AI News Feed
Market watch
Products & Applications

Gravwell 5.10 Adds Five AI Agents That Gather Their Own Investigation Context

Gravwell 5.10 adds five AI agents that gather investigation context via MCP, with three for analysts and two for admins.

According to the report, an agent can pull live telemetry, detections, system state and saved searches, then call the platform’s own tools to run queries and collect evidence until it has something worth an analyst’s time. Gravwell said none of that depends on preassembled context, the alert body or case file that AI features in security tooling typically work from.

Three of the five agents work alongside analysts. The Case Agent stays with an investigation from the start, writing and validating Gravwell queries, running them and suggesting the next pivot. It remains read-only unless told to save something. The Alert Triage Agent sits between a detection and the analyst who receives it, running supporting queries and assembling an opening report so the alert does not land bare. Overnight work goes to the Daily Summary Agent, which reviews the previous day’s telemetry and hands over queries analysts can run against what it found.

The remaining two agents answer to administrators. The Admin Agent fields configuration questions about a deployment, covering ingesters, access controls, storage and replication. The Audit Agent runs a read-only hygiene pass across automations, alerts, query content and data flows. Stalled searches, duplicate extractors and dead data feeds go into one prioritized report.

All five arrive in what Gravwell calls the AI Agent Preview kit. Each agent specification defines which tools and which portions of the MCP environment that agent can reach, which actions it can take and which procedure it follows. The update also draws agent runs on-screen, so a team can see which tools were called, what was read and how the agent got to its conclusion.

“Autonomy without context or boundaries can create more problems than it solves,” said co-founder and Chief Executive Corey Thuen. Agents that draw on a customer’s real environment while operating inside defined tools and permissions give security teams a controlled path toward more autonomy, he said, without handing AI unrestricted access to security operations.

The preview kit ships across Gravwell editions, including the free Community Edition, rather than sitting behind a premium AI tier.

Founded in 2017, Gravwell sells its platform as a replacement for legacy security information and event management systems, ingesting data in full fidelity and applying structure only at query time, according to the report. Two Bear Capital led a $15.4 million Series A round for the Minneapolis-based company last October. Gula Tech Adventures Inc., Next Frontier Capital and Kickstart also took part.

Agentic tooling has become a common thread across security operations vendors this year. Blumira Inc. opened a pilot of its own agentic investigation engine, Kindling, in May.