Response
A fix that can be undone, applied only if you say so again
Turning a finding into a change is an add-on rather than the product, and it is the part of our loop with the thinnest evidence behind it. Both of those are deliberate.
Two properties make this sellable rather than alarming
Every change ships with its rollback
A deny rule, a permission removed, a service disabled, a vulnerable handler switched off — and the exact steps to put it back. A recipe that cannot be reversed is refused when it is built, not when someone runs it.
Nothing fires without a second grant
Containment needs an authority on top of the engagement's own. Without it the proposed action is still shown to a human, in full — withheld, never hidden. You should always be able to see what we would have done.
Applying a change runs through the same path as everything else: your agent, your audit, your kill switch. There is no separate channel with different rules.
Then you run the attack again
A fix you cannot verify is a belief. After a change, you re-run the technique that found the problem — from your own console, against your own baseline — and get back one of three things.
The same technique no longer works. You re-ran it; this is not inference.
It still works. Whatever changed did not change this.
The technique did not actually run this time, so we cannot say. It exists because a run that did no real work must never resolve another run's findings.
Between runs you also get a delta: what is new, what is resolved, what is unchanged. A run that could not do real work reports itself as inconclusive and resolves nothing, because a clean report from a broken run is worse than no report.
Vendor-neutral by construction
Changes are expressed as ordinary automation — a configuration management task, remote execution on a Windows host, or a command against a container. Detection content is exported for several products from one source rule.
We ship apps for Splunk and for Splunk SOAR so results land in the console your analysts already have open. They are a distribution channel, not the price boundary. Tying response to one vendor would contradict our own measurements, since the loop has been run against more than one monitoring product.