Calyvex SOC
A security operations workspace concept for ingesting events, elevating relevant signals and supporting analyst investigation.
- Event and alert visibility
- Severity and confidence context
- Incident timelines
Calyvex combines cybersecurity engineering, AI-assisted analysis and responsible validation to help organizations detect threats, improve security operations and make defensible decisions.
Our focus extends beyond a single tool or research project. We connect detection, analysis, validation and continuous improvement.
Improve log visibility, detection quality, dashboards and analyst workflows across SIEM and SOC environments.
Explore capability 02Use language models and automation to summarize evidence, support triage and improve reporting while keeping analyst control visible.
Explore capability 03Investigate suspicious behavior through threat hunting, malware analysis, network evidence and detection engineering.
Explore capability 04Test whether security controls detect realistic techniques through authorized, scoped and evidence-driven validation.
Explore capabilityGood security automation should reduce friction without hiding the evidence. Our approach keeps context, limitations and human approval visible.
Collect and structure relevant security signals.
Identify behavior that deserves attention.
Connect the finding to readable evidence and uncertainty.
Test whether controls work against realistic techniques.
Turn findings into measurable defensive changes.
A sequence of failed authentication attempts was followed by a successful privileged login from an unfamiliar source.
A security operations workspace concept for ingesting events, elevating relevant signals and supporting analyst investigation.
An explainable assistance layer for incident summaries, investigation questions and consistent security reporting.
A detection engineering toolkit direction for reusable rules, validation cases, telemetry requirements and tuning notes.
Run a safe, simulated security scenario. Inspect events, review an elevated signal and see how an AI-assisted explanation can support—not replace—an analyst.
The Lab is where we test ideas, document limitations and build the technical evidence behind future services and products.
An unsupervised anomaly-detection pipeline with LLM-assisted incident explanations and an interactive SOC dashboard.
A controlled Windows and Linux environment for generating telemetry, testing detections and documenting analyst investigations.
Researching how excessive low-quality alerts, missing context and repetitive validation affect analysts—and how assistance can help.
View researchWhy alert quality, false positives, missing context and repeated exposure matter more than raw volume alone.
Read insightAn automated recommendation becomes useful only when an analyst can understand and verify its reasoning.
Read insightHow context, playbook design and human judgement shape the space between an alert and an action.
Read insightTell us what you are trying to detect, understand, validate or improve.