Behavioural analytics (UEBA)
Argus maintains a living behavioural baseline for every user and entity, flagging meaningful deviation — surfacing insider threats and compromised credentials that signature rules miss entirely.
Home / Argus
Argus is CFC's multi-agent intelligence engine: specialized agents that detect, triage and reason over normalized OCSF signal — proposing actions people approve.
Argus is not a single model — it is a layered intelligence stack, each capability purpose-built for a distinct function in the security operations lifecycle.
Argus maintains a living behavioural baseline for every user and entity, flagging meaningful deviation — surfacing insider threats and compromised credentials that signature rules miss entirely.
When signal fires, Argus fuses asset history, recent events, intelligence and attacker TTPs into a plain-language threat narrative — analysts open a case that already explains what is happening and why it matters.
For well-understood threat patterns, Argus assembles the containment and remediation playbook — isolation, credential revocation, indicator blocking — and queues it behind approval gates configurable per action class.
Argus correlates and deduplicates indicators and events across the normalized OCSF stream and threat-intelligence context, weighing every match for confidence, recency and relevance before it reaches a case.
Models learn from fresh telemetry, analyst feedback and newly observed attack patterns — tuned within each tenant's boundary, so the engine keeps adapting to your environment's own baseline.
Every conclusion ships with its reasoning: the signals that drove it, comparable historical cases, and an honest statement of confidence. Analysts are never left trusting a black box.
Intelliorbit (I.O) coordinates six specialist capabilities across the security lifecycle — one orchestrated, auditable system.
Argus Chat routes your question to the right agent and answers grounded in your own tenant data — not generic model knowledge. Live today on Argus-PACT for compliance and risk.
Every answer is built from your live GRC data — assessments, risks, evidence — with multi-turn context. Grounded answers typically land in under 90 seconds.
A full chat workspace plus a slide-in drawer on every page of CFC — desktop-docked or full-screen mobile, bilingual EN / AR with full RTL.
Conversations are tenant- and user-isolated. The router is multi-agent-ready: as more agents come online, the same chat reaches each specialist.
Residency-classed agents: any agent that touches raw customer data runs on local, on-prem models — permanently barred from off-premises routing.
From kill-chain detection to board-ready reporting — the operational surface the engine covers out of the box.
Multi-agent automation is only acceptable when every decision is explainable after the fact — to your analysts, your auditors and your regulator.
Argus proposes — analysts decide. Every agent decision is logged, explainable and auditable.
Containment and response actions require analyst approval by default. Autonomy thresholds are configurable per tenant, per action class.
Every finding, task and proposed action is retained with the case — reconstruct any decision, any time, message by message.
Agents reason within a tenant's boundary. Models, context and conclusions never bleed across customers — visibility exists only for the roles you authorize.
Book a demo and we'll run the engine against scenarios from your environment — then show you every step of its reasoning.