From security signals
to decisions and response.
Imperum Autonomous SOC brings alert intake, AI analysis, case investigation and controlled response into one operating flow. It resolves eligible noise, builds evidence for threats and keeps unresolved work with your team—so analysts spend less time moving information between queues and tools.
Security alerts, endpoint detections and reported emails enter the appropriate workflow. Rules decide what runs; AI and analysts examine the evidence; cases carry the findings and actions through to resolution.
Select any stage for detail. Storage retains context; Direct creates cases by rule. Neither is a mandatory step after Triage.
WS-EXAMPLE → Triage escalation → case → open, with isolation awaiting approval. Guided example; other routes remain available.
Different paths. A traceable result.
Incoming signals become alert records. Triage can close eligible noise, queue uncertainty or escalate a case. Rules can also create cases directly. Case investigations use available evidence and tools; actions follow the configured execution and approval policy.
An open case is still work to do. A resolved case retains its findings and recorded action results.
A decision is useful when the next step is clear.
Route the signal, then assess it.
Ingested events and connected security products supply the records. Modus rules determine which alerts enter Triage and which create or join a case directly. Triage applies policy checks, enrichment and retrieved knowledge before recording a verdict and its reasons.
Result: eligible noise can close; uncertainty stays in an analyst queue.Carry evidence into the investigation.
An escalated alert can create a case and start Pilot, subject to routing and run limits. Rule-based cases provide another entry point. Investigations bring together alert entities, security records and available tool results; the AI Engine supplies stored data and knowledge for retrieval.
Result: a case with findings, a plan and recommendations.Act within policy. Keep the outcome reviewable.
Pilot can propose or execute connector actions. Audit skips execution, Guided waits for approval, and Auto follows risk and approval rules. The investigation records action status and findings; open and resolved cases remain distinguishable.
Result: the next analyst can see what was found, what ran and what still needs attention.Reported email can enter a dedicated phishing investigation. AI Assistant lets an analyst query and follow up on the evidence. Neither is a mandatory step after every triage decision.
Four distinct ways to move the work forward.
Use Triage for the alert decision, Email Phishing for the message investigation, Pilot for deeper casework, and AI Assistant for analyst-led questions. Each contributes a different result to the wider SOC workflow.
Give each alert a reasoned next step.
Use Virtus Triage when an alert needs an initial disposition. It extracts the host, user and indicators, enriches the available evidence, applies policy gates and retrieves relevant knowledge. Where needed, an AI model assesses that context; validation and audit stages retain the decision and its reasons.
Configured actions can close eligible false positives, escalate into a case or send uncertain alerts to the Virtus Triage Queue. Analysts can inspect the reasoning and correct the verdict. Escalation can start Pilot; routing, safety checks and run limits govern that handoff.
Less repeated first-pass work. Analysts receive the alert, supporting context and next step together, instead of repeating the first-pass checks for each alert.
- Source context
- Process lineage: document application → PowerShell. User and host identified.
- Additional evidence
- A network event records a connection to 203.0.113.24 after the process launch.
- Decision and reason
- Escalate. The process chain and subsequent connection need deeper investigation.
Find out what a reported email is trying to do.
Use the Email Phishing agent for a suspicious message submitted through a configured reporting or email workflow. It works with the message itself: unwraps forwarded content, examines authentication headers and sender information, extracts links and attachments, and correlates findings with available security data.
The analysis brings those checks into a verdict with supporting evidence. Optional intelligence and sandbox services add further checks when configured. Response depends on the verdict and response policy; legitimate, spam and marketing results do not enter the response branch.
One reviewable email investigation. An analyst can assess the sender, payload and verdict together, rather than manually collecting each check in a separate tool.
- Authentication
- DMARC fails for the claimed sender.
- Link analysis
- The sign-in link points to a domain unrelated to the claimed organization.
- Attachment checks
- Extracted document content contains the same sign-in link; an optional sandbox can add behavioral evidence.
Take the case beyond the first verdict.
Use Virtus Pilot when an alert or case warrants deeper investigation—for example, a suspected endpoint compromise. It enriches the alert, retrieves relevant knowledge, builds an investigation plan and uses configured connector tools to test that plan. It evaluates the results and can continue investigating before producing its report.
The report brings together findings, recommendations and action status. It gives the analyst a record to review and continue, while execution modes determine whether proposed actions are recommendations, approval requests or permitted automatic actions.
Turn an escalation into casework. Evidence gathering, the investigation plan and its results stay together, reducing the work required to reconstruct what happened at handoff.
- 01Enrich and retrieve
Read the alert entities, related security records and relevant investigation knowledge.
- 02Plan and check
Inspect the process lineage and network activity using the tools available in this deployment.
- 03Evaluate and report
Bring findings into a report. Propose isolation of WS-EXAMPLE for analyst review.
The process and network evidence agree on the host and sequence.
Case remains open. A proposed action is not an executed response.
Inspect the plan without running response actions.
Audit mode skips the execution phase. Review the investigation and its recommendations before deciding how to respond.
No response action is executed in this mode.
Review every proposed action.
Guided mode requires human approval for every planned action, regardless of its risk level. Your team decides what proceeds.
The investigation pauses for a decision.
Automate within an explicit boundary.
Auto mode runs actions allowed by your risk threshold. Higher-risk actions and actions on the approval list wait for review.
Isolation is on the default approval list.
Follow the question that the evidence raises.
AI Assistant—Virtus Assistant in the platform—is the analyst-led entry point. Ask a question about a host, user, alert or case in natural language. The configured search and investigation services retrieve relevant records; the answer can include findings and source citations for inspection.
Keep an entity pinned as context and ask a follow-up without rebuilding the query. This complements the structured agents: Triage decides how to route an alert, Pilot investigates a case, and the Assistant helps an analyst explore a specific question in the available evidence.
Move from an answer to its source. Analysts can inspect the records behind a finding and decide the next question, instead of accepting an unexplained summary.
What happened on this host around the PowerShell alert?
A process launch followed by a network connection.
An Office application launched PowerShell on WS-EXAMPLE. A later network event records a connection to 203.0.113.24. Review the process command line and destination evidence before deciding on containment.
Inspect the example sources
- Process event
- Host: WS-EXAMPLE
Parent: Office application
Child: PowerShell - Network event
- Host: WS-EXAMPLE
Destination: 203.0.113.24
Sequence: after process launch
See what was handled—and what still needs you.
The SOC overview brings verdict distribution, case workload and investigation measures together. Use the record to distinguish alerts closed by triage, decisions needing a person and cases still open. Review the evidence and action status before treating work as resolved.
Decisions and case status
Review verdict counts, analyst overrides and open or closed cases. These describe what happened in the selected period.
Time and speed estimates
Analyst time savings and speed comparisons use a configurable manual-triage baseline. They are estimates, not measured hours returned to your team.
Start with one workflow your team knows.
Choose a recurring alert or reported-email workflow. Confirm the data, tools and permissions it needs, then review the evidence and response boundaries with your analysts.
- 01Choose the input
Select one alert source or reported-email route and verify the records and tools the investigation can use.
- 02Define the handoff
Set triage routing and decide when Pilot or an analyst takes over.
- 03Review before expanding
Use Audit or Guided mode to assess Pilot’s plans and proposed actions.
- 04Extend deliberately
Adjust boundaries based on reviewed outcomes and your team’s operating policy.
Questions about Autonomous SOC.
1How do the agents work together?
They serve different entry points within the system. Rules route alerts into Triage or directly into cases. Triage can close, queue or escalate. Pilot investigates selected alerts or cases; Email Phishing examines reported messages; AI Assistant supports analyst-led questions. They do not always run as a sequence.
2Will every alert trigger an investigation?
No. Triage can close an alert, escalate it or queue it for review. Escalation can launch Pilot, subject to configured routing, run limits and the deployment’s licensing state.
3Can we keep response actions under human control?
Yes. Pilot’s Guided mode requires approval for each planned action. Audit mode skips execution. Auto mode uses a risk threshold and approval list; its built-in defaults allow low-risk actions and require review for actions such as isolation and blocking.
4Where does AI Assistant fit?
It is the analyst-led part of the workflow. Ask questions in natural language, examine returned sources and follow up on what you find. It complements the agents’ structured investigations.
5What needs to be configured first?
Confirm your licensed modules, connected data sources, AI services and user permissions. Then agree the routing and execution policy. The checks and actions available depend on those choices; a demo can map them to your environment.
Have any other questions? Talk to our team
See your SOC workflowfrom signal to outcome.
Bring an alert or suspicious email. We’ll follow its route, examine the evidence and show where your team decides what happens next.