ORYEN
01Towards autonomous security operations

Automate SOC investigations.Keep control of every alert.

Cutting through the noise.

Oryen gathers evidence from the security tools you already run and closes approved alert types only when explicit evidence checks pass. Uncertain cases, and every alert type you have not approved, reach your analysts with the findings attached.

380
events
8
log sources
1
hypothesis
1
verified verdict
proof attached
Illustrative investigation · sample case
  1. 01
    Alert
  2. 02
    Evidence
  3. 03
    Proof contract
  4. 04
    Verdict
02How it works

One technique. One hypothesis. The evidence to prove it.

Every detection rule maps to an investigation hypothesis. The hypothesis names the facts that must hold to close the alert, and each fact is bound to the telemetry that answers it. Below, a sample offense runs through it.

How an investigation works
  1. 01

    Connect

    On top of the SIEM and the tools you already run, whatever the vendor. Nothing replaced.

  2. 02

    Investigate

    Agents gather evidence from your telemetry, typed and quality-scored.

  3. 03

    Prove

    A fixed, versioned proof contract decides. Never the model.

  4. 04

    Decide

    Close what is proven. Escalate what matters.

Technique
T1110 · Credential guessing
The adversary behaviour your detection rule fires on.
Hypothesis
“This offense is benign.”
One investigable question per case type, with the evidence that would kill it named in advance.
Evidence
The facts the proof contract needs: closing facts TRUE, danger checks FALSE.
  • No success after the failure burstAD auth
  • Source is an internal server, owned in CMDBCMDB
  • Password expired that morningIdP
  • Threat-intel match on the sourceTI
  • Success from a new geo or deviceIdP / MFA
Telemetry
Which of your tools answers each fact. Bound, not coded.
AD authCMDBIdPTIIdP / MFA
Illustrative investigation · sample caseSample
Service account, expired password
Alert #4471 · T1110 · credential guessing
  1. 10:14
    No success after the failure burst
  2. 10:16
    Source is an internal server, owned in CMDB
  3. 10:18
    Password expired that morning
  4. 10:20
    Threat-intel match on the source
  5. 10:22
    Success from a new geo or device
  6. 10:24
    Gathering evidence
    0/5
Alert
#4471 · QRadar
Rule
“Multiple Login Failures for a Single Username”
Tactic
T1110 · credential guessing
Account
svc-backup-02 · service account
Verdict
Why this matters

Gathering evidence
Three terms, once
Hypothesis
The one question an investigation answers for a given alert type, for example “this credential-guessing offense is benign”.
Proof contract
The fixed, human-approved checklist of facts that must hold before that alert type may be closed.
Verdict
Closed as a false positive with the proof record attached, or escalated to L2 with the evidence enclosed. Nothing else.
03Safety and deployment

Autonomy only where you approved it. Escalation everywhere else.

Oryen closes alerts autonomously only for the alert types you have approved after validation on your own history. Every other alert, and every case with an unknown fact, goes to your analysts with the findings attached. Automation coverage is therefore a number you set and can read, not a promise.

The guarantees are conditional and we say so: they hold for the facts the proof contract checks, on the evidence your tools supply. Missing or stale evidence resolves to UNKNOWN and escalates. A wrong evidence source or an incomplete contract is a coverage gap to fix in configuration, and the proof record makes it visible. A proof record establishes that the configured checks passed on the evidence available. It does not by itself establish that the activity was benign.

Unknown never closes

A fact can be true, false, or unknown: missing, stale, ambiguous, contradictory. Unknown is treated as unsafe. It always fails toward a human.

Escalation beats close

Any open suspicion blocks closure. Whenever the evidence could go either way, the tie goes to safety.

Every close is auditable

The attached proof shows exactly which facts were checked, on what evidence, and why that was sufficient. It proves the configured checks passed; whether the activity was benign rests on the contract being right.

How autonomy is granted
  1. 01
    Train

    Proves itself on offenses your team already closed. Before it ever touches a live alert.

    Past cases only
  2. 02
    Shadow

    Investigates live alerts and shows its work. A human still makes every call.

    Human decides: 100%
  3. 03
    Earn

    Closes proven case types on its own. Each close carries its proof.

    Human reviews: the rest
  4. 04
    Extend

    Takes on broader, more complex cases as each new type is validated.

    Human reviews: everything unproven
Deployment

Next to your SIEM, air-gapped or in your private cloud. Telemetry stays where it is; verdicts and proofs stay local. Compact self-hosted models do the exploratory work because the safety lives in the contract, not in the model.

Structured like a playbook.Adaptive like an agent.Trusted like an analyst who has earned it.