Ship detections 40× faster,
without an extra headcount.
Aegisyst is an agentic detection engineering platform for lean SOCs. It reads threat intel, drafts tested Sigma rules, and closes MITRE coverage gaps — while you sleep.
Live Threat Feed → AI drafts
A background watcher polls CISA's Known Exploited Vulnerabilities catalog and the SigmaHQ community repo every 6 hours, checks each new threat against your library, and asks Claude Opus 4.7 to draft Sigma for the gaps. Uncovered threats land in an Active Threats banner on your dashboard, and the drafts arrive flagged High Priority — as drafts, never auto-deployed, so a human always signs off.
Deception Module (Enterprise)
Active defence, not just detection. Generate honey service accounts (e.g. srv_metabase_admin) as deployable Sigma rules under MITRE T1078.002 — tagged type: decoy, shipped at level: critical, zero expected volume so any hit is real. Then flip on Randomize Logic to emit functionally identical but syntactically different SPL / KQL / EQL / Wazuh queries so attackers can't fingerprint your detection content.
Public Intelligence Library
A free, no-login feed of curated production-grade Sigma detections at /feed — each one MITRE ATT&CK mapped and shipped with its detection-logic reasoning (strategy → exclusions → tuning). Community 'Verify' votes surface the rules that actually hold up in real environments. Reading is always free, every account gets one full Multi-SIEM translation on the house, and unlimited translation + GitHub sync unlock on the Builder tier.
Autonomous Detection Agents
Three 24/7 agents work in tandem — Threat Intel ingests real CISA KEV CVEs and MalwareBazaar malware samples, Rule Generator drafts Sigma/YARA/KQL, Rule Optimizer analyzes false positives and retunes thresholds. Powered by GPT-5.2 with RAG on MITRE ATT&CK v14.
Multi-SIEM Translation
Write a rule once as Sigma. Translate to Splunk SPL, Elastic Query DSL, and Microsoft Sentinel KQL in one click. Field mappings for CIM, ECS, and ASIM ship out of the box.
AI-mapped Custom Log Profiles
Paste a sample of your own logs (JSON, CSV, KV, syslog — any shape). GPT-5.2 detects each column and maps it to the Master Schema with a confidence score. Save the profile once; every future rule you generate translates cleanly onto YOUR SIEM's exact field names.
Real SIEM Connectors
Native Splunk HEC, Elastic, and Microsoft Sentinel connectors with signed health checks and end-to-end test events. Secrets never leave the server; the UI only ever sees ****. Live status widget on the dashboard flags failing connectors with a red-dot alert.
Historical TP Regression Guard
Every rule change is auto-tested against your historical true-positive corpus. If a proposed edit would silence a real detection, the save is blocked (HTTP 409) with a clear reason — with an explicit override for the analyst who understands the trade-off.
MITRE ATT&CK Coverage Heatmap
Visual green/red grid across all 14 tactics and 200+ techniques. Instantly see what you cover, what you don't, and generate rules for gaps with one click.
Git-like Version History + CI Badges
Every rule change is versioned. Side-by-side Monaco diff view, rollback in one click, full audit trail. The Rule Lab list shows CI-style regression badges (pass / fail / stale) so risky rules are visible at a glance.
Freemium — Real Value Free
Free tier includes 50 detection rules and 30 AI generations every month. Upgrade to Team ($49/user/mo or ₹4,000/user/mo) only when you outgrow the sandbox. No credit card required to start.
India-first Payments
Pay in INR via Razorpay (UPI, cards, netbanking, wallets) or in USD via Stripe. All payments PCI-compliant; card data never touches Aegisyst servers.
Privacy-safe Analytics
Admin dashboard shows Today / 7-day authenticated user counts, activated users (logged in + connected SIEM + generated a rule), and anonymous visits — all computed from daily-rotated SHA-256 hashes. No IP addresses, user agents, or device fingerprints are ever collected.
Product Adoption Metrics
Track "Activated Users" (today / 7d / 30d) on the dashboard so you know exactly how many of your teammates have crossed the value line — logged in, connected a SIEM, and shipped a rule. Same privacy-safe hashing; auto-prune after 30 days.
No Sensitive Data Leaves Your Network
Sample logs and rule tests stay on your infrastructure. Only the abstract technique description is sent to the AI — never your alerts, IoCs, or telemetry. Connector credentials are stored server-side and redacted from every API response.
Ready to try it?
Demo mode is read-only and pre-loaded with T1059.001 & T1059.003 — no signup required.