https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dspm_investigation_agent-83ec8c7e-9885-4f46-bd13-0cbf4e4916ad/a9a2b7f0-a0e2-4996-86f1-335191541d79_cyeraicon216.png

Cyera DSPM Investigation Agent

durch Cyera

Streamline securing your sensitive data risks with Cyera's powerful investigation agent.

Cyera DSPM Investigation Agent

An AI-powered Security Copilot agent that helps security analysts investigate data security posture issues across cloud and SaaS environments. Run on-demand from the Agent Management view to identify at-risk data assets, analyze security gaps, and receive actionable remediation guidance.

Agent Tasks

- Identify riskiest data assets based on security issue types and severity
- Analyze asset distribution across cloud providers (AWS, Azure, GCP, SaaS)
- Investigate open security issues and violations
- Calculate risk scores for data assets using weighted severity (Critical×100 + High×50 + Medium×25 + Low×10)
- Generate security posture reports with actionable recommendations
- Track asset security configurations (encryption, public access, sensitivity)
- Distinguish between unique issue types and total records at risk

Agent Workflow

**How to Use:**
1. Navigate to Agent Management view in Security Copilot
2. Select "Cyera DSPM Investigation Agent"
3. Click "Run one time"
4. Provide investigation parameters:
- **UserRequest** (required): Describe your investigation (e.g., "Show top riskiest assets")
- **DaysLookback** (optional): Number of days to look back for issues (default: 30)
5. Review results with executive summary, data tables, and recommendations

**Inputs:**
- Data Tables: CyeraAssets_CL, CyeraIssues_CL from Microsoft Sentinel/Log Analytics
- UserRequest: Natural language investigation request parameter
- DaysLookback: Time range for recent issues (default: 30 days)
- Queries multiple cloud providers: AWS, Azure, GCP, and SaaS platforms

**Outputs:**
- Executive summary with key statistics and critical findings
- Top riskiest assets with risk scores, issue type counts, and records at risk
- Asset distribution by cloud provider with security metrics
- Open security issues with severity, remediation advice, and affected assets
- Distinction between issue types (unique security findings) and records at risk (affected data volume)
- Actionable recommendations prioritized by risk

Prerequisites

- Microsoft Security Copilot with active SCU capacity
- Microsoft Sentinel workspace with Log Analytics
- Cyera DSPM data ingested into CyeraAssets_CL and CyeraIssues_CL tables
- Agent installed and configured with workspace connection

Key Features

- **Execution-Based**: Run on-demand from Agent Management view with specific investigation parameters
- **Risk Scoring**: Automatic calculation of asset risk scores based on unique issue types and severity
- **Data Model Clarity**: Distinguishes between issue types (unique findings) and records at risk (data volume)
- **Multi-Cloud Coverage**: Analyze assets across AWS, Azure, GCP, and SaaS platforms
- **Security Gap Identification**: Highlights unencrypted sensitive data and publicly accessible assets
- **Actionable Remediation**: Provides specific remediation advice for each security issue
- **Provider Comparison**: Compare security posture across different cloud providers
- **Flexible Investigations**: Parameterized requests for different analysis types

Typical SCU Consumption

Approximately 0.5-1.0 SCU per agent execution, depending on investigation complexity and data volume.

Auf einen Blick

https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dspm_investigation_agent-83ec8c7e-9885-4f46-bd13-0cbf4e4916ad/263e46f9-2236-4165-baa0-658f003d6685_trailer.png
/staticstorage/20260315.2/assets/videoOverlay_62a424ca921ff733.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dspm_investigation_agent-83ec8c7e-9885-4f46-bd13-0cbf4e4916ad/64b9b0fb-8cd4-4605-8445-183a94ca34c1_screenshot1398.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dspm_investigation_agent-83ec8c7e-9885-4f46-bd13-0cbf4e4916ad/d943441d-b1f5-48f3-bce8-c36079ab7344_screenshot1401.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dspm_investigation_agent-83ec8c7e-9885-4f46-bd13-0cbf4e4916ad/3de4ea2f-1b5b-4256-b653-067482e69c3d_screenshot1402.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dspm_investigation_agent-83ec8c7e-9885-4f46-bd13-0cbf4e4916ad/8e04c454-9c75-4aea-b471-067e78660827_screenshot1403.png
https://catalogartifact.azureedge.net/publicartifacts/cyera1658314682323.cyera_dspm_investigation_agent-83ec8c7e-9885-4f46-bd13-0cbf4e4916ad/2100e01e-f030-476c-95c6-827596014b4a_screenshot1405.png