Skip to content
Explore platformSecOps Platform
SecOps Platform

Move the investigation forward.
Keep the context.

Imperum SecOps Platform brings detections, case management, response playbooks and endpoint forensics into one working environment. Your team can investigate an alert, act with the right context and leave a clear record for the next analyst.

From detection to investigationPlaybooks with case context
The work around a caseIllustrative workflow · synthetic data
Detection Lake
Deployed rule
Encoded PowerShellAlert · LAB-WS-07

An analyst or rule creates or groups a case.

CasebookInvestigation
CASE-041 · illustrativeSuspicious script execution
HostLAB-WS-07
Userdemo.analyst
SourceDetection alert
Investigation contextAlert, entities and analyst notes
OverviewPlaybooksNotes
Automatio
  1. 1
    Use case contextHost, user and indicators
  2. 2
    Check reputationConfigured connector
  3. 3
    Human approvalPending in this example

Run history stays linked to the case.

Digital ForensicsLAB-WS-07 · collected events
09:14Sign-in
09:16Process
09:17Network
Analyst records findingsEvidence informs the case notes
One investigation, with the context behind the next decision.

A deployed detection rule produces an alert. An analyst or a configured rule can create a case or group it with related alerts.

Casebook brings the alert, entities and investigation notes together. The team can set ownership and follow the work through its stages.

A selected playbook receives the case’s available context. This example pauses at a configured human approval node; its run remains linked to the case.

An analyst inspects collected endpoint events and records findings in the case notes. The response is still awaiting approval; evidence collection does not close the case.

An example of connected workflows, not a required sequence. Actions depend on the playbook, permissions and configured services.
01 - Detection Lake

Choose what deserves an investigation.

Author or import detection rules, deploy the ones you need and inspect the alerts they produce. Keep the rule and the matching activity close enough to understand why work entered the queue.

From rule to alertIllustrative rule
Detection ruleEncoded PowerShell
Event source
Process activity
Match
Encoded command argument
Result
Alert for analyst review
01

Prepare the ruleReview the pattern and the data it needs.

02

Deploy deliberatelyRule auto-deploy is off by default.

03

Inspect the matchUse the alert’s context to start investigating.

A traceable starting point. Analysts can follow the detection into the investigation instead of working from a severity label alone.

Explore Detection Lake
02 - Casebook

Give the next analyst the whole picture.

Casebook holds related alerts, entities, notes and the investigation timeline. Run a playbook from the case and review its execution history there. The next person can pick up the work with its context intact.

CASE-041 · investigation recordSynthetic example
Source alertEncoded PowerShell on LAB-WS-07Linked
PlaybookReview suspicious host activityAwaiting approval
Analyst noteProcess activity followed the sign-in. Review the account and command.Team note

Virtus Case Prioritizer

Recommends a priority from signals such as alert severity, threat intelligence and entity risk. When available, Cerebrum’s machine-learning estimate of false-positive likelihood adds context. Priority updates follow your configuration.

Help the team decide what to investigate first.

Virtus Case Router

Ranks eligible analysts using skills and available capacity. A trained tenant model can add learning from closed-case history; deterministic ranking provides a fallback. Assignment follows the configured routing policy.

Match the work to the people who can take it.

Explore Casebook
03 - Automatio

Turn the response procedure into a playbook.

Automatio connects triggers, actions and conditions in a visual workflow. A case can supply the host, user and indicators a playbook needs. Connector actions perform the work, and configured approval steps give the team a decision point.

Review suspicious host activityIllustrative playbook
TriggerRun from caseCASE-041 · LAB-WS-07
Connector actionCheck reputationUse case indicators
Suspicious result?Condition on the action output
Match
Human approvalApprove host isolationAwaiting a decision
Approved ↘Isolate hostConfigured action
Rejected ↘Analyst follow-upNo isolation on this path
No match
Continue investigationSkip this containment branch
Explore a decision

This example waits at an explicit human approval node. Select a path to see what happens next.

Approval and timeout behavior are configurable. An approval step is not a universal default for every action. Available actions depend on connected services and permissions.

Repeat the procedure, keep the evidence of the run. Execution history shows which steps ran and what they returned, so the team can review the response.

Explore Automatio
04 - Digital Forensics

Find out what happened on the endpoint.

Collect endpoint artifacts, search the indexed evidence and inspect events on a forensic timeline. Filter by host and time, then open an event to examine its detail. The chronology helps the analyst test an explanation against the evidence.

Forensic timelineLAB-WS-07 · synthetic events
09:14—09:17Collected activity
Authentication event

Account sign-in

Host
LAB-WS-07
Account
demo.analyst
Time
09:14

Establish which account was active before the process event.

Process event

Encoded PowerShell

Host
LAB-WS-07
Process
powershell.exe
Argument
-enc [sample]

Review the command and its surrounding activity. An encoded argument alone does not establish malicious intent.

Network event

Outbound connection

Host
LAB-WS-07
Destination
203.0.113.24
Time
09:17

Investigate the destination and correlate it with other evidence before drawing a conclusion.

The handoff: the analyst records relevant findings in Casebook notes. Collection and indexing must be configured; the timeline shows the evidence available to the user.

A clearer basis for the next decision. Keep the findings and the reasoning with the investigation so another analyst can review them.

Explore Digital Forensics
Getting started

Start with one investigation your team knows.

SecOps Platform extends Autonomous SOC with operational surfaces including Detection Lake, Automatio and endpoint forensics. Alerts and Cases are shared foundations. Access depends on your license, permissions and configured services.

  1. 01Connect the relevant data

    Choose the event sources and endpoint evidence needed for the investigation.

  2. 02Review the procedure

    Check the case context, connector actions, approval steps and timeout policies.

  3. 03Follow the record

    Review the playbook run and save the findings that support the next decision.

Explore Integrations

Questions about SecOps Platform.

1How does it relate to Autonomous SOC?

Autonomous SOC provides the AI capabilities and analyst-facing workflows. SecOps Platform extends that foundation with operational surfaces such as detection management, playbook automation and endpoint forensics. Cases are available in both. Individual module grants and permissions still apply.

2Does every alert follow the same path?

No. Cases can be opened by analysts or configured workflows. Playbooks can run against a case, and forensic investigation is available when endpoint evidence is needed. The illustration shows one example, not a mandatory sequence.

3Will every response action wait for approval?

No. Approval depends on the action, playbook and applicable policies. A human approval node creates an explicit decision point with approved and rejected paths; timeout behavior is also configurable. Review those controls when designing the procedure.

4Do forensic findings appear in the case automatically?

The forensic timeline presents indexed endpoint events. In the workflow shown here, the analyst reviews those events and records the relevant findings in the case notes. It does not represent automatic attachment of every collection or automatic case closure.

Have any other questions?
Talk to our team

Bring an incident.See the whole investigation.

See how your team could connect the alert, the response procedure and the evidence in Imperum.