All features

Features · Triage

Automated triage

Every alert read, none of your time wasted. AI classifies each signal against MITRE ATT&CK in seconds — with judgement applied in layers and a human on every consequential call.

Vindex · live data

Every alert

Classified against MITRE ATT&CK with a calibrated confidence score — before a human ever needs to look

bar

Alert fatigue is the quiet killer of security programmes. When hundreds of alerts arrive daily and almost all are noise, humans stop looking — and the real one slips through in the crowd. Vindex solves the volume problem the only way it can be solved: read everything, at machine speed, with each verdict checked before anything acts on it.

automated

What's Included

Everything you need, nothing you don't.

Normalise & deduplicate

  • Every alert parsed into a standard schema on arrival
  • Repeats and alert storms folded, so one event doesn't become fifty tickets
  • Automatic false-positive suppression based on your tenant's context

Anonymise & enrich

  • Personal data replaced with placeholders before any AI model sees the alert — privacy enforced by the pipeline, not by policy
  • Indicators checked against global threat intelligence the moment an alert fires
  • Behaviour compared against per-user and per-entity statistical baselines
  • Related history retrieved and attached to the case

Route & classify

  • A deterministic, rules-based planner (no AI involved) decides how much analysis each alert deserves
  • Known noise resolves cheaply, routine alerts get standard analysis, high-risk signals trigger a full deep investigation
  • AI agents classify against MITRE ATT&CK and assign severity
  • A calibrated confidence score — a 0.8 is built to mean 80%, not "the model felt good"

Guard the output

  • A deterministic firewall checks every AI verdict for consistency, over-claiming, and policy violations before anything acts on it
  • Severities can be corrected downward automatically; only evidence can push them up
  • The AI's action space only ever shrinks under its guardrails — it can never grant itself new powers

How it works

Precise at every stage.

01

Ingest

Alerts arrive from 24/7 monitoring, are normalised, deduplicated, and anonymised.

02

Enrich

Threat intel, behavioural baselines, and incident history are assembled automatically.

03

Classify

AI scores the alert against MITRE ATT&CK; the output firewall validates the verdict.

04

Route

Clear threats proceed to containment; anything ambiguous or high-impact goes to a human analyst with evidence, reasoning, and a recommended plan already prepared.

What this means for your team

Decision-ready, not inbox-ready.

The 3am alert flood is handled before your morning coffee

What reaches you is decision-ready: context, evidence, recommendation

False-positive patterns are learned once, not endured daily

Every verdict is explainable and sits in the audit trail

Right for you if…

The teams who are drowning in alerts but short on analysts.

Your team is drowning in alerts from tools nobody has time to watch

You've missed a real incident because it was buried in noise

You want SOC automation without handing a black box the keys

You need every triage decision documented for auditors and insurers

You might also need

24/7 monitoring

The telemetry that feeds the triage engine.

Learn more

Containment

What happens when triage confirms a threat.

Learn more

Audit trail

Where every verdict and its reasoning is recorded.

Learn more

Watch triage happen live on real alerts. Book a demo.

Viktrix Logo

Ready to close the gap?

Get enterprise-grade protection running in minutes. No disruption, no long contracts, no lock-in.