Blueprints — AI Workflow Automation for the SOC | Anvilogic

Anvilogic 8.0 is generally available

Learn more

Automate how AI works in your SOC.

Anvilogic Blueprints turn your team's expertise into AI workflows that automate onboarding, search, detection, triage, and investigation.

Book a Demo Watch the Demos →

Blueprint Builder — Security Workflow Automation

This blueprint investigates encoded PowerShell alerts. Collect context, identify affected users and hosts, analyze suspicious activity.

Preferences

Clear, guided workflow with essential context. Reasonable defaults for time and credit limits, automatic enrichment where possible.

  1. Review Alert Details
    Collect Alert information from Triage Agent and search users or machines in the CMDB with Axonius for context.

  2. Intel Enrichment
    Enrich the alert details with relevant information from VirusTotal.

  3. Check for Suspicious Execution
    YES

  4. Analyst Approval
    NO

  5. Run Exposure Check
    Search for signs of lateral movement or infection spread using the Investigation Agent with VirusTotal and MITRE ATT&CK...

  6. Close & Document
    Document the investigation and close the case.

Why Blueprints

Your team's expertise built in.

Modern SOCs need more than generic AI. They need AI that follows their processes, understands their environment, and operates with human oversight.

That's what Blueprints do. They orchestrate AI agents across the Anvilogic platform, turning your team's expertise into governed, repeatable workflows.

What makes up a Blueprint?

Blueprints in production.

Use Case 01 · Data Lake Feed Onboarding

Blueprints → Snowflake Data Onboarding → Instructions

  1. Sample the Bronze Table: Sample the raw feed, understand its shape, propose a gold domain.
  2. Confirm Event Time: Resolve timestamp format, timezone, and conversion.
  3. Human review gate: Field Coverage Check: Every source field mapped before the final SELECT.
  4. Human review gate: Performance Testing: Validate the SELECT runs inside a serverless task.
  5. Audit Report: Document every decision made onboarding the feed.
  6. Human review gate: Deploy Gold Macro: Wrap the SELECT into a recurring ETL pipeline in production.

The ROI

Use Case 02 · Detection Engineering

Blueprints → SafeBreach Simulation Detection Engineering → Instructions

  1. Simulation Result Intake & Triage: Pull completed SafeBreach results via the Read API, normalize into a structured triage.
  2. Detection Design: For each priority candidate, produce one or more atomic detection plans.
  3. Human review gate: Data Source Binding & Query Authoring: Hand each plan to the Search agent to bind data sources and author queries.
  4. Threat Identifier Creation: Convert each detection into a deployed Threat Identifier — tested and tuned.

The ROI

Use Case 03 · Investigations

Blueprints → Investigation — Threat Scenario → Instructions

  1. Alert Context & Initial Triage: Gather context around the triggering alert — does it warrant a full investigation?
  2. Contextual Activity Check: Search the originating source for activity in a ±5 minute window.
  3. Third-Party Enrichment: Validate timeline events and IOCs against third-party intelligence.
  4. Human Approval Checkpoint: Malicious activity observed?
  5. Conduct Exposure Check: Is the confirmed activity isolated, or has it spread to other entities?
  6. Case Closure & Report: Compile findings, evidence, and conclusions into a formal report.

The ROI

Put your SOC's expertise into every AI workflow.

Anvilogic Blueprints help your team automate security operations the way your team actually works: AI execution, human approval, and governance across the platform.