Command Zero’s Throughline Turns Closed Cases Into Living Investigations

Estimated reading time: 5 minutes

Command Zero wants security investigations to stop dying young. The Austin-based company previewed Throughline this week, ahead of Black Hat USA 2026. The company calls it a “living investigation” capability. Related alerts merge into one evolving case. When new evidence arrives, closed cases reopen. The verdict gets re-examined with everything on the table.

The pitch targets a structural flaw in SOC operations. Attackers work across weeks. Investigations close in hours.

“CISOs don’t want yet another tool that demands a month of learning or data migration before it proves its worth,” said Dov Yoran, co-founder and CEO, in the announcement.

Command Zero says early adopter testing cut the verdicts analysts had to consider by up to 41 percent. That figure is company-reported. No methodology has been published.

Illustration of scattered security alerts connecting into a single investigation line, representing Command Zero's Throughline announcement. As reported by cyber insurance news

One Case, One Evolving Verdict

CINI spoke with co-founder and CTO Dean De Beer and VP of Marketing Erdem Menges ahead of the announcement.

Menges framed the problem as a failure of memory. Traditional alert analysis takes a snapshot, renders a verdict, and moves on. Benign findings get buried.

“When you think about how alerts are processed today, it’s always point in time,” Menges said. “You get an alert, you do an analysis, you close the case, you move on. Sophisticated attackers will have 500 low-severity alerts, and they will not be detected. But if you combine all those alerts, you can see what’s going on.”

Throughline reopens the case instead. Each new alert triggers fresh analysis of the full history, looking back roughly 30 days. Five exploitation attempts against one server, each with a different IP and incident ID, become one investigation. That example comes from the company’s own testing.

Show Your Homework

De Beer spent much of the conversation on a less glamorous word: citability.

See also  Cyber Monitoring Centre Launches UK Cyber Event Classification System

The platform structures every investigation as a decision graph. Each step proves or disproves a small hypothesis. No citation, no conclusion.

“In any industry that requires auditability and validation, you cannot make a decision without being able to cite the data associated with that decision,” De Beer said. “If you can’t cite information, you’re unable to prove it.”

That discipline matters for insurers and regulators as much as analysts. An evolving verdict is only useful if you can show why it evolved. Command Zero also runs a dedicated efficacy team. When customers overturn a verdict, humans and systems review the miss.

The Cyber Insurance Angle

Command Zero did not build Throughline for the insurance market. Menges was candid about that. But the fit is hard to ignore.

The industry keeps inching from annual questionnaires toward continuous assessment. A living investigation trail is, in effect, continuously generated evidence of security maturity.

“From a cyber insurance perspective, it becomes a way to reduce and manage risk for both the insurance companies and for consumers,” Menges said. “I see this as direct risk reduction, which will have reassurance and cost improvements for both parties.”

Underwriters should treat that as a thesis, not a proof. But the direction of travel is familiar to anyone reading loss-control requirements lately.

Where the Conversation Widened

The briefing started with a product. It ended somewhere bigger. Asked about AI agents making mistakes, De Beer did not reach for reassurance. He reached for engineering.

“We’re dealing with intent- or context-driven assistants today, which are very different to a classic deterministic system,” De Beer said. “You end up with graduated layers of trust that have to be built in. We’re in a world where prototypes become production very quickly.”

See also  2025 Cybersecurity Trends - AI Risks and Soaring Attack Costs

That last line should hang over every AI procurement meeting this year.

The underlying idea has an Enlightenment pedigree. David Hume argued in 1748 that a wise man proportions his belief to the evidence. His contemporary Thomas Bayes turned the instinct into mathematics: revise your conclusions when new information arrives. The throughline is, in effect, Bayesian reasoning with a case file. The philosophy is old. The automation is the news.

Attempted Crime Is Still Crime

Menges offered the argument that stayed with us longest. Society treats attempted burglary, theft, and murder as serious offenses. Attempted cybercrime barely registers.

“Attempted cybercrime is not even seen or registered as bad behavior,” Menges said. “When a big bank gets attacked and blocks it, this happens multiple times a day. We don’t even hear about it. I think we need to hear more. Attempted crime is criminal too.”

The under-reporting problem in cyber runs deeper than breach disclosure. It starts with the millions of attempts nobody counts at all.

The Analyst’s New Constituent

De Beer closed with a prediction about who, or what, security products will actually serve.

“The constituent for our product in the near future will be the agent,” De Beer said. “The agent will be the interface that the analyst interacts with. The product should be invisible until it’s not.”

He sees trust relationships, like today’s information-sharing communities, moving to the agent level. Products hunting across organizational boundaries. Reports assembling themselves at line speed.

Whether that future arrives on schedule is anyone’s guess. Command Zero shows its hand at Black Hat USA 2026 in August.

FAQ – Command Zero Throughline

How does Throughline differ from correlation rules?

Correlation rules match patterns someone predicted in advance. Command Zero says Throughline re-analyzes the entire case with each new alert, grounded in an organization’s own context, policies, and prior investigations.

Why does this matter for cyber insurance?

A continuously updated investigation trail amounts to ongoing evidence of security maturity. That aligns with the industry’s shift from annual questionnaires toward continuous risk assessment. Command Zero positions it as risk reduction for insurers and insureds alike, though the insurance use case remains untested.

What results does Command Zero claim?

The company reports that early adopter testing reduced verdicts requiring analyst attention by up to 41 percent. The figure is self-reported, with no published methodology.

Leave a Comment

×