Built for modern SOC teams

Manage security incidents at the speed of threats

Case Sphere gives your team a single pane of glass to triage alerts, investigate cases, track SLA compliance, and respond faster — with AI-powered analysis built in.

Get started free → See it in action
No credit card required
ISO 27001 / OJK ready
Mandatory MFA enforced
8+ SIEM integrations
3×
Faster incident response
99.9%
Platform uptime
8+
SIEM integrations
Everything your SOC needs
From alert ingestion to case closure, Case Sphere covers the full incident lifecycle.

AI-powered case analysis

Powered by Claude (Anthropic), Case Sphere automatically analyzes each incident — summarizing indicators, suggesting MITRE techniques, and recommending next steps.

  • Instant AI summary for every new case
  • Automatic MITRE technique suggestions
  • Recommended investigation steps
  • Natural language threat intelligence
AI analysis — C-011
Internal host 192.168.1.45 conducted a broad port scan across the /24 subnet. The hash matches a known reconnaissance tool. Lateral movement is suspected — isolate host immediately.
T1046 Network Scan T1021 Lateral Move
Recommended actions
1. Isolate WKSTN-042 from network
2. Check for new scheduled tasks
3. Review SMB traffic from this host

Universal SIEM integration

Auto-detect and normalize alerts from all major SIEM platforms with a single API endpoint. Point your SIEM and go — no custom parsers required.

  • Auto-detect Splunk, Elastic, QRadar, Wazuh, Sentinel, Darktrace, CEF, LEEF
  • Single ingest endpoint for all formats
  • Auto-extract observables (IPs, hashes, domains)
  • Auto-promote to case with X-Auto-Promote header
Critical · Wazuh
Ransomware behavior detected
WKSTN-042 · 2 min ago
High · Splunk
Failed login spike — 47× admin
auth.log · 8 min ago
Medium · Elastic
Port scan from 192.168.1.45
network · 22 min ago

SLA monitoring that keeps you honest

Automatic TTR and TFR deadlines per severity level. Visual indicators warn your team before SLAs breach — never miss a response deadline again.

  • Critical: 20 min TTR / 3 hour TFR
  • High: 45 min TTR / 4 hour TFR
  • Medium: 90 min TTR / 12 hour TFR
  • Color-coded alerts as deadlines approach
SLA status — C-011 (Medium)
Time to respond
54 min remaining of 90 min
Time to resolve
9h 50m remaining of 12h
⚠ SLA breach risk — C-009 (Critical)
3 min to TTR deadline

Security-first authentication

Mandatory TOTP-based MFA for every user, no exceptions. Built to satisfy BSSN, OJK, and ISO 27001 A.9.4 authentication requirements out of the box.

  • TOTP (RFC 6238) mandatory for all users
  • Google Authenticator / Authy compatible
  • 8 backup codes per user (single-use)
  • Account lockout after 5 failed attempts
  • Full MFA audit trail
Two-factor authentication
Enter the code from your authenticator app
7
3
8
_
Verify

True multi-tenant architecture

Run multiple client environments from a single deployment. Each organization gets fully isolated cases, alerts, API keys, and dashboards.

  • Per-organization data isolation at query level
  • Switch between clients instantly
  • Separate API keys per organization
  • Independent SIEM feeds per org
  • Perfect for MSSPs
Organization
XYZ Corp 24 cases
Company A 11 cases
Company B 7 cases

MITRE ATT&CK built in

Browse the full ATT&CK matrix and tag techniques directly on cases. Turn individual incidents into strategic threat intelligence over time.

  • Full ATT&CK framework browser
  • Tag techniques directly on cases
  • AI auto-suggests relevant techniques
  • Track tactic trends across your environment
MITRE tags — C-011
T1046Network Service Scanning
T1021Remote Services
T1078Valid Accounts
Tactic frequency this month
Discovery
Lateral Move
Credential
See Case Sphere in action
Click through Dashboard, All cases, SIEM feed, and Case detail to explore the platform.
⚠ 9 SIEM alerts
AD
Dashboard
All cases3
SIEM feed9
Observables
MITRE map
SLA monitor
42
Total cases
↑ 8 this week
3
Critical open
↑ 1 today
94%
SLA compliance
↑ 2% vs last week
18m
Avg response
↓ 4m faster
Cases by day (last 7 days)
Mon
Tue
Wed
Thu
Fri
Sat
Sun
By severity
Critical (7)
High (12)
Medium (15)
Low (8)
42 cases
IDTitleSeverityStatusAssigneeDate
C-011Port scan from internal host MediumIn progress B. SantosoToday
C-010Malware on endpoint — mktg HighOpen A. RahmanToday
C-009Phishing email — exec team CriticalOpen UnassignedYesterday
C-008Brute force — SSH server HighResolved B. Santoso3 days ago
C-007Suspicious outbound DNS MediumResolved A. Rahman5 days ago
9 unreviewed alerts
Ransomware behavior detected — WKSTN-042
Wazuh · Critical · 2 min ago
Failed login spike — admin account (47×)
Splunk · High · 8 min ago
Lateral movement — SMB traffic anomaly
Elastic · High · 15 min ago
Port scan detected from 192.168.1.45
Snort-IDS · Medium · 22 min ago
Unusual outbound data volume — SRV-DB01
Darktrace · Medium · 31 min ago
C-011 Medium In progress B. Santoso
Port scan detected from internal host

Observables / IOC

IP192.168.1.45Suspicious
IP10.0.0.1Clean
Hasha3f9...cc12Malicious
Domaincdn-service.ioSuspicious

Timeline

09:14Case promoted from SIEM alert (Snort-IDS)
09:17Assigned to B. Santoso
09:22Observable 192.168.1.45 checked — suspicious
09:31MITRE T1046 tagged
09:45AI analysis completed

SLA status

Time to respond
54 min of 90 min remaining
Time to resolve
9h 50m of 12h remaining

AI analysis

Internal host 192.168.1.45 conducted a broad port scan across the /24 subnet. Hash matches known recon tool. Lateral movement suspected — isolate host, check scheduled tasks.
T1046 T1021 Lateral move
From alert to closure in four steps
1

Ingest alerts

SIEM pushes alerts via API key. Case Sphere auto-detects the format and normalizes it instantly.

2

Triage & promote

Analysts review the feed and promote high-priority alerts to full investigation cases.

3

Investigate

Add observables, run VirusTotal checks, tag MITRE techniques, assign tasks to the team.

4

Close & report

Resolve the case, review the audit trail, and export findings for compliance reporting.

Works with your existing stack
No rip-and-replace. Case Sphere plugs in alongside your existing security tools.
Splunk
Elastic / Kibana
Microsoft Sentinel
IBM QRadar
Wazuh
Darktrace
VirusTotal
Claude AI (Anthropic)
CEF / LEEF format
Simple, transparent pricing
No hidden fees. No per-alert pricing. Pick a plan and focus on security.
Starter
Free / forever
For small teams getting started with structured incident management.
  • Up to 5 users
  • 1 organization
  • 100 cases / month
  • SIEM integration
  • MFA enforced
Contact me
Enterprise
Custom
For MSSPs and enterprises needing on-premise, SSO, and custom SLAs.
  • Everything in Pro
  • On-premise deployment
  • SSO / SAML
  • Dedicated support
  • ISO 27001 / OJK ready
  • Custom SLA thresholds
Contact me

Ready to modernize your SOC?

Join security teams already using Case Sphere to respond faster, investigate smarter, and stay compliant.

Get started free → Talk to us