Autonomous investigation, containment, and remediation. Every action attributed to the SOC analyst who authorized it, every attack chain caught mid-flight. AI agent security and prompt-injection prevention for SOC automation stacks.
The agent isolates hosts, revokes tokens, disables accounts. Some actions are correct. Some are catastrophic. Nothing attributes back to a signed analyst.
Every SOC agent action inherits the analyst’s scope, only-tighter. High-blast-radius actions escalate. Every action carries a signed principal chip.
“Autonomy is not the goal. Attributable autonomy is.”
SOC automation only works if the agent is scoped tighter than the analyst who dispatched it, if high-blast actions escalate, and if the chain across every action, tenant, and agent is correlated in flight. Three of Veldt’s pillars carry that surface.
Fraud, lateral movement, and data-exfil chains cross agents and tenants. Veldt’s attack-chain detection correlates action sequences in flight, at 89% detection on real chains. The pattern gets caught mid-execution, not next month.
Attack Chains →Isolate host, revoke tokens, block CIDR: every autonomous SOC action passes through the verdict pipeline in under 50ms. Allow, redact, throttle, escalate, or block. High blast radius always escalates.
Runtime Governance →The agent inherits scope from the analyst who dispatched it. Never wider. Cross-tenant actions require an on-shift analyst attestation. The chain shows who authorized every action, every time.
Authority →Autonomous phishing triage, cross-tenant compromise correlation, automated containment, threat hunting, and the post-mortem. Every one of them needs an attributable chain to survive audit.
A phishing-triage agent processes thousands of user-reported emails. When it’s wrong (releases a real phish or quarantines a legit sender to a distribution list), there’s no attribution to argue over.
Every triage verdict attributes to the on-shift analyst’s dispatch. Bulk releases and cross-distribution quarantines escalate. The chain shows: input email hash, model verdict, analyst scope, final action.
Every verdict · attributed.The same attacker touches ten customer tenants. Each tenant sees a slice. The MDR provider sees isolated alerts. The pattern only surfaces when someone manually stitches it together weeks later.
Attack-chain detection correlates action sequences across all tenants at once. Multi-victim campaigns light up in-flight. 89% detection on real chains.
Campaign · caught early.The containment agent isolates a host. Then it isolates the domain controller. Then it revokes every token in the tenant. The blast radius runs away, and every minute costs a business unit.
Containment actions carry a blast-radius budget. Endpoint-level: allow. Tenant-wide: escalate. Cross-tenant: block until dual sign-off. Every action carries a signed analyst principal.
Blast radius · bounded.A hunting agent runs open-ended queries across telemetry. It touches employee PII, executive comms, and legal-privileged material. Every query is a data-governance liability with no attribution.
PII, exec, and privileged surfaces are redacted at the perimeter. Query scope inherits from the hunter’s dispatch. Every hunt hit is signed to the on-shift analyst.
Hunt scope · enforced.The post-mortem needs a full action log: who did what, when, and under whose authority. Teams reconstruct from Slack, tickets, and memory. Weeks of work, and no guarantee the log wasn’t edited.
The post-mortem is a query against the signed action chain. Every autonomous action, every analyst attestation, every escalation lands with a signed hash. The log cannot be rewritten.
Chain · immutable.Bring a real SOC surface: the phishing triage agent, the containment bot, the hunter. Thirty minutes: see the verdict pipeline, cross-tenant chain correlation, and the exact analyst attribution for every action.
Book a demo → Read the Attack Chains docs