Overview
The detection pipeline converts security observations into structured context for detection, correlation, risk evaluation, and defensive decision support. The pipeline is designed to support:- Threat visibility.
- Event understanding.
- Context generation.
- Risk identification.
- Security awareness.
Detection Objectives
The detection pipeline is designed to support:- Threat visibility.
- Event understanding.
- Context generation.
- Risk identification.
- Security awareness.
- Defensive decision support.
Signal Collection
The platform may receive multiple categories of security signals. Signal categories may include:- Security telemetry.
- Monitoring signals.
- Integrity signals.
- Platform events.
- Security detections.
Signal Normalization
Different signal categories are normalized into a consistent representation. Normalization is intended to support:- Reliable correlation.
- Consistent event interpretation.
- Risk evaluation.
- Security context generation.
- Operator review.
Event Correlation
The platform may correlate observations across:- Time.
- Infrastructure surfaces.
- Device classes.
- Security domains.
Risk Evaluation
Risk evaluation may consider:- Severity.
- Context.
- Recurrence.
- Cross-surface activity.
- Historical patterns.
Security Context Generation
The output of the pipeline is security context rather than raw event volume. Security context may include:- Event summaries.
- Risk explanations.
- Related observations.
- Investigation context.
- Defensive decision support.
- Operators.
- Dashboards.
- Security workflows.
- Enyra.
Defensive Decision Support
The pipeline supports defensive decisions. It may support:- Prioritization.
- Investigation.
- Notification.
- Review.
- Risk reduction measures.
Relationship With Enyra
Enyra consumes security context produced by the detection pipeline. Enyra is not the detection pipeline itself. It provides a conversational interface for authorized users to understand, summarize, and interact with security context generated by Enigm Intelligence. Enyra should not be treated as the source of detection truth. It operates on context produced by the underlying security pipeline and related Enigm Intelligence systems.Privacy Considerations
The pipeline is designed around minimization and aggregation where possible. The pipeline is not intended to collect:- Message content.
- Call content.
- Media content.
- User conversations.
- Scope signal processing to security objectives.
- Prefer aggregated context where possible.
- Avoid unnecessary identity metadata.
- Separate security visibility from message confidentiality.
- Limit access to authorized workflows.
Security Limitations
Correlation and risk assessment improve visibility but cannot eliminate uncertainty. Limitations include:- Some activity may not produce sufficient security signal.
- Related events may not always be correlated.
- Historical context may be incomplete.
- Risk evaluation depends on available evidence.
- Defensive decisions may require human review.
- Future unknown attack techniques may reduce detection confidence.
- External systems may introduce risk outside Enigm control.