Architecture Features AI Engine Integrations Security Pricing FAQ

Works with the stack
you already run.

Triage Beacon plugs into the tools your team already runs. We issue you an ingestion API key; you add one forwarding rule in your SIEM. Setup takes minutes per connector.

Microsoft Defender (Identity · Endpoint · Office 365 · Cloud Apps)
Microsoft Sentinel
CrowdStrike Falcon
Splunk Enterprise Security
Wazuh SIEM
Elastic Security Q3
Push / webhook ingestion Q4
AbuseIPDB
VirusTotal
Microsoft Entra ID
Okta
URLhaus
MISP
Shodan
ANY.RUN
ServiceNow CMDB
Tenable
Farsight DNSDB

Enrichment sources are enabled per tenant based on the API keys you hold. Every lookup tolerates failure independently, and the pipeline reports an evidence-coverage score so a missing source can never silently inflate confidence.

Slack
PagerDuty
Email
Webhook (feed your SOAR)

One API key, one forwarding rule,
alerts start flowing.

🔑

Tenant-scoped API keys

We generate ingestion keys per tenant and send them to you at onboarding. Your SIEM forwards alerts to Triage Beacon with the key; Triage Beacon never needs credentials into your environment.

🔐

Keys hashed, never stored

Ingestion keys are hashed (SHA-256 + bcrypt) before they touch the database, the same way passwords are. A leaked database dump reveals no usable key, and any key can be revoked and reissued per tenant in seconds.

🧱

Validated at the door

Every forwarded payload is schema-validated, size-capped, and rate-limited before it enters the queue. Malformed alerts are rejected with a clear error instead of being half-processed.

Alert families, V1 launch scope.

Eight families cover the bulk of a typical tier-1 queue, each with its own AI playbook and MITRE ATT&CK mapping. Twelve more are scheduled across Q3/Q4. Alerts outside a known family are handled conservatively and never confidently closed.

Risky Sign-In
Defender Identity
T1078 · Initial Access
Privileged Anomalous Sign-In
Defender Identity
T1078 · Privilege Escalation
Malware Detected
Wazuh · Defender Endpoint
T1204 · Execution
Suspicious PowerShell
Wazuh · Defender Endpoint
T1059.001 · Execution
Brute Force / Password Spray
Defender · Sentinel · Splunk
T1110 · Credential Access
MFA Fatigue / Push Bombing
Defender · Entra ID · Okta
T1621 · Credential Access
Phishing Email
Defender for Office 365
T1566 · Initial Access
Credential Dumping
Defender · CrowdStrike · Wazuh
T1003 · Credential Access

Your SOAR picks up
where triage ends.

SOAR automates your playbooks; Triage Beacon produces the verdict your playbook needs as its first input. Escalations carry the full case record (verdict, confidence, evidence, policy trail) over webhook into your existing automation.