Combines Security Information and Event Management (SIEM) with Security Orchestration, Automation, and Response (SOAR) capabilities in a single cloud-native platform.
02
Out-of-the-Box Data Connectors
Provides pre-built connectors for Microsoft sources (e.g., Microsoft Entra ID, Azure Activity) and third-party solutions via Common Event Format (CEF), Syslog, or REST-API.
03
Advanced Security Information Model (ASIM)
Uses query-time and ingestion-time normalization to create uniform data schemas across diverse sources.
04
Analytics Rules
Configurable threat detection rules using Kusto Query Language (KQL), including scheduled analytics and machine learning-based behavior analysis.
05
Fusion Correlation Engine
Detects multistage attacks by correlating low-fidelity alerts across multiple products using machine learning algorithms.
Your plan caps how many capabilities are shown — upgrade to see the full list