Cybermatic SIEM
Every log. Collected, watched, searched — and explained.
The agents you already run collect security logs from every Windows, macOS, and Linux device. Your firewalls and switches ship syslog. 29 built-in detections correlate into offenses. And Cybermatic Copilot tells you what happened in plain English.
Unlimited log sources · Never per-GB billed · No-charge 3× burst protection · Nothing charged until day 14
Collection with nothing to deploy
Existing Cybermatic agents flip into log collectors within one check-in of activation. New machines: one agent, both products. Network gear: syslog to your Discovery Agent, encrypted out.
29 detections out of the box
Cleared audit logs, credential dumping, shadow-copy deletion, encoded PowerShell, brute force, password sprays, sudoers changes, rogue services — evaluated on every event, plus hourly correlations.
Offenses, not alert noise
Related alerts group into one offense per machine or account with a magnitude score — ten detections on one workstation is one incident to triage, not ten emails.
Search everything, fast
Full-text and field search across your entire retention window — host, user, event ID, source, time range. Powered by a columnar data lake, not a struggling database.
Copilot triage
“What happened on WKS-FINANCE-03?” gets a real answer: the offense, the evidence, the next steps. With Security Posture Management, Copilot also folds in the machine's CVEs and posture — a standalone SIEM can't.
Auditor-ready reports
Executive summary, authentication activity, alert & offense review, source inventory, rule activity — print-ready over any window. The “show me you review your logs” evidence, on demand.
How it works
From raw log to plain-English answer
1 · Collect
Cybermatic agents ship curated security events from every Windows, macOS & Linux device; network gear sends syslog to your Discovery Agent — encrypted before it leaves your LAN.
2 · Normalize
Every event lands in one schema — host, user, process, event ID, source IP — so a firewall line and a Windows event are searchable the same way.
3 · Detect
29 built-in rules plus your custom rules run on every single event as it arrives — cleared audit logs, credential dumping, shadow-copy deletion, brute force, rogue services.
4 · Correlate
Related alerts group into one offense per machine or account with a magnitude score. Ten detections on one workstation is one incident — not ten emails.
5 · Explain
Copilot reads the offense, its evidence, and (with Security Posture Management) the device's security posture — then tells you what happened and what to do.
The detection pack
29 detections on from day one — plus your own
No consultants, no rule-writing project. The pack covers the attacks that actually hit SMBs, and admins add custom rules — match any host, user, process, or log pattern, alone or as a repeated-event threshold, with email notifications to whoever should know.
Windows & Active Directory
- Security audit log cleared
- Account added to administrators
- Defender disabled or tampered
- New services & scheduled tasks
- Account lockouts & admin logons
Endpoints & processes
- Credential dumping tools
- Shadow copies deleted (ransomware tell)
- Encoded PowerShell
- certutil download abuse
- UAC weakened via registry
Linux, macOS & network
- SSH root logins & brute force (correlated)
- Password sprays across accounts
- sudoers & cron changes
- macOS privacy (TCC) tampering
- VPN & firewall admin failures
Professional services
Expert implementation, and a security professional on your calendar
Guided Deployment
$2,500 · included with annual Business & Enterprise
Full standard deployment in 6–8 expert hours: integrations, endpoint rollout, up to five SIEM/syslog sources onboarded, EPP policies, your first Insurance Readiness and board reports, and a 30-day review.
Quick Start
$750
One environment connected, agents deployed, initial configuration done — the guided first hour for smaller teams.
Quarterly Security Review
$950 · $3,000/yr · included with Enterprise
Each quarter a security professional reviews your data and delivers a written review with a 90-day action plan you can hand to leadership, your board, or your insurer.
Purchased from your workspace's Settings page, so we can schedule against your real environment. All services and details →
What it catches
Ransomware precursors
Shadow-copy deletion, encoded PowerShell, and new services on one machine become a critical offense before encryption starts.
Account attacks
Brute force and password sprays correlated across events — with the most-targeted accounts named in the Authentication report.
Insider & admin drift
New local admins, weakened UAC, sudoers edits, disabled Defender — the quiet changes that precede loud incidents.
Audit evidence
The Alert & Offense Review report is the “show me you review your logs” answer for SOC 2, HIPAA, PCI, and cyber-insurance questionnaires.
See it, search it, prove it
One search box across every log you own
A brute-force attempt shows up in your firewall, your Linux server, and a Windows workstation — Cybermatic shows all three in one query, then hands you the audit-ready report without anyone building it.
Why teams choose Cybermatic
A SIEM you'll actually run — without hiring for it
Working in an afternoon, not a quarter
Legacy SIEMs are six-month integration projects. Here: pick a plan, agents flip on with zero installs if you run Cybermatic already, point syslog at your collector — detections are live the same day.
A bill you can predict
Per-GB pricing means every new log source is a budget conversation. Flat tiers with 3× burst protection mean an incident — when logs spike hardest — never turns into an invoice.
Answers, not dashboards
Most SIEMs hand you a query language and wish you luck. Copilot reads the offense and its evidence, then tells you what happened and what to do — in plain English, at 2am, without a SOC on payroll.
Detections curated for SMBs
29 rules tuned to the attacks that actually hit small and mid-size businesses — ransomware precursors, account takeover, admin drift — plus your own custom rules with email notifications.
One incident, not fifty emails
Correlation groups related alerts into a single offense per machine or account with a magnitude score, so a noisy attack reads as one prioritized story.
Posture context built in
Run it alongside Security Posture Management and Copilot connects the dots: the machine under attack is the one with the unpatched critical CVE. No other SMB tool sees both sides.
Card required · nothing charged until day 14 · cancel any time before at no charge
Why not Splunk, Sentinel, or QRadar?
Enterprise SIEMs bill by the gigabyte. That's backwards.
Per-GB pricing punishes visibility
When every log costs money, teams turn sources off to control the bill — and miss the attack. Our tiers are flat: connect everything.
No consultants required
Enterprise SIEMs assume an analyst team and a services budget. Cybermatic ships detections on, correlation on, collection automatic — useful on day one.
It knows your environment
Standalone SIEMs see logs in a vacuum. Ours shares a brain with your posture data — detections become findings on your dashboard, and Copilot reasons across both.
SIEM pricing
Flat. Predictable. Never per-GB.
Every plan: unlimited log sources, all 29 detections, offenses, search, reports, Copilot, and 3× burst protection at no charge. Annual billing = 2 months free.
Starter
$599 /mo
billed monthly
Full SIEM coverage for a small fleet — the same engine as every tier above it.
- 5 GB/day ingest allowance
- 60-day searchable retention
- 2 users: 1 admin + 1 viewer (owner included)
- Email support
Growth
$1,499 /mo
billed monthly
The right fit for 25–100 employees — room for every device and network appliance you own.
- 15 GB/day ingest allowance
- 90-day searchable retention
- 5 users: 2 admins + 3 viewers
- Priority support
Pro
$2,999 /mo
billed monthly
Longer memory and a bigger team — retention that satisfies most audit look-back windows out of the box.
- 30 GB/day ingest allowance
- 180-day searchable retention
- 8 users: 3 admins + 5 viewers
- Questionnaire Copilot (100/yr) & public Trust Center
- Priority support
Business
$5,499 /mo
billed monthly
A full year of searchable logs, standard — HIPAA, PCI, and cyber-insurance retention answered by default.
- 50 GB/day ingest allowance
- 365-day retention included
- 2-year (+$149/mo) or 3-year (+$249/mo) archive retention available
- 22 users: 7 admins + 15 viewers
- Questionnaire Copilot (250/yr) & Trust Center with NDA vault
- Priority support
- Guided Deployment included with annual billing
- Billed from day one (no trial)
Enterprise
$8,999 /mo
billed monthly
Serious volume with a fixed, predictable bill — where per-GB vendors quote you six figures.
- 100 GB/day ingest allowance
- 365-day retention included — add a 2-year (+$299/mo) or 3-year (+$499/mo) archive
- Unlimited admins & viewers
- Dedicated success manager · 99.9% uptime SLA in writing
- MSA, DPA & BAA · invoicing and PO terms
- Quarterly Security Reviews & Guided Deployment included
- Early access to new features
- Billed from day one (no trial)
Enterprise+ — over 100 GB/day
Custom ingest allowance and retention, dedicated success manager, written 99.9% SLA, MSA/DPA/BAA, invoicing and PO terms, Quarterly Security Reviews, and early access — the flat-price promise at any volume.
Trials: card required · nothing charged until day 14 · cancel any time before at no charge. Business & Enterprise bill from day one.
Every SIEM plan includes
- Unlimited log sources — devices, firewalls, switches, NAS, servers
- All 29 built-in detections + unlimited custom rules
- Offense correlation with magnitude scoring
- Full-text log search across your entire retention window
- Five scheduled report types (auth, offense review, ingest, compliance evidence…)
- Cybermatic Copilot — plain-English incident explanations
- Email notifications on high & critical detections
- 3× daily burst absorbed at no charge — never billed per GB
Already a Cybermatic customer? Add SIEM from SIEM settings — one click on your saved card.
Common questions
- Can Cybermatic help with customer security questionnaires and a trust page?
- Yes — on Growth and above (Posture) or Pro and above (SIEM, Endpoint Protection). Questionnaire Copilot drafts answers from live evidence, your approved policies, and an Approved Answer Library, marking each as Verified, Document-supported, or Attestation required, and flags any reused answer that now conflicts with current evidence. The Trust Center publishes a public page with controls measured live by Cybermatic, published policies, and documents released under a click-through NDA with recorded acceptance.
- Do I need new agents?
- No. If you run Cybermatic Security Posture Management, the same agents begin collecting security logs the moment SIEM is active — nothing to install. New customers install one agent per device; it does both jobs.
- What about firewalls, switches, NAS — things that can't run an agent?
- Point their syslog at the machine running the Cybermatic Discovery Agent (port 514). It receives on your LAN and forwards over encrypted HTTPS. Unlimited syslog sources on every plan.
- What counts against my GB/day?
- Only what you ingest, measured transparently. Bursts up to 3× your allowance are absorbed at no charge — incidents are exactly when logs spike, and we won't bill you for being attacked. Nothing is ever dropped silently, and there are no overage invoices, ever.
- Why never per-source pricing?
- Per-source and per-GB pricing punish visibility — teams turn off log sources to save money, then miss the attack. Flat tiers mean you connect everything and sleep.
- What happens if I cancel?
- Collection stops within one agent check-in, the ingest API refuses further data, your logs are retained 30 days in case you return, then permanently deleted. Your Security Posture Management subscription is completely unaffected.
- Is my data isolated?
- Every workspace's logs live under its own encrypted prefix (AWS KMS), searches are workspace-scoped at the query layer, and retention is enforced per plan daily.
- How does the trial work?
- 14 days on Starter, Growth, or Pro — a card is required but nothing is charged until day 14, and canceling before then costs nothing. The trial runs at the full limits of the tier you pick, converts to it automatically, and you can buy now, switch tiers, or cancel at any point mid-trial. One trial per workspace; Business and Enterprise bill from day one.
- How many people can use it?
- Seats scale with the plan (owner included): Starter 1 admin + 1 viewer, Growth 2 + 3, Pro 3 + 5, Business 7 + 15, Enterprise unlimited. Roles are per product — someone can be a SIEM admin and a Posture viewer, or SIEM-only with no dashboard access at all.
- How long is my log history kept?
- Searchable retention scales with the plan — Starter 60 days, Growth 90, Pro 180, Business and Enterprise 365 — and Business and Enterprise can extend to a 2-year (730-day) or 3-year (1,095-day) archive as an add-on. Designed for regulated organizations, incident-response investigations, cyber-insurance requirements, legal and internal retention policies, and enterprise customers that require extended security-event history. Older data stays searchable from the archive tier.
- Can I write my own detection rules?
- Yes — admins build custom rules from field conditions (host, user, process, message and more), optionally firing only on repeated matches per hour, with email notifications to up to 10 addresses per rule, distribution lists included.
Not ready for a trial? Run a free security scan — your score in 10 minutes, no card.