A verdict on every alert, not just the loud ones
Imperum's autonomous alert triage runs Virtus Triage, a 7-stage AI pipeline, on every incoming alert: enrichment, your policy checks, your organizational context, then a verdict with confidence and the evidence attached. Analysts open finished work, not a raw queue.
Runs on every alert Your policy gates before any model call Every verdict shows its evidence
Triage is where SOCs lose the day
Your analysts already know how the shift goes. The queue fills faster than anyone can read it, most of what is in it turns out to be nothing, and the alerts that matter wait behind the ones that do not. Sorting takes the day. The investigation starts when the day is nearly over.
Virtus Triage does the sorting. Every incoming alert goes through the same seven stages and comes out with a verdict, a confidence score and the evidence behind it. Known-good and known-bad resolve on your rules before a model is called. What reaches an analyst is a decision to check, not a queue to work.
The seven stages,
in plain words
The same path for every alert. The first three stages are deterministic and run on your data and your rules. A model is called only for the alerts that get past them.
-
01
No model
Ingest
The alert is read from the Search Index. Its entities are pulled out, hosts, users, hashes, domains, and its severity is normalized so every source reads the same way.
-
02
No model
Enrich
Asset criticality, compliance tags, whether the account is privileged, and related events from the last 24 hours. Read-only lookups in your connectors add what the alert itself did not carry.
-
03
No model
Policy Gates
Your rules run first, in order, and the first match wins. Six gates ship with the pipeline: never auto-close, high-fidelity EDR, compliance mandate, privileged account, duplicate and alert storm. A match ends triage here with a verdict at full confidence.
-
04
Retrieval
RAG + KAG Context
Similar past decisions, threat intelligence, related alerts and attack chains from the entity graph are retrieved in parallel. Your analysts' earlier verdicts on alerts like this one are part of that context.
-
05
Model
LLM Decision
The model receives the enriched alert and the retrieved context and returns one of three verdicts with a confidence score, reason codes from a fixed list and a written summary. Low temperature, fixed output schema.
-
06
No model
Validate
The confidence is checked against your thresholds. A close verdict under the threshold, or one with no evidence behind it, is not executed. An alert whose text carries known threat indicators is promoted to escalate.
-
07
No model
Audit & Execute
The decision is written to the audit index and the knowledge graph, the alert is updated, and a case or a review item is created when the verdict calls for one. The record is complete before anything else happens.
Three verdicts, and what
happens after each
Every alert ends in one of three states. What the pipeline does next is a setting on the rule, not a decision the model makes.
The alert is closed as a false positive
The reasoning and the evidence stay attached. The alert remains searchable and the decision stays in the audit index, so a later analyst can see why it closed and reopen it if they disagree.
- Close Alert
- Close & Notify Team
A case is created in Casebook
The case opens with the triage record on its own tab: verdict, confidence, the stage that decided it and the context it used. You choose whether Virtus Pilot starts the full investigation at the same time.
- Create Case
- Create Case + Trigger Pilot
- Trigger Pilot Investigation
An analyst gets the alert, with the work done
The model could not decide with confidence, or your threshold was not met. The alert goes to the Virtus Triage queue in Approvals with the enrichment, the context and the model's reasoning already attached. The analyst closes, escalates or overrides.
- Queue for Analyst Review
- Escalate to SOC Lead
Your thresholds, your overrides,
your record
The pipeline decides inside limits you set, shows its work on every decision, and changes its behaviour when your analysts correct it.
The thresholds are yours
Auto-close needs a confidence of 0.85 by default and escalate needs 0.70. Critical severity always escalates. Each rule can carry its own numbers, its own severity filter and its own list of sources, so a vulnerability scanner and an EDR do not share one setting.
Every verdict shows its evidence
One report behind every decision: the verdict and its confidence against your thresholds, why it was reached, the entities, the enrichment, the retrieved references, the graph context and the similar past cases. Sections appear when there is data for them.
Analysts override, and the system remembers
An override needs a new verdict and a written reason. It is saved to the triage history, retrieved as context the next time a similar alert arrives, and counted in the override rate you watch in Virtus Stats.
It learns your false positives
Virtus Cerebrum scores the same alert against your analysts' confirmed history and passes its estimate to the model as advice. It never closes an alert on its own.
See Virtus CerebrumNothing reaches the model unredacted
Veil masks IP addresses, hostnames, usernames, email addresses and other identifiers before the model call and restores them in the response. Which categories are masked is your setting.
Questions about Virtus Triage
1Which alerts does Virtus Triage run on?
Every alert your rules route to it, from any source your connectors normalize. A rule can filter by severity or by source, or leave both open. Alerts from a connector without a normalizer profile are held until you add one, so the pipeline never decides on fields it cannot read.
2Does every alert reach the language model?
No. Ingest, enrichment and your policy gates run first with no model call. A gate match produces the verdict on its own. Only alerts that pass the gates go on to retrieval and the model, which is why the gates you write have the largest effect on cost and speed.
3What can it decide without a person?
Close an alert when confidence clears your auto-close threshold, create a case when it clears the escalate threshold, and queue anything else for review. Whether a new case also starts a Virtus Pilot investigation is a setting on the rule. Anything that would change a host or an account belongs to the investigation and approval steps that follow, not to triage.
4Which model does it use?
The one you assign to it in Virtus AI Engine, from a cloud provider or a model you host yourself. Triage and Pilot can run on different models, so triage can use a smaller, faster one. Veil redaction applies before the call either way.
5Can it run on-premises or air-gapped?
Yes. Cloud, on-premises and air-gapped are all supported, with a self-hosted model where network policy requires it. Each tenant's alerts, decisions and access stay separate, which is what enterprise and provider deployments need.
Have any other questions?
Read the full question library
See Virtus Triage work a day of your alerts
Bring a day of alerts from your SIEM or EDR. We will route them through the seven stages and read the verdicts back to you with the evidence attached.