SecSight alert lifecycle

From raw detection signal to closed incident

SecSight alert lifecycle From raw detection signal to closed incident raw event arrives normalized event in tenant context matches verdict → 22 playbooks auto-execute L0–L3 within budget L4 over budget → human review approve · modify · reject incident closed + postmortem Alert · SIEM / NIDS · Sequence participant Alert SIEM / NIDS Ingest · normalize · tag · Sequence participant Ingest normalize · tag Copilot · multi-agent + SOAR · Sequence participant Copilot multi-agent + SOAR Human · L4 reviewer · Sequence participant Human L4 reviewer Legend request return

Ingest

  • • Detection signal arrives from SIEM, NIDS, or threat-intel
  • • Normalized, deduped, tagged before downstream agents see it

Analyze

  • • Triage → Investigate → Enrich → Report agents collaborate
  • • Verdict carries full evidence chain into SOAR

Act

  • • SOAR picks one of 22 playbooks within autonomy budget
  • • L4 over-budget items land in human review with full trail