Intent-driven detection
Describe a threat model in natural language and use agents to continuously hunt for threats across your environment, including places where you may not have central log visibility.
Cotool is an AI platform for security operations teams that automates detection, response, and threat hunting with natural-language agents.
Cotool is an AI platform for security operations teams that builds agents for detection, response, and threat hunting. The site positions it as a way to scale security work beyond headcount by automating repetitive tasks and extending coverage across a security stack.
Across the product pages, Cotool describes agents that can be created in natural language, connected to existing tools, and evaluated over time. The platform emphasizes practical security workflows such as writing or tuning detections, triaging alerts, investigating threat intel, and turning investigations into always-on agents.
Describe a threat model in natural language and use agents to continuously hunt for threats across your environment, including places where you may not have central log visibility.
Create new detections with AI-assisted authoring, apply agents to existing rules to tune false positives, and map coverage gaps against MITRE ATT&CK.
Build response agents that triage alerts, enrich tickets, investigate signals, and run playbooks with human approval points where needed.
Ingest external threat intel and your own feeds, filter relevance to your environment, investigate IOCs, and propose detections to close gaps.
Trigger agents from API, webhook, cron, Slack, or ticketing workflows, with configurable prompt, model choice, tools, and output format.
Track every agent run with searchable logs, evaluation metrics, version control, and improvement suggestions based on agent failures.
Use Cotool to describe a threat model in plain language and have agents continuously search for indicators and behaviors that static rules might miss.
Use AI-assisted authoring to create new detections, tune noisy existing rules, and map coverage gaps across the MITRE ATT&CK framework.
Use response agents to enrich alerts, triage incidents, automate playbook steps, and add human review where the workflow needs approval.
Use the threat intel feed to filter incoming intel, check whether it is relevant to your environment, investigate associated IOCs, and propose new detections.
Use evaluation, monitoring, logs, and version control to compare agent behavior over time and improve workflows with clearer lineage.
Cotool is designed for security operations teams that want to automate detection, response, and threat hunting tasks with AI agents. The site presents it as a fit for teams working across multiple security tools and log sources.
The source describes agents that can be created in natural language, run against environment context from connected tools, and produce structured outputs. Detection and response workflows can also include humans in the loop at any step.
Cotool says agents can be triggered from an API, webhook, or cron, and it also mentions native hooks into tools like Slack and ticketing systems. The exact setup process is not detailed on the site text provided.
The site says Cotool can create new detections, tune existing rules, investigate alerts, enrich tickets, perform threat hunts, and produce reports or detections from threat intelligence. It also emphasizes evaluation, monitoring, and agent version control.
The provided pages do not list a pricing plan. The pricing URL currently shows a page not found response, so pricing appears unavailable from the source material.