The Netgraph difference
The graph is the substrate not a feature.
Every incumbent “NextGen SIEM” treats logs, identities, assets, vulnerabilities, code, and cloud posture as separate index domains stitched together with dashboards. Netgraph treats them as a single typed graph where every event, alert, finding, asset, identity, and CVE is a node with edges, and detection, hunting, and containment are graph operations.
Closed-loop detection engineering
Alerts become detections. Detections validate themselves.
L1 triages every alert. L2 investigates with a full entity subgraph. RCA emits a “gap list” of detections that shouldhave fired. The Detection-Drafting agent writes the rule, ships it through the same PR & validation pipeline as a human author, and retroactively replays it across history. The loop closes.
- Eight-agent SOC, L1 · L2 · L3 · RCA · Threat Analyst · Threat Hunter · Forensic · SOC Manager, plus Phish-triage, a SOAR agent, and the app-wide Frontal assistant.
- L1 autopilot triages every new alert autonomously.
- 75-skill library with policy-as-code graduated autonomy (single / dual / auto approval, durable HITL queue).
Open by construction
Your data, your formats. No proprietary lock-in.
Tiered storage from day one: hot interactive tier · warm columnar archive · cold object storage, all federated by one query layer. Detections live in open standards-based rule languages. If you ever leave, your data is in open columnar formats, you keep querying with any standard reader.
- OCSF / ECS-conformant normalized fields plus raw JSON preserved.
- 90-day hot / warm retention; 7-year cold archive on object storage.
- Detection-as-Code in Git: PRs, A/B tests, automatic regression.
How the graph works
The security knowledge graph.
Four stages, one closed loop. Where competing platforms stop at “AI investigates an alert,” Netgraph closes the loop, every investigation produces a drafted detection, every detection is BAS-validated, and every change replays against seven years of history before going live.
Unlike AI-SOC overlays that investigatealerts on top of someone else’s stack, Netgraph owns the loop: ingest → correlate → reason → act, all on one graph, all on open formats, all auditable, all on-prem if you want.
23 modules · one product
Breadth is shipped not aspirational.
Each module is a full slice, model, repository, API, and frontend page, all reading and writing the same graph.
Detect & Respond
The streaming core, ingest to verdict to containment, in one loop.
NextGen SIEM
Streaming ingest, OCSF/ECS open schema, NQL, the platform-native query language, Detection-as-Code with backtesting, 1,100+ curated detections, ingest-time suppression, retro replay, tiered open storage.
Explore→EndpointEDR / EPP, Unified Endpoint Agent
One cross-platform agent (macOS · Linux · Windows): rich telemetry, on-host behavioural scoring, AV/EPP with quarantine, 2,600+ YARA rules, OSQuery, FIM, live response, and full fleet management.
Explore→NetworkNDR, Network Detection & Response
Flow, protocol and host-observed connection analytics, a rule engine and detector fabric mapped to ATT&CK, TAP/SPAN sensor control, and multi-format packet / IDS / flow forensics.
Explore→BehaviourUEBA, Behaviour Analytics
20-model analytics across the full Gartner taxonomy, baselines, peer groups, link analysis, Bayesian risk, 62 use-cases with sector packs, visual rule canvas, watchlists, and explainable 0–100 entity risk.
Explore→AI SOCAgentic AI SOC
An eight-agent SOC, L1, L2, L3, RCA, Threat Analyst, Threat Hunter, Forensic, SOC Manager, plus Phish-Triage, a SOAR agent and the app-wide Frontal assistant, with a 75-skill library and HITL approval gates.
Explore→AutomationSOAR & Case Management
Code-first playbooks with approval ladders, a durable HITL queue, full case lifecycle with evidence vault, PICERL checklists that auto-progress, semantic timelines, and on-call escalation.
Explore→Cloud & Data Security
Control plane to data plane, posture, runtime and sensitive data on the same graph.
Cloud Security, CDR · CNAPP · CSPM
Cloud detection & response across AWS, Azure and GCP; workload, IaC and supply-chain scanning with drift detection and admission control; CIS benchmarks, framework mapping and custom policy-as-code.
Explore→DataDSPM, Data Security Posture
Discover, classify and monitor sensitive data in the cloud and on the endpoint, with out-of-box recognizers for Aadhaar, PAN, bank, passport and health identifiers, and custom classifier packs.
Explore→Exposure & Validation
Find what's reachable, prove what's detectable, close the gap.
CTEM, Continuous Threat Exposure Management
The full five-stage lifecycle, scoping, discovery, prioritization by real attack paths, validation, mobilization, with reachability-aware ranking across runtime, code, identity and data.
Explore→Add-onDark Web Monitoring
Licensed CTEM add-on: feed-agnostic dark-web ingest, credential-liveness checks, exposure scoring, and graph fusion that publishes findings into alerts, TIP and compliance evidence.
Explore→VulnerabilityVulnerability & Asset Management
Full hardware / software / patch / kernel inventory from the endpoint agent, a rich per-asset profile, an incrementally-synced Asset Register, and findings prioritized by actual blast radius, not CVSS in isolation.
Explore→BASAttack Simulation, BAS & Red Team
Five-stage attack scenarios validated against real telemetry read-back, scheduled runs, endpoint deploy targeting, ATT&CK coverage mapping, and Detection-CI gap wiring into the flywheel.
Explore→PhishingPhishing Simulation
Real-send campaigns over your SMTP, cohort or direct-address targeting, templates and scheduling, just-in-time training, KPIs, and a native Phish-Triage agent for the inbound side.
Explore→Intelligence & Operations
Hunt it, attribute it, prove it, with the graph as evidence.
Threat Hunting & NQL Data Search
Hypothesis-driven hunts in NQL with natural-language synthesis, scheduled hunt jobs with run history, the interactive Data Search console, entity graph exploration and blast-radius analysis.
Explore→IntelThreat Intelligence Platform
Feed ingest with live OSINT, Indicator-Match against confirmed indicators, embedded local GeoIP/ASN/WHOIS enrichment, and detection orchestration that pushes IOCs to EDR, firewalls, proxies and zero-trust via enabled integrations.
Explore→ForensicsForensics & Incident Response
Tamper-resistant artifact vault with hash-chained chain-of-custody, scope/investigate/explore consoles, declared-incident statutory clocks, PICERL-driven response, and regulator-ready evidence exports.
Explore→Governance & Platform
Compliance evidence, KPI reporting, and the multi-tenant plane it all runs on.
Compliance & KPI Reporting
Continuous compliance scoring with evidence, a 136-KPI / 15-section report generator with prebuilt packs, cron-scheduled delivery over SMTP in CSV/XLS/HTML/PDF, and DPDP / CERT-In statutory-clock tracking.
Explore→PlatformPlatform, Multi-tenancy & Licensing
Native multi-tenancy with hard isolation, 390-permission RBAC/ABAC with SSO, hash-chained AAA audit, Ed25519-signed offline license files, region-aware billing, a super-admin plane, and cloud, on-premise or fully air-gapped deployment.
Explore→Origin · Ethos
Built in India by practitioners, for practitioners.
Two non-negotiables shape every decision we make about Netgraph, from the data model to the default playbooks. They aren’t bullet points on a deck; they’re filters we apply to every PR.
Exclusively Made in India
Designed, engineered, and operated end-to-end inside India. No offshored core, no foreign-controlled data plane, no telemetry leaving the country.
- All code, infrastructure, and SOC operations India-resident.
- Compliant with DPDP Act 2023, CERT-In 6-hour reporting, RBI, SEBI, IRDAI, MeitY guidelines, by construction.
- Available on GeM for government and PSU procurement.
- Air-gapped deployment supported from day one.
Practitioner-driven, not market-driven
Every module starts from a real SOC pain, an alert that took too long, an investigation that hit a dead end, a regulator clock that almost missed. Not from an analyst report or a competitor's roadmap.
- Closed-loop detection engineering: RCA drafts detections, BAS validates them, retro replay proves them.
- Detection-as-Code in Git: PRs, A/B tests, automatic regression.
- SMB compute footprint (32 vCPU · 128GB · 2TB SSD), because most Indian SOCs aren't running hyperscale.
- Open columnar formats, if you ever leave, you keep querying with any standard reader.
Vs. the incumbents
Why customers pick Netgraph.
Across the three dominant categories of incumbent platforms, legacy enterprise SIEM, hyperscaler-bundled XDR, and AI-SOC overlays, each covers a slice. Netgraph covers the stack on one graph, with open data, at SMB-feasible compute.
| Capability | Netgraph | Legacy enterprise SIEM | Hyperscaler-bundled XDR | AI-SOC overlay |
|---|---|---|---|---|
| Native security knowledge graph | Yes, substrate | No | Partial | No |
| SIEM + XDR + NDR + SOAR unified | Yes | Bolted-on | Partial | No |
| CNAPP · DSPM · VM native | Yes | No | Partial | No |
| Detection-as-Code with BAS gate | Yes | No | No | No |
| Open columnar & telemetry formats | Yes | Proprietary | Proprietary | N/A |
| Air-gapped deployment | Yes | Partial | No | No |
| DPDP · CERT-In · RBI built-in | First-class | Add-on | Add-on | No |
| SMB compute footprint (32 vCPU) | Yes | No | Cloud-only | Cloud-only |
| Made in India · India-resident ops | Yes | No | No | No |
Specific vendor names omitted by design. Read the full comparison & evaluation checklist →
Indian regulatory · first-class, not bolted on
DPDP Act 2023. CERT-In 6-hour. RBI · SEBI · IRDAI · MeitY.
Statutory clocks run on the Declared Incidents module, surfaced on the CISO scorecard and exportable as regulator-ready evidence packs with hash-chained chain-of-custody.
Ready to see it?
One platform. One graph. Live in your stack.
Book a 45-minute live demo. We’ll wire a sample tenant against your data sources and show the closed loop, alert → investigation → drafted detection → BAS-validated rollout, end-to-end.
Explore the resource library field notes, whitepapers, security research, and case studies from the practitioner team.