A verdict on every alert, not just the loud ones

Imperum's autonomous alert triage runs Virtus Triage, a 7-stage AI pipeline, on every incoming alert: enrichment, your policy checks, your organizational context, then a verdict with confidence and the evidence attached. Analysts open finished work, not a raw queue.

Book a Demo Watch Tour

Runs on every alert Your policy gates before any model call Every verdict shows its evidence

Triage is where SOCs lose the day

Your analysts already know how the shift goes. The queue fills faster than anyone can read it, most of what is in it turns out to be nothing, and the alerts that matter wait behind the ones that do not. Sorting takes the day. The investigation starts when the day is nearly over.

Virtus Triage does the sorting. Every incoming alert goes through the same seven stages and comes out with a verdict, a confidence score and the evidence behind it. Known-good and known-bad resolve on your rules before a model is called. What reaches an analyst is a decision to check, not a queue to work.

The seven stages,
in plain words

The same path for every alert. The first three stages are deterministic and run on your data and your rules. A model is called only for the alerts that get past them.

  1. 01

    Ingest

    The alert is read from the Search Index. Its entities are pulled out, hosts, users, hashes, domains, and its severity is normalized so every source reads the same way.

    No model
  2. 02

    Enrich

    Asset criticality, compliance tags, whether the account is privileged, and related events from the last 24 hours. Read-only lookups in your connectors add what the alert itself did not carry.

    No model
  3. 03

    Policy Gates

    Your rules run first, in order, and the first match wins. Six gates ship with the pipeline: never auto-close, high-fidelity EDR, compliance mandate, privileged account, duplicate and alert storm. A match ends triage here with a verdict at full confidence.

    No model
  4. 04

    RAG + KAG Context

    Similar past decisions, threat intelligence, related alerts and attack chains from the entity graph are retrieved in parallel. Your analysts' earlier verdicts on alerts like this one are part of that context.

    Retrieval
  5. 05

    LLM Decision

    The model receives the enriched alert and the retrieved context and returns one of three verdicts with a confidence score, reason codes from a fixed list and a written summary. Low temperature, fixed output schema.

    Model
  6. 06

    Validate

    The confidence is checked against your thresholds. A close verdict under the threshold, or one with no evidence behind it, is not executed. An alert whose text carries known threat indicators is promoted to escalate.

    No model
  7. 07

    Audit & Execute

    The decision is written to the audit index and the knowledge graph, the alert is updated, and a case or a review item is created when the verdict calls for one. The record is complete before anything else happens.

    No model

Three verdicts, and what
happens after each

Every alert ends in one of three states. What the pipeline does next is a setting on the rule, not a decision the model makes.

Auto-closedclose

The alert is closed as a false positive

The reasoning and the evidence stay attached. The alert remains searchable and the decision stays in the audit index, so a later analyst can see why it closed and reopen it if they disagree.

  • Close Alert
  • Close & Notify Team
Escalatedescalate

A case is created in Casebook

The case opens with the triage record on its own tab: verdict, confidence, the stage that decided it and the context it used. You choose whether Virtus Pilot starts the full investigation at the same time.

  • Create Case
  • Create Case + Trigger Pilot
  • Trigger Pilot Investigation
Needs humanneeds_human

An analyst gets the alert, with the work done

The model could not decide with confidence, or your threshold was not met. The alert goes to the Virtus Triage queue in Approvals with the enrichment, the context and the model's reasoning already attached. The analyst closes, escalates or overrides.

  • Queue for Analyst Review
  • Escalate to SOC Lead

Your thresholds, your overrides,
your record

The pipeline decides inside limits you set, shows its work on every decision, and changes its behaviour when your analysts correct it.

The thresholds are yours

Auto-close needs a confidence of 0.85 by default and escalate needs 0.70. Critical severity always escalates. Each rule can carry its own numbers, its own severity filter and its own list of sources, so a vulnerability scanner and an EDR do not share one setting.

Every verdict shows its evidence

One report behind every decision: the verdict and its confidence against your thresholds, why it was reached, the entities, the enrichment, the retrieved references, the graph context and the similar past cases. Sections appear when there is data for them.

Analysts override, and the system remembers

An override needs a new verdict and a written reason. It is saved to the triage history, retrieved as context the next time a similar alert arrives, and counted in the override rate you watch in Virtus Stats.

It learns your false positives

Virtus Cerebrum scores the same alert against your analysts' confirmed history and passes its estimate to the model as advice. It never closes an alert on its own.

See Virtus Cerebrum

Nothing reaches the model unredacted

Veil masks IP addresses, hostnames, usernames, email addresses and other identifiers before the model call and restores them in the response. Which categories are masked is your setting.

Questions about Virtus Triage

1Which alerts does Virtus Triage run on?

Every alert your rules route to it, from any source your connectors normalize. A rule can filter by severity or by source, or leave both open. Alerts from a connector without a normalizer profile are held until you add one, so the pipeline never decides on fields it cannot read.

2Does every alert reach the language model?

No. Ingest, enrichment and your policy gates run first with no model call. A gate match produces the verdict on its own. Only alerts that pass the gates go on to retrieval and the model, which is why the gates you write have the largest effect on cost and speed.

3What can it decide without a person?

Close an alert when confidence clears your auto-close threshold, create a case when it clears the escalate threshold, and queue anything else for review. Whether a new case also starts a Virtus Pilot investigation is a setting on the rule. Anything that would change a host or an account belongs to the investigation and approval steps that follow, not to triage.

4Which model does it use?

The one you assign to it in Virtus AI Engine, from a cloud provider or a model you host yourself. Triage and Pilot can run on different models, so triage can use a smaller, faster one. Veil redaction applies before the call either way.

5Can it run on-premises or air-gapped?

Yes. Cloud, on-premises and air-gapped are all supported, with a self-hosted model where network policy requires it. Each tenant's alerts, decisions and access stay separate, which is what enterprise and provider deployments need.

Have any other questions?
Read the full question library

See Virtus Triage work a day of your alerts

Bring a day of alerts from your SIEM or EDR. We will route them through the seven stages and read the verdicts back to you with the evidence attached.

Book a 30-minute demo Watch the platform tour