free plan
AirMDR FAST - Free self-serve AI alert investigations
Get 100 free AI-powered alert investigations.
Start with sample alerts. Connect read-only when ready. No sales call.
Try our sample alerts before connecting anything
Review evidence, reasoning, and next steps
Most investigations complete in under 5 minutes
100 investigations free.
No Credit Card. No Pressure.
Up and running in 60 minutes
40+ integrations
Get started in three steps.
Built for lean teams that need fast, high-quality alert triage.
- Create your free account
Use your browser. No download or credit card required. - Try sample alerts or connect your stack
Start with our sample alerts, or connect one of 40+ supported sources when ready. - See your first investigations
Our AI Agent, Darryl, reviews alerts, explains the evidence, and recommends what to do next.
INTEGRATIONS
Works with your EDR, SIEM, cloud, identity, email security, and more.
40 integrations included free. Cover all your integrations with a paid plan.
AbuseIPDB
Active Directory
Astrix
AWS
Cisco AMP
Cloudflare
CrowdStrike
Datadog
Duo Security
GCP SCC
GitHub
Chronicle
G Workspace
Incident.io
Jamf Pro
Jamf Protect
Jira
Mimecast
M365 Quarantine
MS Defender
MS Teams
MS Sentinel
Okta
OpenAI
OpenCVE
PagerDuty
Push Security
QRadar
Rapid7
Recorded Future
SentinelOne
Slack
SumoLogic
Darryl delivers 20x reduction in manual effort.
CASE STUDY
ENGINEERING & CONSTRUCTION
1,000 EMPLOYEES
2-PERSON IT TEAM
150 ALERTS/WEEK
BEFORE DARRYL
- 42+ Hours per week in manual operations
- 40+ hrs/week on triage on investigation
- 2 hrs/week responding to the 5 real issues
WITH DARRYL
- 02 Hours per week responding to real issues
- Automated Focus State: Darryl handles all triage & investigation
- 2 hrs/week responding to the 5 real issues
What changes when Darryl joins your team.
| CAPABILITY | Before Darryl | With Darryl |
|---|---|---|
| Real Threats vs Noise | Real threats buried in the queue. | The 3–5% that matter, surfaced and prioritized. |
| Investigation Speed | Alerts pile up. Many go unreviewed. | 95% completed in under 5 minutes. |
| Investigation Quality | Shallow, inconsistent, or skipped when the queue gets heavy. | Thorough and consistent, every alert, every time. |
| Transparency | Answers without the work behind them. | Every finding documented. Coverage, MTTI, and case quality in one dashboard. |
| Response Guidance | What to do next is not always clear. | See what was reviewed, what was found, and what to do, every time. |
Autonomous investigation Human-controlled response.
Investigates
Reviews alert and context to determine what happened and whether it needs attention.
Recommends
Explains what looks noisy, risky, or worth escalation, with evidence and a suggested next step.
YOU
You choose what to ignore, escalate, investigate further, or act on.
DATA & SECURITY
Clear controls.
Your data stays isolated and encrypted end to end.
Least-privilege access, audit-logged on every action.
Configurable retention. You decide what is kept and where.
Audit-ready by design with SOC 2 controls built-in.
Start free. Expand when you need more.
Start for Free
AI investigations for up to 100 alerts.
Add More
volume or integrations if needed.
Move to our AI MDR
Managed AI SOC with 24/7 human coverage and escalations when needed.
See what AI-powered investigation can do with your alerts.
Create your free account. Connect a source. Run your first investigation.
100 investigations free, then $4/investigation.
FREQUENTLY ASKED
Everything you need to know.
What's Included
What is AirMDR FAST?
AirMDR FAST is a self-serve way to experience autonomous alert triage.
Connect a source, and Darryl – AirMDR's AI analyst – investigates your alerts: reviewing context, checking connected sources, evaluating evidence, assigning a disposition and confidence score, and recommending next steps. Most investigations complete in minutes. You review the work and decide what to do.
What does Darryl do?
Darryl investigates security alerts.
For each alert, Darryl reviews alerts and comes up with questions it needs to answer to determine if the alert is really malicious or benign. It then tries to fetch the data needed to answer those questions using the systems it has access to. Once it has gathered the full context, it analyzes the evidence, determines what likely happened, assigns a disposition and confidence score, and recommends what to do next.
Who is FAST built for?
FAST is built for hands-on security teams that need help investigating alerts faster.
Getting Started
How do I get started?
Sign up, connect an alert source, and let Darryl start investigating. FAST is designed to move quickly: connect a source, review Darryl's investigation, and decide what to do next.
What if I need help setting up integrations?
You can contact fast@airmdr.com.
Upgrade & Pricing
How many free investigations do I get?
You get 100 free investigations.
What happens after I use my 100 free investigations?
You can still view your previous investigations, but you cannot run new investigations until you add more capacity or upgrade.