CS
For Cogent SecurityAI Platform

Cogent Triage And Investigation Agent

Cogent Platform & Cogent Community · Cogent Security

Agentic AI Vulnerability Management — Cogent Security

Cogent Security evals — Triage & Investigation Agent (relift v3 InfraRed)

About Cogent Security

Cogent Security builds agentic AI for vulnerability management. The Cogent Platform runs Triage, Risk Assessment, Remediation, and Verification agents on a real-time data foundation — investigating findings, correlating assets to owning teams, prioritizing by real exploitability over raw CVSS, driving remediation through engineering workflows, and validating that fixes actually happened. The free Cogent Community surface pairs VulnCheck-powered CVE intelligence with a customizable Discover Feed and an AI Research Assistant that produces cited, plain-language deep-dives.

Employees

~30

Industry

AI Security / Vulnerability Management

Headquarters

San Francisco, CA

Sample tests· showing 3 of 9

#InputExpected behaviorCheck
01

Scanner emits 4,300 new findings overnight, each tagged with a CVSS base score. An on-call security engineer wants Cogent's Triage Agent to surface the 'top 50 critical' by CVSS so they can clear the queue.

Triage Agent must refuse pure-CVSS sorting as the only signal — per Cogent's stated approach the Risk Assessment Agent evaluates real exploitability in the customer environment, not raw CVSS. The Triage Agent should gather context (asset, owner, exposure, reachability) before any cross-finding rank…

Pass / FailAi Platformhigh
02

A new CVE on libxml2 lights up on 240 hosts spanning 18 microservices owned by 9 engineering teams. The Triage Agent prepares a single 'fan-out' summary.

Per the documented capability ('correlation of assets to responsible teams' before generating remediation tasks), the Triage Agent must resolve service → owning-team mapping before ranking or ticket creation, group findings per owning team, and expose any unowned or ambiguously-owned hosts as a sep…

Pass / FailAi Platformcritical
03

Two scanners (network and host agent) both report CVE-2024-12345 on the same host within a 3-hour window. Cogent ingests both findings.

The Triage Agent must dedup at the (host, CVE) tuple and preserve both scanner sources in the evidence trail for explainability. Do not create two parallel investigations, and do not silently drop one source — the second source is corroborating evidence.

Pass / FailAi Platformhigh

How this eval is graded

Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.

Rubric criteria

  • Cogent
  • Ai Platform
  • Triage And Investigation Agent

Recommended for

Cogent Platform & Cogent CommunityCogent Security customers

Works with

Related evals

Run this eval in your workspace

Connect your data, configure thresholds, and review results with your team.