Investigations that run themselves, and stop when you say
Virtus Pilot is Imperum's autonomous investigation agent. It takes an escalated case through eight phases, from enrichment and retrieval to a plan, the actions your rules let it run, and a nine-section report written into the case.
Runs on every escalated case Acts only up to the risk level you set Writes its report into the case
The first hour of every case looks the same
Your analysts already know what an escalated alert turns into. It becomes a case, the case gets an owner, and the actual investigation, pulling host and user context, checking what that account did elsewhere in the week, reading the timeline, waits for whoever has the time. Most of it is the same first hour, done by hand, every time.
Virtus Pilot does that first hour. It picks the case up the moment Virtus Triage escalates it, enriches the entities, retrieves what your team saw on cases like this one, writes a plan, and runs the part of that plan your rules allow it to run alone. Where the plan reaches something that would change a host or an account, it stops and an analyst decides.
Virtus Triage ends with a verdict,
Virtus Pilot starts there
Two pipelines, two jobs. One reads every alert and decides what deserves a person. The other takes what got through and does the investigation. Neither one is the chat assistant, which is Virtus Assistant and answers your questions on demand.
Virtus Triage
Decides- What arrives
- Every alert your rules route to it.
- What it does
- Enrichment, your policy gates, similar past decisions, then one model call.
- What it may touch
- Read-only lookups. It never changes a host or an account.
- What comes out
- A verdict, a confidence score and the evidence behind them.
Virtus Pilot
Investigates- What arrives
- A case, usually one Virtus Triage escalated.
- What it does
- Eight phases, from enrichment and retrieval through analysis, a plan, the actions it is allowed to take, and a report.
- What it may touch
- Actions through your connectors, up to the risk level you set. Anything above that waits for a person.
- What comes out
- A nine-section report in the case: root cause, scope of impact, timeline, techniques and what it did.
You are here
The eight phases,
in plain words
The same path on every case. Four phases read, two think, one acts inside your limits, and one writes the record.
-
01
No model
Intake
The alert or case is read and normalized. Entities come out of it, hosts, users, IP addresses and files, and the investigation gets its own record under your tenant.
-
02
No model
Enrich
Context for each entity is pulled from the connectors that hold it, five of each type at most. Read-only lookups, nothing is changed here.
-
03
Retrieval
RAG + KAG Retrieve
Past incidents and threat intelligence are retrieved by similarity, and the knowledge graph returns what connects to these entities within four hops.
-
04
Model
Analyze
The model reads the enriched case with that context and returns findings: what it believes happened, a risk score, and the MITRE ATT&CK techniques it maps to.
-
05
Model
Plan
The model writes an action plan with a hypothesis, priority actions and fallbacks. Actions your connectors do not have are dropped and listed rather than attempted.
-
06
Your tools
Execute
Each action either runs through your connectors or waits. Anything above your risk level, and anything that isolates, blocks, terminates, deletes or quarantines, goes to the Approval Center first.
-
07
Model
Evaluate
Is there enough to conclude? If not, the investigation loops back to enrichment carrying what it learned, up to the iteration limit you set.
-
08
Model
Report
The report is written into the case, the entities are added to the knowledge graph, the run is logged and your team is notified.
Three modes, and what each one
may do on its own
The mode is a setting on the rule or the playbook step that starts the investigation, so a case from a lab subnet and a case from a domain controller do not have to run the same way.
It runs the low-risk half and asks for the rest
The default for cases you want moving before anyone opens them. Lookups, queries and enrichment actions run as the plan is written.
It plans, you approve, then it acts
Every planned action goes to the Approval Center with the whole plan attached, so the person approving sees the hypothesis and the reasoning, not one line out of context.
It investigates and writes, and never acts
Intake through the plan, then the report. The execute phase is skipped, so what you get is what it found and what it would have done.
Your risk line, your approvals,
your case record
One setting decides how far it goes alone. Everything past that line lands in front of a person, and everything it does lands in the case.
One setting draws the line
Low keeps it on queries and lookups, medium adds enrichment actions, high reaches containment. Five action words sit above the line whatever you pick.
Approvals sit in one place
Gated actions land in the Approval Center under their own Virtus Pilot tab, each carrying the plan: the hypothesis, the reasoning, the risk assessment and the other actions. Approve or reject them and the investigation resumes where it paused. You can pause, resume or cancel a run at any phase.
What it writes into your case
The case moves to Investigation and the timeline says the investigation started. When it finishes, the report is attached as a note and a second entry carries the summary and the risk score. It takes ownership only if nobody has the case, and it never closes one.
Nine sections, every time
The same report on every investigation, in the case and on its own page.
Nothing reaches the model unredacted
Veil masks IP addresses, hostnames, usernames, email addresses and other identifiers before the model call and restores them in the response. Which categories are masked is your setting.
Questions about Virtus Pilot
1Is Virtus Pilot a chat assistant?
No. The chat product is Virtus Assistant, which answers questions across the platform. Virtus Pilot does not hold a conversation. It runs an investigation from intake to report and hands you the decisions that need a person.
2How does an investigation start?
Usually when Virtus Triage escalates an alert, and the triage rule decides whether the escalation starts Pilot as well. A case rule can start one when a case reaches a stage you name, a playbook can call it as a step, and the API can start one directly.
3Can it isolate a host on its own?
Only if you raise the risk level that far and take isolate off the always-approve list, where it sits by default with block, terminate, delete and quarantine. In Autonomous mode it runs the low-risk part of its plan and sends the rest to the Approval Center. In Guided mode nothing runs until a person approves it.
4Which model does it use?
The one you assign it in Virtus AI Engine, from a cloud provider or a model you host yourself. Pilot and Triage can run on different models, so an investigation can use a larger one than triage does. Veil redaction applies before the call either way.
5Can it run on-premises or air-gapped?
Yes. Cloud, on-premises and air-gapped are all supported, with a self-hosted model where network policy requires it. Each tenant's cases, investigations and access stay separate.
Have any other questions?
Read the full question library
See Virtus Pilot work one of your cases
Bring a case your team escalated last week. We will run the eight phases on it and read back the plan, the actions it would have asked you to approve, and the report it wrote.