Incidents

Effective incident management requires a clear and structured interface that allows SOC teams to quickly identify, investigate, and remediate threats. The List View provides a consolidated overview of incidents and alerts, while the Incident Summary pane offers detailed information and actionable options for each incident. This document describes the fields, filters, and actions available to users for managing incidents efficiently.

List View

Scroll through the list to view previously generated alerts. Clicking on a host name opens the Device View for that alert.

Incident Fields

Column Description
INCIDENT ID Select the severity from the drop-down values.
INCIDENT NAME Select the type of an incident form the drop-down values.
TYPE Type of Incident is based on the Source of the initial alert based on which the Incident is formed. It could be one the following: · Endpoint · Insider Threat
SEVERITY Severity of the incident is based on the combined severity of the alerts that are part of the incident.
PRIORITY Priority is assigned by the analyst.
STATUS The status value is initially set to Initial when the Incident is generated. As the analysis progresses, analysts have the flexibility to update the status to Investigation, Remediation, or Closed.
NO. OF ALERTS Displays the count of alerts in the Incident.
CREATED ON Displays the date on which the Incident was created.
ASSIGNED TO Displays the name of the assignee.

Alert Fields

Field Description
ALERT NAME Displays the name of the alert.
ALERT TYPE Displays alert type: Custom, Associated Alerts, Unassociated Alerts.
SOURCE Displays the source of the alert.
SEVERITY Displays severity: High, Medium, Low, Base.
TACTICS Displays tactics associated with the alert.
CREATED ON Displays the date and time when the alert was created. Sortable.

View Options

You can view incidents by time slots:

  • Hour-wise: Last 1 hour, Last 24 hours
  • Day-wise: Last 7 days, Last 15 days, Last 30 days
  • Custom: Select From Date and To Date using the calendar control, then click Save

My Incidents

Click My Incidents to view only the incidents assigned to you (logged-in user).

Filter

Apply filters to narrow down search results. You can filter by:

  • Severity
  • Status
  • Alert details (Process Name, Host Name, Assignee, Tactics)

View Details

Click View Details to navigate to the Alerts page.

Incident Summary

Clicking any row displays the incident summary in the right pane. Available actions include:

  • View Audit Report – Access detailed audit reports.
  • Add Notes – Add notes to the incident, visible in the Notes section.

Basic Information

Field Description
Incident ID Displays the incident ID. Copyable via icon.
Incident Name Displays the incident name. Editable via icon.
Incident Type Displays type: Unknown, Phishing, Malware, MITM, Insider Threat, Privilege Escalation, Web Application Attack, Anomaly Detection, APT. Editable via icon.
Created On Displays the creation date and time.
Occurred On Displays the endpoint where the incident occurred.
Last Updated On Displays the last update timestamp.
Number of Alerts Displays the number of alerts linked to the incident.
View Details Redirects to the Alerts page.

Response Summary

Field Description
Severity Displays severity: High, Medium, Low, Base.
Priority Displays priority: Critical, High, Medium, Low. Editable via icon.
Assigned To Displays the assignee’s name.
Status Displays status: New, Investigation, Remediation, Closed. Also shows response timeliness (On Time, Late, Closed). Editable via icon. Allows document uploads. Note: Max 5 files per incident, each ≤ 1 MB. Supported formats: .xlsx, .pdf, .docx, .jpeg, .jpg, .png.

Description and Analysis

  • Description – Editable incident description.

Notes

  • Notes – Displays notes with author and timestamp. Add notes via Add Note icon.

Endpoints and Users

  • Endpoints (#) – Displays endpoint hostnames.
  • Users (#) – Displays associated users.

Key Attributes

  • Process, Registry, File, Network – Each displays count, value, reputation, and associated alerts.

Add Note

  1. Click the Add Note icon (top-right corner).
  2. Enter the note in the Note field.
  3. Click Save.
  4. A confirmation message appears.

Notes are visible in the Notes section of the Incident Summary.

Scheduling Incident Reports

Note: Only users with Admin, or SOC Manager privileges can schedule incident reports.

To schedule reports, follow the instructions here.

Was this page helpful?