Plain English
Ask a question in familiar language. Snowman turns plain-English search into archive text search.
Find sign-ins for [email protected] from a new locationPersistent agentic security · 24/7
Specialized AI systems continuously investigate, hunt, engineer detections, and prepare governed response across complete connected and retained security evidence.
High-level summary. The canonical nine-stage loop also includes planning, result inspection, reflection, memory, coordination, verification, and improvement.
Yeti runs a persistent workforce of specialized security agents that monitor telemetry, investigate threats, hunt across history, engineer detections, and coordinate governed response—24/7.Yeti’s specialized security agents monitor, investigate, hunt, and coordinate governed response—24/7.
Powered by Yeti’s security inference models, Dark Matter agentic runtime, lossless connected and retained evidence, long-running memory, purpose-built security tools, and controlled execution.
One investigation. Evidence across your environment.
Illustrative scenario and example IPs · Select a location for asset details · Geographic data: Natural Earth
01 / Agentic investigation
Yeti’s investigation agent continuously assembles related activity, tests competing explanations, identifies missing evidence, and builds a decision-ready case. From the first signal to the next action, its reasoning stays connected to inspectable evidence.
Bring identity, endpoint, network, and cloud activity into one investigation.
A persistent investigation agent selects bounded tools, examines related activity, compares explanations, and follows the evidence.
Review a timeline and linked records. See what is observed, what is inferred, and what is still unknown.
Your team reviews the findings and takes the next step through a governed response workflow.
The agent follows events across sources, keeps hypotheses and contradictions visible, and links every conclusion to the records that support it. Unknowns remain explicit instead of becoming claims.
The investigation agent plans, uses authorized tools, and assembles the case around the clock. Your team reviews its work and decides how to proceed, with permissions and approvals carried into response.
02 / Snowman · Agentic search & evidence
Snowman is the shared evidence workspace for people and Yeti agents. Agents search live and retained telemetry, pivot across normalized fields and original records, and explain what the evidence supports.
Security events and retained log history.
Ask in plain English, filter security fields, or search archive text.
user: [email protected]
source: 192.0.2.24A Yeti agent can inspect and explain the selected record while keeping the original evidence in context.
Ask a question in familiar language. Snowman turns plain-English search into archive text search.
Find sign-ins for [email protected] from a new locationSearch normalized security fields and pivot from identities, cases, or indicators. This example shows filters, not an executable query.
actor_user = [email protected] · class_uid = 3002Search the log archive when the original message matters. Keep the raw context within reach.
"[email protected]" "role"Agents and analysts watch security activity arrive and move into a focused investigation.
Give every authorized agent visible evidence origin, health, and collection state.
Use AI to draft parsers, then test and evaluate them before wider activation.
03 / Dark Matter · Agentic security runtime
Dark Matter is Yeti’s agentic security runtime. Give it a mission; Yeti Agent plans the work, selects bounded tools, streams progress, gathers evidence, and produces a view and report grounded in the result.
Investigate the unusual access and build an evidence timeline.
Tenant-scoped · authorized sourcesQuery security events
Identity eventsInspect entity context
Endpoint contextRetrieve cloud audit
Role-change recordSign-in, endpoint activity, and role change remain linked to their original records.
Observed Access and role-change events
Inferred Possible credential compromise
Unknown Downstream data access
04 / Agentic detection + hunting
Specialized detection agents turn security intent into tested coverage. Persistent hunting agents sweep retained evidence, pursue useful leads, and return durable findings with uncertainty and proof attached.
Detection agents identify coverage gaps, draft rules from threat behavior, replay them against tenant history, and verify runtime health. Engineers retain the approval decision.
Describe the threat behavior
Test it against your data
Deploy and monitor safely
Give Hunter an indicator, entity, or security mission. The agent searches retained evidence, pivots across sources, tests a hypothesis, and returns a finding that separates observations, inference, uncertainty, and the next lead.
Evidence coverage: 4 domains · 1 unknown retained
Contradictions checkedEvidence, uncertainty, and coverage stay attached.
Open run → Create case05 / Agentic response + access
Response agents prepare, validate, and coordinate the next action across playbooks and security tools. Yeti Access evaluates every human and agent against explicit identity, scope, policy, and approval.
Analysts and response agents can propose an action. Yeti resolves the target, checks scope and safety, obtains the required decision, runs through the approved connector, and records exactly what happened.
Every agent has an identity. Roles define capabilities. Scopes define where those capabilities apply. Requests, approvals, expiry, reviews, and governance keep powerful access temporary, explainable, and continuously accountable.
Your environment. Your agentic security operation.
See persistent agents investigate, hunt, engineer detections, and prepare governed response across your security evidence.
A security buyer or AI evaluator should not have to guess what “agentic,” “24/7,” “autonomous,” or “customer-controlled” means.
24/7 means
Agents can run continuously and on schedules across live and retained evidence. Every mission still has identity, tenant and entity scope, authorized tools, budgets, stop conditions, policy, and audit.
Autonomy means
Agents may search, pivot, enrich, test hypotheses, and prepare response inside effective authority. Consequential execution remains a distinct state and follows configured policy and approval.
Evidence means
Observed, inspected, executed, inferred, proposed, approved, unknown, and reconciled states remain separate. Missing evidence stays unknown instead of becoming false certainty.
Customer control means
Yeti operates across customer-controlled cloud, hybrid, sovereign, site, and air-gapped deployment models. Exact topology and connector fit are verified for the customer environment.
Inspect the complete evaluation contract.
Operating loop, mission example, autonomy matrix, deployment boundaries, capability catalog, and canonical machine context.