Security operations on autopilot.
Detect. Investigate. Remediate. Automatically.
ProPera is an AI-powered security operations platform built around Microsoft Defender for Endpoint - unified with Defender XDR, Microsoft Sentinel (SIEM/SOAR), Intune, Purview, Secure Score and Microsoft Graph. It turns your SOC's manual playbooks into governed, auditable automation: detection, investigation, MITRE ATT&CK mapping, risk scoring, AI analysis, approval-gated remediation and continuous compliance - all from one console.
One platform. Every Microsoft security signal. Full automation.
ProPera is purpose-built to remove manual security operations. It connects to the Microsoft security stack, correlates telemetry, maps activity to MITRE ATT&CK, scores risk, investigates with AI, and executes remediation through governed automation policies.
Defender for Endpoint first
MDE is the primary security engine: Endpoints, alerts, incidents, vulnerabilities, exposure and response actions - surfaced and automated in one console.
Automation, not scripting
No registry edits, no ASR rule scripts, no manual Intune policy juggling. Build WHEN/THEN automation policies with dry-run, approval and emergency modes.
AI Security Analyst
Attack paths, risk scores, MITRE mapping and recommended responses - generated from real evidence, with honest confidence levels. Never claims malicious without proof. Surfaces SIEM-relevant signals from Defender, Sentinel and audit logs in one view.
Advanced Hunting (SIEM queries)
Full KQL editor with query history, saved & scheduled hunts, charts, export - and one-click conversion into detection rules or automation triggers. Write SIEM-grade detection logic across your entire Microsoft security stack.
MITRE ATT&CK engine
Every alert, evidence item and incident mapped to tactics, techniques and sub-techniques - with heatmaps, attack maps and technique-to-automation linking.
Governed & auditable
Every action logged with actor, reason, approval, before/after state and rollback info. Role-based access for analysts, admins, auditors and viewers.
From detection to remediation - end to end, governed
Every automation supports four modes: Disabled, Recommend, Approval required, Automatic and Emergency automatic. Destructive actions are never automatic by default.
Incident & alert triage
Assign, classify, investigate, run automation, create Sentinel incidents, notify Teams.
Automated remediation
Isolate Endpoints, run AV scans, collect packages, block indicators, stop processes - approval-gated.
Vulnerability automation
CVE → affected Endpoints → risk → remediation plan → approval → remediation → verification.
Secure Now
Secure Score and recommendations with one-click governed remediation workflows and verification.
Dry run first
See exactly what an automation WOULD do - isolate 3 Endpoints, notify Teams, create 1 ticket - before any action.
Approval workflow
Recommendation → risk analysis → approval request → SOC analyst approve/reject → execute → verify → audit.
Detection rules
Turn hunting queries into scheduled detections with automated response triggers.
Background workers
Continuous sync of incidents, vulnerabilities, Secure Score, Sentinel and automation evaluation.
From detection to verified action — autonomously
ProPera doesn't just detect problems. It fixes them, verifies the fix, and provides the evidence. The Orchestration layer turns your SOC from reactive to autonomous.
Remediation Command Centre
Unified real-time view of all remediation activity: active, awaiting approval, completed, failed. Verification engine pass rates and rollback success rates.
Fix Everything
Analyse all open issues, categorise by fixability, then auto-remediate safe issues. Critical/high issues queued for approval. Dry-run preview first.
Verification Engine
Post-remediation verification: version checks, service health, vulnerability rescans, config checks. Never marks resolved without proof.
Evidence Vault
Generate audit evidence packages for CIS, ISO 27001, NIST, SOC 2, PCI DSS, NZISM. SHA-256 checksummed, filterable by framework.
Playbooks (Automation Studio)
Version-controlled workflows with triggers, conditions, steps. Trust scores from execution history. Draft → Publish → Execute lifecycle.
Asset Digital Twin
Complete contextual view: hardware, OS, apps, ports, vulns, dependencies, impact analysis. If it fails, you know what's affected.
Executive Risk Score
Unified 0-100 enterprise risk from live data. ROI dashboard: hours saved, cost savings, automation rate. All metrics dynamic.
Rollback Engine
Enterprise rollback for supported actions. Before/after state, rollback status (SUPPORTED/UNSUPPORTED/FAILED), full audit trail.
Notifications
Teams, Slack, email, webhooks. Event-type and severity filtering. Rich cards with color coding. Delivery tracking.
Deep Microsoft coverage - with optional third-party extension
Microsoft Defender for Endpoint is the primary security engine. Everything else extends the platform. Connect live with your Microsoft tenant, or explore instantly in Demo Mode.
Intune
Device compliance, managed Endpoints and policy context from Microsoft Intune - surfaced alongside MDE device data.
Purview
Compliance posture, data-loss-prevention context and audit signals from Microsoft Purview in the same console.
Sentinel (SIEM / SOAR)
Microsoft Sentinel serves as your SIEM and SOAR engine. ProPera syncs incidents both ways, runs analytics rules, executes hunting queries and correlates automation workflows - turning raw logs into actionable intelligence.
Extend further
Teams, Slack, ServiceNow, Jira, PagerDuty, VirusTotal, AbuseIPDB and OTX - clearly labeled as third-party. SIEM-ready: forward alerts, indicators and enrichment data to your SIEM of choice.
Continuous compliance - the ProPera model, built in
A continuous control-monitoring model: control catalogs mapped to real platform evidence, automatically re-assessed as your environment changes. No manual evidence collection spreadsheets.
Control catalogs
ISO 27001, NIST CSF, CIS v8 and Essential Eight control libraries with mapped evidence from live platform data.
Automated evidence
Evidence is collected automatically: audit logs, automation runs, approvals, RBAC, secure score and integration health.
Continuous re-assessment
Control status recomputed as data changes - remediation closes gaps, evidence stays fresh, reports stay current.
Bulletproof by design
Entra ID auth
OAuth 2.0 with Entra ID, optional per-tenant SSO, client secret or certificate, managed identity support, MFA enforcement.
Role-based access
Administrator, Security Admin, SOC Analyst, Analyst, Automation Admin, Auditor, Viewer and Platform Admin.
Secure by default
Secrets never hard-coded or logged. HTTPS, CSRF protection, secure headers, rate limiting, input validation.
Multi-tenant SaaS
Isolated customer workspaces with per-tenant credentials, plans and usage limits. Sell security as a service.
Relational database
Postgres in production (SQLite in demo), full migrations, Endpoints, incidents, alerts, vulnerabilities, audit logs.
Containerized
Frontend, backend, worker, database and Redis via docker-compose - ready for Azure deployment.
Live status
System status panel with database, worker, mode and API health on every page. Public status page included.
OpenAPI
Full REST API with OpenAPI documentation for every module.
Put your Microsoft security on autopilot
Explore the full platform right now - no Microsoft tenant required. When you're ready, connect your tenant and ProPera starts working against your real environment.