Volume
The queue outgrows whoever is watching it. With analysts, triage eats the day and most of it ends in "no action." Without them (and most companies under a few hundred people have none), the alerts fire into an empty room.
Intruex turns the security alerts your tools already produce into decisions you can defend, in an audit, a board review, or a post-incident inquiry. It does the work a SOC analyst would do, whether or not you have one. If nothing is producing alerts yet, we set that up first.
The hunt found 8 sign-ins through the same corporate proxy in 24 hours. Its egress node rotates between requests, producing an apparent 3,180 km displacement. No authentication anomaly. Root cause, not suppression.
Where Intruex fits
SOAR platforms execute playbooks. XDR consolidates telemetry. SIEMs fire rules. Every one of them assumes a human has already worked out what the alert means.
That judgment is the bottleneck. It is the layer Intruex adds, and the only one it touches.
Why alert triage stays broken
All three show up whether you have a security team or nobody watching at all.
The queue outgrows whoever is watching it. With analysts, triage eats the day and most of it ends in "no action." Without them (and most companies under a few hundred people have none), the alerts fire into an empty room.
Detection is not documentation. Regulations are written with operational verbs (review, detect, analyze), and a policy binder cannot perform a verb. You need the record that the work happened.
Black-box AI is a finding. Automation that cannot explain a decision cannot be defended in an audit, a board review, or a post-incident inquiry.
A verdict you cannot audit has to be redone, which means it saved you nothing.See what we retain on every decision
The pipeline
Each step writes to the record. Nothing is inferred after the fact.
Alerts arrive from Splunk, Microsoft Sentinel, Defender, Intune, Acronis EDR, or any system that can POST JSON. We do not collect your logs.
Everything is mapped to OCSF so one specialist can reason across sources. The original payload is retained verbatim alongside it.
Indicators are resolved against threat-intelligence sources and against what this environment has seen before. Results are cached, not re-billed.
A specialist analyst, not one generic model, scores the alert and writes a disposition with a confidence value and plain-language reasoning.
Alerts that share indicators are grouped into one attack narrative with a kill-chain timeline and the correlation factors written out.
Response is a recommendation with an approval gate. No automated action fires without a human. That is a default, not a setting we hope you find.
Inside the product
Not a score. A case file, with the reasoning, the evidence, and every step that produced it.
Every alert that arrives is scored, enriched and dispositioned. Not a sample. Not the criticals. Every severity, every time.
When triage says investigate or escalate, a tool-using agent takes over and does what a human analyst would do next.
It has the full investigative toolset available to it and chooses which to reach for, iterating until it can conclude. Every call it makes is logged with what it asked and what came back.
Decoded command invokes a signed vendor updater present on 214 other endpoints. Matches the documented patching runbook. No outbound connection observed.
Alerts that share indicators are grouped into an attack narrative with a kill-chain timeline, and the correlation factors are written down, so you can disagree with the grouping.
When an auditor, an examiner or your own board asks what was done about a specific alert on a specific date, the answer is a record you can open, not a reconstruction somebody assembles the week before the review.
This is the same record a security reviewer inspects. See what is retained on every decision →
The analyst team
A model asked to be good at everything is good at nothing in particular. Each Intruex analyst owns a threat class and carries its own heuristics, and the roster grows as new detection families appear. A sample of who is on it today:
Password spray, credential stuffing, impossible travel
Spearphishing, BEC, mail-forwarding rules
Ransomware, C2 traffic, webshells, injection
PowerShell abuse, log tampering, AD attacks
SMB/RDP/SSH movement, pass-the-hash, exfil
UAC bypass, token theft, IAM role changes
Malicious domains, DNS tunneling, SQLi/XSS
Network reconnaissance, scans and sweeps
Anything a specialist does not yet cover, so nothing goes unanalyzed
Plus specialists for the endpoint and identity platforms teams actually run, and new ones as the threat classes we see change. Routing sends anything unmatched to the General Analyst, so coverage never has a hole in it while a specialist is being built.
Case study
This is what the platform does with a live queue, measured end to end at a managed security provider. July 2026 is the month we publish in full.
Not filtered, not deduplicated, not parked in a lower-priority queue for someone to get to. Every alert was routed to a specialist, enriched, investigated and dispositioned with a written verdict and a confidence value, at a median of 48 seconds each.
What reached the analyst was the small remainder that genuinely warranted a human, and it arrived as a finished case file. The analyst reviewing that month's escalations did not re-investigate a single one.
That capacity comes back every month, and it does not depend on anything being tuned. The analysis also surfaces structural problems the queue was hiding. In July it traced 617 of 619 impossible-travel alerts to a single rotating proxy egress node, permanently removing roughly 600 alerts a month on top of the hours already returned, with zero alerts dropped to get there.
Transparency
If you cannot reconstruct the decision, you have to redo it. So every input that moved the verdict is kept, in order.
The routed specialist applies its own scoring rules to the normalized alert. Deterministic, inspectable, and identical on a replay.
Indicators are resolved against external intelligence and against this environment's own history. Each signal is stored with its source and its age.
Historical patterns first, then risk rules, then a conservative fail-safe. When the signals disagree, the resolver escalates rather than guessing.
Published with the verdict, not hidden behind it. A low-confidence benign is a very different object from a high-confidence one, and the queue treats them differently.
Investigate and escalate verdicts trigger the tool-using agent. Its tool calls, observations and conclusion are all persisted with the alert.
Response actions are recommendations. No automated action fires without a human, and every status change records its actor: user, system or AI.
Open a thread on any alert or narrative. The original analysis and scoring stay in context, so the discussion picks up from that decision rather than starting over.
Status history, the full investigation record, correlation factors and any automation run, retained per alert, exportable.
The AI never overrides an analyst decision. Where autonomy is enabled it is opt-in, confidence-gated, and attributed in the audit trail.
Deployment
Three tiers, scoped individually, never as one blanket claim. Only the third supports "no data leaves your network" without qualification, so only the third says it.
Managed SaaS in a dedicated, isolated tenant. Fastest to value; we run the infrastructure and the upgrades.
Runs inside your own AWS account with managed model inference. Your VPC, your keys, your logging, your retention policy.
Open-weight models on your hardware. This is the tier where no data leaves your network is true without a footnote.
Who this is for
HIPAA says review. Reg S-P says detect. NIST 800-171 says analyze and report. Each of those is something that has to happen in your environment, and a policy document cannot do any of them.
NIST 800-171 · CMMC
"Three requirement families a policy binder cannot satisfy." §3.3.5 asks you to review, analyze and report audit records.
DefenseHIPAA · HITECH
HIPAA does not ask you to keep logs. §164.308(a)(1)(ii)(D) asks you to review them. Required, not addressable.
HealthcareSEC Reg S-P · GLBA
Your program is required to detect, respond to and recover. Documents cannot detect anything.
Financial servicesState · Local · Public sector
Deployment sovereignty is the requirement, not the differentiator. Run it in your own environment and keep the record.
GovernmentMulti-tenant
Per-tenant isolation, per-tenant thresholds, per-tenant cost visibility. The unit economics work at the bottom of your book.
MSSPsNo SOC yet
An obligation to monitor, no analyst to do it, and managed detection priced well above the problem. We stand the detection layer up first, then run the platform on it.
Talk to usThe question the one-pagers never answer
| Where the category is | Where Intruex is |
|---|---|
| Filters, groups and deduplicates, then leaves the judgment call to your analyst | Analyzes every alert end to end and writes the verdict, with the reasoning and the confidence attached, so most never reach a human at all |
| Quotes an alert-reduction percentage without saying where the alerts went | Every alert ends in a disposition you can open and read. The reduction is a list you can audit, not a percentage, and in production, zero were dropped to produce it |
| One general model asked to reason about every threat class | Specialist analysts routed by event type, each owning a threat class, with a general analyst behind them |
| Sovereignty as a configuration option in a cloud product | On-premises and air-gapped as a first-class tier of the same platform |
| "Full autonomy on day one", named as a warning sign in every 2026 evaluation guide | Recommendation-first, with the approval gate on by default |
| Sells hours saved to organizations that already employ analysts | Also serves organizations with no SOC, by standing the detection layer up first |
An integration count tells you how many places an alert can come from. It tells you nothing about the quality of the answer on the other side. We put the engineering into the answer: specialist analysis, correlation into a narrative, and a reasoning record an auditor can read.
Integrations
Intruex takes alerts from whatever your stack already produces. Purpose-built connectors for the sources most teams are on, a generic REST endpoint for everything else, and OCSF normalization on the way in, so whatever route an alert takes, it lands in the same decision record.
Non-native sources are not a degraded mode. Routing, specialist analysis, enrichment, correlation and the full decision record all work identically, and a new source is usually an afternoon of mapping. See the connector detail →
The fastest way to evaluate this is to hand it something from last week and read the reasoning. If the verdict is wrong, you will be able to see exactly where it went wrong, which is the whole point.
Thirty minutes. Your alert, our screen, and the reasoning behind the verdict.