Security alert review
Network security alerts sorted and escalated
How a run goes
The steps this agent takes, in order, and what each one leaves behind.
Reads the alert stream and the asset inventory
Triages security alerts from the network and the signaling layer against known patterns and the asset inventory
Correlates alerts and applies the triage rules
Groups related alerts into one case and drafts the first analysis with the affected elements
Opens the case or logs the closure
Escalates the cases that match an active threat and closes the noise with the reason logged
Works in

Splunk, ServiceNow, PagerDuty
What it does
- Triages security alerts from the network and the signaling layer against known patterns and the asset inventory
- Groups related alerts into one case and drafts the first analysis with the affected elements
- Escalates the cases that match an active threat and closes the noise with the reason logged
Connects to
Need it to work differently?
Every agent can be changed: the steps it takes, the systems it uses and who approves what.