Phoenix / Products / Nest
XDR · Detection & response — endpoint · network-behavior · log

Phoenix Nest

The autonomous SOC analyst that never leaves the building.

What did we miss last night? Nest is the answer — an agentic SOC analyst that runs entirely on your own hardware, reasons with a local open-weights model, and reads the alert stream so a human doesn't have to read all of it. It can request a firewall block — but by default it cannot execute one, and the code refuses whole categories of action even when a human approves them.

alert & log content sent to a hosted model0
What it actually does

Five jobs, running continuously.

Each is a job a human would do — if a human had unlimited time.

1

Triage every alert worth triaging

Polls alerts above a severity floor (default rule.level ≥ 7), collapses near-duplicates into one representative carrying an occurrence count, and triages the batch with tools to look up the host, search neighboring alerts, and check indicator reputation. The output is a recorded verdict. An alert at rule.level ≥ 12 triggers a full investigation immediately, on its own thread.

2

Read the logs no rule matched

A second lane reads the raw archive firehose — every event recorded, not just rule matches — and escalates anything that looks wrong. The by-product is the prize: an event the model flags that fired no rule is recorded as a coverage_gap — a detection-engineering backlog with rule IDs attached, instead of a blind spot nobody can see.

3

Hunt without being asked

On a timer — and out-of-band whenever something critical arrives — it runs aggregate queries across alerts and archives: beaconing, brute force, rare processes, lateral movement, data staging. The analysis nobody has time to run, that a machine runs nightly for the cost of electricity.

4

Investigate its own findings properly

A second daemon does the deep pass: extract every indicator, gather reputation on the public ones (VirusTotal, AbuseIPDB, abuse.ch, CIRCL, DShield — see below), map behavior to MITRE ATT&CK, and write an investigation. It also asks whether a finding is actually a false positive — and where well-evidenced, offers a scoped one-click suppression rule.

5

Tell a human — and be checkable about it

Everything that reaches a person goes through a single exit that records the decision whether or not it sends, and attaches the raw log lines the claims rest on beneath the prose. A human reading a confident paragraph with the evidence under it can spot a wrong conclusion in seconds.

Why it's safe to point at a firewall

A fallible local model still can't cause an outage.

Authority lives in code, not the model

The model can name an action from a fixed list; it can't invent one. The confidence value that gates anything is a code-owned constant chosen by whichever evidence source fired — never the model's estimate of itself.

The approver is an input, not an override

For the narrow class of actions that can take a network down, a code-owned refusal outranks a human "Allow." An approved block once targeted the SIEM's own address and took the box off its network — that class of action is now refused under any approval.

Fail-open on notify, fail-closed on response

An unverifiable report is delivered stamped unverified, never silently dropped. An unverifiable action is not taken. What deserves a human always gets one; what could cause harm waits.

Nothing is armed before it's measured

Every gate ships on an observe → shadow → enforce ladder — recording the decision it would have made against live traffic before it can suppress or act.

Threat-intelligence sources

It cross-checks indicators against curated feeds — on your terms.

Investigation and hunting rate every public indicator against the threat-intel feeds your SOC already trusts — free community sources and the commercial subscriptions most teams already license — then cache the answer and attach what they found to the report. You choose the mix; a residency chokepoint guarantees only public indicators are ever sent, and internal ones never leave the building.

ON-PREMISE · ALWAYS ALLOWED

MISP

Your own MISP instance is queried locally for every indicator — no egress, ever — returning matching attributes and event context.

COMMERCIAL FEED

VirusTotal

IP, domain, hash and URL reputation — the multi-engine last-analysis verdict.

COMMERCIAL FEED

AbuseIPDB

IP abuse-confidence score and report volume across the trailing 90 days.

COMMUNITY FEED

abuse.ch — ThreatFox

Names the malware family and threat type behind a specific IOC, with a confidence level.

COMMUNITY FEED

abuse.ch — MalwareBazaar

File-hash intelligence: file type, signature and delivery method for known samples.

COMMUNITY

CIRCL hashlookup

Known-malicious / known-good flags for file hashes — a decisive, indicator-specific signal.

COMMUNITY

SANS ISC DShield

Community IP reputation from the Internet Storm Center sensor network.

RESIDENCY GATE

Internal indicators never leave

A chokepoint classifies every indicator before any URL is built and fail-closed refuses to egress an internal one — so "enrich" can never become a data-egress path, whatever the model asks.

Widely used reputation feeds — wired into the subscriptions your SOC may already run, alongside community feeds. Public indicators only, one auditable path out, and your policy in control.
How it fits

Between the SIEM and the analyst — replacing neither.

   Endpoint + network agents ──► SIEM manager ──► alerts + archives ──► OpenSearch
                                                        │
                                                        ▼
                                                 [ Phoenix Nest ]
                                                        │
                      ┌─────────────────────────────────┼─────────────────────────────────┐
                      ▼                                  ▼                                  ▼
                Slack / chat                        audit trail                     active response
               (your analyst)                   (queryable record)             (gated · opt-in · dry-run)
How you'd know it's working

You shouldn't have to take "it's working" on trust.

Any product that can't tell you how to check it's working is asking for exactly that. Nest reports these signals about itself:

QuestionSignal it emits
Is it running at all?cycle_health_state — healthy / degraded / escalated / stalled
Is it keeping up?Ingest lag in bytes; a sustained backlog notifies once, not per cycle
Is it doing work?Triage verdicts/day measured against cycle errors/day — the ratio is the diagnosis
Is our detection improving?coverage_gap trend, with the missing rule IDs
Is it declining things it shouldn't?triage_declined, with rule levels present ("declined a level 12" is searchable)
Did the deploy land?A content fingerprint per box, compared between boxes — drift caught by disagreement
What is armed today

Capability lands dark, gets measured, then is armed per box.

CapabilityStatus
Alert triageIn production — multiple deployments
Firehose scanning + coverage-gap detectionIn production — per-box opt-in
Scheduled + critical-triggered huntingIn production
Deep investigation · MITRE · IOC reputationIn production
Notification gatingLive in observe — records, doesn't suppress
Hunt-report severity + grounding gatesLive in shadow — annotates, doesn't withhold
Active responseDry-run by default
External threat intel (VT · AbuseIPDB · abuse.ch · CIRCL · DShield)In production — connect the feeds your team licenses
What Nest is not

The non-goals are the more informative half.

  • Not autonomous response. The default is dry-run. Real execution needs a deliberate config change, and even then matches an explicit allowlist of command and target, or waits for a human.
  • Not a replacement for detection engineering. It surfaces gaps; humans write rules. Quietly compensating for a missing rule would let the ruleset rot while looking healthy.
  • Not a replacement for the analyst. It's the analyst's first pass — context assembled, a view stated, evidence shown, a question asked.
  • Not a frontier-model product waiting for a bigger model. It assumes a small, fallible local model permanently, and bounds the damage from its errors by construction.
  • Not a SIEM, a log store, or a compliance tool. It reads them; it does not replace them.
Across ~18 months of operation, model hallucination cost roughly one afternoon. A three-day window in which deployments were blind while every health indicator read green cost considerably more. That is why "prove it is working" is a feature here, not an afterthought.

See what your detection missed last night.