Skip links
Building a Multi-Agent AI Security Analyst on Anthropic Claude

Building a Multi-Agent AI Security Analyst on Anthropic Claude for a Modern Security Data Platform

Building a Multi-Agent AI Security Analyst on Anthropic Claude for a Modern Security Data Platform

Building a Multi-Agent AI Security Analyst on Anthropic Claude

Executive Summary

Crest Data partnered with a leading AI-native security platform to extend its AI agent for SecOps, a multi-agent AI security analyst embedded in their security data platform and powered by Anthropic’s Claude models. An AI agent for SecOps already existed as a Claude-powered platform; Crest Data’s role was to add new capabilities, sharpen the existing agents, and harden the system for production scale — building on that foundation rather than rebuilding it.

The Copilot turns security operations into a conversation with an expert analyst: questions that once meant hand-writing queries and pivoting across tools are now answered in plain English, grounded in the customer’s own security data. A new natural-language-to-query agent lets analysts interrogate their data without knowing query syntax; a supervisor coordinates specialized Claude agents to plan investigations, analyze events, and build detections; and every unit of AI consumption is metered and governed. Because the platform runs Claude through Amazon Bedrock, inference stays inside the customer’s cloud boundary — the data control a security product demands.

About the Customer  

The customer is a leading AI-native security platform provider focused on helping organizations collect, understand, and act on security telemetry. Its platform helps security teams cut through noise, streamline detection and response, and apply generative AI to the day-to-day work of security operations — operating directly on sensitive customer security telemetry and integrating with the tools and detection frameworks teams already rely on.

Customer Challenge  

  1. Manual Investigation: Answering even a routine security question — whether an alert is a genuine threat, what a set of events means, or how to express a detection — required analysts to pull data from multiple sources, correlate it by hand, reason about it against known attacker behavior, and write up a conclusion.

  2. Query Expertise Barrier: Interrogating security data meant knowing query languages like KQL (Kusto). That expertise is scarce, slowing investigations and limiting who on the team could dig into the data directly.

  3. Governing AI at Scale: As adoption of the AI analyst grew, the customer needed to meter and control generative-AI consumption — both to keep costs predictable and to package and commercially license the capability.

  4. Non-Negotiable Trust: Sensitive customer telemetry could never leak to external model endpoints, the AI could not hallucinate guidance, and a human had to stay in control of consequential decisions such as final verdicts.

Proposed Solution

The customer wanted an AI security analyst that could investigate like a senior engineer — plan the work, query the data, reason about the findings, and return an evidence-backed answer — while keeping humans in the loop and data in the boundary. Built on Anthropic’s Claude models (Claude Sonnet with extended thinking for deep reasoning, and Claude Haiku for fast, high-volume work) and delivered through Amazon Bedrock, an AI agent for SecOps offers:

  • Natural-Language Investigation: A new Claude-powered agent, built by Crest Data, translates an analyst’s plain-English question into a Kusto (KQL) query, executes it against the customer’s security data, and returns the results — letting analysts interrogate their data conversationally, without writing query syntax by hand.
  • Multi-Agent Investigations: A planning supervisor interprets each request, decomposes it into tasks, and delegates to specialized Claude agents — generating insights, building queries, filtering and analyzing events, and taking follow-up actions — with background workflows handling verdict determination, summarization, and detection-rule creation. The agentic, tool-using orchestration is built with LangGraph over Anthropic’s Claude models, with Claude Sonnet’s extended thinking reserved for the reasoning-critical steps.
  • Grounded, Context-Aware Answers: Crest Data sharpened the existing insight and chat agents with richer user context, entity and name resolution, and fixes to combined-query handling — making Claude’s answers more precise and firmly grounded in the customer’s own security data rather than general knowledge.
  • Human-in-the-Loop Verdicts: For consequential outcomes such as security verdicts, an AI agent for SecOps produces a structured, evidence-backed recommendation for analyst review rather than acting autonomously — the analyst confirms, overrides, or refines the conclusion.
  • Usage Governance and AI SOC Licensing: Crest Data built a credit- and entitlement-based governance layer (“Balance Gate”) that meters generative-AI consumption across chat and background workflows and checks it against each tenant’s plan before expensive Claude work runs — the metering foundation that lets the platform provider package and commercially license an AI agent for SOC capabilities.
  • Enterprise Guardrails: Inference runs inside the customer’s AWS boundary via Amazon Bedrock, so telemetry never reaches external model endpoints; model access uses IAM-based credentials with no long-lived API keys; multi-tenant isolation is derived server-side and cannot be spoofed; user identity is carried to the AI service through an encrypted, self-expiring token reference and forwarded so the platform’s role-based permissions apply to every action; and all of it is backed by production-grade resilience — a single guarded model-access path with concurrency control, automatic retries, and per-model usage and cost metering.

Outcomes & Success Metrics

  • Lower Barrier to Investigation: Analysts interrogate their security data in plain English instead of hand-writing KQL, opening up direct investigation to more of the team and shortening time-to-answer.
  • Consistent, Grounded Analysis: Multi-agent investigations grounded in the customer’s own data standardize investigation quality and reduce the variability of analyst-by-analyst work — with every answer tied to the underlying evidence.
  • Governed AI Consumption: Per-tenant credit and entitlement metering gives the customer control and visibility over generative-AI spend, plus the foundation to package and license an AI agent for SOC capabilities commercially.
  • Data Never Leaves the Boundary: Running Claude through Amazon Bedrock keeps all inference inside the customer’s cloud account — meeting the strict data-handling expectations of a security product without sacrificing frontier-model capability.
  • Reliable at Production Scale: Reliability fixes across the chat experience, upgrades to newer Claude models, and hardening of caching and audit logging made an AI agent for SecOps more stable and consistent under real-world load.
  • Ready for What’s Next: The multi-agent design and deep Claude integration form a durable foundation for expanding AI capabilities across the platform.

About Crest Data

Crest Data is a data and AI-driven technology solutions provider for enterprises and technology innovators in cybersecurity and observability. The company specializes in building practical, integration-led solutions that connect leading security intelligence platforms with the tools enterprise SOC teams use every day.

This engagement reflects Crest Data’s broader capability in building production-grade security integrations that connect leading threat intelligence platforms with the SIEM, XDR, and SOC tooling that enterprise security teams rely on, creating durable value for platform vendors and their customers alike.