Skip to content
Explore solutionsThreat, Detection & DFIR
For Threat, Detection & DFIR teams

Turn a finding into
your next line of defense.

Imperum brings threat hunting, detection engineering and incident investigation into one security operations platform. Investigate a hypothesis, carry the findings into a case, and use the evidence to improve what you detect next.

Hunt with contextInvestigate with evidenceTest your detections
One finding. Work your team can build on.Illustrative workflow · synthetic data
HUNT / ASSISTANT
Is remote service execution suspicious on LAB-WS-07?
Finding with an evidence referenceService installationReview against expected admin activity.
Analyst opens a case
CASEBOOKOpen
CASE-DEMO-07

Remote service activity

LAB-WS-07 · investigation

ReportHunt findings
ContextCited alert & host
Next question
What ran on the endpoint?
FORENSICS / SOURCE RECORD
LAB-WS-07
Selected process recordremotesvc.exeProcess
Source artifact
Windows.System.Pslist
Parent process
services.exe

Inspect original fields before concluding what happened.

DETECTION ENGINEER / HUMAN HANDOFFMake the finding useful next time.

Author a Sigma rule → inspect test matches → deploy deliberately.

Test results reviewed

An analyst reviews the hunt, opens a case and inspects endpoint evidence. A detection engineer then authors and tests a rule; the hunt is not automatically converted into one.

01 - Threat hunting & intelligence

Start with a question. Keep the evidence behind the answer.

Hunters need to establish whether a threat is present in their environment. Intelligence analysts need to make an actor’s behavior useful to that search.

Investigate the hypothesis

In the AI Assistant, Deep Hunt plans an investigation, queries available data and follows up on findings. Evidence references and reported gaps help you judge what the investigation established—and what still needs work.

Explore the AI Assistant ↗

Give the hunt a direction

Use Cognitio to research actor aliases, target sectors and mapped MITRE ATT&CK techniques, with source references. Turn the relevant behavior into a hypothesis for your own estate.

Explore Cognitio ↗
A finding the next analyst can use.

Open a case from a persisted Assistant report. Its report text and cited alerts provide a starting point for investigation; in a case-scoped conversation, attach the report as a note.

Deep Hunt requires enabled Assistant Threads, the appropriate permissions and available data. Actor mappings depend on the intelligence available for that profile.

02 - Detection engineering

Know what your rule matches before you switch it on.

A useful hunt can inform a detection. Your engineer authors or imports a Sigma rule—a shared detection format—then tests it against indexed data and inspects the returned matches. Testing and deployment are separate controls.

ILLUSTRATIVE RULE REVIEW

Remote service installation

Windows event data · Sigma

  1. 01
    Author or import

    Express the behavior to detect.

  2. 02
    Inspect test matches

    Check whether expected admin work also matches.

  3. 03
    Deploy

    Enable the detector with the required permission.

Operate your detections

Detection Lake keeps rule definitions, deployment status and errors together. A test result gives you evidence about matches in available data; it does not establish complete threat coverage.

Explore Detection Lake ↗

Investigate rule health

When licensed and connected, Virtus Optimus adds detection health and proposed fixes across supported technologies. Review the proposed change and its checks before applying it under your configured controls.

Explore Virtus Optimus ↗
03 - Digital forensics & incident investigation

Move from a suspicious signal to an explanation you can inspect.

Incident investigators bring alerts, indicators and affected entities into Casebook. Forensic examiners collect suitable endpoint artifacts, search indexed records and inspect the source fields behind timeline entries.

Collect for the question

Select an endpoint and artifacts appropriate to its operating system. Check collection and indexing results before relying on the evidence.

Examine the source

Filter the forensic timeline and open a record’s detail. Compare original timestamps and fields before inferring sequence, cause or dwell time.

Coordinate the response

Use the case to organize the investigation and run response playbooks. Risk rules and configured approvals govern actions such as endpoint isolation.

Keep the conclusion connected to its basis.

The report, case context and source records give the next investigator something to check, rather than a verdict to accept on trust.

Forensic collection needs a configured, reachable endpoint service and collection permission. The forensic timeline is a separate evidence view; collecting an artifact does not automatically attach every record to a case.

04 - Malware analysis

Bring sandbox findings into suspicious email investigations.

In the Email Phishing workflow, selected sandbox connectors can analyze suspicious attachments and, when enabled, URLs. The returned findings add another source of evidence for the investigation.

Use the analysis tools you connect

Sandbox submission is optional and must be configured. Verdicts can arrive later or remain unavailable. This supports malware investigation through connected services; it is not a dedicated reverse-engineering workbench.

Explore Email Phishing investigation ↗
Getting started

Bring one hypothesis and one data source.

Start with a hunt your team needs to resolve. Confirm the relevant data and endpoint access, review the findings together, then test a detection based on what you learned. Availability depends on your licensed modules, integrations and role permissions.

Questions from the team.

1Can we hunt in plain language?

Yes. Deep Hunt in the AI Assistant supports iterative investigation with evidence references. Assistant Threads must be enabled, and the investigation depends on the data, tools and permissions available to your team.

2Does a hunt become a detection automatically?

The workflow shown uses a human handoff. An engineer authors or imports a Sigma rule, tests it against indexed data and deploys it separately. A successful hunt does not automatically create or enable that rule.

3Is every forensic record attached to the case?

No. Casebook holds case context, linked alerts and report notes. Digital Forensics provides collection, search and timeline inspection. Review the available records and the evidence you include in your investigation; collection alone does not mean every record was indexed or attached.

4Which actions need approval?

It depends on the tool, action risk and configured workflow. Response playbooks apply risk and approval controls; endpoint isolation is a high-impact example. Approval requirements vary by action and configured workflow.

Have any other questions? Talk to our team

Bring your next hunt.Build on what you find.

See how a hypothesis, a case and a detection review fit together using the data and tools your team works with.