A SOC analyst spots suspicious activity from an internal IP. They need to understand what is happening. They open their SIEM's built-in AI assistant and type: "Tell me about 192.168.0.10."
The assistant checks the entity store. Nothing. The analyst rephrases: "This is in our environment. Can you please check the logs and walk me through what's going on with this device?"
A moment later, the assistant returns a summary. The host is involved in Windows file sharing and remote administration. It is performing operations with different users. And that is where it stops. The information is accurate, but surface-level, and not enough to drive an investigation forward.
Now watch what happens when the same analyst asks the same question of an agent built with the Corelight Agent Builder Library.
Same data, same question, completely different investigation
The Corelight Threat Hunter agent, built using resources from the Agent Builder Library, immediately goes deeper. It forms a hypothesis: the device may be compromised and involved in lateral movement. It identifies potential ransomware activity and flags possible data exfiltration. It pulls IDS alerts, maps other hosts that may be involved, provides a timeline spanning the activity window, and lays out concrete next steps the analyst can take, including follow-up pivots on related IP addresses.
The investigation took about the same amount of time. But the depth of the output was on a completely different level.
The difference is not the model. Both agents had access to the same underlying LLM capabilities. The difference lies in the investigative expertise guiding the agent's reasoning: what to look for, how to pivot between entities, which protocol fields matter, and which patterns indicate real threat activity versus noise.
What is the Corelight Agent Builder Library?
The Agent Builder Library is a set of resources you can drop into any AI agent framework or SIEM that supports agent building. In the demo, we used Elastic's agent builder, but the resources work with any agent.
The library includes:
- Investigation playbooks that walk agents through structured decision trees for specific alert types and threat scenarios
- Schema documentation that tells an agent what each field means and why it matters during an investigation
- Custom skills and tools designed for import into agent platforms
- Prompts and reasoning logic that keep agents on a structured investigative path instead of open-ended summarization
In the demo, you can see the custom instructions and skills copied directly from the repository into the Elastic agent builder's configuration. Each component can be modified to fit your specific environment and threat model. For the demo, we used the defaults, and the results speak for themselves.
Why generic AI assistants fall short on network investigations
This is not a knock on any particular SIEM AI assistant. The gap the demo exposes is architectural, not product-specific. General-purpose AI assistants are designed to answer broad questions across an entire platform. They are very good at that job. But network investigation is a specialized discipline with its own logic, pivoting patterns, and decision trees that have been refined over years of real-world incident response.
When an analyst asks about a suspicious IP, a general assistant looks for what it can find and summarizes it. An agent with investigative expertise knows to check for lateral movement indicators, correlate IDS alerts, determine the timeline of the compromise, assess whether the host is the attacker or the victim, and recommend specific next steps to advance the investigation.
That expertise does not emerge from a larger model or a better prompt. It comes from structured, purpose-built investigation logic authored by people who have spent years doing this work.
Try it yourself
The Corelight Agent Builder Library is freely available to all Corelight customers. You can access the full repository, pick the playbooks and skills relevant to your environment, and have a specialized investigation agent running in your SIEM in under an hour.
The demo in the video above uses Elastic, but the same resources work with any platform that supports custom agent building. You can also use your own local AI models, so internet access is not a requirement.
If you want to see what your SOC's AI agents can do when they have real network forensics expertise behind them, contact your customer success manager.
Book a demo to see the full picture.