Security playbook · AI Employee: Sig

Security Alert Triage & Context

Analyst decision time reduced by 40%

The problem

Security-tool alert volume is unmanageable. CrowdStrike, SentinelOne, SIEM correlations, cloud posture alerts, DLP, CASB, WAF blocks, IDS matches — each generates 100-2000 alerts per day. Analysts triage a fraction; the rest sit in queues. Real threats hide behind repeat false positives; alert fatigue kills discipline; the one legitimate ransomware alert last quarter looked identical to 300 benign versions.

At a glance
Trigger
Monitor event
Approvals
None (read-only enrichment)
What it does
Read-only
Systems
SIEM · SOAR · Identity · EDR
How it feels in production

An hour-by-hour walkthrough.

Every alert entering the queue gets picked up by Sig within seconds. For each, Sig assembles the context that would take an analyst 20-40 minutes manually: - Alerting rule + confidence + severity per source - Affected entity (user, device, service) with their behavioural baseline - Correlated events in the last 24h across all sources - Historical: has this exact pattern fired before, and what was the resolution - Threat intel: does the IOC (hash, IP, domain) match known-bad in any feed Sig scores each alert 0-1 on the fusion signal and buckets: - Under 0.2: auto-close with note ("identical to 47 prior FPs, same rule, no correlation") - 0.2-0.5: quick-review queue with the context bundle attached - 0.5-0.8: analyst-review queue with elevated priority - Over 0.8: promote to incident, page on-call, execute pre-containment per playbook Analyst starts their day looking at 5-15 real alerts with pre-built context, not 800 raw alerts. Each triage decision (validated true, validated FP, tuned rule) feeds the model. Alert volume to human review drops 90%+; real threats surface fast.
How it works

Step by step.

  1. 01

    Ingest alerts from every security source

    EDR, SIEM, cloud posture, DLP, CASB, WAF, IDS. Normalise to a common alert schema.

    CrowdStrike · SentinelOne · SIEM · Wiz · Netskope · CloudFlare
  2. 02

    Assemble context per alert

    Affected entity + baseline + correlations + historical + threat intel. Context ready before analyst opens the alert.

    Context Graph · Threat intel feeds · Historical alert store
  3. 03

    Score + bucket by fusion signal

    Multi-source correlation + threat intel + entity behaviour. Score drives auto-close vs. review-queue vs. incident.

    Fusion scoring · Playbook config
  4. 04

    Auto-close low-fusion + surface elevated to analyst

    Under 0.2 auto-close with note. 0.2-0.8 to review queue with context. Over 0.8 promotes to incident + page.

    Alert queue · Note storage · Incident promotion
  5. 05

    Feed decisions back to tune the model

    Every analyst decision (true, FP, tune) feeds the fusion model + rule tuning. Volume compounds down over time.

    Analytics · Rule tuning · Model retrain
Systems and wiring

What you connect to make this run.

EDR · SIEM · CSPM · DLP · CASB · WAF · IDS

read+write

Alert ingestion + rule-tuning writes. Deduplication across sources for the same underlying event.

Threat intel feeds

read

IOC matching against known-bad hashes, IPs, domains. Commercial + open-source feeds combined.

Context Graph · Baseline model

read

Entity behavioural baseline. Deviation from baseline is a strong fusion signal.

PagerDuty · Incident tracker

write

Elevated alerts promote to incident + page on-call. Pre-containment per playbook config.

What changes

Before and after, honestly.

Alerts requiring human review
Before
300-1500 per day
After
5-30 per day
Time to triage per real alert
Before
20-40 minutes
After
3-8 minutes (context ready)
Alert false-positive rate reaching analyst
Before
70-90%
After
15-30%
Mean time to detect real threat
Before
3-14 days
After
20-90 minutes
Frequently asked

Answers about this playbook.

Won't auto-close miss the one real threat that looks like a false positive?

Auto-close only fires when fusion signal is very low + the specific pattern has fired-and-been-FP many times. Analyst spot-checks the auto-close queue weekly to catch drift.

How does it handle novel attack patterns (zero-day, new IOC)?

Novel patterns bypass historical matching + hit the elevated queue by default. Fresh IOC lookups get priority; unknown entity behaviours score higher fusion signal.

What about alerts requiring specific expertise (network, cloud, endpoint)?

Analyst routing per alert type. Network alerts route to network-savvy analyst; cloud posture to cloud-savvy. Rotation respects expertise mapping.

Can we tune per business unit or environment?

Yes — env-specific fusion thresholds. Production has tighter thresholds than staging; regulated environments (payments, PII) tighter than internal tools.

How does this coordinate with our SOC / MSSP?

SOC / MSSP sees the triaged queue. Reduces their alert-review burden; they focus on decision-making rather than triage. Feedback loop from their decisions feeds tuning.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.