COBRA² detection: rules that respect your stack
COBRA² (Correlated Observation-Based Risk Assessment) is Dual-Strike XISEM’s detection engine. It sits above raw telemetry: agent harvests, browser sessions, identity events, EDR exports, and PSA signals feed rules that fire only when the story matches.
Route: Threat Center · Settings → Detection policies
What COBRA² is (and isn’t)
• Evidence-correlated rules — A replacement for your EDR
• Tunable per client org — Autonomous blocking
• Linked to compliance controls — A SIEM log dump
• PSA-ticket aware — Generic syslog regex only
Rule categories MSPs use first
1. Identity drift — stale admins, impossible travel patterns (when the Entra Gateway is enabled)
2. Shadow AI / unsanctioned SaaS — from Browsing Insights categories
3. Posture regression — ASPIRE pillar drop after patch Tuesday
4. FIM-class changes — hosts file, scheduled tasks (agent + platform)
5. Integration gaps — EDR agent missing on managed asset
Tuning workflow (field-tested)
1. Enable browsing + agent on a pilot client before turning on aggressive rules
2. Start rules in learning mode where available — review volume for one week
3. Map high-value rules to PSA boards so technicians see context in the ticket body
4. Tie recurring findings to compliance controls for vCISO reporting
Evidence in every detection
When a COBRA² detection opens, the analyst sees:
• Source signals (which Gateways contributed)
• Affected assets and identities
• Related browser sessions or sign-ins when applicable
• Suggested remediation links (wiki / runbook paths in console)
Pair with Threat Center
Threat Center is your triage queue: severity, assignment, investigation pivot, PSA create/close sync. COBRA² produces; Threat Center operationalizes.
Next read: Browsing Insights field guide · Shadow AI signal post · dual-strike.com/downloads
Rule names and internal engine codenames are omitted — configure in-console per client.


