Anomaly & Risk Analytics.
Rules-based and unsupervised scoring, on one calibrated axis. Every entity has a score. Every score has an evidence chain.
Illustrative visualisation of the anomaly-scoring pipeline using seeded sample data — nothing is uploaded, and toggling detectors or injecting anomalies only changes what this terminal draws.
The process,
in full.
Rules catch what analysts already know is dangerous. Unsupervised scoring catches what nobody wrote a rule for yet. Both feed a single calibrated score with an evidence chain attached.
Per-entity baseline
A rolling behavioral profile is built per entity — access patterns, connections, volumes — decayed continuously so it tracks the present, not the past.
Dual scoring
Deterministic rules catch known-bad behavior; unsupervised outlier scoring catches what nobody wrote a rule for yet.
Calibrated thresholds
Every score is calibrated against the environment's own noise floor — an "0.94" means the same thing on day one as day one thousand.
Explainable escalation
Every alert ships with its evidence trail: which detectors fired, what changed, and how it compares to the baseline.
Point it at your baseline.
Bring your entity data. X∞RAY will start scoring against its own baseline in the first hour.