newWe just got even fanciersee why ↓
v11.25 · enterprise license · 4,000+ detection rules

One enterprise SIEM stack.
The end of the volume-based SIEM tax.

Land your security data as OCSF Parquet on any S3-compatible storage. Query it in seven languages, SPL, SQL, KQL, Sigma, PromQL, natural language, or the native Caver UI, over one lake you own. Caver is the enterprise SIEM you run on top: no per-GB ingest tax, no proprietary tsidx format, no vendor lock-in on storage.

how it fitslive · streaming queries in <800ms p95
SEND FROM ANYWHERE
caver-collector
Vector pipelines
OTel Collector
Splunk UF / HEC
Splunk S2S
Syslog · Kafka · OTLP
70+ SaaS APIs
OCSF Parquet
on any S3-compatible storage
MinIO · S3 · GCS · Azure · R2
your bucket · your keys · open format
QUERY WITH ANYTHING
Caver UI
SPL
SQL
KQL
Sigma
PromQL / Grafana
Natural language (MCP)
ingest
21 receivers
HEC · S2S · Syslog · OTLP · Kafka · 70+ SaaS
storage
OCSF Parquet
S3 · MinIO · R2 · GCS · Azure
query with
7 languages
SPL · SQL · KQL · Sigma · PromQL · NL · UI
per-GB ingest
$0
flat per-deployment license

Five layers. One lakehouse.

What used to require a stack of separately licensed products, SIEM, detection, service monitoring, UBA, and SOAR, and the licenses that come with all of them. Caver ships it as one integrated commercial stack reading and writing one OCSF Parquet bucket.

Caver

SIEM core: a multi-language query engine on OCSF Parquet, plus operator console + scheduler.

Query in SPL, SQL, KQL, Sigma, PromQL, or natural language. Federates with most search tools, Splunk, Elastic, Sentinel, and more, and the search head you already run treats it as a native indexer.

/ui/home · caver v11.25
index=auth status=failure | stats count by user1.8 GB · 220ms
alice52
bob3
─ remote_caver_lake returned in 198ms5 rows
SLAM

SOAR + case management.

Notables, operator-editable YAML playbooks, case management, signed PDF exports, plus Telegram/Slack/Teams oncall.

POST /api/slam/notables
{ "rule": "brute-force",
  "severity": "high",
  "entity": "alice" }
CAVERN

Enterprise Security: risk-based alerting + ATT&CK coverage.

123 content packs, 100% SigmaHQ mapped, Detection IDE with live backtest. Per-rule risk contributions, ATT&CK-tagged aggregation.

ECHO

ITSI-equivalent: service tree, KPIs, propagated health, NEAP episodes.

A KPI is just SPL + thresholds. Episodes assemble on cron and surface in the analyst queue.

checkout.payments CRIT
├─ stripe-adapter OK
├─ payments-api WARN
└─ db-prod01 CRIT ← propagates
UBA

Per-entity baselines. Multi-anomaly threats promoted to your queue.

65+ unsupervised models, no labelled training data. Off-hours bursts, beaconing, lateral movement.

3.2σ peak z-score
1 threat promoted
80 users baselined
INSTALL

Every common deploy path. Pick the one that fits your stack.

From bare-metal Helm to one-click cloud templates, the deployment surface is documented and runnable end-to-end on every target below, including a .spl that registers Caver as a search peer of your existing search head (Splunk, for example). Enterprise license includes installer access for all targets.

Helmenterprise registryTTerraformawsTTerraformgcpTTerraformazureDDockercompose --profile demo upRRenderRRailwayFFly.ioSSplunk SHcaver-peer.spl
evidence locker

Forensic-grade chain of custody. Built in, not bolted on.

SLAM gives every incident a tamper-evident evidence locker. The bytes you collect during an investigation are cryptographically pinned and provably unchanged from upload to export, the kind of custody your legal team asks for, that almost no SIEM ships.

SHA-256 · HMAC-signed audit · tamper-evident · signed PDF

1

SHA-256 per artifact

Every file attached to an incident is hashed on upload, with uploader and timestamp recorded.

2

Re-verified on every read

The hash is recomputed on each fetch. If a stored byte ever diverges, the download is refused, not silently served.

3

HMAC-signed audit trail

Every upload, download, verify, and delete is signed, so who-touched-what-when cannot be quietly rewritten.

4

Court-ready exports

One click produces a signed PDF of the full case: timeline, evidence, and custody record intact.

what's new

Beyond the five layers. The companion products.

The core stack consolidates your SIEM, detection, service-monitoring, UBA, and SOAR tools into one platform. These ship alongside it, reading and writing the same OCSF Parquet lake: the data pipeline that feeds it, the AI-security layer, the agent + orchestration surface, and the OT/ICS plugin.

caver-collector

The security data pipeline. Three equally-featured backends.

Python for orchestration and complex normalisation, Vector (Rust) for high-throughput hot paths, and an OpenTelemetry distro for shops already running OTel. Drops the universal-forwarder dependency.

21 receivers44 transform + normalise22 sinks70+ SaaS adaptersv1.175
ai observatory

The deepest AI / LLM security coverage in the industry.

24 dedicated content packs and 200+ purpose-built CAVERN rules across the full AI threat surface: prompt injection, shadow AI, agent-framework abuse, vector-DB exfiltration, and supply-chain compromise. No DLP agent required.

24 AI content packs200+ detection rulesOCSF 6005agentless
intelligence & ai

Full platform surface exposed to AI agents over MCP.

Connect Claude Desktop, Claude Code, or any MCP client and run SPL/SQL/KQL, search CAVERN rules, pull notables, trigger playbooks. A Claude-powered orchestrator turns plain-language requests into config, rules, and backtests.

MCP server13 orchestrator primitives7 query languages
Caver industrial

OT / ICS plugin with native Dragos + Claroty integration.

Extends the platform to operational technology: IT/OT correlation, asset discovery, and protocol-aware detection normalised into the same CAVERN pipeline as your IT telemetry. Per-deployment pricing.

BACnetDNP3ModbusIEC 104S7CommEtherNet/IP
caver forge

AI that writes and tests your detections, from a CVE or a sentence.

Describe a threat, or point Forge at a freshly published CVE, and it authors a CAVERN rule grounded in your actual OCSF lake schema, transpiles it to SPL, and backtests it against your history to confirm it fires (and at what false-positive rate) before a human ever sees it. It collapses 'CVE published' to 'working detection' from weeks to minutes. You promote to production; Forge does the grind.

CVE → detection in minutesgrounded in your schemaauto-backtestedhuman-approved to prod
supported technologies

121+ integrations. Every one OCSF-normalised.

Out-of-box coverage across 11 categories. Every integration ships a caver-collector receiver or adapter and at least one CAVERN content pack with detection rules tuned to the source's event shape.

121+integrations
11categories
100%CAVERN-mapped
OCSFnormalised output

Cloud platforms

12
AWSMicrosoft AzureGoogle CloudCloudflareDigitalOceanLinodeVercelNetlifyFastlyHashiCorpTerraformKubernetes

Identity & SSO

10
OktaAuth0JumpCloudDuo SecurityOneLoginKeycloakBitwardenAzure AD / EntraGoogle WorkspacePing

Productivity & collaboration

12
Microsoft 365SlackMicrosoft TeamsZoomCisco WebexMattermostDiscordIntercomBoxDropboxNotionAsana

Developer & DevOps

14
GitHubGitLabJiraConfluenceCircleCIBuildkiteLaunchDarklySnykLinearTinesPostHogSysdigMongoDB AtlasSnowflake

EDR & endpoint

10
CrowdStrikeSentinelOneMicrosoft DefenderCarbon BlackTrend MicroWazuhClamAVYARAFalcoosquery

Network & perimeter

11
TailscaleCloudflare Zero TrustCisco MerakiCisco UmbrellaFortinetPalo Alto NetworksIvantiCitrixSuricataZeekWireshark

Cloud security

8
WizLaceworkTenableSysdig SecureMicrosoft SentinelAWS GuardDutyAWS SecurityHubTrivy

AI & LLM

12
OpenAIAnthropicMicrosoft CopilotAmazon BedrockAzure OpenAIGoogle Vertex AIHugging FaceLiteLLMPortkeyLangFlowOllamaLM Studio

OT / ICS

7
DragosClarotySiemensRockwell / Allen-BradleySchneider ElectricABBHoneywell

Sales, CRM & support

15
SalesforceHubSpotStripeShopifyZendeskServiceNowPagerDutyTwilioSendGridPostmarkMailgunMimecastAtlassian StatuspageOpsgenieDatadog

Observability & analytics

10
SplunkGrafanaPrometheusElasticKibanaLokiOpenTelemetryVectorApache KafkaConfluent

Already have a search head you love? Keep it.

Caver registers as a peer on most search tools (Splunk, for example), so your existing dashboards, saved searches, and correlation rules keep running unchanged against the OCSF lake. Federation modes ship for Elastic / Kibana, Microsoft Sentinel, Sumo Logic, Datadog, and growing.

Don't see a tool you rely on?

Suggest it and we'll scope it. New integrations land as a caver-collector receiver plus a CAVERN content pack, typically inside a single release cycle.

Request an integration →

Several ways to adopt.
Take all of it, or any one piece.

Caver is modular. Migrate fully, run it in parallel during a transition, or just drop in the collector to trim or enrich what your existing SIEM ingests. Any single layer stands on its own and augments the SIEM you already run.

1

Full migration

Point caver-migrate at your legacy SIEM and it ports the lot in one command: dashboards, saved searches, scheduled alerts, correlation and risk rules, service trees + KPIs, behavior models, and SOAR playbooks, each mapped onto the matching Caver layer.

  • Day one your SOC opens the same dashboards and runs the same queries, on Caver, on your storage.
  • Auditable: --dry-run prints a full coverage report before --apply touches anything.
  • Every migrator is tested end-to-end before it touches your data.
$ caver-migrate --apply-all
2

Run in parallel

Stand Caver up beside what you already have. It registers as a peer on most search tools (Splunk, for example) and federates with Elastic, Sentinel, and more, so existing dashboards and correlation rules keep running, now against your OCSF lake. New data lands in the lake instead of the indexer tier.

  • Forwarders unchanged: they tee to Caver, or speak their native protocol directly.
  • Search head unchanged: the peer app drops in via the standard install flow.
  • Object storage runs roughly 10× cheaper than indexer storage at the same retention.
federate > add Caver as a search peer
3

Just the collector

Not ready for the full platform? Run only caver-collector. Its 21 receivers and 44 transforms sit in front of your existing SIEM to filter, route, and OCSF-normalise, cutting ingest volume or enriching events before they land.

  • Trim noisy, low-value data before it hits your per-GB ingest tier.
  • Enrich, reshape, and fan out to multiple destinations at once.
  • Vector (Rust) hot path, an OTel distro, or Python, your choice of backend.
$ caver-collector up
4

Any single layer

Every layer stands alone. Add CAVERN detections, ECHO service monitoring, UBA, or SLAM case management one at a time, against the same OCSF lake, to assist or extend the SIEM you already run.

  • Adopt incrementally: no big-bang cutover required.
  • Each layer reads and writes the one OCSF Parquet lake you own.
  • Mix and match alongside your legacy SIEM for as long as you like.
pick a layer > CAVERN · ECHO · UBA · SLAM

Frequently asked.
Probably what you came here to know.

If your question is not here, the answer is almost always in the docs.

Commercial. Caver is closed-source proprietary software, delivered as binaries plus a commercial license in the same shape as every other commercial SIEM in this market. Source is not publicly distributed. Historical note for the record: Caver v0.1 was released publicly under the MIT License on 2026-05-13 to validate the architecture, and that v0.1 grant is permanent and irrevocable for anyone who obtained the v0.1 code under it; active development has since moved to a private commercial codebase. Full transition explainer at /caver/transition/. Contact [email protected] for evaluation access and license terms.

The whole legacy SIEM stack, consolidated onto one OCSF Parquet lake you own. Caver is the query and analytics core, a multi-language engine speaking SPL, SQL, KQL, Sigma, PromQL, and natural language. CAVERN delivers detection engineering and risk-based alerting with full MITRE ATT&CK coverage and 123 content packs. ECHO gives you service trees, KPIs, and episode correlation. UBA runs 65+ behavioral models. SLAM handles SOAR, playbooks, and case management. Five integrated layers, plus an AI-security observatory and a collector pipeline, so you can retire whichever legacy products you pay for today, Splunk, Elastic, Sentinel, or others, and run it all on storage you control.

No. Caver speaks the languages your team already knows. Address the same OCSF lake in SPL, SQL (via DuckDB, Trino, or Athena), KQL (Sentinel-compatible), Sigma (the full SigmaHQ corpus transpiles), PromQL through Grafana, or plain natural language over MCP, and the native Caver UI routes each to the right engine. Existing dashboards, saved searches, and correlation rules keep running unchanged. Seven interfaces, one lake, zero re-training.

Yes. Caver slots into the stack you already run, no rip-and-replace. Splunk: yes, it registers as a distributed-search peer so existing dashboards, saved searches, and correlation rules keep running against your OCSF lake. Elastic / Kibana, Microsoft Sentinel, Sumo Logic, and Datadog: yes, via federation modes. New data lands in your OCSF lake instead of an expensive indexer tier, and any licensing change with a tool you keep is made through that vendor per your existing contract. Running something not named here? Ask, integrations land as a caver-collector receiver plus a CAVERN content pack, typically within a release cycle.

OCSF Parquet on any S3-compatible storage: AWS S3, MinIO (self-hosted), Google Cloud Storage, Azure Blob, Cloudflare R2. Your bucket, your keys, open format. Same files are also queryable by Trino, DuckDB, AWS Athena, AI agents, no proprietary file format gates you in.

Two cost lines disappear: the per-GB ingest license (the biggest line item in most legacy SIEMs) and the indexer storage tier (replaced by roughly 10× cheaper object storage at the same retention). For an org ingesting hundreds of GB/day, that's typically six to seven figures annually, before you count the consolidation of detection, ITSI, UBA, and SOAR into one platform.

Yes, end-to-end. CAVERN ships RBA contributions per detection rule, tactic-spread and source-diversity aggregators, identity and asset risk-factor multipliers (admin 2×, crit-prod 1.875×, service-account 0×), and per-entity timelines. ATT&CK technique and tactic tags propagate from rule to contribution to aggregation.

Tagged v11.25 and running in real deployments. 123 CAVERN content packs and 4,000+ detection rules ship today, with migrators covering dashboards, saved searches, correlation rules, service trees, behavior models, and SOAR playbooks end-to-end. Treat the version number seriously and follow the docs runbook before standing up critical SOC workflows.

Request evaluation access and we'll set up a short intro call to understand your environment (current SIEM, storage tier, on-prem vs. cloud), then ship a time-bound evaluation installer. Prefer to dig in first? The full technical docs are linked below.

Caver · v11.25Replace your legacy SIEM on your own stack.
see pricing →MIT → commercial: what changes →
Content packs123
Detection rules4,000+
Integrations121+
per-GB ingestGone