Company
Date Published
Author
Tiit Hallas
Word count
1007
Language
American English
Hacker News points
None

Summary

Dynatrace Security Investigator is a powerful application designed for security operations and analysts, offering an evidence-driven approach to enhance the speed and accuracy of security investigations on the Dynatrace platform. Utilizing the Dynatrace Grailâ„¢ and Dynatrace Query Language (DQL), the app enables seamless threat hunting and incident analysis by allowing users to track multiple investigation steps through a tree-like visualization that maintains the context and integrity of executed queries. Its branching navigation feature supports the nonlinear nature of threat hunting, enabling analysts to explore new leads without losing sight of the original investigation path. The app's ability to manage and attach evidence, along with flexible filtering options, allows for precise and efficient analysis, even on a petabyte scale. Additionally, the "schema-on-read" capability preserves data in its original format, providing a flexible structure based on specific use cases, while the multi-line content view enhances the understanding of raw data by displaying it in its original form. Overall, the Security Investigator app is designed to streamline the complex process of security investigations, making it easier to uncover critical insights and accelerate response times in time-sensitive situations.