SOC Prime License provides access to a cybersecurity platform focused on detection engineering, threat detection content, threat intelligence, and threat hunting. SOC Prime helps security teams find, adapt, validate, translate, and deploy detection content across SIEM, EDR, XDR, and data lake environments.
Quick Benefits
- Detection-as-Code content library
- Real-time threat intelligence
- Detection engineering support
- Threat hunting capabilities
- MITRE ATT&CK mapping
- Cross-platform detection translation
- AI-assisted detection engineering
- IOC-to-query generation
- Detection content validation

SOC Prime License At a Glance
What it is: Detection engineering and threat detection intelligence platform
Current platform products: Prime Core, Prime Architect, and Prime Hunt
Former product names: Threat Detection Marketplace, Uncoder AI, and Attack Detective
Primary role: Detection engineering, threat intelligence, and threat hunting
Security areas: Threat detection, detection engineering, threat hunting, SIEM content, IOC analysis, and MITRE ATT&CK
Core technologies: Detection-as-Code, Sigma, AI-assisted engineering, threat intelligence, query translation, and detection coverage analysis
Supported environments: SIEM, EDR, XDR, data lake, and security analytics platforms
Deployment model: Cloud-based platform with integrations to customer security environments
License Overview
A SOC Prime License provides access to selected capabilities within the SOC Prime Platform according to the organization’s detection engineering, threat intelligence, and threat-hunting requirements.
SOC Prime’s current platform is organized into three principal products:
- Prime Core — detection content repository and delivery
- Prime Architect — detection engineering and AI-assisted content creation
- Prime Hunt — threat hunting and detection coverage analysis
These products were previously known as Threat Detection Marketplace, Uncoder AI, and Attack Detective respectively. The current naming should therefore be considered when evaluating a new subscription.
SOC Prime licensing is not simply based on the number of endpoints or servers. The required capabilities, user type, platform integrations, and subscription tier are more important when determining the appropriate configuration.
How SOC Prime Licensing Works
SOC Prime licensing follows the security team’s detection workflow.
A typical process includes:
Threat Intelligence
→ Identify emerging threats, threat actors, IOCs, and attack techniques
Detection Research
→ Search the detection library for relevant rules and detection ideas
Detection Engineering
→ Create, modify, translate, and validate detection content
Platform Adaptation
→ Convert detection logic into the syntax required by the organization’s SIEM, EDR, XDR, or data lake
Deployment
→ Push detection content into connected security platforms
Threat Hunting
→ Use detection and threat intelligence data to investigate potential threats
This workflow allows organizations to connect intelligence with operational detection rather than treating threat intelligence as a separate information source.
SOC Prime Platform Overview
| SOC Prime Solution | Primary Purpose |
|---|---|
| Prime Core | Detection content repository, threat intelligence, search, translation, and content deployment |
| Prime Architect | Detection engineering, AI-assisted rule creation, translation, validation, and IOC-query generation |
| Prime Hunt | Data-driven threat hunting and detection coverage analysis |
| Active Threats | Threat intelligence and detection content related to emerging threats |
| Detection-as-Code Library | Searchable repository of detection rules and algorithms |
| Custom Repositories | Storage and management of organization-specific detection content |
Licensing Options and Models
| Licensing Option | Description | Suitable For |
|---|---|---|
| Personal Access | Free access to selected SOC Prime capabilities, including detection content and limited platform functionality | Individual security professionals and researchers |
| Solo Subscription | Individual subscription providing expanded Threat Detection Marketplace and Uncoder AI capabilities | Independent security engineers |
| Enterprise Subscription | Corporate access to the SOC Prime Platform and its detection engineering capabilities | Enterprise SOC and security teams |
| Prime Core Enterprise | Enterprise access to detection content, threat intelligence, translations, and deployment capabilities | Detection engineering teams |
| Prime Architect Enterprise | Enterprise detection engineering and AI-assisted content development | Security engineering teams |
| Prime Hunt | Threat-hunting capabilities using connected security data | Threat hunters and SOC teams |
| Detection Engineering Service | Managed or service-oriented detection engineering capabilities | Enterprises and MSSP/MDR providers |
| Threat Hunting Service | Data-driven threat hunting services and coverage analysis | Enterprises and managed security providers |
Features and Benefits
Detection-as-Code Library
Prime Core provides access to a large detection-content repository covering security platforms and detection languages.
Security teams can search for detection rules according to:
- Threat actors
- Malware
- CVEs
- MITRE ATT&CK techniques
- Tactics
- Log sources
- Security platforms
- Detection types
This reduces the time required to develop every detection rule from the beginning.
Threat Intelligence
SOC Prime combines detection content with threat intelligence to provide context around active and emerging threats.
The Active Threats capabilities can provide information such as:
- Threat context
- Related IOCs
- Attack techniques
- Detection content
- Behavioral rules
This allows analysts to move from threat information to actionable detection more quickly.
Detection Engineering
Prime Architect provides tools for creating and modifying detection content.
Security engineers can:
- Create detection rules
- Modify existing rules
- Translate detections
- Validate syntax and logic
- Generate hunting queries
- Parse indicators of compromise
Activation and Deployment
A typical SOC Prime deployment includes:
- Select the required platform capabilities
- Create the SOC Prime account
- Choose the applicable subscription
- Configure users and permissions
- Connect security platforms or data planes
- Select required detection repositories
- Configure integrations
- Search or create detection content
- Validate detection rules
- Deploy content to connected platforms
Enterprise deployments can also establish custom repositories for internally developed detection content. For organizations with multiple security platforms, the integration architecture should be planned before deployment so that detection content can be translated and delivered to the appropriate environments.
Pricing and Quote Process
Pricing for SOC Prime License depends on the selected platform capabilities, subscription tier, and organizational requirements.
SOC Prime offers different models for individual users, enterprise organizations, and service providers. Enterprise pricing is generally determined through a sales quotation rather than a single universal public price.
Before requesting a quote, prepare:
- Number of SOC and detection engineers
- Required Prime Core capabilities
- Prime Architect requirements
- Prime Hunt requirements
- SIEM platforms
- EDR/XDR platforms
- Data lake environments
- Number of security integrations
- Threat intelligence requirements
- Detection deployment requirements
SOC Prime pricing depends on your detection engineering requirements, content library access, threat intelligence capabilities, deployment model, license term, and support needs.
