Skip to main content
Sweet Security
Runtime Detection and Response

AI Storyline (investigation)

An AI-generated incident narrative: what happened, what the impact is, who needs to act

AI Storyline turns raw telemetry into a chronological incident narrative: a plain-language description, an assessment of the actual impact, top events, a graph of related identities, processes and assets, and a timeline with executed scripts and commands. The LLM-based detection engine, covered by a U.S. patent on identifying anomalous log sessions, points to the root cause and the decisive events, and for every finding shows the process tree, command line and MITRE mapping. According to Sweet, detection and a full investigation together take less than two minutes.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • A plain-language incident story with an assessment of the actual impact
  • A timeline and IR graph: identities, processes, assets, logs and a process tree with command lines
  • Root cause and decisive events identified by an LLM-based detection engine
  • A U.S. patent on training an LLM to identify anomalous log sessions
  • Statuses, comments, actions on findings (e.g. process termination) and a 30-day incident report export

Business benefits

  • Detection and full investigation in under 2 minutes (Sweet Security data)
  • Fast qualification of false positives without manual log searches
  • The team or developer responsible for the fix identified
  • A lower skill threshold for tier-one SOC: a narrative instead of raw events
  • Ready material for post-incident reports and regulatory notifications (DORA, NIS2)
Sweet Security

Why Sweet Security?

Sweet Security is a Runtime CNAPP that detects and blocks attacks on cloud infrastructure, workloads, applications and AI agents while the attack is still under way. A lightweight eBPF sensor and cloud logs build a behavioral baseline of the environment, and a single detection engine correlates events across every layer to cut MTTR to minutes, according to Sweet Security data.

All products

Need AI Storyline (investigation) in your organization?

As a certified Sweet Security partner, we'll help you deploy and configure the solution.

Book a free consultation