// Detection & response · XDR
Attacks, not alerts.
Prevention blocks most of it at the edge. XDR handles the rest: every engine’s signals — WAF, bots, DLP, BOLA, API shield, trust, intent — are correlated per entity into a single triaged incident, explained in plain English, and contained in one click on SecKav’s own enforcement plane.
// live inspection
Many engines, many signals, one entity — folded into a single incident with a verdict and a containment button.
ip 203.0.113.9 · WAF + BOLA + bot, one actor
hover a request to inspect its decision
Correlate
- Signals grouped per entity — IP, identity, or agent
- Cross-engine: WAF · bot · DLP · BOLA · API shield · trust · intent · breach
- Attack-chain detection across stages
- MITRE ATT&CK tactic & technique mapping
Triage & explain
- Priority + correlation score on every incident
- AI verdict with a plain-English why-trail
- Deterministic by default; LLM only on high / critical
- Threat-intel enrichment on the source IP
Respond
- One-click containment on our own enforcement plane
- Block / challenge IP · revoke sessions · step-up auth
- SOAR-lite playbooks — recommend by default, opt-in auto
- Tamper-evident audit of every action · MTTC tracked
Learn & extend
- Per-tenant learning loop — your verdicts drive down false positives
- Auto-suppression of confirmed-benign patterns
- Connectors for external EDR · cloud · IDP · network telemetry
- Token-authed collect endpoint — seckav-JSON or an OCSF subset
Status: correlation, triage, one-click containment on the SecKav enforcement plane, SOAR-lite playbooks, external connectors and the per-tenant learning loop are live in the product. LLM-assisted triage is optional and runs only on high / critical incidents — deterministic triage is the default — so a missing model key degrades the explanation, never the detection.