Skip to main content

Monitor and respond

This is the operational queue: alerts that detections raised, incidents they escalate into, and the actions you can take from either.

Nothing arrives here until Detection and Alerting are enabled. See Security Operations.

Alerts​

An alert is one detection that fired. It carries a severity on the same five-level scale as everything else in the platform - and, separately, the source's own verbatim severity before normalization.

Screenshot pending

SCREENSHOT: the alert queue.

That second value is worth knowing about. A vendor's "High" and the platform's High are not necessarily the same judgement, and when you are deciding whether a normalization is treating a source sensibly, the original is what tells you.

Alert statuses​

StatusMeaning
NewRaised, untouched
TriagingBeing assessed
TriagedAssessed, awaiting action
InvestigatingActively worked
ResolvedDealt with
ClosedFinished
False PositiveNot a real detection
SuppressedMuted by a suppression rule

Suppressed is distinct from False Positive on purpose. Suppressed means a rule you wrote muted it; False Positive means an analyst judged this instance wrong. Reading a suppressed alert as an analyst verdict would overstate how much anyone actually looked at.

AI triage​

If enabled, alerts are scored before a human sees them. Each triaged alert carries:

  • A priority score from 0 to 100
  • Reasoning - why it scored that way
  • A recommendation - suggested next steps
  • The model that produced it

The score is a queue-ordering aid, not a verdict. The reasoning is the useful part: it tells you what the triage actually keyed on, which is what lets you decide whether to trust it on this class of alert.

Triage never turns itself on

It spends tokens, so it fails closed - if the service gating it is unavailable, triage stops rather than proceeding. An outage cannot start spending on your behalf.

Incidents​

An incident groups related alerts into one piece of work. Escalate when several alerts are one event, or when something needs a response rather than a verdict.

StatusMeaning
NewRaised
InvestigatingBeing worked
ContainedSpread stopped, not yet fixed
RemediatedFixed
ClosedFinished
False PositiveNot a real incident

Contained before Remediated is the distinction that matters under pressure. Stopping an attacker moving is a different milestone from removing them, and collapsing the two loses the ability to say "we have stopped the bleeding, we are not yet clean" - which is exactly what people ask during an incident.

Incidents also carry a sub-status recording what is happening inside the current phase:

PhaseSub-statuses
InvestigationGathering Evidence, Analyzing, Correlating
ContainmentIsolated, Blocked, Account Disabled, System Quarantined
RemediationRemediating
HandlingEscalated, On Hold

These are what make a status meaningful to someone joining mid-incident. "Investigating" tells them little; "Investigating / Correlating" tells them where to pick up.

Response actions​

Available from an alert or an incident, depending on what the affected system is connected through - isolating a host, blocking an indicator, disabling an account, quarantining a system. The containment sub-statuses above record which were taken.

Automated response guardrails fail open

Guardrails on automated response are evaluated before an action runs. If a guardrail cannot be evaluated, the action is allowed with its safety check skipped rather than blocked.

That is a deliberate availability choice - a guardrail service outage does not stop incident response - but it means an alert is raised for exactly that case, and it is the only signal that an action ran unchecked. Treat one seriously: it means something happened without the constraint you configured.

Where alerts come from​

Alerts are not only produced by the platform's own detections. They also arrive from connected sources, each keeping its identity so you can tell what saw what:

  • Microsoft 365 - security alerts, management activity, Intune
  • Entra ID and Azure - sign-ins, risk detections, audit, provisioning, activity logs
  • Network and security appliances - Barracuda, Fortinet, Palo Alto, Cisco
  • Endpoint - CrowdStrike
  • Your own collectors and agents
  • Custom - anything you raise yourself through the API

API​

The endpoints behind this section are in the API reference.

Next​