Home / Argus

Argus — the engine behind the floor

Argus is CFC's multi-agent intelligence engine: specialized agents that detect, triage and reason over normalized OCSF signal — proposing actions people approve.

Core capabilities

What the engine does

Argus is not a single model — it is a layered intelligence stack, each capability purpose-built for a distinct function in the security operations lifecycle.

CAP / 01

Behavioural analytics (UEBA)

Argus maintains a living behavioural baseline for every user and entity, flagging meaningful deviation — surfacing insider threats and compromised credentials that signature rules miss entirely.

CAP / 02

Threat narrative generation

When signal fires, Argus fuses asset history, recent events, intelligence and attacker TTPs into a plain-language threat narrative — analysts open a case that already explains what is happening and why it matters.

CAP / 03

Orchestrated playbooks (human-approved)

For well-understood threat patterns, Argus assembles the containment and remediation playbook — isolation, credential revocation, indicator blocking — and queues it behind approval gates configurable per action class.

CAP / 04

Signal correlation

Argus correlates and deduplicates indicators and events across the normalized OCSF stream and threat-intelligence context, weighing every match for confidence, recency and relevance before it reaches a case.

CAP / 05

Continuous model improvement

Models learn from fresh telemetry, analyst feedback and newly observed attack patterns — tuned within each tenant's boundary, so the engine keeps adapting to your environment's own baseline.

CAP / 06

Explainable decisions (XAI)

Every conclusion ships with its reasoning: the signals that drove it, comparable historical cases, and an honest statement of confidence. Analysts are never left trusting a black box.

Argus Chat

Ask your security posture a question

Argus Chat routes your question to the right agent and answers grounded in your own tenant data — not generic model knowledge. Live today on Argus-PACT for compliance and risk.

CHAT / 01

Grounded, not guessing

Every answer is built from your live GRC data — assessments, risks, evidence — with multi-turn context. Grounded answers typically land in under 90 seconds.

CHAT / 02

Everywhere in the console

A full chat workspace plus a slide-in drawer on every page of CFC — desktop-docked or full-screen mobile, bilingual EN / AR with full RTL.

CHAT / 03

Isolated by design

Conversations are tenant- and user-isolated. The router is multi-agent-ready: as more agents come online, the same chat reaches each specialist.

Residency-classed agents: any agent that touches raw customer data runs on local, on-prem models — permanently barred from off-premises routing.

Scope of operation

What Argus handles

From kill-chain detection to board-ready reporting — the operational surface the engine covers out of the box.

SCOPE / 01

Detection & triage

  • Multi-stage attack chains across kill-chain phases
  • Credential abuse & account takeover
  • Ransomware precursor behaviour
  • Data exfiltration patterns
  • Cloud misconfiguration & IAM abuse
SCOPE / 02

Reporting & evidence

  • Analyst shift briefings, generated automatically
  • Executive-level threat summaries
  • Regulatory evidence collection
  • Attack-chain reconstruction for the case record
Governance

Autonomy you can defend

Multi-agent automation is only acceptable when every decision is explainable after the fact — to your analysts, your auditors and your regulator.

Argus proposes — analysts decide. Every agent decision is logged, explainable and auditable.

CTRL / 01

Human-in-the-loop

Containment and response actions require analyst approval by default. Autonomy thresholds are configurable per tenant, per action class.

CTRL / 02

Full audit trail

Every finding, task and proposed action is retained with the case — reconstruct any decision, any time, message by message.

CTRL / 03

Tenant-scoped reasoning

Agents reason within a tenant's boundary. Models, context and conclusions never bleed across customers — visibility exists only for the roles you authorize.

Next step

Meet Argus on your data.

Book a demo and we'll run the engine against scenarios from your environment — then show you every step of its reasoning.