Platform

Prove your alerts actually work

PurveX runs real attack tests in your environment and shows which alerts fired, which missed, and why.

PurveXDetection tests

T1059.001ExecutionWIN-TEST01

PowerShell run by a user

Not run
  1. Attack runs
  2. Log arrives
  3. Log is read
  4. Rule matches
  5. Alert fires

Run this test to see if the alert fires.

Coverage: 0 of 6 alerts proven
Example results
Works with
  • Splunk
  • Elastic
  • Microsoft Sentinel
  • Atomic Red Team
  • MITRE ATT&CK

Stop guessing whether your alerts work

Most teams find out a detection is broken during a real attack. PurveX tells you first.

Know which alerts fire

Test your detections against real attack behavior instead of assuming they work.

  • PowerShell run by a userFired
  • Password theft from memoryMissed
  • Scheduled task createdFired

See exactly where it broke

A miss is traced to the stage that failed, with a suggested fix.

  1. The log never reached your SIEM
  2. The log arrived but was not read
  3. No rule matched it
  4. The alert never reached anyone

See your coverage

A heatmap across MITRE ATT&CK shows what is covered, what is missed, and what is untested.

  • Fired
  • Missed
  • Not tested

Prove progress

Every run is scored and kept, so reports show improvement with evidence behind it.

How a test works

Four steps from install to a result you can act on.

  1. 1Connect your SIEM

    Read-only access to Splunk, Elastic, or Microsoft Sentinel.

  2. 2Pick an attack

    Choose from the Atomic Red Team library, mapped to MITRE ATT&CK.

  3. 3Run the test

    A test runner you control plays the attack in your environment.

  4. 4Read and fix

    See what fired, where a miss broke, and how to fix it.

Built for the whole security team

Everyone reads the same result, from the person writing rules to the person reporting risk.

  • Detection engineers

    See exactly which stage failed and fix the rule with confidence.

  • SOC managers

    Know which alerts your analysts can trust, and which need work.

  • Security leaders

    Show real coverage and progress to the board, backed by evidence.

Safe to run in your environment

PurveX runs on your own server and only asks your SIEM one question: did the alert fire?

  • Read-only on your SIEM

    PurveX only checks whether an alert fired. It never changes your rules.

  • Your logs stay put

    No raw logs, personal data, or case notes are copied out of your SIEM.

  • Production is opt-in

    Tests only run on production machines when you turn that on.

  • Every run is recorded

    A full audit trail shows who ran what, where, and when.

Your environment
PurveXSelf-hosted on your server Every run recorded
Your SIEMSplunk, Elastic, or Sentinel
Test machineA runner you choose

Stays in your SIEMRaw logs, personal data, and case notes are never copied out.

Start free. Upgrade when your team grows.

Same software on both plans. Paid removes the limits.

Free

$0self-hosted

  • Full Atomic Red Team library, mapped to ATT&CK
  • Splunk, Elastic, or Microsoft Sentinel
  • Coverage heatmap
  • Up to 3 team members
  • 1 test runner, 3 runs a day
  • 30 days of audit history
Get started free
Paid

$99per month

  • Everything in Free
  • Unlimited team members
  • Multiple runners, unlimited runs
  • Scheduled, recurring tests
  • Detection-as-code, synced from git
  • Unlimited audit history
Start with Paid

Find out what your alerts miss

Install free with one command, or book a call and we will walk you through it.

Hold30 min
Open conversation