An AI analyst built into every screen
The UTMStack AI assistant sits beside every page and works with your real alerts, incidents, logs and settings. It investigates, explains, writes rules and handles routine actions, using the AI model provider you choose.
Ask in plain language
Type a question such as which hosts talked to a flagged address this week, and get an answer built from your own data.
Automatic alert triage
The assistant reads each new alert with its related logs and past decisions. It then closes false positives, moves alerts to review or opens incidents, depending on what you allow.
Writes rules and pipelines
Describe what you want to detect or parse, and the assistant drafts the rule or pipeline for you to test and save.
190 built-in tools
A built-in Model Context Protocol (MCP) server gives the assistant 190 tools across alerts, incidents, response flows, dashboards, logs, rules, pipelines, compliance and tenants.
Your choice of model
Use ThreatWinds with no setup, or connect OpenAI, Anthropic Claude, Google Gemini, Groq, Mistral, DeepSeek, Azure OpenAI, a local Ollama model or any OpenAI-compatible service.
Usage per tenant
Multi-tenant installs measure AI use for each tenant and can set a limit for each one.
Questions buyers ask
Which AI models can I use?
Ten providers are supported: ThreatWinds (the default, with no setup), OpenAI, Anthropic Claude, Google Gemini, Groq, Mistral, DeepSeek, Azure OpenAI, Ollama running locally, and any service that offers an OpenAI-compatible interface.
Will the assistant change things without asking?
Only if you allow it. Alert triage can be set to act on its own, for example closing false positives or opening incidents. It can also run in investigate-only mode, where it changes nothing and writes a report with findings and recommendations.
Does my data leave my network?
That depends on the provider you pick. With a cloud provider, your questions and the data needed to answer them are sent to that provider. With Ollama, the model runs on your own hardware.
Is the AI assistant included in the free edition?
AI features are part of UTMStack Enterprise. Contact us if you want to see them working on your own data.
Related capabilities
- Threat detection600+ detection rules mapped to MITRE ATT&CK run on every event in real time. Tag false positives, mute noisy rules and see who is attacking whom.
- Automated responseBuild response flows on a visual canvas to isolate hosts, kill processes, log off and block users or IPs. Track every run and use a live console.
- DashboardsDrag-and-drop security dashboards for logs and alerts. Ask the AI assistant to build or change one, and set auto-refresh for wall screens.
- Incident managementGroup related alerts into incidents with a guided wizard, assign owners, track progress on a board and run response actions from the incident.
Protect your organization this week, not next quarter
Talk to an engineer today, or start using UTMStack in minutes.
Need to extend your SOC team?
Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.
Want to try UTMStack?
Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.