Black Hat USA 2026Startup City, Booth 5815 · Aug 4–6 · Mandalay Bay, Las VegasBook a booth demo

Attack Detection

Individual alerts do not tell the story. Attack chains do.

See the attack while it’s still unfolding.

Correlated incidents are assembled into one attack case — so you respond to the operation, not the symptoms.

Step 1 · Collect

Incidents arrive — and start connecting.

Every investigated incident brings the entities it touched: accounts, hosts, keys, IPs. When two incidents share one, that’s rarely a coincidence — and the engine notices.

WIN-FIN-07jdoesvc-backupINC-38INC-39INC-41INC-42

Incidents linked to the user, host, and service account they share

Step 2 · Correlate

Related incidents become one case.

Shared entities, tight timing, matching behavior — every incident that belongs to the same attack resolves into a single case. The whole operation, in one place.

Step 3 · Sequence

Every incident lands on the attack chain.

Ordered by when it happened, placed by how deep it reached. One glance tells you how far the attacker has gotten — and what’s likely next.

ExfiltrationCommand & ControlDiscoveryExecutiontime →

Incidents plotted over time climb the attack chain from execution toward exfiltration

Step 4 · Escalate

One prioritized case, handed off.

The whole operation — incidents, entities, stages — becomes a single prioritized case for Response & Containment.

nine investigated incidentsINC-38INC-39INC-41INC-42INC-45INC-40INC-44INC-46INC-48CORRELATION ENGINEentities · timing · behaviourATK-7one prioritized caseResponse & Containmenttasks proposed, humans approveS1 · 6 entities · Apr 13 → 16

Nine related incidents converge into one prioritized attack case, handed to Response and Containment

Nine related incidents converge into one prioritized attack case, handed to Response and Containment

Inside the attack topology.

The case is live — watch it grow, replay it, trace the route.

Attack map

New incidents join the moment they connect.

An incident that shares an entity with the case joins it as soon as it’s verdicted — the map grows while the attack does.

Timeline

Replay the attack from day one.

Scrub back to the first move and watch the operation unfold in order — no reconstructing from memory.

Attack path

The route, reconstructed.

Which account, to which host, to which door out — the attacker’s movement across your environment, drawn as a path.

See a real attack reconstructed.

Related incidents correlated into one attack case

The full attack chain, mapped end to end

One case to respond to — not nine alerts