Skip to content
Platform

One platform.
SIEM · SOAR · XDR · UEBA.

An autonomous Integrated Security Operations Center (ISOC): a Modern SIEM and a native Security Data Lake in one cloud-native platform. Connect any source, correlate across IT, OT and blockchain, and respond automatically, all from one console with one pricing model.

Alert Command Center
Last 12 months
Sources 11 live
  • Edge firewall WAN gateway 12.5B
  • Web gateway Proxy + filter 5.8B
  • Microsoft Windows AD 1.3B
  • Fortinet FortiGate 728M
  • Cloudflare Audit + WAF 638M
  • Microsoft SharePoint 495M
  • Microsoft Exchange Online 123M
  • Microsoft SQL audit 78M
  • Aruba ClearPass 21M
  • CrowdStrike Falcon EDR 12M
  • Okta System Log 5.3M
21.7B 11%

Events ingested

109,191 18%

Signals triaged

59,158 6%

Auto actions

Active cases 22,068
  • 9,083 New +18%
  • 508 In progress steady
  • 12,477 Escalated +29%
Resolved cases 87,123
  • 49,635 Resolved +41%
  • 36,825 False positive +6%
  • 663 Critical handled +12%
First action <1s · Investigation ~5 min --:--:-- UTC
Sources
11
connected today
Events / yr
21.7B
avg 59.4M/day
First action
<1s
median, signal-raised
Auto actions
59,158
one every 9 min
Platform

The security command centre
for any SOC.

Blacklight unifies a security data lake, SIEM, SOAR, XDR, UEBA, threat intelligence and agentic response into one cloud-native plane. One pipeline, one console, one reasoning trail, across IT, OT and blockchain estates.

  • Unified detection
    SIEM + XDR + UEBA correlated.
  • Automated response
    SOAR playbooks, no scripting.
  • Cloud-native
    Elastic, multi-region, residency-aware.
  • Three estates
    IT · OT · Blockchain — one console.
One platform 8 capability modules
  • SIEM

    Correlate signals across IT, OT and cloud.

    • Multi-tenant
    • Hot + cold
    • Retention
  • SOAR

    Auto-contain, rotate and notify in seconds.

    • Playbooks
    • Reversible
    • No scripting
  • XDR

    Endpoint, network and cloud telemetry, joined.

    • Endpoint
    • Network
    • Cloud
  • UEBA

    Behaviour baselining for users and entities.

    • Baselining
    • Peer cohort
    • Risk graph
  • Threat Intelligence (TIP)

    KEV, OSINT and leak corpora correlated daily.

    • KEV
    • OSINT
    • Leak corpora
  • Case Management

    Every case tracked from alert to closure, with full context.

    • Case memory
    • Custody chain
    • SLA
  • Compliance

    ISO, SOC 2 and audit-ready reporting wired in.

    • ISO 27001
    • SOC2
    • Audit
  • Data Plane

    Ingest everything across IT, OT and cloud. Nothing sampled or dropped.

    • Independent
    • Residency
    • Sovereign
One platform

A platform, not an overlay.

Blacklight is the stack, not a co-pilot bolted onto someone else's SIEM: an autonomous Integrated Security Operations Center (ISOC) with a Modern SIEM and native Security Data Lake, agentic AI native, not added on.

Detection pipeline

From source
to response.

Every event walks the same six steps. No glue code, no swivel-chair triage — a single pipeline, fully observable, fully audited.

  1. Sources
    IT · OT · Cloud
    11 connectors live
  2. Ingest
    Parse · Normalise · Enrich
    21.7B events / yr
  3. Correlate
    SIEM · UEBA · XDR · CTI
    109,191 signals · 12 mo
  4. Decide
    AI Reasoning & Verdict · Devil’s Advocate Test
    82% absorbed by AI
  5. Respond
    Automated playbooks · Contain & Mitigate
    59,158 auto actions / yr
  6. Report
    Investigation Details · Compliance & Audit
    <1s first action
Event stream
  1. 8s ago Detection mapped to T1566 · Phishing · Microsoft 365 · Audit Log
  2. 24s ago KEV correlation hit on Microsoft · 55 CVEs in window
  3. 47s ago Auto-triage closed FP 0.91 confidence · no analyst touch
  4. 1m ago Detection mapped to T1190 · Exploit Public App · Cloudflare WAF · edge
  5. 1m ago Identity anomaly: impossible travel · Manila → Geneva · 14m
  6. 2m ago SOAR playbook completed in 2m 14s · isolate-asn · edge block
  7. 2m ago Detection mapped to T1078 · Valid Accounts · Okta · System Log
  8. 3m ago Threat intel pushed: Mustang Panda · LOTUSLITE · APAC · +3 IOCs
  9. 4m ago KEV correlation hit on Fortinet · 14 CVEs in window
  10. 5m ago Hunt complete: guest-financial-dlp-gap · 0 hits · closed
  11. 7m ago Detection mapped to T1556 · Modify Auth Process · Azure AD · risky sign-in
  12. 9m ago UEBA cluster: 42 IPs · 11 ASNs · RDP spray pattern
  13. 12m ago Auto-disposition: bulk SharePoint download · escalated · T2 ticket
  14. 16m ago KEV correlation hit on Ivanti · 13 CVEs in window
  15. 21m ago Detection mapped to T1114 · Email Collection · Exchange · forwarding rule
  16. 28m ago SOAR playbook completed in 47s · revoke-session · credentials
  17. 36m ago Threat intel pushed: Iranian low-frequency ops · EMEA · low confidence
  18. 47m ago Source ingest: CrowdStrike Falcon EDR · +47k events/min
Guided Tour

Click through the product.

Step 1 of 12
3
12
28
47
JS
Available Sources
Microsoft 365
Office 365 audit logs
CrowdStrike
Detection stream
G
Git Audit
GitHub / GitLab logs
W
Windows Logs
Event Log audit
S
Generic Syslog
Universal receiver
U
Universal Push
AI-parsed ingestion
Active Sources 0 connected
No active data sources
Select a source type to begin
M
Connect Microsoft 365
Office 365 audit log integration
Available Sources
Microsoft 365
Connected ✓
CrowdStrike
Detection stream
G
Git Audit
GitHub / GitLab logs
Active Sources 1 connected
M
Microsoft 365
AzureAD · Exchange · SharePoint · General
Active
Events/s
247
Uptime
100%
Health
Good
Blacklight Default
+
Global Intelligence
Alert Priority
90 ALERTS
Events Over Time (24h)
Top Alerts
Brute force login attempt — user-c@corp.com 14:28
Suspicious SharePoint bulk download 14:15
New inbox forwarding rule created 13:52
Standard login from known device 13:41
Blacklight Default
New Dashboard
+
Generate with AI
Describe what you want
Generate AI Dashboard
Describe the dashboard you want
⌘ + Enter to generate
Tips:
• Be specific about metrics and time ranges
• Mention data sources or user groups
• Describe preferred chart types
Creating your dashboard...
AI is building widgets based on your description
Analyzing data sources...
Translating to query language...
Generating widget layout...
Blacklight Default
AI Usage Per User
Last 30 days
24h 7d 30d
AI Queries by User
User C · 7,832
A
B
C
D
E
F
Total Queries
12,847
Avg / User
2,141
Outlier
User C
7,832 queries
Usage Trend
Top AI Models
GPT-4o
72%
Claude 3.5
18%
Gemini Pro
10%
Verdict
Incident Suspicious Benign Hygiene
Priority
High Medium Low
3 results
Explorations
Reports Research
Incident · High confidence
12 min ago
SharePoint exfiltration via shared accounting mailbox
Forwarding rule on shared accounting inbox routed 1,628 documents to a personal cloud location. Cross-correlated with ATT&CK T1114 / T1567 · 0.94 confidence.
Entity
accounting-shared
Files
1,628
Sources
5
exfiltration M365 shared-account
Hygiene · process gap
2 h ago
Credit-card numbers in inbound guest email
Spa booking inbox · 14 DLP hits, all blocked. Customer-driven process gap, not a compromise.
Suspicious · external campaign
5 h ago
RDP password spray from 11 ASNs
42 source IPs · 1.2M requests · MFA held. Mapped to ATT&CK T1190.
Contents
Overview
Key Findings
Timeline
Affected Resources
Recommendations
Incident
EXP-2026-0473 · 0.94 confidence
SharePoint exfiltration via shared accounting mailbox
Mapped to ATT&CK T1114 / T1567 · Explored 12 minutes ago
Key Findings
Forwarding rule FWD:invoices* set on the shared accounting-shared@ mailbox at 02:14 UTC
1,628 SharePoint documents downloaded over 41 minutes; 92% from Finance team site
3 new Power Automate flows created with external webhook endpoints
Recommendations
Revoke shared mailbox tokens and audit delegated permissions
Disable the forwarding rule and quarantine the Power Automate flows
Ask a follow-up question...
Contents
Overview
Key Findings
Follow-up Results
Follow-up Question
Resource Access Analysis
Accessed 14 SharePoint sites across 3 departments (Finance, HR, Engineering)
Downloaded 2,847 files totalling 12.3 GB — 89% from Finance team site
Created 3 new Power Automate flows with external webhook endpoints
Accessed Azure Key Vault (first-time access for this user)
Risk Assessment: High
Cross-department data access combined with external automation rules strongly suggests data exfiltration. Immediate containment recommended.
Layer
KEV exposure
Credential leaks
Active campaigns
Severity
Critical High Med
Tracked KEVs
216
+8 this week
N. America · 47
Europe · 38
APAC · 62
LATAM · 14
Africa · 9
216 KEVs · 11 active campaigns · 3 critical
7d 30d 90d
APAC drilldown Live
62
KEVs in this region
Crit
11
High
28
Top campaigns
Salt Typhoon · telecoms
Volt Typhoon · LotL
FortiGate SSL VPN spray
Correlated to your estate
3 of 62 APAC KEVs match assets you own
3 actionable
CVE-2024-21887 CRIT · 9.1 2 hosts
Ivanti Connect Secure command injection
Matches vpn-sgp-01, vpn-sgp-02 · KEV added 5d ago
CVE-2024-3400 HIGH · 8.6 1 host
PAN-OS GlobalProtect arbitrary file create
Matches fw-tyo-edge · campaign tag Volt Typhoon
CVE-2023-46805 PATCHED 0 hosts
Ivanti auth bypass (older variant)
No exposure — verified by last sweep
Updated 14:32 UTC · refreshes every 5m View all 62 →
Capabilities

Four pillars, one platform.

01 Ingest & Monitor

Plug & Monitor

Log integration made simple — rapid ingestion with centralised, consolidated controls to keep every data source healthy.

  • 145+ pre-built connectors across cloud, on-prem, OT and blockchain
  • AI-parsed Universal Push for sources without dedicated integrations
  • Source-health dashboards, ingest budgets and quota alerts built in
  • Field-level normalisation to OCSF + your house schema
02 Detect & Respond

AI Modelling Built In

AI baselining for faster threat detection, combined with multi-level rules to protect sensitive data, critical systems and blockchain infrastructure.

  • Behavioural baselines (UEBA) per identity, host, segment
  • Rule, ML and graph correlation in a single pass
  • Reasoning trail on every verdict — auditable, override-able
  • Multi-trigger automation: 38+ SOAR playbooks fire on any signal, schedule or chained event
03 Report & Action

Decisions From Data

Built-in trends and metrics turn your security telemetry into business decisions — a data-driven view of where to invest next.

  • Executive dashboards aligned to NIST CSF, ISO 27001, NIS2, DORA
  • MTTD / MTTR tracked per source, per playbook, per analyst
  • Continuous control attestations exportable to GRC tools
  • Coverage heat-maps mapped to MITRE ATT&CK
04 Lean & Efficient SOC

Built For Modern Teams

Designed to address the cybersecurity skills shortage and help SOCs and managed providers run lean, focused operations.

  • AI co-pilot triages tier-1 inbox with confidence scores
  • Hand-offs between human and AI are explicit, not invisible
  • Multi-tenant for MSSPs — isolated data, shared content library
  • Analyst telemetry: where time is spent, where it is wasted
Connectors

145+ sources.
Out of the box.

Plus a Universal Push connector that AI-parses anything we have not seen yet.

Microsoft 365
CrowdStrike
AWS
Microsoft Sentinel
Google Cloud
Okta
SentinelOne
Cisco Secure
Palo Alto
Fortinet
SYS
Generic Syslog
+
and many more
Capabilities

Built for analysts.
Trusted by leaders.

The work that used to take a Tier-1 analyst all morning now happens in seconds, with a reasoning trail you can put in front of an auditor.

Threat Intelligence

Global threat landscape,
mapped to your geography.

KEV, OSINT and known-actor activity correlated against the regions and platforms you operate in — not generic feeds.

  • 54 unique KEVs in the last 30-day window
  • Industry-specific actor mapping (MITRE ATT&CK)
  • Auto-routed to the analyst who owns that estate
Threat Landscape
Period close
HKG · 132 TYO · 78 MNL · 54 BKK · 41 SHA · 36 LHR · 19 NYC · 27
KEV / 30d 54 Identities exposed 682 Breaches 108
Active campaigns period close
  • APAC crit
    Mustang Panda / LOTUSLITE
  • Global crit
    Microsoft credential abuse
  • Global high
    Cisco edge backdoors
  • Supply high
    Axios NPM compromise
  • Supply med
    Trivy scanner trojan
  • EMEA med
    Iranian low-frequency ops

Pins reflect direct operational presence. Side list shows the global campaigns currently relevant to the estate.

Identity Exposure

Continuous leak monitoring
for every identity you protect.

Every employee, contractor and partner identity is checked daily against breach corpora, paste sites and underground forums — with reasoned context, not just a hit count.

  • 682 identities surfaced across 108 distinct breaches
  • Severity scored against role, MFA state and past breaches
  • One-click rotation playbooks via SOAR
Leak Intelligence
Continuous scan
682
Identities exposed
across 108 distinct breaches
8.7M
Latest material event
Loyalty programme breach · Apr 2026
23
Of yours hit
flagged within hours of disclosure
Recent breach hits 5 of 108
  • LY
    •••@•••.com
    Customer-facing role
    Loyalty programme breach
    4d ago
    crit
  • CO
    •••@•••.com
    Senior leadership
    Corporate-network breach
    2w ago
    crit
  • FM
    •••@•••.com
    Operations team
    Combo-list aggregator
    11d ago
    high
  • TG
    •••@•••.com
    IT / support staff
    Telegram channel dump
    3w ago
    med
  • PB
    •••@•••.io
    External contractor
    Public paste-site dump
    1mo ago
    med
12-mo trend +682
Latest material event: Loyalty programme breach (Apr 2026) — 7.5M loyalty emails exposed.
Autonomous Triage

AI absorbs the volume.
Humans see only what matters.

A reasoning agent grades every signal against your environment, intel and history. Every decision is explained, every escalation is auditable, every action reversible.

  • 82% of signals absorbed before human review (last 30 days)
  • Median first action <1s, full investigation ~5 min
  • 59,158 autonomous lifecycle actions in the last 12 months
Autonomous Triage
Autonomous
4,003 signals · last 30 days
721 reached human review · 82% absorbed by AI + auto-rules
  1. high · Microsoft 365 · Audit Log T1556 Modify Authentication Process
    Anomalous OAuth grant on M365 tenant
    • Identity context: rare-app, never-seen-before scope set
    • Threat intel: app id matches recently published consent-phishing IOC
    • Cross-correlating with sign-in graph for 5 peers…
    AI triaging · first action <1s
  2. crit · Cloudflare · WAF + edge firewall T1190 Exploit Public-Facing App
    ADFS metadata-discovery flood, login.* edge
    Escalated
    • 1.2M discovery requests in 7 days — known password-spray signature
    • Cluster of 42 source IPs across 11 ASNs, MFA held
    • Mapped to ATT&CK T1190 with confidence 0.94
    SOAR · isolate-asn · blocked at edge · 02m 14s
  3. high · Microsoft · SharePoint T1114 Email Collection
    Bulk SharePoint download, terminated account
    Escalated
    • Account flagged "leaver" 18h ago, still propagating in directory sync
    • 1,628 documents downloaded to a personal cloud location
    • Mapped to ATT&CK T1114 / T1567 with confidence 0.88
    Routed to T2 SOC · ticket BL-44912 · evidence pack attached
  4. med · Microsoft · Exchange Online T1566 Phishing
    Inbox forwarding rule, finance senior
    Benign
    • Rule created via legitimate session from known device
    • Forward target matches finance team SaaS rollout window
    • Reasoning trail flagged false-positive after host context check
    Auto-closed · added to allowlist (90d)
Plugin Hub · Autonomous detection engineering

Detection content that writes, proves and tunes itself.

Legacy SIEMs ship generic content and leave the hard part, relevance, tuning, false-positive control and lifecycle, to your detection engineers. The Plugin Hub inverts that. Detection is generated from your environment, validated in your environment, and deployed only once it has proven its value in your environment. It is an autonomous detection engineering team, operating inside the platform.

Observe what can be detected Propose what should be Prove it works here Deploy, then keep tuning
STAGE 01

Coverage intelligence

What could we detect?

A live model of the environment's detection potential, built from four signal sources and mapped to MITRE ATT&CK.

Telemetry & schemaThreat intelligenceAI hunt findingsAlert history

Telemetry-honest gaps: a technique is only "coverable" if the data to detect it actually exists here, so the Hub can name the one log source that closes the most gaps.

STAGE 02

Candidate generation

What should we deploy?

Each candidate, a rule, a behavioural model, or a multi-signal use case, carries a full engineering record: ATT&CK technique, exact fields consumed, trigger logic, rationale and a predicted noise profile.

Prioritised by risk relevance: techniques active against your sector now, and gaps adjacent to past confirmed incidents, rank above theoretical coverage.

STAGE 03

The QA gate

Does it actually add value here?

No candidate reaches production on plausibility. Each passes a multi-phase gate, run inside your environment against real data.

Dedup analysisValue-add scoringBuildShadow runAgent cross-checkFP ratio

Unique, valuable, correct and quiet: a noisy candidate is auto-tuned and re-shadowed; one that covers no confirmed gap is held, not shipped as dead weight.

STAGE 04

Deployment & lifecycle

And it never stops.

Promotion is fully automated: no change window, no professional-services engagement. Each plugin ships with its validation evidence attached.

QA never ends: live plugins are continuously monitored, re-tuned on environment drift, and retired when their telemetry disappears or a better detection supersedes them.

Per-environment ATT&CK coverage matrix
Covered & validated Partial Gap (telemetry-limited)

Every claim is auditable: each deployed plugin carries its QA record, measured false-positive ratio and technique mapping. A defensible, current answer to "what can we detect today?" (Matrix shown is illustrative.)

Included at every tier.

Like everything in Blacklight, the full Plugin Hub comes standard. Detection content that grows with your telemetry and the threat landscape, MITRE-aligned by construction, at no extra cost.

No add-ons · No content packs · No PS fees
Automated incident response

Hours of investigation,
compressed to minutes.

From the first signal to a regulator-ready forensic report, Blacklight's agents run the incident end to end, correlating IT, OT, cloud, identity and SaaS telemetry into one forensic timeline and catching ransomware before encryption executes.

3x
Analyst capacity per engagement
<15 min
Agentless time to deploy
<24 hr
Time to forensic report
24/7
Autonomous hunting & triage
  1. 01 Onboard

    Connect IT, OT, cloud, identity, SaaS and email in under 15 minutes. Isolated workspace per client, chain-of-custody from Day 0.

  2. 02 Investigate

    AI agents correlate cross-domain telemetry and build the forensic timeline. Alerts arrive pre-investigated.

  3. 03 Triage

    Active attacker or post-impact? Blast radius, threat surface, and what's burning right now.

  4. 04 Hunt

    Patient zero, lateral path, persistence and IOCs. Months of historical telemetry reconstructed.

  5. 05 Contain & evict

    Isolation, credential rotation, attacker eviction and clean-state validation, before encryption fires.

  6. 06 Report & retain

    Regulator, carrier and counsel packages in under 24 hours. The platform stays on for continuous MDR.

For IR & DFIR firms · MSSP / MSP partners

Turn one-off incident response into recurring revenue.

When the engagement ends, the platform stays on: continuous monitoring per client, white-labelled or co-branded under your firm. Per-client isolated workspaces, audit-tracked chain-of-custody, and multiple engagements in parallel with no cross-contamination.

Partner with Blacklight
The proof

SIEM, MDR, or Blacklight.
The gap is measured in minutes, not hours.

Traditional SIEM

Rule-based detection

Time to assign
3.6 hours
Investigation to resolution
3.8 hours
Full lifecycle
4.9 hours

Legacy MDR

Human-led service

Time to assign
45 minutes
Investigation to resolution
2.1 hours
Full lifecycle
3.2 hours

Blacklight AI

Agentic, autonomous

Time to assign
59 seconds 216x
Investigation to resolution
5.2 minutes 44x
Full lifecycle
5.3 minutes 56x
The analyst receives a completed investigation report. They did not open a ticket, search logs, build a timeline, or write a summary. They review and act.

The Blacklight figures come from our own enterprise deployments. The Traditional SIEM and Legacy MDR columns are representative industry baselines drawn from SOC operations research (SANS 2024 SOC Survey and industry reporting), not vendor-specific claims. Done comparing? See the same table run against your own telemetry. We connect, you watch, and you decide whether the numbers hold.

Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.