GREYCORTEX Mendel 5.0
See what’s urgent. Understand why. Decide faster.
Mendel 5.0 gives your security teams what matters most: understanding.
Instead of working through endless alerts, your analysts can see which device needs their attention, understand what it is doing, and know what to do next. Risk score, the Traffic flow map, and the AI Assistant work together to reduce investigation time and enable fast and confident decisions.
Live webinar
26 August ▪ 10:00 CEST
PRIORITY ->
Know which device to check first
Every investigation starts with the same question: Where do I begin? A screen full of critical alerts rarely provides the answer. Everything looks equally urgent, and a device whose risk has increased overnight just blends in with devices that have been showing minor issues for months. The new Risk score gives every device one score based on its behavior over time, making real priorities clear.
-> Where should I start today?
Every device is ranked by real risk so you know where to begin.
-> Is this device getting worse?
Mendel tracks the risk score over time, so any device heading toward high risk stands out immediately.
-> What is driving this score?
The risk score is based on the security events involving the device, and how unusual its behavior is compared with other devices on the same network.
CONTEXT ->
See who a device is talking to, in one view
When a device looks suspicious, the next question is: What is it doing? Finding the answer often means switching between multiple views and trying to manually connect the dots. The Traffic flow map brings it into one view: the device with every connected system and how much traffic is flowing in each direction.
-> What is this device doing?
One click shows you the device and its most important communication partners on a single map.
-> Which connection should I look at?
The map highlights the strongest communication by the metric you choose: flows, packets, data volume, retransmissions, or unreplied flows.
-> Where does the problem lead?
Open any device on the map to reveal its own connections and follow the trail from one device to the next without leaving the map.
Want to see it live?
26 August ▪ 10:00 CEST ▪ 60 min
UNDERSTAND ->
Turn security data into clear answers
Security data is full of technical details, and making sense of it often needs an experienced analyst. What is this device? Is this IP address malicious? Does this event require attention? The AI Assistant answers these questions in plain language, directly in the interface. When a decision is needed, it takes a position.
-> What is this device?
The Assistant identifies the likely role of any internal device, server, workstation, printer, camera, PLC, medical device, from the data Mendel already has.
-> Is this external IP dangerous?
The Assistant gives a clear verdict on every external address, from malicious to benign, with a brief explanation of why.
-> What does this event mean?
The Assistant explains the security events in plain language: what happened, why it matters, and the recommended next step.
Investigate the event
Your analyst can dig into one event and get a full assessment: whether it’s a real threat and what to do about it.
-> Is this a real threat?
The Assistant gives you a verdict on whether the threat is real, evaluates its severity, and explains the reasoning behind its assessment.
-> Could this be a false positive?
The Assistant tells you how likely the event is a false positive, and why.
-> What should I do first?
The Assistant gives you investigation steps in priority order, specific to this host and this event.
-> What if the activity is actually allowed?
When an event is legitimate, the Assistant can suggest a narrow exception, so the same alert stops repeating.
Built for European infrastructure
Powerful security tooling shouldn’t cost you the control of your data. Mendel 5.0 is built to meet the requirements of European critical infrastructure.
- AI processing runs within EU infrastructure and can be disabled entirely.
- Mendel itself runs on-premises, including fully air-gapped deployments.
- Tag and risk history give you the audit trail regulators ask for.
- Identity context comes from Active Directory, Cisco ISE, and Microsoft Entra ID.
See it for yourself: Mendel 5.0 in practice
Join our live session to see the new features solving real security investigations.
26 August ▪ 10:00 CEST ▪ 60 min