Skip to main content

Frequently Asked Questions

How does CheckMate integrate with existing client security stacks and legacy systems?

CheckMate powered by Phen.AI, is built to operate across diverse enterprise environments, supporting both modern security platforms and long‑standing legacy systems. Its architecture enables flexible ingestion, normalization, and real‑time analysis of security telemetry, allowing organizations to maximize existing investments without disruption.

Integration with Enterprise Security Tools: The platform connects natively with solutions such as Nessus, Trellix, and Splunk, enabling automated ingestion of vulnerability data, endpoint telemetry

SIEM events, and threat intelligence: This creates a unified operational picture and consistent analytics across the customer’s security ecosystem.

Support for Legacy and Heterogeneous Telemetry Sources:
CheckMate ingests and correlates data from a wide range of systems, including:

  • Unix, Linux, and Windows system and application logs
  • DNS and DHCP logs
  • NetFlow and DPI telemetry
  • Firewall and IDS/IPS logs
  • Honeypot and deception system logs
  • Endpoint and EDR logs
  • PCAP data
  • Vulnerability scan outputs

This broad compatibility ensures effective operation in environments with mixed generations of hardware, software, and network infrastructure.

Multi‑Interface Operational Capability: Phen.AI interacts with systems through Bash, PowerShell, WMI, and Cisco CLI. These interfaces enable automated analysis, configuration, and response actions across cloud‑native, on‑premises, and legacy platforms.

Outcome: By integrating cleanly with existing tools, modern devices and legacy systems, CheckMate strengthens an organization’s security posture without requiring costly rip‑and‑replace efforts. The platform delivers unified analytics, improved detection fidelity, and greater operational efficiency across the entire security stack.

What changes will SOC analysts notice in their daily monitoring and incident response routines?

CheckMate powered by Phen.AI introduces a more streamlined, accurate, and centralized operational experience for SOC analysts. Daily monitoring becomes more cohesive, and investigative workflows become significantly faster and more informed.

Centralized and Enriched Monitoring: Endpoint, network, cross‑domain, and cloud telemetry are correlated in real time, giving analysts a unified operational picture. The AI‑driven ingest engine reduces noise by enriching events with context, allowing analysts to focus on meaningful activity rather than sifting through fragmented alerts.

AI‑Assisted Investigation and Faster Triage: Phen.AI accelerates triage and root‑cause analysis by automatically correlating logs, events, and behavioral indicators. Built‑in profiling, signature alerting, and anomaly detection reduce manual workload and help analysts quickly identify patterns, anomalies, and emerging threats.

Enhanced User and Entity Behavior Analytics (UEBA): Behavioral analytics provide deeper visibility into user activity, insider threat indicators, and lateral movement. Continuous evaluation of deviations from normal behavior gives analysts early alerts signals and actionable insights.

Active and Automated Mitigation Options: CheckMate supports both guided and automated response actions. Analysts can initiate mitigations directly or rely on Phen.AI to execute predefined countermeasures based on weighted recommendations. This approach improves response speed while preserving human oversight.

Continuous Testing and Proactive Security Posture Management: Phen.AI enables ongoing validation of the organization’s defenses through daily penetration testing, continuous vulnerability assessments, and Red and Blue Team exercises, all with minimal operational impact. Trend analysis and real‑time risk scoring help analysts prioritize remediation based on actual exposure and threat likelihood. This continuous validation ensures controls remain effective and misconfigurations are addressed early.

Overall Impact: SOC operations shift from reactive alert handling to a proactive, intelligence‑driven model. With centralized monitoring, accelerated investigations, and automated mitigation, CheckMate reduces analyst fatigue while improving speed, accuracy, and consistency of incident response.

Can detection rules, response playbooks, or dashboards be customized to fit our organization’s needs?

Yes. CheckMate is built on a modular and highly extensible architecture that allows organizations to tailor detection logic, response workflows, and operational dashboards to their unique security requirements. The platform supports full customization of detection rules, alert thresholds, correlation logic, and automated response actions, ensuring alignment with each customer’s environment, risk profile, and operational processes.

Active Response Capabilities: Phen.AI’s Active Response engine further extends customization by enabling automated or semi‑automated remediation actions. For example, in patch management scenarios, Phen.AI identifies unpatched systems, engages a human‑in‑the‑loop for validation, and applies the required updates, unless security teams have already addressed the issue or instructed the system to disregard a specific patch. This model ensures both operational efficiency and analyst oversight.

Active Response capabilities continue to expand across additional operational domains, providing organizations with increasing flexibility to automate routine tasks, accelerate incident response, and reduce operational burden.

Role‑based dashboards, visualizations, and reporting modules can be adapted to meet the needs of SOC analysts, incident responders, executives, and compliance teams. This flexibility enables organizations to highlight the metrics, alerts, and operational insights most relevant to their mission.

To support deeper customization, Phen.AI aids with:

  • Custom report and dashboard creation
  • Threat analysis and rule tuning
  • Alert configuration and correlation logic
  • Development of tailored response playbooks
  • Integration of customer‑specific workflows and data sources

These services ensure that CheckMate not only fits into an organization’s existing processes but enhances them.

Outcome: Through modular design, customizable workflows, and expert support services, CheckMate ensures that detection rules, response playbooks, and dashboards can be fully tailored to meet the unique needs of any organization, without compromising security, visibility, or control.

To what extent can consultants customize detection rules, analytics, or response workflows within CheckMate?

Consultants have extensive flexibility to tailor CheckMate to an organization’s specific security requirements. The platform’s modular architecture allows for deep customization across detection logic, analytics workflows, and automated or guided response actions. This ensures that CheckMate aligns with each customer’s operational environment, threat landscape, and internal processes.

Consultants can adjust and refine detection rules, correlation logic, and analytic models to improve accuracy and reduce noise. They can also customize alert handling, reporting formats, and dashboards to match organizational workflows and role‑based needs.

CCG’s professional services team supports these efforts by providing expertise in implementation tuning, report development, threat analysis, alert optimization, and broader product enhancement planning. This partnership ensures that customers receive a solution tailored to their operational maturity and evolving security priorities.

Phen.AI’s Active Response capabilities further expand customization options. Consultants can design automated or human‑validated remediation workflows, such as identifying unpatched systems, confirming actions with analysts, and applying updates unless instructed otherwise. These capabilities continue to grow, enabling broader automation across additional operational domains.

Outcome: Through this combination of platform flexibility and expert support, CheckMate powered by Phen.AI empowers consultants to deliver highly customized detection, analytics, and response workflows that evolve alongside the organization’s security program.

How does CheckMate powered by Phen.AI, minimize false positives and alert fatigue for analysts?

CheckMate reduces false positives and alert fatigue by combining multi‑source correlation, behavioral context, and advanced cognitive learning to ensure that only meaningful, high‑confidence alerts reach analysts. The platform focuses on identifying genuine vulnerabilities, threats, and active attacks rather than overwhelming teams with noise.

Multi‑Source Correlation for High‑Fidelity Alerts: Phen.AI correlates data across a wide range of telemetry sources, including logs, NetFlow, DPI, firewalls, honeypots, endpoints, vulnerability data, and behavioral indicators. By evaluating events in context rather than isolation, CheckMate filters out benign activity and elevates only those alerts that demonstrate true risk.

Cognitive Learning and Behavioral Analysis: The platform applies cognitive learning models, historical network knowledge, and user/entity behavior analytics to distinguish normal patterns from suspicious deviations. This continuous learning process improves detection accuracy over time and reduces repetitive or irrelevant alerts.

MITRE ATT&CK Mapping for Threat Relevance: CheckMate aligns detections with MITRE ATT&CK techniques, ensuring alerts are tied to real adversary behaviors. This mapping helps analysts quickly understand the significance of an event and reduces time spent investigating low‑value signals.

Automated False Positive Resolution: Phen.AI can ingest alerts from other security tools and automatically suppress or resolve false positives. When an alert is validated as benign, the system learns from the outcome and adjusts future detection logic, further reducing unnecessary noise.

Actionable, Context‑Rich Notifications: When alerts are generated, they include clear context, recommended actions, and supporting evidence. This reduces investigation time and helps analysts focus on events that truly require attention.

Outcome: By combining correlation, behavioral analytics, cognitive learning, and automated suppression, CheckMate significantly reduces false positives and alert fatigue. Analysts receive fewer, higher‑quality alerts, enabling them to concentrate on real threats and respond more effectively.

What is CheckMate powered by Phen.AI’s pricing model?

The CheckMate powered by Phen.AI platform, offers both secure cloud subscription pricing and on‑premises annual appliance options to accommodate different deployment needs.

Cloud Subscription Model: Phen.AI provides monthly cloud tiers based on the number of IPs or endpoints being monitored. Pricing begins at $1,699 per month for environments up to 25 IPs/endpoints and scales to $3,750 per month for up to 150 IPs/endpoints. Cloud deployments include a one‑time installation fee, sensors and providing organizations with a fully managed, continuously updated service.

On‑Premises Appliance Model: For customers requiring local deployment, on‑premises pricing starts at $75,699 annually for support of up to 500 IPs, endpoints, or devices. Higher‑capacity tiers are available, including an Enterprise appliance that includes the AdminCore consisting of a utility node, multiple ingest nodes, compute resources, and 25 sensors. Enterprise‑level pricing is provided through direct consultation to ensure alignment with infrastructure scale and operational requirements.

Operational Efficiency and Cost Reduction: Because CheckMate powered by Phen.AI is an all‑in‑one security operations AI platform, organizations often reduce reliance on traditional manned operations centers and lower workforce‑related costs. The platform consolidates monitoring, analytics, investigation, and response capabilities, delivering measurable operational savings alongside improved security outcomes.

How does CheckMate powered by Phen.AI, scale to support global, multi‑site organizations with complex infrastructures?

CheckMate is engineered to operate reliably across large, distributed environments by leveraging a scalable architecture built around distributed sensors, and AdminCore. This design allows the platform to expand seamlessly as organizations grow or as monitoring needs increase across multiple geographic locations.

Distributed sensors collect telemetry from endpoints, networks, and security devices across all sites, feeding data into AdminCore and the analytic compute layer for correlation, enrichment, and real‑time analysis. Additional compute nodes can be deployed to handle increased ingest volume, higher event throughput, or expanded device coverage, ensuring consistent performance even in complex, high‑density environments.

Phen.AI enhances this scalability by providing a secure environment and flexible compute resources that can be added as needed. Its architecture supports incremental expansion, whether adding more ingest capacity, increasing analytic horsepower, or integrating additional device types.

For organizations requiring on‑premises deployments, Phen.AI offers appliance tiers up to the Enterprise level, capable of supporting unlimited IPs (Class C network), endpoints, or devices. This configuration includes AdminCore consisting of a utility node, multiple ingest nodes, compute resources, and sensors, providing a robust foundation for large, multi‑site operations.

Outcome: Through this combination of distributed collection, modular compute scaling, and flexible deployment options, CheckMate powered by Phen.AI delivers reliable performance and unified visibility across global infrastructures, regardless of size or complexity.

Can CheckMate reduce workforce costs, improve ROI, and deliver operational gains for similar enterprises?

CheckMate powered by Phen.AI is designed to streamline security operations and significantly reduce the manpower required to maintain a compliant and resilient cybersecurity posture. By consolidating monitoring, analysis, and response into a single platform, organizations can support 24/7 operations without the staffing levels typically associated with traditional SOC models.

The platform provides real‑time, automated evidence of CMMC compliance, eliminating the need for extensive manual data collection and documentation. For many Level 2 environments, this continuous monitoring replaces an estimated 300–600 hours of manual effort that would otherwise be required each month to maintain compliance readiness.

CheckMate’s automation, integrated analytics, and centralized workflows reduce operational overhead, lower escalation and staffing costs, and improve overall efficiency. Phen.AI’s documentation library also includes a dedicated ROI analysis, helping organizations quantify cost savings and operational improvements achieved through platform adoption.

Outcome: By reducing labor demands, improving compliance efficiency, and consolidating security functions, CheckMate delivers measurable ROI and long‑term operational benefits for enterprises with similar security and regulatory requirements.

What ongoing support, training, and SLAs are included with Phen.AI?

CCG’s customer service program is built on four pillars: responsiveness, escalation discipline, technical depth, and continuous improvement.

1. Customer Support Intake and Initial Response

All customer service requests, whether submitted via email, phone, or support portal, are routed through CCG’s centralized support system. Each request is automatically logged, time stamped, and assigned a severity level based on impact and urgency.

Standard Support

  • Initial response: within 48 hours (M–F, excluding holidays)
  • Issue acknowledgment: within 5 working days
  • Resolution target: within 3 working weeks

Gold Support

  • Initial response: within 24 business hours (M–F, excluding holidays)
  • Issue acknowledgment: within 3 working days
  • Resolution target: within 2 working weeks

Platinum Support

  • Initial response: within 2 business hours
  • Issue acknowledgment: within 1 working day
  • Resolution target: within 1 working week

These response objectives are contractually defined and monitored to ensure consistent performance.

2. Escalation Protocols

CCG uses a structured, multi tier escalation model to ensure that issues are resolved quickly and by the appropriate level of expertise.

Tier I (Partner or CCG Frontline Support)

  • Handles basic troubleshooting, configuration questions, and common operational issues
  • Provides initial triage and gathers diagnostic information
  • Escalates unresolved or complex issues to Tier II

Tier II (Advanced Technical Support)

  • Performs deeper investigation, log analysis, and system level troubleshooting
  • Coordinates with deployment engineers when needed
  • Escalates platform level or code level issues to Tier III

Tier III (CCG Engineering & Development)

  • Manufacturer direct support from the engineers who build and maintain the platform
  • Handles complex, high severity, or security critical issues
  • Provides patches, hot-fixes, and advanced remediation guidance

Escalation is automatic when response thresholds are reached or when issue severity warrants immediate elevation.

3. Issue Resolution Procedures

CCG follows a disciplined, repeatable process to ensure timely and accurate issue resolution:

1. Issue Logging & Severity Classification

  • Categorized as Critical, High, Medium, or Low
  • Determines response and escalation timelines

2. Initial Diagnosis

  • Tier I collects logs, system data, and user context
  • Quick fixes are applied when possible

3. Technical Investigation

  • Tier II or Tier III performs root cause analysis
  • Reproduces issues in lab environments when needed

4. Remediation & Verification

  • Fixes are applied, validated, and documented
  • Customer confirms resolution

5. Closure & Reporting

  • Ticket is closed with full documentation
  • Lessons learned are fed into continuous improvement

For critical issues affecting security or system availability, CCG initiates an immediate escalation to Tier III and provides continuous updates until resolution.

4. Incentives and Quality Assurance

CCG maintains several internal incentives and quality controls to ensure service excellence:

  • Performance based metrics for support staff tied to response times, resolution rates, and customer satisfaction
  • Quarterly service reviews to evaluate partner performance and adherence to SLAs 
  • Continuous training and certification for all support personnel
  • Root cause analysis reviews for recurring issues to prevent future incidents
  • Customer satisfaction scoring integrated into support workflows

These incentives ensure that both CCG employees and authorized partners consistently meet or exceed service commitments.

5. Customer Communication and Transparency

Throughout the support process, CCG provides:

  • Regular status updates
  • Clear timelines for next steps
  • Documentation of findings and resolutions
  • Escalation contacts for urgent matters

Customers always have direct access to CCG’s Tier III engineering team for high severity issues. CCG’s customer service program is a structured, disciplined, and Manufacturer direct support model designed to meet the mission critical needs of Sourcewell Participating Entities. With defined response times, clear escalation pathways, rigorous issue resolution procedures, and strong performance incentives, CCG ensures that every customer receives timely, expert, and reliable support throughout the lifecycle of the CheckMate powered by Phen.AI platform.

Can CheckMate powered by Phen.AI be successfully deployed in an environment with over 1 million+ endpoints?

Yes. The platform has been successfully deployed in large, distributed enterprise environments, and its modular architecture has been proven to scale toward 1M+ endpoints.

CheckMate, powered by Phen.AI, was engineered from the ground up for massive, distributed, multi‑site environments. Its modular deployment model allows sensors and AdminCores to be placed, expanded, and load‑balanced across extremely large networks without architectural limits. We have several real‑world deployments that demonstrate this scalability:

Why This Scales to 1M+ Endpoints

CheckMate’s architecture is intentionally modular to be scalable both horizontally and vertically:

  • Unlimited sensors can be deployed across the enterprise, enabling full‑spectrum visibility without architectural constraints.
  • Multiple AdminCores may be fielded, co‑located, or regionally distributed to support diverse operational environments.
  • Each AdminCore supports horizontal and vertical scaling. Additional hardware resources can be added per system, and additional systems can be brought under a single AdminCore to increase processing capacity and overall performance.
  • Sensors are fully assignable and can be dynamically reassigned to any AdminCore as operational needs evolve.
  • Regional AdminCores can operate autonomously while remaining visible to a designated primary site for centralized oversight.
  • Remote sites can monitor any AdminCore, and multiple locations may simultaneously monitor the same AdminCore, supporting distributed operations and redundancy.
  • The system supports any number of private or public IP addresses, with no inherent architectural limitations.

This architecture allows the platform to scale non-linearly as the enterprise grows. Whether it’s a single heavy system, multiple lightweight systems, or a mix of field‑deployed and centralized systems, CheckMate adapts effortlessly to the operational model.

CheckMate has already proven itself in environments with tens of thousands of systems, thousands of sites, and extensive IP reuse. Its modular, sensor‑driven architecture is built specifically to scale to 1M+ endpoints, and real‑world deployments demonstrate that it performs reliably in large, distributed, mission‑critical networks.

Does your platform prioritize vulnerability findings or reference them in investigation packages?

Yes. The CheckMate platform actively prioritizes vulnerability findings and incorporates them directly into investigation packages. CheckMate powered by Phen.AI is designed to elevate the most important vulnerability information so analysts can quickly understand risk, exposure, and potential exploitation paths. Out of the box, the platform automatically prioritizes vulnerabilities based on several key dimensions, including:

  • Systems with the highest number of vulnerabilities

  • Vulnerabilities most commonly observed across the environment

  • Criticality based on NIST’s Common Vulnerability Scoring System (CVSS)

  • Customers can define their own custom vulnerability conditions, including behavioral indicators such as prolonged user login sessions, excessive login longevity, repeated failed login attempts, or any other user‑defined criteria relevant to their environment.

This built‑in prioritization ensures that the most urgent issues rise to the top without requiring manual tuning.

Beyond the defaults, the security platform supports fully customizable views, filters, and prioritization logic, enabling customers to tailor vulnerability presentation to their operational needs even in ways CCG may not have originally envisioned. New reports, dashboards, and prioritization schemes can be rapidly configured to match mission requirements.

During investigations, Phen.AI automatically references relevant vulnerability data within its investigation packages. This provides analysts with immediate context about whether an affected system has known weaknesses, how severe those weaknesses are, and whether they may be related to the observed threat activity. Summary as follows;

  • Vulnerabilities are prioritized automatically and intelligently.

  • Criticality, prevalence, and asset importance drive default ranking.

  • Customers can define their own filters, views, and prioritization models.

  • Investigation packages automatically reference relevant vulnerabilities.

  • New reporting and prioritization logic can be quickly configured.

The Vulnerability Summary Dashboard includes drill down details for each result to include system‑specific findings, explanations of the impact, the scope of required remediation, detailed resolution steps, and CCG’s Quality of Detection (QOD) score. QOD is a percentage‑based measure of the likelihood that a result is accurate, derived from Phen.AI’s testing methodology and the steps it performs to validate the finding.

What is the proposed deployment model (e.g., self-contained hardware or dedicated cloud instances)?

CCG’s recommended deployment model for CheckMate powered by Phen.AI is a fully self‑contained, all‑in‑one hardware platform supplied directly by CCG. This dedicated hardware used for both the AdminCore and sensor components is TAA‑compliant and purpose‑built to deliver maximum security, performance, and isolation. This model has been successfully deployed into NIPR, SIPR, and JWICS lab environments, where dedicated hardware provides the highest assurance and the cleanest integration path for government networks. The hardware‑based deployment offers several advantages:

  • Strongest security posture through physical isolation. No data leaves the system nor ever reaches back to the vendor environment.

  • Dedicated compute resources optimized for CheckMate powered by Phen.AI.

  • Predictable performance regardless of local infrastructure variability.

  • Straightforward scalability by adding additional appliances as needed.

  • Ease of management with a consistent, hardened platform.

However, the platform is not limited to physical deployments. CheckMate’s AdminCore can also operate in virtualized and hybrid cloud environments (Ex: VMware, Azure, AWS) when mission needs require it. CCG has successfully worked with MITRE and the FMX lab to deploy a fully functional AdminCore within VMware, demonstrating that the platform can run effectively as a virtual instance when hardware deployment is not feasible or when a hybrid model is preferred. To summarize:

  • Preferred model: Self‑contained, TAA‑compliant hardware appliances for AdminCore and sensors.

  • Proven alternative: Fully functional AdminCore deployed in VMware environments.

  • Flexible architecture: Supports hardware, virtual, or hybrid deployments depending on mission requirements.

  • Validated across DoD networks: Successfully deployed on NIPR, SIPR, and JWICS lab environments with all DoD security controls addressed.

  • CCG maintains Secret and Top Secret System Security Plans (SSPs), with all appliance‑related hardware and software documentation, a complete Security Control Traceability Matrix (SCTM), a full Security Test Plan (STP), and comprehensive hardware/software inventory sheets.

Can the solution operate without being installed on existing government-furnished equipment?

Yes. The solution can operate fully without being installed on existing government‑furnished equipment. CheckMate is delivered as a standalone hardware platform. CCG provides both the AdminCore and sensor appliances as TAA‑compliant, purpose‑built systems that require no installation on customer‑owned or government‑furnished equipment. These appliances are designed for rapid, low‑impact deployment and have already been successfully fielded across NIPR, SIPR, and JWICS lab environments.

The platform is also engineered to meet stringent Department of Defense cybersecurity requirements. CheckMate powered by Phen.AI platform, is STIG‑compliant, consistently scoring around 96%, demonstrating its alignment with DoD hardening standards and secure‑configuration expectations. This high level of compliance ensures the system can be deployed into sensitive environments without adding risk or requiring modification of existing GFE systems. To further support DoD operational workflows CheckMate has been integrated with key enterprise security tools, including:

  • Nessus / ACAS for vulnerability management and compliance scanning.

  • Splunk for SIEM ingestion, correlation, and enterprise‑level visibility.

  • Trellix for endpoint and network security interoperability.

These integrations ensure CheckMate fits seamlessly into existing DoD cybersecurity architectures while maintaining its independence from GFE hardware including:

  • No installation on GFE is required.

  • TAA‑compliant AdminCore and sensor hardware are provided.

  • Successfully deployed on NIPR, SIPR, and JWICS lab networks.

  • STIG‑compliant with consistant 96% scores.

  • Integrated with ACAS (Nessus), Splunk, and Trellix for DoD alignment.

Does the solution require full, continuous packet capture (PCAP) for its core functions?

No. The solution does not require full, continuous packet capture (PCAP) for its core functions.  
CheckMate’s sensors gain visibility by connecting to SPAN ports at key network locations. This provides the necessary traffic observation without requiring the system to capture, store, or process full PCAP data. PCAP is not used or needed for core operations.

Instead, the sensors perform Deep Packet Inspection (DPI) in real time, extracting only the relevant metadata, behavioral indicators, and threat signals as the bits move across the wire. The system does not store raw packets or write packet data to disk. It observes traffic, analyzes it on the fly, and immediately discards the raw bits after inspection.

The enriched intelligence generated by DPI is then securely transmitted to the AdminCore, using secure data channels, where it is correlated with historical insights, cross‑sensor intelligence, and updated detection logic that is redistributed to all sensors.

Strategic sensor placement is key.  
Because defense systems and assets can appear or disappear dynamically, sensors must be positioned close to the systems they protect. Proximity ensures maximum visibility into traffic patterns and allows sensors to engage with active systems at the right moments, without requiring full PCAP retention.

CheckMate does not depend on any single data source.  
While PCAP can be useful in specific investigations, it is not required for CheckMate powered by Phen.AI’s core capabilities. The platform is designed to combine multiple lightweight data sources, flow data, DPI‑derived indicators, alerts, inferences, correlations, summaries, conclusions, trends, patterns, behavioral indicators, and cross‑sensor intelligence. When these sources are fused, Phen.AI becomes significantly more accurate and context‑aware, enabling high‑fidelity detections without the burden of full packet capture. Key points include:

  • Full, continuous PCAP is not required.
  • The system does not capture or store packet bits on disk.
  • Sensors perform real‑time DPI as traffic moves across the wire.
  • SPAN‑port visibility + DPI provides the necessary intelligence.
  • Sensors send enriched insights, not raw packet captures, to AdminCore.
  • Strategic sensor placement maximizes visibility without heavy data collection.
  • Phen.AI thrives on combined, lightweight data sources to deliver high‑fidelity detection.

How does the solution leverage NetFlow and similar network metadata for threat detection and analysis?

CheckMate powered by Phen.AI makes extensive use, but is not reliant, on NetFlow and similar network‑metadata sources to enrich high‑fidelity threat detection, behavioral analysis, and long‑term intelligence development. The system continuously collects NetFlow data from strategically placed sensors that observe traffic through SPAN ports at key points in the network, prioritizing the areas with the highest threat exposure. This ensures broad visibility with minimal operational impact.

Once collected, the flow data is analyzed locally on the sensor to extract meaningful indicators about infrastructure behavior, communication patterns and potential anomalies. These distilled insights are then sent to the AdminCore, where they are correlated with historical patterns, cross‑sensor intelligence, and anonymized threat signals from other environments.

NetFlow’s low storage cost is a strategic advantage in providing Phen.AI the ability to look back in time and maintain an understanding of network history. NetFlow is lightweight and inexpensive to retain. CheckMate powered by Phen.AI can maintain long‑term historical visibility without requiring massive storage infrastructure. This allows the system to:

  • Reconstruct past events to understand when and where a newly discovered threat first appeared.

  • Identify subtle, slow‑moving, or low‑and‑slow adversary behaviors.

  • Build richer behavioral baselines over time.

  • Detect long‑term trends and infrastructure misuse that would be invisible in short‑retention systems.

Phen.AI uses this historical flow intelligence to deepen its understanding of threat presence, propagation, and recurrence. When a new threat or indicator is identified, Phen.AI can immediately search historical NetFlow patterns to determine whether the threat has been active previously, how it moved, and what systems may have been affected. To conclude:

  • Sensors collect NetFlow via SPAN ports at high‑value network locations

  • Flow data is analyzed for behavioral intelligence and sent to AdminCore

  • AdminCore correlates flow insights with historical and cross‑environment intelligence

  • NetFlow’s low storage cost enables long‑term retention and future‑focused analysis

  • Phen.AI uses this data to detect threats, understand their history, and identify patterns that would otherwise remain hidden.

What is the strategy for simultaneously querying and correlating data from Microsoft Sentinel (Azure) and ELICSAR BDP (AWS)?

CheckMate powered by Phen.AI’s strategy for simultaneously querying and correlating data from Microsoft Sentinel (Azure) and ELICSAR BDP (AWS), is built around Phen.AI’s ability to act as an intelligent intermediary between on‑premise CheckMate data and cloud‑native security platforms. The platform is designed to integrate flexibly with both Azure and AWS environments, enabling Phen.AI to gather alerts, query APIs, and correlate cloud‑sourced telemetry with CheckMate’s sensor‑derived intelligence.

Azure / Microsoft Sentinel Integration

CCG is actively deploying CheckMate with Azure integration today. The AdminCore is granted a controlled account within the Azure tenant, allowing Phen.AI to:

  • Authenticate into Azure.

  • Access the Sentinel console.

  • Query application logs, security alerts, and telemetry.

  • Pull relevant threat data for correlation with CheckMate findings.

Microsoft provides a Python SDK for the Microsoft Graph API, which Sentinel uses for programmatic access. When API credentials are supplied through the CheckMate “Options” configuration, Phen.AI can directly query Sentinel for:

  • Alerts

  • Incidents

  • Log Analytics data

  • Threat indicators

  • User and device activity

This requires an elevated Azure role (typically an admin‑level service principal) to authorize API access.

AWS / ELICSAR BDP Integration

ELICSAR BDP (AWS) exposes multiple API paths via ElasticSearch/OpenSearch, cloud‑native logging services, and security event feeds that Phen.AI can use to retrieve alerts and metadata. Phen.AI can ingest:

  • Syslog‑forwarded alerts

  • Email‑based notifications

  • API‑queried threat events

  • OpenSearch/ElasticSearch log data

This allows Phen.AI to correlate AWS‑sourced threat indicators with CheckMate’s on‑premise sensor data, even when the cloud environment is isolated or segmented.

Phen.AI as the Correlation Engine

Regardless of whether alerts originate from Azure Sentinel or AWS ELICSAR BDP, Phen.AI can:

  • Interpret incoming alerts (email, syslog, API, or log feed).

  • Query cloud APIs for additional context.

  • Cross‑reference cloud events with CheckMate’s collected network, flow, and behavioral data.

  • Build a unified investigation picture across on‑premise and cloud environments.

Phen.AI does not require full log ingestion from cloud systems, but it can absorb cloud logs if deeper or faster correlation is desired.

Flexible Integration Paths

CheckMate supports multiple integration mechanisms depending on mission needs and cloud architecture:

  • HIDS log ingestion

  • Syslog or email alert feeds

  • Microsoft Graph API (Sentinel)

  • ElasticSearch/OpenSearch APIs (AWS / ELICSAR BDP)

  • Cloud infrastructure APIs (Azure/AWS)

This flexibility allows CheckMate to operate in highly controlled, segmented, or classified environments while still enabling cross‑cloud correlation. Key takeaways include:

  • Phen.AI acts as the intelligence bridge between CheckMate and cloud security platforms.

  • Azure Sentinel is accessed via Microsoft Graph API using an AdminCore‑configured service account.

  • ELICSAR BDP (AWS) is accessed via syslog, email alerts, or Elastic/OpenSearch APIs.

  • Phen.AI correlates cloud alerts with CheckMate’s on‑premise data to produce unified investigation results.

  • CheckMate supports multiple integration paths.

Can the solution perform cross-cloud investigations without moving or ingesting all data into a single repository?

Yes. The solution can perform cross‑cloud investigations without moving or ingesting all data into a single repository.  CheckMate powered by Phen.AI is built for distributed, multi‑cloud environments where data sovereignty and confidentiality are non‑negotiable. Each sensor operates independently, guided by intelligence from its local AdminCore, allowing investigations to occur in place without requiring large‑scale data consolidation.

In our Small-Medium business (SMB) architecture, sensors reside at separate customer sites, each maintaining strict data separation. Customer findings remain isolated to preserve confidentiality. However, the AdminCore provides a secure, anonymized intelligence‑exchange layer that enables cross‑identification of threats and indicators. Only minimal, high‑value signals, never raw logs, are shared across AdminCore instances. This allows CheckMate, powered by Phen.AI, to correlate threat activity across clouds while respecting data boundaries.

Phen.AI further enhances this capability through intelligent network‑aware data management.

Phen.AI continuously monitors network conditions and usage patterns to ensure that security operations never interfere with mission‑critical workloads. It can automatically throttle bandwidth for inter‑system communications, and users can set a hard upper limit if desired. This ensures that any cross‑cloud intelligence exchange remains lightweight and non‑disruptive.

Phen.AI is designed with two core principles:

(a) mission first

(b) protect the network.

To uphold these priorities, Phen.AI organizes and prioritizes data exchange so that smaller, lighter, and more critical threat indicators move first. Less urgent or larger data transfers are deferred to periods of lower operational impact, ensuring investigations remain effective without degrading mission performance. In summary:

  • No centralized data lake is required.

  • Sensors operate independently across clouds and customer sites.

  • Strict data separation is preserved.

  • AdminCore shares only anonymized, high‑value intelligence.

  • Phen.AI performs cross‑cloud correlation without bulk data movement.

  • Bandwidth is intelligently managed and throttle‑controlled to protect mission operations.

  • Critical threat signals are prioritized; non‑critical data moves only when safe.

Does the solution require the installation of new agents or software on endpoints to be effective?

No. The solution does not require installing new agents or endpoint software to be effective.  CCG was deliberately designed to avoid the operational overhead of deploying “Intelligent Endpoint Shippers” (IES) across an entire environment. The CheckMate platform collects and correlates the telemetry it needs with minimal customer footprint, operating efficiently without endpoint‑level installations.

Phen.AI thrives on data volume and diversity, but it does not depend on pervasive endpoint agents to deliver high‑fidelity detection. Its models extract deep behavioral intelligence from sensor‑only data sources, enabling accurate threat identification and rich contextual understanding without intrusive deployments. The IES’s improve visibility by tracking user activity and events on endpoint systems. This gives Phen.AI richer, real‑time context, allowing it to pinpoint threat origins more accurately and better understand cause‑and‑effect relationships behind suspicious behavior.

IES components remain entirely optional.

For organizations that want deeper visibility on specific high‑value systems, IES can be selectively installed on key infrastructure servers such as DNS, DHCP, Active Directory, or LDAP hosts. This can enhance data richness where it matters most, but it is not required for the platform to function effectively. In summary:

  • No mandatory endpoint software.

  • No need to deploy IES across the environment.

  • Optional IES installation on select critical servers if desired.

  • CheckMate powered by Phen.AI, remains fully effective using existing data sources.

  • Phen.AI’s accuracy increases naturally as more data flows in, without increasing endpoint burden.