For each new alert ingested into the platform, Tier4 extracts critical indicators like hostname, username, device user, file hash, and others. All cases are then aggregated by a common indicator: hostname or username. This aggregate view show a full summary of relevant correlated events, a chronological view of relevant cases, and the ability to perform bulk response actions.
Host and User entities pages will default to only showing entities with new/open cases, filtered by highest severity level. You can filter at any point to see entities with closed cases, false positives, or any combination you would like. This default sorting is designed to optimize your view and reduce manual work.
Available Features
1. Aggregate Summary
Tier4 provides a consolidated summary of all relevant events on the entity that currently pose a threat to the customer environment. This smart aggregation considers the decision of the cases (true positive vs. false positive), critical facts, threat intelligence assessments, and performed remediation actions. Use this summary as a guide to understand the actions and intentions of the threat actor.
2. Associated Cases
The entity page contains a chronological view of all cases that are relevant to the chosen entity. You can use the status filter to see any combination of cases (new, open, closed). Clicking each individual case will open a drawer that contains a full audit of the individual alert. This audit includes a summary, suggested response actions, and critical evidence used by the AI to make the assessment. This drawer serves as a quick view into the event where compartmentalized response actions can be taken.
3. Critical Actions
The critical actions component shows all of the required response actions which have automated or one-click response. This view consolidates duplicate recommended actions and allows an analyst to take actions across multiple cases. Response actions that have been completed will be shown in green with a Done tag, while those still needing attention will be highlighted in red with Resolve.
4. Global Entity Options (top right ellipsis)
There are a number of global entity options available to the analyst, including:
- Add Knowledge: add or edit knowledge for the given entity that will be leveraged by the AI system on all future events containing that entity.
- On-demand Actions: critical automated actions availble to the analyst at any time, regardless of recommendations by the AI (e.g. isolate host, disable user, etc.).
- Close All Associated Cases: when response actions have been completed, analysts can close all new/open cases with a single click.
- Mark as False Positives: analysts can mark multiple cases as false positives in the event that benign behavior has been flagged by the AI. Marking as a false positive will automatically close the given case.