UltraViolet Cyber Launches Equinox, a Proprietary AI Detection Engineering Platform
New technology maximizes detection coverage across customer environments, mapping against both MITRE ATT&CK and MITRE
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
UltraViolet Cyber (UltraViolet), the only security operations partner that unifies red, blue and purple team capabilities into one integrated offering, today announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence & Detection Engineering (TIDE) team. Equinox maximizes detection coverage across customers’ Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tooling using AI and automation.
Security environments, telemetry and threat frameworks change constantly. Vendor detection libraries can include thousands of options, but what is relevant depends on each organization’s data, technology and risk profile, which can take weeks to manually analyze. Equinox closes that gap: it identifies each customer’s current detections and available log sources and maps them against both MITRE ATT&CK and MITRE ATLAS frameworks. UltraViolet is the first to provide a full map and scorecard to coverage status using MITRE ATLAS, specifically for adversarial tactics and techniques targeting AI and machine learning systems. The coverage prescriptively determines where mapped coverage exists, where gaps remain and which detections or log sources could improve it.
Equinox uses automation to perform the analysis in under 30 minutes, then recommends vendor or custom detections to be built and enabled to fill the identified gaps. UltraViolet’s TIDE engineers then review, backtest and approve every recommended detection before deployment, tuning it as needed. Customers receive framework-aligned evidence of where mapped detection coverage exists, how mapped coverage is changing and what to prioritize next to maximize coverage without increasing alert volume.
“Every SOC team has heard the question ‘are we actually covered?’ and struggle to answer it with full confidence,” said Dan Gittis, Director, TIDE Team at UltraViolet Cyber. “Equinox gives our TIDE engineers a real answer, in minutes instead of weeks, on not just which detections exist, but validates that a detection can actually fire against the data rather than assuming a mapped rule is effective. That’s the difference between a coverage dashboard and coverage you can defend in an audit.”
Independent industry research puts average enterprise detection coverage at 21% of MITRE ATT&CK techniques1, suggesting many organizations have telemetry capable of supporting far more mapped coverage than they currently have enabled. In a customer trial, a single Equinox review identified and validated a path from 59 of 222 covered techniques (26.6%) to 136 of 222 (61.3%) after implementation of the recommended detections. This represents a 34.7 percentage-point gain and a 130% increase in mapped technique coverage, achieved without an increase in SOC alert volume.
“Security leaders don’t lack detections, they lack visibility into whether the ones they have actually work against their own data,” said Atif Ghauri, Chief Operating Officer of UltraViolet Cyber. “Equinox closes that gap using the telemetry customers already have, before they spend a dollar on anything new. It’s a clear example of what we mean by practitioner-led, AI-accelerated: automation does the heavy lifting, our TIDE engineers make the calls that matter.”
Key benefits of Equinox include:
- A quantified answer to “are we covered?”: Equinox shows security leaders where mapped detection coverage exists, where gaps remain and how coverage changes over time on a MITRE ATT&CK map built from a sector-specific threat model—critically validated against live telemetry, not just rule presence.
- One coverage picture across every platform: Where a SIEM’s own dashboard shows only its own rules and data, Equinox maps coverage across every platform a customer runs into a single MITRE view, so gaps that fall between tools stay visible.
- Maximum coverage from existing investments: Equinox identifies the detections a customer’s current telemetry and security stack can already support, expanding coverage before any new tool or data source is purchased.
- Clearer telemetry investment priorities: A log-source gap report quantifies the additional mapped detection coverage each new log source could support, giving teams a business case for telemetry investment.
- Practitioner-led, AI-accelerated: Every recommended detection is reviewed, backtested against the customer’s own data and approved by a TIDE engineer before deployment — automation provides the speed, TIDE engineers provide the judgment.
- AI-related detection coverage: Equinox extends the same assessment process to MITRE ATLAS, helping teams assess and close mapped detection coverage gaps and prioritize improvements for AI-targeted threats alongside MITRE ATT&CK.
Equinox is delivered as part of UltraViolet’s Managed SOC offering at no additional charge, used during onboarding for every new customer and quarterly thereafter, and is also available as a standalone engagement for organizations that run their own SOC, or for clients that utilize UltraViolet’s embedded security experts. It is vendor-agnostic by design: SentinelOne, CrowdStrike, Elastic and Panther are fully integrated today, with Splunk and Microsoft Defender in development. To learn more about Equinox, visit: https://www.uvcyber.com/solutions/equinox.
About UltraViolet Cyber
UltraViolet Cyber is the only security operations partner that unifies red, blue, and purple team capabilities into one integrated team — finding what’s vulnerable, stopping active threats, and validating that your defenses hold under real pressure. Built by former U.S. intelligence community operators with 30+ years of experience, we serve 400+ Global 2000 enterprises and federal agencies. Our practitioner-led and AI-accelerated closed-loop operations turn offensive findings into defensive weapons immediately so gaps close in real time and defenses improve before attackers can exploit what testing uncovers. Offense informs defense. Defense sharpens offense. Security that gets smarter and stronger with every iteration.
UltraViolet is at the forefront of AI security. Purpose-built to test, validate, and govern the AI systems organizations are deploying today, UltraViolet brings the same offensive and defensive rigor to AI that it applies across the enterprise. UltraViolet is ranked #19 on the Top 250 MSSP List and is headquartered in McLean, Virginia. For more information, visit our website, read our blog, or follow us on LinkedIn.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260915809407/en/
Media gallery
