Reading an incident
An incident page describes the activity with four values that move independently. Reading them as one number is the most common mistake, so the Evidence tab labels them separately.
The four values
| Value | What it answers |
|---|---|
| Evidence verdict | What the evidence says this activity is. It rises only when checks confirm it and falls when something refutes it. |
| Severity | How damaging this kind of activity is if it is real. It comes from the detection rules that fired, so verifying evidence does not change it. |
| Evidence strength | How much independent proof exists — the amount of proof, not how confident anyone is. |
| Response priority | How urgently to act. This is the one to work a queue from. |
An incident can therefore be urgent before anything is confirmed — and that is deliberate: destructive activity is worth interrupting for even while the proof is still circumstantial. Equally, a single refuting finding can close a noisy incident as a false positive. Hover any value on the page to see what it means.
A large alert count does not mean a worse incident
The counters on the Evidence tab separate two different things:
- Supporting, refuting, weak, and missing count distinct behaviours, deduplicated — one rule firing 300 times is still one behaviour.
- Total occurrences counts the raw alerts behind them.
An incident with 400 alerts and one behaviour is weaker evidence than one with four independent behaviours, so volume on its own is not a reason to escalate.
Verification is what reaches a confirmed verdict
Evidence found automatically can support a verdict but cannot confirm one. Only a check a person runs by hand does that, and it takes two independent confirmed behaviours to reach a confirmed malicious verdict. That is why the Verification section is usually the most useful work on an open incident.
Recording an outcome updates the verdict immediately, and all three outcomes are progress:
- Confirmed can raise the verdict.
- Ruled out lowers it — and can close the incident as a false positive. Ruling something out is often the most valuable result, not a failure.
- Could not tell is recorded honestly and leaves the evidence unchanged.
A row reading triaged real is not the same as confirmed. It means the platform judged the underlying alerts to be a real threat automatically — an assessment of the alerts, not a hand check of the behaviour — so it does not count toward the two confirmations.
Why an incident is marked urgent
Some conditions make an incident worth interrupting other work for, regardless of what is confirmed:
- Things destroyed or wiped.
- Data that may have left the network.
- An account that may be taken over.
- A machine that may be under attacker control.
These are read from the attack techniques on the underlying alerts, and the MITRE tab marks exactly which tactic or technique raised each one.
Re-analysing an incident with AI
The Overview tab can re-run the AI summary using everything collected since it was written — worth doing after you verify evidence. Because it spends credit, it asks for confirmation first, is never triggered automatically, and only an admin can start it. If the evidence has changed since the summary was written, a marker says so; treat the summary as a snapshot of an earlier state rather than the current verdict.
Re-analysis is subject to the same limits as any other AI work: it is refused if you are over your monthly budget, if your free credit is used up and no payment method is on file, or while an operator has paused the platform — and the message tells you which one it was. The tokens it uses appear on the billing page under incident analysis, so a re-analysis is never an unexplained charge. See Billing & pricing.
What the console will not claim
Blank does not mean nothing was found. A dash where a value should be means the platform cannot answer yet — which is different from a zero. If no surrounding activity was collected, the page says so rather than implying nothing was happening; if a check was run and settled nothing, it says that instead of showing a tick. An honest gap is more useful than a confident guess.