exposure. Output is a ranked remediation plan, not a CVSS spreadsheet.

Living-off-the-Land Detection

Correlates endpoint process execution with cloud API calls and identity changes in the same time window. Finds the cross-boundary chains EDR misses.

Access Review

Collects entitlements across every identity source, flags orphaned accounts and excessive privileges, and produces an audit-ready review package.

Cloud Configuration Audit

Multi-cloud posture assessment normalized to CIS benchmarks. Correlates misconfiguration with vulnerability and identity exposure for compound risk scoring.

Third-Party Risk Monitoring

Maps every OAuth grant, API token, and service account representing a vendor trust boundary. Technical evidence, not questionnaire responses.

Supply Chain Risk

Maps every way external code and entities enter your environment: dependencies, CI/CD pipelines, vendor integrations, and infrastructure trust.

The Query security data mesh

AI is only as good as
the data beneath it.

Workers are built on the mesh, which connects your sources, normalizes every field into a common model, and gives them complete, structured access to your environment.

Coverage.Security operations means combining data from many sources. Workers query and reason across every source connected to the mesh, and every source you add compounds what every Worker can do. No ingestion or data movement required.
Structure.The mesh resolves every field into a common data model before the AI touches it. actor.alternateId in Okta and userPrincipalName in Entra are the same entity. Workers are more accurate and more efficient as a result.
Context.Workers source answers from logs and other data types, all normalized to an entity and event-centric data model. A suspicious user isn’t just a row in a table. It’s identity and access events, endpoint activity, network connections, department, role, and more — derived from every connected source.

Any agent can reach your data. The mesh is why Workers understand it.

Trust architecture

Engineered to earn trust.

Query Workers use AI, and AI can be wrong. These are the design principles and implementation decisions that shape how Workers operate.

Authority

Workers investigate. Analysts act.

Workers produce findings, recommendations, and a complete evidence chain. They don’t automate containment, remediation, or case closure. Your analysts decide what happens next.

Authority

Every disposition is a recommendation

Workers output RECOMMEND ESCALATION, never INCIDENT DECLARED. Dispositions are proposals. Your analysts review the evidence, apply judgment, and make the call.

Evidence

Show the work

Every investigation produces a complete FSQL query chain, evidence blocks with source attribution, and a report that documents what Workers found and what they couldn’t reach. On high-severity cases, an independent review audits the investigation itself. Not a summary. The queries, the data, the reasoning.

Evidence

Absence is a finding

When a Worker queries a source and finds nothing, that’s documented as evidence, not omitted from the report. “No authentication events for this user in the investigation window” is a finding. Gaps in data coverage are surfaced, not hidden. Every investigation accounts for what was searched, what was found, and what wasn’t there.

Calibration

Multi-state classification

Workers never classify cases as simply malicious or benign. Every skill outputs graduated verdicts with explicit confidence levels — Confirmed, Suspicious, Benign, Insufficient Data. When the data doesn’t support a call, a Worker says so.

Calibration

Confidence is load-bearing

Confidence scores aren’t decorative. They change what Workers do. A severity score caps at Medium when the only input is a vendor label. Low-confidence findings trigger deeper investigation, not faster disposition. Confidence determines the path, not just the output.

See what your team can do
with Query Workers.