Product Tour
Case Management — Every Incident, Start to Finish
Step 5 of 8
Account Compromise: AWS root
4 findings · 3 response actions · Assignee: Alice Chen · MTTR: 18 min
Finding fnd_01HX001 created: AWS Root Account Login (critical). Blast radius: 100.
Triage complete: True positive (99% confidence). Login from UA/Kyiv; no MFA; no change ticket.
Case cas_00142 auto-created. Severity: Critical. Assignee: Alice Chen (on-call rotation).
Investigation started. Attack chain reconstructed: 4 events, 4 MITRE techniques, 14 GB exfiltration detected.
Proposed action plan: suspend root Okta user, deactivate access key, request approval for IAM user delete.
Analyst note: Confirmed account compromise. Approved IAM user deletion. Notified legal team per IR policy.
IAM backdoor user deleted. All 3 response actions complete. Containment verified.
MTTR calculated: 18 min (detect to containment). IR report generated and attached to case.
Unified case timeline
Every agent action, analyst note, system event, and response action appears in a single chronological timeline. No stitching together separate systems to reconstruct what happened.
Auto-calculated MTTR
Mean time to respond is calculated automatically from case open to containment verified, giving you accurate IR metrics without manual tracking. Export to your reporting dashboard via API.
One-click compliance reports
Generate a formatted incident report from the case data — timeline, entities, response actions, MITRE mapping — suitable for security leadership, legal, or compliance auditors.