Shape is SignalStructured Intelligence
SIETStructural SIEMPatent pending
Available for evaluation

Your SIEM watches events.
SIET watches the system.

Detect attacks by how relationships change, without detection rules or signatures.

A structural preprocessing layer for the SIEM you already run. SIET evaluates security telemetry before it reaches your SIEM, forwards what is structurally significant for investigation, and retains everything else at full fidelity.

An attacker does not have to match a known pattern. They only have to do something, and doing something changes the structure of what talks to what. SIET learns your estate and reports departures from it.

100%

Attacks detected and surfaced

every attack, and all 19 attacked hosts

<1 min

Median time to detect

most detections inside the first minute

3

Cases on a benign control day

not hundreds of thousands of alerts

0

Detection rules written

no signatures, no training, no threat feed

Measured on CICIDS2017, Canadian Institute for Cybersecurity. A public benchmark, so the figures are independently reproducible. See the evaluation

The problem

Security generates millions of events. Attackers do not.

Every rule you own describes an attack somebody already survived. The technique has to exist, get published, get written up, get deployed. Only then does it protect you, and from that day on somebody has to keep it alive.

Meanwhile the volume keeps climbing, almost none of what you index is ever read again, and your analysts get the incident delivered one fragment at a time and have to assemble it themselves.

Pointing a model at the whole firehose is one answer. It also means the costly part of your stack grows with your log volume, and your log volume is not going down.

An attack is not a pile of suspicious events. It is a change in what talks to what. You can see that change without knowing a single thing about who is behind it.

Where it sits

SIEM preprocessing, in front of the SIEM rather than instead of it.

SIET is a layer in your pipeline. Telemetry reaches it before it reaches your SIEM, it works out what is structurally significant, and it decides what your SIEM is asked to index. Everything else goes to archive. Your SIEM, your analysts and your existing detection content all stay exactly where they are. How the preprocessing layer works.

Your telemetry

endpoints, network, identity, cloud

→

SIET

reads everything, decides what matters

→

Your SIEM

cases, and the logs behind them

Cold archive

everything else, in full

The routing decision is arithmetic

Nothing about which tier an event lands in involves a model, an inference call or a judgement. SIET measures how far each part of your estate has moved from its own recorded history. That number decides where the event goes.

Which means it is deterministic and repeatable: the same input produces the same decision every time, and you can be told exactly why any event went where it went. No model to retrain, nothing to hallucinate, and no inference bill that scales with your log volume.

What does not change

  • /Your SIEM stays. SIET feeds it, it does not replace it.
  • /Your analysts keep working in the tool they already use.
  • /Your existing detection rules keep running throughout.
  • /Your retention is unchanged. Every raw log is still kept, in full.
The category difference

SIET changes the first question.

Everyone else asks whether an event looks dodgy. SIET asks whether your estate is still shaped the way it was yesterday.

Traditional SIEM

  1. 01Events
  2. 02Rules
  3. 03Alerts
  4. 04Correlation
  5. 05Analyst

Somebody has to describe the attack before you can catch it.

AI-first SIEM

  1. 01Events
  2. 02Model inference
  3. 03Behaviour interpretation
  4. 04Alert
  5. 05Analyst

Expensive thinking, applied to everything, most of which is nothing.

SIET

  1. 01Events
  2. 02Relationships
  3. 03Structural state
  4. 04Shape change
  5. 05Evidence
  6. 06Adjudication
  7. 07Analyst

Your estate sets its own baseline. Breaking it is the alert.

They ask

“Does this event look suspicious?”

SIET asks

“Has the structure of the environment changed in a way I cannot account for?”

What shape means

The estate has a shape. Attacks change it.

SIET models your estate as endpoints and the attributes of those endpoints: the ports a machine offers, the accounts seen on it, the machines it talks to. Each one keeps its own history, so busy for a domain controller and busy for a printer are different questions.

Normal

user → laptop

laptop → file server

laptop → mail

laptop → print

Three peers, every day, for as long as the baseline has existed.

Structural transition

user → laptop

laptop → server A

laptop → server B

laptop → server C

server C → server D

server D → server E

Nothing here is a known-bad indicator. The shape is the finding.

01

It grows

Something does far more than it has ever done. Load, brute force, floods.

02

It spreads

More neighbours than usual. Scanning and propagation.

03

It appears

Something happens that has never happened here at all. The strongest signal of the three.

Where AI belongs

Do not make AI understand twenty million events.

Expensive reasoning is worth paying for at the point where judgement is genuinely needed. Pointed at an entire event stream, all it does is tie your bill to your log volume.

Structural analysis is cheap and deterministic. It runs first, on everything, and reduces the stream to a small number of transitions that need an opinion. Only then does anything costly happen.

SIET changes what expensive computation scales with. That is an architectural argument, and this is its honest form: we have measured the volume reduction, not a production inference bill.

Millions of events

↓

Structural analysis

↓

A handful of transitions

↓

Evidence and context

↓

Adjudication, where useful

↓

Analyst

How the layers divide

Deterministic detection. Adaptive interpretation.

SIET is not an AI that detects attacks, and describing it that way would hide what makes it different. Detection is structural and deterministic. Learning sits downstream of it, where being wrong is recoverable.

01

Structural detection

“What changed?”

The graph. Each thing is judged against its own history, and this is the only step that decides whether something is an attack.

02

Evidence

“What else supports this?”

What else moved at the same time, pulled together into one case with a timeline.

03

Adjudication

“Have I seen this kind of thing here before?”

A small memory per machine that learns which weak signals matter where. It never decides what counts as an attack.

04

Analyst

“What should I do?”

One case, in the SIEM your team already lives in.

The adjudication layer is deliberately kept out of the detection path. A learned model that decides what counts as an attack can be argued into a relaxed state, and an attacker resident while it trains becomes part of what it considers normal. Detection stays in the graph, judged against the estate’s own recorded history.

What you get

What this changes for the team running it.

No more detection engineering

No rule library to write, tune, or babysit. Nobody picks a threshold, because they are computed from what your estate has actually done. This is a salary line, not a software line.

Less alert noise

Three cases on the quiet day of our benchmark. Each one already joined up, with the timeline attached, so nobody spends the morning stitching events together.

Coverage of unknown behaviour

Nobody has to have seen the attack before. Whatever the tooling, it has to touch something to achieve anything, and that is what SIET is watching.

AI where it earns its cost

The cheap maths runs first and hands off a handful of things worth thinking about. Your inference bill tracks what actually happened, not how much you ingested.

Explainable investigations

Every case says what changed, on which machines, and when. No mystery score that nobody can talk you through.

A smaller SIEM bill

Only the events that matter reach your SIEM. The rest goes to Glacier-class archive, in full, because SIET already read it and found nothing. A year of 1 TB/day costs about £1,750 to keep there and about £886,000 to index.

Proof

See it work.

SIET has been implemented and tested against CICIDS2017, the intrusion dataset published by the Canadian Institute for Cybersecurity. It is public, so you can check every number here yourself. We would rather you did.

A CICIDS2017 replay. Every machine starts quiet, judged against a baseline warmed on two benign days. As the attack spreads, the machines involved depart from their own history and the chain is drawn between them. Cases open on the right as the structure changes. Nothing here is matching a rule.

Frozen baseline

Warmed once on two benign days, then frozen. Every attack day is replayed independently against that identical state.

Benign control day

A day with no attacks replayed on every run. Its output is the false positive figure: 3 cases.

Deterministic replay

The same input produces the same frozen graph every time, so a run can be repeated and checked.

Detection and reporting stated apart

Every attack detected, and every attacked host reported. A host that departs on its own still surfaces, one tier below a case, so nothing is detected and left unsaid.

The same detector, with no tuning between them and no signature anywhere, caught brute force, DoS, port scan, DDoS and C2. That includes a command and control channel whose only distinguishing feature was that one host stopped talking to 3,000 external peers and started talking to one.

See the evaluation
The product

Two tiers. One detector.

Core is the detection engine and bolts on to the SIEM you already run. Enterprise adds the layer that decides what your SIEM is ever asked to index.

SIET-Core

Detection

One annual fee, whole estate

The detection engine. Learns what each part of your estate normally does and raises a correlated case when something departs from it. No signatures, no rules, no training. Cases land in the SIEM your team already uses.

What Core detects →

SIET-Enterprise

Detection and routing

Priced against what it saves you

Everything in Core, plus the routing layer. Only structurally significant events reach your SIEM index. Everything else goes to archive-class storage at full fidelity, so nothing is discarded and most of your telemetry leaves the per-GB path.

See the cost model →
What Core replaces

Detection content is a salary, not a licence.

Somebody on your team writes the rules. Somebody tunes them when they fire on the backup window. Somebody revisits them when the estate changes, and somebody rewrites them when a technique moves on. That work never finishes, and it is charged to headcount rather than to your security software budget.

SIET-Core is licensed as a single annual fee covering your whole estate. Not per user, not per endpoint, not per GB. You are buying the end of that job, so the honest comparison is against what the job costs you: a detection engineer, their tooling, and the hours the rest of the team spend on content that was never the reason you hired them.

Because it is flat, nobody has to scope it. Every machine you own is covered on the day you deploy, including the ones nobody remembered to tell you about.

Where the detection budget goes today

Writing and tuning detection contentOngoing
Chasing false positives it generatesOngoing
Revisiting rules as the estate changesOngoing
Coverage for techniques nobody has written upNone

SIET-Core removes the first three and covers the fourth, on one annual fee that covers everything you own.

The CFO case

You are paying to index data nobody will read.

SIEM licensing is billed per GB ingested, which puts security visibility in direct conflict with the budget. Pipeline tools trim the stream and send the rest into the index anyway, so the expensive thing just gets smaller.

SIET-Enterprise decides structurally what needs indexing, and everything else goes somewhere else entirely: archive-class object storage, at full fidelity. A year of 1 TB/day is about £1,750 to keep in deep archive. The same data indexed is closer to £886,000.

On the benign control day of the benchmark, 99.4% of events never reached the hot index. Across the full test week, seven of its eight replay segments carrying attack traffic by construction, 72.9% still avoided indexing. Retention did not change: every raw log was still written to cold storage.

See the cost model →

Illustration, 1 TB per day at £1.98 per GB

Annual index spend today£738,000
Saving at the week-wide ratea week that is mostly attack days£538,000
Saving at the benign ratea normal operating day£734,000

Your figures, not ours: the forwarding rates are measured on CICIDS2017 and applied to published per-GB list pricing. Swap in your own ingest volume and rate, and we would rather measure the reduction on your data than model it.

SIET sits on a broader structural framework, proved out in fields with nothing in common. More here.

Find out what your SIEM is missing.

Run SIET alongside your existing alerting, switch nothing off, and after a month compare cases raised, alerts missed by each, and actual indexed volume. That is the test we would want to see too.