Security tools can generate a high-confidence alert in seconds, but determining what happened, how far it spread, which endpoints were affected, and whether an attacker or insider was responsible can still take hours or days. This session examines how investigators can pose plain-language questions across live endpoints to identify malware, gather time-sensitive artifacts, correlate evidence, reconstruct attack activity, and scope potential insider threats without manually building every query or collection step. It also addresses the controls required when AI participates in an investigation: authorized scope, transparent actions, evidence-grounded findings, human validation, and a defensible record. Attendees will leave with a practical framework for evaluating whether natural-language investigation can shorten time-to-scope without sacrificing investigative control.