From THOUSANDS of findings to just a FEW that MATTER T12's Security Analyst Agent will: 1. Perform an initial triage of your most critical *Cloud* security findings 2. Prioritize the few issues that matter most 3. Assist your team through chat during investigation and remediation So that your team: • Stop drowning in thousands of critical findings • Eliminate repetitive initial triage work • Always have a small, manageable set of the most important security issues to work on next
I was building a standard Cloud Security CNAPP platform (T12) but then realized after speaking to my users that the industry does not need another scanner that produces thousands of findings; instead what is needed is something that prioritizes the next few most critical findings to work on.
This way instead of getting overwhelmed by thousands of critical findings, security teams can focus on the next few (5 - 10) most critical findings to work on with initial investigation already done by AI.
And this is exactly what this agent does.
How it works ------------- The agent sits on top of T12’s core cloud security stack and continuously analyzes findings across: • Cloud Infrastructure Scanning (CSPM) • Kubernetes Cluster Scanning (KSPM) • IAM Monitoring (CIEM) • Cloud Runtime Monitoring (CWPP) • Application Runtime Monitoring / Detection (CDR)
It then enriches and evaluates those findings using: • Threat Intelligence • Triage Context • Risk Factors • Security Graphs • Internal Risk Scoring
Agent Output -------------- Then it provides the following outputs: • Detailed Analysis Report: This is of the same quality as an analysis done by a senior cloud security engineer • Prioritized Findings: the next *few* most important findings your team should work on. • Remediation chat: AI chat consisting of all the context from the analysis. Use this chat when actually remediating the issue. Ask clarifying questions, remediating instructions, generate terraform code etc
I was building a standard Cloud Security CNAPP platform (T12) but then realized after speaking to my users that the industry does not need another scanner that produces thousands of findings; instead what is needed is something that prioritizes the next few most critical findings to work on.
This way instead of getting overwhelmed by thousands of critical findings, security teams can focus on the next few (5 - 10) most critical findings to work on with initial investigation already done by AI.
And this is exactly what this agent does.
How it works
-------------
The agent sits on top of T12’s core cloud security stack and continuously analyzes findings across:
• Cloud Infrastructure Scanning (CSPM)
• Kubernetes Cluster Scanning (KSPM)
• IAM Monitoring (CIEM)
• Cloud Runtime Monitoring (CWPP)
• Application Runtime Monitoring / Detection (CDR)
It then enriches and evaluates those findings using:
• Threat Intelligence
• Triage Context
• Risk Factors
• Security Graphs
• Internal Risk Scoring
Agent Output
--------------
Then it provides the following outputs:
• Detailed Analysis Report: This is of the same quality as an analysis done by a senior cloud security engineer
• Prioritized Findings: the next *few* most important findings your team should work on.
• Remediation chat: AI chat consisting of all the context from the analysis. Use this chat when actually remediating the issue. Ask clarifying questions, remediating instructions, generate terraform code etc