The solution
Autonomous alert investigation for the SOC you already run. Oryen connects to your SIEM and tools, investigates on top, and writes every verdict back with its proof. No new data lake. Nothing replaced.
Existing options force you to pick a corner.
Playbooks give you deterministic decisions, but every one is authored and maintained by hand, per scenario, per environment. AI agents bolted onto a SIEM adapt cheaply, but the decision to close is probabilistic and the required checks are not fixed in advance.
The idea in one move: generalize the meaning of the investigation. Not the playbook, not the prompt. Decisions stay deterministic and auditable. Adapting to each client becomes declarative configuration. You climb both axes at once.
Next to your SIEM. Not instead of it.
Oryen automates L1 investigation for the alert types you approve. Every alert of an approved type is investigated, and at L1 there are exactly two outcomes.
Your rules fire, offenses open. Detection stays exactly as it is.
Provider bindings pull facts on demand, with quality scores.
Deterministic verdicts over the evidence.
Analyze, search, map, rank, summarize, propose next actions. Never decide.
The L1 verdict, written back to the SIEM case with the machine-checkable proof attached. Audit-ready.
Suspicious. Handed to your L2 analyst queue or ITSM with the evidence enclosed, so L2 starts from the findings, not from the alert.
Nothing is replaced. No new data lake. Oryen is vendor-agnostic: your SIEM keeps detecting and your tools keep collecting, whichever products they are. Oryen does the L1 work on top, and every verdict flows back with its proof.
We bind to your environment. We don't build in it.
Implementation is three mappings and a gate. Because the meaning of an investigation is shared, each deployment reuses what the last one validated.
- 01
Connect, on top of your SIEM
Vendor-agnostic by design: QRadar, Sentinel, Splunk, Elastic or another SIEM, and the EDR, identity, cloud and ticketing tools around it. No new cloud data lake, no migration. Integrations are established once, during implementation.
- 02
Map rules to hypotheses
Every detection rule or offense type maps to an investigation hypothesis: the checklist of what must be true to close it.
- 03
Bind evidence to telemetry
Each fact the checklist needs is bound to the tool that supplies it. Provider bindings and entity maps, declared, not coded.
- 04
Gate by policy, prove on history
Automation gates come from your policy. Autonomy is proposed only after verdicts hold up on your already-closed offenses.
- Investigation semantics: which facts to check, and when they suffice
- Predicates: single TRUE / FALSE / UNKNOWN facts about the case
- Proof contracts: the fixed checklists that justify a close or force an escalation
- Provider bindings: which of your tools supplies each fact
- Typed parameters: your thresholds and tolerances
- Reference data: your allowlists and known-good sets, under governance
- Entity maps: which accounts, hosts and addresses are the same thing
Configuration, not authoring.
Oryen stays inside your perimeter.
LLM inference can run internally or through an external SaaS provider. Either way the investigation library, the evidence and every verdict stay where your telemetry lives.
- 01
Small models are enough
Compact, tailored LLMs do the exploratory work. The harness carries the safety.
- 02
Sovereignty by default
Investigations run where telemetry lives. With internal inference, security data stays inside your perimeter.
- 03
Swap models freely
The harness defines “safe to close”. Model changes leave verdict logic intact.
- Investigation library
- Evidence and proof
- Deterministic verdicts
Self-hosted or private cloud
SaaS
- Investigation library
- Evidence and proof
- Deterministic verdicts
Self-hosted or private cloud
SaaS
The harness carries the safety. The model only has to be useful.
Built for the SOC you already run.
Faster verdicts on day one. A safer SOC every month after.
Detect
Bind your telemetry and detection rules, map coverage per alert family, and declare what matters: critical assets, identities, policy.
Investigate
Autonomous, evidence-backed investigation for the alert types you approved. Proven case types close with proofs. Everything else, and every uncertain case, escalates to your analysts enriched.
Improve
Having seen every investigation, Oryen tells you which detections are noisy, where telemetry has gaps, and which weak spots recur. Advice is a proposal. Your people approve.