Investigate a security detection in Microsoft Defender
IVON reads an incident you pick yourself and gives you a second opinion. You watch the reasoning as it happens, and you keep the report.
One incident per tenant, free of charge. Read-only consent, and a run usually finishes within ten minutes.
The yellow button takes you to a sign-in on your own tenant. After signing in you grant IVON the read permissions it needs for this run only, and you come back to our website to follow the investigation.
One run, start to verdict
Preview- 10:00:00 Reading the evidence
- 10:00:41 Flagged url https://phish.example.net/login
- 10:02:04 Following the identity
- 10:02:52 Flagged account [email protected]
IVON's verdict
True positive Confidence 86%Account compromise confirmed after a phishing click
One attacker session ties the phishing click to a PowerShell download cradle on the same workstation, and the download destination is on current threat-intel feeds.
- Reset credentials and revoke every session for the account
- Isolate the workstation until the dropped binary has been examined
- Block the destination address at the egress proxy
Illustration with documentation-range placeholders. A real run reads your own incident and finishes with a verdict and the steps to take. See a live sample analysis.
It reads everything
A run usually finishes within ten minutes. In that time IVON reads every alert in the incident and every entity on them, enriches what it finds against global threat intelligence, and reasons about the whole thing as one case. The activity feed shows that work while it happens.
No black box
The activity feed shows which stage IVON is in and every indicator it flags, as it flags them. Intermediate steps are labelled as intermediate, so nothing half-formed is presented as a finding. The verdict is the only conclusion on the page, and it comes with the evidence trail that produced it.
Read-only, and short-lived
Delegated consent to read security incidents, and nothing else. There is no background access, so no refresh token exists to steal. The access token is dropped when the run ends, and the removal steps are on your results page whether or not you buy anything.
Four steps, no onboarding.
You do not deploy an agent, ship us data, or sit through an onboarding call.
- 1
Connect
A global admin signs in once and grants read-only consent to the enterprise application [ATTIC] IVON Incident Investigation. That is one screen, and there is nothing to install.
- 2
Pick an incident
We list your recent Defender incidents. You choose the one you want a second opinion on. One incident per tenant.
- 3
Watch it work
IVON pulls the incident, its alerts and its entities, enriches what it finds, and reasons to a verdict. The feed streams its progress and every indicator it flags.
- 4
Take the report
The finished analysis renders on the page with the full evidence trail, and downloads as a PDF you can hand to your team.
What IVON can and cannot do.
You are handing a security vendor a consent screen. This is what it asks for.
- Read security incidents
- SecurityIncident.Read.All (delegated, read-only)
- Sign you in
- openid, profile, email (to prove which tenant you administer)
- Nothing in the background
- no offline_access, so no refresh token exists
- Nothing written, ever
- IVON has no write scope in any Microsoft API
The full description of the access, the retention periods and the processing is in the terms of the IVON incident investigation.
Who you are giving consent to
Attic Security is a Dutch cybersecurity company, founded by four colleagues from DearBytes and KPN Security, building Attic since 2021. IVON is our agentic MDR for Microsoft 365, used by SMBs and by MSPs who run security for them. The incident investigation is the same engine, pointed at one incident.
- Attic B.V., Molenstraat 36, 4761 CL Zevenbergen, the Netherlands (KvK 83973206)
- Founders: Erik Remmelzwaal (CEO), Wesley Neelen, Rik van Duijn, Theo Snelleman
- Where the analysis runs, and what does and does not leave the EU, is set out in Part B and Part C of the terms.
Questions we get.
The IVON incident investigation is free of charge and limited to one incident per tenant.
A run usually finishes within ten minutes. You can watch along while IVON works.
That is set out in the terms of the IVON incident investigation. Part A covers the access and the scope, Part B the processing arrangements, and Part C what we record, for how long and where. We deliberately do not restate that here in our own words: there should be one legal source.
Microsoft Entra admin centre, Enterprise applications, [ATTIC] IVON Incident Investigation, Properties, Delete. The same steps are repeated on your results page, so you do not have to come looking for them.
Granting admin consent is a normal interactive admin sign-in, so it is subject to your CA policies exactly like any other. MFA is one extra tap. If a device-compliance or approved-app policy blocks the sign-in outright, look at the sample analysis first, which needs no connection at all.
No, these are two separate offers. The IVON incident investigation is a one-off and covers a single incident you choose yourself. The trial is the full Attic MDR service in your own environment, and you start it on our pricing page.
The full terms are on the IVON incident investigation terms page.
See it on your own incident.
One consent screen and one incident, and you have a report. If you would rather not connect anything yet, start with the sample incident.
Looking for the full service rather than a single investigation? See Attic MDR and pricing.