Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Incident Operations

Alert Triage and Incident Adjudication

This use case addresses alert fragmentation. KRYOS-XS Console is used to determine whether several apparently independent events constitute one incident, several routine changes or an unresolved pattern that requires additional evidence.

Product
KRYOS-XS Console
Decision domain
Incident Operations
Organizational setting
Research institute using Google Workspace security alerts
Related capability
Alert Triage and Incident Adjudication
Correlation diagram. unusual login, new mail-forwarding rule, bulk file downloads and unfamiliar oauth grant enter the Hypercube Decision Engine, which tests whether the evidence supports unrelated administrative activity, legitimate travel behaviour and one account-compromise incident. The output is one decision packet stating incident owner, severity and consequence, missing evidence, recommended containment and required approver, preserved in the KRYOS Decision Ledger.
Figure 2. Correlation of authorized source evidence into a single adjudication problem, with competing explanations held open and one governed decision packet as the output.

Abstract

This use case addresses alert fragmentation. KRYOS-XS Console is used to determine whether several apparently independent events constitute one incident, several routine changes or an unresolved pattern that requires additional evidence.

Decision problem

Security teams often review alerts according to the order in which they arrive. This encourages duplicate work and obscures relationships across identity, email, file and application activity. The institutional decision is not which alert looks most alarming. It is whether the combined evidence supports a coherent incident hypothesis and what governed response should follow.

Evidence and Hypercube reasoning

Console retrieves approved alert and activity records from existing systems. Hypercube performs entity and temporal correlation across users, devices, applications, files and administrative changes. It tests alternative explanations and records which facts support or weaken each one. Missing evidence remains visible, preventing a group of weak alerts from being converted into unwarranted certainty.

Governed workflow

Console ingests the available alerts, resolves shared entities and presents the evidence as one adjudication problem. Hypercube ranks the competing explanations and estimates consequence under each. The resulting packet identifies the incident owner, required authority, immediate containment options and outstanding evidence requests. Completed actions and verified outcomes are added to the ledger.

Evaluation design

The pilot should examine duplicate reviews eliminated, related alerts correctly consolidated, analyst time per incident, time from first alert to decision, missed relationships, inappropriate consolidations and the proportion of decision packets with complete source references.

Boundary condition

Correlation is not proof of causation. Console should preserve alternative explanations until the evidence is strong enough to dismiss them.

Reading time 2 minutes. Every decision described here is recorded in the KRYOS Decision Ledger with its evidence, authority and verified outcome.

Related Use Cases

Protect the Systems Your Mission Depends On.

Eligible nonprofit organizations may apply for grant-funded access to ArtOfTheHack cybersecurity services powered by KRYOS-XS Hypercube.