AlphaSOC Analytics Engine
Process your network telemetry with AlphaSOC AE to uncover infected hosts, emerging threats, and targeted attacks within your environment. The engine supports many data sources and formats, including VPC flow and DNS resolver logs within Amazon Web Services, Google Cloud Platform, and Microsoft Azure, and can be fed data from Corelight network sensors, Zeek, Suricata, or big data platforms such as Splunk, Snowflake, or Elastic.
Upon processing network telemetry and highlighting anomalies and threats, alerts can be retrieved from AlphaSOC AE in JSON format for use within your SIEM or SOAR platform, or escalated to third-party services such as Slack, PagerDuty, or email. AlphaSOC AE also supports Amazon Web Services EventBridge and Google Cloud Platform Pub/Sub for the quick escalation and routing of alerts.
The AlphaSOC system architecture, AE capabilities, and API details are described in our documentation at https://docs.alphasoc.com
To configure AE you can use the web UI that is bundled with the snap package, or adjust the configuration files on-disk. The setup instructions can be found in our documentation at https://docs.alphasoc.com/ae/on-premise-installation/