SOC Console & Telemetry Ingestion
Ship your cloud, identity and VCS logs in — heimdallX normalises them, runs detections, and turns each one into an incident an analyst can work to closure.
Scanning tells you where you are weak; telemetry tells you when someone is already inside. heimdallX takes both. A collector — a log forwarder, a Lambda, a cron shipping CloudTrail, Okta or GitHub events — posts raw events with an ingest key. Each batch is normalised to a common schema, run through a Sigma-compatible detection engine, and every detection becomes an incident in a queue with deduplication, escalation and time targets. Metered by the gigabyte per day, on every paid plan.
Detections, not raw logs
Brute force, multi-IP authentication, privilege-escalation chains, data exfiltration and off-hours activity ship as rules; community Sigma rules compile into the same engine, and a rule the compiler cannot express is refused rather than approximated. Every detection carries its ATT&CK technique, and a coverage matrix shows which tactics your rules actually populate.
A queue an analyst can finish
Detections are correlated into incidents, deduplicated and suppressed by rules you tune. An AI triage pass reads the incident and its corroborating events and proposes a verdict with a confidence bounded by that corroboration — never by the model's tone. Acknowledge and resolve targets per severity turn MTTA and MTTR into numbers you can report.
Live, and honest about volume
Incidents push to the console over a live socket the moment they open. Ingestion is metered per workspace against the plan's daily allowance, and the queue says when noisy rules are opening cases a suppression rule would recover.
How it works
Ingest
POST events with an ingest key; batches are normalised.
Detect
Built-in and Sigma rules fire with ATT&CK context.
Triage
Dedup, suppress, escalate; AI proposes a verdict.
Resolve
Work the case against MTTA / MTTR targets.
$ curl -X POST /api/ingest/events -H 'Authorization: Bearer hxin_…' -d @cloudtrail.json→ 1,204 events normalised · 3 detections→ incident #418 opened: brute force → console login (T1110)→ AI triage: likely credential stuffing · confidence 0.82 · escalate
Put it to work
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX