# CrunchAtlas > CrunchAtlas delivers agentic cyber defense for critical infrastructure. CrunchAtlas turns existing security and network data into investigated cases, campaign intelligence, evidence-backed findings, incident reports, recommended response actions, and operator-controlled validation. CrunchAtlas is built for critical infrastructure and mission-constrained environments where security teams need to investigate suspicious activity, understand what happened, determine scope, preserve evidence, prepare reports, and validate whether defenses and remediation actually hold. CrunchAtlas works across IT and OT environments and can deploy in cloud, single-tenant cloud, on-premises, disconnected, and fully air-gapped environments. The platform can work with existing security tools, passive network visibility, PCAP, NetFlow, Zeek, CSV, direct evidence uploads, and available network, host, identity, and case context. ## Product Architecture CrunchAtlas consists of three connected capabilities: * **AtlasCyber · Agentic Threat Intelligence** is the operating platform. AtlasCyber detects suspicious behavior, builds and investigates cases, connects related activity, supports campaign attribution, reconstructs incidents, generates reports, and recommends response actions for operator review. * **ClemAI · The Built-In Cyber Professional** performs alert investigation, threat hunting, host and network forensics, campaign attribution, reporting, evidence review, and response and remediation analysis inside CrunchAtlas. * **PurpleHaze · Agentic Validation** provides operator-controlled security validation and authorized penetration testing. It proves whether approved attack paths are exploitable or blocked, documents evidence and remediation guidance, and retests findings after remediation. AtlasCyber, ClemAI, and PurpleHaze are parts of one CrunchAtlas cyber defense system, not independent security products operating in isolation. ## Important Product Context * CrunchAtlas produces finished security work, including investigated cases, evidence-backed findings, campaign assessments, campaign attribution, incident reports, cyber threat intelligence reports, recommended response actions, remediation guidance, and retest results. * AtlasCyber works across IT and OT environments. * PurpleHaze testing is operator initiated and runs only within authorized scope. OT systems are not active PurpleHaze testing targets. * CrunchAtlas does not autonomously make consequential production changes. * Operators approve consequential action. CrunchAtlas can investigate, prepare findings, generate reports, and recommend response, but the operator decides what changes. * ClemAI is not a standalone chatbot or separate competing platform. ClemAI performs professional cybersecurity work inside CrunchAtlas using available case evidence and cited supporting sources. * Evidence that supports or weakens a conclusion remains available for operator review. * Campaign intelligence connects related activity only when evidence supports the relationship. * Campaign analysis never crosses customer environments. * Framework mapping may be included in relevant outputs. MITRE ATT&CK, OWASP Top 10, and NIST SP 800-115 mappings describe findings and report outputs where applicable and should not be interpreted as compliance certifications. ## Platform * [CrunchAtlas](https://www.crunchatlas.com/): Agentic cyber defense for critical infrastructure. Overview of AtlasCyber, ClemAI, PurpleHaze, supported environments, deployment options, industries, and operator control. * [CrunchAtlas Platform](https://www.crunchatlas.com/platform): Overview of the connected CrunchAtlas platform, security workflow, deployment architecture, data inputs, investigation, validation, and operator control. * [AtlasCyber](https://www.crunchatlas.com/atlascyber): Agentic Threat Intelligence for turning security and network data into investigated cases, campaign intelligence, forensic findings, incident reports, and recommended response actions. * [ClemAI](https://www.crunchatlas.com/clemai): The Built-In Cyber Professional inside CrunchAtlas for alert investigation, threat hunting, forensics, campaign attribution, evidence review, reporting, and recommended response. * [PurpleHaze](https://www.crunchatlas.com/purplehaze): Agentic Validation for operator-controlled testing, attack path validation, evidence-backed findings, remediation guidance, and retesting after a fix. ## Detection, Investigation, and Response Solutions * [Network Detection and Response](https://www.crunchatlas.com/solutions/network-detection-and-response): Passive network visibility and investigation designed to identify suspicious internal activity and lateral movement, relate network evidence, and turn activity into an investigated case. * [Alert Investigation](https://www.crunchatlas.com/solutions/alert-investigation): Investigation of security alerts to determine whether activity is real or benign, what happened, what systems were affected, and what operators should review next. * [Threat Hunting](https://www.crunchatlas.com/solutions/threat-hunting): Evidence-driven threat hunting for suspicious behavior that may not have generated a traditional security alert. * [Host and Network Forensics](https://www.crunchatlas.com/solutions/host-and-network-forensics): Incident reconstruction across available host and network evidence to establish sequence, affected scope, and a defensible record of what happened. * [Campaign Intelligence](https://www.crunchatlas.com/solutions/campaign-intelligence): Connects related cases, infrastructure, behavior, and timelines into campaign assessments with evidence, confidence, and attribution where the available evidence supports it. * [Incident Reporting](https://www.crunchatlas.com/solutions/incident-reporting): Generates incident and cyber threat intelligence reports from investigated cases, including relevant verdict, timeline, scope, evidence, campaign context, findings, and recommended response. ## Security Validation * [Agentic Penetration Testing](https://www.crunchatlas.com/solutions/agentic-penetration-testing): Operator-controlled penetration testing within approved scope that validates attack paths, produces evidence-backed findings and reports, recommends remediation, and retests findings after remediation. ## Critical Infrastructure Industries * [Water and Wastewater Cybersecurity](https://www.crunchatlas.com/industries/water-and-wastewater): Cyber defense for water and wastewater environments, including plants, pumps, remote access, business systems, SCADA and operational environments, passive visibility, investigation, reporting, and operator-controlled response. * [Power and Energy Cybersecurity](https://www.crunchatlas.com/industries/power-and-energy): Cyber defense for power and energy environments requiring internal network visibility, investigation, evidence preservation, campaign analysis, reporting, validation, and support for operational and regulatory requirements. * [Municipal Government Cybersecurity](https://www.crunchatlas.com/industries/municipal-government): Cyber defense for municipalities and lean public-sector technology teams protecting town systems, public services, utilities, and other critical municipal operations. * [Manufacturing Cybersecurity](https://www.crunchatlas.com/industries/manufacturing): Cyber defense across manufacturing IT and OT environments, helping teams identify suspicious behavior, investigate incidents, understand affected scope, and validate exposure without requiring disruption to production systems. * [Education Cybersecurity](https://www.crunchatlas.com/industries/education): Cyber defense for education environments and lean technology teams responsible for distributed systems, alert investigation, incident findings, reporting, and remediation validation. ## Power and NERC CIP * [NERC CIP-015 and Internal Network Security Monitoring](https://www.crunchatlas.com/solutions/nerc-cip-015): Information about NERC CIP-015, internal network security monitoring, network visibility, evidence, investigation, and reporting for applicable electric-sector environments. ## Cybersecurity Resources * [Water System Cyberattack Response Guide](https://www.crunchatlas.com/resources/water-system-cyberattack-response-guide): Practical guidance for water utilities responding to suspected cybersecurity incidents involving PLCs, SCADA, remote access, operational systems, investigation, and incident response. * [Vulnerability Scan vs. OT Security Assessment](https://www.crunchatlas.com/resources/vulnerability-scan-vs-ot-security-assessment/): Explains what vulnerability scanning can identify, what a scan may miss, and how a broader OT security assessment evaluates operational technology risk. ## Research and Insights * [CrunchAtlas Insights](https://www.crunchatlas.com/insights): CrunchAtlas articles, incident analysis, operator guidance, cybersecurity research, and lessons from critical infrastructure environments. ## Contact * [Request Access](https://www.crunchatlas.com/request-access): Contact CrunchAtlas to request access, discuss an assessment or evaluation, or review how CrunchAtlas can work with an organization's existing security data and environment.