UltraViolet Cyber has launched Equinox, an AI-assisted detection engineering platform designed to identify gaps across customers’ existing security tools and expand mapped threat coverage without adding unnecessary alert volume.
Equinox maps customer-specific detection gaps
In its official announcement, UltraViolet Cyber highlighted how security teams may have thousands of detections available across their security information and event management (SIEM) and endpoint detection and response (EDR) platforms.
However, having those rules available does not necessarily mean they provide effective coverage for a particular environment.
UltraViolet Cyber is targeting that gap with Equinox, a proprietary platform developed and operated by its Threat Intelligence & Detection Engineering (TIDE) team.
Equinox inventories a customer’s existing detections and available log sources, maps them against MITRE ATT&CK and MITRE ATLAS, and identifies where coverage exists and where gaps remain. UltraViolet said the automated analysis takes under 30 minutes, compared with a process that can otherwise take weeks.
Speaking with Channel Insider, Dan Gittis, director of the TIDE team at UltraViolet Cyber, said the gaps identified can vary considerably between organizations.
“It varies from one customer to another. We could audit one customer and see that they have very little detection coverage for a MITRE Tactic, just to find that the next customer has very good detection coverage for that same Tactic,” Gittis said.
According to Gittis, gaps can stem from insufficient telemetry, limited threat intelligence for mapping attacker behavior, or detections that already exist but were never enabled.
UltraViolet reports coverage gains without more SOC alerts
According to UltraViolet, they had one customer trial in which an Equinox review initially identified mapped coverage for 59 of 222 techniques, or 26.6%. After implementing recommended detections, that increased to 136 of 222 techniques, or 61.3%.
The company noted that the 34.7 percentage-point improvement was achieved without increasing SOC alert volume.
Gittis said most of the rules evaluated during the trial generated either no alerts over a 30-day period or only one or two. Noisier rules underwent additional tuning before deployment, while Equinox can also identify existing noisy rules that could be replaced.
Human review remains part of that process. TIDE engineers review, backtest, and approve recommended detections before they are deployed.
“You don’t want to blindly let an AI tool, no matter how sophisticated, mass-enable detections without a human reviewing them,” Gittis said. “If that were the approach, we’d almost certainly see an increase in alert volume, and a substantial one at that.”
The platform is designed to work across multiple security products. SentinelOne, CrowdStrike, Elastic, and Panther are fully integrated today, while Splunk and Microsoft Defender integrations are in development.
Telemetry gaps complicate AI threat detection
UltraViolet is also extending its coverage assessments to MITRE ATLAS, which focuses on threats involving AI and machine learning systems.
Gittis said AI-related threats continue to use many established attacker tactics, techniques, and procedures, but insufficient telemetry can leave organizations unable to detect some of that activity.
“We’re seeing a number of organizations who aren’t sending sufficient log sources to detect some of these behaviors, particularly those tied to ATLAS, to their SIEMs,” Gittis said.
“At the end of the day, we can’t detect what we can’t see.”
Equinox can identify those telemetry gaps alongside missing detections, giving security teams a view of where additional log sources could improve mapped coverage.
Detection assessments create an MSSP opportunity
For MSPs and MSSPs managing multiple customer environments, detection coverage can differ substantially even when customers use similar security technologies.
Gittis pointed to the ability to consolidate coverage information across platforms as one of the practical benefits of the approach.
“Having to go back and forth between platforms and manually map out what coverage is or isn’t there is such a tedious and time-consuming effort,” he said. “So to be able to do this quickly and reliably is a massive benefit for customers.”
For security partners, that type of assessment could provide another way to identify where customers can improve coverage using their existing security stack and where additional telemetry or technology investment may be warranted.
Sophos recently found that 46% of MSPs already act as CISOs for their customers as rising compliance demand creates opportunities for higher-value security services. Read more about how MSPs are expanding their cybersecurity leadership and compliance roles.





