---
title: "Triage threat clusters"
slug: "triage-threat-clusters"
updated: 2025-03-05T16:56:15Z
published: 2025-03-05T16:56:15Z
canonical: "docs.hunters.ai/triage-threat-clusters"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Triage threat clusters

After investigating the cluster and its leads, you can now perform actions on the cluster and leads.

- [Comment on a cluster](/v1/docs/triage-threat-clusters#comment-on-a-cluster)
- [Assign a cluster](/v1/docs/triage-threat-clusters#assign-a-cluster)
- [Classify cluster](/v1/docs/triage-threat-clusters#classify-a-cluster)
- [Update a cluster's status](/v1/docs/triage-threat-clusters#update-a-cluster%E2%80%99s-status)
- [Bulk triage](/v1/docs/triage-threat-clusters#bulk-triage)

---

## Comment on a cluster

Use the cluster comments to add any important information about the cluster. Any comment added to the cluster will be also added to all of the leads below it.

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC16.png)

---

## Assign a cluster

When assigning a cluster to someone, you’re actually assigning some or all of the leads below it. You can assign all of the leads in the cluster, some of the leads in the cluster, or only the leads that answer your filtering preferences.

****Assign all clustered leads****

**To assign all clustered leads:**

1. Click on the cluster row to open the cluster details window. ![TC10](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC10.png)
2. Scroll down to the leads grid.
3. Select the **All leads** view to expose all of the leads in the cluster.
4. Check the **Select all** checkbox to select all leads and then click **Assign** to select the required assignee. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC17.png)

****Assign leads in filtered view****

**To assign leads in filtered view:**

1. Filter the Leads page or SOC Queue to your needs.
2. Hover over the cluster row and click **Assign**.
3. Select the required person to assign the leads to from the drop-down list. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC20.png)

📘 Note

This will assign the leads in the filtered view and not all of the leads in the cluster.

****Assign selected leads****

**To assign selected leads:**

1. Click on the cluster row to open the cluster details window. ![TC10](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC10.png)
2. Scroll down to the leads grid.
3. Mark the relevant leads and select the required assignee. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC22.png)

---

## Classify a cluster

When classifying a cluster, you’re actually changing the classification of some or all of the leads below it. You can classify all of the leads in the cluster, some of the leads in the cluster, or only the leads that answer your filtering preferences.

****Classify all clustered leads****

**To classify all clustered leads:**

1. Click on the cluster row to open the cluster details window. ![TC10](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC10.png)
2. Scroll down to the leads grid.
3. Select the **All leads** view to expose all of the leads in the cluster.
4. Check the **Select all** checkbox to select all leads and then click **Classify** to select the required classification. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC18.png)

****Classify leads in filtered view****

**To classify leads in filtered view:**

1. Filter the Leads page or SOC Queue to your needs.
2. Hover over the cluster row and click **Classify**.
3. Select the required classification from the drop-down list. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC21.png)

📘Note

This will change the classification of the leads in the filtered view and not all of the leads in the cluster.

****Classify selected leads****

**To classify selected leads:**

1. Click on the cluster row to open the cluster details window. ![TC10](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC10.png)
2. Scroll down to the leads grid.
3. Mark the relevant leads and select the required classification. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC23.png)

---

## Update a cluster’s status

When updating the status of a cluster, you’re actually changing the status of some or all of the leads below it. You can change the status of all of the leads in the cluster, some of the leads in the cluster, or only the leads that answer your filtering preferences.

****Update all clustered leads****

**To update all clustered leads:**

1. Click on the cluster row to open the cluster details window. ![TC10](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC10.png)
2. Scroll down to the leads grid.
3. Select the **All leads** view to expose all of the leads in the cluster.
4. Check the **Select all** checkbox to select all leads and then click **Set status** to select the required status. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC19.png)

****Update leads in filtered view****

**To update leads in filtered view:**

1. Filter the Leads page or SOC Queue to your needs.
2. Hover over the cluster row and click on the status indication.
3. Select the required status from the drop-down list. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC25.png)

📘Note

This will change the status of the leads in the filtered view and not all of the leads in the cluster.

****Update selected leads****

**To update selected leads:**

1. Click on the cluster row to open the cluster details window. ![TC10](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC10.png)
2. Scroll down to the leads grid.
3. Mark the relevant leads and select the required status. ![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC24.png)

To speed up the triage process, you can perform any of the above mentioned actions in bulk.

---

## Bulk triage

**To triage in bulk:**

1. Tick the checkbox next to the leads you wish to triage.
2. From the pop-up select the actions you want to perform on all of the selected leads, and then click **Apply**. ![image.png](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/image%2888%29.png)
