Reports
Reports provide detailed, filterable views of signals, cases, and SOC metrics. Use reports for analysis, auditing, and generating insights beyond real-time dashboards.
Signal Reports
Signals : New
- Purpose: Lists all new signals that haven't been claimed or started
- When to Use: Daily triage to identify unworked signals
- Filters: Use filters to narrow by source, severity, or organization
- Best Practice: Review at shift start to claim signals for investigation
Signals : In Progress
- Purpose: Shows signals currently being investigated
- When to Use: Monitor active investigations and workload distribution
- Filters: Filter by owner, priority, or severity
- Best Practice: Use to balance workload across analysts
Signals : Blocked
- Purpose: Lists signals that are blocked or waiting on dependencies
- When to Use: Identify signals that need unblocking or escalation
- Filters: Filter by blocking reason or owner
- Best Practice: Review daily to prevent signals from being forgotten
Signals : Elevated To Case
- Purpose: Lists Case Management records that entered sustained handling (report name may vary by package; often aligned with Escalated status or similar workflow on CASE- records)
- When to Use: Track when records move to sustained investigation or formal response
- Filters: Filter by date, status, or signal type (as exposed in your report)
- Best Practice: Monitor trends to calibrate routing and pending resolution rules
Signals : High Severity
- Purpose: Lists all high-severity signals
- When to Use: Prioritize high-severity investigations
- Filters: Filter by status, verdict, or owner
- Best Practice: Ensure high-severity signals are being addressed promptly
Signals : Critical Severity
- Purpose: Shows all critical-severity signals
- When to Use: Immediate triage for critical threats
- Filters: Filter by status, verdict, or source
- Best Practice: Critical signals should be reviewed immediately
Signals : Malicious Verdicts
- Purpose: Lists signals with malicious verdicts (AI, manual, or TI)
- When to Use: Focus on confirmed threats requiring response
- Filters: Filter by severity, status, or escalation state
- Best Practice: Prioritize malicious verdicts for investigation and response
Signals : Suspicious Verdicts
- Purpose: Shows signals requiring further investigation
- When to Use: Identify signals that need additional analysis
- Filters: Filter by confidence level, severity, or age
- Best Practice: Review suspicious verdicts to determine if they need Escalated status or further investigation
Signals : Malicious & Critical
- Purpose: Combines malicious verdicts with critical severity
- When to Use: Identify highest-priority confirmed threats
- Filters: Filter by source, organization, or owner
- Best Practice: These signals require immediate attention
Signals : Suspicious & Critical
- Purpose: Shows suspicious verdicts with critical severity
- When to Use: Prioritize high-risk signals needing investigation
- Filters: Filter by age, source, or enrichment status
- Best Practice: Investigate promptly to confirm or dismiss threats
Signals : Verdict & Severity Overall
- Purpose: Cross-tabulation of verdicts and severity levels
- When to Use: Analyze verdict distribution patterns
- Filters: Filter by time period, source, or organization
- Best Practice: Use for trend analysis and capacity planning
Signals : AI Verdicts
- Purpose: Lists signals with Hero AI-generated verdicts
- When to Use: Review AI analysis coverage and accuracy
- Filters: Filter by confidence level, verdict type, or manual override
- Best Practice: Compare AI verdicts with manual verdicts to assess AI performance
Signals : Threat Intel Verdicts
- Purpose: Shows signals with threat intelligence verdicts
- When to Use: Assess TI enrichment coverage and effectiveness
- Filters: Filter by TI provider, verdict type, or enrichment status
- Best Practice: Monitor TI verdict distribution to identify threat trends
Signals : Status
- Purpose: Lists signals grouped by workflow status
- When to Use: Monitor signal progression through workflow
- Filters: Filter by status, priority, or time period
- Best Practice: Use to identify workflow bottlenecks
Signals : Severity
- Purpose: Shows signals grouped by severity level
- When to Use: Assess severity distribution and resource allocation
- Filters: Filter by status, verdict, or source
- Best Practice: Ensure severity levels are set appropriately
Signals : Require Attention
- Purpose: Lists signals that need analyst action
- When to Use: Daily triage to identify signals needing review
- Filters: Filter by attention reason, priority, or owner
- Best Practice: Review at shift start and throughout the day
Signals : Ready For Prioritization
- Purpose: Shows signals that have been triaged but need priority assignment
- When to Use: Identify signals waiting for priority determination
- Filters: Filter by source, severity, or age
- Best Practice: Assign priorities promptly to maintain workflow
Signals : Priority
- Purpose: Lists signals grouped by priority level
- When to Use: Monitor priority distribution and workload
- Filters: Filter by status, severity, or owner
- Best Practice: Ensure priorities reflect business impact
Signals : Oldest
- Purpose: Shows signals ordered by creation date (oldest first)
- When to Use: Identify stale signals that may need closure
- Filters: Filter by status, priority, or source
- Best Practice: Review weekly to prevent signal backlog
Signals : Intel Verdict & Severity
- Purpose: Cross-reference of threat intelligence verdicts with severity
- When to Use: Prioritize signals based on TI verdict and severity
- Filters: Filter by TI provider, verdict type, or time period
- Best Practice: Focus on high-severity signals with malicious TI verdicts
Case Reports
Case : Requires Attention
- Purpose: Lists cases that need immediate analyst action
- When to Use: Daily case triage
- Filters: Filter by attention reason, priority, or owner
- Best Practice: Review at shift start
Case : Status
- Purpose: Shows cases grouped by workflow status
- When to Use: Monitor case progression and identify bottlenecks
- Filters: Filter by status, priority, or time period
- Best Practice: Track case resolution rates
Case : Oldest
- Purpose: Lists cases ordered by creation date (oldest first)
- When to Use: Identify cases that may be stuck
- Filters: Filter by status, priority, or owner
- Best Practice: Review weekly to prevent case aging
Cases : Priority
- Purpose: Shows cases grouped by priority level
- When to Use: Assess case workload and resource allocation
- Filters: Filter by status, severity, or owner
- Best Practice: Ensure critical cases are progressing
Cases : Oldest
- Purpose: Lists cases that have been open the longest
- When to Use: Identify cases needing escalation or additional resources
- Filters: Filter by status, priority, or organization
- Best Practice: Review weekly to prevent case backlog
Routing Rule Reports
Routing Rule Management
- Purpose: Provides detailed view of routing rule performance
- When to Use: Monitor rule effectiveness and optimize routing logic
- Filters: Filter by rule status, match count, or rule order
- Best Practice: Review weekly to identify rules needing adjustment
Key Metrics:
- Rules matched count
- Rules with no matches (may need updating)
- Rule execution errors
- Rules by order and priority