ResponseControlled response & verification

Investigate with AI. Keep authority human.

Connect signals, asset context and candidate paths in one on-site investigation. Rehearse the response, route it through explicit approval and verify the outcome with fresh evidence.

Evidence informs. People authorize. Execution and a verified outcome remain separate steps.

RESPONSE / INVESTIGATIONScripted scenario
Scenario
Ransomware activity on file-03
Proposed response
Isolate the server and affected workstations
Decision state
Human review required

8.2 seconds · silent · replay anytime

InvestigateConnect signals to the evidence and question
ChallengeCompare explanations and missing context
GovernReview authority, impact, recovery and approval
VerifyUse fresh evidence to confirm the outcome
Why Breakwater Response

Move from alert handling to an accountable outcome.

What action can we safely authorize, and did it work?

Detection and enforcement tools remain essential. Response connects their evidence to AI-orchestrated investigation, digital rehearsal, explicit authority and fresh verification.

01InvestigateEvidence and competing explanations
02RehearseImpact, recovery and assumptions
03AuthorizeNamed authority and policy
04VerifyFresh post-action evidence
EvidenceWhat happened?
AuthorityWho may act?
VerificationDid it work?

AI accelerates the investigation. People retain authority. Fresh evidence closes the loop.

Response investigation view connecting a modeled ransomware signal, candidate blast radius and multiple reasoning roles.
Investigate inside the evidence.Compare the signal, candidate path and competing explanations before proposing action.
Response decision view showing an illustrated path, reasoning record, recommended containment and a pending human gate.
Keep the decision inspectable.Preserve dissent, impact, the proposed boundary and the human gate.
Your existing layerIt providesBreakwater addsDecision enabled
SIEM, EDR, IDS and NDRSignals, detections and telemetryEvidence-scoped investigation and candidate pathsWhat the signal supports and what is missing
Automation and change systemsA playbook, script or requested actionRehearsal, blast radius, recovery and approvalWhether the action is safe to authorize
Enforcement controlsCommand or policy executionSeparate execution record and fresh verificationWhether the intended outcome was achieved
From signal to accountable action

Investigate before you automate.

Your SIEM, IDS, EDR and vulnerability tools already collect signals. Response helps the people working those signals determine what they mean, inspect a proposed next step and keep authority with the responsible operator.

  1. Frame the question

    Start with the asset, time window, supplied evidence and investigation scope.

  2. Inspect the explanation

    Examine observations, candidate paths, timelines and competing hypotheses.

  3. Review the proposal

    Check target, permissions, impact, recovery, approvals and the evidence still missing.

  4. Verify the outcome

    After an authorized action, collect fresh evidence and determine whether the intended state was achieved.

One workspace, different ways to investigate

Depth for the analyst. Control for the engineer.

The useful distinction is whether people can inspect the inputs, challenge the reasoning and govern the next action.

01 / CHAT

Reason inside the evidence

Work through an alert, ask for alternative explanations and identify the specific context needed next.

02 / LIVE

Read coverage with the signal

Inspect operating observations alongside provenance and coverage instead of treating a composite count as a conclusion.

03 / PATHS

Explore candidate routes

Use inventory and connectivity evidence to examine possible attack paths while retaining the assumptions behind each route.

04 / REPLAY

Rehearse a scenario

Review modeled event timelines, digital-twin state and checkpoints before considering a change to the environment.

05 / CONSOLE

Make the proposal inspectable

Review generated queries, scripts, detection logic or control changes as drafts with explicit authority and recovery boundaries.

06 / VERIFY

Confirm with fresh evidence

Keep the authorization record, execution result and post-action verification distinct so success is measured rather than assumed.

The product, on screen

See investigation, replay and review as one controlled workflow.

Selected recorded workflows show how Response separates reported facts from hypotheses, preserves event origin and keeps operational drafts behind technical review.

Response analyst briefing separating reported facts, unknowns, next evidence to collect and competing explanations.
01 / INVESTIGATE

Turn an alert into an investigation.

Separate what is reported from what remains unknown, then name the next evidence checks before drawing a verdict.

Response replay view showing a timeline with real and injected event labels and source-preserving event detail.
02 / REPLAY

Reconstruct the sequence.

Inspect real, modeled and injected event sources on one timeline without flattening them into the same evidence class.

Response firewall review showing an editable draft, explicit no-execution state and technical review requirements.
03 / REVIEW

Review the rule before changing the boundary.

Generated operational code remains an editable, review-blocked proposal until scope, recovery and execution checks are complete.

Integrated digital twin & digital rehearsal

Test the assumptions before the environment.

Response can bring a candidate attack path, modeled asset state and proposed change into a rehearsal that preserves inputs, checkpoints, expected postconditions and rollback references.

Use rehearsal to expose unsafe assumptions.

A proposed response often depends on identity, reachability, credentials, adapter behavior and recovery steps that are easy to overlook in a ticket. A rehearsal turns those dependencies into reviewable conditions.

  • Sealed scenario inputsKnow which graph, policy and evidence set shaped the rehearsal.
  • Checkpoint and rollbackDefine the recovery reference before execution is considered.
  • Expected postconditionsState what fresh evidence must show for the action to count as successful.

Keep simulation separate from production truth.

Modeled and injected events remain labeled. A rehearsal supports planning and review; it does not prove that the same behavior will occur in production or authorize an operational change.

Competitive edge

Digital twin and rehearsal are integrated with investigation, candidate attack paths and governed response instead of being a separate exercise with no decision lineage.

Built around the people doing the work

A shared view with distinct responsibilities.

Each role can work from the same evidence while keeping investigation, engineering authority and business accountability explicit.

SOC analysts

Investigate a signal without losing the distinction between reported facts, hypotheses and the evidence still required.

Threat hunters

Trace candidate routes, examine timelines and turn uncertainty into a focused next evidence request.

IT and OT engineers

Inspect operational drafts, identify unsafe assumptions and review recovery before considering execution.

Security leaders and governance teams

Ask what is known, what remains unverified, who owns the decision and what authorizes the response.

On-site and restricted operations

Keep your controls. Add an investigation workspace.

Response is designed for on-site operation, including environments with tightly controlled connectivity and air-gapped operating configurations. The selected release and deployment controls must be validated for the customer environment.

A practical starting point

Choose one alert, hunt or operational review. Confirm supported inputs, named owners, access, retention, approvals and recovery before expanding scope.

Existing detection and enforcement

Keep SIEM, EDR, IDS, identity, network and endpoint controls as sources and enforcement points where supported adapters are configured.

Local models and processing

Review model selection, update paths, data retention and outbound connectivity for the intended restricted or offline configuration.

Explicit execution authority

Validate adapter support, credentials, allowed actions, blast radius, cancellation and rollback for every capability that can affect a target.

Operating boundary

A proposal is not permission.

Response is designed to make the authority boundary inspectable throughout the workflow.

  • An AI-generated explanation is a hypothesis to examine, not proof of an incident.
  • A candidate attack path is a route to investigate, not evidence that the route was used.
  • Generated code, queries and control changes remain drafts until the required review and authorization complete.
  • Active response depends on the installation, configured adapters, credentials and approved scope.
  • A successful command is not a verified outcome; collect fresh evidence after any authorized action.
Before an evaluation

Questions worth asking.

How is Response different from a SIEM?

Detection and correlation tools collect and organize signals. Response focuses on investigating the evidence, comparing explanations, reviewing an operational proposal and preserving the authorization and verification record.

Can Response change production systems?

Execution is installation- and capability-dependent. Review the target, credentials, allowed actions, approval route, blast radius and rollback. Generated content alone is never authorization.

Are digital twins proof of production behavior?

No. They support scenario exploration and change planning under stated inputs. Modeled, illustrative and injected records remain distinct from measured events.

Can it operate in an air-gapped environment?

Response is designed to support restricted and air-gapped operating configurations. Validate offline updates, local models, supported adapters, retention, identity, credential handling and recovery for the selected release.

One ASOC platform

Respond with the full evidence chain.

Discover establishes what is connected and exposed. Provenance tests what supports the finding. Response governs the operational next step and verifies the outcome.

Start with one real investigation

Plan a focused Response evaluation.

Bring one alert, hunt or operational review and the people responsible for the decision. We will define evidence, authority and verification before the workflow begins.

Product view