1 · Collect
Syslog (UDP/TCP), edge-collector HTTPS forwarding and cloud API polling converge into one reliable queue.
SIEM, SOAR, XDR, UEBA and threat intel on one event-driven platform — from an event hitting the wire to an automated, audited response, on a single data model.
XDR includes everything in VultSight SOC.
Collect → Parse → Normalize → Enrich → Index → Detect. A decoupled streaming queue for reliable, near-real-time processing.
Syslog (UDP/TCP), edge-collector HTTPS forwarding and cloud API polling converge into one reliable queue.
Hierarchical parser lookup across JSON, Regex, Grok and CEF — a broad built-in parser library plus a custom-parser framework.
Vendor fields mapped to a 30+ field canonical schema, enabling true cross-vendor correlation.
Real-time IOC matching and asset enrichment tag every event with threat and criticality context.
Bulk-indexed into a high-performance search store with per-tenant isolation and dedup.
Enriched events stream to real-time detection; IOC hits raise alerts instantly, bypassing rule evaluation.
Real-time stream processing for known threats and scheduled deep analytics for advanced ones — both running simultaneously, every rule mapped to MITRE ATT&CK.
Entity-overlap, temporal clustering and kill-chain progression group related alerts into unified INC-YYYYMMDD-XXXX incidents with an interactive entity graph and auto-generated attack story.
Statistical baselines for every user, host, IP and service. Sigma-based anomaly detection, peer-group comparison and a 0–100 composite risk score driving dynamic thresholds.
Curated threat-intel feeds with real-time IOC matching, confidence decay, Sigma rules and full MITRE ATT&CK coverage analysis and heatmap.
Retroactive IOC sweeps across historical data, hypothesis-driven hunts and recurring scheduled sweeps for continuous hunting.
Three-panel deep-dive: evidence timeline, interactive entity graph and an AI assistant answering natural-language questions about the incident.
13-stage ATT&CK overlay showing observed tactics with color-coded progression and technique-to-rule gap analysis.
Provider-agnostic across Anthropic Claude and OpenAI, with governed token budgets, validated queries and a full audit trail of every AI call.
type: sequence group_by: username window: 2h condition: distinct(country) >= 2 // MITRE T1078 · Valid Accounts
Visual playbooks orchestrate tiered response — from auto-executed notifications to approval-gated endpoint isolation.
Multiple step types — action, approval, notification, condition and delay — with a rich condition engine referencing alert, entity and execution context.
Across multiple risk tiers — from tagging and enrichment to endpoint isolation, token revocation and network isolation via connectors.
High-risk actions pause for human approval with justification, expiry and a dedicated approval inbox.
Full lifecycle with tasks, comments, evidence, alert linking and SLA-tracked closure for audit.
VultSight is the ticketing system — auto-ticket rules, 60-second SLA monitoring and L1→L2→L3 auto-escalation.
Malware containment, phishing response, data-exfil, impossible-travel and brute-force mitigation, ready to deploy.
SHA-256 hash chain — any change to historical entries breaks the chain.
RLS on every tenant-scoped table; complete data isolation.
SAML 2.0 + OIDC with auto-provisioning and granular RBAC roles.
Per-tenant region controls with CERT-In and GDPR-EU presets.
Time-limited emergency elevation with full audit trail.
Multi-framework compliance scoring against live audit evidence.
Pre-built connectors with bidirectional response actions.
Detection, investigation and automated response on a single data model — owned by you, or run by our team.