◉ ANTEMURE ASRP · Autonomous Security Remediation Platform Fleet Console license loading…
Endpoints
–
– online
Open incidents
–
across the fleet
Max risk
–
highest node
Agents live
0
idle across fleet
✦Analyst · AI copilot for managing the fleet
Hi — I'm the Antemure Analyst. Ask me about node health, security incidents, or run an operational investigation against specific nodes. I can look up MITRE ATT&CK, talk through remediation and incident‑management options, and take action across the fleet (dispatching parallel agents) — I'll confirm before anything destructive.
nodesFleet heat map 0
lowcriticalofflinescroll = zoom · drag = pan · click a node
🛡️Threat remediation · attacks stopped
Remediation funnel · signal → stopped
Incidents vs. remediations · recent
incidents remediations
By severity
Top ATT&CK techniques
By node
incidentsFleet incidents0
No open incidents across the fleet.
🛡Fleet immunity · learned threat indicators0
No indicators learned yet. When any node opens an incident, its indicators (dropped files, C2 IPs, persistence) are pushed to every node — so the same attack is caught across the fleet before it spreads. You keep the override: clear anytime.
meshAgent communication · hub ↔ fleet awareness0

Live log of the hub learning an indicator from one agent and broadcasting it to every other agent — so knowledge from one node protects the whole fleet.

Quiet — no cross-fleet awareness traffic yet. This lights up when a node reports an indicator and the hub relays it.
approvalsPending remediation0
Target:
0 selected
Loading pending remediation…
⌖Fleet hunt · one query, every node in parallel
telemetryFleet telemetry · cross-fleet event search

Every node's events are polled into one hot store on the hub — search and timeline across the whole fleet at once (the SIEM hot store over the per-node tables). Retention & the ingest risk floor are set in Settings → Data, retention & archive.

⚙Fleet configmanaged by hub
Applies to every node. Select specific nodes to override just them (per-node config wins over the fleet default).
Detect-and-act sensitivity — the risk score at which Antemure opens an incident and proposes remediation (still approval-gated below). Lower = acts on weaker signals (more sensitive, more noise); higher = only strong signals. This is not inline prevention — Antemure detects and contains, it does not block before an action completes.
Checked actions wait for a human; unchecked ones auto-run. Antemure never remediates its own daemon or critical infra (sshd/systemd/PID 1), even autonomously.
🔒Credential vault · admin

Credentials the Analyst can use for actions. Values are encrypted at rest (AES‑256‑GCM), write‑only — never shown again, never sent to the model, never logged.

No credentials stored.
🔌Connected sources · integrations

Third-party integrators feed signals into Antemure; the hub correlates them and the LLM reasons over them — so an identity attack (e.g. MFA fatigue against a credential in Okta) flows into the same detect → reason → remediate loop, remediating through the integration (suspend the user, revoke sessions) and the fleet (block the source IP).

Loading integrations…
⚑Integration alerts · SIEM correlation
No integration alerts yet. Correlated red flags — MFA fatigue, password spray, impossible travel — appear here with a reasoned verdict and one-click remediation.
Live integration event feed
🕸️Knowledge graph · incidents & remediations

Every incident, ATT&CK technique, indicator, host and the remediation that neutralized it — shared across the whole fleet. Agents query this graph before they remediate, reusing a proven playbook instead of re-deriving it. Hover a node for detail, click to focus its neighborhood, drag to rearrange, scroll to zoom.

No knowledge yet — incidents and their remediations populate the graph as the fleet handles them.
🛡️Data protection · redaction & spend

Every entity attribute, command line and event payload is scrubbed of secrets & PII before it leaves a node for the reasoning gateway, and each node runs a hard token budget so reasoning cost can never run away.

Pushed to every node on its next poll. 0 = unlimited. Raising or lowering the cap never resets accrued usage.
Loading…
Show what redaction does to a sample command line
🗄️Data, retention & long-term archive

The telemetry lifecycle, fleet-wide: how long the hot store keeps events / incidents / audit, whether events stream to your SIEM, and long-term archive to an S3 bucket (rehydrate on demand). Retention & archive are pushed to every node on its next poll. Secrets are write-only — a blank field keeps the stored value.

Hot-store retention · days (0 = keep forever)



Fleet-wide hot store (hub) · cross-fleet search


The hub polls every node's events into one searchable store (Fleet Management → Fleet telemetry). Floor 0 = ingest everything.
Customer SIEM push · CEF/syslog + Splunk HEC / Sentinel
S3 long-term archive
Rehydrate archived telemetry



✦Getting started · setup wizard

Re-run the first-run onboarding any time — secure the console, set the license & AI gateway key, and grab the fleet enrollment one-liner.

🔑License · this dashboard

The hub validates its own cp_ license key against Access8 (fail-open). Set it here and the badge, the Analyst, and the gateway all pick it up immediately — no restart, no editing the service. It persists across restarts.

🧠Models · fleet-wide

Which gateway model each layer uses, pushed to every node. The remediation agent does the hardest reasoning (investigate → find the root cause → act → verify) — keep it on a strong reasoning tier.

Model provider · bring your own key

Use the managed Aura gateway, or point reasoning at any OpenAI-compatible endpoint (OpenAI, Azure OpenAI, a local vLLM / Ollama) with your own API key — pushed to every node. Keys are stored on the hub, sent only to nodes, and never shown here.

🧾Audit trail · admin hub

Every operator/admin action taken through this hub — approvals, denials, dispatches, license changes, autonomy toggles, and model/config changes. Append-only.

No hub actions recorded yet.
👤Access & identity · admin
Single sign-on (WorkOS AuthKit)

Connect your IdP + Directory Sync in WorkOS; users get roles from their AD groups. Secrets are stored encrypted (blank a secret field to keep the current value).

Local accounts (built-in RBAC)

For when SSO/SCIM isn't used. Create accounts and assign roles directly. Adding the first account turns auth on.

No local accounts.
◆SOAR · Playbook operationsOpen the tab to load playbooks
Select a playbook
Durable, version-pinned response workflows.
Published workflow—
Choose a published playbook to inspect its steps.
Autonomous executionAuthorization and activation are deliberately separateNot authorized

1 · Admin authorization

Authorize the exact immutable version and its safety envelope.

2 · Trigger activation

A binding chooses shadow, automatic, or paused behavior.

3 · Tenant emergency control

Autonomous starts are enabled for this tenant.
Shadow runs propose a plan without scheduling Temporal activities. Automatic runs still stop for approval when the authorization envelope requires it.
Runs0
No runs yet.
Run inspection & audit
Select a run to inspect step state, approvals, and the append-only audit trail.