Description
PocketSOC puts your security operations center in your pocket. Get real-time alerts from CrowdStrike, Microsoft Defender, and AWS GuardDuty -- and respond to threats without opening a laptop.
BUILT FOR SECURITY TEAMS ON CALL
When a critical detection fires at 2 AM, you need to act fast. PocketSOC delivers push notifications straight to your phone with alert details, severity, and one-tap access to take action. Acknowledge, investigate, and contain threats from anywhere.
MULTI-VENDOR, ONE APP
Connect CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, and AWS GuardDuty -- all in a single view. No more switching between vendor consoles. PocketSOC normalizes alerts across your stack so your team gets a unified picture.
RESPOND, DON'T JUST READ
PocketSOC is not a read-only dashboard. Take real action:
- Isolate and release compromised hosts (CrowdStrike, Defender)
- Update alert status, assign to analysts, add comments
- Archive and manage GuardDuty findings
- View full detection details with deep-linked navigation
SMART NOTIFICATION ROUTING
Not every alert needs to wake the whole team. PocketSOC supports:
- On-call schedules so off-duty analysts are not disturbed
- Group-based routing to target the right team for each vendor
- Webhook integration for flexible alert delivery pipelines
ENTERPRISE-GRADE SECURITY
- Vendor credentials encrypted at rest (AES-256-GCM) and in transit
- Authentication via passkeys, MFA, or enterprise SSO
- Role-based access control (Admin, Member, Viewer)
- Full audit logging of all actions
- iOS Keychain protection for on-device secrets
TEAM MANAGEMENT PORTAL
Manage your entire security team from portal.pocketsoc.com:
- Invite team members and assign roles
- Create groups with vendor-specific configurations
- Register and manage devices across your organization
- Configure webhooks and on-call schedules
- Monitor audit trails and API keys
SUPPORTED VENDORS
- CrowdStrike Falcon (detections, containment, assignment)
- Microsoft Defender for Endpoint (alerts, machine isolation)
- Microsoft Defender for Cloud (alerts, status management)
- AWS GuardDuty (findings, archive management)
- More vendors on the roadmap
PocketSOC is an independent product and is not affiliated with, endorsed by, or sponsored by CrowdStrike, Microsoft, or Amazon. All trademarks are property of their respective owners.
Nouveautés (v1.6.1)
PocketSOC 1.6.0 introduces Personal Use mode — a new way to monitor your own security environments directly from your phone, without a portal or organization setup.
NEW: Personal Use Mode
Connect your own vendor API keys (CrowdStrike, Microsoft Defender, Defender for Cloud, AWS GuardDuty) directly inside the app.
• No portal required
• No team admin required
• Credentials stay in the iOS Keychain
• No PocketSOC server ever receives Personal Use credentials
• Optional iCloud Keychain sync across your Apple devices
Perfect for consultants, researchers, home labs, and small-team operators who want a lightweight mobile pane of glass.
Trial & Subscription
• 7-day free trial (no credit card required)
• $4.99/month or $49.99/year via the App Store
• Cancel anytime from inside the app or iOS Settings
Real detections only - no sample data and no feature gating.
Mode Selection Improvements
Choose your workflow on first launch:
• My Organization (existing portal flow)
• Personal Use (new local-only mode)
• Try Demo (no credentials required)
Switch modes anytime from Settings. Switching securely clears local credentials and cached detection data.
New WeaveHub Brand System
PocketSOC now ships with an updated navy-and-gold visual system:
• Improved light and dark mode surface hierarchy
• Updated typography across the entire app
• Cleaner severity presentation and detection lists
• Consistent visual identity across all screens
Improved Launch Experience
A new branded launch animation provides a smooth transition from app icon to interface with no visual flash between system launch and app content.
Subscription Management Improvements
Manage your subscription directly from inside Settings:
• View renewal status
• Cancel or reactivate plans
• Switch between monthly and annual options
• Clear status messaging synced with App Store subscription state
Security & Reliability Improvements
• Rebuilt credential storage layer for improved iCloud Keychain compatibility
• Fixed repeated Face ID prompts during detection refresh in some configurations
• Added migration logic to clean up legacy keychain access settings
• Additional stability and performance improvements across detection views and profile management
Coming Next
• Additional dashboard polish updates