Welcome to the SOC Prime Platform!
It's a cybersecurity platform designed to support detection engineering and threat search across security environments. It brings together detection content, threat intelligence, automation tools, and AI-powered capabilities to help security teams identify, validate, and respond to threats more efficiently.
This guide helps you get started with the Platform making the most of its capabilities.
We also encourage you to use additional educational resources on the Platform: tooltips, embedded videos, and short explanations across different pages.
If you have any questions, you can contact us via the chat by clicking the green bubble in the lower right corner on any screen or start a discussion in our Discord community.
Start exploring the Platform by selecting the product that best suits your needs:
Threat Detection Marketplace – A comprehensive library where you can explore the detection content enriched with threat intelligence and metadata, helping you understand the context of the threat and map it to the MITRE ATT&CK framework, discover Active Threats with real-time threat intelligence and quick access to relevant detections, use platform-specific translations of detections, and customize content for your security environment.
Uncoder AI – A detection engineering tool that provides capabilities for translating and optimizing detection logic, and also includes an AI-powered chat interface with predefined AI tasks for generating responses based on user prompts.
Attack Detective – A solution for validating threat coverage, identifying active threats, and running an automated investigation in your security environment using all relevant detection rules from the world's largest collection.
The Platform also provides the following capabilities to support detection operations and platform management:
Account Settings – View your account details and configure preferences that influence your Platform experience, such as your role, account security, and your organization’s industry.
Platform Settings – Configure integrations, data planes, and other shared settings to adapt the Platform to your organization’s environment and requirements.
Automation – Enable automated management and deployment of detection content to keep detection rules up to date, apply changes, and deploy them across your environment.
Analytics – Access dashboards and leaderboards to analyze platform usage, monitor trends, and evaluate detection coverage.
