← Back to site
FR EN NL

A SOC doesn't die from a lack of alerts. It dies from their volume.

Verdex is a multi-agent SOC platform. It turns a raw alert stream into reasoned, sourced investigation reports: the agents correlate, form hypotheses, query the SIEM themselves to verify them, then return an argued verdict — while the analyst watches the reasoning unfold live.

Verdex, the security agent by BeLogic AI
4 chained agentsInvestigation, SIEM mapping, evidence hunting, verdict.
Cited evidence, or nothingNo conclusion without a log found in your own data.
100% tracedQueries sent and logs kept as evidence, all reviewable.

What Verdex does

01 · Investigate

The agent reads the case like a senior analyst: it extracts the indicators, forms hypotheses mapped to MITRE ATT&CK and writes its hunting plan.

02 · Prove

It turns each hypothesis into real queries against your logs, reads the results, widens the search when it finds nothing, and only concludes absence after actually looking.

03 · Decide

Verdict, severity, scope and confidence, then immediate actions and remediation, naming the hosts and accounts involved.

How it runs

1

Alerts arrive

From your endpoints, through your collection agents and detection rules.

2

Noise is sorted

A first pass correlates contemporaneous alerts and drops the obvious noise.

3

The investigation starts

Four agents pass the case along: hypotheses, SIEM mapping, evidence hunting, verdict.

4

Campaigns get rebuilt

A graph engine links steps scattered over weeks into a single attack chain.

5

The analyst stays in control

They follow the reasoning live in the console, reopen every query, and decide.

Who it's for

In-house SOC teams MSSPs and shared SOCs CISOs and security teams High alert volume

What stays human

Absence of evidence is not innocenceIt lowers confidence; it does not clear a case.
A failed search is not a false positiveThe case moves to a cautious verdict, never closed as benign.
A MITRE label is not proofA true positive requires hostile context, not just a rule match.
The final call stays yoursThe analyst sees the reasoning, rates it and comments on it.

Security & compliance

Cited evidence for every conclusionEvery claim points back to the log that establishes it.
Full investigation journalExecuted queries and retained logs, all reviewable.
Authentication & MFADedicated service, signed tokens, database isolated from the rest of the platform.
No database exposedA single gateway serves the console and routes to the services.
Controlled degradationSearch engine down? The case moves to a cautious verdict, never wrongly closed.

Pricing & deployment

  • Subscription, on quote — scaled to your perimeter, your endpoints and your alert volume.
  • Platform hosted by BeLogic — endpoint onboarding, collection agents and MITRE detection rules included.
  • Access to the real-time analyst console, with authentication and MFA.