Structural translation. Still check the fields and behavior in your environment.
Keep your detections
ready for the next threat.
Virtus Optimus maintains the detection rules across your connected security tools. Find noisy or silent rules, trace broken data feeds and build missing coverage—with reviewable changes your team can test and control.
Available analyst outcomes point to a rule worth tuning.
Review the change.
Failed Logon Burst · Splunk
where count > 5where count > 25Example threshold only. Tune against your own data.
Inspect the proposal and simulation results. An authorized operator can approve, then apply the change; later verification checks its outcome.
Adapted product view with synthetic data. This example follows manual review; configured automatic paths are explained below.
Find the rules that need attention.
Watch brings rule health and MITRE ATT&CK coverage together across connected technologies. See silent detections and use available analyst verdicts to identify noise, so your team can focus its tuning effort.
Failed Logon Burst
Available verdicts show repeated false positives.
Privileged Group Change
No recent matches in the observed alert history.
A technique needs coverage
Find a relevant Library rule or start a Design.
Silence is a reason to investigate, not proof that a rule is broken. Noise findings depend on available verdict data and rule matching.
Trace a detection problem to its data.
A valid rule cannot detect an event it never receives. Broken Pipe flags stopped ingestion and parser drift, brings the underlying evidence into view and can add an AI explanation of the likely cause.
Events are arriving unparsed. Check the recent source format and parser configuration, then review the proposed remedy and its checks.
The explanation helps direct an investigation; the evidence remains the basis for the decision.
Build for the data you actually collect.
Tell Optimus Architect what you want to detect. It looks for relevant existing content and grounds authoring in your connected platforms and available schema—the tables and fields in your data.
Start with an existing detection?
When relevant content is found, choose to adopt it or generate a new draft.
Two paths: adopt the existing rule, or generate a new draft.
A reviewable detection
- Chosen target and detection language
- Available field and log-source context
- Draft logic and target-specific checks
- Deployment through the fix lifecycle
Review the result against your environment before it goes live.
Moving to a different platform?
Design also supports rule migration. Convert source rules for a target platform, inspect each result and deploy where the target supports it.
Fill a gap without starting from scratch.
Browse community detection content by technique, source and detection language. Check whether the required data is available, convert for your target and review how faithfully the logic translated.
Field mapping needs attention. Review the conversion notes and adapt fields for your target.
An AI-produced draft. Review the logic and test it against your data.
No usable conversion for this target. Choose another path.
Target capabilities determine whether you can deploy directly or export for manual import. Some content sources require licence acceptance.
Keep the decision connected to the evidence.
Review, apply, verify
Inspect the diff and simulation, approve and apply with the required permissions, then follow the change history and available verification checks. Rollback depends on the target and change type.
Scope automatic changes
Autopilot applies eligible low-risk fixes only for opted-in technologies, allowed fix types and passed simulations. Library auto-deploy is a separate per-technology setting.
A few practical details.
1What do I need to get started?
Virtus Optimus requires its own licence entitlement. Connect a supported technology with the relevant access, import its rules and harvest its schema. AI authoring and explanations also need a configured model provider.
2Does every change need human approval?
The manual path separates simulation, approval and application. Autopilot can apply eligible low-risk fixes for opted-in technologies. Library auto-deploy is a separate opt-in and also requires simulation to pass. Neither setting means every type of change can run automatically.
3Can every connected platform receive rules?
No. Read, test, create, update and rollback capabilities vary by target. Where direct rule creation is unavailable, use export for manual import. Library rules are requested disabled on creation; activation behavior can vary by vendor, so check the target before deployment.
4Does Optimus need Cerebrum?
No. Optimus can operate separately. When Cerebrum rule statistics are available, Optimus can use matched noisy-rule evidence. Missing statistics do not prevent the other health checks.
5Does a passed simulation prove a rule will work?
No. The checks depend on the target and may include syntax, field grounding or execution. They support review; they do not guarantee detection effectiveness or low noise in your environment.
Have a detection estate to improve? Talk to our team
Make your detections
worth maintaining.
Bring a noisy rule, a silent detection or a coverage gap. See how Virtus Optimus helps your team move it forward.