Make repeat alerts
cheaper to resolve.
Virtus Cerebrum learns from your analysts and Virtus Triage. Familiar alerts can resolve on your own CPU, without another LLM call, so less of your budget goes to the same answer twice.
Two teachers. Knowledge that stays.
The work your analysts already do becomes training data. Human decisions carry more weight than automated verdicts.
Your team does the work. The knowledge stays.
Every analyst disposition, case outcome and Triage verdict can become a lesson. Cerebrum trains a small model on your tenant’s history, with human decisions carrying more weight.
New labels feed later training runs. Validation gates, shadow evaluation and drift monitoring help you judge whether a candidate is ready for your environment.
No separate labelling project. The work already happening in your SOC builds the knowledge for the next shift.
The right amount of autonomy, for your SOC.
Cerebrum can advise an analyst, help order the queue, or resolve proven noise locally. You choose the operating mode. When the model lacks evidence, it returns uncertainty and the alert continues through triage.
Build a history before you score.
Analysts and Virtus Triage keep working as usual. Labels are captured, but Cerebrum does not score alerts or change the queue.
Known account · scheduled backup window
Control stays with your team. Automatic closure needs rule-level evidence and an allow-list. Daily caps limit it; a reopened alert can suspend that rule’s automation.
Your own brain. A wider pool of experience.
Local learning works on its own. If you opt in to Main Brain, signed, anonymised contributions can help train a fleet model that is offered back to participating deployments.
Each tenant keeps its own model and controls. Contributions need consent; incoming packages are verified and evaluated before deliberate activation.
A useful starting point for a new tenant. MSSPs can bring fleet experience to multiple SOCs while keeping each activation under control.
See the decisions. Account for the savings.
Cerebrum makes the learning loop visible. See the model that is active, compare its performance, inspect disagreements and roll back. Then follow what local resolutions avoided in LLM calls, tokens, energy and carbon.
At 10,000 repeat false positives a month and about 900 tokens per triage verdict, that’s 9 million LLM tokens avoided. Cerebrum resolves eligible alerts locally on standard CPUs, reducing usage of your LLM provider or self-hosted model.
at 2.0 Wh per 1,000 tokens and 475 g per kWh
Illustrative volume, not a customer result or guaranteed saving. Actual figures depend on the alerts eligible for local resolution, and on the model and hardware you run.
Decisions resolved locally instead of by an LLM.
Counted from the calls that did not happen, against usage measured in the reporting window.
Modeled from the tokens saved. Both conversion assumptions are shown on screen and tunable.
An estimate with the time baseline made explicit.
Know what is live.
Review training gates, compare model versions and inspect shadow outcomes before raising the level of automation.
Change course quickly.
Roll back a model or use the audited kill switch to stop Cerebrum scoring and label capture.
Fix noise at its source.
Rank noisy rules by their cost, then hand a rule to Virtus Optimus when licensed to investigate a fix.
Start with the decisions you already make.
Cerebrum is included in the Autonomous SOC and SecOps Platform tiers. Training and inference run on standard CPUs inside your deployment, including on-premises and air-gapped environments.
Begin with capture. Advance when the evidence and your team are ready.
- 01Capture
Leave the mode off while normal triage builds your history.
- 02Train and evaluate
Review a candidate’s validation gates and shadow outcomes.
- 03Advise and prioritize
Use the score to support decisions and order the queue.
- 04Automate selectively
Allow proven rules, set caps and review the impact.
Questions about Virtus Cerebrum.
1Does Cerebrum replace Virtus Triage?
No. Cerebrum learns from previous verdicts and scores alerts locally. Virtus Triage investigates the cases that still need the larger model, while Cerebrum can supply useful context or resolve eligible familiar cases without another LLM call.
2Does every score save tokens?
No. Advisory scoring can still be followed by an LLM investigation. Token savings arise when an eligible case resolves locally and the LLM call is avoided.
3Will Cerebrum close alerts automatically?
The default operating mode is Off: labels are captured, but alerts are not scored. Automatic closure requires automation mode and rule-level evidence, an allow-list and caps. Reopened alerts can suspend a rule’s automation.
4Does our learning data leave the deployment?
Local training and inference stay inside your deployment. Optional Main Brain participation can share signed, anonymised contributions with Imperum under consent controls. Imported fleet models require deliberate activation.
5How do we know a new model is ready?
Training candidates pass validation gates and can be compared against real outcomes in shadow. The console exposes evaluation results, disagreements and model versions so your team can review performance and roll back when needed.
Have any other questions?
Talk to our team
Bring the rule your team istired of closing.
We’ll show you how Cerebrum learns from your triage history, where it can help, and what local resolution could save.