Straight answers
Frequently asked questions
Everything security leaders ask us before a demo. Still curious? Ask Jarvis in the corner, or book a call.
Does the AI act on my environment on its own? +
No. Argus proposes containment — isolating a host, mitigating a threat, resetting a session — and a human analyst approves it before anything runs. Every action is scoped, logged, and reversible. Detection and investigation are automated; response always has a person in the loop.
What does DefHunt connect to? +
Your existing stack. DefHunt ingests alarms and events from USM Anywhere and endpoint telemetry from SentinelOne today, correlates them, and layers vulnerability and asset intelligence on top — so you get more from the tools you already pay for, not a rip-and-replace.
What is Argus, exactly? +
Argus is DefHunt’s AI threat-hunter. When a meaningful alarm fires, Argus runs a two-phase investigation — gathering evidence, pivoting across hosts, users and source IPs — and returns a plain-language verdict with the blast radius and recommended next steps. It cites every claim to a specific event and never fabricates evidence.
Is my data isolated from other clients? +
Completely. DefHunt is multi-tenant by design: every client’s alarms, assets, and reports are scoped to that client, with per-account access control. It’s the same platform MSSPs use to run dozens of customers side by side without their data ever touching.
How fast can we go live? +
Most environments are ingesting, correlating, and being hunted within days of connecting a sensor — not months. You’ll see a populated operations console and your first automated verdicts on the same call we set it up.
Do you offer a fully managed SOC, or just the software? +
Both. Run DefHunt as a fully managed detection & response service, as a co-managed force-multiplier for your own analysts, or as the multi-tenant platform behind your MSSP practice. See Services.
How are reports and KPIs handled? +
DefHunt generates client-ready monthly reports automatically, with real SOC metrics (MTTA, MTTR, coverage) and a security-posture score — written in language a board understands, not raw log dumps.
See it on your own alarms
Book a working demo of DefHunt.
Bring a sensor or a sample of your alarms. In 30 minutes you’ll watch DefHunt ingest them, hunt the ones that matter, and hand back verdicts — live, on your data.