Automated DFIR | Human-led

Investigate the graph.
Not the alert pile.

Automation loses the plot when it sees alerts in isolation. Pentra Graph connects identities, assets, evidence, prior cases, and analyst decisions into one investigation, so every closed case holds up under audit and a person stays in charge of every write-back.

Watch: Pentra Graph in one minute 1:09

The problem

Alert-centric tools meet attacker reality.

Modern adversaries move across identities, devices, mailboxes, cloud control planes, and tickets. A queue of disconnected alerts, even with automation on top, still leaves analysts stitching context by hand, and every hour of stitching is dwell time, burnout, and a harder story to defend at the next audit.

Pentra Graph

An investigation graph engine for SOC and DFIR.

Bring detections and telemetry into a time-aware graph. Let automated investigations follow that graph under policy. Keep analysts responsible for verdicts, evidence, and updates to the system of record.

01 | Collect

Read your tools

Connect to the security stack you already run. Credentials stay in your environment.

02 | Graph

Bind the story

Actors, accounts, devices, processes, files, network, alerts, cases, evidence, and decisions, linked in time.

03 | Investigate

Guided investigation

The system proposes next questions and evidence to review. Humans stay responsible for judgment and updates.

04 | Close

Structured outcomes

Investigations produce durable reports that hold up in front of the board. Updates to your system of record are reviewed, explicit, and auditable.

What it is

  • Graph-nativeInvestigate entities and relationships, not a chat window attached to a ticket.
  • IntegratorWorks with the SIEM, EDR, identity, and case tools you already own. See the connectors.
  • Operator-firstBuilt for analysts and DFIR leads who need evidence trails and clear decisions your auditors can follow.

What it is not

  • Not a SIEMWe do not ask you to rip out the platform that holds your logs.
  • Not a SOAR canvasNo flowchart. A clear investigation structure is easier to review after the fact than a brittle playbook.
  • Not a model companyWe provide controls around automation, including a clear stop when evidence is weak, so automation never outruns what you can defend.

Pentra Graph connectors

The tools Pentra Graph connects to.

  • Rapid7 InsightIDR
  • SentinelOne
  • Microsoft Defender
  • Google Workspace
  • AWS
  • Cloudflare
  • GitHub
  • CrowdStrike

Control layer

Knowing when to stop is part of the answer.

Pentra Graph is built to stop when the evidence is weak. It records uncertainty, tests benign explanations, and shows how each decision was reached, so every closed case leaves an audit trail your compliance team can stand behind.

A system that cannot stop is not ready to close an investigation.

Who we are

Practitioners who still do the work.

Pentra Graph comes from people with experience in assurance and governance, offensive security, purple-teaming, and DFIR across enterprise, cloud, and industrial environments.

Assurance

Governance that ships

Program design, control selection, and executive-ready risk language, grounded in long-term advisory work.

Offense & purple

Attacker-literate defense

Manual testing and collaborative purple-team engagements make adversary paths visible, then turn those findings into better investigation practice.

DFIR & MDR craft

Response under pressure

Forensics, hunting, containment, and operator workflows from teams that have handled incidents and detection programs in enterprise and industrial environments, including specialized OT and ICS contexts.

We are building Pentra Graph for teams that are accountable for outcomes, from the SOC floor to the boardroom, and need automation that can stop when the evidence is weak.

Read our story

Getting started

Connect what you already have.

Getting started means connecting your sign-in, your security tools and the AI assistants your team uses. Nothing to replace, and nothing to install in your security tools.

  • 01 | Set upWe set up an Omni that belongs to you alone.
  • 02 | Sign inYour team signs in the way they already do, and your groups decide who can do what.
  • 03 | ConnectYour administrator connects each security tool once, and Omni keeps the access safe.
  • 04 | ConfigureOne command on each analyst's computer connects their AI assistants.

See how it works

Questions

What people ask us first.

Is Pentra Graph a SIEM or a SOAR?

Neither. It reads from the SIEM, EDR, identity and case tools you already run, links what it finds into one investigation, and leaves your logs where they are.

Does it change anything in my tools?

Investigations only read. Any change to your case records is suggested first and waits for a person, and containment, such as isolating a device, always needs a second person's approval.

Where do my credentials live?

In your own Omni, encrypted. Pentra Graph and your AI assistants reach your tools through Omni and never see a password or key.

What does the automation decide on its own?

It gathers evidence, tests benign explanations and proposes a verdict. When the evidence does not clear the bar, it stops and hands the case to an analyst instead of guessing.

Can we see AI use outside the security team?

Yes. Omni shows which AI apps are installed across your company and where their requests go, lets you allow or block AI services, and alerts your team when someone tries one you have not approved.

Is my data used to train models?

No. Pentra only uses AI models you approve, from providers that do not keep your data, and your data is never used to train models for anyone else.

Contact

Bring a real investigation. We will bring the graph.

Tell us about your SOC or DFIR practice, the tools you already run, and the outcomes you need to show upward. We will keep the conversation practical.

Email Pentra Graph

Send a note

We read every message.

Your message goes straight to our team inbox, and we reply by email. We do not keep a copy on this site.

Or write directly to hello@pentrasecurity.com