Platform · How it works

From sensor to report.

A complete walkthrough of how Viktrix detects, triages, contains, and documents threats, and what accountability looks like at every stage.

HOW THE PLATFORM WORKS

Five steps, fully accountable

From the first signal to the report your insurer reads, AI handles the volume, humans make the judgement calls, and every step is recorded.

01

Detect

Lightweight agents on your devices stream sign-ins, files, processes and network activity to the SOC in real time.

02

Triage

AI reads every alert in seconds, checks it against known attacker techniques (MITRE ATT&CK), and scores how confident it is.

03

Contain

Clear threats are cut off first, and the affected device is isolated in under a second, before anything spreads.

04

Respond

Then Vindex deals with it: blocking the addresses involved, locking compromised accounts, cleaning up. Anything new or unclear waits for human validation.

05

Report

Every step lands in a permanent, tamper-evident record you can hand to your insurer or auditor.

Signal ingestion

Four planes. One correlation engine.

Endpoint

Process · Registry· Memory

Identity

Sign-ins · MFA · Privilege

Network

DNS · Flow · Proxy

Cloud

Azure · M365 ·Entra

VINDEX

Correlation
Engine

MITRE ATT&CK V14

Auto-contain
Analyst queue
Audit ledger

01

Onboarding

Up and running in under a day.

The Viktrix MSI bundle deploys silently across your Windows fleet with no reboot and no user disruption. macOS and Linux agents install via a single command. Once agents are live, we integrate your identity provider (Azure AD / Entra ID, Okta), your cloud workloads, and any existing SIEM. There's no migration; Vindex sits alongside what you have and enriches it.

  • Silent MSI installer, no reboot, no downtime
  • macOS and Linux agents via single command
  • Azure AD / Entra ID / Okta integration
  • Existing SIEM ingested, not replaced
  • SOC active from first sensor connection
Viktrix Hero
Viktrix Hero

02

Detection

Every signal, in context.

Vindex ingests telemetry from four planes simultaneously: endpoint process and file activity, identity sign-ins and privilege changes, network flows and DNS, and cloud API calls. All four are fused into a single correlation engine. A credential dumping attempt on endpoint WIN-4471 is immediately correlated with the admin sign-in from an impossible travel location that preceded it.

  • Endpoint: process tree, file writes, registry, memory
  • Identity: sign-ins, MFA events, privilege escalation
  • Network: flow data, DNS queries, proxy logs
  • Cloud: Azure audit logs, M365 activity, Entra sign-in risk
  • Cross-plane correlation before any alert is raised
More on detection

03

Triage

AI scores it. Analysts own it.

Every alert is normalised, deduplicated, and anonymised, names, emails and identifiers are replaced with placeholders before any AI model is involved. Indicators are enriched against global threat intelligence; behaviour is compared to per-user baselines; history is consulted for similar incidents. A deterministic planner routes each alert by risk: known noise resolves cheaply, routine alerts get standard AI analysis, high-risk signals trigger a full deep investigation. AI agents classify against MITRE ATT&CK and produce a calibrated confidence score, then a rule-based safety check, with no AI involved, reviews every verdict before anything acts on it.

  • Confidence threshold configurable per tenant
  • AI reasoning and evidence surface in one view
  • SLA timers visible on the client dashboard
  • Every decision carries an analyst signature
More on automated triage
Viktrix Hero
Viktrix Hero

04

Contain

Cut off first, in under a second.

Clear threats are cut off before anything else happens. The affected device is isolated at the network layer in under a second and a containment record is written to the audit chain. Containment is reversible by design; it buys time without destroying evidence, so an analyst can still see exactly what the attacker did.

  • Host isolation at network layer, not just process kill
  • Isolation completes in under a second on high-fidelity alerts
  • Rollback available for every automated action
  • Contain-and-investigate mode preserves forensic evidence
  • Lateral movement paths severed automatically
More on containment

05

Respond

Then Vindex deals with it.

Once the threat is contained, Vindex responds, blocking the addresses involved, locking compromised accounts, and clearing what the attacker left behind. Automatic on high-fidelity alerts; anything new or irreversible waits for human validation.

  • Firewall blocks pushed to all gateway integrations
  • Compromised accounts locked and sessions revoked
  • Attacker persistence cleared, artefacts removed
  • Every response action reversible and written to the audit chain
  • Human validation on anything new or irreversible
More on autonomous response
Viktrix Hero
Viktrix Hero

06

Audit

Everything is on the record.

Every detection, decision, and action lands in a tamper-evident, hash-chained ledger. Incident timelines, compliance evidence, and board reports export on demand, evidence built to the standards your auditor and insurer ask for, not a reconstruction.

  • SHA-256 hash-chained incident records
  • Exportable as structured JSON
  • Meets common UK cyber insurance evidence standards
  • ISO 27001 incident-logging compliant
  • Immutable: no edit or delete capability
More on the audit trail

Want the technical detail?

The Vindex product page has the agent architecture, guardrail model, and specs.

See all five steps live, on real alerts. Book a demo.

Viktrix Logo

Ready to close the gap?

Get enterprise-grade protection running in minutes. No disruption, no long contracts, no lock-in.