Back to the overview
Agent passport

Entity Guard Investigator Agent

adaQuest · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

Entity Guardrisk verdictsThreat Intelligence
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 7 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Entity Guard Investigator Agent is a Security Copilot agent designed to investigate and enrich all entities associated with security incidents across Microsoft Defender XDR and Microsoft Sentinel.

The agent helps SOC analysts understand users, devices, IP addresses, URLs, domains, file hashes, files, and other entities involved in an incident. Instead of only summarizing the incident, it expands the investigation around each entity and provides contextual evidence, observed signals, anomalies, confidence, and verdicts.

Show the rest of the publisher’s description (38 more lines)

It correlates incident details, alert evidence, entity data, sign-in telemetry, audit context, endpoint activity, network activity, file/hash information, Microsoft Defender Threat Intelligence results, and Sentinel threat intelligence context when available.

Inputs

Entity Guard Investigator Agent requires an incident identifier and a lookback period. The identifier can refer to a Microsoft Defender XDR incident or a Microsoft Sentinel incident in the configured workspace.

Tasks

  • The agent investigates the incident in Microsoft Defender XDR and Microsoft Sentinel, extracts relevant entities, normalizes and deduplicates them, and enriches each entity by type.
  • For users, it analyzes identity context, risky user information, sign-in behavior, login failures, regions, IP usage, Conditional Access context when available, audit signals, and possible login anomalies.
  • For devices and hosts, it analyzes endpoint telemetry, observed users, logon activity, process/file context, network activity, and Defender XDR signals.
  • For IPs, it classifies private, loopback, link-local, APIPA, mapped IPv4, gateway-like, and public addresses. Public indicators are enriched with Microsoft Defender Threat Intelligence and Sentinel threat intelligence when available.
  • For URLs, domains, hashes, and files, it uses threat intelligence, Defender XDR telemetry, and Sentinel data when available to provide reputation, DNS, WHOIS, sightings, and related context.

Outputs

The agent generates a structured entity intelligence report with incident summary, source coverage, entities investigated, and per-entity findings with observed signals, insights, evidence, anomalies, confidence, and verdict.

Key capabilities

  • Investigates incidents from Microsoft Defender XDR and Microsoft Sentinel
  • Extracts, normalizes, deduplicates, and enriches discovered entities
  • Provides insights for users, devices, IPs, URLs, domains, hashes, and files
  • Analyzes sign-in behavior, login failures, regions, IP usage, and possible anomalies
  • Enriches devices with endpoint, logon, process, file, and network context
  • Classifies IPs and enriches public indicators with threat intelligence
  • Filters administrative metadata such as owner, analyst, comments, and portal links

Required products and permissions

Entity Guard Investigator Agent requires Microsoft Security Copilot and access to relevant Microsoft security data sources, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Defender Threat Intelligence when available.

Users running the agent need permissions to read incidents, alerts, entity evidence, advanced hunting data, Sentinel workspace data, Entra identity/sign-in context, audit context, and threat intelligence results.

Security Copilot Units consumption

Estimated SCU consumption per execution:

  • Small scope: about 1.2 to 2.0 SCUs for up to 5 entities, limited telemetry, and low indicator volume.
  • Medium scope: about 2.1 to 4.5 SCUs for 6 to 15 entities, multiple users or devices, and moderate identity, endpoint, Sentinel, and threat intelligence enrichment.
  • Large scope: about 4.6 to 8.0+ SCUs for more than 15 entities, multiple affected users or hosts, high telemetry volume, many indicators, and deeper correlation.

Actual SCU consumption may vary depending on tenant telemetry volume, data availability, incident complexity, enabled plugins, and entities requiring enrichment.

___

Changelog

Version 2.3.3

Added dual-source investigation across Defender XDR and Sentinel, Sentinel workspace support, deterministic sign-in analysis, Sentinel threat intelligence lookup, improved entity normalization, metadata filtering, IP classification, endpoint enrichment, and threat intelligence usage. Removed recommended actions to focus on entity intelligence.

Version 2.0.0

Production baseline release with entity investigation for Defender XDR incidents.

Version 1.2.0

Improved entity extraction, enrichment logic, report formatting, and threat intelligence context.

Version 1.0.0

Initial release.

Preview

2 images
Entity Guard Investigator Agent preview 1Entity Guard Investigator Agent preview 2

Agent build and provenance

Sign in to see the provenance.

The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.

Sign in

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyadaQuestAutomated
HQUnited States of AmericaAutomated
IndustryTechnologyAutomated
Websitehttps://www.adaquest.com/

Plans and pricing as listed

1 listed
Free Plan Offer
$0.00/month
1-month subscription

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource
License TermsLicense TermsSource

Publisher resources

2 links
Entity Guard Investigatorcatalogartifact.azureedge.netSource
Pricing
Paid
1 plan listed
Delivery
SaaS
https://www.adaquest.com/contact-us-2/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.