UnderDefense, a cybersecurity company delivering Agentic AI SOC and Compliance AI to enterprise clients across the US and EU, today announced the launch of Incidents Timeline 2.0. The new capability captures every automated action, AI agent decision, and analyst determination in real time, giving security teams a complete chronological record of every incident that runs through the platform.
Security teams have long faced the same challenge after an incident closes: reconstructing a response timeline from disconnected systems to answer questions from auditors, cyber insurers, or the board. Incidents Timeline 2.0 removes that step. Every action is captured automatically as the incident runs.
"You can only trust autonomous security tools when you can see how they think," said Nazar Tymoshyk, Founder and CEO of UnderDefense. "Every AI reasoning step, every analyst decision is now captured as it happens. When a CISO needs to answer for the quality and speed of a response, the proof is already there."
What Incidents Timeline 2.0 Delivers
Every incident now has a complete log from first alert to final verdict, recorded automatically as it runs, with no manual reconstruction. Every run of the AISOC Tier 1 Agent shows its individual steps: inputs analyzed, reasoning path, execution time, and conclusion. Security leaders can see not just what the AI decided, but how it reasoned. All SIEM queries, playbook executions, and enrichment steps are visible, including checks that were skipped and why.
Mean Time to Detect (MTTD) and Mean Time to Triage (MTTT) are calculated and displayed directly on each incident, with the calculation method shown. Every action is timestamped and exportable for internal reviews, auditors, cyber insurers, or board presentations, without preparation.
Analyst verdicts include reasoning, risk levels, and recommended next steps. Security teams can ask follow-up questions directly inside the incident without switching tools.
Common Scenario: The Morning After an Incident, A Call from the CTO
It is a situation most security teams have been in. Tuesday, 8:40 AM. An incident triggered overnight. An hour later, the CISO receives a call from the CTO. The question is always the same: "Did we handle this properly, and were we fast enough?" With Incidents Timeline 2.0, the CISO opens the incident and sees the complete overnight story, tracked second by second: the exact moment the alert fired, when the Concierge ticket opened, what the AI agent verified, when human analysts joined, and why they reached their verdict. In less than two minutes, the CISO has the answer and the proof to show for it.