Research ideas. Build evidence. Test what works.
The Lab is the technical foundation of Calyvex, organizing applied work into research tracks, practical projects and clearly labelled prototypes.
Alert Fatigue and Explainable Triage
Researching how excessive low-quality alerts, missing context and repetitive validation affect analysts—and how assistance can help.
SIEM, SOAR and Adaptive Security Operations
Examining where detection, orchestration and analyst workflows remain fragmented, rigid or difficult to maintain.
Large Language Models for SOC Analyst Assistance
Evaluating where language models can support summarization, investigation and reporting—and where their limitations create risk.
AI-Based Threat Detection & SOC Dashboard
An unsupervised anomaly-detection pipeline with LLM-assisted incident explanations and an interactive SOC dashboard.
Security Detection & Attack Simulation Lab
A controlled Windows and Linux environment for generating telemetry, testing detections and documenting analyst investigations.
XSAR / AXSAR Security Operations Framework
A research-led framework exploring explainable automation between SIEM detection and SOAR response.
Browser-Based SOC Investigation Demo
A static, safe demonstration of event review, elevated signals and evidence-linked incident explanation.
Detection Content Library
A structured prototype for storing detection logic together with telemetry requirements, validation steps and tuning notes.
Useful research must survive contact with real constraints.
We separate concepts, research, prototypes and completed work.
Every result is presented with scope and known constraints.
Security validation is controlled, authorized and evidence-led.
Research should inform tools, services, training or operational improvement.
Need a practical security solution?
Tell us what you are trying to detect, understand, validate or improve.