
Intruex provides an alert triage and decision platform that analyzes security alerts from existing tools (SIEM, EDR, cloud, identity, email) and produces defensible verdicts with reasoning and confidence scores. The system uses specialist AI analysts per threat class, retains all decision records for audits, and integrates without replacing current infrastructure. It measures a median 48-second triage time in production.
Funding
Funding not disclosed
Founders
Product
Problem
Security operations teams face a bottleneck in alert triage: detection tools produce a constant stream of alerts, but interpreting them accurately requires scarce human analyst judgment. Existing automation and SOAR platforms execute playbooks but still assume a human has already determined what an alert means, leaving the decision-making layer unautomated and difficult to scale.
Solution
Intruex automates the decision layer of security operations by receiving alerts from existing detection tools and converting them into reasoned verdicts. The platform ingests alerts via native connectors or REST endpoints, normalizes them to the Open Cybersecurity Schema Framework, enriches them with threat intelligence and environment-specific entity memory, and routes each event to a specialist AI analyst that owns a specific threat class. Each analyst writes a disposition with a confidence value and plain-language reasoning, and suspicious cases trigger deep investigations where a tool-using agent performs hunts across the organization's existing infrastructure. Every step is written to an audit record, and response actions require human approval before execution.
Target Audience
Primary customers are security operations teams at mid-to-large enterprises and managed security service providers that need to scale alert triage, especially those facing audit, board, or regulatory scrutiny requiring documented evidence of analysis work.
Features
- Native integrations with Splunk, Microsoft Sentinel, Defender for Endpoint, Intune, and Acronis EDR, plus a generic REST endpoint for any system that can POST JSON
- OCSF-level normalization with MITRE ATT&CK tactic and technique attribution on standardized event types
- Two-tier investigation pipeline: heuristic triage for routine alerts and automatic deep investigation for ambiguous or high-severity cases
- Specialist AI analysts per threat class (brute force, phishing, malware, lateral movement, privilege escalation, and more), with a general analyst fallback ensuring no alert goes unhandled
- Entity memory that persists facts about IPs, users, hosts, and domains with confidence decay over time and analyst-pinning capability
- Hybrid retrieval over customer-uploaded runbooks and policies for context-aware analysis
- Deterministic routing dictionary for known event types, with model judgment reserved for ambiguous cases
- Correlation engine that groups related alerts into attack narratives with kill-chain timelines and scoped per-tenant isolation
- Full audit trail with verdict, confidence score, reasoning, and tool-call logs persisted for every alert