Home › Use Cases › Sort a security team's alert bundles into real incidents
Use caseUC0028

Sort a security team's alert bundles into real incidents

Alerts arrive in bundles that look related, and someone must decide which are real and which belong together. This app calls each alert real or false, groups the real ones into incidents and drafts a containment note for the on-call analyst to approve.

For the security operations deskCross-domain · Retail

Why it matters

Today's manual process, and the same job with the app

A security analyst on shift, working a queue of alert bundles for a retailer or any company's IT team.

✕Today's manual process

1Read every alert in the bundle and its clues: addresses, devices, accounts and files.
2Decide which alerts are real, and which a user has already explained away.
3Decide which real ones are one incident, then write the containment note.
4One wrong merge hides a second break-in behind the fix for the first.
Every bundle read and written up manually

✓With the app

1Each alert is read on its own clues, not on how calmly it is worded.
2Each alert is called real or false, so a polite phishing report is still caught.
3Real alerts are grouped into incidents on real links, not a shared address alone.
4One containment note per incident cites a real clue and waits for the on-call analyst to approve it.
The analyst approves every containment step

See it work

One real alert bundle: what the app reads, step by step

Account bcollins is broken into after 18 failed logins, while cbennett logs in from the same address during a conference trip.

Sort a security team's alert bundles into real incidentsReference appBuilt to be shaped to your process
  1. 1The first alert a login that worked right after a string of failed ones.
  2. 2The break-in 18 failed tries on the same account, from the same address.
  3. 3A third login a different user, who confirmed a conference trip by phone.
  4. 4What does not count one shared address alone does not make these one incident.

For engineers

How it is built, and how we measured it

All fourteen steps of the build are written up, from the business case to running it in your own environment.

Kit overview →
82 of 82alerts called real or false correctlymeasured in 06 Evals →
0 of 52real threats missedmeasured in 06 Evals →
0 of 47unrelated alert pairs wrongly mergedmeasured in 06 Evals →
0.55¢to check one alert bundlemeasured in 07 Unit cost →

The build, step by step

14 steps

Make it yours

What you see is a reference app. We shape it to how you work.

Every part of it is built to change, and none of it means starting over.

Your rulesWhat counts as real, what links two alerts, and who approves containment.
Your recordsYour alert history, asset list and the notes analysts already keep on each case.
Your systemsReads from your alert queue; drafted notes land in your ticketing tool for approval.
Your screensThe fields, alert names and wording your security team already uses.

Want this for your team?

Talk to us

We can run this on your own alert queue, with your own rules, inside your environment.

Talk to us →
A living map of modern AI — kept current every morning