Skip to content
Explore platformAutonomous SOC
Autonomous SOC

From security signals
to decisions and response.

Imperum Autonomous SOC brings alert intake, AI analysis, case investigation and controlled response into one operating flow. It resolves eligible noise, builds evidence for threats and keeps unresolved work with your team—so analysts spend less time moving information between queues and tools.

Security alerts, endpoint detections and reported emails enter the appropriate workflow. Rules decide what runs; AI and analysts examine the evidence; cases carry the findings and actions through to resolution.

Imperum · Autonomous SOCHow work moves through your SOC
Product workflow · illustrative
Illustrative endpoint investigation
01 / Security inputs
02 / Assess & decideClose · Review · Escalate
Triage dispositions
03 / Investigate & act
Escalate

Select any stage for detail. Storage retains context; Direct creates cases by rule. Neither is a mandatory step after Triage.

01 Intake02 Assess03 Investigate04 Review
An alert becomes an investigation to continue.

WS-EXAMPLE → Triage escalation → case → open, with isolation awaiting approval. Guided example; other routes remain available.

The complete workflow

Different paths. A traceable result.

Incoming signals become alert records. Triage can close eligible noise, queue uncertainty or escalate a case. Rules can also create cases directly. Case investigations use available evidence and tools; actions follow the configured execution and approval policy.

What your team receivesA documented disposition or an investigation to continue

An open case is still work to do. A resolved case retains its findings and recorded action results.

Adapted from the Autonomous SOC overview. Examples are synthetic; no live counts or customer results are shown. Available checks, data and actions depend on your deployment.
The operating flow

A decision is useful when the next step is clear.

01

Route the signal, then assess it.

Ingested events and connected security products supply the records. Modus rules determine which alerts enter Triage and which create or join a case directly. Triage applies policy checks, enrichment and retrieved knowledge before recording a verdict and its reasons.

Result: eligible noise can close; uncertainty stays in an analyst queue.
02

Carry evidence into the investigation.

An escalated alert can create a case and start Pilot, subject to routing and run limits. Rule-based cases provide another entry point. Investigations bring together alert entities, security records and available tool results; the AI Engine supplies stored data and knowledge for retrieval.

Result: a case with findings, a plan and recommendations.
03

Act within policy. Keep the outcome reviewable.

Pilot can propose or execute connector actions. Audit skips execution, Guided waits for approval, and Auto follows risk and approval rules. The investigation records action status and findings; open and resolved cases remain distinguishable.

Result: the next analyst can see what was found, what ran and what still needs attention.

Reported email can enter a dedicated phishing investigation. AI Assistant lets an analyst query and follow up on the evidence. Neither is a mandatory step after every triage decision.

The agents within the system

Four distinct ways to move the work forward.

Use Triage for the alert decision, Email Phishing for the message investigation, Pilot for deeper casework, and AI Assistant for analyst-led questions. Each contributes a different result to the wider SOC workflow.

01 - Virtus Alert Triage Agent

Give each alert a reasoned next step.

Use Virtus Triage when an alert needs an initial disposition. It extracts the host, user and indicators, enriches the available evidence, applies policy gates and retrieves relevant knowledge. Where needed, an AI model assesses that context; validation and audit stages retain the decision and its reasons.

Configured actions can close eligible false positives, escalate into a case or send uncertain alerts to the Virtus Triage Queue. Analysts can inspect the reasoning and correct the verdict. Escalation can start Pilot; routing, safety checks and run limits govern that handoff.

Less repeated first-pass work. Analysts receive the alert, supporting context and next step together, instead of repeating the first-pass checks for each alert.

Alert → evidence → escalationSynthetic example
Endpoint alert · WS-EXAMPLEOffice application launched PowerShellNeeds investigation
Source context
Process lineage: document application → PowerShell. User and host identified.
Additional evidence
A network event records a connection to 203.0.113.24 after the process launch.
Decision and reason
Escalate. The process chain and subsequent connection need deeper investigation.
Case created with the alert evidenceConfigured handoff → Virtus Pilot
Illustrative evidence and verdict, not a detection guarantee. Missing or uncertain evidence can lead to human review instead.
02 - Virtus Email Phishing Agent

Find out what a reported email is trying to do.

Use the Email Phishing agent for a suspicious message submitted through a configured reporting or email workflow. It works with the message itself: unwraps forwarded content, examines authentication headers and sender information, extracts links and attachments, and correlates findings with available security data.

The analysis brings those checks into a verdict with supporting evidence. Optional intelligence and sandbox services add further checks when configured. Response depends on the verdict and response policy; legitimate, spam and marketing results do not enter the response branch.

One reviewable email investigation. An analyst can assess the sender, payload and verdict together, rather than manually collecting each check in a separate tool.

Reported email → message analysisSynthetic example
Verdict: phishingEvidence retained · response follows policy
Synthetic message and findings. A phishing verdict is not proof that quarantine, deletion or case closure occurred; review the response result.
03 - Virtus Pilot Agent

Take the case beyond the first verdict.

Use Virtus Pilot when an alert or case warrants deeper investigation—for example, a suspected endpoint compromise. It enriches the alert, retrieves relevant knowledge, builds an investigation plan and uses configured connector tools to test that plan. It evaluates the results and can continue investigating before producing its report.

The report brings together findings, recommendations and action status. It gives the analyst a record to review and continue, while execution modes determine whether proposed actions are recommendations, approval requests or permitted automatic actions.

Turn an escalation into casework. Evidence gathering, the investigation plan and its results stay together, reducing the work required to reconstruct what happened at handoff.

Pilot investigation · possible endpoint compromiseGuided mode · synthetic example
Case · endpoint alert escalated from TriageEstablish the scope on WS-EXAMPLE
  1. 01
    Enrich and retrieve

    Read the alert entities, related security records and relevant investigation knowledge.

  2. 02
    Plan and check

    Inspect the process lineage and network activity using the tools available in this deployment.

  3. 03
    Evaluate and report

    Bring findings into a report. Propose isolation of WS-EXAMPLE for analyst review.

FindingSuspicious process chain with a follow-on connection

The process and network evidence agree on the host and sequence.

Next actionIsolation awaiting approval

Case remains open. A proposed action is not an executed response.

Synthetic investigation. Pilot’s plan depends on the alert, findings and configured tools; it is not the same checklist for every case.
Pilot execution modesChoose a mode to explore
Analysis before execution

Inspect the plan without running response actions.

Audit mode skips the execution phase. Review the investigation and its recommendations before deciding how to respond.

Illustrative proposed actionIsolate affected endpointRecommendation only

No response action is executed in this mode.

Analyst approval

Review every proposed action.

Guided mode requires human approval for every planned action, regardless of its risk level. Your team decides what proceeds.

Illustrative proposed actionIsolate affected endpointAwaiting approval

The investigation pauses for a decision.

Configured execution

Automate within an explicit boundary.

Auto mode runs actions allowed by your risk threshold. Higher-risk actions and actions on the approval list wait for review.

Illustrative proposed actionIsolate affected endpointApproval required by default

Isolation is on the default approval list.

This selector explains Pilot’s modes; it does not change your SOC. The built-in mode is Auto with a low-risk threshold. Tenant configuration can override defaults.
04 - AI Assistant

Follow the question that the evidence raises.

AI Assistant—Virtus Assistant in the platform—is the analyst-led entry point. Ask a question about a host, user, alert or case in natural language. The configured search and investigation services retrieve relevant records; the answer can include findings and source citations for inspection.

Keep an entity pinned as context and ask a follow-up without rebuilding the query. This complements the structured agents: Triage decides how to route an alert, Pilot investigates a case, and the Assistant helps an analyst explore a specific question in the available evidence.

Move from an answer to its source. Analysts can inspect the records behind a finding and decide the next question, instead of accepting an unexplained summary.

AI Assistant · evidence-led follow-upSynthetic example
Pinned hostWS-EXAMPLE
Analyst

What happened on this host around the PowerShell alert?

AI Assistant · synthetic answer

A process launch followed by a network connection.

An Office application launched PowerShell on WS-EXAMPLE. A later network event records a connection to 203.0.113.24. Review the process command line and destination evidence before deciding on containment.

Inspect the example sources
Process event
Host: WS-EXAMPLE
Parent: Office application
Child: PowerShell
Network event
Host: WS-EXAMPLE
Destination: 203.0.113.24
Sequence: after process launch
Was that destination seen on other hosts?
All identifiers and findings are synthetic. Actual answers and available tools depend on connected records, permissions and configured AI services. The Assistant is not a required stage in every case.
05 - Oversight & operational value

See what was handled—and what still needs you.

The SOC overview brings verdict distribution, case workload and investigation measures together. Use the record to distinguish alerts closed by triage, decisions needing a person and cases still open. Review the evidence and action status before treating work as resolved.

Operational record

Decisions and case status

Review verdict counts, analyst overrides and open or closed cases. These describe what happened in the selected period.

Modeled benefit

Time and speed estimates

Analyst time savings and speed comparisons use a configurable manual-triage baseline. They are estimates, not measured hours returned to your team.

The practical gain: a disposition with its reasons, a case with its findings, and an explicit place for the next human decision. Validate workload benefits against your own reviewed outcomes before expanding automation.
Getting started

Start with one workflow your team knows.

Choose a recurring alert or reported-email workflow. Confirm the data, tools and permissions it needs, then review the evidence and response boundaries with your analysts.

  1. 01Choose the input

    Select one alert source or reported-email route and verify the records and tools the investigation can use.

  2. 02Define the handoff

    Set triage routing and decide when Pilot or an analyst takes over.

  3. 03Review before expanding

    Use Audit or Guided mode to assess Pilot’s plans and proposed actions.

  4. 04Extend deliberately

    Adjust boundaries based on reviewed outcomes and your team’s operating policy.

Questions about Autonomous SOC.

1How do the agents work together?

They serve different entry points within the system. Rules route alerts into Triage or directly into cases. Triage can close, queue or escalate. Pilot investigates selected alerts or cases; Email Phishing examines reported messages; AI Assistant supports analyst-led questions. They do not always run as a sequence.

2Will every alert trigger an investigation?

No. Triage can close an alert, escalate it or queue it for review. Escalation can launch Pilot, subject to configured routing, run limits and the deployment’s licensing state.

3Can we keep response actions under human control?

Yes. Pilot’s Guided mode requires approval for each planned action. Audit mode skips execution. Auto mode uses a risk threshold and approval list; its built-in defaults allow low-risk actions and require review for actions such as isolation and blocking.

4Where does AI Assistant fit?

It is the analyst-led part of the workflow. Ask questions in natural language, examine returned sources and follow up on what you find. It complements the agents’ structured investigations.

5What needs to be configured first?

Confirm your licensed modules, connected data sources, AI services and user permissions. Then agree the routing and execution policy. The checks and actions available depend on those choices; a demo can map them to your environment.

Have any other questions? Talk to our team

See your SOC workflowfrom signal to outcome.

Bring an alert or suspicious email. We’ll follow its route, examine the evidence and show where your team decides what happens next.