Case lifecycle and control
Move incidents from open through containment, eradication, recovery, and governed closure. Track severity, classification, TLP, PAP, confidence, command, source identity, affected services, and SLA state.
Incident response for focused SOC teams
Triage signals, coordinate the investigation, govern response actions, preserve evidence, and close with one complete operational record.

Case operationsQueues, ownership, hand-offs, SLAs, and closure controls.
Investigation & evidenceConnected findings, ATT&CK context, custody, and legal holds.
Human-approved responseGoverned provider actions with separation of duties.
Self-hosted controlRun the platform and keep response data in your environment.
Case operations
Replace the reconstruction work across tickets, chats, spreadsheets, and consoles. Kelpie keeps ownership, queues, decisions, evidence, tasks, controls, and reporting attached to the case from intake through review.

Run each incident through a consistent process while preserving the technical and human decisions that shaped the response.
Investigation workbench
Use a governed playbook catalogue, cross-case observables, local intelligence feeds, investigation graphs, ATT&CK coverage, and evidence controls without moving the incident into a second system.


Product map
Kelpie covers the work around the alert: coordination, investigation, custody, approvals, closure, reporting, and the feedback loop that improves the next response.
Move incidents from open through containment, eradication, recovery, and governed closure. Track severity, classification, TLP, PAP, confidence, command, source identity, affected services, and SLA state.
Manage team queues, assignments, watchers, acknowledgements, hand-offs, waiting reasons, escalations, workload, aging, saved views, and bulk triage without losing the case history.
Connect normalised alerts, entities, observables, evidence, hypotheses, findings, decisions, and case relationships. Correlate, merge, split, and trace an attack story through a typed investigation graph.
Preserve SHA-256 integrity, chain of custody, collections, and legal holds. Scan uploads, quarantine suspicious files, record reasoned overrides, and retain evidence when case records are removed.
Apply ordered timed tasks and reusable templates, or start from a versioned catalogue of 16 common SOC scenarios with evidence guidance, decision points, approval gates, and closure criteria.
Request Cloudflare blocks, Entra user disablement, Defender device isolation, or CrowdStrike host isolation. High-impact actions require independent administrator approval and expire after 15 minutes.
Bring asset, identity, application, and business-service context into the case. Explain priority using criticality, exposure, privilege, environment, and recovery needs instead of relying on severity alone.
Ingest from Microsoft Sentinel, Defender XDR, Tawny, or a secure mailbox. Enrich observables with VirusTotal and match local CSV, MISP, OTX, and PhishTank intelligence to active investigations.
Use organisation roles, SAML or OIDC SSO, scoped tokens, sensitivity controls, need-to-know compartments, break-glass access, and an append-only audit explorer with controlled export and redaction.
Enforce closure requirements, record disposition and root cause, generate controlled Markdown or PDF reports, run post-incident reviews, publish knowledge, and track detection, control, and process improvements.
Governed action
Kelpie makes high-impact response explicit. The target is fixed at request time, a second administrator approves it, and the resulting provider action becomes part of the incident record.
Approval requests expire after 15 minutes. Rollback remains a deliberate manual operation.
An analyst selects an action supported by case observables.
A different administrator reviews the immutable target and request.
Kelpie invokes the configured provider and records the result.
Timeline, run state, retries, and approval evidence stay with the case.
Connected by design
Use configured integrations for intake, identity, enrichment, approved response, and external workflows. Integration health, credentials, diagnostics, schedules, and sync conflicts remain visible to administrators.
MCP access is read-only and scope-controlled. REST APIs and the TypeScript SDK support governed write workflows; SDK coverage is intentionally narrower than the full API.
Operational loop
Every phase stays visible. Every hand-off and approval stays attached to the record.
Work from saved team views, see ownership and SLA pressure, acknowledge the case, and bring the right responders into the queue.
Correlate alerts and entities, structure findings, map ATT&CK techniques, preserve evidence, and keep analyst decisions attached to the investigation.
Run timed playbooks and bounded automations, or request provider actions that require independent approval before execution.
Meet closure requirements, export the final record, complete a post-incident review, and turn lessons into tracked improvements and reusable knowledge.
Customer-controlled deployment
Run Kelpie with Docker Compose or on your container platform. Operate the web application and background worker with customer-managed PostgreSQL and Redis, plus optional S3-compatible storage and email delivery.
AWS buyer deployment assets are prepared for ECS/Fargate and EKS. Marketplace listing availability remains pending final seller configuration.
Inside your environment
KelpieWeb + background workerBuilt and maintained in Canberra
Yuma IT is an Australian Indigenous-led software company based in Watson, ACT, and a Supply Nation Certified Supplier.
Visit Yuma IT ↗
Give your team one place to prioritise the work, govern the response, preserve the evidence, and improve what happens next.