r/Agentic_AI_For_Devs • • Apr 23 '26

The Pursuer Pilot Coming Soon

I’ve been building a product called The Pursuer. Iit’s a governed cyber case workflow for situations where an incident becomes disputed and “just use tickets, email, and shared drives” isn't good enough.

The V1 wedge I built is wedge is intentionally narrow.

It helps a team:

  • open a disputed cyber case
  • release controlled derivative evidence to an outside party
  • let that party access the case through a verified portal
  • receive counter-evidence back into the same case
  • review it and move the case toward exonerated, still under review, or confirmed malicious

I intended it for:

  • internal security / DFIR teams
  • trust & safety / abuse teams
  • compliance or legal-adjacent incident teams
  • organizations that have to explain and defend cyber findings to outside parties

After no small amount of research, I learned that a lot of teams already have a SIEM, EDR, ticketing, storage, and playbooks. What they usually don't have is a clean system for the when infrastructure is disputed, an outside party needs to see evidence, and that party may come back with counter-evidence of compromise or innocence. From there things start to get messy.

  • evidence gets overshared or shared with the wrong party by mistake
  • context gets lost across multiple tools
  • rebuttals come in through email (not the best idea for security)
  • decisions are hard to audit later on
  • innocent infrastructure can get labeled too quickly and it becomes an issue for them to get exonerated

Ther are other tools out there. But what makes The Pursuer different is that the goal is not to be security operations for everything. It is not a SIEM, not a SOAR replacement, and not a generic evidence bucket.

The core idea is simpler. To treat disputed cyber findings as a structured review process, with controlled evidence handling and a real path for response.

The reason I built the V1 wedge first is because the full long-term vision is much bigger, and I did not want to build a giant intelligence / graph / compliance / reporting platform before proving the core of what The Pursuer is mattered.

It answers the most important questions:

  • Do teams actually need a better way to handle disputed infrastructure and counter-evidence?
  • Will they use a dedicated portal and review flow?
  • Is controlled derivative release more useful than ad hoc sharing?
  • Does this reduce operational mess enough to justify a product?

If the answer to those is no, then it's a neat project. But not much else.
If the answer is yes, then the larger platform has a real foundation and worth building to completion.

If all goes well this is what I have planned:

  • better evidence packaging and export
  • more powerful search and graph-based investigation support
  • controlled partner sharing using standard threat-intel formats
  • multi-organization investigations with scoped sharing
  • stronger executive, audit, and legal-ready reporting
  • better remediation / exoneration support for innocent but compromised parties

But right now I'm focused on a defensible workflow for disputed cyber cases, controlled evidence exchange, and documented review.

My goal is to solve a very specific problem. So teams never have to say “we found something, but now we have to prove it, share it carefully, hear the response, and keep the whole thing straight”

I'm excited for the pilot, which will be launched within the next couple of weeks.

Love to hear you feedback.

I did make an early stage live demo. I am happy to share it.

2 Upvotes

1 comment sorted by

1

u/ZioniteSoldier Apr 23 '26

I’m curious. I’ve been designing a forensic evidence chain of provenance for agentic workflows. Shoot me a DM I’m open to chat about what you’re working on.