Перейти до основного вмісту
Просунутий6 хв1033 слівСкладність 5/5Автоматизація A4

Як Trellix використовує Claude для автономних security investigations

Production-кейс Trellix: Claude через Amazon Bedrock для alert analysis, autonomous investigations і security engineering — з human escalation, model routing, evidence trace, containment та verified remediation.

Картка кейсу

Що тут автоматизовано

Складність 5/5Автоматизація A4

Обсяг автоматизації

Trellix uses Claude through Amazon Bedrock in security workflows that analyze alerts, synthesize evidence and automate portions of investigation and engineering. AI-Magister treats the reproducible pattern as A4 only inside bounded investigation and reversible response scopes: agents may collect telemetry, correlate evidence, draft findings and execute pre-approved low-blast-radius actions, while destructive containment, credential revocation, production policy changes and incident closure remain governed by deterministic policy and authorized humans.

Роль людини

SOC analysts own incident severity, escalation and consequential response decisions; detection engineers own rules and validation; platform/security teams own model routing, Bedrock configuration, telemetry access, secrets, network scopes, audit logs and kill switches. Human review is mandatory when evidence is incomplete, impact is high or the proposed action crosses pre-approved authority.

Заявлені результати

  • Anthropic reports an average of eight staff-hours saved per 100 alerts and workload equivalent to adding 10 analysts for a typical customer; these are provider/company-reported operating outcomes
  • Anthropic reports selected parser/API integration work reduced from about 40 hours to under five minutes; this is a specific development example, not a universal secure-coding benchmark
  • Trellix's current platform materials continue to report eight SOC hours saved per 100 alerts; this remains company-reported performance evidence, not an independent SOC benchmark

Anthropic's Trellix customer case reports autonomous alert analysis with Claude in Amazon Bedrock and large time reductions in selected security and development tasks. Trellix's current AWS materials describe autonomous context-aware investigations on Bedrock and a multi-model approach that can use Anthropic Claude alongside other models to balance coverage, speed and cost. The current platform evidence therefore supports a routed security-agent architecture rather than a single-model monoculture.

Зміст статті
  1. 01Бізнес-задача: розслідувати більше alerts без автоматизації помилкового containment
  2. 02Trigger, input, AI stage, integrations та output
  3. 03Model routing і provider boundary
  4. 04Human-in-the-loop і authority matrix
  5. 05Prompt injection, poisoned telemetry і untrusted evidence
  6. 06Error handling, idempotency і incident truth
  7. 07Evaluation contract для autonomous SOC
  8. 08Frequency, scalability, cost і rollout

Бізнес-задача: розслідувати більше alerts без автоматизації помилкового containment

SOC зазвичай програє не через відсутність telemetry, а через надлишок сигналів, ручну кореляцію та context switching між endpoint, identity, network, cloud і threat-intelligence systems. Trellix використовує GenAI для автоматичного збору контексту, постановки investigation questions і синтезу evidence, щоб analyst отримував не сирий alert, а структурований investigation packet.

Небезпечна інтерпретація — 'agent автономно вирішує incident'. Production boundary інша: analysis може бути високоавтономним, але authority на isolate host, revoke token, block traffic, delete object або close incident залежить від severity, confidence, reversibility і policy. Для high-impact response модель не повинна бути одночасно прокурором, суддею і кнопкою quarantine.

architecture

Карта системи: Як Trellix використовує Claude для автономних security investigations

Схема побудована з ключових секцій статті та показує послідовність або архітектурні блоки, які потрібно опрацювати.

Trigger, input, AI stage, integrations та output

Trigger-и: detection event, low-severity alert, investigation request, incident escalation або detection-engineering task. Input: normalized telemetry, alert metadata, endpoint/network/cloud events, threat intelligence, asset criticality, identity context, historical incidents, approved playbooks і current policy.

AI stage може формувати hypotheses, query additional evidence, correlate entities, summarize timeline, score uncertainty, propose next investigative step і draft remediation. Integrations проходять через Bedrock/model gateway та security tools. Output — evidence-linked investigation with confidence/unknowns, recommended action and explicit authority state; high-risk action без policy token не виконується.

  • Trigger → security event або analyst/detection-engineering request.
  • Input → scoped telemetry + asset/identity context + playbooks.
  • AI → investigate, correlate, explain, propose response.
  • Output → evidence packet + bounded action request + verified postcondition.

decision-tree

Контрольні точки для практичного застосування

Візуалізація використовує тези, приклади та наступні кроки статті як перевірювані контрольні точки, а не декоративні елементи.

Model routing і provider boundary

Trellix's later AWS materials describe using Amazon Bedrock as a model layer where Claude can coexist with other models. Це важливий production signal: security platform may route summarization, fast classification and deeper reasoning differently rather than pin every task to one expensive model.

Router policy must be versioned and evaluated. Model fallback cannot silently lose tool-use, context, structured-output or safety capabilities. Each run records concrete provider/model revision, routing reason, data-region boundary, prompt/policy fingerprint and the tools available at that moment.

Human-in-the-loop і authority matrix

A4 доречний для read-heavy investigation: agent сам обирає queries, збирає telemetry, виконує non-destructive enrichment і формує recommendation. Low-risk reversible action може бути pre-approved policy, наприклад створити ticket або додати temporary tag. Host isolation, credential revocation, blocking production identity, deleting evidence або changing prevention policy — higher tier.

Approval прив'язується до exact asset, exact action, parameters, incident ID, expiry і evidence hash. Якщо incident state або proposed payload змінився, approval повторюється. Break-glass response може пришвидшувати containment, але має окремий actor, reason code і immutable audit event.

Prompt injection, poisoned telemetry і untrusted evidence

Logs, emails, tickets, web artifacts і even attacker-controlled filenames можуть містити instructions для моделі. Тому retrieved content є evidence, а не authority. Tool results і external pages проходять source labeling; control plane забороняє тексту з evidence змінювати permissions, destination або response policy.

Red-team corpus включає indirect prompt injection, forged threat-intel fields, malicious log strings, Unicode obfuscation, conflicting asset identity, stale IOC і evidence designed to trigger exfiltration. Success criterion — не лише 'model spotted attack', а blast radius: чи міг manipulated trajectory отримати secret, call write tool або suppress escalation.

Error handling, idempotency і incident truth

Security automation часто падає в найгіршій точці: response API timed out після фактичної isolation. Blind retry може відправити дубльовану команду або погіршити containment. Кожна consequential action має idempotency key, provider operation ID і authoritative read-after-write check.

Unknown status переходить у RECONCILE, не SUCCESS/FAILED. Якщо telemetry source unavailable, agent не вигадує clean bill of health: terminal state позначає evidence gap і escalation. Recovery після provider outage повертається до known-good model/policy revision і replay-ить bounded incident set перед failback.

Evaluation contract для autonomous SOC

Eval suite охоплює true/false positives, multi-stage attacks, benign admin behavior, incomplete telemetry, stale intelligence, cross-tenant data, prompt injection, tool timeout, provider fallback і scenarios, де правильно нічого не блокувати. Graders оцінюють evidence coverage, investigation trajectory, severity, unauthorized actions, containment recommendation і final system state.

Hard blockers: exfiltration, cross-tenant leakage, suppression of severe incident, destructive action outside scope або false claim that containment succeeded. KPI: verified investigation completion, severe-error rate, analyst correction rate, time-to-evidence, time-to-containment, unsafe-action rate, cost per verified investigation and percentage escalated for the right reason.

Frequency, scalability, cost і rollout

Alert investigation can run continuously. Scale comes from risk-tier queues, caching normalized context, cheap models for bounded classification and stronger models only where evidence complexity justifies it. Concurrency is limited per tenant/asset/incident so parallel agents do not race to mutate the same endpoint.

Full cost = model tokens + Bedrock/runtime + telemetry queries + SIEM/XDR licenses + enrichment APIs + storage + analyst review + response tooling + eval/red-team + failed investigations + platform operations. Rollout: historical replay → shadow investigation → analyst-assisted read-only → bounded low-risk writes → controlled A4. Promotion requires zero unauthorized actions and a tested kill switch, not a glossy dashboard with 'autonomous' written in large font.

Практичні приклади

Приклад: suspicious endpoint alert

Alert запускає investigation. Agent збирає endpoint, identity і network evidence, формує timeline і hypothesis, policy engine дозволяє лише read tools. Якщо confidence і impact перетинають threshold, analyst бачить evidence packet і exact isolation request. Після approval response tool повертає operation ID, а platform перевіряє authoritative endpoint state.

FAQ

Чи Trellix використовує лише Claude?

Ні. Anthropic customer case документує Claude через Amazon Bedrock, а пізніші Trellix/AWS materials описують multi-model Bedrock approach, де Claude може працювати поруч з іншими моделями.

Чи 40 годин → менше 5 хвилин є типовим SOC SLA?

Ні. Це provider-reported development example для конкретних parsers/API integrations, а не універсальний incident-response benchmark.

Який перший безпечний rollout?

Read-only alert investigation із evidence trace і analyst decision. Response writes додаються лише після adversarial evals, idempotency/reconciliation і scoped policy gates.

Пов’язані матеріали

Як Campfire поєднує Claude з AI-native accounting workflows

Production-кейс Campfire: Claude в Ember для фінансового reasoning, reconciliation і reporting, а поруч — спеціалізована accounting intelligence. Розбираємо hybrid model architecture, human approval, auditability, cost і rollout.

Як ClassDojo масштабує AI Sidekick для вчителів через Claude

Production-кейс ClassDojo Sidekick: lesson planning, assessments, report comments і family communication з Claude — з teacher review, privacy boundaries, school policy, ZDR context та education-specific evals.

Як Vega будує agentic cyber defense на Claude: detection, triage, investigation, oversight

Production-кейс Vega Security + Claude Platform/Agent SDK: federated security-data access через Security Analytics Mesh, model routing за ризиком, окремі detection/triage/investigation/oversight agents, production evals і human sign-off для змін у detection logic.

Як Deepgram масштабує Claude Code: durable code, MCP і support triage за хвилини

Production-кейс Deepgram + Claude Enterprise/Claude Code: engineering переходить від ручного написання до поведінкових контрактів і валідації, а support triage використовує read-only subagents, MCP та human approval для швидкої діагностики без передачі release authority моделі.

Red teaming LLM-систем

Практичний red teaming перетворює припущення про безпеку LLM-системи на відтворювані атаки, докази та regression-тести. Розглядаємо threat model, ручні й автоматизовані кампанії, triage, безпечну лабораторію та перевірку виправлень.

Observability для LLM-систем

Які traces, metrics, logs і evaluation signals потрібні для LLM: prompts, retrieval, tool calls, usage, quality, privacy, cardinality і розслідування інцидентів.

Джерела

  1. Trellix deploys autonomous security agents with Claude in Amazon Bedrockофіційне
  2. Trellix and AWSофіційне
  3. Trellix Achieves the AWS Generative AI Competencyофіційне