Scanner's MCP integration enables three complementary approaches to security operations:
Interactive Investigations
Guided, real-time exploration of your security data. You ask questions, your AI queries Scanner iteratively, and you refine the investigation direction as findings emerge.
Best for: Incident response, alert triage, threat hunting, following investigative leads
Write, test, and validate detection rules with your AI. Get rule suggestions, test them against your data, migrate rules from other platforms, and tune for your environment.
Best for: Building new detections, tuning existing rules, migrating from other platforms, ensuring coverage