ORYEN
Next to your SIEM. Not instead of it.

The solution

Autonomous alert investigation for the SOC you already run. Oryen connects to your SIEM and tools, investigates on top, and writes every verdict back with its proof. No new data lake. Nothing replaced.

01What Oryen is

Existing options force you to pick a corner.

Playbooks give you deterministic decisions, but every one is authored and maintained by hand, per scenario, per environment. AI agents bolted onto a SIEM adapt cheaply, but the decision to close is probabilistic and the required checks are not fixed in advance.

The idea in one move: generalize the meaning of the investigation. Not the playbook, not the prompt. Decisions stay deterministic and auditable. Adapting to each client becomes declarative configuration. You climb both axes at once.

Easier to build and maintain
Deterministic and auditable
Hover a corner
02Where it sits

Next to your SIEM. Not instead of it.

Oryen automates L1 investigation for the alert types you approve. Every alert of an approved type is investigated, and at L1 there are exactly two outcomes.

Evidence and context sources
EDR
Identity
Cloud
Email
Threat intel
CMDB
Ticketing / ITSM
Internal context
Detection
SIEM

Your rules fire, offenses open. Detection stays exactly as it is.

Investigation · L1
Oryen
Evidence layer

Provider bindings pull facts on demand, with quality scores.

Proof engine

Deterministic verdicts over the evidence.

LLM agents

Analyze, search, map, rank, summarize, propose next actions. Never decide.

L1 outcomes
Closed as false positive

The L1 verdict, written back to the SIEM case with the machine-checkable proof attached. Audit-ready.

Escalated to L2

Suspicious. Handed to your L2 analyst queue or ITSM with the evidence enclosed, so L2 starts from the findings, not from the alert.

Nothing is replaced. No new data lake. Oryen is vendor-agnostic: your SIEM keeps detecting and your tools keep collecting, whichever products they are. Oryen does the L1 work on top, and every verdict flows back with its proof.

03Implementation

We bind to your environment. We don't build in it.

Implementation is three mappings and a gate. Because the meaning of an investigation is shared, each deployment reuses what the last one validated.

  1. 01

    Connect, on top of your SIEM

    Vendor-agnostic by design: QRadar, Sentinel, Splunk, Elastic or another SIEM, and the EDR, identity, cloud and ticketing tools around it. No new cloud data lake, no migration. Integrations are established once, during implementation.

  2. 02

    Map rules to hypotheses

    Every detection rule or offense type maps to an investigation hypothesis: the checklist of what must be true to close it.

  3. 03

    Bind evidence to telemetry

    Each fact the checklist needs is bound to the tool that supplies it. Provider bindings and entity maps, declared, not coded.

  4. 04

    Gate by policy, prove on history

    Automation gates come from your policy. Autonomy is proposed only after verdicts hold up on your already-closed offenses.

Global · the same for every client
  • Investigation semantics: which facts to check, and when they suffice
  • Predicates: single TRUE / FALSE / UNKNOWN facts about the case
  • Proof contracts: the fixed checklists that justify a close or force an escalation
Declared · per client, as configuration
  • Provider bindings: which of your tools supplies each fact
  • Typed parameters: your thresholds and tolerances
  • Reference data: your allowlists and known-good sets, under governance
  • Entity maps: which accounts, hosts and addresses are the same thing

Configuration, not authoring.

04Built for the agentic era

Oryen stays inside your perimeter.

LLM inference can run internally or through an external SaaS provider. Either way the investigation library, the evidence and every verdict stay where your telemetry lives.

  1. 01

    Small models are enough

    Compact, tailored LLMs do the exploratory work. The harness carries the safety.

  2. 02

    Sovereignty by default

    Investigations run where telemetry lives. With internal inference, security data stays inside your perimeter.

  3. 03

    Swap models freely

    The harness defines “safe to close”. Model changes leave verdict logic intact.

Your infrastructure
Oryen
  • Investigation library
  • Evidence and proof
  • Deterministic verdicts
Option A / internal
LLM inference

Self-hosted or private cloud

Option B / external
LLM inference

SaaS

The harness carries the safety. The model only has to be useful.

05What you get

Built for the SOC you already run.

Faster verdicts on day one. A safer SOC every month after.

See

Detect

Bind your telemetry and detection rules, map coverage per alert family, and declare what matters: critical assets, identities, policy.

Decide

Investigate

Autonomous, evidence-backed investigation for the alert types you approved. Proven case types close with proofs. Everything else, and every uncertain case, escalates to your analysts enriched.

Get better

Improve

Having seen every investigation, Oryen tells you which detections are noisy, where telemetry has gaps, and which weak spots recur. Advice is a proposal. Your people approve.