How VisionHeight’s AI Security Analyst, Elliot, triages CrowdStrike Falcon® detections using its own view of the internet and returns the evidence where analysts already work.
From Earth, we only ever see one side of the moon. The far side is not dark because nothing is there. It is dark because seeing it requires another vantage point.
Security operations live with the same constraint. CrowdStrike Falcon® Next-Gen SIEM detects activity inside an organization with high fidelity. But the verdict often depends on facts outside it: what an unfamiliar IP actually is, what sits behind a proxy, whether or not an organization is being specifically targeted.
VisionHeight provides that second vantage point. Elliot evaluates Falcon detection context against what VisionHeight observes directly across the internet every day: current proxy telemetry, internet-scale scanning, DNS and certificate intelligence, honeypot signals, behavioral telemetry, and infrastructure classification.
Falcon detects and orchestrates. Elliot adds the external evidence. Together, they turn alerts into defensible decisions.
Triage delivered inside the Falcon workflow
When a detection triggers, CrowdStrike Charlotte AgenticSOAR sends the security-relevant event context to Elliot. Elliot returns a verdict, a confidence level, and its reasoning. CrowdStrike Falcon® Fusion, the workflow engine of Charlotte Agentic SOAR, adds the result to the detection as a tag and a comment, so the analyst begins detection triage with a true or false positive classification and evidence to support it. VisionHeight is bringing this workflow to the content library.
Different alerts require different kinds of triage
Identity: the same rule, opposite verdicts
In this production geo-suspicious-login detection, a user appeared to authenticate from two U.S. IPv6 addresses one minute apart. Here is the detection, and Elliot’s response as it landed back in Falcon (redacted):
{
"detection": {
"description": "[REDACTED_USER] performed geo-suspicious events: logged in from United States (2600:6c5a:xxxx:xxxx::) and after 1 minute logged in from United States (2a02:26f7:f6c1:a1bd::)",
"severity": "Medium"
},
"elliot_response": {
"verdict": "False Positive",
"confidence": "high",
"explanation": "The user authenticated from a Charter Communications residential IPv6 (US) and then, within one minute, from an Akamai IPv6 that our enrichment identifies as an iCloud Private Relay node. Both IPs are unrated in our data, with no hostile tags, blocklist entries, or threat indicators. The rapid apparent location shift is fully explained by iCloud Private Relay, which routes traffic through Akamai infrastructure and commonly generates impossible-travel alerts as a known artifact. The underlying behavior is a legitimate user browsing with Private Relay enabled - not account compromise."
}
}
The detection was right to notice the anomaly. The added context made closure defensible — and immediate.
A second detection from the same rule showed a Philippines login followed one minute later by a U.S. login. This time, VisionHeight observed the Philippines residential address operating across three commercial proxy networks on the day of the detection, and the U.S. address was Microsoft Azure infrastructure — not a home or office. Elliot returned True Positive, moderate confidence and recommended escalation for possible credential compromise.
That Philippines address appears on no blocklist or IOC feed and never will; proxy nodes churn daily. The alert name did not determine either verdict. Current proxy observation and infrastructure attribution did.
Perimeter: infrastructure caught mid-staging
A firewall detection fires on an inbound connection from an IP that is clean in every feed. Elliot’s view is different:
{
"detection": {
"description": "Firewall permitted inbound connection from 91.xxx.xxx.xxx to external-facing service (port 443)",
"severity": "Medium"
},
"elliot_response": {
"verdict": "True Positive",
"confidence": "moderate",
"explanation": "Our internet scanning history shows this host first appeared online four days before the detection, presenting a self-signed TLS certificate we have already fingerprinted on at least two additional hosts - a reuse pattern typical of infrastructure cloned from a single template. The associated domain was registered within the last week, and another IP in the same certificate cluster has been observed probing our honeypot sensors. The IP, the domain, and the related cluster hosts are all unrated in our data, with no hostile tags or blocklist entries. The combination of newly stood-up hosting, certificate reuse across a young cluster, fresh domain registration, and active probing indicates attack infrastructure in staging rather than an established benign service. We recommend blocking the source and reviewing this connection for follow-on activity."
}
}Since a victim has not been reported yet, no feed entry can exist. Four independent datasets converged to classify this detection as a True Positive: scanning history, certificate intelligence, WHOIS, and honeypots.
Noise: recognizing a benign scanner
At the other end of the spectrum is the highest-volume alert class in any SIEM — perimeter detections firing on internet-wide scanners:
{
"detection": {
"description": "Multiple service discovery scans detected from 71.6.xxx.xxx across perimeter assets",
"severity": "Low"
},
"elliot_response": {
"verdict": "False Positive",
"confidence": "high",
"explanation": "The source is a known internet-wide research scanner. Our sensors have observed it continuously scanning broadly across the internet with a stable scanning fingerprint and published reverse DNS identifying the operator, and no exploitation attempts have been recorded from it against our honeypots. The activity against this perimeter matches its internet-wide pattern - untargeted enumeration, not reconnaissance specific to this organization. The alert reflects routine background scanning and can be closed per policy."
}
}
Less dramatic than catching staging — but multiplied across a month, this is where automated, explainable triage returns the most hours to a SOC. Note the judgment inside it: the same behavior from attacker-operated infrastructure, or aimed at this organization specifically, would have flipped the verdict.
The advantage is the observation point
Reputation and indicator feeds help teams act on infrastructure that has already been reported. These examples required different questions: Was this residential address functioning as a proxy today? Was the apparent anonymizer actually a benign privacy service? Was this host stood up days ago as part of a larger cluster? Is the source a known research scanner, or attacker-operated infrastructure?
No model can infer facts it has never observed. Elliot’s differentiation is not more fluent reasoning; it is the data behind the reasoning — facts it observes itself, not lists aggregated from others.
What this returns to the SOC
The obvious return is time. Multiple times a month, geo-suspicious logins take 20 minutes each to triage. An analyst must check WHOIS, geolocation, reputation lookups, and proxy checkers to prove a detection is negative. Elliot answers in seconds, before anyone opens a tab.
The most valuable return of all: verdicts that were completely unobtainable before Elliot. No amount of analyst time with public tools could reveal that a home router joined three proxy networks today, or that a device behind a proxy researched your company yesterday. Because these datasets live in one place, Elliot reasons over the whole picture at once — so fewer false positives are escalated, and fewer true positives are closed as noise. An incorrect misclose could cost your company an account takeover, not just 20 minutes.
Better together — and a new way to start
The CrowdStrike Falcon platform’s unified architecture enables seamless integration with best-in-class partners like VisionHeight, extending Falcon’s native detection capabilities with specialized external intelligence.
CrowdStrike Falcon Next-Gen SIEM provides the detection. Charlotte Agentic SOAR automates the path from detection to action. Elliot adds current infrastructure context and returns its reasoning to Falcon, where the analyst remains in control.
VisionHeight is now beginning a freemium offering for CrowdStrike Falcon® Complete managed detection and response (MDR) customers, including access to the Elliot platform and agentic triage through CrowdStrike Falcon.
Visit VisionHeight at Fal.Con 2026 in Las Vegas to see the workflow live — and to see the far side of the moon.
