Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
Home/Platform/Analyst team

The analyst team

A specialist per threat class, not one general model

A single model asked to be good at phishing, ransomware, Active Directory abuse, cloud IAM and DNS tunneling is good at none of them in particular. Each Intruex analyst owns a threat class, carries its own heuristics, and knows the boundary of what it covers.

Routed, not guessed

A coordinator matches each alert to the specialist that owns its threat class before any model is asked to reason about it.

Nothing unmatched

The General Analyst picks up anything a specialist does not yet cover, so coverage never has a hole in it.

A growing roster

New specialists are added as detection families change. Adding one does not disturb the others, because each is scoped to its own domain.

The roster

Who handles what

A sample of the roster as it stands today, with coverage stated so you can check it against your own alert mix. It grows as the threat classes we see change.

Bring your own alert mix to a demo and we will show you exactly which analyst each one routes to.

01

Brute Force Analyst

Failed-login bursts, password spray, credential stuffing, MFA bypass attempts, impossible travel and off-hours access.

credential access identity
02

Phishing Analyst

Spearphishing, business email compromise, malicious attachments and suspicious mail-forwarding rules.

initial access email
03

Malware Analyst

Ransomware, trojans, command-and-control traffic, webshells, cryptominers, process injection and DLL hijacking.

execution C2
04

Windows Security Analyst

Suspicious PowerShell, event-log tampering, Active Directory attacks, and registry, scheduled-task and WMI abuse.

persistence defense evasion
05

Lateral Movement Analyst

SMB, RDP and SSH movement, pass-the-hash, data exfiltration, DLP violations and suspicious object-storage replication.

lateral movement exfiltration
06

Privilege Escalation Analyst

Sudo and SUID exploitation, UAC bypass, token theft, cloud IAM role changes and container escapes.

privilege escalation cloud
07

Web Proxy Analyst

Malicious domains, DNS tunneling, SQL injection and cross-site scripting attempts, and URL filtering events.

network web
08

Port Scan Analyst

Network reconnaissance, port scans and sweeps, including the internal vulnerability scanner that fires the same signature every Tuesday.

reconnaissance
09

Microsoft Defender Analyst

Defender for Endpoint alerts, Microsoft Sentinel incidents and M365 events, with ATT&CK tactic extraction carried through from the source.

endpoint Microsoft
10

Acronis EDR Analyst

Acronis EDR incidents and endpoint behavioral detections, normalized into the same decision record as everything else.

endpoint
+

General Analyst

The fallback. Anything unknown, anything that spans several categories, and anything a new detection starts producing before a specialist has been written for it.

fallback, not a gap

Routing

A dictionary lookup before a model call

Most alerts do not need a language model to work out which specialist should read them. brute_force_success goes to the Brute Force Analyst every single time, and asking a model to confirm that is a cost with no benefit.

Ambiguous or unmapped event types get model judgment. That is the whole trick: deterministic where the answer is knowable, judgment where it is not.

routing decision
directbrute_force_successbrute_force
directmalicious_attachmentphishing
directransomware_behaviormalware
judgedcustom_rule_2291lateral_movement
fallbackunmapped_vendor_eventgeneral
deterministic map first model judgment on miss

Why it is built this way

Three reasons specialists beat one big model

  1. Scoping makes the reasoning checkable

    When a named analyst with a stated remit writes the verdict, you can tell whether the alert was even in its remit. "The AI decided" gives you nothing to check.

  2. Heuristics carry the boring cases

    Each specialist has scoring rules that resolve the routine majority deterministically. That is why triage is fast and cheap, and why the expensive path is reserved for alerts that earn it.

  3. Nothing falls through

    Alerts landing on the General Analyst are a signal worth watching: something in your environment is producing a class of event that deserves its own specialist. You can see that number, and it tells us what to build next.

Bring us an alert you already know the answer to

Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.