Incident response for focused SOC teams

Keep every case together.

Triage signals, coordinate the investigation, govern response actions, preserve evidence, and close with one complete operational record.

Kelpie operations dashboard showing active cases, severity, response metrics, SLA pressure, and recently opened incidents
Operations dashboardFictional demo data

Case operationsQueues, ownership, hand-offs, SLAs, and closure controls.

Investigation & evidenceConnected findings, ATT&CK context, custody, and legal holds.

Human-approved responseGoverned provider actions with separation of duties.

Self-hosted controlRun the platform and keep response data in your environment.

Case operations

The operation stays connected to the incident.

Replace the reconstruction work across tickets, chats, spreadsheets, and consoles. Kelpie keeps ownership, queues, decisions, evidence, tasks, controls, and reporting attached to the case from intake through review.

Kelpie case detail showing incident summary, MITRE ATT&CK techniques, SLA status, case controls, reporting, and playbook actions
Case operations · Summary, controls, reporting, SLA, and playbooks

A complete lifecycle, not another alert queue.

Run each incident through a consistent process while preserving the technical and human decisions that shaped the response.

  • Team queues, saved views, assignments, watchers, and escalations
  • Open, contain, eradicate, recover, close, archive, and restore
  • Structured findings, case relationships, and duplicate detection
  • Configurable closure requirements and privileged overrides
  • Real-time collaboration, mentions, presence, and version-guarded edits
Explore the product map

Product map

The controls a response team needs, in one operating record.

Kelpie covers the work around the alert: coordination, investigation, custody, approvals, closure, reporting, and the feedback loop that improves the next response.

01

Case lifecycle and control

Move incidents from open through containment, eradication, recovery, and governed closure. Track severity, classification, TLP, PAP, confidence, command, source identity, affected services, and SLA state.

02

Queues and team coordination

Manage team queues, assignments, watchers, acknowledgements, hand-offs, waiting reasons, escalations, workload, aging, saved views, and bulk triage without losing the case history.

03

Structured investigation

Connect normalised alerts, entities, observables, evidence, hypotheses, findings, decisions, and case relationships. Correlate, merge, split, and trace an attack story through a typed investigation graph.

04

Evidence governance

Preserve SHA-256 integrity, chain of custody, collections, and legal holds. Scan uploads, quarantine suspicious files, record reasoned overrides, and retain evidence when case records are removed.

05

Playbooks, tasks, and SLAs

Apply ordered timed tasks and reusable templates, or start from a versioned catalogue of 16 common SOC scenarios with evidence guidance, decision points, approval gates, and closure criteria.

06

Governed response actions

Request Cloudflare blocks, Entra user disablement, Defender device isolation, or CrowdStrike host isolation. High-impact actions require independent administrator approval and expire after 15 minutes.

07

Context and priority

Bring asset, identity, application, and business-service context into the case. Explain priority using criticality, exposure, privilege, environment, and recovery needs instead of relying on severity alone.

08

Intake and intelligence

Ingest from Microsoft Sentinel, Defender XDR, Tawny, or a secure mailbox. Enrich observables with VirusTotal and match local CSV, MISP, OTX, and PhishTank intelligence to active investigations.

09

Access and audit

Use organisation roles, SAML or OIDC SSO, scoped tokens, sensitivity controls, need-to-know compartments, break-glass access, and an append-only audit explorer with controlled export and redaction.

10

Closure, reporting, and learning

Enforce closure requirements, record disposition and root cause, generate controlled Markdown or PDF reports, run post-incident reviews, publish knowledge, and track detection, control, and process improvements.

Governed action

Contain with a human in the loop.

Kelpie makes high-impact response explicit. The target is fixed at request time, a second administrator approves it, and the resulting provider action becomes part of the incident record.

CloudflareMicrosoft EntraDefenderCrowdStrike

Approval requests expire after 15 minutes. Rollback remains a deliberate manual operation.

  1. 01

    Request

    An analyst selects an action supported by case observables.

  2. 02

    Approve

    A different administrator reviews the immutable target and request.

  3. 03

    Execute

    Kelpie invokes the configured provider and records the result.

  4. 04

    Audit

    Timeline, run state, retries, and approval evidence stay with the case.

Connected by design

Bring the systems around the case with you.

Use configured integrations for intake, identity, enrichment, approved response, and external workflows. Integration health, credentials, diagnostics, schedules, and sync conflicts remain visible to administrators.

Intake

  • Microsoft Sentinel
  • Defender XDR
  • Tawny
  • Secure mailbox

Intelligence

  • VirusTotal
  • MISP
  • OTX
  • PhishTank
  • Cloudflare Radar

Identity & access

  • SAML 2.0
  • OIDC + PKCE
  • Passkeys
  • Scoped API tokens

Response

  • Cloudflare
  • Microsoft Entra
  • Defender
  • CrowdStrike

Interfaces

  • REST API
  • Read-only MCP
  • TypeScript SDK
  • Native iOS companion

MCP access is read-only and scope-controlled. REST APIs and the TypeScript SDK support governed write workflows; SDK coverage is intentionally narrower than the full API.

Operational loop

From first signal to a better next response.

Every phase stays visible. Every hand-off and approval stays attached to the record.

  1. Triage the operation

    Work from saved team views, see ownership and SLA pressure, acknowledge the case, and bring the right responders into the queue.

  2. Build the record

    Correlate alerts and entities, structure findings, map ATT&CK techniques, preserve evidence, and keep analyst decisions attached to the investigation.

  3. Contain with control

    Run timed playbooks and bounded automations, or request provider actions that require independent approval before execution.

  4. Close, review, improve

    Meet closure requirements, export the final record, complete a post-incident review, and turn lessons into tracked improvements and reusable knowledge.

Customer-controlled deployment

Your environment. Your response data.

Run Kelpie with Docker Compose or on your container platform. Operate the web application and background worker with customer-managed PostgreSQL and Redis, plus optional S3-compatible storage and email delivery.

Docker ComposeContainer platformsPostgreSQL + RedisOptional S3 + email

AWS buyer deployment assets are prepared for ECS/Fargate and EKS. Marketplace listing availability remains pending final seller configuration.

Inside your environment

AnalystsBrowser + iOS
KelpieWeb + background worker
Response dataPostgreSQL, Redis, optional S3
Security toolsThreat intelligenceIdentity providersAutomation

Built and maintained in Canberra

Kelpie is built and maintained by Yuma IT.

Yuma IT is an Australian Indigenous-led software company based in Watson, ACT, and a Supply Nation Certified Supplier.

Visit Yuma IT
Yuma ITSupply Nation Certified Supplier

Incidents. Managed. Closed.

Give your team one place to prioritise the work, govern the response, preserve the evidence, and improve what happens next.