Plain English
Ask a question in familiar language. Snowman turns plain-English search into archive text search.
Find sign-ins for [email protected] from a new locationYeti · Enterprise security operations
Yeti is the evidence-native security operations platform for your entire environment. It unifies telemetry, detection, investigation, threat hunting, governed AI, and controlled response without breaking the chain of proof.
01 / Investigation
Yeti connects scattered security activity, investigates it with AI, and gives your team an explained case with the evidence behind it. From the first signal to the next action, the context stays together.
Bring identity, endpoint, network, and cloud activity into one investigation.
The AI Case Analyst examines related activity, compares explanations, and follows the evidence.
Review a timeline and linked records. See what is observed, what is inferred, and what is still unknown.
Your team reviews the findings and takes the next step through a governed response workflow.
Analysts can follow the events, understand the conclusion, and inspect the records that support it. Unanswered questions remain visible so the next step is based on what is actually known.
The AI Case Analyst helps assemble and explain the case. Your team can review its work and decide how to proceed, with permissions and approval requirements carried into response.
02 / Snowman · Log search & analysis
Snowman is Yeti’s workspace for viewing, searching, and analyzing logs. Find the events that matter, inspect the original records, and ask AI to explain what you’re looking at.
Security events and retained log history.
Ask in plain English, filter security fields, or search archive text.
user: [email protected]
source: 192.0.2.24Ask AI to explain a log row, with the selected record as context.
Ask a question in familiar language. Snowman turns plain-English search into archive text search.
Find sign-ins for [email protected] from a new locationSearch normalized security fields and pivot from identities, cases, or indicators. This example shows filters, not an executable query.
actor_user = [email protected] · class_uid = 3002Search the log archive when the original message matters. Keep the raw context within reach.
"[email protected]" "role"Watch security activity arrive and move into a focused investigation.
Understand where evidence comes from and the state of its collection.
Use AI to draft parsers, then test and evaluate them before wider activation.
03 / Dark Matter · Agentic investigation
Dark Matter is Yeti’s investigation harness. Ask naturally; Yeti Agent selects bounded tools, streams its work, gathers evidence, and creates the view and report relevant to the question.
Investigate the unusual access and build an evidence timeline.
Tenant-scoped · authorized sourcesQuery security events
Identity eventsInspect entity context
Endpoint contextRetrieve cloud audit
Role-change recordSign-in, endpoint activity, and role change remain linked to their original records.
Observed Access and role-change events
Inferred Possible credential compromise
Unknown Downstream data access
04 / Detection + hunting
Yeti turns security knowledge into dependable detections—and gives your team an AI hunter for the questions that need deeper investigation.
Describe the behavior you care about. Yeti helps create and test the detection against your environment, then verifies that the approved version is running where it should.
Describe the threat behavior
Test it against your data
Deploy and monitor safely
Give Hunter an indicator, entity, or security question. It searches retained evidence, follows useful leads, and returns a finding that shows what was observed, what remains uncertain, and where to continue.
Confidence 87% · 4 evidence domains
Contradictions checkedEvidence, uncertainty, and coverage stay attached.
Open run → Create case05 / Response + access
Yeti coordinates response across people, agents, playbooks, and security tools—while Access ensures every actor can only see and do what the organization has explicitly allowed.
Analysts and AI agents can propose a response. Yeti resolves the target, checks scope and safety, obtains the required decision, runs through the approved connector, and records exactly what happened.
Roles define capabilities. Scopes define where those capabilities apply. Requests, approvals, expiry, reviews, and governance keep powerful access temporary, explainable, and continuously accountable.
Your environment. Your security operation.
Walk through your sources, a detection, an investigation, and a governed response with the Sasquatch team.