A case, not a ticket
bolted onto a SIEM.
Alerts triage to cases, cases carry observables and tasks, and an SLA worker escalates the ones going stale without anybody remembering to check. It reads like the issue tracker your team already uses, because that is the interaction people actually know.
Cases in a familiar shape. Key, status, severity, owner, age.
Alerts arrive already scored and deduplicated.
A finding above the level you choose becomes an alert. Alerts carry the whole event, so triage happens with the evidence on screen rather than in another tab. Acknowledge it, ignore it, or convert it to a case in one action.
- ▸The full event travels. An alert carries the entire finding, so the raw log is one expansion away.
- ▸Deduplicated before it arrives. The alerting engine collapses repeats on the fields you choose, inside a window you set.
- ▸Convert to case in one click, keeping the source finding linked and the observables extracted.
- ▸Sequential identifiers. ALERT-1, CASE-1, TASK-1. Readable in a conversation, not a random identifier.
The alert queue. Acknowledge, ignore, or promote to a case.
Everything about the incident, on one page.
The description holds the triggering event flattened to readable key and value pairs, not a wall of JSON. Around it sit comments, the full history, the observables extracted from the evidence, the tasks and the attachments.
- ▸Observables are extracted, not typed. Addresses, users, hosts, hashes and paths are pulled from the evidence by an editable field map.
- ▸Analysers and responders run against an observable or the whole case, and the verdict is recorded on the timeline.
- ▸Attachments render inline. Images preview in the case, everything else downloads, with a twenty megabyte ceiling.
- ▸Every change is on the history. Status, severity, assignment, analysis and escalation, timestamped in your timezone.
The incident dashboard: what is open, what is aging, what breached.
The clock runs whether or not anyone is watching it.
An SLA nobody enforces is a promise, not a control. A worker checks every open case against your policy each minute, warns at eighty percent of the window and, at breach, raises the severity, reassigns to whoever you nominated, and notifies the channel you chose.
- ▸Two stages. At risk when eighty percent of the window has elapsed, breached when it is past due.
- ▸It fires once. The escalation is written to the case timeline, so a restart never re-escalates the same case.
- ▸Escalation is configurable. Severity step, the assignee to escalate to and the notification channel are all yours.
- ▸Off until you configure it. The worker ships disabled, so it cannot escalate a backlog the moment it is installed.
One intrusion, opened four times.
Parallel detections produce parallel cases. Link two that are related and both timelines record it. Merge one into another and its observables move across, a link is recorded, and the source closes with its evidence intact and reachable.
- ▸Linking is bidirectional and noted on both timelines, so neither side loses the context.
- ▸Merging moves the observables into the target and closes the source rather than deleting it.
- ▸Nothing is destroyed. A merged case keeps its data and stays reachable through the link.
- ▸Templates and routing decide what opens automatically and who it lands on.
Bring your worst duplicate
alert storm.
Show us the detection that opens forty tickets for one intrusion. We will collapse it with a dedup window and merge the cases on the call.
Powered by Codesecure Solutions. Self hosted, cloud or fully managed.