Skip to content
Explore platformVirtus Optimus
Virtus Optimus

Keep your detections
ready for the next threat.

Virtus Optimus maintains the detection rules across your connected security tools. Find noisy or silent rules, trace broken data feeds and build missing coverage—with reviewable changes your team can test and control.

Detection healthDetection-as-CodeControlled changes
Detection estateIllustrative workflow
Rule healthNoisy rule found
Data signalsFeeds in view
Change controlAwaiting review
Connected technologies Example estate
MMicrosoft Sentinel
Rule inventory
Checks available
SSplunk
Failed Logon Burst
Needs review
EElastic Security
Rule inventory
Checks available
IImperum
Native detections
Checks available
Selected rule evidenceRepeated false-positive verdicts

Available analyst outcomes point to a rule worth tuning.

Medium risk · exampleRule logic

Review the change.

Failed Logon Burst · Splunk

Proposed SPL change Illustrative
where count > 5
+where count > 25

Example threshold only. Tune against your own data.

Simulation passed · example Pending approval
A proposal your team can inspect.Review the diff and checks before approving.

Inspect the proposal and simulation results. An authorized operator can approve, then apply the change; later verification checks its outcome.

Adapted product view with synthetic data. This example follows manual review; configured automatic paths are explained below.

01 - Watch

Find the rules that need attention.

Watch brings rule health and MITRE ATT&CK coverage together across connected technologies. See silent detections and use available analyst verdicts to identify noise, so your team can focus its tuning effort.

From a finding to the next actionIllustrative findings
Noisy

Failed Logon Burst

Available verdicts show repeated false positives.

Review a fix
Silent

Privileged Group Change

No recent matches in the observed alert history.

Inspect rule & data
Coverage gap

A technique needs coverage

Find a relevant Library rule or start a Design.

Build coverage

Silence is a reason to investigate, not proof that a rule is broken. Noise findings depend on available verdict data and rule matching.

02 - Broken Pipe

Trace a detection problem to its data.

A valid rule cannot detect an event it never receives. Broken Pipe flags stopped ingestion and parser drift, brings the underlying evidence into view and can add an AI explanation of the likely cause.

Events arriveSource is active
Parser driftExpected fields are missing
Detection at riskInspect the affected rule
Illustrative evidence

Events are arriving unparsed. Check the recent source format and parser configuration, then review the proposed remedy and its checks.

The explanation helps direct an investigation; the evidence remains the basis for the decision.

03 - Design

Build for the data you actually collect.

Tell Optimus Architect what you want to detect. It looks for relevant existing content and grounds authoring in your connected platforms and available schema—the tables and fields in your data.

Optimus Architect Illustrative session
Detect suspicious PowerShell execution on our Windows hosts.
Recall

Start with an existing detection?

When relevant content is found, choose to adopt it or generate a new draft.

Two paths: adopt the existing rule, or generate a new draft.

A reviewable detection

  • Chosen target and detection language
  • Available field and log-source context
  • Draft logic and target-specific checks
  • Deployment through the fix lifecycle

Review the result against your environment before it goes live.

Moving to a different platform?

Design also supports rule migration. Convert source rules for a target platform, inspect each result and deploy where the target supports it.

04 - Library

Fill a gap without starting from scratch.

Browse community detection content by technique, source and detection language. Check whether the required data is available, convert for your target and review how faithfully the logic translated.

Know what a conversion preservesConversion fidelity
Exact

Structural translation. Still check the fields and behavior in your environment.

Partial

Field mapping needs attention. Review the conversion notes and adapt fields for your target.

AI-translated

An AI-produced draft. Review the logic and test it against your data.

Unsupported

No usable conversion for this target. Choose another path.

Source and attribution stay with the rule.

Target capabilities determine whether you can deploy directly or export for manual import. Some content sources require licence acceptance.

05 - Control & handoffs

Keep the decision connected to the evidence.

Review, apply, verify

Inspect the diff and simulation, approve and apply with the required permissions, then follow the change history and available verification checks. Rollback depends on the target and change type.

Scope automatic changes

Autopilot applies eligible low-risk fixes only for opted-in technologies, allowed fix types and passed simulations. Library auto-deploy is a separate per-technology setting.

A few practical details.

1What do I need to get started?

Virtus Optimus requires its own licence entitlement. Connect a supported technology with the relevant access, import its rules and harvest its schema. AI authoring and explanations also need a configured model provider.

2Does every change need human approval?

The manual path separates simulation, approval and application. Autopilot can apply eligible low-risk fixes for opted-in technologies. Library auto-deploy is a separate opt-in and also requires simulation to pass. Neither setting means every type of change can run automatically.

3Can every connected platform receive rules?

No. Read, test, create, update and rollback capabilities vary by target. Where direct rule creation is unavailable, use export for manual import. Library rules are requested disabled on creation; activation behavior can vary by vendor, so check the target before deployment.

4Does Optimus need Cerebrum?

No. Optimus can operate separately. When Cerebrum rule statistics are available, Optimus can use matched noisy-rule evidence. Missing statistics do not prevent the other health checks.

5Does a passed simulation prove a rule will work?

No. The checks depend on the target and may include syntax, field grounding or execution. They support review; they do not guarantee detection effectiveness or low noise in your environment.

Have a detection estate to improve? Talk to our team

Make your detections
worth maintaining.

Bring a noisy rule, a silent detection or a coverage gap. See how Virtus Optimus helps your team move it forward.