VultSight XDR · Premium security

Five tools' worth of signal.
One incident.

SIEM, SOAR, XDR, UEBA and threat intel on one event-driven platform — from an event hitting the wire to an automated, audited response, on a single data model.

  • Stop chasing alerts — related signals correlate into one incident with an attack story
  • See the whole entity — user, host, identity and asset joined in one graph
  • Catch the unsignatured — UEBA flags behaviour no rule was written for

XDR includes everything in VultSight SOC.

How it works

An end-to-end ingestion pipeline

Collect → Parse → Normalize → Enrich → Index → Detect. A decoupled streaming queue for reliable, near-real-time processing.

📡

1 · Collect

Syslog (UDP/TCP), edge-collector HTTPS forwarding and cloud API polling converge into one reliable queue.

🔤

2 · Parse

Hierarchical parser lookup across JSON, Regex, Grok and CEF — a broad built-in parser library plus a custom-parser framework.

🧭

3 · Normalize

Vendor fields mapped to a 30+ field canonical schema, enabling true cross-vendor correlation.

4 · Enrich

Real-time IOC matching and asset enrichment tag every event with threat and criticality context.

🗂️

5 · Index

Bulk-indexed into a high-performance search store with per-tenant isolation and dedup.

🚨

6 · Detect

Enriched events stream to real-time detection; IOC hits raise alerts instantly, bypassing rule evaluation.

Detection engine

Flexible rule types,
real-time & scheduled

Real-time stream processing for known threats and scheduled deep analytics for advanced ones — both running simultaneously, every rule mapped to MITRE ATT&CK.

  • Match — known-bad patterns with boolean logic and wildcards
  • Threshold — count/cardinality limits with per-entity group-by
  • Sequence — ordered multi-step chains within a time window
  • Correlation — cross-source entity co-occurrence
  • Statistical — sigma deviation from UEBA baselines
SafeguardMechanism
Suppression windowsPer-entity, real-time
Rule exceptionsConditional + expiring
Deduplication1-hour TTL window
MITRE mappingTactics + techniques
Real-time latencySub-second, in-memory
Investigate

From alert noise to attack story

🕸️

XDR correlation

Entity-overlap, temporal clustering and kill-chain progression group related alerts into unified INC-YYYYMMDD-XXXX incidents with an interactive entity graph and auto-generated attack story.

📊

UEBA

Statistical baselines for every user, host, IP and service. Sigma-based anomaly detection, peer-group comparison and a 0–100 composite risk score driving dynamic thresholds.

🌐

Threat intelligence

Curated threat-intel feeds with real-time IOC matching, confidence decay, Sigma rules and full MITRE ATT&CK coverage analysis and heatmap.

🔭

Threat hunting

Retroactive IOC sweeps across historical data, hypothesis-driven hunts and recurring scheduled sweeps for continuous hunting.

🔬

Investigation workbench

Three-panel deep-dive: evidence timeline, interactive entity graph and an AI assistant answering natural-language questions about the incident.

🗺️

MITRE kill chain

13-stage ATT&CK overlay showing observed tactics with color-coded progression and technique-to-rule gap analysis.

AI-native SecOps

AI in every workflow,
not bolted on

Provider-agnostic across Anthropic Claude and OpenAI, with governed token budgets, validated queries and a full audit trail of every AI call.

NL searchPlain English → a safe, tenant-scoped query.
Autonomous triageTP/FP + auto-closure of false positives.
Investigation assistantContext-aware incident Q&A.
Rule generationDescribe a threat, get a rule.
"Alert when a user logs in from two countries within 2 hours"
↓ generates
type: sequence
group_by: username
window: 2h
condition: distinct(country) >= 2
// MITRE T1078 · Valid Accounts
Rule validated & saved
Respond

SOAR, cases and native ITSM

Visual playbooks orchestrate tiered response — from auto-executed notifications to approval-gated endpoint isolation.

⚙️

Playbook engine

Multiple step types — action, approval, notification, condition and delay — with a rich condition engine referencing alert, entity and execution context.

🛡️

Tiered response actions

Across multiple risk tiers — from tagging and enrichment to endpoint isolation, token revocation and network isolation via connectors.

Approval workflows

High-risk actions pause for human approval with justification, expiry and a dedicated approval inbox.

🗃️

Case management

Full lifecycle with tasks, comments, evidence, alert linking and SLA-tracked closure for audit.

🎫

Native ITSM

VultSight is the ticketing system — auto-ticket rules, 60-second SLA monitoring and L1→L2→L3 auto-escalation.

📑

Built-in playbooks

Malware containment, phishing response, data-exfil, impossible-travel and brute-force mitigation, ready to deploy.

Trust & compliance

Forensic-grade by default

🔗

Tamper-evident audit

SHA-256 hash chain — any change to historical entries breaks the chain.

🏢

Row-Level Security

RLS on every tenant-scoped table; complete data isolation.

🔐

Enterprise SSO

SAML 2.0 + OIDC with auto-provisioning and granular RBAC roles.

📍

Data residency

Per-tenant region controls with CERT-In and GDPR-EU presets.

🚨

Break-glass access

Time-limited emergency elevation with full audit trail.

📋

Automated assessment

Multi-framework compliance scoring against live audit evidence.

Integrations

Works with your existing stack

Pre-built connectors with bidirectional response actions.

CrowdStrike FalconSentinelOneMicrosoft Defender OktaAzure ADCyberArk AWS CloudTrailGCP AuditPalo Alto Networks FortinetZeekSuricata ProofpointMicrosoft 365Tenable QualysosqueryWazuh

The whole security stack, one platform

Detection, investigation and automated response on a single data model — owned by you, or run by our team.