What is AlphaSOC?
AlphaSOC is a security data platform built for agentic threat hunting and investigations. Our detection engine analyzes telemetry from your identity, cloud, application, network, and endpoint sources to surface targeted attacks and threats that don't yet have known indicators, without the overhead of managing detection pipelines or threat intel feeds yourself.
Every event we process is normalized to the Open Cybersecurity Schema Framework (OCSF) and indexed into AlphaSOC's data lake, where it stays queryable for months instead of days. Security teams can query that data lake directly, and so can their AI tools: connect Claude, Cursor, or another MCP client to ask a question in plain language and get an answer sourced from your own telemetry.
How it Works
AlphaSOC turns raw telemetry into useful OCSF data in three stages. Normalized events are stored in a purpose-built lake which houses detection findings, evidence, activity, and events. Analysts and AI agents work from the same enriched data to hunt threats and close out investigations fast.
Collect & Normalize
Load raw telemetry from any source
Automatically map events to OCSF
Enrich & Detect
In-built threat intelligence and scoring
Bring your own Sigma detection rules
Index & Store
Run fast, optimized, low-cost searches
Long-term retention for threat hunting
For a detailed breakdown of the pipeline, scoring dimensions, and deployment models, see the Architecture page.
Key Differentiators
Dedicated threat detection. Security teams reduce SIEM costs and increase threat hunting efficacy by embracing detection-as-code and shifting detection logic to AlphaSOC. Our dedicated engine never slows down and runs your Sigma rules alongside our managed detections without you having to translate or redeploy them.
Fast retrospective hunting. AlphaSOC indexes every scored event into a dedicated data lake, retained hot for 18 months by default instead of the 7 to 30 days typical of a SIEM. Query it directly from your SIEM, your SOAR, an AI tool, or AlphaSOC's Web Console, and get results back in seconds.
Managed threat intelligence. AlphaSOC aggregates indicators from 70+ sources, including threat feeds, our commercial partners, and AlphaSOC's own network scanning infrastructure. Our threat intelligence platform houses 1M+ live, curated indicators used to highlight threats in your telemetry.
Detect Anything™ with Sigma. Sigma is an open source YAML format used by security professionals to create and share detection rules. We enable threat hunters to quickly deploy new rules and uncover emerging threats within their cloud, application, network, and endpoint logs.
Patient zero coverage. AlphaSOC solves the patient zero problem to reveal novel threats that are unknown to security vendors. As it runs, our engine tracks the prevalence of artifacts, highlights suspicious patterns, and performs active network scanning to discover malicious infrastructure.
AI-ready via MCP. Connect Claude, Cursor, and other MCP clients directly to your AlphaSOC data lake. Ask a question in plain language, such as "what fired last night" or "is suspicious-domain.example malicious?", and get an answer sourced from your own telemetry instead of a query you have to write yourself.
Learn More
Want to try AlphaSOC for yourself? Visit our Getting Started Guide to create an account and explore the platform.
- Architecture: system overview, the data lake, and deployment models
- Capabilities: supported platforms and detection categories
- MCP Server: connect Claude, Cursor, and other AI tools to your data lake
- Sigma Rules: build and deploy custom rules
Need help? support@alphasoc.com