Platform · How it works

From sensor to report.

A complete walkthrough of how Viktrix detects, triages, contains, and documents threats — and what accountability looks like at every stage.

HOW THE PLATFORM WORKS

Four steps, fully accountable

From the moment a sensor fires to the report your insurer reads — AI handles the volume, humans own the calls, and the ledger records all of it.

01

Detect

Lightweight agents collect endpoint, identity, and network telemetry and stream it into the SOC in real time.

02

Triage

Every signal is classified against MITRE ATT&CK and assigned a calibrated confidence score, in seconds.

03

Contain

High-confidence threats are isolated automatically. Ambiguous signals are escalated to a human analyst for review and sign-off.

04

Report

Every action is recorded in a tamper-evident, hash-chained ledger, giving you auditable proof your insurer will accept.

Signal ingestion

Four planes. One correlation engine.

Endpoint

Process · Registry· Memory

Identity

Sign-ins · MFA · Privilege

Network

DNS · Flow · Proxy

Cloud

Azure · M365 ·Entra

VINDEX

Correlation
Engine

MITRE ATT&CK V14

Auto-contain
Analyst queue
Audit ledger

01

Onboarding

Up and running in under a day.

The Viktrix MSI bundle deploys silently across your Windows fleet with no reboot and no user disruption. macOS and Linux agents install via a single command. Once agents are live, we integrate your identity provider (Azure AD / Entra ID, Okta), your cloud workloads, and any existing SIEM. There's no migration — Vindex sits alongside what you have and enriches it.

  • Silent MSI installer — no reboot, no downtime
  • macOS and Linux agents via single command
  • Azure AD / Entra ID / Okta integration
  • Existing SIEM ingested, not replaced
  • SOC active from first sensor connection
Viktrix Hero
Viktrix Hero

02

Detection

Every signal, in context.

Vindex ingests telemetry from four planes simultaneously: endpoint process and file activity, identity sign-ins and privilege changes, network flows and DNS, and cloud API calls. All four are fused into a single correlation engine. A credential dumping attempt on endpoint WIN-4471 is immediately correlated with the admin sign-in from an impossible travel location that preceded it.

  • Endpoint: process tree, file writes, registry, memory
  • Identity: sign-ins, MFA events, privilege escalation
  • Network: flow data, DNS queries, proxy logs
  • Cloud: Azure audit logs, M365 activity, Entra sign-in risk
  • Cross-plane correlation before any alert is raised
More on 24/7 monitoring

03

Triage

AI scores it. Analysts own it.

Every alert is normalised, deduplicated, and anonymised — personal data is replaced with placeholders before any AI model is involved. Indicators are enriched against global threat intelligence; behaviour is compared to per-user baselines; history is consulted for similar incidents. A deterministic planner routes each alert by risk: known noise resolves cheaply, routine alerts get standard AI analysis, high-risk signals trigger a full deep investigation. AI agents classify against MITRE ATT&CK and produce a calibrated confidence score — then a deterministic output firewall checks the verdict before anything acts on it.

  • Confidence threshold configurable per tenant
  • AI reasoning and evidence surface in one view
  • SLA timers visible on the client dashboard
  • Every decision carries an analyst signature
More on automated triage
Viktrix Hero
Viktrix Hero

04

Containment

Under a second, or human-approved.

When confidence is sufficient, Vindex acts immediately: the affected host is isolated at the network layer, associated malicious domains and IPs are blocked across all gateway integrations, and a containment record is written to the audit chain. For ambiguous or destructive calls, the analyst approves or modifies before anything changes; irreversible actions always require explicit sign-off.

  • Host isolation at network layer — not just process kill
  • Firewall blocks pushed to all gateway integrations
  • Rollback available for every automated action
  • Contain-and-investigate mode preserves forensic evidence
  • Lateral movement paths severed automatically
More on containment

05

Audit

Everything is on the record.

Every detection, decision, and action lands in a tamper-evident, hash-chained ledger. Incident timelines, compliance evidence, and board reports export on demand — proof your auditor and insurer will accept, not a reconstruction.

  • SHA-256 hash-chained incident records
  • Exportable as structured JSON
  • Meets common UK cyber insurance evidence standards
  • ISO 27001 incident-logging compliant
  • Immutable — no edit or delete capability
More on the audit trail
Viktrix Hero

Want the technical detail?

The Vindex product page has the agent architecture, guardrail model, and specs.

See all four steps live, on real alerts. Book a demo.

Viktrix Logo

Ready to close the gap?

Get enterprise-grade protection running in minutes. No disruption, no long contracts, no lock-in.