What happened
DigitalToday reports that S2W launched DRI, or Deep Research Investigator, an autonomous AI agent designed for criminal investigations. S2W says DRI will be embedded in its XARVIS security platform and connect information from the dark web, deep web, Telegram and hacking forums to support investigations.
DigitalToday reports that S2W described DRI as an autonomous AI agent specialized for criminal investigations. According to the outlet, the agent is intended to use real-time knowledge context assembled from data that S2W collects from cybercrime-related sources, including the dark web, deep web, Telegram and hacking forums. The report says DRI will be integrated into XARVIS, S2W’s security AI platform.
S2W told DigitalToday that investigators will be able to submit a natural-language query and have DRI select and extract relevant information from large volumes of data. The company also said the agent can combine different detection and analysis tools to produce more detailed answers. DigitalToday reports that S2W plans to introduce DRI at Cyber Summit Korea 2026, a cybersecurity event hosted by South Korea’s National Intelligence Service and National Security Research Institute, from September 16 at COEX in Seoul. The supplied report does not establish that the product is generally available, and it provides no access terms or price.
Source details: digitaltoday.co.kr ↗
Why it matters
If S2W’s description is accurate, DRI represents a shift from conventional threat-intelligence search toward an agent that can assemble investigative context and coordinate multiple analysis tools from natural-language requests. That could reduce routine information-gathering work for investigators, but the supplied report does not independently verify the system’s accuracy, safeguards, deployment status, or performance in real cases. Those unknowns are especially important when the underlying sources may include criminal, misleading or unlawfully obtained material.
The reported design could make threat-intelligence work more accessible to investigators who need to connect scattered indicators across several kinds of online sources. S2W security chief Jae-young Lee told DigitalToday that the intended benefit is to delegate cumbersome routine work to the agent while investigators focus on higher-level decisions, such as setting the direction of a case. That is a stated product goal, not an independently measured outcome.
The system’s proposed use also raises practical verification questions. Information from criminal forums and other hard-to-monitor sources can be incomplete, deceptive or difficult to authenticate, while an autonomous system that combines multiple tools may make it harder to identify how a conclusion was reached. DigitalToday’s report does not provide independent testing, error rates, case results, data-governance details or safeguards, so the product’s real investigative value and risks remain unconfirmed.
What to watch next
The next concrete milestone is S2W’s planned introduction of DRI at Cyber Summit Korea 2026 beginning September 16 in Seoul. Key unknowns include whether DRI is available beyond demonstrations, which organizations can access it, how investigators validate its findings, what human approval controls exist, and whether S2W has disclosed pricing or evaluation results.
Watch for the September 16 demonstration or introduction at Cyber Summit Korea 2026 and for evidence that DRI has moved from announcement to operational deployment. The report does not say which law-enforcement, corporate-security or other customers can use it, whether access is limited, or whether it is offered as a separate product or only through XARVIS.
Further reporting should seek details on human review requirements, audit logs, source provenance, retention and lawful access to dark-web, deep-web and messaging data. It should also clarify how DRI handles conflicting or fabricated information and whether investigators can reproduce the evidence behind its answers.
S2W said it plans to apply technologies developed for DRI to its cyber-threat-intelligence products and industry-specific AI platforms. DigitalToday reports that intention but gives no schedule, named deployments, pricing or independent assessment of those planned extensions.