Brute Force Analyst
Failed-login bursts, password spray, credential stuffing, MFA bypass attempts, impossible travel and off-hours access.
The analyst team
A single model asked to be good at phishing, ransomware, Active Directory abuse, cloud IAM and DNS tunneling is good at none of them in particular. Each Intruex analyst owns a threat class, carries its own heuristics, and knows the boundary of what it covers.
A coordinator matches each alert to the specialist that owns its threat class before any model is asked to reason about it.
The General Analyst picks up anything a specialist does not yet cover, so coverage never has a hole in it.
New specialists are added as detection families change. Adding one does not disturb the others, because each is scoped to its own domain.
The roster
A sample of the roster as it stands today, with coverage stated so you can check it against your own alert mix. It grows as the threat classes we see change.
Bring your own alert mix to a demo and we will show you exactly which analyst each one routes to.
Failed-login bursts, password spray, credential stuffing, MFA bypass attempts, impossible travel and off-hours access.
Spearphishing, business email compromise, malicious attachments and suspicious mail-forwarding rules.
Ransomware, trojans, command-and-control traffic, webshells, cryptominers, process injection and DLL hijacking.
Suspicious PowerShell, event-log tampering, Active Directory attacks, and registry, scheduled-task and WMI abuse.
SMB, RDP and SSH movement, pass-the-hash, data exfiltration, DLP violations and suspicious object-storage replication.
Sudo and SUID exploitation, UAC bypass, token theft, cloud IAM role changes and container escapes.
Malicious domains, DNS tunneling, SQL injection and cross-site scripting attempts, and URL filtering events.
Network reconnaissance, port scans and sweeps, including the internal vulnerability scanner that fires the same signature every Tuesday.
Defender for Endpoint alerts, Microsoft Sentinel incidents and M365 events, with ATT&CK tactic extraction carried through from the source.
Acronis EDR incidents and endpoint behavioral detections, normalized into the same decision record as everything else.
The fallback. Anything unknown, anything that spans several categories, and anything a new detection starts producing before a specialist has been written for it.
Routing
Most alerts do not need a language model to work out which specialist should read them. brute_force_success goes to the Brute Force Analyst every single time, and asking a model to confirm that is a cost with no benefit.
Ambiguous or unmapped event types get model judgment. That is the whole trick: deterministic where the answer is knowable, judgment where it is not.
Why it is built this way
When a named analyst with a stated remit writes the verdict, you can tell whether the alert was even in its remit. "The AI decided" gives you nothing to check.
Each specialist has scoring rules that resolve the routine majority deterministically. That is why triage is fast and cheap, and why the expensive path is reserved for alerts that earn it.
Alerts landing on the General Analyst are a signal worth watching: something in your environment is producing a class of event that deserves its own specialist. You can see that number, and it tells us what to build next.
Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.