The Problem This Solution Solves
While SIEM and SOAR modernization will be a giant leap forward in streamlining and automating a multitude of operator tasks, a large gap still exists in how fast operators can respond to new threats and relate them to ongoing event alerts.
The DoD seeks an innovative commercial solution that can harness the power of AI/ML to
drastically reduce the time it takes for cyber operators to address malicious activity on the
DODIN by acting as a “virtual tier one operator.” The solution should be aimed at automating
some of the triage, analytical, and investigative work that make up the bulk of an analyst’s
workload.
The Solution
Analyst1 is an intelligence driven, threat detection, response, and automation platform. Utilizing AI/ML, Analyst1 correlates indicators of compromise, detects malicious network behavior, and recommends counter measures to deploy to sensors. With a flexible, Restful API, Analyst1 seamlessly integrates with SIEM, SOAR, ITSM, sensors, and any security tool in the architecture. Analyst1 consumes hundreds of open source, paid premium, and/or classified threat intelligence reporting sources, correlates and curates the data, and relates it to activity on the network.