https://catalogartifact.azureedge.net/publicartifacts/semperis.semperis-identity-investigation-agent-074253f0-c505-43c3-ac6f-d2901aab6552/04207561-6876-4caf-98a3-87b263bb56d4_semperisLOGO.png
Semperis Identity Investigation Agent
by Semperis
Just a moment, logging you in...
Investigates identity's security risk posture using Semperis Lightning identity graph data
Semperis Identity Investigation Agent delivers a comprehensive risk posture assessment for any identity. Built on Semperis Lightning identity graph data ingested into the Microsoft Sentinel data lake, the agent enables SOC analysts, identity security teams, and incident responders to rapidly investigate whether an identity is exposed, over-privileged, or under active threat — without writing queries or navigating multiple tools.
The agent accepts any identity identifier — display name, Distinguished Name, SID, OID, or UPN — and returns a structured security report that spans Tier-0 classification, attack path analysis with step-by-step relationship chains, Indicators of Exposure (IOEs) with severity and remediation guidance, and Tier-0 attacker status. Attack path exploitability is classified into three levels — Highly exploitable, Moderately exploitable, and Minimally exploitable — giving analysts immediate clarity on the urgency of each finding.
Semperis Identity Investigation Agent:
- Deep identity risk assessment: Analyzes an identity across Tier-0 status, inbound and outbound attack paths, security exposures, and attacker classification in a single query
- Attack path visualization: Reconstructs full attack path chains showing each step, relationship type, and exploitability level from source to Tier-0 targets
- Actionable remediation guidance: Surfaces Indicators of Exposure with severity, MITRE ATT&CK mapping, indicator scores, and specific remediation steps
Prerequisites
- Semperis Lightning data connector installed from Microsoft Sentinel Content Hub and actively ingesting data into a Log Analytics workspace. The connector requires a valid Semperis Lightning API key.
Agent Tasks
Investigate identity risk posture, Identify Tier-0 assets, Analyze inbound and outbound attack paths with step-by-step chain reconstruction, Surface Indicators of Exposure with remediation, Detect Tier-0 attacker classification, List known identities across the environment
Agent Workflow
- Input: Identity name, Distinguished Name, SID, OID, or UPN
- Output: Tier-0 status, Attack path analysis with exploitability levels, risk scores, and step-by-step relationship chains, Indicators of Exposure with severity and remediation guidance, Tier-0 attacker classification, Risk summary with prioritized critical findings
At a glance
https://catalogartifact.azureedge.net/publicartifacts/semperis.semperis-identity-investigation-agent-074253f0-c505-43c3-ac6f-d2901aab6552/0cd858a3-d763-4936-8fda-148ddd570e4e_Agent1.png
https://catalogartifact.azureedge.net/publicartifacts/semperis.semperis-identity-investigation-agent-074253f0-c505-43c3-ac6f-d2901aab6552/413016a2-e02d-4eaa-b3e4-831f118b8fcf_Agent2.png
https://catalogartifact.azureedge.net/publicartifacts/semperis.semperis-identity-investigation-agent-074253f0-c505-43c3-ac6f-d2901aab6552/91688a6a-ac29-4ba5-a36f-17eaff58268f_Agent3.png
Other apps from Semperis
Semperis Directory Services ProtectorSemperisThe industry’s most comprehensive hybrid Active Directory threat detection and response platform
+1
Applicable to:
Azure Applications
NaN out of 2
Semperis Hybrid Active Directory ProtectionSemperisGet the industry’s most comprehensive hybrid AD protection.
+1
Applicable to:
SaaS
NaN out of 2