Alerts outnumber analysts
Real threats wait in queues nobody reaches, behind thousands of routine events.
Evercept investigates security alerts on the SIEM you already run. Claude triages each one, hunts through your own logs for evidence and reaches a verdict, and every step is recorded so an analyst can see exactly why.
Illustrative data. The real pipeline writes the same stages to a live event trace.
Security teams can't reach every alert, and they can't hand alerts to an AI that won't show its work. When a model clears an alert, someone has to be able to say why.
Real threats wait in queues nobody reaches, behind thousands of routine events.
An AI that closes alerts without showing its evidence is a liability, not an analyst.
A SIEM vendor's built-in agent stays with that vendor, and so does its history.
Evercept sits beside your SIEM, reads its alerts and investigates with the SIEM's own data, the way a tier-1 analyst would.
Alerts are pulled from your SIEM's API or pushed to Evercept. A disk spool survives restarts, and a reconciler finds and repairs gaps.
Related activity on the same host and source IP is attached. Claude rates severity and proposes follow-up hunts.
Each hunt query is validated before it runs against your logs. A rejected hunt is reported as an evidence gap, never as "nothing found".
Confirmed, disputed or clear, with the evidence and the reasoning behind it, delivered into the ticketing and chat tools your team already uses.
Triage forms a hypothesis and enrichment tests it. When they disagree, the ticket says so. Select a verdict to see the ticket an analyst would receive.
198.51.100.7 in six minutes, then Accepted password for deploy from the same address.deploy credential, block the source, review the shell history on web-01./usr/lib during a maintenance window.Illustrative tickets. Real tickets carry nine sections per finding.
The engine is built around one question an auditor, a CISO or an analyst will ask: why did it decide that?
Every verdict is recorded with the model, the prompt hash, the context attached and the path to the decision.
If the model rates an alert well below what its rule implies, the ticket is flagged. A critical alert can't be silently cleared.
"No related alerts" and "the lookup failed" are opposite facts, and tickets never confuse them.
One auditable module decides which alert fields are sent to the model. Nothing else crosses your boundary.
Attackers write log content, so it's treated as untrusted data and fenced off from the instructions the model follows.
Rate limits park alerts for retry instead of dropping them. Analysis failures are named in the digest, and every drop is counted.
Claude does the reasoning. The engine makes sure every answer is well-formed, bounded and accounted for.
Every verdict is constrained to a fixed JSON schema by the API. A malformed or incomplete answer isn't possible, only a missing one.
A triage pass forms the hypothesis and an enrichment pass tests it against hunt results, with reasoning effort set explicitly.
Alerts carry attacker payloads as evidence. Refusals are handled explicitly, with a server-side fallback, so they can't silently drop an alert.
Claude is the default. Gemini is also supported, behind the same contract, the same audit trail and the same egress control.
Evercept is SIEM-agnostic by design. Each platform plugs in through an adapter that ingests its alerts, investigates in its own data and writes the verdict back, so you get one analyst and one audit trail whichever SIEM an alert came from.
Triage and enrichment, schema-constrained.
Full tickets in the case management and chat tools your team already uses.
model passes per alert: triage, then enrichment
sections in every ticket, evidence to provenance
automated tests across the engine
verdict states, so uncertainty is never hidden
The engine is being generalised so the same analyst, and the same audit trail, works across platforms and survives a SIEM migration.
Ingest by API or push, validated hunts, and delivery to your ticketing and chat tools.
The first new adapter, sharing the existing OpenSearch query path.
KQL and SPL investigation, with verdicts written back to incidents and findings.
Migration continuity: the same analyst on the old SIEM and the new one.
We think the AI that watches your network should be held to the same standard as an analyst: show your evidence, or don't make the call.
We're working with a small number of SOC teams and MSSPs running OpenSearch-based SIEMs, Elastic, Microsoft Sentinel or Splunk. Tell us about your environment and we'll show you the engine on your own alerts.