Point Alba at the alerts assigned to your team and it works them inside the stack you already run — pulling context, chasing every entity lead across the SIEM, weighing the evidence, and reaching a confidence-scored verdict. It then proposes a response, or carries one out within the limits each customer sets. And it doesn’t wait for alerts — Alba proactively hunts your environment with hypothesis-driven threat hunts, exposure and posture mapping, and dark-web monitoring, surfacing the threats that never tripped a rule.
Each customer decides how far Alba goes on its own — surface a recommendation, wait for sign-off, or act automatically — set per class of action. And nothing happens off the record: queries, enrichment, hunts, classifications, and responses all land in the audit trail.
The category was built for enterprise SOCs with full-stack commitments. MSPs and MSSPs operating across mixed customer stacks have different constraints — and most platforms work against them.
Most AI analysts are tightly coupled to a specific EDR, SIEM, or productivity-suite license. If your customers run mixed stacks, you're operating multiple platforms — or asking customers to migrate.
Per-investigation, per-SCU, or platform-bundled pricing scales with alert volume — the opposite of what an MSP needs as customer count grows. Your margin shouldn't move when alert volume does.
Many AI SOC products stop at real or not real. They don't pivot across the SIEM, follow entity trails, or close the response loop — that work still falls to your analysts.
Where MSP support exists, it's often a services wrapper around a single-tenant product. Onboarding tenant 47 becomes a project, not a config change.
A rule has to catch something before anyone looks at it. The valid credential bought on a leak market, the internet-facing asset with a known-exploited CVE, the actor staging quietly — none of it is in the queue. Hunting is supposed to close that gap, and it's the first thing dropped when the queue is full.
Investigation, hunting, response, governance, and intelligence — eight surfaces of the Alba SOC Control Plane.
Alba doesn't wait for you to ask questions. It triages the queue, investigates alerts end-to-end, posts its analysis, and learns from the outcome. And it doesn't only work what fired — it hunts hypotheses, maps exposure, and watches the dark web for the threats that never raised an alert.
Processes your entire alert queue automatically. Fetches context, extracts IOCs, enriches via your threat intelligence platform, runs SIEM queries, and classifies with confidence scores.
Doesn't stop at the first query. Discovers entities in SIEM results, follows trails across hosts, users, and IPs. Iterates until every lead is exhausted.
Every IOC enriched through your threat intelligence platform — OSINT, commercial, and proprietary feeds. MITRE ATT&CK mapping. Dark web monitoring. Per-IOC depth scoring.
Microsoft Defender integrated today; major EDRs adapter-ready. Pull endpoint telemetry, device timelines, and identity-context signals into the investigation flow.
Phishing isn't a separate product — the chat agent, EDR, and TI tools handle suspect emails in the same investigation flow as everything else. Headers, URLs, attachments, sender reputation.
Alba doesn't wait for an alert to go hunting. Hypotheses are seeded from cross-customer intel, new vulnerabilities, and dark-web signals — then tested as real queries against live SIEM and EDR telemetry. Hunt tiers run on their own cadence: weekly, daily, hourly. Hunt in plain English, or let Alba run the board.
Every hunt follows one contract — gather, ledger, advocate, verdict. Evidence is recorded with direction (supports, refutes, neutral) and strength, and each hunt carries an explicit kill criterion written before it runs. A mandatory devil's-advocate pass argues the best innocent explanation, and a hypothesis that can't survive it never escalates. The model weighs evidence; deterministic code does the arithmetic and the state transitions.
Attack surface and vulnerable assets ranked by real-world exploitability — EPSS scoring and known-exploited status, not raw severity. Posture checks across identity, email, and endpoint configuration land as remediation guidance in a tracked queue.
Leaked credentials, brand and executive exposure, and threat-actor chatter — monitored continuously and entity-graphed, feeding hunt hypotheses and alert enrichment rather than sitting in a separate portal.
The executive roll-up: dark-web intelligence fused with the customer's own SIEM alert data and investigation history. Risk level, threat actors and campaigns, MITRE ATT&CK coverage, IOCs, alert correlation, a 30–90 day outlook, and P1/P2/P3 prioritized actions. Where a dark-web IOC also turns up in that customer's own alerts, the overlap is called out as active targeting.
Every investigation produces a tailored response plan. Alba executes it through five safety gates (classification, confidence, age, allow/deny, risk ceiling) against an 18-action catalog spanning EDR, case management, and threat intelligence — or hands the plan to the analyst with one-click approval.
Customer-tunable rules for the repeat patterns. JSON conditions, configurable actions (close, tag, comment, assign, escalate), full audit trail. Run unattended on the high-confidence long tail.
Debug mode exposes every query Alba runs against your SIEM. Full audit trails. Structured logging with timing and cost metrics. You see exactly what Alba did and why.
Alba remembers every investigation. False positive rates per detection rule. IOC prevalence across customers. Historical context that makes every new analysis smarter.
Confirmed true-positive IOCs are pushed back into the AlbaCyber Threat Exchange with TLP marking, scoring, and provenance labels. Every confirmed TP your tenants see makes every other tenant smarter.
Automatically audits every detection rule across your SIEM. Finds broken syntax, silent encoding failures, case sensitivity issues. Auto-generates corrected rules and validates them end-to-end.
Search thousands of past investigations by meaning, not just keywords. "Have we seen this attack pattern before?" Answers in milliseconds, with cross-customer anonymization.
Natural language interface via web UI or Slack with RBAC-gated tools. Real-time streaming. Ask "search for lateral movement in the last 24h" and watch Alba work.
Alba runs a 17-step investigation pipeline for every alert. Here's the path from raw alert to classified, contextualised outcome — followed by the loop Alba runs when nothing fired at all.
Fetch alert from your case management platform. Parse alert context, source content, and detection query. Extract IOCs from text with junk filtering. Deduplicate.
Every IOC is enriched through your threat intelligence platform. Cross-referenced against investigation history for prevalence. Detection rule exceptions are pre-analyzed for syntax bugs.
Run alert-type-specific SIEM queries against your existing platform. Extract new entities from results. Follow the trail: discovered hosts, users, IPs feed follow-up queries. Repeat until exhausted or depth limit.
Full context sent to your chosen LLM for analysis. Executive summary, evidence chain, MITRE mapping, confidence score. If prior analysis exists, Alba states agreement or disagreement.
For confirmed threats: isolate hosts via your EDR, block IPs at the firewall, disable compromised accounts in your identity provider, create incidents in your ITSM. Each action is configurable: autonomous, approval-gated, or recommend-only.
Post analysis to case management. Tag and close the alert. Store the outcome for future context. Index the investigation for semantic recall. Notify your team. The next investigation is already smarter.
Threat Discovery runs on its own cadence — hunt tiers scheduled weekly, daily, or hourly — and every hunt follows the same four-phase contract. Running in production today.
Seeded from cross-customer intelligence, newly published vulnerabilities, dark-web signals, and the customer's own alert history. Each hunt is written down as a testable statement with an explicit kill criterion — the finding that would end it — agreed before any query runs.
Real queries against live SIEM and EDR telemetry — not a summary of what the alert already said. Every result is entered in an evidence ledger with its direction (supports, refutes, neutral) and its strength. The model assesses the evidence; deterministic code does the arithmetic and the state transitions.
A mandatory devil's-advocate pass builds the best innocent explanation for everything gathered — the admin script, the misconfigured backup job, the travelling user. A hypothesis that can't survive its own counter-argument doesn't escalate; it closes, with the reasoning recorded.
What survives becomes a confidence-scored verdict with its evidence attached, handed into the same investigation and response path an alert takes — including policy-gated response. Findings roll up, alongside exposure and dark-web intelligence, into the customer's Threat Landscape Report.
Six dimensions matter when an MSP or enterprise SOC is choosing what to put in front of a customer. Most platforms in this category were architected for a different buyer — here's how the archetypes fall out.
AI assistants tightly coupled to a specific EDR or productivity-suite license. The copilot is a feature of the bigger platform purchase.
Independent triage and investigation tools. Typically priced for the enterprise SOC; multi-tenancy is a services wrapper.
Service-led offerings that compete for the customer relationship rather than through it.
| Evaluation dimension | Platform-bundled copilots |
Standalone AI SOC analysts |
MDR with AI overlay |
Alba |
|---|---|---|---|---|
| Stack independence Works with any SIEM, any LLM, no platform lock-in |
○ | ◐ | ○ | ● |
| Depth of investigation Multi-pass SIEM investigation, entity-trail following, full audit chain |
◐ | ◐ | ◐ | ● |
| Response controls Policy-gated execution, configurable autonomy |
◐ | ○ | ● | ● |
| Multi-tenancy Multi-tenant by architecture, not by services overlay |
○ | ◐ | ○ | ● |
| Proactive coverage Hunting, exposure mapping and dark-web signal feeding the same investigation and response loop |
◐ | ◐ | ◐ | ● |
| Pricing structure Predictable, scales with endpoints not alert volume |
○ | ○ | ◐ | ● |
Alba was built from day one as a multi-tenant SOC platform. Customer isolation isn't bolted on — it's the architecture.
Every query runs inside the requesting customer's boundary — scoped by tenant mapping, gated by role-based access control, and written to the audit log. Each SIEM query is validated against that customer's index patterns before it runs.
Investigation memory tracks IOC prevalence across all customers. Analysts see "IOC seen across 3 customers" — never names or details.
Every customer on a different SIEM? No problem. One Alba instance handles all of them through unified query abstraction. No rip-and-replace required.
Analysts only see customers they're assigned to. Admins see everything. Tool permissions are enforced at execution time, not the UI.
Configure which customers get automated analysis. Alba processes the queue, restores the previous alert owner, and tags completion. Zero manual intervention.
Hunt tiers run per customer on their own cadence, scoped to that tenant's telemetry. The Threat Landscape Report — dark-web exposure, actors and campaigns, ATT&CK coverage, and correlation against that customer's own alerts — becomes a deliverable you can put in front of them without writing it.
Alba runs on the stack you already own. Every layer connects through plugin-based adapters, so your SIEM, EDR, ticketing and threat-intel tools stay exactly where they are — and swap freely if they ever change.
A small monthly fee per protected endpoint, plus a simple markup on the LLM usage Alba's investigation engine drives. Because Alba clears the queue your analysts can't, most teams spend less per resolved alert than they do today — even after the markup.
Deploy Alba on your own hardware. Run local LLMs for complete data sovereignty. Nothing leaves your network.
Fully managed Alba deployment. We handle infrastructure, updates, and scaling. You handle investigations.
Custom deployment, dedicated support, and joint development of industry-specific capabilities.
A two-week proof of value run against your own environment — one SIEM, three detection rules, and a scorecard you agree to before it starts. Prefer to see it run first? Take the demo.