Inbridge · SentivexInbridge · Sentivex

Sentivex Evolution Engine

SEE

SEE turns a flood of security alerts into cases people can trust and act on. It fixes evidence first so the AI can't fabricate facts, and keeps both the analysis process and the analyst-facing screens so response stays trustworthy.

Capabilities

What SEE does

Grounded Bundle

Fixes multi-source cases and evidence before analysis, leaving little room for the AI to invent facts.

TI Exact Match

Confirms IOC, CVE, and hashes by deterministic lookup instead of similarity, and leaves unknowns as unknown.

21+ Lens Analysis

Turns on only the specialist lenses that fit the case, in parallel, analyzing just the perspectives needed.

Dual Reconciler

Different model families merge conclusions and surface the points where they conflict.

Critic & HITL

Reviews false-clears, evidence gaps, and execution risk, and stops at the human approval boundary.

SIT Handoff

Cases hard to automate are turned into Agentic Tickets and handed to MDR/SOC for response.

Process

How a single case moves through

  1. 01Case intake
  2. 02Grounding
  3. 03Multi-lens review
  4. 04Critique & reconcile
  5. 05Report trace
  6. 06SIT handoff

Operating Principles

SEE Operating Policy

SEE exists to reduce the cases people must look at, and to make the cases that need human judgment faster to understand. It separates the boundaries of fact collection, AI inference, and execution decision so analysis automation never encroaches on operational authority.

FACT

Facts are gathered by code

Raw events, IOCs, and internal evidence are fixed deterministically before the AI sees them.

INFERENCE

Inference is done by AI

Multiple expert perspectives analyze the same case and review each other's conclusions.

DECISION

Decisions are made by rules and people

High-risk actions and uncertain calls stop at the HITL boundary and proceed only with human approval.

NO SCORE UI

Scores are not put in front of users

Confidence is used only as an internal routing signal; users see evidence and the handling flow.

Live / see_analysis_pipeline

SEE analysis pipeline

Stage 1 fixes the case bundle deterministically; Stage 2 records multi-lens analysis, consensus, critic, HITL, reporting, and SIT conversion as one operational trace.

LIVE / see_analysis_pipeline
Analysis pipeline, 9-stage live● In progress, 73e6caa2
Step 0
Data preprocessing
1ms
Step 1
Threat data classification
1 hints
Step 2
9 analyzers in parallel
2.4s
Step 3
Threat intel lookup
631ms
Step 4
Dual AI analysis
50.1s
Step 5
AI conclusion reconciliation
10.5s
Step 6
Result verification
Pending
Step 6.5
HITL Gate
Pending
Step 7
Report
Pending
Step 8
Ticket creation
Pending
Step 8.5
Follow-up tickets
Pending
Step 9
Dispatch
Pending
Multi-attack-pattern simultaneous analysis12/9, BASE 12, CANDIDATE 0
Process chain
Credentials
Network comms
Defense evasion
Persistence
Lateral movement
IOC forensics
MITRE mapping
Classification & severity
Data exfiltration
Scheduled tasks
User behavior
Cloud identity
Vulnerability correlation
DNS exfiltration
Endpoint hardening
Timeline correlation
Kill-chain stage
Insider threat
Container security
Email phishing

Consensus: 8 inconclusive, 3 suspicious, confidence 0.82 → HITL recommended

LIVE FEED, 6 channels● Waiting 1.2s
AllStepsAlertsTicketsChatAnalyzers
02:23:50SYST-CONF disagreement, Model A Suspicious 0.82 ↔ Model B Benign 0.71 — Reconciler arbitrating
02:23:50SYSStep 8, Ticket creation complete
02:23:50SYSStep 8.5, Follow-up ticket breakdown complete (13ms), 4 sub
02:23:50Forensic1) Immediate preservation targets: memory (volatile data). Collect remote-access tool logs, C2 artifacts.
02:23:50Hunterhunting hypothesis: 3 similar campaigns, MITRE T1078.004 match, reviewing links to known campaigns
02:23:50IRCurrent IR phase: HITL sign-off (after Containment→Eradication, awaiting final approval and closure)
02:23:50SOCOpinion: further review needed — inconclusive. Recommend reviewing the 2 critic findings in detail.
02:23:50DispatcherA16 DXE selected — CAP-0042 (score 0.72), Critical Asset → forced T3
02:23:49SOCThis is Vendor A's EDR data — why was it analyzed with Vendor B's engine?
02:23:49SYSStep 7, Report generation complete
SOCIRHunterForensicDispatcher
Ask about the current analysis/ticket (Enter)

Processing Flow

SEE Core Patterns

Autonomous vendor-event analysis, 21+ parallel lenses, and the Decision Report are SEE's core operating structure.

Pattern 01

Vendor-event-driven Sentivex autonomous analysis

Vendor incidents and alerts enter Sentivex Core as individual cases, undergo deterministic grounding, TI hunting, and AI-agent analysis, and are routed to their respective handling paths following a verdict and consensus.

Pattern 02

21+ Lens Parallel Analysis

After an incident or alert undergoes pre/post-processing and TI hunting, only the required specialist lenses are selected and run in parallel. The number of active lenses varies depending on the case — such as 2, 3, 6, 18, or 22.

Pattern 05

Critic, HITL, Reporter, and ITSM

A four-column tree structure where verification results pass through a human gate and report generation, and are ultimately issued as operational tickets.