Nebulock Helix

Just-in-time enrichment that connects Nebulock's agents to the security tools you already run

Nebulock Helix connects Nebulock's agents to the security tools you already run, so they can query and reason over that data on demand — at the exact moment an investigation, detection, or hunt needs it. That includes Vespyr running an autonomous hunt, and it includes you, mid-investigation, asking a question yourself.

Unlike Data Ingestion integrations, Helix does not stream data into the Nebulock platform. Nothing is pre-ingested, indexed, or stored. Helix queries the authoritative system directly when it's relevant, and folds what comes back into the finding.

How Helix is used

Hunt-led. A hunt built from an actively-exploited CVE's TTPs flags a host showing that behavior. Before the finding reaches you, the agent queries your vulnerability scanner to check whether the host is actually vulnerable to that CVE — escalating likely active exploitation, or routing unaffected hosts to standard triage.

Operator-led. You're investigating a host and want its patch status as part of your workup. Ask Nebulock in plain English — "are any of my assets vulnerable to CVE-2026-XXXX" or "what devices have nginx installed" — and Helix translates that into the right query for your VM tool. No pivoting to the scanner console, no learning its query syntax.

Intel-led. A threat intel brief describes a CVE under active exploitation. Paste the URL into Nebulock, and Helix queries your VM tool to determine which hosts are actually vulnerable — before a single hunt query runs. The hunt is then scoped to exactly those hosts.

Supported providers

Helix launches with just-in-time enrichment for vulnerability management platforms:

ProviderSetup guide
CrowdStrike Spotlight / Exposure ManagementSetup guide
Rapid7 InsightVM (beta)Setup guide
Tenable Vulnerability Management (beta)Setup guide
Qualys VMDR (beta)Setup guide
Axonius (beta)Setup guide
Microsoft Defender Vulnerability Management (beta)Setup guide
Iru (beta)Setup guide
Wiz (beta)Setup guide

Helix will expand to cloud, network, and other systems that hold context worth pulling into a hunt.

Where enrichment appears

Helix enrichment is available in both Hunt and Investigate. Findings enriched by Helix include the vulnerability context inline. For example, whether a flagged host is vulnerable to the CVE a hunt is scoped to.


Did this page help you?