Services

The AI Attack Readiness Assessment

A fixed-scope engagement. We run LogLM against your historical telemetry and report the attacks your current stack missed. No agents to deploy, no disruption to operations, results in weeks.

How the assessment runsFixed scope
1
Share historical telemetryFlow logs and telemetry you already collect. Data stays in your environment.
2
LogLM replays the recordZero-shot detection across the lookback window. No rules to write, no tuning.
3
Findings reviewMITRE-mapped findings, ranked and explained, reviewed with your team.
4
Readiness readoutWhat was missed, why, and a concrete plan — SOC-ready and board-ready.
What you get

Evidence, not a pitch

Missed-attack report

Every finding LogLM surfaced from your own telemetry that your current stack did not flag. Ranked, MITRE-mapped, and explained in plain language.

Detection-gap map

Where your coverage is strong and where it is thin, by tactic and technique. A basis for engineering priorities, not a scorecard.

SIEM cost analysis

Which log sources earn their ingestion cost and which do not. Most teams find meaningful savings before the readout ends.

A path to production

If the results warrant it, the assessment environment becomes the deployment. Start with workflows in Vigil or detections in your data lake.

Why teams run it

Proof on your own data

Benchmarks and demos are easy to stage. Your own telemetry is not. The assessment answers one question with evidence: what is getting through right now?

Data stays in your environment. Bring your own cloud or run on-prem.

Typical engagementIllustrative
Lookback window30–90 days of telemetry
Your effortHours, not weeks
Agents installedNone
DeliverableFindings + readiness readout

See what LogLM and Vigil add to your stack

Run a 30-day assessment. LogLM analyzes your operational telemetry and reports what your stack missed. Vigil, the open source AI SOC, turns the findings into action.