Agents break detection built for people.
Agents run commands, touch data, and change state at machine speed. They act nothing like human users, and most of the time they are not malicious. Rules and conventional ML read that as thousands of alerts a day. The Intelligent Defense Platform reads it as behavior: LogLM scores the compound sequence, Vigil investigates it to a decision.
Runs in your environment. On premises, in your data lake, or fully air-gapped.
Vigil: individually low-signal. As one sequence, a service account turned a package mirror into an egress path and reached a live credential. Grouped, enriched with identity and asset context, raised as one case, not 1,200 alerts.
The output is not the risk. The sequence is.
A single agent action tells you almost nothing. A package install, a file written to shared storage, a fetch through a mirror: each is ordinary in isolation, and a rule written for one of them either stays silent or fires on everything. Agents generate these actions in volume, around the clock, with no regard for the working-hours and single-session patterns detection was tuned against.
The signal lives in the combination. LogLM was built to read sequences of telemetry as compound behavior, so a run of individually benign steps that together describe egress and escalation surfaces as one concerning sequence rather than a thousand disconnected anomalies. Vigil takes that sequence, assembles the identity, asset, and history around it, and resolves it to a case a person can act on.
zero-shot detection accuracy, across environments LogLM has never seen
false positives, so analysts work cases, not noise
false-negative rates measured at a top-four global bank and at BNY
lower SIEM cost by moving detection off raw-log volume
Two layers, one owned loop.
Detection and investigation are different problems. The platform keeps them distinct, and keeps the learning loop that connects them inside your environment, under your control.
Compound detection at machine speed
LogLM is an encoder-only foundation model that understands cybersecurity telemetry across protocols and sources. It embeds sequences of activity into a high-dimensional space, then purpose-built classifiers score what that behavior means. Because it is trained across diverse environments rather than tuned to one tenant, it works on day one, with no baselining period and no learning window.
- Reads agent behavior as a sequence, not a stream of unrelated events
- Scores the combination of steps that individually clear every rule
- Computationally inexpensive and always on, so it holds up as attackers add intelligence and volume
The investigation and context layer
Vigil is the leading open-source AI SOC, Apache 2.0, and it performs substantially all of a SOC's day-to-day work. It takes a scored sequence and does what a good analyst does: pulls the identity behind the actor, the assets it touched, the history that precedes it, and the detections already covering it, then resolves the whole thing to a decision-ready case. Agent actions trigger the same investigation logic as a human's.
- Groups low-signal events into one case instead of a flood of alerts
- Manages the detection rules an environment runs, including federated detections in Splunk and Elastic
- Reconstructs a full agent session across endpoint, network, cloud, and the agent's own log
Red team your own environment, keep what you learn
The learning loop spans the whole platform, Vigil's workflows, Vigil itself, and LogLM, and it stays in your environment. Teams red team their own systems, turn that experience into detections, and measure efficacy inside the loop. Declared intent lives as Markdown under change control per environment. Nothing egresses to a vendor cloud for this to work.
- Detection coverage assessment against the behavior you actually see
- Policy and intent stored as versioned, reviewable artifacts
- The loop that connects detection to investigation is yours to own and secure
Not human. Mostly not malicious. Still a detection crisis.
Conventional ML and rules assume a human on the other end: a person who sleeps, works one session at a time, and whose intent can be inferred from a single bad action. Agents violate every one of those assumptions. They persist across tasks, coordinate over channels no one provisioned, and chain weak permissions into paths that are invisible when each weakness is assessed alone.
The result, before anyone is attacked, is noise. Benign agents trip the same tripwires as adversaries, and the SOC drowns. The answer is not a tighter rule. It is detection that reads behavior as a sequence and an investigation layer that turns that sequence into a decision.
Read the deep dive on the OpenAI and Hugging Face incidentWhat a rule sees vs. what LogLM sees
The same five actions, two readings.
See it, detect it, investigate it.
Sequence-level detection
LogLM scores the combination of actions an agent takes, catching what single-event rules miss and what per-tenant ML needs weeks to learn.
Agents treated like any other actor
Agent activity runs through the same detection and investigation path as a human's, with the identity and asset context attached.
One session, every layer
Vigil reconstructs a full agent session across endpoint, network, cloud, and the agent's own log, in a single timeline.
Fewer alerts, better cases
Low-signal events group into investigated cases. Analysts spend their time on decisions, not on triaging benign agent noise.
Works with what you own
Vigil extends existing detections, including federated rules in Splunk and Elastic, rather than asking you to rip and replace.
No egress required
Defense does not depend on a model provider's compliance API or a vendor cloud. The model travels to your data; your telemetry stays in place.
Inside your boundary, on your terms.
On premises or air-gapped
Run the full platform where your telemetry already lives, including fully disconnected environments, with no special-purpose hardware.
In your data lake
Ingestion scales horizontally through the platform's scale-out architecture. Batch or continuous real-time stream, your choice.
Bring your own cloud
BYOC or Kubernetes. The control plane scales LogLM inference alongside ingestion as volume grows.
See a benign agent flood become one investigated case.
Send us telemetry for an assessment, or stand up Vigil in your own environment. Either way, you keep control of the data and the loop.
