Automated DFIR | Human-led
Investigate the graph.
Not the alert pile.
Automation loses the plot when it sees alerts in isolation. Pentra Graph connects identities, assets, evidence, prior cases, and analyst decisions into one investigation, so every closed case holds up under audit and a person stays in charge of every write-back.
The problem
Alert-centric tools meet attacker reality.
Modern adversaries move across identities, devices, mailboxes, cloud control planes, and tickets. A queue of disconnected alerts, even with automation on top, still leaves analysts stitching context by hand, and every hour of stitching is dwell time, burnout, and a harder story to defend at the next audit.
Pentra Graph
An investigation graph engine for SOC and DFIR.
Bring detections and telemetry into a time-aware graph. Let automated investigations follow that graph under policy. Keep analysts responsible for verdicts, evidence, and updates to the system of record.
Read your tools
Connect to the security stack you already run. Credentials stay in your environment.
Bind the story
Actors, accounts, devices, processes, files, network, alerts, cases, evidence, and decisions, linked in time.
Guided investigation
The system proposes next questions and evidence to review. Humans stay responsible for judgment and updates.
Structured outcomes
Investigations produce durable reports that hold up in front of the board. Updates to your system of record are reviewed, explicit, and auditable.
What it is
- Graph-nativeInvestigate entities and relationships, not a chat window attached to a ticket.
- IntegratorWorks with the SIEM, EDR, identity, and case tools you already own.
- Operator-firstBuilt for analysts and DFIR leads who need evidence trails and clear decisions your auditors can follow.
What it is not
- Not a SIEMWe do not ask you to rip out the platform that holds your logs.
- Not a SOAR canvasNo flowchart. A clear investigation structure is easier to review after the fact than a brittle playbook.
- Not a model companyWe provide controls around automation, including a clear stop when evidence is weak, so automation never outruns what you can defend.
Control layer
Knowing when to stop is part of the answer.
Pentra Graph is built to stop when the evidence is weak. It records uncertainty, tests benign explanations, and shows how each decision was reached, so every closed case leaves an audit trail your compliance team can stand behind.
A system that cannot stop is not ready to close an investigation.
Who we are
Practitioners who still do the work.
Pentra Graph comes from people with experience in assurance and governance, offensive security and purple-team work, digital forensics and incident response, and detection and response across enterprise, cloud, and industrial environments.
Governance that ships
Program design, control selection, and executive-ready risk language, grounded in long-term advisory work.
Attacker-literate defense
Manual testing and collaborative purple-team engagements make adversary paths visible, then turn those findings into better investigation practice.
Response under pressure
Forensics, hunting, containment, and operator workflows from teams that have handled incidents and detection programs in enterprise and industrial environments, including specialized OT and ICS contexts.
We are building Pentra Graph for teams that are accountable for outcomes, from the SOC floor to the boardroom, and need automation that can stop when the evidence is weak.
Contact
Bring a real investigation. We will bring the graph.
Tell us about your SOC or DFIR practice, the tools you already run, and the outcomes you need to show upward. We will keep the conversation practical.
Send a note
We read every message.
Your message goes straight to our team inbox, and we reply by email. We do not keep a copy on this site.