Leon AI
Meet Leon
Booli’s Artificial Intelligence entity, “Leon” (short for “LeonAIdas”) was incorporated at the inception of the Booli solution. He is NOT an ‘add-on’ or slideware. Leon is a constantly evolving assistant who is helping enrich our identity-centric detection and response.
Leon represents the conglomeration of public and private agentic and GenAI (RAG) solutions in the Booli platform.
Analysts and threat hunters can interact with Leon directly via chat interface persistent in the UI as they navigate through investigations as well as create new searches and analyze user ‘stories’ to answer the ‘who, what, when and where’ questions.

Your Force Multiplier in the SOC
Leon AI is designed to think like a seasoned SOC operator — correlating identity signals, surfacing anomalies, and guiding every investigation with speed and clarity.
Leon isn’t a bolt-on chatbot — it’s natively wired into the Booli architecture, built to:
- Summarize complex incidents in seconds
- Triage alerts and reduce false positives
- Assist with root cause analysis and impact assessments
- Surface recommended actions based on historical and real-time behavior
Key Features of Leon AI
Leon transforms raw data into actionable security outcomes, reducing human error and operational costs.
/01
Enrich Alerts
- Review full context of alert (machine, user, action, impact, etc)
- Review pre-alert and post-alert status for user, machine, IP address
- Provide an opinion on the score for the analyst to follow up on
/02
AI Scorecard
Assists analysts and threat hunters to identify ‘low and slow’ threat actor activities or IOC’s where human-curated use cases may need to be rescored or reconsidered.
/03
Enrich Alerts to AI Investigation
- Review past logs and alerts for anomalies and repetitive behavior
- Pattern match against known MITRE attack patterns
- Query IOCs w/ external sources (eg MISP, etc)
- Summarize context, alert and findings into the investigation case
/04
Response & Remediation
- Provide contextual response
- Automate remediation (through agents deployed into the environment)
- Deliver a structured report back to stakeholders
- Feed learnings back into detection & monitor for future flare ups
Booli — where identity comes first, integrations are fast, and your team finally gets the clarity and control they need.