Triage threat clusters

Prev Next

After investigating the cluster and its leads, you can now perform actions on the cluster and leads.



Comment on a cluster

Use the cluster comments to add any important information about the cluster. Any comment added to the cluster will be also added to all of the leads below it.

image



Assign a cluster

When assigning a cluster to someone, you’re actually assigning some or all of the leads below it. You can assign all of the leads in the cluster, some of the leads in the cluster, or only the leads that answer your filtering preferences.


Assign all clustered leads

To assign all clustered leads:

  1. Click on the cluster row to open the cluster details window.
    TC10

  2. Scroll down to the leads grid.

  3. Select the All leads view to expose all of the leads in the cluster.

  4. Check the Select all checkbox to select all leads and then click Assign to select the required assignee.
    image

Assign leads in filtered view

To assign leads in filtered view:

  1. Filter the Leads page or SOC Queue to your needs.

  2. Hover over the cluster row and click Assign.

  3. Select the required person to assign the leads to from the drop-down list.
    image

📘 Note

This will assign the leads in the filtered view and not all of the leads in the cluster.

Assign selected leads

To assign selected leads:

  1. Click on the cluster row to open the cluster details window.
    TC10

  2. Scroll down to the leads grid.

  3. Mark the relevant leads and select the required assignee.
    image


Classify a cluster

When classifying a cluster, you’re actually changing the classification of some or all of the leads below it. You can classify all of the leads in the cluster, some of the leads in the cluster, or only the leads that answer your filtering preferences.

Classify all clustered leads

To classify all clustered leads:

  1. Click on the cluster row to open the cluster details window.
    TC10

  2. Scroll down to the leads grid.

  3. Select the All leads view to expose all of the leads in the cluster.

  4. Check the Select all checkbox to select all leads and then click Classify to select the required classification.
    image

Classify leads in filtered view

To classify leads in filtered view:

  1. Filter the Leads page or SOC Queue to your needs.

  2. Hover over the cluster row and click Classify.

  3. Select the required classification from the drop-down list.
    image

📘Note

This will change the classification of the leads in the filtered view and not all of the leads in the cluster.

Classify selected leads

To classify selected leads:

  1. Click on the cluster row to open the cluster details window.
    TC10

  2. Scroll down to the leads grid.

  3. Mark the relevant leads and select the required classification.
    image


Update a cluster’s status

When updating the status of a cluster, you’re actually changing the status of some or all of the leads below it. You can change the status of all of the leads in the cluster, some of the leads in the cluster, or only the leads that answer your filtering preferences.

Update all clustered leads

To update all clustered leads:

  1. Click on the cluster row to open the cluster details window.
    TC10

  2. Scroll down to the leads grid.

  3. Select the All leads view to expose all of the leads in the cluster.

  4. Check the Select all checkbox to select all leads and then click Set status to select the required status.
    image

Update leads in filtered view

To update leads in filtered view:

  1. Filter the Leads page or SOC Queue to your needs.

  2. Hover over the cluster row and click on the status indication.

  3. Select the required status from the drop-down list.
    image

📘Note

This will change the status of the leads in the filtered view and not all of the leads in the cluster.

Update selected leads

To update selected leads:

  1. Click on the cluster row to open the cluster details window.
    TC10

  2. Scroll down to the leads grid.

  3. Mark the relevant leads and select the required status.
    image

To speed up the triage process, you can perform any of the above mentioned actions in bulk.


Bulk triage

To triage in bulk:

  1. Tick the checkbox next to the leads you wish to triage.

  2. From the pop-up select the actions you want to perform on all of the selected leads, and then click Apply.
     image.png