Working prototype — preparing early-access pilots

Help your security team triage alerts faster, with a human in the loop.

PurifySec is a defensive AI assistant for enterprise security operations. It reads SIEM and EDR alerts and logs from systems you own, drafts triage notes, incident summaries, MITRE ATT&CK mappings and remediation reports, and leaves every decision to your analysts.

Built on Anthropic's Claude API. Working prototype; no customers yet. Defensive use only, on systems customers own or are authorized to manage.

triage-note.md — illustrative example
# Illustrative example with fictional sample data
Alert:   Multiple failed logins, then success
Source:  EDR + identity provider logs (sample)
Summary: 14 failed sign-ins for one account from a
         new IP, followed by a successful login.
ATT&CK:  T1110 Brute Force (candidate mapping)
Suggested next steps (analyst to confirm):
  1. Verify with the account owner
  2. Review MFA logs for the session
  3. Reset credentials if not recognized
Status: awaiting analyst review
Sample output for illustration only. Not a real customer or incident.

The problem

Security teams spend much of their day on repetitive triage and write-ups.

Alert queues from SIEM and EDR tools keep growing, while the people who investigate them are few. A lot of analyst time goes into reading raw logs, correlating context and writing the same kinds of summaries and reports.

1

Alert fatigue

Large volumes of alerts, many of them low-risk, make it hard to focus on the ones that matter.

2

Scattered context

Evidence sits across log sources, tickets and documentation, and must be pieced together by hand.

3

Reporting overhead

Incident summaries, ATT&CK mappings and remediation notes take time to write consistently.

What we are building

A defensive assistant for the SOC workflow

We have a working prototype and are preparing early-access pilots. The capabilities below describe the product we are building; some are still being completed and refined.

⚑

Alert triage

Summarizes SIEM/EDR alerts, groups related events and drafts a suggested priority for analyst review.

≡

Incident summaries

Turns raw alerts and analyst notes into clear timelines and summaries for handoffs and management.

⌕

Log analysis

Explains suspicious patterns in logs from customer-owned systems in plain language.

◎

MITRE ATT&CK mapping

Suggests candidate ATT&CK techniques for observed behavior, with reasoning analysts can verify.

{ }

Secure code review

Reviews code the customer owns for common security weaknesses and explains fixes.

✎

Remediation & reports

Drafts remediation guidance and incident reports in English or Korean for analysts to edit and approve.

How we use Claude

Claude does the reading and drafting. Analysts make the calls.

PurifySec is built on Anthropic's Claude API. We use Claude models to read alert and log data supplied by the customer, extract structured fields, reason about likely causes, map behavior to ATT&CK and draft summaries and reports. Our application adds the workflow around the model: data connectors, structured outputs, review queues and audit history.

  1. Ingest. Alerts and logs from systems the customer owns or is authorized to manage.
  2. Analyze. Claude extracts key facts, correlates events and proposes a triage note.
  3. Draft. Suggested ATT&CK mappings, remediation steps and report text.
  4. Review. A human analyst approves, edits or rejects every output before anything is acted on.

Human-in-the-loop by design

PurifySec suggests. People decide.

✓ In scope (defensive)

  • Alert triage and incident summaries for SIEM/EDR
  • Log analysis on customer-owned or authorized systems
  • MITRE ATT&CK mapping
  • Secure code review of customer-owned code
  • Remediation guidance and report drafting

✕ Out of scope

  • Penetration testing or attacking any system
  • Writing exploits or proof-of-concept attack code
  • Malware analysis or creation
  • Automated actions without analyst approval
  • Use on systems without the owner's authorization

Read our Responsible Use policy for details.

Status: working prototype — preparing early-access pilots

PurifySec is a new product from Purify Solution Co., Ltd., a Korean solutions company. We have a working prototype and are preparing an early-access pilot program with a small number of security teams. We do not have any customers yet, and we will say so plainly until that changes.

Interested in an early-access pilot?

Tell us about your team, the SIEM/EDR tools you use and the triage work you would like help with. We will reply by email.

Email hello@purifysec.com