On-Demand Webinar

Anvilogic 8.0 Helps SOC Teams Automate Work From Data Onboarding Through Investigation

Agentic SecOps
Blueprints
Modern SOC
July 30, 2026 9:00 AM
CST
Online
On-Demand Webinar

Anvilogic 8.0 Helps SOC Teams Automate Work From Data Onboarding Through Investigation

Detection Strategies

Today we released Anvilogic 8.0, a major milestone that changes four things: how you search across your environments, how your team builds automation, how cases move from alert to resolution, and what data you can reach in the first place.

Why this release matters now

Security teams collect more data, face more alerts, and defend against faster attacks than their headcount can keep pace. Data goes unsearched, detections go unbuilt, and investigations stall in the queue. Anvilogic moves that repetitive work from people to AI agents that run the full SOC lifecycle (onboard, search, detect, and investigate), with humans in control of the decisions that matter. 8.0 extends that on every front: it reaches more of your data, opens agentic workflows to every customer, and carries an alert all the way to a documented, resolved case.

The Agentic SecOps platform, in four jobs

Anvilogic automates the four jobs of day-to-day security operations, and everything in this release maps back to them:

  • Onboard: Parse, normalize, and enrich raw events into the schema you choose (OCSF, CIM, or your own) and deliver detection-ready data in minutes, not weeks, on any SIEM or data lake.
  • Search: Ask one question in plain language across every connected source, wherever the data lives.
  • Detect: Turn threat intelligence into deployed, tuned detections across every platform, drawing on thousands of MITRE ATT&CK-mapped detections curated weekly by the Anvilogic Purple Team.
  • Investigate: Triage every alert, then investigate incidents end to end.
Anvilogic runs on the stack you already own, standalone on a data lake, alongside an existing SIEM, or shifting to a data lake gradually while your SIEM stays live. Nothing gets ripped out.

Blueprints: your team's expertise, running as automated AI workflows

Blueprints are the orchestration layer of the platform, and as of today they are generally available to every Anvilogic customer. Anyone on your team can build an agentic workflow in plain language and connect it to any downstream system.

A Blueprint chains several AI agents into a single workflow that runs the same way every time, with a human approval checkpoint wherever your process requires one, and keeps running on every matching event. The important part is that it's not generic AI automation. Blueprints capture how your team already works and make the agents follow your process, not one a vendor assumed for you.

If you have used Claude Skills, the idea will feel familiar: plain-language instructions, no code, plus connectors to your stack like Splunk, Jira, and VirusTotal. Because the platform already understands your data, detections, and schemas, the AI follows your investigation methods and approval gates instead of guessing, and it learns your environment over time.

GA opens Blueprints in both directions:

  • Anvilogic MCP Server: Connect from your own Claude or internal AI system and run tasks directly on the platform.
  • Third-party connectors: Bring tools like Atlassian and GitHub into the AI Operating System, so a Blueprint acts across your real environment.

See Blueprints in action:

Federated Search, extended by Anvilogic Compute

Security data is distributed by design. Two things get in the way of asking one question across it: analysts pivot between consoles, each with its own query language, and some data (the high-volume logs teams leave in storage to control cost) can't be searched at all. Federated Search solves the first, Anvilogic Compute solves the second.

With Federated Search, you can ask one question, in plain language, across every connected environment and get every event back in one consolidated result set inside the AI Operating System, each result labeled by source. The Search Agent translates to each platform's language (SPL, KQL, SQL), queries run in place under each analyst's unique credentials, and a successful hunt becomes a production-ready detection in one click. Anvilogic 8.0 adds Elastic, CrowdStrike LogScale, CrowdStrike NG-SIEM, and Dynatrace, with SentinelOne, Google SecOps, ClickHouse, and OpenSearch coming next.

If you have data you want to search, but don't want to move, that's what Compute is for. You put it in a storage service like Amazon S3, and Anvilogic indexes it in place and makes it available for search, detection and hunting, and investigation. It's built for the data most teams leave in storage, like cloud audit logs, CloudTrail and VPC flow logs, long-retention compliance archives, and niche OT, IoT, and app logs. Your data stays in your bucket, and nothing is migrated.

Case Management: from alert to resolved case, in one place

With Anvilogic 8.0, Case Management brings the full path from alert to resolution into the platform. Escalate an alert into a case, assign it to an analyst, and move it into triage, with investigation agents on hand the whole way. Inside a case you get:

  • An AI workspace with investigation agents that gather context, run checks, and answer questions as you work.
  • Alert-to-case escalation with assignment, so a triggering alert becomes a tracked case owned by a named analyst.
  • An interactive timeline that tracks case progress and every related event.
  • Case notes documented directly in reports, built as you go.

With AI and Blueprints, the analyst opens a case that's already being investigated, saving the time normally lost to setup and manual triage. The result is consistent, audit-ready documentation across every analyst and shift, and faster handoffs, because the next person inherits a complete case instead of a half-finished one. Because Anvilogic connects to the ticketing and case systems you already run, cases close the loop in the tools your team lives in.

See Anvilogic 8.0 in action at Black Hat

Want a live demo of Anvilogic 8.0? Meet our team at Black Hat USA 2026 (August 1 to 6) at Mandalay Bay, Booth 5724, or book time at anvilogic.com/demo.

Get the Latest Resources

Leave Your Data Where You Want: Detect Across Snowflake

Demo Series
Leave Your Data Where You Want: Detect Across Snowflake
Watch

MonteAI: Your Detection Engineering & Threat Hunting Co-Pilot

Demo Series
MonteAI: Your Detection Engineering & Threat Hunting Co-Pilot
Watch
White Paper

Anvilogic 8.0 Helps SOC Teams Automate Work From Data Onboarding Through Investigation

Agentic SecOps
Blueprints
Modern SOC
July 30, 2026

Anvilogic 8.0 Helps SOC Teams Automate Work From Data Onboarding Through Investigation

Agentic SecOps
Blueprints
Modern SOC
No items found.

Today we released Anvilogic 8.0, a major milestone that changes four things: how you search across your environments, how your team builds automation, how cases move from alert to resolution, and what data you can reach in the first place.

Why this release matters now

Security teams collect more data, face more alerts, and defend against faster attacks than their headcount can keep pace. Data goes unsearched, detections go unbuilt, and investigations stall in the queue. Anvilogic moves that repetitive work from people to AI agents that run the full SOC lifecycle (onboard, search, detect, and investigate), with humans in control of the decisions that matter. 8.0 extends that on every front: it reaches more of your data, opens agentic workflows to every customer, and carries an alert all the way to a documented, resolved case.

The Agentic SecOps platform, in four jobs

Anvilogic automates the four jobs of day-to-day security operations, and everything in this release maps back to them:

  • Onboard: Parse, normalize, and enrich raw events into the schema you choose (OCSF, CIM, or your own) and deliver detection-ready data in minutes, not weeks, on any SIEM or data lake.
  • Search: Ask one question in plain language across every connected source, wherever the data lives.
  • Detect: Turn threat intelligence into deployed, tuned detections across every platform, drawing on thousands of MITRE ATT&CK-mapped detections curated weekly by the Anvilogic Purple Team.
  • Investigate: Triage every alert, then investigate incidents end to end.
Anvilogic runs on the stack you already own, standalone on a data lake, alongside an existing SIEM, or shifting to a data lake gradually while your SIEM stays live. Nothing gets ripped out.

Blueprints: your team's expertise, running as automated AI workflows

Blueprints are the orchestration layer of the platform, and as of today they are generally available to every Anvilogic customer. Anyone on your team can build an agentic workflow in plain language and connect it to any downstream system.

A Blueprint chains several AI agents into a single workflow that runs the same way every time, with a human approval checkpoint wherever your process requires one, and keeps running on every matching event. The important part is that it's not generic AI automation. Blueprints capture how your team already works and make the agents follow your process, not one a vendor assumed for you.

If you have used Claude Skills, the idea will feel familiar: plain-language instructions, no code, plus connectors to your stack like Splunk, Jira, and VirusTotal. Because the platform already understands your data, detections, and schemas, the AI follows your investigation methods and approval gates instead of guessing, and it learns your environment over time.

GA opens Blueprints in both directions:

  • Anvilogic MCP Server: Connect from your own Claude or internal AI system and run tasks directly on the platform.
  • Third-party connectors: Bring tools like Atlassian and GitHub into the AI Operating System, so a Blueprint acts across your real environment.

See Blueprints in action:

Federated Search, extended by Anvilogic Compute

Security data is distributed by design. Two things get in the way of asking one question across it: analysts pivot between consoles, each with its own query language, and some data (the high-volume logs teams leave in storage to control cost) can't be searched at all. Federated Search solves the first, Anvilogic Compute solves the second.

With Federated Search, you can ask one question, in plain language, across every connected environment and get every event back in one consolidated result set inside the AI Operating System, each result labeled by source. The Search Agent translates to each platform's language (SPL, KQL, SQL), queries run in place under each analyst's unique credentials, and a successful hunt becomes a production-ready detection in one click. Anvilogic 8.0 adds Elastic, CrowdStrike LogScale, CrowdStrike NG-SIEM, and Dynatrace, with SentinelOne, Google SecOps, ClickHouse, and OpenSearch coming next.

If you have data you want to search, but don't want to move, that's what Compute is for. You put it in a storage service like Amazon S3, and Anvilogic indexes it in place and makes it available for search, detection and hunting, and investigation. It's built for the data most teams leave in storage, like cloud audit logs, CloudTrail and VPC flow logs, long-retention compliance archives, and niche OT, IoT, and app logs. Your data stays in your bucket, and nothing is migrated.

Case Management: from alert to resolved case, in one place

With Anvilogic 8.0, Case Management brings the full path from alert to resolution into the platform. Escalate an alert into a case, assign it to an analyst, and move it into triage, with investigation agents on hand the whole way. Inside a case you get:

  • An AI workspace with investigation agents that gather context, run checks, and answer questions as you work.
  • Alert-to-case escalation with assignment, so a triggering alert becomes a tracked case owned by a named analyst.
  • An interactive timeline that tracks case progress and every related event.
  • Case notes documented directly in reports, built as you go.

With AI and Blueprints, the analyst opens a case that's already being investigated, saving the time normally lost to setup and manual triage. The result is consistent, audit-ready documentation across every analyst and shift, and faster handoffs, because the next person inherits a complete case instead of a half-finished one. Because Anvilogic connects to the ticketing and case systems you already run, cases close the loop in the tools your team lives in.

See Anvilogic 8.0 in action at Black Hat

Want a live demo of Anvilogic 8.0? Meet our team at Black Hat USA 2026 (August 1 to 6) at Mandalay Bay, Booth 5724, or book time at anvilogic.com/demo.

Resources

No items found.

See what Anvilogic can do for your SOC.

Talk to a practitioner who has been on your side of the problem.

July 30, 2026

Anvilogic 8.0 Helps SOC Teams Automate Work From Data Onboarding Through Investigation

Agentic SecOps
Blueprints
Modern SOC

Resources

No items found.

See what Anvilogic can do for your SOC.

Talk to a practitioner who has been on your side of the problem.

Product Vision
|
July 30, 2026
|
4 min read

Anvilogic 8.0 Helps SOC Teams Automate Work From Data Onboarding Through Investigation

This is some text inside of a div block.

| Author

Anvilogic 8.0 extends the Agentic SecOps platform across all four SOC jobs, with Blueprints now generally available, an expanded Federated Search, and Case Management.

Today we released Anvilogic 8.0, a major milestone that changes four things: how you search across your environments, how your team builds automation, how cases move from alert to resolution, and what data you can reach in the first place.

Why this release matters now

Security teams collect more data, face more alerts, and defend against faster attacks than their headcount can keep pace. Data goes unsearched, detections go unbuilt, and investigations stall in the queue. Anvilogic moves that repetitive work from people to AI agents that run the full SOC lifecycle (onboard, search, detect, and investigate), with humans in control of the decisions that matter. 8.0 extends that on every front: it reaches more of your data, opens agentic workflows to every customer, and carries an alert all the way to a documented, resolved case.

The Agentic SecOps platform, in four jobs

Anvilogic automates the four jobs of day-to-day security operations, and everything in this release maps back to them:

  • Onboard: Parse, normalize, and enrich raw events into the schema you choose (OCSF, CIM, or your own) and deliver detection-ready data in minutes, not weeks, on any SIEM or data lake.
  • Search: Ask one question in plain language across every connected source, wherever the data lives.
  • Detect: Turn threat intelligence into deployed, tuned detections across every platform, drawing on thousands of MITRE ATT&CK-mapped detections curated weekly by the Anvilogic Purple Team.
  • Investigate: Triage every alert, then investigate incidents end to end.
Anvilogic runs on the stack you already own, standalone on a data lake, alongside an existing SIEM, or shifting to a data lake gradually while your SIEM stays live. Nothing gets ripped out.

Blueprints: your team's expertise, running as automated AI workflows

Blueprints are the orchestration layer of the platform, and as of today they are generally available to every Anvilogic customer. Anyone on your team can build an agentic workflow in plain language and connect it to any downstream system.

A Blueprint chains several AI agents into a single workflow that runs the same way every time, with a human approval checkpoint wherever your process requires one, and keeps running on every matching event. The important part is that it's not generic AI automation. Blueprints capture how your team already works and make the agents follow your process, not one a vendor assumed for you.

If you have used Claude Skills, the idea will feel familiar: plain-language instructions, no code, plus connectors to your stack like Splunk, Jira, and VirusTotal. Because the platform already understands your data, detections, and schemas, the AI follows your investigation methods and approval gates instead of guessing, and it learns your environment over time.

GA opens Blueprints in both directions:

  • Anvilogic MCP Server: Connect from your own Claude or internal AI system and run tasks directly on the platform.
  • Third-party connectors: Bring tools like Atlassian and GitHub into the AI Operating System, so a Blueprint acts across your real environment.

See Blueprints in action:

Federated Search, extended by Anvilogic Compute

Security data is distributed by design. Two things get in the way of asking one question across it: analysts pivot between consoles, each with its own query language, and some data (the high-volume logs teams leave in storage to control cost) can't be searched at all. Federated Search solves the first, Anvilogic Compute solves the second.

With Federated Search, you can ask one question, in plain language, across every connected environment and get every event back in one consolidated result set inside the AI Operating System, each result labeled by source. The Search Agent translates to each platform's language (SPL, KQL, SQL), queries run in place under each analyst's unique credentials, and a successful hunt becomes a production-ready detection in one click. Anvilogic 8.0 adds Elastic, CrowdStrike LogScale, CrowdStrike NG-SIEM, and Dynatrace, with SentinelOne, Google SecOps, ClickHouse, and OpenSearch coming next.

If you have data you want to search, but don't want to move, that's what Compute is for. You put it in a storage service like Amazon S3, and Anvilogic indexes it in place and makes it available for search, detection and hunting, and investigation. It's built for the data most teams leave in storage, like cloud audit logs, CloudTrail and VPC flow logs, long-retention compliance archives, and niche OT, IoT, and app logs. Your data stays in your bucket, and nothing is migrated.

Case Management: from alert to resolved case, in one place

With Anvilogic 8.0, Case Management brings the full path from alert to resolution into the platform. Escalate an alert into a case, assign it to an analyst, and move it into triage, with investigation agents on hand the whole way. Inside a case you get:

  • An AI workspace with investigation agents that gather context, run checks, and answer questions as you work.
  • Alert-to-case escalation with assignment, so a triggering alert becomes a tracked case owned by a named analyst.
  • An interactive timeline that tracks case progress and every related event.
  • Case notes documented directly in reports, built as you go.

With AI and Blueprints, the analyst opens a case that's already being investigated, saving the time normally lost to setup and manual triage. The result is consistent, audit-ready documentation across every analyst and shift, and faster handoffs, because the next person inherits a complete case instead of a half-finished one. Because Anvilogic connects to the ticketing and case systems you already run, cases close the loop in the tools your team lives in.

See Anvilogic 8.0 in action at Black Hat

Want a live demo of Anvilogic 8.0? Meet our team at Black Hat USA 2026 (August 1 to 6) at Mandalay Bay, Booth 5724, or book time at anvilogic.com/demo.

Resources

No items found.