Use it after a clue
Start from an alert, IP, account, process, path, Java service, or vague anomaly that needs host-level evidence.
Open Investigator · Boundary comparison
Teams often ask whether Open Investigator replaces existing detection and response tools. It does not. It sits in the first-pass investigation gap after a clue appears and before humans choose containment, remediation, or escalation.
Search intent
Practical workflow
Start from an alert, IP, account, process, path, Java service, or vague anomaly that needs host-level evidence.
The product deliberately avoids containment and cleanup actions so first-pass investigation can remain reviewable.
Reports and evidence can support SIEM notes, incident tickets, customer communication, escalation, and manual remediation planning.
Common searches
The source, usage examples, contribution notes, and issue tracker live in the public Open Investigator repository.