AI SOC analyst · Built on Claude

Every alert investigated. Every verdict provable.

Evercept investigates security alerts on the SIEM you already run. Claude triages each one, hunts through your own logs for evidence and reaches a verdict, and every step is recorded so an analyst can see exactly why.

  • Self-hosted, inside your network
  • SIEM-agnostic by design
  • Audit trail on every verdict

Illustrative data. The real pipeline writes the same stages to a live event trace.

Works with
OpenSearch-based SIEMs Ticketing & chat Claude Elastic Security Microsoft Sentinel Splunk ES IBM QRadar
The problem

AI triage is everywhere. Proof isn't.

Security teams can't reach every alert, and they can't hand alerts to an AI that won't show its work. When a model clears an alert, someone has to be able to say why.

The queue

Alerts outnumber analysts

Real threats wait in queues nobody reaches, behind thousands of routine events.

Evercept investigates every eligible alert and reports which ones it didn't.
The black box

Verdicts without reasons

An AI that closes alerts without showing its evidence is a liability, not an analyst.

Every ticket carries the evidence, the hunts and the reasoning behind its verdict.
The lock-in

Agents tied to one vendor

A SIEM vendor's built-in agent stays with that vendor, and so does its history.

Evercept is a layer on top of your SIEM, and its audit trail stays with you.
How it works

Four steps per alert. Every one of them recorded.

Evercept sits beside your SIEM, reads its alerts and investigates with the SIEM's own data, the way a tier-1 analyst would.

01 · INGEST

Nothing gets lost

Alerts are pulled from your SIEM's API or pushed to Evercept. A disk spool survives restarts, and a reconciler finds and repairs gaps.

02 · TRIAGE

Claude forms a hypothesis

Related activity on the same host and source IP is attached. Claude rates severity and proposes follow-up hunts.

03 · HUNT

It tests the hypothesis

Each hunt query is validated before it runs against your logs. A rejected hunt is reported as an evidence gap, never as "nothing found".

04 · VERDICT

A ticket you can trust

Confirmed, disputed or clear, with the evidence and the reasoning behind it, delivered into the ticketing and chat tools your team already uses.

Three honest outcomes

Uncertainty is shown, not averaged away.

Triage forms a hypothesis and enrichment tests it. When they disagree, the ticket says so. Select a verdict to see the ticket an analyst would receive.

TICKET KTRL-20261008-4E1ACONFIRMED · HIGH

SSH brute force followed by a successful login

Detection rule 5712 · level 10 · asset web-01
What happened
412 failed logins from 198.51.100.7 in six minutes, then Accepted password for deploy from the same address.
Hunts
✓ 2 ran against the SIEM · ⚠ 1 rejected by the validator and reported as an evidence gap
Reasoning
A login succeeded after sustained failures from one source, and that IP has no earlier logins in the lookback window.
Actions
Disable the deploy credential, block the source, review the shell history on web-01.
Provenance
Model, prompt hash and attached context recorded in the audit trail.

Illustrative tickets. Real tickets carry nine sections per finding.

Built for trust

Designed so a wrong call can be explained, not just regretted.

The engine is built around one question an auditor, a CISO or an analyst will ask: why did it decide that?

Append-only audit trail

Every verdict is recorded with the model, the prompt hash, the context attached and the path to the decision.

Severity floor in code

If the model rates an alert well below what its rule implies, the ticket is flagged. A critical alert can't be silently cleared.

Gaps stay visible

"No related alerts" and "the lookup failed" are opposite facts, and tickets never confuse them.

You control what leaves

One auditable module decides which alert fields are sent to the model. Nothing else crosses your boundary.

Hardened against injection

Attackers write log content, so it's treated as untrusted data and fenced off from the instructions the model follows.

Fails honestly

Rate limits park alerts for retry instead of dropping them. Analysis failures are named in the digest, and every drop is counted.

Built on Claude

A frontier model, held to an engineering contract.

Claude does the reasoning. The engine makes sure every answer is well-formed, bounded and accounted for.

Structured outputs

Every verdict is constrained to a fixed JSON schema by the API. A malformed or incomplete answer isn't possible, only a missing one.

Two-pass reasoning

A triage pass forms the hypothesis and an enrichment pass tests it against hunt results, with reasoning effort set explicitly.

Built for hostile evidence

Alerts carry attacker payloads as evidence. Refusals are handled explicitly, with a server-side fallback, so they can't silently drop an alert.

Your boundary, your model

Claude is the default. Gemini is also supported, behind the same contract, the same audit trail and the same egress control.

Integrations

Sits on top of the SIEM you already run.

Evercept is SIEM-agnostic by design. Each platform plugs in through an adapter that ingests its alerts, investigates in its own data and writes the verdict back, so you get one analyst and one audit trail whichever SIEM an alert came from.

  • Read-only, least privilege. A dedicated SIEM account with only the access the investigation needs.
  • Your data stays home. Alerts are processed in your environment. One auditable module decides which fields reach the model.
  • Secrets stay secret. Credentials live in the operating system's credential store, never on a command line or in the app directory.
  • Changes you can preview. Setup shows every change before making it, and rolls back automatically if a check fails.
2

model passes per alert: triage, then enrichment

9

sections in every ticket, evidence to provenance

1,450+

automated tests across the engine

3

verdict states, so uncertainty is never hidden

Roadmap

One analyst across every SIEM you run.

The engine is being generalised so the same analyst, and the same audit trail, works across platforms and survives a SIEM migration.

Available

OpenSearch-based SIEMs

Ingest by API or push, validated hunts, and delivery to your ticketing and chat tools.

Next

Elastic Security

The first new adapter, sharing the existing OpenSearch query path.

Planned

Sentinel & Splunk

KQL and SPL investigation, with verdicts written back to incidents and findings.

Later

QRadar & more

Migration continuity: the same analyst on the old SIEM and the new one.

Company

About Evercept

We think the AI that watches your network should be held to the same standard as an analyst: show your evidence, or don't make the call.
  • Founded2026
  • ServingSOC teams and MSSPs, worldwide
  • ProductEvercept Analyst, a self-hosted AI SOC analyst
  • Built onClaude by Anthropic
  • Contact[email protected]
Design partner programme

Put Evercept on your alert queue.

We're working with a small number of SOC teams and MSSPs running OpenSearch-based SIEMs, Elastic, Microsoft Sentinel or Splunk. Tell us about your environment and we'll show you the engine on your own alerts.

  • Early access
  • Direct input on the roadmap
  • Runs inside your network