Architecture
01Why the storage story is deliberately split
PostgreSQL is the active system of record today. ClickHouse and Neo4j are the scale path for high-volume telemetry and graph queries once a deployment actually needs that shape.
Observability instrument
1000 Beacons is a security observability platform for teams using Microsoft Sentinel and Defender XDR. It connects telemetry and incidents into an inspectable evidence map so analysts can trace sources, understand relationships, assess confidence, and decide what to do next.
01
Keep source truth
Every beacon remains traceable to the tool that produced it.
02
Prove relationships
Edges form only when timing, identity, and behavior support them.
03
Lower the load
Teams get a case narrative instead of another alert pile.
ID selected
Identity path elevated
Selected evidence
Identity path elevated
Session, device, and role changes converge into a single route.
source ID
confidence 0.84
Section 01 / Product posture
The product should show signal branching into evidence, triage, and coverage instead of hiding the work behind a finished score.
$
> identity + endpoint + cloud agree
Section 02 / Event resolution
Impossible travel observed
Identity
Unsigned process spawned
Endpoint
Privilege boundary touched
Cloud
Lookalike sender matches session
Raw beacons remain inspectable, timestamped, and source-bound.
Relationships are weighted before they become a case.
Contradictions lower confidence instead of being hidden.
Human action is suggested with the evidence attached.
Section 03 / Emergence
The console should never ask an analyst to trust a finished score without showing the route that produced it.
source truth
original payload kept
tenant stamped
time window set
common shape
schema applied
source table retained
entity ids attached
linked context
identity reused
device agrees
conflicts surfaced
human accountable
case narrative built
rollback noted
audit written
Section 04 / Operator view
Every conclusion can be opened, challenged, and traced back to the beacons that produced it.
Live now
Postgres-backed tenants, incidents, assets, audit events, onboarding validation, signed web-to-API identity, Hunt Ledger proof-of-work surface.
Implemented path
Connector ingestion, telemetry envelopes, graph rebuild, tenant-scoped realtime, nightly deterministic hunts, Test Fire breach simulation, governed automation playbooks, and operational observability over the same telemetry.
Deployment proof
ClickHouse and Neo4j should be proven under a design-partner environment before marketing them as the default runtime.
Case confidence
84%
tenant scoped
audit ready
Proof rail
Source rows stay linked to each claim.
Contradictions lower confidence visibly.
Response actions wait for role checks and approval.
Section 05 / Onboarding
Workspace creation rejects personal, disposable, reserved, and shared role mailboxes.
The company domain is attached to the organization and queued for verification before production activation.
Sentinel, Defender XDR, identity, cloud, and endpoint access are reviewed before telemetry moves.
Operators enter incidents, integrations, evidence review, and reporting with tenant-scoped realtime updates.
The onboarding path rejects personal email, temporary domains, reserved domains, and shared role accounts. The backend enforces the same rules and records a domain claim for verification.
Section 06 / Architecture
$
> 04 source events
Inbound queue
source-native
Signed envelope
{
tenant_id: attached,
source_table: attached,
observed_at: attached,
raw_payload: attached,
}
Evidence window / 15m
3 relationships agree
Operator case
.87INC-2047
Identity, endpoint, and cloud agree.
recommended next move
Review evidence route
human approval required
Section 07 / Trust posture
The product story should expose its constraints as clearly as it exposes its ambition.
The console should not blur demo data with real detections. Empty states stay honest until connectors and the control plane are live.
Containment and response flows need approval, audit evidence, and rollback paths. The system can recommend; humans stay accountable.
The architecture is strongest when customers can keep sensitive logs, identity records, graph data, and evidence trails in their own environment.
Section 08 / Hunt ledger
Deterministic overnight checks compare threat intel and historical telemetry. The console shows what was checked, what was found, and what was proposed for approval — not silent auto-fix. Hunt Ledger is continuous hunting and proof of work; Automation is the playbook layer that responds after a case exists.
01
Every configured cross-check records events inspected, disposition, and coverage — even when nothing fires.
02
Findings stay tied to evidence events, entities, and severity so analysts can trace the route.
03
Response actions remain gated. The ledger proposes; operators approve, audit, and roll back.
Section 09 / Decision trace
1000Beacons is designed around source truth, visible relationships, confidence, contradiction, and reversible action. The system does not ask an analyst to trust a mystery score; it shows the route from raw telemetry to a defensible decision.
01
Less context switching
02
Evidence stays attached
03
Actions stay accountable
01
Preserve raw source truth.
02
Explain why beacons belong together.
03
Measure confidence and contradiction.
04
Suggest action with a rollback path.
Section 10 / Field notes
Architecture
01PostgreSQL is the active system of record today. ClickHouse and Neo4j are the scale path for high-volume telemetry and graph queries once a deployment actually needs that shape.
Connectors
02The first connector path focuses on Sentinel and Defender XDR because that is where many teams already work. The data model stays source-neutral.
Test Fire
03Breach-and-attack simulation injects a labeled synthetic attack, runs the real detection engine, and scores which detectors actually fired — never a live containment, never disguised as production.
Observability
04The same beacons that feed detection also read as operational health — ingest throughput, connector uptime, pipeline lag, silent sources — with no new agents and no new collection.
Hunt ledger
05Nightly hunts cross-check intel and telemetry, then leave a morning ledger of checked, found, and proposed items — never silent auto-fix.
Section 11 / Resolution
A complete picture should feel calmer: source truth, relationships, confidence, and action in one inspectable view.
Privacy controls
We use necessary cookies to keep the site working. Optional analytics help us understand which product pages are useful. Marketing cookies stay off unless you allow them.