AEGISFOUNDARY
API DocsEnter the Forge

◆ Threat intelligence, forged for defense

Raw intelligence
is only ore.

AEGIS Foundary transforms fragmented threat intelligence into deployable SIEM content, threat-hunting pipelines, and defensive artifacts.

INPUTRAW INTELLIGENCE
HEPHAESTUSFORGE ACTIVE
OUTPUTACTIVE DEFENSE
BUILT TO BRIDGEOPEN INTELCOMMERCIAL FEEDSINTERNAL FINDINGSSIEM-NATIVE DEFENSE

The Foundary pipeline

From signal to shield.

One controlled workflow transforms inconsistent intelligence into repeatable defensive content.

01

Collect

Open, commercial, and internal intelligence enters one controlled pipeline.

02

Refine

Normalize, deduplicate, enrich, score, expire, and map indicators to ATT&CK.

03

Forge

Generate target-native detections, hunts, lookups, watchlists, and portable artifacts.

04

Defend

Deliver usable content to the platforms your defenders already operate.

Operational by design

Intelligence that leaves the dashboard.

A feed is not a defense. AEGIS Foundary closes the distance between “we know” and “we can detect it.”

01
Intelligence Engineering

Stop feeding raw indicators to analysts.

Confidence, expiry, provenance, deduplication, and ATT&CK context turn disconnected indicators into defensible intelligence.

02
Detection-as-Code

Forge once. Deploy to the stack you have.

Generate platform-specific content from a common intelligence model while retaining the artifacts that prove what was created.

03
Retroactive Hunting

Ask whether the threat was already inside.

Prepare threat-hunting content that lets defenders search historical telemetry for prior exposure.

04
Auditable Pipelines

Know exactly what entered the forge.

Preserve source, target, counts, hashes, artifacts, and tenant-scoped records for every run.

Multi-platform output

Your stack.
Our steel.

Select the source. Select the platform. Forge the intel. Produce what your tooling expects—not another proprietary format your team must translate.

Explore the API
● ● ●forge://outputsREADY
01Splunk lookupsFORGEABLE
02Splunk saved searchesFORGEABLE
03Sentinel watchlistsFORGEABLE
04KQL huntsFORGEABLE
05Elastic detectionsFORGEABLE
06Elastic queriesFORGEABLE
07QRadar reference setsFORGEABLE
08AQL queriesFORGEABLE
09Sigma rulesFORGEABLE
10STIX bundlesFORGEABLE
11TAXII collectionsFORGEABLE
12Normalized IOC CSVFORGEABLE
13Enriched IOC JSONFORGEABLE
14Enrichment seedsFORGEABLE

The Foundary in operation

See intelligence become an artifact.

Follow a forge operation from conversational command through source selection, target-aware processing, generated output, and auditable run history.

PRODUCT CAPTUREDashboard Overview/screenshots/dashboard-overview.webpEditorial placeholder — replace with approved application screenshot
AEGIS Foundary dashboard overview showing operational intelligence activity
Dashboard Overview
PRODUCT CAPTURERun Detail/screenshots/run-detail.webpEditorial placeholder — replace with approved application screenshot
AEGIS Foundary run detail with command, generated output, artifacts, and status
Run Detail
PRODUCT CAPTURERecent Audit Events/screenshots/audit-events.webpEditorial placeholder — replace with approved application screenshot
AEGIS Foundary recent audit events with event types and traceable metadata
Recent Audit Events
AGENT // HEPHAESTUS

Meet Hephaestus.

The operational intelligence engine behind AEGIS Foundary.

Hephaestus is the conversational control surface for inspecting available sources, checking readiness and configuration, selecting targets, launching forge runs, reviewing artifacts, and inspecting audit history.

“I am Hephaestus and I run the AEGIS Foundary. Hammering threat intelligence into your SIEM. Turning threat intelligence into a defense shield and threat-hunting pipeline.”
PRODUCT CAPTUREHephaestus Console/screenshots/hephaestus-console.webpEditorial placeholder — replace with approved application screenshot
Hephaestus Console showing a completed conversational forge operation
Hephaestus Console

Built to bridge

From fragmented sources to operational defense.

AEGIS prepares defensive content for the systems your team already operates. Artifacts remain available for review and controlled deployment.

01 // INPUT

Intelligence Sources

  • Open intelligence
  • Commercial feeds
  • Internal findings
  • Rules and exposure data
02 // TRANSFORM

AEGIS Foundary

  • Collect · normalize · enrich
  • Validate · forge · audit
  • Target-aware generation
  • Reviewable artifacts
03 // OUTPUT

Defensive Outputs

  • Splunk · Sentinel · Elastic · QRadar
  • Sigma · STIX/TAXII
  • Hunts · watchlists · lookups
  • Enriched artifacts

Operational by design

Built for controlled security operations.

Enterprise-ready foundations keep operator actions authenticated, execution traceable, and generated content reviewable.

01

Federated authentication

Controlled operator access through established identity.

02

Authenticated API access

API-first operations protected by authorization controls.

03

Tenant-aware execution

Source, target, run, and artifact context stays scoped.

04

Audit logging

Operational events retain meaningful metadata and history.

05

Artifact traceability

Run history connects commands, outputs, and generated content.

06

Cloud-native architecture

Independently deployable services with clear operating boundaries.

PRODUCT CAPTUREProfile Settings/screenshots/profile-settings.webpEditorial placeholder — replace with approved application screenshot
AEGIS Foundary profile settings showing federated identity and license state with personal data redacted
Profile Settings

Identity made visible. Profile and license state give operators clear context without exposing private account information in public assets.

The practical questions

What the forge is—and is not.

How is AEGIS different from a threat intelligence platform?

AEGIS does not merely aggregate and display intelligence. It transforms source intelligence into target-aware defensive artifacts and workflows, with validation and traceability throughout. It can consume intelligence from TIPs and feeds without requiring you to replace them.

Does it replace the SIEM?

No. It makes the SIEM more useful by delivering normalized indicators, searches, detections, watchlists, and enrichment artifacts built for the target platform.

Can it support more than one platform?

Yes. A common intelligence pipeline can forge content for Splunk, Microsoft Sentinel, Elastic, QRadar, and portable standards such as Sigma and STIX.

Where does Hephaestus fit?

Hephaestus is the conversational operational layer for inspecting sources and readiness, selecting targets, launching forge runs, reviewing artifacts, and inspecting audit history.

Does AEGIS deploy changes blindly?

No. AEGIS generates and prepares target-aware artifacts that remain reviewable, traceable, and auditable. Production deployment stays under the controls and approval paths of the operating team.

The forge is ready

Turn intelligence into armor.

Stop collecting threat data your defenders still have to translate. Forge operational content built for the systems already protecting your environment.

Enter the Forge opens the authenticated AEGIS application.