Apex Engine decides; Sandbox detonates; Mega Lake records.
Who this serves
Persona-specific value, not a generic value proposition.
DFIR and case handling
Incident Responder
Investigative continuity across the retention horizon. Schema-governed lake retention, reproducible deterministic correlation, and chain-of-custody-aligned evidence preservation are preconditions of the investigation, not deliverables to assemble under deadline.
Tier-1 / Tier-2 triage and investigation
SOC Analyst
Reduced verdict ambiguity and faster triage. Each alarm arrives with its rule, source telemetry, enrichment, and confidence weighting — so the first question of the shift is decision, not interpretation.
The Principle
Theoretical foundation.
Sandbox detonation is a high-cost analytical act. It is most valuable when invoked by a decision substrate that has earned the cost — Apex Engine — rather than triggered by every artefact.
The Mechanism
How NOGTUS implements this.
Apex decision analysis evaluates an artefact against policy preconditions. When admitted, the artefact is handed off to the Sandbox Server. The detonation report is returned to Mega Lake under the schema contract for downstream correlation.
Operational Consequence
What this enables for the operator.
Outcome
Cost-Justified Detonation
Sandbox cycles are spent on artefacts that have earned them.
Before: sandbox queues filled with low-signal artefacts.
Outcome
Lake-Bound Reports
Detonation reports are correlatable, retentioned, and audited.
Before: reports lived in sandbox-local storage.
Outcome
Handoff Lineage
Each handoff carries its decision record.
Before: handoffs were untraceable.
Canonical Platform Specification
From the NOGTUS Platform Specification.
"Menerima file dari keputusan Apex Engine untuk di kirim ke sandbox"
— NOGTUS Platform Specification
Related Capabilities
Engage the Team
Discuss your security operation with the engineers who built NOGTUS.