Share:
How Is Legion Security Trying to Solve the Messy Middle of Security Investigations?

TL;DR: Security teams don’t always struggle because information is missing. Sometimes, the harder part is piecing together what they already know. We spoke with Legion Security about how DragonClaw is approaching that problem, and what its early use is revealing about the way security investigations actually happen.

Security teams often use runbooks, a set of instructions for investigating familiar types of incidents. But when an incident doesn’t fit those instructions, the analyst may have to piece together the answer from security tools, old cases, internal documentation, and what the team has learned from experience.

Legion Security builds AI agents that automate security operations work, from investigating alerts to managing vulnerabilities.

In July, Legion launched DragonClaw, which lets analysts and security leaders ask for what they need in plain language and routes the request to the right agents.

When developing, Legion expected analysts to ask questions like, “How many critical alerts came in overnight?” or “Are we affected by the latest vulnerability?”

Instead, analysts started asking it to “walk me through this.”

They wanted DragonClaw to piece together an entire incident, compare it with previous cases, and explain not just what happened, but why it reached that conclusion.

The Information Existed. Getting to the Answer Was the Problem

Legion kept hearing versions of that frustration from analysts. But at the same time, security leaders were coming to the company with what sounded like a different problem. They wanted to know which attacks were actually getting through, how the team’s performance was changing, or where a particular detection needed tuning. Much of that information already existed in case records and tool logs. But getting an answer still meant asking an analyst to stop, pull it together, and turn it into a report.

DragonClaw grew out of that realization. Analysts could ask for the context they needed to investigate, while security leaders could ask for answers about what was happening across their security program.

Questions That Used to Wait for the Monthly Review 

Take attack patterns. A security leader might want to know what the past week’s real incidents have in common.

Before DragonClaw, getting that answer meant comparing case records with what Legion had found during its investigations, then assembling the results manually. Andrew Silberman, VP Marketing, told SaaSTake that customers typically did this monthly at best because of the work involved.

Now, a security leader can ask DragonClaw to look across the past week’s confirmed incidents and identify the patterns showing up.

You see, false positives create a slightly different problem. Security teams already know when a detection rule is flagging too many harmless events as threats. What they want to know is what to change. According to Silberman, leaders are now asking DragonClaw to look at the previous week’s false positives, break them down by incident type, and recommend what should be tuned and why. Previously, that kind of tuning could wait for a quarterly review.

Further, incident impact pushes the idea further. After a real incident, leaders can ask DragonClaw what operational or business impact it had and what could prevent a similar attack. DragonClaw can draw on what was observed during the investigation rather than requiring someone to go back and interview the person who handled it afterward, according to Silberman.

None of these questions is new, however. What changes is how often they are practical to ask.

When an answer takes hours of manual assembly, the calendar starts deciding when it gets asked: monthly for attack trends, quarterly for detection tuning, after the fact for incident impact. With less assembly work in between, some of those questions can move closer to the work itself, while the answer can still change what happens next.

Learning From Analysts Without Copying Their Shortcuts 

Some of the context behind those answers comes from watching how Legion’s customers actually investigate. The environments themselves can vary considerably: in a May evaluation of 163 real-world decisions about which security alerts required action across eight Legion customers, the tools involved ranged from CrowdStrike and Splunk to ServiceNow, Proofpoint, Wiz, and Google SecOps.

But learning from the people working across those environments raises another problem: two analysts can handle the same alert differently.

One analyst might check something another skips. Sometimes that difference reflects expertise, whereas other times it is simply a shortcut.

Legion says it does not simply turn the most common behavior into the workflow. If most analysts skip a step that matters, the system is designed to look for the better route rather than reproduce the popular shortcut.

The security team also gets the final say. If Legion picks up a pattern that reflects a workaround, poor practice, or something that does not fit the organization’s risk tolerance, a security leader can keep it out of the workflow.

Snapshot of quote by Andrew Silberman

Observing how people work also means picking up two kinds of knowledge: the useful practices nobody documented, and the habits nobody should have copied.

The challenge, then, isn’t simply learning how an organization works. It’s deciding which parts are worth turning into the way it works next time.

With DragonClaw, Legion is also trying to take that knowledge one step further.

From Finding the Answer to Acting on It

When we asked Silberman what security leaders were doing with DragonClaw, he made another distinction: what they ask it to know, and what they ask it to do.

A security leader might ask which vulnerabilities affect the organization and stop at the answer. Or they could have DragonClaw carry the work forward by starting the process of fixing the affected systems. A phishing question, for instance, can become an investigation rather than another answer waiting for someone to act on it.

An answer can remove the search. Acting on it can remove the next handoff.

That second step is where DragonClaw moves beyond reporting. It can hand work to Legion’s other agents when a request requires more than a lookup, then carry the resulting action across the customer’s existing security tools, including older systems and tools the company has built internally.

Analysts asking DragonClaw to “walk me through this” may not have been what Legion expected first. But the request gets at what Legion has been trying to build: a system that can draw on more of what a security team has already learned. It is an attempt to connect what already exists across tools, previous cases, and the judgment analysts have built over time. In other words, they are trying to make more of that context reusable. Moreover, it also impacts what happens next. 

 An analyst can bring it back into the next investigation. A security leader can use it to spot patterns that previously surfaced only during periodic reviews. And when the answer requires action, the request can move into Legion’s other agents instead of becoming another handoff.

That makes the more interesting question around DragonClaw less about how much security work an AI agent can automate. It is whether the knowledge created during one investigation can become useful soon enough to change the next one.