Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
SOC 2 Type II Certified & in production

Every alert analyzed.
Every decision explained.

Intruex turns the security alerts your tools already produce into decisions you can defend, in an audit, a board review, or a post-incident inquiry. It does the work a SOC analyst would do, whether or not you have one. If nothing is producing alerts yet, we set that up first.

Intruex-hosted Your AWS account On-prem / air-gapped
intruex: alert triage live
high
impossible_travel
splunk · user j.rahman@ · 2 sources · 41 min apart
Normalized
Mapped to OCSF · 14 fields · source retained verbatim
Routed → Brute Force Analyst
Event type matched to a specialist, not a general model
Enriched
4 indicators · ASN, geo, reputation, prior sightings
Triage inconclusive
Confidence 0.41 · deep investigation triggered
Deep investigation
4 tool calls · SIEM hunt, indicator history, 8 related alerts
Disposition written
Verdict, confidence and full reasoning persisted

false positive confidence

The hunt found 8 sign-ins through the same corporate proxy in 24 hours. Its egress node rotates between requests, producing an apparent 3,180 km displacement. No authentication anomaly. Root cause, not suppression.

recommendation only awaiting analyst approval
Illustrative: mirrors the shipping pipeline median triage 48s
0%
Of alerts received are analyzed, every severity
measured none sampled, none deferred
0s
Median time from alert to verdict
measured in production
0%
Resolved without analyst involvement
measured in production
0+
Alert types routed straight to the specialist that owns them
by design growing with every new detection family

Where Intruex fits

Everyone else automates the do.
Intruex automates the think.

SOAR platforms execute playbooks. XDR consolidates telemetry. SIEMs fire rules. Every one of them assumes a human has already worked out what the alert means.

That judgment is the bottleneck. It is the layer Intruex adds, and the only one it touches.

where intruex sits
DETECT already yours
SIEM · EDR · cloud · identity · email
alerts, as they fire
DECIDE Intruex
Triage · investigate · correlate · disposition
A verdict, its reasoning and a confidence value on every alert, retained and replayable
a recommendation, for a human to approve
ACT already yours
SOAR · automation · ticketing · your runbooks
one layer added, nothing replaced
Nothing moves No new log pipeline No agent to deploy No detections to rewrite No data migration You keep the stack you have

Why alert triage stays broken

Three problems, and only one of them is volume

All three show up whether you have a security team or nobody watching at all.

Volume

The queue outgrows whoever is watching it. With analysts, triage eats the day and most of it ends in "no action." Without them (and most companies under a few hundred people have none), the alerts fire into an empty room.

Evidence

Detection is not documentation. Regulations are written with operational verbs (review, detect, analyze), and a policy binder cannot perform a verb. You need the record that the work happened.

Trust

Black-box AI is a finding. Automation that cannot explain a decision cannot be defended in an audit, a board review, or a post-incident inquiry.

A verdict you cannot audit has to be redone, which means it saved you nothing. See what we retain on every decision

The pipeline

Six steps between an alert and a decision

Each step writes to the record. Nothing is inferred after the fact.

01

Ingest

Alerts arrive from Splunk, Microsoft Sentinel, Defender, Intune, Acronis EDR, or any system that can POST JSON. We do not collect your logs.

02

Normalize

Everything is mapped to OCSF so one specialist can reason across sources. The original payload is retained verbatim alongside it.

03

Enrich

Indicators are resolved against threat-intelligence sources and against what this environment has seen before. Results are cached, not re-billed.

04

Analyze

A specialist analyst, not one generic model, scores the alert and writes a disposition with a confidence value and plain-language reasoning.

05

Correlate

Alerts that share indicators are grouped into one attack narrative with a kill-chain timeline and the correlation factors written out.

06

Respond

Response is a recommendation with an approval gate. No automated action fires without a human. That is a default, not a setting we hope you find.

Inside the product

What the analyst actually receives

Not a score. A case file, with the reasoning, the evidence, and every step that produced it.

Tier 1: triage at ingestion

Every alert that arrives is scored, enriched and dispositioned. Not a sample. Not the criticals. Every severity, every time.

  • Five dispositions: benign, false positive, investigate, escalate, true positive
  • A confidence value on every one of them
  • Routed by event type to one of 11 specialists, with a general analyst behind them
  • Anything the specialist is not sure about is handed up, not guessed
alert queue: last 60 min
fpimpossible_travel0.94
benignoff_hours_access0.88
escalatepowershell_encoded_cmd0.71
investigatesmb_lateral_auth0.63
fpdns_tunnel_suspect0.91
benignport_scan_internal0.86
6 of 6 dispositioned1 awaiting analyst

The analyst team

A specialist per threat class,
not one model doing everything

A model asked to be good at everything is good at nothing in particular. Each Intruex analyst owns a threat class and carries its own heuristics, and the roster grows as new detection families appear. A sample of who is on it today:

01
Brute Force

Password spray, credential stuffing, impossible travel

02
Phishing

Spearphishing, BEC, mail-forwarding rules

03
Malware

Ransomware, C2 traffic, webshells, injection

04
Windows Security

PowerShell abuse, log tampering, AD attacks

05
Lateral Movement

SMB/RDP/SSH movement, pass-the-hash, exfil

06
Privilege Escalation

UAC bypass, token theft, IAM role changes

07
Web Proxy

Malicious domains, DNS tunneling, SQLi/XSS

08
Port Scan

Network reconnaissance, scans and sweeps

+
General Analyst

Anything a specialist does not yet cover, so nothing goes unanalyzed

Plus specialists for the endpoint and identity platforms teams actually run, and new ones as the threat classes we see change. Routing sends anything unmatched to the General Analyst, so coverage never has a hole in it while a specialist is being built.

Case study

What a month looks like

This is what the platform does with a live queue, measured end to end at a managed security provider. July 2026 is the month we publish in full.

measured Managed security provider · July 2026

728 alerts analyzed in a month.
98.1% never needed an analyst.

Not filtered, not deduplicated, not parked in a lower-priority queue for someone to get to. Every alert was routed to a specialist, enriched, investigated and dispositioned with a written verdict and a confidence value, at a median of 48 seconds each.

What reached the analyst was the small remainder that genuinely warranted a human, and it arrived as a finished case file. The analyst reviewing that month's escalations did not re-investigate a single one.

That capacity comes back every month, and it does not depend on anything being tuned. The analysis also surfaces structural problems the queue was hiding. In July it traced 617 of 619 impossible-travel alerts to a single rotating proxy egress node, permanently removing roughly 600 alerts a month on top of the hours already returned, with zero alerts dropped to get there.

Alerts analyzed
728
every severity, none sampled
Resolved without an analyst
98.1%
Analyst hours returned
357hrs
in the month, roughly $26,775 of analyst capacity at $75 an hour
modeled 30-minute manual triage assumption
Median time to verdict
48s
and the same throughput next month, without adding headcount

Transparency

How a verdict is made

If you cannot reconstruct the decision, you have to redo it. So every input that moved the verdict is kept, in order.

  1. Heuristic score

    The routed specialist applies its own scoring rules to the normalized alert. Deterministic, inspectable, and identical on a replay.

  2. Enrichment signals

    Indicators are resolved against external intelligence and against this environment's own history. Each signal is stored with its source and its age.

  3. Disposition resolver

    Historical patterns first, then risk rules, then a conservative fail-safe. When the signals disagree, the resolver escalates rather than guessing.

  4. Confidence

    Published with the verdict, not hidden behind it. A low-confidence benign is a very different object from a high-confidence one, and the queue treats them differently.

  5. Deep investigation, if warranted

    Investigate and escalate verdicts trigger the tool-using agent. Its tool calls, observations and conclusion are all persisted with the alert.

  6. Human approval

    Response actions are recommendations. No automated action fires without a human, and every status change records its actor: user, system or AI.

Question it

Open a thread on any alert or narrative. The original analysis and scoring stay in context, so the discussion picks up from that decision rather than starting over.

Replay it

Status history, the full investigation record, correlation factors and any automation run, retained per alert, exportable.

Override it

The AI never overrides an analyst decision. Where autonomy is enabled it is opt-in, confidence-gated, and attributed in the audit trail.

Deployment

Runs where the data has to live

Three tiers, scoped individually, never as one blanket claim. Only the third supports "no data leaves your network" without qualification, so only the third says it.

Intruex-hosted

Managed SaaS in a dedicated, isolated tenant. Fastest to value; we run the infrastructure and the upgrades.

  • Row-level tenant isolation
  • Per-tenant encrypted credentials
  • SOC 2 Type II certified

Your cloud

Runs inside your own AWS account with managed model inference. Your VPC, your keys, your logging, your retention policy.

  • Deployed by Terraform into your account
  • Deployable on FedRAMP High authorized infrastructure
  • Per-tenant cost observability

On-premises & air-gapped

Open-weight models on your hardware. This is the tier where no data leaves your network is true without a footnote.

  • Zero outbound network calls
  • Local inference: no external model provider
  • External threat intel degrades gracefully by design

The question the one-pagers never answer

Why Intruex rather than a generic AI SOC?

Where the category isWhere Intruex is
Filters, groups and deduplicates, then leaves the judgment call to your analyst Analyzes every alert end to end and writes the verdict, with the reasoning and the confidence attached, so most never reach a human at all
Quotes an alert-reduction percentage without saying where the alerts went Every alert ends in a disposition you can open and read. The reduction is a list you can audit, not a percentage, and in production, zero were dropped to produce it
One general model asked to reason about every threat class Specialist analysts routed by event type, each owning a threat class, with a general analyst behind them
Sovereignty as a configuration option in a cloud product On-premises and air-gapped as a first-class tier of the same platform
"Full autonomy on day one", named as a warning sign in every 2026 evaluation guide Recommendation-first, with the approval gate on by default
Sells hours saved to organizations that already employ analysts Also serves organizations with no SOC, by standing the detection layer up first

An integration count says nothing about the answer

An integration count tells you how many places an alert can come from. It tells you nothing about the quality of the answer on the other side. We put the engineering into the answer: specialist analysis, correlation into a narrative, and a reasoning record an auditor can read.

What you get on day one

  • Every alert triaged, every severity, with written reasoning
  • A confidence value on every verdict, published rather than hidden
  • Related alerts grouped into one incident with the factors stated
  • An audit trail that survives a board review or a post-incident inquiry

Integrations

Connect what you already run

Intruex takes alerts from whatever your stack already produces. Purpose-built connectors for the sources most teams are on, a generic REST endpoint for everything else, and OCSF normalization on the way in, so whatever route an alert takes, it lands in the same decision record.

Non-native sources are not a degraded mode. Routing, specialist analysis, enrichment, correlation and the full decision record all work identically, and a new source is usually an afternoon of mapping. See the connector detail →

Native connectors REST / OCSF Your feeds, your keys

Ingestion
Any alert source. Native connectors for Splunk, Microsoft Sentinel, Defender and others, plus REST/OCSF for the rest of your stack
Enrichment
Multi-source threat intelligence with per-tenant keys and cached indicators, extensible to whatever feeds you already pay for
Automation
Generic REST playbooks into your automation layer, or one we set up with you, with an execution audit trail per alert
Notification
SMTP escalation and Slack, configured per tenant

Bring us an alert you already know the answer to

The fastest way to evaluate this is to hand it something from last week and read the reasoning. If the verdict is wrong, you will be able to see exactly where it went wrong, which is the whole point.

Thirty minutes. Your alert, our screen, and the reasoning behind the verdict.