Triage leads

After investigating the lead, you can perform one or more of the below-mentioned actions on it.

Comment on a lead

The lead comments panel allows you to comment and view comments from others regarding the lead at hand. It also displays a log of actions performed on the lead.

To view a lead's comments and log:

  1. From the SOC Queue or Leads page, click on the Lead to open it.
  2. From the Lead Details panel, click Comments to open the Collaboration panel.
    image
📘Learn more

If the lead is part of a cluster, you can decide whether to view toggle between viewing comments made on the cluster or not.
image


To comment, reply, delete, or edit a comments:

  1. From the SOC Queue or Leads page, click on the Lead to open it.
  2. From the Lead Details panel, click Comments to open the Collaboration panel.
    image
  3. From the collaboration panel:
    • To add a comment: type your comment in the text box and click the send icon. You can format the text using the editing options.
      image
    • To reply: Click the menu icon next to the comment you want to reply to, and then click Reply.
    • To delete/edit your comment: Click the menu icon next to the comment you want to reply to, and then select the required option.
      image



Assign a lead

You can assign leads to other team members or to yourself.

To assign a lead:

  1. From the SOC Queue or Leads page, click on the Lead to open it.
  2. From the Lead Details panel, click Assign or the assignee name to open a list of team members.
  3. Select the required person or Clear to remove any assignee.
    image



Classify a lead

You can classify a lead as benign, malicious or unknown.

📘Learn more

Lead classification affect the way Stories are built and displayed. If the benign lead is part of a story, the system will recalculate the story and remove the benign lead. Then, the relevant story will be update with an accurate score and visualization.

To classify a lead:

  1. From the SOC Queue or Leads page, click on the Lead to open it.
  2. From the Lead Details panel, click Classify to open a list of classification options.
  3. Select the classification of the lead according to your findings.

image



Update a lead’s status

As you progress in the triaging and handling of the lead, you can change its status to open, WIP (work in progress) and done.

To update a lead's status:

  1. From the SOC Queue or Leads page, click on the Lead to open it.
  2. From the Lead Details panel, click the status indication to open a list of statuses.
  3. Select the relevant status.

image



Bulk triage

To speed up the triage process, you can perform any of the above mentioned actions in bulk.

To triage in bulk:

  1. Tick the checkbox next to the leads you wish to triage.
  2. From the pop-up select the actions you want to perform on all of the selected leads, and then click Apply.
    image.png