Accepting pilot partners · limited spots
AI triage for MSSPs and in-house SOC teams

Stop triaging alerts.
Start investigating threats.

Evidence-backed AI triage for your SIEM and XDR, with analyst review built in. Live in week one. No autonomous closures, ever.

See how it works
case_record.json — risky_signin
{
  "alert_id": "DEF-2026-0871",
  "alert_family": "risky_signin",
  "severity": HIGH,
  "verdict": "false_positive",
  "confidence": 0.88,
  "band": "high",
  "next_action": "close_with_note",
  "key_evidence": [
    "Known VPN IP — 47 prior logins",
    "MFA completed successfully",
    "Geo baseline match: London"
  ],
  "analyst_required": "one_click_confirm"
}
~70%
of L1 alerts are false positives
12 min
average analyst time per alert
< 2 sec
Triage Beacon triage time per alert
100%
analyst override control, always

Your analysts spend 12 minutes per alert.
Most of it is noise.

MSSPs and in-house SOCs hit the same wall every shift. SOAR playbooks trim the easy cases. Volume, inconsistency, and burnout stay.

🌊

Alert volume

200–800 L1 alerts per day. The vast majority is low-fidelity noise. Analysts cannot review them all without losing focus.

Severity: Critical
🔍

Manual enrichment

Analysts pivot between IP reputation, AD, host context, and SIEM consoles. Three to five browser tabs per alert.

5–10 min / alert
⚖️

Inconsistent verdicts

Different analysts close the same alert differently. No documented triage logic means quality varies shift to shift.

Severity: High
⏱️

Escalation lag

False positives pile on top of real alerts. By the time a threat surfaces, dwell time grows.

Severity: High
📝

Documentation burden

Analysts write ticket notes from scratch per alert. Without templates, context disappears when a case moves between analysts.

5–10 min / alert
🔥

Analyst burnout

Fatigue from repetitive low-value work drives attrition. Replacing a SOC analyst takes months and disrupts clients.

Severity: Medium

From raw alert to closed case
in under a minute.

Triage Beacon plugs into your existing SIEM and XDR, enriches every alert with context, and presents a structured recommendation your analyst confirms with one click.

01

Ingest

Alerts stream in from your SIEM and XDR connectors. Raw payloads are normalized into a shared canonical schema.

02

Enrich

IP reputation, user role, device compliance, host criticality, and related alerts in the past 30 days are gathered automatically.

03

Triage

The AI reasons over the evidence bundle and drafts a verdict with a confidence band and the exact fields that drove it.

04

Review

Your analyst sees the recommendation, the evidence, and the confidence, then confirms or overrides with one click.

05

Record

Case closed, escalated, or deferred. Full audit trail: verdict, override reason, and an auto-generated ticket note.

Everything analysts need.
Nothing that slows them down.

Every decision is explainable. Every verdict is overridable. Every action is logged.

🔌

Native SIEM + XDR connectors

Live alerts from your existing stack normalized into one canonical pipeline. Setup in hours, not weeks.

🧠

Evidence-backed AI

The model only uses the provided evidence bundle. It never invents facts. If evidence is insufficient, it returns inconclusive, not a guess.

🎛️

Analyst review console

Alert summary, evidence list, confidence score, recommended verdict, and override button. One focused view.

📈

Confidence scoring

Three-tier policy: ≥0.75 recommend close/monitor, 0.50–0.74 send to review, <0.50 auto-escalate.

🏢

Multi-tenant isolation

Customer A cannot see Customer B's alerts, evidence, or reports. Strict per-tenant isolation, tested and enforced. Essential for MSSPs.

📋

Full audit trail

Every verdict change, override, and escalation is logged with timestamp and actor. Searchable history for compliance and client reporting.

📊

Weekly client reports

Automated reports showing alerts processed, top families, override rate, tuning changes, and open issues, ready to share with clients.

🔍

Enrichment engine

Deterministic context first: IP reputation, user role, host criticality, and related alerts from the last 30 days, attached to every case.

📁

Case timeline

Ingestion → enrichment → AI verdict → human override → final action. A complete, auditable case history for every alert.

Risky Sign-InDefender Identity
MITRE: Initial Access · Credential Access
Privileged Anomalous Sign-InDefender Identity
MITRE: Privilege Escalation
Malware DetectedWazuh / Defender Endpoint
MITRE: Execution · Defense Evasion
Suspicious PowerShellWazuh / Defender Endpoint
MITRE: Execution
Brute Force / Password SprayDefender · Sentinel · Splunk
MITRE: Credential Access (T1110)
MFA Fatigue / Push BombingDefender · Azure AD · Okta
MITRE: Credential Access (T1621)
Phishing EmailDefender for Office 365
MITRE: Initial Access (T1566)
Credential DumpingDefender · CrowdStrike · Wazuh
MITRE: Credential Access (T1003)
Expanding this quarter : 12 families and capabilities in progress

12 more families and capabilities scoped for this quarter. Here's what's in progress.

Persistence Mechanism CreatedQ3
Ransomware IndicatorsQ3
Beaconing / C2 TrafficQ3
Mail Forwarding Rule CreatedQ3
OAuth App Consent (Suspicious)Q3
Impossible / Atypical TravelQ3
DNS TunnelingQ4
Cloud IAM Privilege ChangeQ4
Bilingual EN/FR case notesQ3
Elastic Security connectorQ3
Push-based ingestion (webhooks)Q4
Customer-deployed LLM optionQ4
Microsoft Defender
Microsoft Sentinel
CrowdStrike Falcon
Splunk Enterprise Security
Wazuh SIEM
Enrichment sources : VirusTotal, AbuseIPDB, Shodan, Entra ID, and more
VirusTotal
AbuseIPDB
Microsoft Entra ID
URLhaus
MISP
Shodan
ANY.RUN
ServiceNow CMDB
Tenable

Four outcomes.
No ambiguity.

Every triage case resolves to one of four mutually exclusive verdicts. No vague "suspicious" labels that leave analysts guessing.

✓ False Positive
⚠ True Positive
? Inconclusive
↑ Escalated

Analyst overrides are always possible. Every override feeds back into prompt tuning.

triage_beacon — suspicious_powershell.json
{
  "alert_id": "WZH-2026-4412",
  "alert_family": "suspicious_powershell",
  "severity": MEDIUM,
  "verdict": "true_positive",
  "confidence": 0.91,
  "next_action": "escalate_to_tier2",
  "key_evidence": [
    "Encoded payload: -EncodedCommand",
    "Outbound conn to 185.220.x.x (TOR)",
    "Host: critical — finance server"
  ],
  "escalation_reason": "Encoded PS + TOR egress on critical host"
}

One offer. Measurable results
in 30 days.

A focused 30-day engagement on your real alerts and real stack. No procurement maze. No annual commitment.

30-day pilot

Triage Beacon Pilot

Live AI triage on your real alerts from day one. Weekly tuning. Measurable ROI at the close.

Flat fee
30 days · scoped alert families · One-time · No renewal obligation

  • One SIEM or XDR connector from your existing stack
  • AI triage across your highest-volume alert families
  • Analyst review console with override
  • 4 weekly tuning sessions with your team
  • Full audit trail + case report export
  • ROI summary delivered at engagement close
  • Priority support throughout

Limited spots. Starts with a 30-min discovery call to confirm fit.

Built on one principle:
AI assists. Analysts decide.

We built this for security operators, not AI demos. Every design decision starts with one question: does this make the analyst more effective?

No hallucinations by design

The model only uses the provided evidence bundle. Insufficient evidence returns inconclusive, not a confident guess.

Every verdict is explainable

Analysts see the full evidence list and reasoning behind each recommendation. Nothing is a black box. Override any decision in one click.

Overrides improve the system

When analysts override a recommendation, that signal feeds back into prompt tuning. The system gets better on your specific alert mix.

Live in one week, not months

We handle the connector, schema normalization, and prompt calibration. Your first AI triage verdict runs within 5 business days of kickoff.

Deterministic enrichment first

Context is gathered via reliable lookups before the AI sees the alert. Reputation data, user roles, and host criticality are facts, not inferences.

Prompt versioning like code

Every prompt version is tracked and can be rolled back. Changes are tested against sample alert sets before they touch live triage.

🍁

Canadian data residency

Optional ca-central-1 deploy keeps every alert, case, and audit record inside Canada, aligned with PIPEDA, OSFI B-13, and Quebec Law 25 obligations.

🌐

Bilingual analyst console

The full console and auto-generated case notes are available in English and French. Per-user preference, built for Canadian SOC teams and Quebec-based MSSPs.

Ready to reclaim your
analysts' focus?

Each partner gets hands-on tuning across all 30 days. Spots stay small by design. Reserve yours before the quarter fills.

No commitment. 30-minute discovery call. We'll tell you honestly if it's a fit.