The threats that matter most don't always trigger alerts.
Hunting shouldn't be a side activity. It should run continuously across your environment, with AI agents and analysts working together. Test 5–10x more hypotheses per analyst. Every hunt is documented and repeatable.
I can perform a threat actor hunt and reporting workflow using the currently available threat intelligence agents, Splunk integrations, IOC enrichment sources, and reporting capabilities.
Proposed investigation plan
Gather IOCs.
Gather TTPs.
Generate Splunk SPL Query for Threat Actor.
Query Splunk for Actor Detection.
Compile Findings into Full Report.
Investigation in progress
#
Task
Agent
Status
Compiling findings…
Findings so far
Threat intelligence analysis identified APT28, also known as Fancy Bear, as a Russian state-sponsored threat actor associated with the GRU and historically linked to cyber espionage campaigns targeting government, military, media, and security organizations.
IOC collection identified multiple indicators associated with recent APT28 activity, including malicious IP addresses, suspicious domains, file hashes, and email addresses commonly associated with phishing, credential theft, and command-and-control operations.
TTP analysis identified several MITRE ATT&CK aligned behaviors associated with APT28 activity, including spear-phishing, exploitation of public-facing applications, credential dumping, command-and-control activity, and malware deployment.
A Splunk SPL query was successfully generated to identify network and security telemetry associated with known APT28 indicators of compromise. The query focused on identifying communications involving known malicious IP addresses and suspicious activity patterns linked to the threat actor.
Splunk query execution identified suspicious IP communications, phishing-related telemetry, multiple failed login attempts followed by successful authentications from unusual locations, and malware signatures associated with known APT28 operations.
Security log analysis confirmed multiple indicators consistent with active threat actor behaviors, including reconnaissance activity, credential theft indicators, and suspicious outbound communications. These findings indicate elevated organizational risk and justify continued monitoring and investigation activities.
Reporting workflows compiled the collected IOC intelligence, TTP analysis, SPL detections, investigative findings, and mitigation guidance into a consolidated threat actor intelligence and detection report for operational and leadership consumption.
Drafting recommendations…
Recommendations
Recommendation
Procedure ready
Requires approval
Status
Action
Operationalize generated Splunk SPL detections
Deploy detections to continuously monitor for APT28-associated indicators, suspicious authentication activity, and malicious outbound communications.
Yes
No
Not started
Enterprise-wide threat hunting
Hunt across the environment for the identified IP addresses, domains, file hashes, and phishing indicators tied to APT28 operations.
Yes
No
Not started
Strengthen access controls and least privilege
Reduce exposure to credential theft and lateral movement on sensitive systems and administrative accounts.
Yes
Yes
Not started
Phishing awareness and cybersecurity training
Organization-wide training focused on spear-phishing and credential theft tactics commonly used by APT28.
Yes
No
Not started
Expand centralized logging and SIEM correlation
Improve visibility into suspicious network traffic and malicious authentication behaviors across the enterprise.
No
No
Not started
Security assessments, vulnerability management, and penetration testing
Proactively identify weaknesses exploitable by advanced threat actors through recurring validation exercises.
No
No
Not started
Review incident response and resilience procedures
Validate IR playbooks, backup strategies, and post-incident review processes for nation-state and APT scenarios.
Hi, I'm your Bricklayer Assistant. I can help you design and execute security workflows such as alert investigations and vulnerability management through conversation.
Connects to your stack
THE PROBLEM
Why most teams can't hunt consistently.
Most teams know they should be hunting. Few can do it consistently.
It takes time and expertise, and it rarely scales.
Hypotheses go untested, coverage is inconsistent, results are hard to document or repeat.
THE APPROACH
What Coordinated AI Agents Actually Look Like.
With Bricklayer, threat hunting is handled by a coordinated workforce of AI agents under your team's command, working with the tools you already use. Your team, now with the experts they've always needed.
Deep expertise across your existing tools and disciplines.
Investigates in parallel across areas of responsibility.
Shares context across every step, nothing gets lost.
Decisions are made with full visibility.
Outcomes and learnings improve over time.
Every decision is governed, consistent, and auditable.
FROM CONVERSATION TO COMMAND
Five steps. One governed workflow.
Security investigations don't fail for lack of data. They fail for lack of coordination. Here's how Bricklayer turns a conversation into organized, executed, and governed action across your SOC.
STEP 01Conversation
Converse With Assistant.
Turn natural language into structured security workflows. Designed, adjusted, and ready to execute.
Consistentproactive coverage across your environment
5–10xmore hypotheses tested per analyst
Documentedrepeatable hunt workflows
100%auditable agent activity
Find what hasn't triggered yet.
IN PRODUCTION
Built for continuous coverage.
Threat Hunting customer deployment data is being compiled as part of our 2026 customer review. Reach out for the most current numbers.
Enterprise & MSSP environments
5–10x more hypotheses per analyst
Continuous hunt coverage, fully documented
Enterprise & MSSP environments
Zero gaps in environment coverage
100% auditable, repeatable workflows
WHY BRICKLAYER
A workforce, not a workflow.
Most AI SOC platforms automate the work. Agents operate independently. Context resets between steps. And when something goes wrong, there's no clear record of why a decision was made.
Our AI agents go farther. They share context, work as a coordinated team, and provide full visibility for analysts. Bricklayer's agentic cybersecurity platform is a workforce for the AI SOC, operating under human control.
ONE PLATFORM
Bricklayer Connects Your Security Operations
One platform aligned to how your SOC works. Bricklayer unifies the workflows that typically live across disconnected tools. No rework required. Just expansion and opportunity.