Automate SOC investigations.Keep control of every alert.
Oryen gathers evidence from the security tools you already run and closes approved alert types only when explicit evidence checks pass. Uncertain cases, and every alert type you have not approved, reach your analysts with the findings attached.
- 01Alert
- 02Evidence
- 03Proof contract
- 04Verdict
One technique. One hypothesis. The evidence to prove it.
Every detection rule maps to an investigation hypothesis. The hypothesis names the facts that must hold to close the alert, and each fact is bound to the telemetry that answers it. Below, a sample offense runs through it.
How an investigation works- 01
Connect
On top of the SIEM and the tools you already run, whatever the vendor. Nothing replaced.
- 02
Investigate
Agents gather evidence from your telemetry, typed and quality-scored.
- 03
Prove
A fixed, versioned proof contract decides. Never the model.
- 04
Decide
Close what is proven. Escalate what matters.
- No success after the failure burstAD auth
- Source is an internal server, owned in CMDBCMDB
- Password expired that morningIdP
- Threat-intel match on the sourceTI
- Success from a new geo or deviceIdP / MFA
- 10:14No success after the failure burst…
- 10:16Source is an internal server, owned in CMDB…
- 10:18Password expired that morning…
- 10:20Threat-intel match on the source…
- 10:22Success from a new geo or device…
- 10:24Gathering evidence0/5
- Alert
- #4471 · QRadar
- Rule
- “Multiple Login Failures for a Single Username”
- Tactic
- T1110 · credential guessing
- Account
- svc-backup-02 · service account
- Verdict
- —
…
- Hypothesis
- The one question an investigation answers for a given alert type, for example “this credential-guessing offense is benign”.
- Proof contract
- The fixed, human-approved checklist of facts that must hold before that alert type may be closed.
- Verdict
- Closed as a false positive with the proof record attached, or escalated to L2 with the evidence enclosed. Nothing else.
Autonomy only where you approved it. Escalation everywhere else.
Oryen closes alerts autonomously only for the alert types you have approved after validation on your own history. Every other alert, and every case with an unknown fact, goes to your analysts with the findings attached. Automation coverage is therefore a number you set and can read, not a promise.
The guarantees are conditional and we say so: they hold for the facts the proof contract checks, on the evidence your tools supply. Missing or stale evidence resolves to UNKNOWN and escalates. A wrong evidence source or an incomplete contract is a coverage gap to fix in configuration, and the proof record makes it visible. A proof record establishes that the configured checks passed on the evidence available. It does not by itself establish that the activity was benign.
Unknown never closes
A fact can be true, false, or unknown: missing, stale, ambiguous, contradictory. Unknown is treated as unsafe. It always fails toward a human.
Escalation beats close
Any open suspicion blocks closure. Whenever the evidence could go either way, the tie goes to safety.
Every close is auditable
The attached proof shows exactly which facts were checked, on what evidence, and why that was sufficient. It proves the configured checks passed; whether the activity was benign rests on the contract being right.
- 01Train
Proves itself on offenses your team already closed. Before it ever touches a live alert.
Past cases only - 02Shadow
Investigates live alerts and shows its work. A human still makes every call.
Human decides: 100% - 03Earn
Closes proven case types on its own. Each close carries its proof.
Human reviews: the rest - 04Extend
Takes on broader, more complex cases as each new type is validated.
Human reviews: everything unproven
Next to your SIEM, air-gapped or in your private cloud. Telemetry stays where it is; verdicts and proofs stay local. Compact self-hosted models do the exploratory work because the safety lives in the contract, not in the model.