IVON: the AI security analyst from Attic Security

Investigate a security detection in Microsoft Defender

IVON reads an incident you pick yourself and gives you a second opinion. You watch the reasoning as it happens, and you keep the report.

One incident per tenant, free of charge. Read-only consent, and a run usually finishes within ten minutes.

Start IVON investigation (opens the Microsoft consent screen) See it on a sample incident

The yellow button takes you to a sign-in on your own tenant. After signing in you grant IVON the read permissions it needs for this run only, and you come back to our website to follow the investigation.

One run, start to verdict

Preview
  1. 10:00:00 Reading the evidence
  2. 10:00:41 Flagged url https://phish.example.net/login
  3. 10:02:04 Following the identity
  4. 10:02:52 Flagged account [email protected]

IVON's verdict

True positive Confidence 86%

Account compromise confirmed after a phishing click

One attacker session ties the phishing click to a PowerShell download cradle on the same workstation, and the download destination is on current threat-intel feeds.

  • Reset credentials and revoke every session for the account
  • Isolate the workstation until the dropped binary has been examined
  • Block the destination address at the egress proxy

Illustration with documentation-range placeholders. A real run reads your own incident and finishes with a verdict and the steps to take. See a live sample analysis.

It reads everything

A run usually finishes within ten minutes. In that time IVON reads every alert in the incident and every entity on them, enriches what it finds against global threat intelligence, and reasons about the whole thing as one case. The activity feed shows that work while it happens.

No black box

The activity feed shows which stage IVON is in and every indicator it flags, as it flags them. Intermediate steps are labelled as intermediate, so nothing half-formed is presented as a finding. The verdict is the only conclusion on the page, and it comes with the evidence trail that produced it.

Read-only, and short-lived

Delegated consent to read security incidents, and nothing else. There is no background access, so no refresh token exists to steal. The access token is dropped when the run ends, and the removal steps are on your results page whether or not you buy anything.

How it works

Four steps, no onboarding.

You do not deploy an agent, ship us data, or sit through an onboarding call.

  1. 1

    Connect

    A global admin signs in once and grants read-only consent to the enterprise application [ATTIC] IVON Incident Investigation. That is one screen, and there is nothing to install.

  2. 2

    Pick an incident

    We list your recent Defender incidents. You choose the one you want a second opinion on. One incident per tenant.

  3. 3

    Watch it work

    IVON pulls the incident, its alerts and its entities, enriches what it finds, and reasons to a verdict. The feed streams its progress and every indicator it flags.

  4. 4

    Take the report

    The finished analysis renders on the page with the full evidence trail, and downloads as a PDF you can hand to your team.

Access and removal

What IVON can and cannot do.

You are handing a security vendor a consent screen. This is what it asks for.

Read security incidents
SecurityIncident.Read.All (delegated, read-only)
Sign you in
openid, profile, email (to prove which tenant you administer)
Nothing in the background
no offline_access, so no refresh token exists
Nothing written, ever
IVON has no write scope in any Microsoft API

The full description of the access, the retention periods and the processing is in the terms of the IVON incident investigation.

Who you are giving consent to

Attic Security is a Dutch cybersecurity company, founded by four colleagues from DearBytes and KPN Security, building Attic since 2021. IVON is our agentic MDR for Microsoft 365, used by SMBs and by MSPs who run security for them. The incident investigation is the same engine, pointed at one incident.

  • Attic B.V., Molenstraat 36, 4761 CL Zevenbergen, the Netherlands (KvK 83973206)
  • Founders: Erik Remmelzwaal (CEO), Wesley Neelen, Rik van Duijn, Theo Snelleman
  • Where the analysis runs, and what does and does not leave the EU, is set out in Part B and Part C of the terms.
Meet the team

Questions we get.

The IVON incident investigation is free of charge and limited to one incident per tenant.

A run usually finishes within ten minutes. You can watch along while IVON works.

That is set out in the terms of the IVON incident investigation. Part A covers the access and the scope, Part B the processing arrangements, and Part C what we record, for how long and where. We deliberately do not restate that here in our own words: there should be one legal source.

Microsoft Entra admin centre, Enterprise applications, [ATTIC] IVON Incident Investigation, Properties, Delete. The same steps are repeated on your results page, so you do not have to come looking for them.

Granting admin consent is a normal interactive admin sign-in, so it is subject to your CA policies exactly like any other. MFA is one extra tap. If a device-compliance or approved-app policy blocks the sign-in outright, look at the sample analysis first, which needs no connection at all.

No, these are two separate offers. The IVON incident investigation is a one-off and covers a single incident you choose yourself. The trial is the full Attic MDR service in your own environment, and you start it on our pricing page.

The full terms are on the IVON incident investigation terms page.

See it on your own incident.

One consent screen and one incident, and you have a report. If you would rather not connect anything yet, start with the sample incident.

Looking for the full service rather than a single investigation? See Attic MDR and pricing.