Cerebrum One
The shared platform layer: tenants, identity, policy, event movement, data contracts, audit and the operational surfaces that modules build upon.
Cerebrum brings support, observability, detection, threat intelligence, response and institutional memory into a shared, multi-tenant platform.
The shared platform layer: tenants, identity, policy, event movement, data contracts, audit and the operational surfaces that modules build upon.
Help desk, user support, workflows and assisted resolution connected to the larger operational picture.
Ingestion and detection for authentication anomalies, scans, brute force, PowerShell abuse, lateral movement, beaconing and campaign patterns.
Clustering, velocity, promotion thresholds and campaign reasoning built on explicit normalized scoring.
Indicator enrichment with pluggable providers, provenance, caching, tenant keys, audit and error isolation.
Preserving what happened, what worked, what failed and why the organization made the decisions it did.
Scoring is a contract, not a decorative number.
Cerebrum’s mathematical foundation uses explicit ranges: severity from 1–5, normalized values from 0–1, threat scores from 0–100 and non-negative velocity. The platform is being designed to make those meanings consistent across services, detectors and dashboards.
The architecture is intended to accept new event sources, detectors, campaign models, enrichment providers and response actions without turning each addition into a rewrite of the core system.