ThreatLens Detection Platform

Overview

ThreatLens is a cloud-native threat detection platform that combines SIEM log analysis with User and Entity Behavior Analytics (UEBA) and automated investigation workflows. Instead of writing static correlation rules that generate false positives, ThreatLens builds behavioral baselines for every user, device, and service in your environment and alerts on statistically significant deviations.

The platform ingests logs from over 200 sources including cloud providers (AWS CloudTrail, GCP Audit Logs, Azure Activity Logs), identity providers (Okta, Azure AD, Google Workspace), endpoint detection tools (CrowdStrike, SentinelOne), and network security appliances. Log normalization and enrichment happen at ingest time, so all data is query-ready within seconds of arrival.

Key Features

Behavioral analytics engines build per-entity baselines covering login patterns, data access volumes, privilege usage, and network communication patterns. When a user logs in from an unusual location, accesses resources they have never touched before, or transfers an anomalous volume of data, ThreatLens generates a risk score that escalates with the number and severity of anomalies. This approach catches novel attacks that rule-based detection misses.

Automated investigation playbooks execute when an alert triggers. The playbook gathers contextual information such as the user's recent activity, related alerts, device posture, and threat intelligence matches, then presents a structured investigation summary to the analyst. Playbooks reduce mean time to investigate (MTTI) from hours to minutes by eliminating manual data gathering.

SOAR integration connects ThreatLens to your existing security orchestration platform. Automated response actions include disabling compromised accounts, isolating affected endpoints, blocking malicious IPs, and creating tickets in ServiceNow or Jira. All automated actions are logged and require human approval for high-impact responses.

Pricing

ThreatLens pricing is based on data ingestion volume with no per-user fees. Growth: up to 50 GB/day at $2,499/month. Business: up to 200 GB/day at $7,999/month. Enterprise: unlimited volume with custom pricing. All plans include 90-day hot retention, 1-year warm retention, and unlimited detection rules.

Start with a 14-day free trial that includes full platform access and 10 GB/day ingestion. Our solutions team will help configure initial data sources and detection rules.

See references

Cite this article: SecureAgent Research, 2025. Data available at the URLs referenced above.