The Netgraph difference
The graph is the substrate — not a feature.
Every incumbent “NextGen SIEM” treats logs, identities, assets, vulnerabilities, code, and cloud posture as separate index domains stitched together with dashboards. Netgraph treats them as a single typed graph where every event, alert, finding, asset, identity, and CVE is a node with edges — and detection, hunting, and containment are graph operations.
Closed-loop detection engineering
Alerts become detections. Detections validate themselves.
L1 triages every alert. L2 investigates with a full entity subgraph. RCA emits a “gap list” of detections that shouldhave fired. The Detection-Drafting agent writes the rule, ships it through the same PR & validation pipeline as a human author, and retroactively replays it across history. The loop closes.
- Eight-agent SOC — L1 · L2 · L3 · RCA · Threat Analyst · Threat Hunter · Forensic · SOC Manager — plus Phish-triage, a SOAR agent, and the app-wide Frontal assistant.
- L1 autopilot triages every new alert autonomously.
- 75-skill library with policy-as-code graduated autonomy (single / dual / auto approval, durable HITL queue).
Open by construction
Your data, your formats. No proprietary lock-in.
Tiered storage from day one: hot interactive tier · warm columnar archive · cold object storage, all federated by one query layer. Detections live in open standards-based rule languages. If you ever leave, your data is in open columnar formats — you keep querying with any standard reader.
- OCSF / ECS-conformant normalized fields plus raw JSON preserved.
- 90-day hot / warm retention; 7-year cold archive on object storage.
- Detection-as-Code in Git: PRs, A/B tests, automatic regression.
How the graph works
The security knowledge graph.
Four stages, one closed loop. Where competing platforms stop at “AI investigates an alert,” Netgraph closes the loop — every investigation produces a drafted detection, every detection is BAS-validated, and every change replays against seven years of history before going live.
Unlike AI-SOC overlays that investigatealerts on top of someone else’s stack, Netgraph owns the loop: ingest → correlate → reason → act, all on one graph, all on open formats, all auditable, all on-prem if you want.
23 modules · one product
Breadth is shipped — not aspirational.
Each module is a full slice — model, repository, API, and frontend page — all reading and writing the same graph.
Detect & Respond
The streaming core — ingest to verdict to containment, in one loop.
NextGen SIEM
Streaming ingest, OCSF/ECS open schema, NQL — the platform-native query language — Detection-as-Code with backtesting, 1,100+ curated detections, ingest-time suppression, retro replay, tiered open storage.
Explore→EndpointEDR / EPP — Unified Endpoint Agent
One cross-platform agent (macOS · Linux · Windows): rich telemetry, on-host behavioural scoring, AV/EPP with quarantine, 2,600+ YARA rules, OSQuery, FIM, live response, and full fleet management.
Explore→NetworkNDR — Network Detection & Response
Flow, protocol and host-observed connection analytics, a rule engine and detector fabric mapped to ATT&CK, TAP/SPAN sensor control, and multi-format packet / IDS / flow forensics.
Explore→BehaviourUEBA — Behaviour Analytics
20-model analytics across the full Gartner taxonomy — baselines, peer groups, link analysis, Bayesian risk — 62 use-cases with sector packs, visual rule canvas, watchlists, and explainable 0–100 entity risk.
Explore→AI SOCAgentic AI SOC
An eight-agent SOC — L1, L2, L3, RCA, Threat Analyst, Threat Hunter, Forensic, SOC Manager — plus Phish-Triage, a SOAR agent and the app-wide Frontal assistant, with a 75-skill library and HITL approval gates.
Explore→AutomationSOAR & Case Management
Code-first playbooks with approval ladders, a durable HITL queue, full case lifecycle with evidence vault, PICERL checklists that auto-progress, semantic timelines, and on-call escalation.
Explore→Cloud & Data Security
Control plane to data plane — posture, runtime and sensitive data on the same graph.
Cloud Security — CDR · CNAPP · CSPM
Cloud detection & response across AWS, Azure and GCP; workload, IaC and supply-chain scanning with drift detection and admission control; CIS benchmarks, framework mapping and custom policy-as-code.
Explore→DataDSPM — Data Security Posture
Discover, classify and monitor sensitive data in the cloud and on the endpoint — with out-of-box recognizers for Aadhaar, PAN, bank, passport and health identifiers, and custom classifier packs.
Explore→Exposure & Validation
Find what's reachable, prove what's detectable, close the gap.
CTEM — Continuous Threat Exposure Management
The full five-stage lifecycle — scoping, discovery, prioritization by real attack paths, validation, mobilization — with reachability-aware ranking across runtime, code, identity and data.
Explore→Add-onDark Web Monitoring
Licensed CTEM add-on: feed-agnostic dark-web ingest, credential-liveness checks, exposure scoring, and graph fusion that publishes findings into alerts, TIP and compliance evidence.
Explore→VulnerabilityVulnerability & Asset Management
Full hardware / software / patch / kernel inventory from the endpoint agent, a rich per-asset profile, an incrementally-synced Asset Register, and findings prioritized by actual blast radius — not CVSS in isolation.
Explore→BASAttack Simulation — BAS & Red Team
Five-stage attack scenarios validated against real telemetry read-back, scheduled runs, endpoint deploy targeting, ATT&CK coverage mapping, and Detection-CI gap wiring into the flywheel.
Explore→PhishingPhishing Simulation
Real-send campaigns over your SMTP, cohort or direct-address targeting, templates and scheduling, just-in-time training, KPIs — and a native Phish-Triage agent for the inbound side.
Explore→Intelligence & Operations
Hunt it, attribute it, prove it — with the graph as evidence.
Threat Hunting & NQL Data Search
Hypothesis-driven hunts in NQL with natural-language synthesis, scheduled hunt jobs with run history, the interactive Data Search console, entity graph exploration and blast-radius analysis.
Explore→IntelThreat Intelligence Platform
Feed ingest with live OSINT, Indicator-Match against confirmed indicators, embedded local GeoIP/ASN/WHOIS enrichment, and detection orchestration that pushes IOCs to EDR, firewalls, proxies and zero-trust via enabled integrations.
Explore→ForensicsForensics & Incident Response
Tamper-resistant artifact vault with hash-chained chain-of-custody, scope/investigate/explore consoles, declared-incident statutory clocks, PICERL-driven response, and regulator-ready evidence exports.
Explore→Governance & Platform
Compliance evidence, KPI reporting, and the multi-tenant plane it all runs on.
Compliance & KPI Reporting
Continuous compliance scoring with evidence, a 136-KPI / 15-section report generator with prebuilt packs, cron-scheduled delivery over SMTP in CSV/XLS/HTML/PDF, and DPDP / CERT-In statutory-clock tracking.
Explore→PlatformPlatform, Multi-tenancy & Licensing
Native multi-tenancy with hard isolation, 390-permission RBAC/ABAC with SSO, hash-chained AAA audit, Ed25519-signed offline license files, region-aware billing, a super-admin plane — and cloud, on-premise or fully air-gapped deployment.
Explore→Origin · Ethos
Built in India, by practitioners — for practitioners.
Two non-negotiables shape every decision we make about Netgraph — from the data model to the default playbooks. They aren’t bullet points on a deck; they’re filters we apply to every PR.
Exclusively Made in India
Designed, engineered, and operated end-to-end inside India. No offshored core, no foreign-controlled data plane, no telemetry leaving the country.
- All code, infrastructure, and SOC operations India-resident.
- Compliant with DPDP Act 2023, CERT-In 6-hour reporting, RBI, SEBI, IRDAI, MeitY guidelines — by construction.
- Available on GeM for government and PSU procurement.
- Air-gapped deployment supported from day one.
Practitioner-driven, not market-driven
Every module starts from a real SOC pain — an alert that took too long, an investigation that hit a dead end, a regulator clock that almost missed. Not from an analyst report or a competitor's roadmap.
- Closed-loop detection engineering: RCA drafts detections, BAS validates them, retro replay proves them.
- Detection-as-Code in Git: PRs, A/B tests, automatic regression.
- SMB compute footprint (32 vCPU · 128GB · 2TB SSD) — because most Indian SOCs aren't running hyperscale.
- Open columnar formats — if you ever leave, you keep querying with any standard reader.
Vs. the incumbents
Why customers pick Netgraph.
Across the three dominant categories of incumbent platforms — legacy enterprise SIEM, hyperscaler-bundled XDR, and AI-SOC overlays — each covers a slice. Netgraph covers the stack on one graph, with open data, at SMB-feasible compute.
| Capability | Netgraph | Legacy enterprise SIEM | Hyperscaler-bundled XDR | AI-SOC overlay |
|---|---|---|---|---|
| Native security knowledge graph | Yes — substrate | No | Partial | No |
| SIEM + XDR + NDR + SOAR unified | Yes | Bolted-on | Partial | No |
| CNAPP · DSPM · VM native | Yes | No | Partial | No |
| Detection-as-Code with BAS gate | Yes | No | No | No |
| Open columnar & telemetry formats | Yes | Proprietary | Proprietary | N/A |
| Air-gapped deployment | Yes | Partial | No | No |
| DPDP · CERT-In · RBI built-in | First-class | Add-on | Add-on | No |
| SMB compute footprint (32 vCPU) | Yes | No | Cloud-only | Cloud-only |
| Made in India · India-resident ops | Yes | No | No | No |
Specific vendor names omitted by design. Read the full comparison & evaluation checklist →
Indian regulatory · first-class, not bolted on
DPDP Act 2023. CERT-In 6-hour. RBI · SEBI · IRDAI · MeitY.
Statutory clocks run on the Declared Incidents module — surfaced on the CISO scorecard and exportable as regulator-ready evidence packs with hash-chained chain-of-custody.
Ready to see it?
One platform. One graph. Live in your stack.
Book a 45-minute live demo. We’ll wire a sample tenant against your data sources and show the closed loop — alert → investigation → drafted detection → BAS-validated rollout — end-to-end.
Explore the resource library — field notes, whitepapers, security research, and case studies from the practitioner team.