Skip to content
Explore platformVirtus Cerebrum
Virtus Cerebrum

Make repeat alerts
cheaper to resolve.

Virtus Cerebrum learns from your analysts and Virtus Triage. Familiar alerts can resolve on your own CPU, without another LLM call, so less of your budget goes to the same answer twice.

Runs on standard CPUsPrivate to your tenantAutomation you control
Virtus CerebrumLive Brain
Illustrative workflow
Analyst decisionsAlert closes, case outcomes, overrides
Virtus Triage verdictsLLM judgement becomes a lesson

Two teachers. Knowledge that stays.

Train Validate Shadow
Virtus CerebrumYour local learning model
CPU onlyPer tenant
Main Brain Optional fleet learning
Eligible noise resolves locallyNo LLM call. No token spend.
Resolved
Uncertain → Virtus TriageFull investigation when it is needed
Advice for your teamA score and the context behind it
New analyst and Triage verdicts feed the next training run.
What local resolution avoidsLLM calls Tokens Repeat triage
Analyst and Triage verdicts train a private model. Validated models score new alerts; eligible noise resolves locally, while uncertain alerts continue to Triage.
01 - Learning

Your team does the work. The knowledge stays.

Every analyst disposition, case outcome and Triage verdict can become a lesson. Cerebrum trains a small model on your tenant’s history, with human decisions carrying more weight.

New labels feed later training runs. Validation gates, shadow evaluation and drift monitoring help you judge whether a candidate is ready for your environment.

No separate labelling project. The work already happening in your SOC builds the knowledge for the next shift.

From verdict to learning signalIllustrative
Decision sourceLearning signal
Analyst closes an alertHuman verdict
Analyst resolves a caseHuman verdict
Analyst corrects the AIHuman verdict
Virtus Triage decidesLower weight
01TrainLocal CPU
02ValidateFive gates
03ShadowLive outcomes
Human and Triage decisions teach the model. Cerebrum’s own verdicts are not recycled as new labels.
02 - Decision

The right amount of autonomy, for your SOC.

Cerebrum can advise an analyst, help order the queue, or resolve proven noise locally. You choose the operating mode. When the model lacks evidence, it returns uncertainty and the alert continues through triage.

Default operating mode

Build a history before you score.

Analysts and Virtus Triage keep working as usual. Labels are captured, but Cerebrum does not score alerts or change the queue.

No Cerebrum scoring. No automatic closure.
Example alertIllustrative
Repeated service-account sign-ins

Known account · scheduled backup window

Handled through normal triageThe eventual verdict becomes a learning signal.

Control stays with your team. Automatic closure needs rule-level evidence and an allow-list. Daily caps limit it; a reopened alert can suspend that rule’s automation.

Main BrainOptional
Fleet experienceImperum Main Brain
Opt-in contribution ↑↓ Signed model update
Your SOCYour own model
Another SOCIts own model
Verify packageShadowActivate deliberately
Participation is optional. Imported fleet models never activate themselves.
03 - Fleet learning

Your own brain. A wider pool of experience.

Local learning works on its own. If you opt in to Main Brain, signed, anonymised contributions can help train a fleet model that is offered back to participating deployments.

Each tenant keeps its own model and controls. Contributions need consent; incoming packages are verified and evaluated before deliberate activation.

A useful starting point for a new tenant. MSSPs can bring fleet experience to multiple SOCs while keeping each activation under control.

04 - Control and impact

See the decisions. Account for the savings.

Cerebrum makes the learning loop visible. See the model that is active, compare its performance, inspect disagreements and roll back. Then follow what local resolutions avoided in LLM calls, tokens, energy and carbon.

An example of what local resolution removes
9,000,000tokens never sent, per month

At 10,000 repeat false positives a month and about 900 tokens per triage verdict, that’s 9 million LLM tokens avoided. Cerebrum resolves eligible alerts locally on standard CPUs, reducing usage of your LLM provider or self-hosted model.

103 kgCO2 avoided per year, modeled from those tokens
at 2.0 Wh per 1,000 tokens and 475 g per kWh

Illustrative volume, not a customer result or guaranteed saving. Actual figures depend on the alerts eligible for local resolution, and on the model and hardware you run.

What the impact view tells you
LLM calls avoided

Decisions resolved locally instead of by an LLM.

Tokens and LLM time avoided

Counted from the calls that did not happen, against usage measured in the reporting window.

CO2 avoided

Modeled from the tokens saved. Both conversion assumptions are shown on screen and tunable.

Analyst time returned

An estimate with the time baseline made explicit.

Scoring an alert does not itself mean an LLM call was avoided.

Know what is live.

Review training gates, compare model versions and inspect shadow outcomes before raising the level of automation.

Change course quickly.

Roll back a model or use the audited kill switch to stop Cerebrum scoring and label capture.

Fix noise at its source.

Rank noisy rules by their cost, then hand a rule to Virtus Optimus when licensed to investigate a fix.

See Virtus Optimus
Getting started

Start with the decisions you already make.

Cerebrum is included in the Autonomous SOC and SecOps Platform tiers. Training and inference run on standard CPUs inside your deployment, including on-premises and air-gapped environments.

Begin with capture. Advance when the evidence and your team are ready.

  1. 01Capture

    Leave the mode off while normal triage builds your history.

  2. 02Train and evaluate

    Review a candidate’s validation gates and shadow outcomes.

  3. 03Advise and prioritize

    Use the score to support decisions and order the queue.

  4. 04Automate selectively

    Allow proven rules, set caps and review the impact.

Questions about Virtus Cerebrum.

1Does Cerebrum replace Virtus Triage?

No. Cerebrum learns from previous verdicts and scores alerts locally. Virtus Triage investigates the cases that still need the larger model, while Cerebrum can supply useful context or resolve eligible familiar cases without another LLM call.

2Does every score save tokens?

No. Advisory scoring can still be followed by an LLM investigation. Token savings arise when an eligible case resolves locally and the LLM call is avoided.

3Will Cerebrum close alerts automatically?

The default operating mode is Off: labels are captured, but alerts are not scored. Automatic closure requires automation mode and rule-level evidence, an allow-list and caps. Reopened alerts can suspend a rule’s automation.

4Does our learning data leave the deployment?

Local training and inference stay inside your deployment. Optional Main Brain participation can share signed, anonymised contributions with Imperum under consent controls. Imported fleet models require deliberate activation.

5How do we know a new model is ready?

Training candidates pass validation gates and can be compared against real outcomes in shadow. The console exposes evaluation results, disagreements and model versions so your team can review performance and roll back when needed.

Have any other questions?
Talk to our team

Bring the rule your team istired of closing.

We’ll show you how Cerebrum learns from your triage history, where it can help, and what local resolution could save.