Building an AI-driven Incident Investigation Platform on AWS
Executive Summary
Security Operations Center (SOC) teams managing modern cloud environments are responsible for investigating growing volumes of security alerts and Data Loss Prevention (DLP) incidents across distributed systems. These investigations often require analysts to retrieve alerts, enrich findings with contextual information, classify severity, and generate structured investigation summaries before remediation actions can begin. As alert volumes increase, these workflows become increasingly manual and difficult to scale.
Crest Data worked with a leading cloud security and SASE platform provider to develop an AI-powered incident investigation solution built using Amazon Bedrock AgentCore, Amazon Bedrock foundation models, and LangGraph. The solution integrates with the customer’s MCP (Model Context Protocol) services to support AI-assisted incident investigation workflows, enabling analysts to interact with security telemetry using natural language while automating alert retrieval, enrichment, classification, and summarization tasks.
The solution was designed as a scalable and extensible AI agent framework that supports secure deployment, operational observability, and future extensibility for additional AI-assisted workflows.
About the Customer
The customer is a leading cloud security and Secure Access Service Edge (SASE) platform provider that helps organizations secure users, applications, devices, and data across distributed cloud environments. The organization provides visibility into cloud applications, web traffic, user activity, and security events while supporting enterprise threat protection and security operations workflows.
Customer Challenge
DLP incident investigations often require analysts to navigate multiple systems and manually execute repetitive workflows to retrieve alerts, enrich findings with contextual information, classify incidents, and prepare investigation reports. As security environments expanded and alert volumes increased, these manual processes introduced operational overhead and slowed investigation timelines.
The customer required a scalable AI-assisted investigation framework that could automate portions of the incident investigation lifecycle while integrating securely with existing security tooling and cloud infrastructure. The solution also needed to support consistent investigation outputs, workflow traceability, and extensibility for evolving AI-assisted security operations requirements.
Without automation, analysts were spending significant time performing repetitive investigation tasks across distributed systems, limiting operational efficiency and making it more difficult to scale investigations across growing cloud security environments.
Proposed Solution
Crest Data developed an AI-powered incident investigation agent using Amazon Bedrock AgentCore as the managed runtime environment for deploying and orchestrating AI-assisted investigation workflows.
Crest Data selected Amazon Bedrock and Amazon Bedrock AgentCore to help the customer rapidly implement generative AI capabilities without managing underlying foundation model infrastructure or custom agent orchestration frameworks.
Amazon Bedrock provided managed access to foundation models for reasoning, summarization, and contextual analysis, while Amazon Bedrock AgentCore enabled scalable deployment and orchestration of AI-powered investigation agents across distributed security environments.
The solution enables analysts to submit natural-language investigation requests such as retrieving recent alerts or analyzing DLP incidents across the customer’s security environments. AI agents process requests through orchestrated workflows that retrieve alerts using MCP integrations, enrich incident data, classify findings, and generate structured investigation summaries for analysts.
LangGraph was integrated to orchestrate multi-step investigation workflows across stages including query parsing, alert retrieval, enrichment, incident classification, and report generation. Amazon Bedrock foundation models provide contextual reasoning and summarization capabilities throughout the investigation lifecycle.
Using Amazon Bedrock AgentCore, Crest Data implemented a modular and extensible architecture supporting stateless deployment, workflow scalability, secure runtime management, and operational flexibility for evolving AI-assisted security workflows. The managed runtime capabilities helped simplify agent deployment and reduce operational complexity associated with scaling distributed AI investigation workflows.
The solution also includes structured logging, workflow traceability, and execution monitoring using Amazon CloudWatch to improve operational visibility across AI-assisted investigation workflows and support consistent investigation outcomes.
Technology Used
AWS Services Used
Amazon Bedrock
Amazon Bedrock provides access to foundation models used for reasoning, contextual analysis, incident classification, and investigation summary generation within the agent workflows.
Amazon Bedrock AgentCore
Amazon Bedrock AgentCore provides the managed runtime environment used to deploy and operate the AI-powered investigation agent, supporting scalable execution and agent orchestration.
Amazon CloudWatch
Amazon CloudWatch was used for operational logging, workflow traceability, and monitoring of AI-assisted investigation workflows to improve observability and operational visibility across the platform.
Outcomes & Success Metrics
Using Amazon Bedrock AgentCore, Crest Data helped the customer enable AI-assisted incident investigation workflows for security operations teams managing DLP incidents and security alerts across cloud environments.
The solution enables analysts to interact with security telemetry using natural language while automating portions of the investigation lifecycle, including alert retrieval, enrichment, classification, and summarization. AI-assisted workflows helped reduce the operational overhead associated with repetitive investigation tasks and improved investigation efficiency across distributed security systems.
The implementation also improved workflow consistency and provided scalable operational foundations for future AI-assisted security workflows, additional integrations, and evolving investigation requirements.
By combining generative AI with scalable AWS-managed services, Crest Data helped the customer modernize DLP investigation workflows and improve security operations scalability.
About Crest Data
Crest Data is an AI-first cloud and cybersecurity engineering company specializing in observability, security operations, intelligent automation, and generative AI solutions. The company helps enterprises modernize operational workflows using cloud-native platforms, AI-driven analytics, and scalable automation frameworks across cybersecurity, DevOps, cloud infrastructure, data engineering, and AI-powered operational intelligence.




