Skip to main content
Audience: SOC leaders, security engineers, analysts
What: AI-powered MDR that triages alerts, runs investigations, and automates response across endpoint, cloud, SaaS, identity, email, and network tools.
Why it matters: Faster, consistent investigations with documented outcomes without scaling headcount.

๐Ÿงญ What is AirMDR?

AirMDR is an AI-native Managed Detection & Response platform. It ingests alerts from your stack, generates or selects the right Investigation Playbook, enriches evidence across tools, applies your Guidelines & Templates, and produces a documented decision with notifications and a feedback loop that continuously improves future outcomes. Deep dive on โ†’ AirMDR Playbooks
Ever-growing Integration catalog โ†’ backed by a dedicated integrations team.
Build & extend โ†’ API Reference

๐Ÿ‘ฅ Who itโ€™s for & where it fits

  • Teams that need low-latency triage and repeatable investigations across many tools.
  • Organizations scaling MDR/SOC outcomes without linear analyst hiring.
  • Works alongside your existing SIEM/EDR/IDP/CASB/email securityโ€”no forklift required.

๐Ÿ”„ How AirMDR works (end-to-end)

Operational sequence at a glance: Alert ingest โ†’ Quick checks (Facts/Allow-Block) โ†’ Playbook select/auto-generate โ†’ Agentic investigation (notes + meta-enrichments) โ†’ Case Management (In Progress ยท Analyst Pending ยท Customer Pending ยท Closed).
Air MDR4 Jp
Key outputs per case
  • ๐Ÿ“„ Executive summary & timeline
  • ๐Ÿง  Enrichment findings and rationale
  • โœ… Final disposition with next steps
  • ๐Ÿ”” Stakeholder notifications (Slack/Email)

๐Ÿงฉ Core concepts & modules

๐Ÿ“ฌ Alerts (ingest & normalize)

What: Incoming detections from your tools (IDP, EDR, SIEM, Email, Cloud, SaaS).
How: Pulled via Integrations with least-privilege scopes; normalized and de-duplicated.
Key fields: source/provider, rule/signature, severity, entities (user/device/IP/app), artifacts (hash/domain/url), timestamps, correlation keys.

๐Ÿ”Œ Integrations: Connect your ย SIEM/EDR/IDP/email/security stack for fetching, enrichment, federated queries, and actions (e.g., reset account, block IP, ticketing).
โ†’ Integrations Catalog & Setup Guide: Integrations Overview

๐Ÿง  Facts and๐ŸšฆAllow/Block Lists:

  • Facts: Durable, structured assertions about entities (users, IPs, apps, assets) that add business context to investigations and explains why something might be benign or risky, reducing false positives and speeding decisions.
  • Allow/Block Lists: Canonical lists labeling indicators (IPs, domains, URLs, hashes, emails, device IDs) as Allowed (benign/expected) or Blocked (malicious/forbidden).
    Facts supply context; Allow/Block Lists set disposition shortcuts. Both feed Guidelines and Darrylโ€™s learning loop to deliver faster, consistent, auditable decisions.

๐Ÿ› ๏ธ Playbooks

What: Opinionated automation for investigation, detection, and case operations.
Trigger: On alert arrival (event/schedule) or on analyst command.
Modes: Use existing playbook for the alert/provider, or
Auto-generate via Darryl from plain English / alert context.
What they do: Run enrichments (IDP/EDR/SIEM/cloud/email), correlate signals, request approvals (Pause-and-Wait), and execute scoped actions (e.g., revoke sessions, block IP).
Output to Case: evidence, rationale, proposed decision (Low / Needs Review / High), and next steps.
โ†’ Read more: AirMDR Playbooks
Air MDR5 Pn

๐Ÿค– โ€œDarrylโ€ โ€” AI Virtual Analyst (Agentic Investigationโ€“Capable)

Darryl turns plain-English instructions and incoming alerts into step-by-step investigations, selecting the right skills, explaining each action, and producing a clear, auditable decision.
  • ๐Ÿ› ๏ธ Automates investigations: Runs Playbooks, enrichment, and containment steps across your tools.
  • ๐Ÿง  Chooses the right skills: Picks queries/actions (IDP, EDR, SIEM, cloud, email) based on alert context.
  • ๐Ÿ“ Explains rationale: Captures โ€œwhyโ€ for each step and the final decision (Low / Needs Review / High).
  • ๐Ÿ” Learns with feedback: Improves using Facts and Allow/Block Lists plus analyst overrides.
  • ๐Ÿ”” Keeps teams in sync: Pushes updates/approvals to Slack/Email; links back to the exact case step.
  1. Ingest alert or analyst prompt.
  2. Select/generate an Investigation Playbook.
  3. Run enrichments & checks (respecting Guidelines).
  4. Propose decision + next steps.
  5. Notify, request approval if needed.
  6. Record everything in the Case and update org knowledge.
  • ๐Ÿงฉ Guidelines first: Deterministic rules set boundaries for decisions and actions.
  • ๐Ÿ‘ค Human-in-the-loop: Analysts can approve, modify, or stop actions at checkpoints.
  • ๐Ÿ•ต๏ธ Auditability: Every query, action, rationale, and notification is written to the case timeline.
  • ๐Ÿ” Least privilege: Uses scoped credentials from Integrations and Vault.
Inputs the agent considers
  • โœ๏ธ Investigation Notes (Guardrails that define how AirMDR investigates and the criteria for making decisions (e.g., Low / Needs Review / High))
    • Inputs: fields from alert/case/enrichment (user, IP, hash, app, risk score, etc.)
    • Context: Facts and Allow/Block Lists (e.g., red-team IPs, sanctioned domains)
    • Conditions: boolean checks, thresholds, pattern matches
    • Actions: run skills (extra queries, containment), request approvals
    • Outcome mapping: set decision (Low / Needs Review / High) + next steps
  • ๐Ÿง  Facts (durable org context) + ๐Ÿšฆ Allow/Block Lists
  • ๐Ÿงฉ Case Templates (Reusable layouts that standardize how case reports and sections are written and presented)
  • ๐Ÿ”Ž Meta Playbook Findings (extra, tool-specific enrichments derived from the alert JSON)
  • Okta: Get user details, group memberships, recent sign-ins, MFA enrollment, app assignments
  • EDR: Device posture, recent detections on host, isolation status
  • SIEM: Correlated events in time-window, peer activity
  • Cloud: IAM role changes, last-modified policies, risky API calls
  1. Parse alert JSON + analyst notes
  2. Pull Facts / Allow/Block Lists
  3. Execute meta enrichments (provider-specific deep dives)
  4. Evaluate Guidelines (deterministic checks/thresholds)
  5. Synthesize findings โ†’ propose decision + actions
  6. Apply Case Template to generate a clean, exec-ready narrative
  7. Emit notifications/approvals (Slack/Email) as configured
  8. Write all steps, rationale, and artifacts to the case timeline

๐Ÿ“ Case Management

What: The system of record for the investigation.
Lifecycle: Created/updated from alert โ†’ enrichment evidence โ†’ guideline checks โ†’ human/auto decision โ†’ notifications โ†’ Closed.
Anatomy: executive summary, timeline (all steps & approvals), findings/rationale, actions taken, attachments, audit trail.
States: In Progress ยท Analyst Pending ยท Customer Pending ยท Closed.
Comms: Slack/Email updates and approvals; deep links back to the exact timeline step.
Governance: Role-based access, redaction controls, full auditability.

๐Ÿ’ฌ Communication & Collaboration

In-case comments, approvals, and Slack/Email notifications so the right people are looped in at the right time.
๐Ÿ”— How they fit together
  • End-to-End Sequence (at a glance)
    1. Alert ingested via Integrations โ†’ normalized & de-duplicated
    2. Eligibility checks (Facts / Allow-Block short-circuit where applicable)
    3. Playbook selected or auto-generated (Darryl)
    4. Agentic investigation: notes + Facts + meta enrichments โ†’ Guidelines โ†’ decision/actions
    5. Case updated (summary, timeline, rationale, artifacts)
    6. Notify/approve in Slack/Email โ†’ execute actions as scoped
    7. Close case (or handoff) โ†’ learning updates (Facts, Allow/Block)
Quick start (recommended sequence)
  1. Pick 2โ€“3 high-volume alert types; draft minimal guidelines per type.
  2. Create a concise org-default template; add a provider-level variant for one source.
  3. Run a 7-day pilot, review 10โ€“20 cases; capture false-positive reasons as Facts or Allow List entries.
  4. Tighten thresholds in guidelines; trim template text; keep summary first.
  5. Enable notifications for decision changes and SLA risks.
  6. Schedule monthly reviews of metrics and guideline efficacy.

๐Ÿ” Vault (secure credential intake)

Secure, auditable way to collect investigation credentials from customers (e.g., temporary API keys, jump-box creds) via one-time, expiring links so analysts can complete time-bound checks without sharing secrets over email/Slack.
โ†’ Read more: Vault
A real-time, role-aware view of investigations and automation performance so user can spot hotspots, track SLAs, and prioritize improvements without digging through individual cases. Air MDR1 Pn

๐Ÿ” AirMDR Security & data handling (at a glance)

  • Integrations-first: Query what you need when you need it; minimize data copying.
  • Scoped access: Use least-privilege roles/API keys per tool.
  • Vaulted secrets: One-time, encrypted submission with audit trails.
  • Auditability: Every automated step and human action is recorded in the case.
    For implementation specifics, see the relevant integration pages and the API reference.

Getting started

AirMDR Quick Start: Recommended Sequence
  1. ๐Ÿ”‘ Access the Platform
    Log in to AirMDR in your web browser with your org credentials.
  2. Create org & users (SSO optional).
  3. ๐Ÿ”Œ Connect Your Tools
    Set up Integrations with your existing security stack (IDP, EDR, SIEM, email, cloud, SaaS) to enable enrichment and actions.
  4. ๐Ÿ“ฅ Enable an Alert-Triage Playbook (schedule or trigger)
    Create Fetcher Playbooks to automatically pull alerts from connected sources on a schedule or trigger โ†’ Read more: AirMDR Playbooks.
  5. ๐Ÿงญ Customize Guidelines & Templates
    Seed organizational context like Facts, Allow/Block Lists and define Investigation Guidelines (how to decide) and Case Templates (how to write it up) at org/provider/alert levels for consistent, auditable outcomes.
  6. Wire up notifications to Slack/Email and ticketing as needed.
  7. ๐Ÿ“Š Monitor Performance
    Use Dashboard & Trends to track volumes, MTTI/MTTR, automation coverage, SLA health, and noisy sources; iterate weekly.

๐ŸŽฏ AirMDR Impact: What โ€œGoodโ€ Looks Like

  • Consistent investigations with clear, defensible decisions.
  • Lower manual toil through playbook-driven enrichment and actions.
  • Faster time-to-decision on routine alerts; analysts focus on true positives.
  • Better signal quality over time via Facts and Allow/Block feedback loops.
  • Stakeholder trust through standardized reports and proactive notifications.

๐Ÿ“š Glossary