Imperum brings threat hunting, detection engineering and incident investigation into one security operations platform. Investigate a hypothesis, carry the findings into a case, and use the evidence to improve what you detect next.
Hunt with contextInvestigate with evidenceTest your detections
One finding. Work your team can build on.Illustrative workflow · synthetic data
HUNT / ASSISTANT
Is remote service execution suspicious on LAB-WS-07?
Finding with an evidence referenceService installationReview against expected admin activity.
Analyst opens a case
CASEBOOKOpen
CASE-DEMO-07
Remote service activity
LAB-WS-07 · investigation
ReportHunt findings
ContextCited alert & host
Next question What ran on the endpoint?
FORENSICS / SOURCE RECORD
LAB-WS-07
Selected process recordremotesvc.exeProcess
Source artifact
Windows.System.Pslist
Parent process
services.exe
Inspect original fields before concluding what happened.
DETECTION ENGINEER / HUMAN HANDOFFMake the finding useful next time.
Author a Sigma rule → inspect test matches → deploy deliberately.
Test results reviewed
An analyst reviews the hunt, opens a case and inspects endpoint evidence. A detection engineer then authors and tests a rule; the hunt is not automatically converted into one.
01 - Threat hunting & intelligence
Start with a question. Keep the evidence behind the answer.
Hunters need to establish whether a threat is present in their environment. Intelligence analysts need to make an actor’s behavior useful to that search.
Investigate the hypothesis
In the AI Assistant, Deep Hunt plans an investigation, queries available data and follows up on findings. Evidence references and reported gaps help you judge what the investigation established—and what still needs work.
Use Cognitio to research actor aliases, target sectors and mapped MITRE ATT&CK techniques, with source references. Turn the relevant behavior into a hypothesis for your own estate.
Open a case from a persisted Assistant report. Its report text and cited alerts provide a starting point for investigation; in a case-scoped conversation, attach the report as a note.
Deep Hunt requires enabled Assistant Threads, the appropriate permissions and available data. Actor mappings depend on the intelligence available for that profile.
02 - Detection engineering
Know what your rule matches before you switch it on.
A useful hunt can inform a detection. Your engineer authors or imports a Sigma rule—a shared detection format—then tests it against indexed data and inspects the returned matches. Testing and deployment are separate controls.
ILLUSTRATIVE RULE REVIEW
Remote service installation
Windows event data · Sigma
01
Author or import
Express the behavior to detect.
02
Inspect test matches
Check whether expected admin work also matches.
03
Deploy
Enable the detector with the required permission.
Operate your detections
Detection Lake keeps rule definitions, deployment status and errors together. A test result gives you evidence about matches in available data; it does not establish complete threat coverage.
When licensed and connected, Virtus Optimus adds detection health and proposed fixes across supported technologies. Review the proposed change and its checks before applying it under your configured controls.
Move from a suspicious signal to an explanation you can inspect.
Incident investigators bring alerts, indicators and affected entities into Casebook. Forensic examiners collect suitable endpoint artifacts, search indexed records and inspect the source fields behind timeline entries.
Collect for the question
Select an endpoint and artifacts appropriate to its operating system. Check collection and indexing results before relying on the evidence.
Examine the source
Filter the forensic timeline and open a record’s detail. Compare original timestamps and fields before inferring sequence, cause or dwell time.
Coordinate the response
Use the case to organize the investigation and run response playbooks. Risk rules and configured approvals govern actions such as endpoint isolation.
Keep the conclusion connected to its basis.
The report, case context and source records give the next investigator something to check, rather than a verdict to accept on trust.
Forensic collection needs a configured, reachable endpoint service and collection permission. The forensic timeline is a separate evidence view; collecting an artifact does not automatically attach every record to a case.
Bring sandbox findings into suspicious email investigations.
In the Email Phishing workflow, selected sandbox connectors can analyze suspicious attachments and, when enabled, URLs. The returned findings add another source of evidence for the investigation.
Use the analysis tools you connect
Sandbox submission is optional and must be configured. Verdicts can arrive later or remain unavailable. This supports malware investigation through connected services; it is not a dedicated reverse-engineering workbench.
Start with a hunt your team needs to resolve. Confirm the relevant data and endpoint access, review the findings together, then test a detection based on what you learned. Availability depends on your licensed modules, integrations and role permissions.
Questions from the team.
1Can we hunt in plain language?
Yes. Deep Hunt in the AI Assistant supports iterative investigation with evidence references. Assistant Threads must be enabled, and the investigation depends on the data, tools and permissions available to your team.
2Does a hunt become a detection automatically?
The workflow shown uses a human handoff. An engineer authors or imports a Sigma rule, tests it against indexed data and deploys it separately. A successful hunt does not automatically create or enable that rule.
3Is every forensic record attached to the case?
No. Casebook holds case context, linked alerts and report notes. Digital Forensics provides collection, search and timeline inspection. Review the available records and the evidence you include in your investigation; collection alone does not mean every record was indexed or attached.
4Which actions need approval?
It depends on the tool, action risk and configured workflow. Response playbooks apply risk and approval controls; endpoint isolation is a high-impact example. Approval requirements vary by action and configured workflow.