SOCPilots
ATT&CK coverage · Wazuh · last 30 days
none 1–2 rules 3–9 10+ interface illustration · switch the source to compare

One SOC platform.Any SIEM.

SOCPilots puts detection, investigation and response on top of the SIEM you already own. Connect Wazuh, Elastic, Splunk or QRadar and your analysts work in a single console — no log migration, no second copy of your data, no rip and replace.

4SIEM backends, each behind the same console
14ATT&CK tactics mapped across roughly 190 techniques
12step types in the automation engine
6tools the investigation agent can reach for

A console that already did the first hour of work

Six things happen between an alert firing and an analyst forming a judgement. SOCPilots does all six in one place, against whichever SIEM is underneath.

Detection and triage

alerts

Alerts stream in from your SIEM, deduplicate into cases, and get scored against asset criticality and threat intelligence. Where the evidence is unambiguous the case is dispositioned without waiting for a human. The queue an analyst opens has already had the obvious work taken out of it.

4 severity levelsauto-dispositioncase dedup

Investigation

agent

Ask a question in plain language. The agent reasons in a loop — searching alerts, enriching indicators, checking prior cases, reading the behaviour graph and the asset inventory — until it can answer. Every step it took is stored alongside the answer, so the reasoning is reviewable rather than asserted.

6 investigation toolsrecorded stepsper-case context

Automation and response

playbooks

Build response in a visual designer and run it durably. Runs survive a restart, pause for human approval wherever you require it, and reach your cloud and identity platforms through configured connectors rather than scripts on someone’s laptop.

12 step types4 trigger typesdurable runs

Behaviour analytics

ueba

User and entity behaviour is modelled as a graph rather than a number in a column, so impossible travel, lateral movement and privilege escalation show up as paths between real entities you can follow — not just a risk score you have to trust.

7 anomaly classesgraph modelML scoring

ATT&CK coverage

coverage

See which tactics and techniques your current rules actually detect, where the gaps sit, and how that changes as you add detections. Export the result to MITRE Navigator to compare it against your own roadmap or a customer’s.

14 tactics~190 techniquesNavigator export

Multi-tenant operations

workspaces

Run many customers from one deployment. Each workspace carries its own SIEM connection and its own data, separated in the database itself rather than by whichever filter a developer remembered to add to a query.

per-tenant SIEMrow-level securityall-tenants view

Your SIEM is a choice. Your console shouldn’t be.

Most platforms make you standardise on their data layer. SOCPilots asks the backend what it can do and shows only that — so an Elastic tenant and a QRadar tenant each get a console that tells the truth about their own environment.

Nothing is faked to look uniform. Where a backend cannot do something, the platform says so and refuses rather than silently trying a different one.

queue4 of 61 open
  • CRITCredential dumping on domain controllerT1003
  • HIGHLateral movement, 3 hosts in 6 minutesT1021
  • MEDOutbound transfer to new destinationT1041
  • LOWKnown scanner, contained at the edgeT1595
interface illustration

Reasoning you can read back

The investigation agent does not return a paragraph and ask you to trust it. It works in a visible loop — search, enrich, correlate, check history — and the trace of what it called and what came back is stored with the case.

Automation follows the same principle. A run that touches something destructive stops for a named human, and what it did is written down whether or not anyone is watching.

investigationcase SP–2291
  • search_alertshost WIN–DC01, last 24h17 hits
  • enrich_ip185.220.101.78/94 flagged
  • query_uebasvc_backuprisk 82
  • check_casessimilar prior cases3 found
  • query_assetsWIN–DC01tier 0
verdict · true positive · credential access · T1003 · escalated to L3

Run it as a service, or run it yourself

The same platform either way. The difference is who operates it and where the data sits.

SOCPilots Cloud

managed subscription
  • We run, patch and monitor the platform
  • Your SIEM stays where it is — SOCPilots connects out to it
  • Isolated workspace per organisation
  • New capability arrives without a maintenance window
  • Onboard a customer by creating a workspace

Self-hosted

your infrastructure
  • Deploy on your own servers with Docker Compose
  • No security telemetry leaves your network
  • Bring your own model keys and intelligence feeds
  • Suits regulated environments and air-gapped estates
  • You choose when to upgrade

Bring your SIEM. We’ll bring the rest.

Tell us which backend you run and what your team is drowning in. We will show you the console against that backend rather than a generic tour.