Available now · connects to your Microsoft security stack

Security operations on autopilot.
Detect. Investigate. Remediate. Automatically.

ProPera is an AI-powered security operations platform built around Microsoft Defender for Endpoint - unified with Defender XDR, Microsoft Sentinel (SIEM/SOAR), Intune, Purview, Secure Score and Microsoft Graph. It turns your SOC's manual playbooks into governed, auditable automation: detection, investigation, MITRE ATT&CK mapping, risk scoring, AI analysis, approval-gated remediation and continuous compliance - all from one console.

No manual registry / ASR / Intune scripting Destructive actions require approval by default Full audit trail · ISO 27001 · NIST CSF · CIS v8 SIEM-ready: Sentinel integration with real-time log correlation
224
API endpoints
42
ML model families
31
Feature definitions
169
MITRE ATT&CK techniques
10
CTI feed sources
16
Compliance frameworks
44
Orchestration endpoints
100%
Audit coverage
What is ProPera

One platform. Every Microsoft security signal. Full automation.

ProPera is purpose-built to remove manual security operations. It connects to the Microsoft security stack, correlates telemetry, maps activity to MITRE ATT&CK, scores risk, investigates with AI, and executes remediation through governed automation policies.

🛡️

Defender for Endpoint first

MDE is the primary security engine: Endpoints, alerts, incidents, vulnerabilities, exposure and response actions - surfaced and automated in one console.

MDEDefender XDRVulnerability Mgmt
🤖

Automation, not scripting

No registry edits, no ASR rule scripts, no manual Intune policy juggling. Build WHEN/THEN automation policies with dry-run, approval and emergency modes.

SOARPlaybooksApprovals
🧠

AI Security Analyst

Attack paths, risk scores, MITRE mapping and recommended responses - generated from real evidence, with honest confidence levels. Never claims malicious without proof. Surfaces SIEM-relevant signals from Defender, Sentinel and audit logs in one view.

AIInvestigationSIEM
🔎

Advanced Hunting (SIEM queries)

Full KQL editor with query history, saved & scheduled hunts, charts, export - and one-click conversion into detection rules or automation triggers. Write SIEM-grade detection logic across your entire Microsoft security stack.

KQLDetection rulesSIEM
🗺️

MITRE ATT&CK engine

Every alert, evidence item and incident mapped to tactics, techniques and sub-techniques - with heatmaps, attack maps and technique-to-automation linking.

169 techniquesHeatmap
📜

Governed & auditable

Every action logged with actor, reason, approval, before/after state and rollback info. Role-based access for analysts, admins, auditors and viewers.

RBACAudit trail
Automation engine

From detection to remediation - end to end, governed

Every automation supports four modes: Disabled, Recommend, Approval required, Automatic and Emergency automatic. Destructive actions are never automatic by default.

01
Detect
MDE alert / incident
02
Investigate
Evidence + timeline
03
Map
MITRE ATT&CK
04
Score
Risk 0–100
05
Decide
Policy match
06
Approve
SOC approval gate
07
Remediate
Isolate, scan, block
08
Verify & audit
Post-check + log
🚨

Incident & alert triage

Assign, classify, investigate, run automation, create Sentinel incidents, notify Teams.

🔧

Automated remediation

Isolate Endpoints, run AV scans, collect packages, block indicators, stop processes - approval-gated.

🐞

Vulnerability automation

CVE → affected Endpoints → risk → remediation plan → approval → remediation → verification.

🏅

Secure Now

Secure Score and recommendations with one-click governed remediation workflows and verification.

🧪

Dry run first

See exactly what an automation WOULD do - isolate 3 Endpoints, notify Teams, create 1 ticket - before any action.

🖊️

Approval workflow

Recommendation → risk analysis → approval request → SOC analyst approve/reject → execute → verify → audit.

📋

Detection rules

Turn hunting queries into scheduled detections with automated response triggers.

🔄

Background workers

Continuous sync of incidents, vulnerabilities, Secure Score, Sentinel and automation evaluation.

Orchestration & Automation

From detection to verified action — autonomously

ProPera doesn't just detect problems. It fixes them, verifies the fix, and provides the evidence. The Orchestration layer turns your SOC from reactive to autonomous.

🎯

Remediation Command Centre

Unified real-time view of all remediation activity: active, awaiting approval, completed, failed. Verification engine pass rates and rollback success rates.

Real-timeKPIs

Fix Everything

Analyse all open issues, categorise by fixability, then auto-remediate safe issues. Critical/high issues queued for approval. Dry-run preview first.

One-clickSafe auto-fix

Verification Engine

Post-remediation verification: version checks, service health, vulnerability rescans, config checks. Never marks resolved without proof.

Evidence-basedAudit trail
📦

Evidence Vault

Generate audit evidence packages for CIS, ISO 27001, NIST, SOC 2, PCI DSS, NZISM. SHA-256 checksummed, filterable by framework.

ComplianceAudit-ready
📋

Playbooks (Automation Studio)

Version-controlled workflows with triggers, conditions, steps. Trust scores from execution history. Draft → Publish → Execute lifecycle.

VersionedTrust Score
🖥️

Asset Digital Twin

Complete contextual view: hardware, OS, apps, ports, vulns, dependencies, impact analysis. If it fails, you know what's affected.

Dependency mapImpact
📈

Executive Risk Score

Unified 0-100 enterprise risk from live data. ROI dashboard: hours saved, cost savings, automation rate. All metrics dynamic.

0-100 scoreROI
↩️

Rollback Engine

Enterprise rollback for supported actions. Before/after state, rollback status (SUPPORTED/UNSUPPORTED/FAILED), full audit trail.

RecoverableTracked
🔔

Notifications

Teams, Slack, email, webhooks. Event-type and severity filtering. Rich cards with color coding. Delivery tracking.

Multi-channelFiltered
Integrations

Deep Microsoft coverage - with optional third-party extension

Microsoft Defender for Endpoint is the primary security engine. Everything else extends the platform. Connect live with your Microsoft tenant, or explore instantly in Demo Mode.

Microsoft Defender for Endpoint
Defender XDR
Defender Vulnerability Mgmt
Microsoft Sentinel (SIEM)
Microsoft Intune
Microsoft Purview
Microsoft Entra ID
Microsoft Graph
Secure Score
Microsoft Teams
💻

Intune

Device compliance, managed Endpoints and policy context from Microsoft Intune - surfaced alongside MDE device data.

🛡️

Purview

Compliance posture, data-loss-prevention context and audit signals from Microsoft Purview in the same console.

🛰️

Sentinel (SIEM / SOAR)

Microsoft Sentinel serves as your SIEM and SOAR engine. ProPera syncs incidents both ways, runs analytics rules, executes hunting queries and correlates automation workflows - turning raw logs into actionable intelligence.

🔗

Extend further

Teams, Slack, ServiceNow, Jira, PagerDuty, VirusTotal, AbuseIPDB and OTX - clearly labeled as third-party. SIEM-ready: forward alerts, indicators and enrichment data to your SIEM of choice.

Compliance & assurance

Continuous compliance - the ProPera model, built in

A continuous control-monitoring model: control catalogs mapped to real platform evidence, automatically re-assessed as your environment changes. No manual evidence collection spreadsheets.

ISO 27001
98%
Controls continuously monitored
NIST CSF 2.0
96%
Govern · Identify · Protect · Detect · Respond · Recover
CIS Controls v8
94%
18 control families mapped
Essential Eight
92%
ACSC mitigation strategies
Azure Marketplace Ready
100%
Containerized deployment, ARM + compose templates
📊

Control catalogs

ISO 27001, NIST CSF, CIS v8 and Essential Eight control libraries with mapped evidence from live platform data.

🔬

Automated evidence

Evidence is collected automatically: audit logs, automation runs, approvals, RBAC, secure score and integration health.

📉

Continuous re-assessment

Control status recomputed as data changes - remediation closes gaps, evidence stays fresh, reports stay current.

Security & trust

Bulletproof by design

🔐

Entra ID auth

OAuth 2.0 with Entra ID, optional per-tenant SSO, client secret or certificate, managed identity support, MFA enforcement.

👥

Role-based access

Administrator, Security Admin, SOC Analyst, Analyst, Automation Admin, Auditor, Viewer and Platform Admin.

🛡️

Secure by default

Secrets never hard-coded or logged. HTTPS, CSRF protection, secure headers, rate limiting, input validation.

🏢

Multi-tenant SaaS

Isolated customer workspaces with per-tenant credentials, plans and usage limits. Sell security as a service.

🗄️

Relational database

Postgres in production (SQLite in demo), full migrations, Endpoints, incidents, alerts, vulnerabilities, audit logs.

⚙️

Containerized

Frontend, backend, worker, database and Redis via docker-compose - ready for Azure deployment.

🩺

Live status

System status panel with database, worker, mode and API health on every page. Public status page included.

🧾

OpenAPI

Full REST API with OpenAPI documentation for every module.

Put your Microsoft security on autopilot

Explore the full platform right now - no Microsoft tenant required. When you're ready, connect your tenant and ProPera starts working against your real environment.