Security operations on autopilot.
Detect. Investigate. Remediate. Automatically.
ProPera is an AI-powered security operations platform built around Microsoft Defender for Endpoint - unified with Defender XDR, Sentinel, Intune, Purview, Secure Score and Microsoft Graph. It turns your SOC's manual playbooks into governed, auditable automation: detection, investigation, MITRE ATT&CK mapping, risk scoring, AI analysis, approval-gated remediation and continuous compliance - all from one console.
One platform. Every Microsoft security signal. Full automation.
ProPera is purpose-built to remove manual security operations. It connects to the Microsoft security stack, correlates telemetry, maps activity to MITRE ATT&CK, scores risk, investigates with AI, and executes remediation through governed automation policies.
Defender for Endpoint first
MDE is the primary security engine: devices, alerts, incidents, vulnerabilities, exposure and response actions - surfaced and automated in one console.
Automation, not scripting
No registry edits, no ASR rule scripts, no manual Intune policy juggling. Build WHEN/THEN automation policies with dry-run, approval and emergency modes.
AI Security Analyst
Attack paths, risk scores, MITRE mapping and recommended responses - generated from real evidence, with honest confidence levels. Never claims malicious without proof.
Advanced Hunting
Full KQL editor with query history, saved & scheduled hunts, charts, export - and one-click conversion into detection rules or automation triggers.
MITRE ATT&CK engine
Every alert, evidence item and incident mapped to tactics, techniques and sub-techniques - with heatmaps, attack maps and technique-to-automation linking.
Governed & auditable
Every action logged with actor, reason, approval, before/after state and rollback info. Role-based access for analysts, admins, auditors and viewers.
From detection to remediation - end to end, governed
Every automation supports four modes: Disabled, Recommend, Approval required, Automatic and Emergency automatic. Destructive actions are never automatic by default.
Incident & alert triage
Assign, classify, investigate, run automation, create Sentinel incidents, notify Teams.
Automated remediation
Isolate devices, run AV scans, collect packages, block indicators, stop processes - approval-gated.
Vulnerability automation
CVE → affected devices → risk → remediation plan → approval → remediation → verification.
Secure Now
Secure Score and recommendations with one-click governed remediation workflows and verification.
Dry run first
See exactly what an automation WOULD do - isolate 3 devices, notify Teams, create 1 ticket - before any action.
Approval workflow
Recommendation → risk analysis → approval request → SOC analyst approve/reject → execute → verify → audit.
Detection rules
Turn hunting queries into scheduled detections with automated response triggers.
Background workers
Continuous sync of incidents, vulnerabilities, Secure Score, Sentinel and automation evaluation.
Deep Microsoft coverage - with optional third-party extension
Microsoft Defender for Endpoint is the primary security engine. Everything else extends the platform. Connect live with your Microsoft tenant, or explore instantly in Demo Mode.
Intune
Device compliance, managed devices and policy context from Microsoft Intune - surfaced alongside MDE device data.
Purview
Compliance posture, data-loss-prevention context and audit signals from Microsoft Purview in the same console.
Sentinel
Incident sync both ways, analytics rules, hunting queries and automation workflow correlation.
Extend further
Teams, Slack, ServiceNow, Jira, PagerDuty, VirusTotal, AbuseIPDB and OTX - clearly labeled as third-party.
Continuous compliance - the ProPera model, built in
A continuous control-monitoring model: control catalogs mapped to real platform evidence, automatically re-assessed as your environment changes. No manual evidence collection spreadsheets.
Control catalogs
ISO 27001, NIST CSF, CIS v8 and Essential Eight control libraries with mapped evidence from live platform data.
Automated evidence
Evidence is collected automatically: audit logs, automation runs, approvals, RBAC, secure score and integration health.
Continuous re-assessment
Control status recomputed as data changes - remediation closes gaps, evidence stays fresh, reports stay current.
Bulletproof by design
Entra ID auth
OAuth 2.0 with Entra ID, optional per-tenant SSO, client secret or certificate, managed identity support, MFA enforcement.
Role-based access
Administrator, Security Admin, SOC Analyst, Analyst, Automation Admin, Auditor, Viewer and Platform Admin.
Secure by default
Secrets never hard-coded or logged. HTTPS, CSRF protection, secure headers, rate limiting, input validation.
Multi-tenant SaaS
Isolated customer workspaces with per-tenant credentials, plans and usage limits. Sell security as a service.
Relational database
Postgres in production (SQLite in demo), full migrations, devices, incidents, alerts, vulnerabilities, audit logs.
Containerized
Frontend, backend, worker, database and Redis via docker-compose - ready for Azure deployment.
Live status
System status panel with database, worker, mode and API health on every page. Public status page included.
OpenAPI
Full REST API with OpenAPI documentation for every module.
Put your Microsoft security on autopilot
Explore the full platform right now - no Microsoft tenant required. When you're ready, connect your tenant and ProPera starts working against your real environment.