- Telemetry domains
- Endpoint (EDR telemetry and process activity), identity (directory changes and sign-in events), cloud (control-plane and workload logs), network (perimeter and internal traffic), and threat intelligence. The ingestion layer is designed so that further sources are added by onboarding, not by rebuilding.
- Data model
- Entity-centric. A user, host, identity, workload or application is one entity whatever source the event came from, resolved across sources into one schema. Correlation, investigation and hunting all read the same model.
- Detection content
- Engineered as code: versioned, tested and peer-reviewed before it runs. Every detection is mapped to MITRE ATT&CK, and coverage against the framework is reported, including the gaps.
- Correlation
- Related detections are resolved into one incident on shared entities and time. Incidents are scored by the blast radius that asset criticality and privilege imply, not by a vendor default.
- Investigation
- When an incident opens, a chronological timeline across every source, entity context with history and criticality, and the evidence behind each step are designed to be ready before an analyst arrives. Case state, notes and handoffs survive a shift change.
- Hunting
- One query surface over normalized, entity-resolved telemetry, so a hypothesis is tested across every layer at once and a successful hunt can become a detection.
- Response model
- Approval-gated. Actions are proposed with the evidence behind them; analysts approve, or playbooks the organization has pre-approved execute. Every action is logged, attributable and reversible where the underlying platform allows.
- Integration intent
- Designed to consume the EDR, identity provider, cloud audit logs and network sensors an organization already runs, and to operate alongside an existing SIEM rather than replace it. Specific integrations are stated here as they are built.
- Deployment intent
- Hybrid and multi-cloud estates with mixed vendors. Storage tiering and cost visibility are part of the design, because security data is expensive to keep.
- Record
- A complete record of what was detected, what was concluded, and what acted, whether a person or an automation, so that an incident stands up to review after it closes.