Command Zero has previewed new platform capabilities ahead of Black Hat USA 2026, highlighted by Throughline, a living investigation feature that continuously connects related security alerts into a single evolving case and updates findings as new evidence emerges. The enhancements combine governed AI, transparent decision-making, and supporting evidence to help security operations centers reduce alert fatigue, improve prioritization, and provide deeper attack context throughout ongoing investigations.
Throughline: Living SOC Investigations
Every current approach to AI in the SOC investigates an alert at a point in time, files the report, and moves on. Attackers work across days and weeks. Throughline closes that gap. When a new alert arrives, it joins the matching investigation: the case reopens if closed, its time window extends, every investigative question re-executes, and the verdict gets re-examined with all evidence on the table. One case, one evolving verdict, one throughline running through the whole attack.
And it does this by reasoning, not rules. Each new alert triggers fresh analysis of the entire case, grounded in your organization’s own context: prior investigations and their analyst notes, company policies, and asset inventories. A correlation rule matches what someone predicted in advance. Throughline reconsiders what the evidence means in your environment.
In testing across early adopters, Throughline reduced the verdicts analysts had to consider by as much as 41 percent. It also connected attack campaigns that the originating tools generating the alerts had left as scattered, unrelated events.
What’s coming
- Throughline. Related alerts merge into one living investigation, evidence trail intact. Verdicts evolve as the attack does.
- Automatic Alert Closure. Analysts set the policies. Command Zero closes the easy calls without a full investigation.
- Alert Tuning. Continuous, evidence-based analysis recommends specific tuning actions, not generic advice.
- Exposure Management. Asset criticality and exposure data feed directly into every verdict, reasoning shown.
- Precision RBAC. Policies define what every analyst, and the AI itself, can see and run. Every decision audited.
- Verdict-Driven Response Actions. Containment fires on investigation verdicts, not raw alert severity. Notify-only by default.
Architected for builders
These features extend a platform already open to developers and security teams who build their own SecOps pipelines. Command Zero’s APIs and MCP server give SOC teams programmatic access to the same governed, auditable data that powers every verdict, now including Throughline case updates and verdict revisions. Teams wire the platform into SOAR playbooks, custom threat hunting frameworks, and AI agents like Claude, without waiting on a vendor roadmap.
“We battle tested Throughline against a month of production alerts in complex customer environments. It cut the verdicts analysts had to consider by up to 41 percent, and it caught what point-in-time analysis structurally cannot. For example: Five exploitation attempts against one server, each with a different IP and a different incident ID from the tool that detected them, assembled into a single living investigation over time. Attackers work across weeks. Now your investigations do too.”
— Dean De Beer, Cofounder and CTO, Command Zero
“CISOs don’t want yet another tool that demands a month of learning or data migration before it proves its worth. Command Zero connects straight to the data our customers already have, goes live in under an hour, and covers investigations across all analyst tiers. Our customers report consistent outcomes and reduced risk thanks to less time spent chasing noise, more time on the threats that put the business at risk.”
— Dov Yoran, Co-founder and CEO, Command Zero
For more information, visit: https://www.commandzero.ai/
Related News:
Glow Launches with $180M to Advance Endpoint Security
Swimlane AI SOC for MSSPs Expands AI-Driven Security Operations