UTMStack

Stop attacks automatically, in seconds

UTMStack's security orchestration, automation and response (SOAR) module acts on alerts the moment they match, without waiting for an analyst. Build flows visually, review every run, and take over any host from a live console.

UTMStack · SOAR Flows
A response flow on the visual canvas: an alert match leads to an AI check, a firewall ban and a notification, with success and error paths. Closing it shows every flow in a list with its platforms, conditions, steps, last run and on/off switch.
  • Visual flows

    Drag steps onto a canvas and connect them with success and error paths, or switch to the code view when you prefer.

  • Act on the endpoint

    Isolate a host, kill a process, log off or disable a user, block an IP address, stop a service or delete a file through the UTMStack agent.

  • Reach devices without an agent

    Proxy agents run commands for firewalls, switches and cloud services over SSH or the device's application programming interface (API).

  • AI steps

    Add an AI step to enrich an alert or choose the next action inside a flow.

  • Execution history

    Every run is recorded with its status, command, target and output, so you can show what happened and when.

  • Interactive console

    Open a live terminal on any connected agent from the browser to investigate or fix a machine by hand.

From alert to action

A flow starts when an alert matches the conditions you set, such as a rule name or a source address. Each step then runs in order, and if/else branches let one flow handle different cases.

  • Run shell or PowerShell commands on Windows, Linux and macOS agents
  • Call any web service, with query parameters and default headers
  • Enrich the alert or decide the next step with an AI model
  • Send emails and in-app notifications
  • Open an incident automatically

Contain ransomware in seconds

Picture ransomware starting to encrypt files on a server at 3 a.m. A flow that matches the ransomware alert can isolate that server from the network right away and notify the on-call analyst. Teams that prefer to approve first can run the same isolation command from the incident or the console.

Every action on record

Execution history lists each run with its status, the command, the host it ran on, what triggered it and its output. Secrets used in commands, such as API tokens, are stored encrypted and masked in logs. Auditors and your own team get a clear record of every automated and manual action.

Hands-on when you need it

The interactive console opens a live terminal to any connected agent, right from the browser. Analysts can check running processes, collect evidence or apply a fix without a separate remote access tool.

Questions buyers ask

Which response actions are available?

Built-in actions include isolating a host, blocking an IP address, killing a process, logging off or disabling a user, removing permissions, stopping a service, deleting a file, uninstalling an application, forcing a shutdown, disabling remote desktop and repairing Windows Defender settings. You can also write custom commands or call any web service.

Do flows run on their own?

Only the flows you switch on. Built-in playbooks ship inactive, so nothing acts on your systems until you review and enable it. Alerts tagged as false positives are skipped.

Can I act on devices that cannot run an agent?

Yes. A proxy agent on a machine that can reach the device runs the command for it. Examples include blocking an address on a firewall over SSH or through its API, or updating a cloud security group.

Can each customer have separate flows?

Yes. In multi-tenant installs, response flows and their history are kept separately for each tenant.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.