Platform / Layer 2
Layer 2

An alert should be something you can check, not something you have to believe.

A row that says suspicious PowerShell, high severity asks for your trust and gives you nothing to test it with. This layer's job is to hand you the reasoning instead — what led here, what followed, and whether this machine has ever done it before.

The argument
Detection has two halves that most products conflate. A rule can tell you a pattern occurred — that is general knowledge, true everywhere, and it is the easy half. Whether the pattern means anything here depends on your estate: what this machine normally does, who normally signs into it, what it can reach.

So this layer keeps them apart. Rules match patterns. Baselines say whether that is unusual for you. And a graph holds the surrounding facts, so the question why do you think so has an answer you can walk through yourself rather than a confidence score.
Walk the graph yourself
click any node · authored example, not live data

This is the shape of a real alert: one moment in the middle, what led to it on the left, what followed on the right. Click a node to see the evidence behind it.

Foothold on web-07 escalated toward the billing database 24 Aug · 11:02–11:06 UTC
Evidence for this node
A service account signed in from an address it had not used before. On its own this is unremarkable — addresses change. It matters here only because of what followed within two minutes.
auth.success · svc-deploy · 203.0.113.44 · first-seen · 11:00:41Z
The honest limits
Severity describes the pattern, not your estate
A rule cannot know whether this is normal for you. That is what the entity's own history is for, and disagreeing with a rule's ranking is a legitimate outcome of triage rather than a fault.
A baseline needs time before it means anything
In the first weeks of a deployment, unusual and unfamiliar look identical. Boards say which they are showing you rather than presenting a young baseline as a confident one.
A graph can only hold what layer one recorded
A gap in coverage becomes a gap in the chain, drawn as a break rather than closed with a plausible guess.
Big searches are bounded, and say so
A query that hits its ceiling returns the newest results and tells you it stopped. Counts from a bounded scan are floors, labelled as floors — never presented as totals.
What this layer deliberately does not do
It does not act. Nothing on this floor can isolate a host, revoke a session or block a connection — it can only propose that something be done, and the floor above decides. Analytics that could enforce its own conclusions would be a system with no independent check on its own false positives.

It also does not close its own alerts on your behalf. Automatic dismissal of things that look routine is how the one that mattered gets closed silently at three in the morning.
Words this page introduced
Full glossary →
Detection — a rule describing a pattern worth noticing, with its reasoning and its tests published rather than hidden.
Baseline — what normal looks like for one machine or person, learned from their own history.
The graph — events joined by what caused what, so a moment can be read with its lead-up and aftermath attached.
Triage — deciding whether a true pattern matters here. A person's job, not a threshold's.
This layer's capabilities
All 88 →
Detection library
included
Behavioural baselines
per machine
The provenance graph
included
Hunting and free query
included
Detection authoring and tuning
per seat
Coverage against known technique
included
← Floor below
Everything that happened
Nothing on this floor can see what that one did not record.
Floor above →
Doing something
Where a proposal becomes an act — or is held, or refused.
The platform
All 88 capabilities Capability atlas Anatomy of an event Integrations Platform support
Commercial
Pricing Sizing your estate Trial licences
Evidence
Proof Honest limits Trust Security Changelog
Who it is for
For partners For auditors Working here
Learn
Resources Research Coverage gates Academy Glossary Essays
Tools
Check a message Stop a report