Skip to main content

AI-Powered Incident Investigations & Faster Phishing Response

Updated today

The new Guardz Incident Experience - investigate incidents faster, with clearer AI reasoning, better visibility into decisions, and guided remediation.

What’s new

  • Investigation Agent panel: In-incident chat that answers incident-specific questions in real time, ask about affected users, attack outcome, supporting evidence, and recommended next step.

  • Incident Overview tab: AI-generated incident summary with key findings and suggested agent follow-up questions to speed triage.
    Including:

    • Action Center: recommended response actions enabling you to remediate faster.

    • Organizational Entities: related users, devices, and other entities tied to the incident.

    • Indicators of Compromise (IOCs): suspicious indicators like malicious IPs and sender email addresses.

  • Investigation Steps tab: step-by-step breakdown of how Guardz reached its conclusion, including evidence at each stage.

  • UI tweaks: breadcrumb navigation, status labels, and banners.

User Reported Phishing automation (Microsoft 365 only)

When an end-user reports a suspicious email, Guardz runs an AI investigation, and if confirmed malicious:

  1. Identifies all affected recipients

  2. Quarantines the email from all inboxes

  3. Revokes compromised user sessions

Use the Investigation Steps tab with full step-by-step investigation reasoning to see exactly why the email was determined malicious, including analysis reasons, scan verdict, per-user compromise assessment, and more.

Did this answer your question?