Endpoint monitoring & investigation
The Windows collector and core investigation model exist. Broader endpoint coverage and deeper telemetry are being developed.
SNOOW – AGENTIC AI SOC PLATFORM
SNOOW brings security telemetry, threat detection, AI-assisted investigation, human-controlled response and incident reporting into one unified SOC platform.
Currently available for pilot evaluation.
From signal
to security.
PRODUCT AVAILABILITY
SNOOW is under active development. Pilot scope is agreed with each organisation; the capabilities below are not a general-availability commitment.
The Windows collector and core investigation model exist. Broader endpoint coverage and deeper telemetry are being developed.
Decision and Action agent foundations exist. Response coverage, reliability and approval controls are being expanded and validated.
Native identity telemetry, account-risk context and controlled identity response are on the roadmap.
Native network ingestion and analysis of firewall, DNS, proxy and flow activity are on the roadmap.
THE SECURITY OPERATIONS CHALLENGE
Security teams often work across disconnected tools, alerts and workflows, increasing investigation time and operational complexity.
Security information is distributed across endpoints, cloud platforms and multiple security products.
Analysts spend significant time gathering context and correlating evidence manually.
Smaller organisations may not have the resources required to maintain large security operations teams.
Delayed investigation and fragmented workflows increase the time required to understand and respond to incidents.
THE SNOOW PLATFORM
SNOOW combines telemetry, detection, investigation, decision support and controlled response into one operational workflow.
Build on Windows endpoint collection, with broader collector coverage under development.
Identify suspicious activity through rules, behavioural logic and event correlation.
Enrich alerts, correlate related activity and build an investigation timeline.
Recommend whether an incident should be blocked, escalated or monitored.
Require analyst approval before executing sensitive response actions.
Generate investigation summaries, evidence and recommended next steps.
HOW SNOOW WORKS
AI accelerates investigation and decision support. Security teams remain in control of sensitive actions.
FIVE SPECIALIST AI ROLES
SNOOW's agentic workflow is designed to pass a shared incident record between specialist roles. Each adds context, while evidence, uncertainty and human decisions stay attached.
Explains why an alert matters and prioritises it using observed signals.
Passes on: alert, source evidence and detection context.Connects related events, assets and indicators into a timeline, flagging missing evidence.
Passes on: timeline, evidence references and confidence.Recommends monitoring, escalation or response, with an evidence-linked rationale.
Passes on: recommendation, rationale and policy checks.An authorised analyst reviews the evidence and approves or rejects the recommendation. A rejected action does not execute.
Executes only permitted actions with the required approval and records success or failure.
Passes on: approval record, execution result and audit evidence.Produces an incident narrative that distinguishes observed facts, inference and recommendations.
Produces: an analyst summary and traceable incident record.Product workflow direction; available steps depend on the agreed pilot scope.
UNIFIED SOC CONSOLE
SNOOW is being designed to bring the information analysts need into a single investigation experience.
INCIDENT SUMMARY
Multiple authentication failures followed by a successful sign-in from an unusual source.
RECOMMENDED RESPONSE
Review session and isolate the affected endpoint.
USE CASES
Bring important security telemetry into one operational view.
Analyse endpoint activity and security events as part of an investigation.
Enrich alerts and correlate evidence before an analyst makes a decision.
Organise investigation context so analysts can focus on higher-priority incidents.
Keep sensitive response actions under analyst control.
Structure evidence, summaries and recommended next steps into consistent reports.