Skip to main content
POST
Agent tool submit investigation

Path Parameters

workspaceId
string<uuid>
required
source
enum<string>
required
Available options:
Sentinel,
DefenderXDR,
QRadar,
Splunk,
CrowdStrike,
SentinelOne,
SumoLogic
incidentId
string
required

Body

application/json

Request DTO for the agent's submit-investigation tool — the closeout call the agent makes after it has finished investigating an incident.

comment
null | string

Final investigation summary. Posted on the incident as the agent's comment as-is — no server-side wrapping or section headers are applied. Write as a detailed security analyst would: cover initial hypothesis, indicators matched, tools called and why, evidence found, classification rationale, response actions, and recommended next steps. This is what a human analyst will read to learn from the agent's analysis.

classification_reason_comment
null | string

Short rationale (1–2 sentences) shown on the incident's closure record when the status transition closes the incident. Surfaces in the closure dialog and audit log alongside the classification reason.

malicious_score

How malicious the agent judged the activity, 0 to 100, where 0 is clearly benign and 100 is clearly malicious. This is not confidence in the verdict: a False Positive the agent is certain about scores near zero, not near a hundred.

classification
null | any

Final incident classification, identical for every security platform. Allowed values: TruePositive (confirmed malicious), FalsePositive (the detection was wrong; no suspicious activity occurred), BenignPositive (real activity confirmed benign, expected, or authorized), Undetermined (no firm verdict reached). Status transition follows from this via the per-severity agent settings.

Available options:
BenignPositive,
FalsePositive,
TruePositive,
Undetermined,
null
classification_reason
null | any

Reason corresponding to the classification; required on every classified closeout and identical for every security platform. TruePositive → MultistagedAttack | Malware | MaliciousUserActivity | UnwantedSoftware | Phishing | CompromisedUser | Apt | SuspiciousActivity | Other. FalsePositive → NotMalicious | NoEnoughDataToValidate | InaccurateData | IncorrectAlertLogic | Other. BenignPositive → SecurityTesting | ConfirmedUserActivity | LineOfBusinessApplication | SecurityPersonnel | SuspiciousButExpected | Other. Undetermined → Unknown | Other. Pick the most specific reason the evidence supports; a pairing outside this list is normalized server-side to Other.

Available options:
InaccurateData,
IncorrectAlertLogic,
SuspiciousActivity,
SuspiciousButExpected,
Unknown,
Apt,
Malware,
SecurityPersonnel,
SecurityTesting,
UnwantedSoftware,
Other,
MultistagedAttack,
CompromisedUser,
Phishing,
MaliciousUserActivity,
NotMalicious,
NoEnoughDataToValidate,
ConfirmedUserActivity,
LineOfBusinessApplication,
null
classification_sop
object

The single classification SOP whose decision tree drove the classification. Null when no SOP applied to this incident type.

response_sops
null | object[]

SOPs whose response steps the agent executed during the investigation. Empty when the agent decided no response action was warranted.

gamebook_ids
null | string[]

IDs of gamebooks the agent queued earlier via submit-gamebook during this investigation. Use the gamebook_id returned by each submit-gamebook call. Receive-only here — submit-investigation does NOT queue additional gamebooks.

tool_calls
null | object[]

Per-tool-call timeline the agent recorded during the investigation. Used to render the activity header on the comment so an analyst can see exactly which tools the agent invoked, on what target, in what order, and how long each took.

Response

OK

Standard v2 API response envelope for single-item responses.

data
object

Result of an agent submit-investigation tool call.

meta
object
Last modified on October 9, 2026