One SOC platform.Any SIEM.
SOCPilots puts detection, investigation and response on top of the SIEM you already own. Connect Wazuh, Elastic, Splunk or QRadar and your analysts work in a single console — no log migration, no second copy of your data, no rip and replace.
A console that already did the first hour of work
Six things happen between an alert firing and an analyst forming a judgement. SOCPilots does all six in one place, against whichever SIEM is underneath.
Detection and triage
alertsAlerts stream in from your SIEM, deduplicate into cases, and get scored against asset criticality and threat intelligence. Where the evidence is unambiguous the case is dispositioned without waiting for a human. The queue an analyst opens has already had the obvious work taken out of it.
Investigation
agentAsk a question in plain language. The agent reasons in a loop — searching alerts, enriching indicators, checking prior cases, reading the behaviour graph and the asset inventory — until it can answer. Every step it took is stored alongside the answer, so the reasoning is reviewable rather than asserted.
Automation and response
playbooksBuild response in a visual designer and run it durably. Runs survive a restart, pause for human approval wherever you require it, and reach your cloud and identity platforms through configured connectors rather than scripts on someone’s laptop.
Behaviour analytics
uebaUser and entity behaviour is modelled as a graph rather than a number in a column, so impossible travel, lateral movement and privilege escalation show up as paths between real entities you can follow — not just a risk score you have to trust.
ATT&CK coverage
coverageSee which tactics and techniques your current rules actually detect, where the gaps sit, and how that changes as you add detections. Export the result to MITRE Navigator to compare it against your own roadmap or a customer’s.
Multi-tenant operations
workspacesRun many customers from one deployment. Each workspace carries its own SIEM connection and its own data, separated in the database itself rather than by whichever filter a developer remembered to add to a query.
Your SIEM is a choice. Your console shouldn’t be.
Most platforms make you standardise on their data layer. SOCPilots asks the backend what it can do and shows only that — so an Elastic tenant and a QRadar tenant each get a console that tells the truth about their own environment.
Nothing is faked to look uniform. Where a backend cannot do something, the platform says so and refuses rather than silently trying a different one.
- CRITCredential dumping on domain controllerT1003
- HIGHLateral movement, 3 hosts in 6 minutesT1021
- MEDOutbound transfer to new destinationT1041
- LOWKnown scanner, contained at the edgeT1595
Reasoning you can read back
The investigation agent does not return a paragraph and ask you to trust it. It works in a visible loop — search, enrich, correlate, check history — and the trace of what it called and what came back is stored with the case.
Automation follows the same principle. A run that touches something destructive stops for a named human, and what it did is written down whether or not anyone is watching.
- search_alertshost WIN–DC01, last 24h17 hits
- enrich_ip185.220.101.78/94 flagged
- query_uebasvc_backuprisk 82
- check_casessimilar prior cases3 found
- query_assetsWIN–DC01tier 0
Run it as a service, or run it yourself
The same platform either way. The difference is who operates it and where the data sits.
SOCPilots Cloud
managed subscription- We run, patch and monitor the platform
- Your SIEM stays where it is — SOCPilots connects out to it
- Isolated workspace per organisation
- New capability arrives without a maintenance window
- Onboard a customer by creating a workspace
Self-hosted
your infrastructure- Deploy on your own servers with Docker Compose
- No security telemetry leaves your network
- Bring your own model keys and intelligence feeds
- Suits regulated environments and air-gapped estates
- You choose when to upgrade
Bring your SIEM. We’ll bring the rest.
Tell us which backend you run and what your team is drowning in. We will show you the console against that backend rather than a generic tour.