CEDX SIEM · IT & Security

2.4 million events.
320 alerts you can work.

CEDX SIEM turns the event stream into a queue an analyst can finish: every alert triaged by an agent with a verdict — benign, true positive, needs human — and every verdict one click from being overturned.

The Overview counts the overturns. This week: zero accepted, zero overturned, 13 minutes median saved per alert. When a human corrects the agent, the number moves — that is the audit trail.

siem.cedxsystems.com — live build
CEDX SIEM overview: events in 24 hours, open alerts, critical open, median triage time, true-positive rate and fatigue score.

Runs on demo data — Northline Production is the software's sample tenant, not a customer.

2.4M events in 24 hoursdistilled to 320 fired detections
18m median time to triageagainst 119 alerts in the active queue
41% true-positive rateon closed alerts — printed, not implied

What it is

A SOC queue that argues back.

The raw stream, when you need it

Under the alerts sits the event stream: 320 events in the sample with action, actor, target and outcome — admin.role.grant, lateral.rdp, file.exfil, auth.mfa.challenge. 211 non-success, 95 policy-blocked denies, 27 critical severity.

  • Action, actor, target, outcome on every row
  • Success, failure and deny as filter chips
  • Service accounts and break-glass actors named
siem — screen-2
The raw stream, when you need it

A verdict on every alert

320 alerts fired; the agent triaged all 320. Verdicts are explicit: benign 86%, true positive 93%, needs human 60–71% — and the ones marked needs-human are the queue a person actually works. Fatigue score rides alongside, so noisy rules surface as noise.

  • Accepted and overturned counters on the cards
  • Fatigue score per alert, P95 at 52
  • Fires count next to every alert name
siem — screen-3
A verdict on every alert

A rule library that grades itself

48 detection rules, 40 enabled, 8 flagged as high false-positive tune candidates. Standing-privilege-unused fired 90 times in 7 days at 85% false positive — the library tells you to tune it, in its own table.

  • IOC, sequence, threshold, anomaly and ML rule types
  • Fires and false-positive % per rule
  • 1,507 fires in 7 days across the library
siem — screen-4
A rule library that grades itself

Product tour

Four screens, captured from the running build.

Not a mockup and not a concept deck. This is what opens at /app/siem.

siem.cedxsystems.com
CEDX SIEM Overview screen.CEDX SIEM Events screen.CEDX SIEM Alerts screen.CEDX SIEM Detections screen.

01 — Overview

The SOC's morning, on one screen

119 open alerts, 24 critical, 28 unowned, fatigue P95 at 52. The root-caused alerts read like a handover: a SEV-1 credential storm — brute force plus MFA fatigue plus lateral RDP in the same window — and a 4.2 GB off-hours bulk export sitting unowned.

  • SOC posture ring 78, with the inputs listed
  • Highest-risk open alerts with entity and score
  • Severity mix: 8 critical, 22 high, 41 medium, 29 low

02 — Events

Down to the raw record

Search actor, action, target or IP and read the stream itself: break-glass-ops failing a lateral RDP, svc-billing denied on a DNS query, a phish report arriving as its own event type. The queue above is only ever a summarisation of this.

  • Timestamps to the second, 08-04 23:31 at the top
  • Deny outcomes separate from failures
  • CSV export of the filtered stream

03 — Alerts

The queue a person actually works

Impossible travel on samir.patel is critical and contained, risk 99, needs-human 60%. The BEC signal on the same principal has fired 79 times with a fatigue score of 71 — the table shows both numbers so the tuning conversation starts from evidence.

  • Open, triaging, contained, closed, suppressed tabs
  • Verdict confidence on every row
  • 13m median time saved per alert, first pass

04 — Detections

Tune the library, not the analyst

The rule table sorts by fires: vpn-new-device-22 at 110 fires and 51% false positive, geo-impossible-travel-10 at 103 fires and 14%. The 8 rules over 50% false positive are marked tune candidates — the library owns its noise.

  • On/off state per rule, 40 of 48 enabled
  • Severity and tactic per rule
  • High-FP chip isolates the tune candidates

Who runs it

Three roles keep the signal honest.

Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.

SOC analyst

Works the needs-human queue by risk and fatigue, overturns the agent when it is wrong, and owns the 28 unowned criticals.

unowned open · 28

Detection engineer

Lives in the rule library: tunes the 8 high-FP candidates, watches fires against false-positive rate, and retires rules that only produce fatigue.

tune candidates · 8

Incident responder

Takes the contained criticals — impossible travel, credential storm — and runs them to closure with the event stream as the evidence.

SEV-1 · credential storm

The shape of it

What the demo SOC actually looks like.

Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.

2.4Mevents in 24 hours320 detections fired from the stream
119open alerts24 critical · 28 unowned
18mmedian time to triage7-day median, on the Overview card
52fatigue P95the noise the queue still carries
Highest-fired rules, 7 daysfires · false-positive %, from the rule library
  • vpn new device 22 — 51% false positive110 fires
  • geo impossible travel 10 — 14% false positive103 fires
  • cloud iam key create 26 — critical, IOC type92 fires
  • Standing privilege unused — 85% false positive, tune candidate90 fires
  • auth mfa fatigue 6 — 4% false positive89 fires
Alerts by state119 open or triaging of 320 fired
  • Open / triaging · 119 in the active queue
  • Closed, contained or suppressed · the rest of 320
SOC posture78 on the Overview ring, inputs listed beside it
78
  • Posture 78 · open 119, critical 24, incidents 17
  • Unowned 28 · high fatigue 52 — the drag on the score

How it runs

An alert's life, in the order it actually happens.

01

Collect

The stream lands as events — 2.4M in 24 hours — with actor, action, target and outcome preserved, so nothing downstream has to guess.

02

Fire

48 rules score the stream into 320 detections; each rule carries its own false-positive rate, so noise has an owner.

03

Triage

The agent puts a verdict and a confidence on every alert — benign, true positive, needs human — and the median triage lands at 18 minutes.

04

Overturn

A person corrects the agent and the counters move: accepted, overturned, time saved. The queue remembers who was right.

One record

The signal is only as good
as what feeds it.

An alert about a device, a login or a flow means more when the device, the identity and the path are the same records the rest of the estate keeps.

All 132 applications

Limits

What SIEM does not do yet.

Finding this out on the third call is worse for you than reading it here, and worse for us.

Start

Open it before you talk to anyone.

Try

Open it right now

  • The live build
  • Demo data
  • No card, no call
Open live SIEM

Pilot

Your streams, your rules

  • Everything in Try
  • Source onboarding plan
  • Rule-tuning workshop
  • Estate map
Talk to sales

Estate

SIEM with the rest of it

  • SIEM with Endpoint, Network, Access and ITSM
  • One identity, one bill
  • CEDX delivery
Book an estate map

Questions

Before you pilot SIEM.

Is the software on this page real?

Yes. Every screenshot is a capture of the running build and you can open the same build at /app/siem. It runs on demo data — Northline Production is the sample tenant.

What does the agent verdict mean?

Every alert gets a triage verdict with a confidence — benign 86%, true positive 93%, needs human 60–71%. The needs-human verdicts form the queue a person works; the accepted and overturned counters on the Overview record how often a human agrees.

How do you keep alert fatigue down?

Fatigue is a score on the alert row, and the rule library prints fires against false-positive rate — the 8 rules over 50% are flagged as tune candidates. The standing-admin rule that fired 90 times in 7 days is exactly what that screen exists to catch.

Can I get from an alert to the raw events?

Yes — the Events screen is the stream underneath: searchable by actor, action, target and IP, with timestamps to the second and success, failure and deny as separate outcomes.

Is SIEM audited or certified?

No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and retention is written up on the security page.

The queue is triaged. Go and look at it.

Live build, demo data, no card. Then ask what your own fatigue P95 would be.