TandemTrace
// Autonomous investigations · Verified by humans

Follow the signal. See the whole attack.

Real-world security investigations reconstructed by TandemTrace AI agents—from the first alert to the final verdict.

Explore the evidence, attack path, competing hypotheses, scope, and response decisions behind every confirmed incident.

95%Autonomous investigation
100%Human authority
TraceableEvery conclusion to evidence
Explore investigations ↓
Ghost Town

Controlled simulations test how the autonomous SOC reasons.

Signal Town

Observed incidents show how evidence changes a real investigation.

Incident archive

Open the case files.

06 published investigations
INC · 001
PublishedIdentityReconnaissance

Coordinated SSPR reconnaissance

A distributed probe across password-reset infrastructure: the alert pattern, infrastructure overlap, evidence boundaries, risk assessment, and recommended response.

404Targeted accounts54Generalized sources
Read investigation ↗
INC · 002
Public-safe TPEndpointCredential access

Endpoint malware followed by credential dumping

An unsigned execution chain establishes persistence, accesses LSASS memory, stages credential material, and begins command-and-control beaconing.

1Affected endpoint2Credentials at risk
Read investigation ↗
INC · 003
Public-safe TPExecutionPowerShell

PowerShell download chain confirmed malicious

A document launches encoded PowerShell, retrieves a second-stage script, executes in memory, and creates scheduled-task persistence.

6Execution stages11mTime to isolation
Read investigation ↗
INC · 004
Public-safe TPSocial engineeringClickFix

ClickFix attack through a fake CAPTCHA

A compromised portal seeds a clipboard command, guides the user through the Run dialog, and launches a staged information-stealing chain.

7Correlated stages9mTime to isolation
Read investigation ↗
INC · 005
Public-safe TPAWSCloud identity

AWS access-key compromise and IAM escalation

A stolen CI access key crosses its workload boundary, assumes a production role, grants wildcard privileges, and creates persistent credentials.

7Cloud attack stages12mTime to containment
Read investigation ↗
INC · 006
Public-safe TPLinuxWeb server

Linux web compromise, persistence, and credential theft

A crafted upload request leads to shell execution, a persistent systemd service, secret collection, and a confirmed outbound transfer.

8Attack stages9mTime to isolation
Read investigation ↗
Observed, not imagined

Every conclusion traces back to evidence captured during the investigation.

Uncertainty stays visible

Confirmed facts, analytical judgments, and unknowns are kept separate.

Built for decisions

Each report closes with risk, investigation delta, and prioritized action.