Skip to main content

Platform Capabilities

This page summarizes what the platform can do across collection, detection, enrichment, retrieval, AI analysis, investigation, and administration.

Endpoint capabilities

  • Reads Sysmon telemetry from Windows endpoints
  • Monitors process, network, image load, file, registry, DNS, WMI, process access, and tampering events
  • Normalizes event fields into a consistent alert schema
  • Evaluates JSON detection rules locally
  • Adds process, file, signature, host, and user context
  • Queues alerts for upload when needed
  • Sends alert payloads to the backend over HTTPS
  • Reports agent status, heartbeat, OS version, registration, and active rule count

Detection capabilities

  • JSON-based rules that can be updated separately from agent code
  • Category-based rule organization aligned with attacker behavior
  • Support for logic operators such as AND and OR
  • Field/operator/value conditions such as contains, equals, matches, and in
  • Enabled/disabled state per rule
  • Severity metadata per rule
  • False-positive exclusion category for suppression logic

The live console currently exposes categories such as collection, command and control, credential access, defense evasion, discovery, execution, exfiltration, initial access, lateral movement, persistence, and privilege escalation.

Investigation capabilities

  • Alert table with search, severity filters, status filters, sorting, and pagination
  • Handled/unhandled workflow for event lifecycle tracking
  • Event details modal for process, file, network, and system evidence
  • VirusTotal lookup and re-analysis controls for hash reputation
  • Process tree view with full process chain depth
  • Command-line and PID inspection
  • Multi-alert selection and correlation entry point

AI capabilities

  • Structured AI analysis generated from alert evidence
  • Risk level and reasoning
  • Key forensic indicators
  • MITRE ATT&CK mapping
  • Confidence and retrieval signal
  • Regenerate analysis control
  • Event-level follow-up chat
  • IOC extraction when evidence contains useful indicators
  • Multi-alert correlation summary, attack-chain reasoning, combined risk, and recommended actions

Retrieval capabilities

  • Pinecone-backed retrieval for ATT&CK grounding
  • Similar-event lookup based on semantic behavior rather than only exact keywords
  • Retrieval context provided to the AI layer before response generation
  • Better consistency across repeated alert analysis

Console capabilities

  • Event overview metrics
  • Recent activity panel
  • Agent status panel
  • Detection event table
  • Agent inventory and heartbeat summary
  • Rule category manager and JSON editor
  • User management
  • Login activity audit log

Administration capabilities

  • Cognito-backed user management
  • User status tracking
  • Login/logout/failure auditing
  • Date, activity type, and user filters for login activity