Home TechnologyStreamlining Security Investigations with Agents...
Technology⭐ Featured

Streamlining Security Investigations with Agents

Slack’s Security Engineering team is responsible for protecting Slack’s core infrastructure and services. Our security event ingestion pipeline handles billions of events per day from a diverse array of data sources. Reviewing alerts produced by our security detection system is our primary responsibility during on-call shifts. We’re going to show you how we’re using AI…

7 April 2026 at 08:41 am
1 views
Streamlining Security Investigations with Agents

Slack’s Security Engineering team is responsible for safeguarding the company’s core infrastructure and services. Their daily operations involve managing a security event ingestion pipeline that processes billions of events per day from a wide range of data sources. During on-call shifts, the team’s primary responsibility is to review alerts generated by the security detection system. To optimize their working efficiency and enhance Slack’s security defenses, the team has been experimenting with AI agents. This article explores how they are using AI to streamline security investigations, marking the beginning of a series that will delve into the design choices made and the lessons learned along the way.

The development process began in May 2025, when the team created a rudimentary prototype of what would eventually become their AI-driven security investigation tool. Initially, the prototype was little more than a 300-word prompt, which was divided into five sections: Orientation, Manifest, Methodology, Formatting, and Classification. The Orientation section introduced the AI agent as a security analyst tasked with investigating security alerts. The Manifest outlined the data sources the agent had access to, including Slack’s internal databases, logs, and external threat intelligence feeds. The Methodology section outlined the steps the agent should follow during an investigation, emphasizing the need to cross-reference evidence across different data sources. The Formatting section specified that the agent should produce a markdown report detailing the investigation, while the Classification section required the agent to choose a response classification from a predefined list.

To safely expose a subset of Slack’s data sources through the tool call interface, the team implemented a simple “stdio” mode MCP server. They repurposed a coding agent CLI as an execution environment for their prototype. However, the performance of the prototype was highly variable. At times, the AI agent produced excellent, insightful results, demonstrating an impressive ability to cross-reference evidence across different data sources. On other occasions, the agent would quickly jump to a convenient or spurious conclusion without adequately questioning its own methods. For the tool to be useful, the team needed consistent performance and greater control over the investigation process.

To address these challenges, the team spent time refining the prompt. They stressed the importance of questioning assumptions, verifying data from multiple sources, and ensuring that the agent’s conclusions were well-supported. They also experimented with different ways to structure the prompt, including adding more detailed instructions and examples. Over time, these refinements helped improve the agent’s performance and reliability.

As the team continued to develop the AI-driven security investigation tool, they faced several design challenges. One of the key issues was balancing the need for flexibility and control with the complexity of the investigation process. The team wanted the AI agent to be able to adapt to different types of alerts and investigate them effectively, but they also needed to ensure that the agent followed a structured approach to avoid missing critical information.

Another challenge was integrating the AI agent with Slack’s existing security infrastructure. The team had to ensure that the agent could access the necessary data sources and that it could communicate with other security tools and systems. This required careful planning and coordination with other teams within Slack.

Despite these challenges, the team was able to make significant progress in developing the AI-driven security investigation tool. By using AI agents, Slack’s Security Engineering team has been able to streamline their investigations, improve efficiency, and enhance the overall security of the company’s infrastructure and services. As the team continues to refine the tool and expand its capabilities, they look forward to sharing more insights and lessons learned in future articles.

📰 Related News
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras founder Palak Shah recently opened up about one of the most expensive mistakes she made while building her luxury textile brand. During the early years of the company, Shah rented a premium billboard near Delhi’s DLF Emporio to increase brand visibility. However, after forgetting to cancel the campaign, the hoarding reportedly continued running for months — resulting in losses of nearly ₹40 lakh. The incident has now become a viral example of how small operational oversights can turn into costly business lessons for startups and entrepreneurs.
28 May
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Before AI was inevitable, it was a gamble—and Jensen Huang went all in.
14 Apr
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat is excited to announce the release of Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1, marking a major leap forward in our confidential computing journey. These releases graduate confidential containers on bare metal from …
14 Apr
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
YC Startup School: India’s talent pool across colleges and universities are key for building next-gen startups, which is what YC is looking to tap into. It wants to target entrepreneurs building for global markets, focussed on fintech, consumer, B2B, and ecom…
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC-RESULTS/ (PREVIEW, PIX):PREVIEW-TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
Any profit result ‌above T$505.7 billion would mark the company's highest-ever quarterly net income ​and its ninth consecutive quarter of profit growth
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
On Thursday, ​TSMC is expected to report a net profit of $17.1 billion for the quarter, according to an LSEG SmartEstimate compiled from 19 analysts. The war in the Middle East threatens to disrupt the supply of production materials for semiconductors such as…
14 Apr
If we can’t kick the habit, how do we manage AI’s energy needs?
If we can’t kick the habit, how do we manage AI’s energy needs?
One can only hope that OpenAI’s Sam Altman was joking when he sought to justify the immense energy consumption of artificial intelligence
14 Apr
What caused Nvidia Blackwell GPU prices to spike? #tech
What caused Nvidia Blackwell GPU prices to spike? #tech
Blackwell GPU hourly “rent” surges on agentic AI demand A compute pricing index tracking hourly costs for Nvidia Blackwell GPUs shows a sharp climb: hourly rental hit $4.08 , up 48% from $2.75 just two months earlier. The reported driver is rising demand tied…
14 Apr
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic has introduced Claude Mythos Preview, its most advanced AI model, improving significantly in reasoning, coding, and cybersecurity. Unlike previous releases, it will not be publicly available. Access is limited to a consortium of tech companies throu…
14 Apr