Pillar 06 of 12

A case, not a ticket
bolted onto a SIEM.

Alerts triage to cases, cases carry observables and tasks, and an SLA worker escalates the ones going stale without anybody remembering to check. It reads like the issue tracker your team already uses, because that is the interaction people actually know.

nullsoc.in / incidents / cases
The NullSOC case list: case key, title, severity, status lozenge, assignee and age.

Cases in a familiar shape. Key, status, severity, owner, age.

5
Case statuses
Open, in progress, contained, resolved and closed.
4
Working tabs
Comments, history, observables and tasks, plus attachments.
2
Escalation stages
At risk at eighty percent elapsed, then breach.
0
Manual SLA checks
The worker escalates without anyone watching a clock.
Triage

Alerts arrive already scored and deduplicated.

A finding above the level you choose becomes an alert. Alerts carry the whole event, so triage happens with the evidence on screen rather than in another tab. Acknowledge it, ignore it, or convert it to a case in one action.

  • The full event travels. An alert carries the entire finding, so the raw log is one expansion away.
  • Deduplicated before it arrives. The alerting engine collapses repeats on the fields you choose, inside a window you set.
  • Convert to case in one click, keeping the source finding linked and the observables extracted.
  • Sequential identifiers. ALERT-1, CASE-1, TASK-1. Readable in a conversation, not a random identifier.
nullsoc.in / incidents / alerts
The alert queue with severity, rule, agent and status, ready for triage.

The alert queue. Acknowledge, ignore, or promote to a case.

The case

Everything about the incident, on one page.

The description holds the triggering event flattened to readable key and value pairs, not a wall of JSON. Around it sit comments, the full history, the observables extracted from the evidence, the tasks and the attachments.

  • Observables are extracted, not typed. Addresses, users, hosts, hashes and paths are pulled from the evidence by an editable field map.
  • Analysers and responders run against an observable or the whole case, and the verdict is recorded on the timeline.
  • Attachments render inline. Images preview in the case, everything else downloads, with a twenty megabyte ceiling.
  • Every change is on the history. Status, severity, assignment, analysis and escalation, timestamped in your timezone.
nullsoc.in / incidents
The incident management dashboard with case counts by status, severity and age.

The incident dashboard: what is open, what is aging, what breached.

SLA

The clock runs whether or not anyone is watching it.

An SLA nobody enforces is a promise, not a control. A worker checks every open case against your policy each minute, warns at eighty percent of the window and, at breach, raises the severity, reassigns to whoever you nominated, and notifies the channel you chose.

  • Two stages. At risk when eighty percent of the window has elapsed, breached when it is past due.
  • It fires once. The escalation is written to the case timeline, so a restart never re-escalates the same case.
  • Escalation is configurable. Severity step, the assignee to escalate to and the notification channel are all yours.
  • Off until you configure it. The worker ships disabled, so it cannot escalate a backlog the moment it is installed.
Case model
Statusesopen, in progress, contained, resolved, closed
Severitythe same scale as detection
Observablesip, domain, url, hash, user, hostname, path
Extractioneditable field map, dotted paths supported
Tasksname, description, priority, due, status
Attachmentsfilesystem stored, images inline, 20 MB cap
Timeline kindscomment, status, analyse, respond, attachment, SLA
SLA stagesat risk at 80 percent, then breach
Identifierssequential, CASE-1 and ALERT-1
ClassificationTLP and PAP on every case
Link and merge

One intrusion, opened four times.

Parallel detections produce parallel cases. Link two that are related and both timelines record it. Merge one into another and its observables move across, a link is recorded, and the source closes with its evidence intact and reachable.

  • Linking is bidirectional and noted on both timelines, so neither side loses the context.
  • Merging moves the observables into the target and closes the source rather than deleting it.
  • Nothing is destroyed. A merged case keeps its data and stays reachable through the link.
  • Templates and routing decide what opens automatically and who it lands on.
Automation in and out
Case opens froma finding, an alert, a playbook or by hand
Alert thresholda level you choose, deduplicated first
Observable seedingfrom the evidence, by editable field map
Respondersper observable or per case
Active responserun a manager command on the affected agent
Notificationany configured channel
SLA workerone minute tick, durable escalation record
Access controlper role read, write and delete
Get started

Bring your worst duplicate
alert storm.

Show us the detection that opens forty tickets for one intrusion. We will collapse it with a dedup window and merge the cases on the call.

Powered by Codesecure Solutions. Self hosted, cloud or fully managed.