Skip to main content
Detection & Response is the SOC surface of Myrmex — a single place to triage what your security tools are reporting and turn it into an AI-led investigation. You open it from Case Management, one of the quick actions in the Directory on the left, and it opens as a tab in the Workspace on the right.

Three Tabs, One Surface

Case Management brings three streams of work together:

Service Management (ITSM)

The tickets and cases from your service-management tools, ready to read and hand to the AI.

Alerts

Unified triage of detections from every connected SIEM, EDR, and threat source.

Threat Intelligence

Look up indicators of compromise and manage the feeds that bring your own indicators in.

Scoped to Your Context

Like the rest of the console, Case Management is scoped to the context you have selected — the working environment chosen when you sign in. The alerts, tickets, and intelligence you see all belong to that context, and the same scope travels with anything you send to the AI. Switch context to move between environments. See Core Concepts.

From a Case to the AI

Detection & Response is where triage meets Myrmex’s AI team. Whenever you send an item to chat or launch an investigation, it reaches Centurion’s SOC variant — a version of the orchestrator tuned for detection and response, which pulls in specialists like Orion for enrichment and Perseus to act on a host.

Centurion, in SOC mode

Learn how the orchestrator coordinates a security investigation across the agent team.

Service Management (ITSM)

The Service Management tab lists the tickets and cases collected from your connected ITSM tools, scoped to your context. Open a ticket to review its details, then use Send to Chat to drop it into the conversation — where you can ask the AI to summarize it, correlate it with recent alerts, or draft a response.
Case Management is a triage and hand-off surface. You read, group, and route items from here; the investigation and any resulting actions happen in chat, where you review and approve them.

Go Deeper

Alerts

Filter, group, and enrich detections, then investigate in bulk.

Investigation Wizard

Turn an alert into a structured SOC investigation in a few clicks.

Threat Intelligence & Feeders

IOC lookups and bring-your-own indicator feeds (CSV, Text, MISP).

Audit Logs

Myrmex’s own trail of who did what, and when — for accountability and compliance.