Use case · AI SOC and Security Operations

CINQUE is not an AI SOC. It is the trusted source that feeds one.

An AI SOC is only as good as what it is reasoning over. Point one at a queue of uncorrelated alerts and it will summarize the queue. Point one at correlated personas, baselines, and journeys and it starts informed.

Pull, not pushPersona and journey contextTorq, Tines, SIEM, ticketing
Book a Discovery WorkshopGet a demo
The problem

Automation applied to uncorrelated signal produces faster uncorrelated signal.

Most security operations tooling reasons over events. An event says what happened. It does not say whether the identity behind it was supposed to be there, what it normally does, or what else it touched on the way. Without that, every triage decision is a lookup across consoles that the analyst has to perform by hand.

Alerts arrive without a subject

A finding attached to an IP or a hostname is a lookup task before it is a decision.

Normal is undefined

Anything can be called anomalous when nothing has a documented baseline.

The journey lives in six places

Reconstructing what an identity did before and after the alert is most of the work and none of the value.

Automation inherits the problem

A playbook that fires on weak context makes a weakly reasoned decision at machine speed.

What CINQUE does

What CINQUE hands the SOC.

Personas and baselines
Every identity belongs to a business persona with a documented normal across all five control points. The subject of a finding is a persona, not an address.
A correlated activity map
The full journey attached to every finding: authentication, device, network path, applications, and data touched, in one timeline.
Risk signals with provenance
Every entity carries the source system it came from, so an analyst can see where an assertion originated without leaving the finding.
Written recommendations
Each correlated finding carries a recommended action and the reasoning behind its ranking.
An API your systems pull from
Personas, signals, user journeys, entity relationships, and risk trends are available through the CINQUE API. CINQUE does not push into your queue. Your systems pull what they need, when they need it.
Where it lands

Into the workflow your team already runs.

Where it lands
Which system
How it gets there
Orchestration
Torq or Tines
Pull the recommendations and the journey behind them, then kick off the orchestration your team already wrote.
Detection and hunting
Your SIEM
Pull personas, baselines, and risk trends so correlation rules reason over a subject with a documented normal.
Assignment and tracking
Your ticketing system
Pull the correlated finding with its recommendation attached, so the work lands where the team already works.
Your own tooling
Security engineering
The same resources through the same API. Nothing is exclusive to a partner integration.

Direction is deliberate and settled: CINQUE does not push. The other system pulls. That constraint holds for every integration described on this page.

Scope

What CINQUE does not do.

Stated plainly, so nobody is surprised in month two.

  • CINQUE is not a SIEM, a SOAR, or an AI SOC, and it replaces none of them. It is the correlated source they reason over.
  • CINQUE performs no enforcement and runs no remediation workflow. It produces the recommendation and the evidence; your systems act.
  • We make no claim about alert volume, false positive rates, or analyst time saved. Those numbers belong to your environment and we will not invent them.
The CINQUE Discovery Workshop · complimentary

Bring your identity export.
Leave with your first correlated picture.