Home Feature Reference

Feature Reference

Bhairava covers the full SOC + NOC lifecycle — from raw telemetry to board-ready reports — with AI agents doing the heavy lifting at each stage. This page summarizes every major module.

Every module below is available from the unified dashboard — no separate consoles to stitch together. Alerts, incidents, hunts, forensics, compliance, and NOC all share the same tenant boundary, search, and navigation.

Alerts & Triage

L1 agents autonomously triage every alert that reaches the platform, so analysts start their day with decisions instead of a raw queue. Each alert is classified, deduplicated, enriched, correlated, scored, matched to a playbook, and — where confidence is high enough — actioned without waiting for a human.

How it works. As telemetry lands, the L1 agent runs each alert through classification, dedup, enrichment, and correlation, assigns a confidence score, then selects and executes the best-matching playbook.

Incidents & SOAR

Bhairava manages the full incident lifecycle and pairs it with a built-in SOAR engine, so investigation and response live in one place. Incidents form automatically from correlated alerts, L2 agents investigate, and playbooks automate the response.

How it works. Correlated alerts auto-form incidents; an L2 agent investigates the entities and timeline; playbooks then drive containment and remediation with human approval where it matters.

AI Agents

The agent orchestration layer is where every autonomous decision on the platform is coordinated, observed, and tuned. It gives you full visibility into what each agent is doing and why, along with the tools to manage the fleet.

How it works. An orchestrator dispatches work across L1, L2, and executor agents, records each reasoning chain, and exposes benchmarks and a prompt library so behavior can be reviewed and refined.

Threat Hunting

Hunt agents proactively look for threats that detections missed by generating hypotheses from coverage gaps and threat intel. Hunts run on a schedule and feed their findings back into detections and incidents.

How it works. A hunt planner derives hypotheses from ATT&CK coverage gaps and current intel, then hunt workers execute them across your data sources on a recurring cadence.

Detection Engineering

Manage Sigma and YARA rules as detection-as-code, with a full workflow from authoring to deployment. Rules are version-controlled, tested, and continuously measured against MITRE ATT&CK coverage.

How it works. A Sigma compiler deploys rules as OpenSearch alerting monitors, while GitOps keeps the rule set in sync with your Git repository.

Digital Forensics

Automated forensic investigation runs each case through a 15-step pipeline, turning raw evidence into a documented findings report. Analysis is real — not simulated — across network captures, memory, malware, and endpoints.

How it works. PCAP analysis uses scapy for flow extraction, DNS/HTTP/TLS parsing, C2 beacon detection, and DNS tunneling and exfiltration detection; memory forensics uses Volatility 3.

UEBA & Anomaly Detection

User & entity behavior analytics surface insider threats and account compromise by learning what normal looks like. Deviations from an entity's own history or its peer group are scored and surfaced for review.

How it works. Per-entity baselines and peer-group models are built from historical activity, then live sessions are scored against them to flag anomalies.

Compliance

Automated framework assessments keep you audit-ready without the manual evidence gathering. Bhairava maps operational activity to controls and assembles the packages an auditor expects.

How it works. A 15-step assessment pipeline maps incidents to controls and collects supporting evidence, producing scored, verifiable assessments.

Threat Intelligence

IOC enrichment and ATT&CK mapping give every alert and incident the context needed to make a call. Indicators are looked up across a broad set of intel sources and mapped to adversary techniques.

How it works. IP, hash, and domain indicators are enriched in parallel across multiple providers, then correlated to ATT&CK techniques and shared via open standards.

Dark Web Monitoring

Continuous external exposure monitoring watches the places attackers trade credentials, data, and access. Bhairava alerts you when your organization or its people show up where they shouldn't.

How it works. Monitors track infostealer logs, ransomware leak sites, and threat-actor messaging, then correlate hits back to your assets, VIPs, and identities.

NOC Console

Network and infrastructure operations live alongside security in the same platform, so availability and security share one view. Track topology, health, and SLAs without leaving Bhairava.

How it works. Live metrics are pulled from Prometheus and Zabbix and rendered on an interactive topology, with SLA and capacity views layered on top.

MSSP Multi-tenancy

Run a managed security service for many clients on a single deployment, with strict tenant isolation throughout. Each client gets its own data boundary, dashboards, and branding.

How it works. A tenant boundary scopes every query, dashboard, and integration, while a tenant switcher lets operators move between clients and bill by usage.