Capability · Detection Substrate · NOGTUS Platform

Decision Lineage Surface

Detection without lineage is opinion. Detection with lineage is evidence.
Who this serves

Persona-specific value, not a generic value proposition.

Tier-1 / Tier-2 triage and investigation

SOC Analyst

Reduced verdict ambiguity and faster triage. Each alarm arrives with its rule, source telemetry, enrichment, and confidence weighting — so the first question of the shift is decision, not interpretation.

Audit, regulatory reporting, control coverage

Governance & Compliance Stakeholder

Audit-ready evidence as a property of the deployed system. Coverage and gap are continuous, not periodic; supervisory inspections receive structured lineage records aligned with control frameworks (ISO 27001, POJK, BSSN sectoral, UU PDP).

CISO, CIO, board reporting

Executive & Decision Stakeholder

Intelligible decision-oriented summaries grounded in evidence. Executive narratives — cited to the lake records that ground them — translate operational telemetry into the register the board can act on.

The Principle

Theoretical foundation.

A detection that arrives without its evidentiary chain is, in epistemic terms, an opinion — a verdict whose grounds cannot be inspected, contested, or audited. The Decision Lineage Surface is the architectural commitment that every verdict produced by the platform carries the rule that fired it, the source data examined, the enrichment applied, and the confidence weighting that arbitrated the outcome.

Without lineage, the SOC operates by deference; with lineage, the SOC operates by evidence. The shift is not cosmetic — it changes what an analyst can defend, what a CISO can report, and what a regulator can verify.

The Mechanism

How NOGTUS implements this.

Each engine — Apex Vision, Apex Static, Minutia, Behavioral Baseline — emits a structured verdict bound to a canonical event identifier and accompanied by its decision metadata. Aptos normalizes these verdict records under the Mega Lake schema. The Investigation Workspace surfaces the lineage to the analyst as a navigable graph of triggers, sources, and weighted contributions.

Crucially, the lineage record persists across the retention horizon, enabling retroactive verification, post-incident reconstruction, and supervisory audit.

Operational Consequence

What this enables for the operator.

Outcome

Auditable Verdicts

Every alarm can be traced from analyst console back to the precise rule and source telemetry.

Before: alarms surfaced without explainability — analysts disputed verdicts they could not inspect.

Outcome

Regulator-Ready Evidence

Supervisory inspections receive structured lineage records aligned with control frameworks.

Before: incident reports were composed manually under deadline pressure.

Outcome

Retroactive Hunting

Hunters can replay historical lineage against new hypotheses without rebuilding context.

Before: each hunt restarted from raw logs.

Canonical Platform Specification

From the NOGTUS Platform Specification.

"Apex Vision Engine data Menghasilkan full decision trail yang memuat rule atau logika pemicu, data sumber, enrichment."

— NOGTUS Platform Specification

Related Capabilities
Engage the Team

Discuss your security operation with the engineers who built NOGTUS.