Observability instrument

1000 Beacons Security observability. See why. Not just what.

1000 Beacons is a security observability platform for teams using Microsoft Sentinel and Defender XDR. It connects telemetry and incidents into an inspectable evidence map so analysts can trace sources, understand relationships, assess confidence, and decide what to do next.

01

Keep source truth

Every beacon remains traceable to the tool that produced it.

02

Prove relationships

Edges form only when timing, identity, and behavior support them.

03

Lower the load

Teams get a case narrative instead of another alert pile.

Beacon field
confidence map

ID selected

Identity path elevated

conf 0.84 2.8k

Selected evidence

Identity path elevated

Session, device, and role changes converge into a single route.

source ID

confidence 0.84

Section 01 / Product posture

The interface should explain the security story while it moves.

Evidence motion

A command layer is credible only when the route is visible.

The product should show signal branching into evidence, triage, and coverage instead of hiding the work behind a finished score.

follow the outcome

$

> identity + endpoint + cloud agree

Security operator Security incident INC-2047 / LIVE

Section 02 / Event resolution

Telemetry becomes evidence when it keeps its context.

Live event chain
trace_4D9A
12:04:11

Impossible travel observed

Identity

0.41
12:05:36

Unsigned process spawned

Endpoint

0.58
12:07:02

Privilege boundary touched

Cloud

0.72
12:09:44

Lookalike sender matches session

Email

0.84
Reasoning workbench
01

Observed

Raw beacons remain inspectable, timestamped, and source-bound.

02

Correlated

Relationships are weighted before they become a case.

03

Validated

Contradictions lower confidence instead of being hidden.

04

Recommended

Human action is suggested with the evidence attached.

Section 03 / Emergence

The product is a route, not a pile of tiles.

Signal route

Every hop changes the evidence, and every hop is inspectable.

The console should never ask an analyst to trust a finished score without showing the route that produced it.

01

Raw beacon

source truth

original payload kept

tenant stamped

time window set

02

Normalized envelope

common shape

schema applied

source table retained

entity ids attached

03

Evidence graph

linked context

identity reused

device agrees

conflicts surfaced

04

Approved action

human accountable

case narrative built

rollback noted

audit written

Section 04 / Operator view

The console should read like a case file under motion.

Investigation timeline

No fake certainty. No black box.

Every conclusion can be opened, challenged, and traced back to the beacons that produced it.

Live now

Postgres-backed tenants, incidents, assets, audit events, onboarding validation, signed web-to-API identity, Hunt Ledger proof-of-work surface.

Implemented path

Connector ingestion, telemetry envelopes, graph rebuild, tenant-scoped realtime, nightly deterministic hunts, Test Fire breach simulation, governed automation playbooks, and operational observability over the same telemetry.

Deployment proof

ClickHouse and Neo4j should be proven under a design-partner environment before marketing them as the default runtime.

Case confidence

84%

tenant scoped

audit ready

Identity drift +22m
Endpoint execution +33m
Cloud privilege touch +44m
Outbound SaaS session +55m

Proof rail

Source rows stay linked to each claim.

Contradictions lower confidence visibly.

Response actions wait for role checks and approval.

Section 05 / Onboarding

Private onboarding starts with verified company identity.

Workspace activation
01

Business email gate

Workspace creation rejects personal, disposable, reserved, and shared role mailboxes.

02

Domain claim

The company domain is attached to the organization and queued for verification before production activation.

03

Connector consent

Sentinel, Defender XDR, identity, cloud, and endpoint access are reviewed before telemetry moves.

04

Console unlock

Operators enter incidents, integrations, evidence review, and reporting with tenant-scoped realtime updates.

Console handoff

A workspace begins with a named owner, not an alias.

The onboarding path rejects personal email, temporary domains, reserved domains, and shared role accounts. The backend enforces the same rules and records a domain claim for verification.

01 Official company email required
02 Domain claim queued for verification
03 Connector consent before telemetry movement
04 Operator access scoped to tenant membership

Section 06 / Architecture

Evidence keeps its custody.

live custody shell
CASE-2047 / REPLAY

$

> 04 source events

Inbound queue

ID signin.risk 12:04:11
EDR process.spawn 12:05:36
CLD role.change 12:07:02
MSG sender.match 12:09:44

source-native

Signed envelope

{

tenant_id: attached,

source_table: attached,

observed_at: attached,

raw_payload: attached,

}

signature verified

Evidence window / 15m

Identity--
Endpoint--
Cloud--
Message--

3 relationships agree

Operator case

.87

INC-2047

Identity, endpoint, and cloud agree.

recommended next move

Review evidence route

human approval required

EVT-2047.1 Receive
Custody ledger
evidence custody intact
owner / northstar
streaming

Section 07 / Trust posture

Enterprise polish means saying what the product will not pretend to do.

Non-negotiables

Trust is built by refusing shortcuts in public.

The product story should expose its constraints as clearly as it exposes its ambition.

01

No fake live telemetry

The console should not blur demo data with real detections. Empty states stay honest until connectors and the control plane are live.

02

No autonomous mystery actions

Containment and response flows need approval, audit evidence, and rollback paths. The system can recommend; humans stay accountable.

03

No vendor lake assumption

The architecture is strongest when customers can keep sensitive logs, identity records, graph data, and evidence trails in their own environment.

Section 08 / Hunt ledger

Quiet nights still leave a ledger.

Morning proof of work

Nightly hunts cross-check intel and telemetry — then wait for humans.

Deterministic overnight checks compare threat intel and historical telemetry. The console shows what was checked, what was found, and what was proposed for approval — not silent auto-fix. Hunt Ledger is continuous hunting and proof of work; Automation is the playbook layer that responds after a case exists.

01

Checked

Every configured cross-check records events inspected, disposition, and coverage — even when nothing fires.

02

Found

Findings stay tied to evidence events, entities, and severity so analysts can trace the route.

03

Proposed for approval

Response actions remain gated. The ledger proposes; operators approve, audit, and roll back.

Section 09 / Decision trace

Built to make complex investigations feel readable.

Analyst load model

The interface reduces the number of things an operator must hold in memory.

1000Beacons is designed around source truth, visible relationships, confidence, contradiction, and reversible action. The system does not ask an analyst to trust a mystery score; it shows the route from raw telemetry to a defensible decision.

01

Less context switching

02

Evidence stays attached

03

Actions stay accountable

01

Observed

Preserve raw source truth.

timestamptenantsource table

02

Correlated

Explain why beacons belong together.

identitydevicetiming

03

Validated

Measure confidence and contradiction.

confidenceconflictrisk reason

04

Recommended

Suggest action with a rollback path.

approvalauditrollback

Section 10 / Field notes

The product has a point of view.

Architecture

01

Why the storage story is deliberately split

PostgreSQL is the active system of record today. ClickHouse and Neo4j are the scale path for high-volume telemetry and graph queries once a deployment actually needs that shape.

Connectors

02

Microsoft-first, not Microsoft-only

The first connector path focuses on Sentinel and Defender XDR because that is where many teams already work. The data model stays source-neutral.

Test Fire

03

Green checkmarks are not proof

Breach-and-attack simulation injects a labeled synthetic attack, runs the real detection engine, and scores which detectors actually fired — never a live containment, never disguised as production.

Observability

04

Security telemetry has a second job

The same beacons that feed detection also read as operational health — ingest throughput, connector uptime, pipeline lag, silent sources — with no new agents and no new collection.

Hunt ledger

05

Proof of work without autonomy theater

Nightly hunts cross-check intel and telemetry, then leave a morning ledger of checked, found, and proposed items — never silent auto-fix.

Section 11 / Resolution

See the complete picture.

A complete picture should feel calmer: source truth, relationships, confidence, and action in one inspectable view.

Start private onboarding

Privacy controls

Your visit should be as controlled as your telemetry.

We use necessary cookies to keep the site working. Optional analytics help us understand which product pages are useful. Marketing cookies stay off unless you allow them.