Abstract is a composable Security Information and Event Management (SIEM) and security data fabric platform. It functions as a vendor-agnostic data pipeline that operates upstream from an organization's existing storage environments, decoupling data collection, detection, and retention. The system processes security telemetry in-stream to normalize, enrich, and route data to multiple analytics or storage destinations simultaneously. A core feature is its streaming detection engine, which identifies threats in real-time before data is indexed or stored, allowing for threat detection independent of centralized data architectures.
The platform integrates artificial intelligence to automate entity resolution, correlate security signals, and generate incident summaries. It supports tiered data retention strategies and allows for detections to be executed against both real-time data streams and historical archives or federated systems. Organizations can deploy Abstract within their own cloud environments to maintain data sovereignty. Technical capabilities include an ETL interface for applying real-time threat intelligence, a visual detection builder, continuous MITRE ATT&CK framework mapping, and automated audit trails for rule versioning.