Skip to content

Automated Triage

Automated triage adjusts the score of an individual observation after it has been detected, based on how often similar activity has already been seen in your environment. Where an adjustment has been made, SenseOn tells you so on the affected observation.

This page explains what those adjustments mean, how to read them, and what to do next. For how scores work in the first place, see Case Scoring.


Where you will see it

An adjustment is reported as a note against the observation it applies to. You will see it in two places:

  • On the observation in the case detail, alongside the observation's current score.
  • In case escalation emails, as a closing note beneath the case detail.

The note names the original score, the adjusted score, and the reason for the adjustment. For example, an observation may be recorded as having been reduced from High to Medium because similar activity involving the same user has been seen roughly once per day.


Why a score is reduced

Adjustments are based on frequency. Where similar activity has been recurring on the same device, or for the same user, the observation's score is reduced to reflect how routine that activity is in your estate.

An observation covering a combination that has not been seen frequently before is left at its original score. Within a single case you may therefore see some observations adjusted and others untouched, and the untouched ones are often the more interesting.


A reduced score is not a verdict

This is the part that most often causes confusion, so it is worth stating plainly.

A reduction records how common the activity is. It does not record a judgement about whether the activity is benign, and it is not a dismissal.

  • The observation is not discarded. It stays on the case and stays fully visible in the platform, at its adjusted score.
  • Recurring is not the same as safe. Activity repeating every day may point to a misconfiguration, a noisy but legitimate application, or an unresolved compromise that has been normalised over time. Any of those warrants attention.
  • The frequency is itself a finding. If the note tells you that something has been happening daily and that is news to you, then the fact that it is routine is the thing to investigate, not a reason to close the case.

💡 Reading the note well: treat it as an answer to "how often does this happen here?" and not as an answer to "is this a threat?". The second question is what the case, the AI case summary, and your own investigation are for.


Investigating an adjusted observation

  1. Read both scores. The note gives the original score as well as the adjusted one, so you can see how far the activity was moved and why.
  2. Establish how far back the pattern goes. Use Hunt Lab to query the relevant telemetry for the device or user named in the note. A pattern that starts abruptly a fortnight ago reads differently from one that has run for a year.
  3. Decide whether the activity is expected. If it maps to a known application, a scheduled job, or a documented business process, it is a candidate for tuning. If nobody can account for it, treat the case on its merits and escalate as you normally would.
  4. Act on the underlying cause. Where the activity is expected and unwanted noise, the fix is usually configuration rather than triage. See EPP Exclusions for known-safe files and processes, and Device Segments for behaviour that should differ by device population.

Standalone Medium and Low cases

Cases are built from correlated observations, but correlation is not a requirement for a case to exist. A single observation can open a case on its own, which means you will sometimes see a Medium or Low case containing one observation and nothing else. That is expected behaviour rather than a fault.

If you would prefer a specific detection to raise a case only when it appears alongside other indicators, that is a tuning conversation rather than a setting you can change yourself. Contact support@senseon.io or your Customer Success Manager with the detection name and the secondary indicators you would want to see required, and the SOC can advise on what is possible for your environment.


What automated triage is not

It is not What that is instead
A way to stop a detection firing EPP Exclusions for known-safe files, paths, and processes
Per-device configuration Device Segments, which control sensor and response behaviour by device population
The confidence score on a Resolve verdict Resolve, which scores its own certainty in an investigation it has carried out
A case outcome The outcome you assign when closing a case, covered in Investigate

  • Investigate: case scoring, case states, and close-out outcomes
  • SenseOn AI Architecture: how detection, correlation, and the specialist agents fit together
  • AI Case Summaries: the generated narrative on a case, which will refer to adjustments where they apply
  • Overview: daily triage workflow and bulk acknowledgement