TECHNOLOGY
AI Engine
Battle Tested, Purpose-built, AI
Go beyond alerts – detect and respond to Incidents. Industry leading Machine Learning (ML) algorithms detect threats in the enterprise. Stellar Cyber’s AI engine is like a team of world class security experts working around the clock at massive scale to make your team faster and more effective.
AI That Delivers Results
The output of Stellar Cyber’s AI Engine can be simplified down to generating two types of data
for security teams: alertsand incidents. Together,alerts and incidents provide the depth and holistic
view teams need to make rapid decisions
Novel Alerts
Alerts are instances of specific suspicious or high risk behavior and are the building blocks of Incidents. Stellar Cyber ships with 200+ Alert Types out of the box; no configuration required. Alert Types are mapped to the XDR Kill Chain, to enable prioritization and correlation. Individual Alerts have a generated, human readable description of what happened, and recommended remediation for fast response.
Example alert types include:
- External Scanner Behavior Anomaly
- Internal RDP Brute Force Attack
- Internal SMB Username Enumeration
Automatically Correlated Incidents
Incidents are correlated sets of Alerts and other supporting data including signals, assets, users and processes. Incidents represent an entire attack or sequence of high risk actions. In real time, as new Alerts are generated, Alerts are assigned to relevant Incidents so that attacks can be detected and responded to before completion. Incidents in Stellar Cyber are mutable, meaning they can get updated, and are not limited to any certain time window so they can pick up complex attacks.
Real-world incidents detected in Stellar Cyber:
- Darkside Ransomware attack
- Sunburst attack