# Threat Severity Triage

*/Problems/Threat_Severity_Triage*

## Problem Overview

Security Operations Center (SOC) analysts confront a continuous, high-volume influx of security alerts from network, endpoint, and cloud monitors. Every flagged anomaly demands immediate evaluation to separate active breaches from benign system behaviors. Because modern infrastructure produces thousands of alerts daily, analysts suffer from acute alert fatigue, forcing them to bulk-close notifications or rely on superficial heuristics rather than thorough investigation.

Current triage systems rely on static rules and vendor-assigned severity scores that ignore specific environmental context. A routine vulnerability scanner probing an internal staging server triggers the exact same critical alert as an external attacker scanning a production database. To determine actual risk, responders manually query identity providers, network logs, and threat intelligence feeds, a repetitive context-gathering process that consumes hours and delays reaction to genuine threats.

This bottleneck persists because rigid security logic cannot interpret the operational nuances of a specific enterprise. Without systems that automatically correlate alert data with historical behavior and internal asset criticality, threat triage remains a manual sorting exercise that breaks under the scale of modern data environments.

## Problem Severity Frequency

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Severity**: 4
**Frequency**: continuous
**Budget Reality**:
- **Price Ceiling**: ~$40k–100k/yr — capped by the cost of one SOC analyst FTE or existing SOAR tool spend
- **Who Controls Spend**: CISO or Director of Security Operations
- **Existing Budget Line**: true
- **Switching Cost From Status Quo**: high: requires deep integration with incumbent SIEM/EDR, identity providers, and altering the SOC's primary daily workflow
**Regulatory Risk**: high
**Time Cost Per Event**: ~30–60 min per investigated alert
**Money Cost Per Event**: ~$40–100 in analyst labor per escalation
**Annual Cost Per Affected Entity**: ~$150k–300k in wasted SOC labor and churn

## Problem Why Now

The rapid expansion of multi-cloud architectures and microservices over the past three years exponentially increased the enterprise attack surface, generating alert volumes that mathematically exceed human review capacity. Legacy Security Information and Event Management tools attempt to manage this data using static correlation rules. These rigid rules fail to capture the ephemeral nature of modern infrastructure, resulting in massive false-positive rates and forcing analysts to ignore warnings just to maintain operational pace.

Until recently, automating threat triage required building rigid security playbooks that immediately broke when network topologies or user behaviors changed. This structural bottleneck is newly addressable because large language models now feature massive context windows capable of ingesting raw unstructured network logs, threat intelligence feeds, and internal asset directories simultaneously. This crossing of the context-window threshold allows systems to perform the contextual reasoning required to differentiate a benign administrative script on a staging server from malicious lateral movement in production.

## Problem Current Solutions

**Status Quo**: SOC analysts manually review high-volume alerts in their SIEM, cross-referencing vendor-assigned severity scores against network logs and identity providers to verify active threats.
**Workarounds**:
- bulk-closing unreviewed alerts
- manual Active Directory queries
- exporting SIEM data to spreadsheets
- custom Python enrichment scripts
**Named Tools In Use**:
- [Splunk Enterprise Security](/Products/Splunk_Enterprise_Security)
- [Palo Alto Cortex XSOAR](/Products/Palo_Alto_Cortex_XSOAR)
- [CrowdStrike Falcon](/Products/CrowdStrike_Falcon)
- [Microsoft Sentinel](/Products/Microsoft_Sentinel)
- [ServiceNow SecOps](/Products/ServiceNow_SecOps)
**Why Insufficient**: Static rules and vendor-assigned scores ignore environmental context and historical asset behavior. They cannot automatically weigh an alert against internal asset criticality, leaving the contextual synthesis entirely to manual human effort.

## Problem Market Profile

**Incumbents**:
- [Splunk Enterprise Security](/Problems/Threat_Severity_Triage/Competitors/Splunk_Enterprise_Security)
- [Palo Alto Cortex XSOAR](/Problems/Threat_Severity_Triage/Competitors/Palo_Alto_Cortex_XSOAR)
- [CrowdStrike Falcon](/Problems/Threat_Severity_Triage/Competitors/CrowdStrike_Falcon)
- [Microsoft Sentinel](/Problems/Threat_Severity_Triage/Competitors/Microsoft_Sentinel)
- [ServiceNow SecOps](/Problems/Threat_Severity_Triage/Competitors/ServiceNow_SecOps)
**Substitutes**:
- Bulk-closing unreviewed alerts
- Manual Active Directory queries
- Custom Python enrichment scripts
- Exporting SIEM data to spreadsheets
**Position Axes**:
- Context Awareness (Generic Vendor Severity vs. Environment-Specific Risk)
- Execution Autonomy (Manual Investigation vs. Autonomous Decisioning)
**Market Dynamics**: The market is consolidating as major SIEM and endpoint vendors absorb standalone orchestration tools to bundle alert generation and response into unified data architectures.
**Competition Concentration**: Incumbent SIEMs and endpoint platforms cluster heavily in the generic vendor severity and manual investigation quadrant, outputting high volumes of static alerts. Legacy SOAR tools push into autonomous decisioning but remain tethered to generic rules, leaving the environment-specific risk and autonomous decisioning quadrant largely unoccupied.

## Mint Vocabulary Bag

**Action Verbs**:
- isolate
- scope
- correlate
- pivot
- validate
- suppress
**Gerund Stems**:
- scop
- triag
- pivot
- hunt
- mapp
**Abstract Nouns**:
- urgency
- exposure
- fidelity
- prevalence
- dwelltime
**Concrete Nouns**:
- payload
- beacon
- packet
- endpoint
- anomaly
- indicator
**Metaphor Nouns**:
- sentinel
- sieve
- prism
- nexus
- anchor
**Structure Nouns**:
- sandbox
- backlog
- stream
- vault
- grid

## Problem Candidate Solutions

- [Urgencybase](/Problems/Threat_Severity_Triage/Startups/Urgencybase) — Agent
- [Payloadguild](/Problems/Threat_Severity_Triage/Startups/Payloadguild) — Service-as-Software
- [Payloadatelier](/Problems/Threat_Severity_Triage/Startups/Payloadatelier) — Software
- [Noisehook](/Problems/Threat_Severity_Triage/Startups/Noisehook) — Software
- [Scopiln](/Problems/Threat_Severity_Triage/Startups/Scopiln) — Agent
- [Fagnos](/Problems/Threat_Severity_Triage/Startups/Fagnos) — Software

## Problem Solution Space2x2

```mermaid
quadrantChart
title Threat Severity Triage Landscape
x-axis Surface Indicators --> Deep Payload Inspection
y-axis Static Rules --> Dynamic ML Correlation
quadrant-1 Deep Context & Adaptive
quadrant-2 Surface Breadth & Adaptive
quadrant-3 Rule-based & Surface Breadth
quadrant-4 Rule-based Deep Analysis
Urgencybase: [0.3, 0.4]
Payloadguild: [0.8, 0.7]
Payloadatelier: [0.7, 0.3]
Noisehook: [0.2, 0.8]
Scopiln: [0.6, 0.6]
Fagnos: [0.4, 0.2]
```

## Problem Affected Roles

- SOC Analyst — Frontline Triage
- Incident Responder — Escalation Handling
- Detection Engineer — Rule Configuration
- Threat Hunter — Advanced Analysis
- Security Operations Manager — Team Leadership
- Cloud Security Engineer — Cloud Alerts
- Vulnerability Analyst — Asset Risk

## Problem Affected Companies

- Managed Security Providers — MSSPs
- Large Financial Institutions — Banking And Finance
- Healthcare Delivery Networks — Health Systems
- Cloud-Native Software Firms — SaaS And PaaS
- Telecommunications Network Operators — ISPs And Telcos
- Defense Contracting Firms — Aerospace And Defense
- Global E-Commerce Platforms — Retail And Commerce

## Problem Affected Processes

- Security Alert Triage — SOC Operations
- Threat Intel Enrichment — Context Gathering
- Asset Criticality Assessment — Risk Management
- Incident Response Workflow — Breach Mitigation
- Detection Rule Tuning — Security Engineering
- Identity Context Verification — Access Management
- Vulnerability Scan Management — Infrastructure Security
- Log Correlation Analysis — Data Operations

## Problem Matching Opportunities

- Autonomous Alert Triage for SOCs — AI Agent
- Vulnerability Scoring for Cloud Security — Predictive Analytics
- Endpoint Incident Classification for MSSPs — Classification Engine
- Phishing Threat Assessment for IT — Scoring Model
- Threat Telemetry Reduction for DevSecOps — Data Pipeline

## Problem Token Hero

**Genre**: problem-hero
**Rendered**: Security Operations Center (SOC) analysts confront a continuous, high-volume influx of security alerts from network, endpoint, and cloud monitors.
**Mechanism**: overview-derived-v1
**Template Id**: problem-overview-derived
**Vocab Fingerprint**: 178d4361b471183f

## Neighborhood

### Related (entails child problem)

- [Emergency Site Dispatch](/Problems/Emergency_Site_Dispatch) — entails child problem · Problems

### Competitors

- [Microsoft Sentinel](/Competitors/Microsoft_Sentinel) — competes with · Competitors
- [Palo Alto Cortex XSOAR](/Competitors/Palo_Alto_Cortex_XSOAR) — competes with · Competitors
- [ServiceNow SecOps](/Competitors/ServiceNow_SecOps) — competes with · Competitors
- [Splunk Enterprise Security](/Competitors/Splunk_Enterprise_Security) — competes with · Competitors
- [CrowdStrike Falcon](/Competitors/CrowdStrike_Falcon) — competes with · Competitors

### What it's used for

- [CrowdStrike Falcon](/Products/CrowdStrike_Falcon) — used for · Products
- [Microsoft Sentinel](/Products/Microsoft_Sentinel) — used for · Products
- [Palo Alto Cortex XSOAR](/Products/Palo_Alto_Cortex_XSOAR) — used for · Products
- [ServiceNow SecOps](/Products/ServiceNow_SecOps) — used for · Products
- [Splunk Enterprise Security](/Products/Splunk_Enterprise_Security) — used for · Products

### Entails child problem

- [Initial Threat Containment](/Problems/Initial_Threat_Containment) — entails child problem · Problems
- [Tier One Alert Sorting](/Problems/Tier_One_Alert_Sorting) — entails child problem · Problems
- [Alert Context Enrichment](/Problems/Alert_Context_Enrichment) — entails child problem · Problems
- [Alert Noise Reduction](/Problems/Alert_Noise_Reduction) — entails child problem · Problems
- [Cross Platform Correlation](/Problems/Cross_Platform_Correlation) — entails child problem · Problems
- [Dynamic Risk Scoring](/Problems/Dynamic_Risk_Scoring) — entails child problem · Problems

### Solves problem

- [Noisehook](/Startups/Noisehook) — candidate solution for · Startups
- [Payloadatelier](/Startups/Payloadatelier) — candidate solution for · Startups
- [Payloadguild](/Startups/Payloadguild) — candidate solution for · Startups
- [Scopiln](/Startups/Scopiln) — candidate solution for · Startups
- [Urgencybase](/Startups/Urgencybase) — candidate solution for · Startups
- [Fagnos](/Startups/Fagnos) — candidate solution for · Startups

### Similar Problems

- [Alert Fatigue](/Problems/Alert_Fatigue) — similar · Problems
- [False Positive Alert Storms](/Problems/False_Positive_Alert_Storms) — similar · Problems
- [Manual Alert Investigation](/Problems/Manual_Alert_Investigation) — similar · Problems
- [False Exception Triage](/Problems/False_Exception_Triage) — similar · Problems
- [False Positive Resolution](/Problems/False_Positive_Resolution) — similar · Problems
- [Violation Investigation Triage](/Problems/Violation_Investigation_Triage) — similar · Problems
- [Security Log Audit Deficits](/Problems/Security_Log_Audit_Deficits) — similar · Problems
- [Missed Security Audit Anomalies](/Problems/Missed_Security_Audit_Anomalies) — similar · Problems
- [Triage Crisis Interventions](/Problems/Triage_Crisis_Interventions) — similar · Problems
- [Multimodal Alert Fusion](/Problems/Multimodal_Alert_Fusion) — similar · Problems
- [False Alarm Signal Triage](/Industries/Investigation_and_Security_Services/Problems/False_Alarm_Signal_Triage) — similar · Problems
- [Critical Outage Alert Fatigue](/Problems/Critical_Outage_Alert_Fatigue) — similar · Problems
- [Manual Incident Triage](/Problems/Manual_Incident_Triage) — similar · Problems
- [Triage Operational Escalations](/Problems/Triage_Operational_Escalations) — similar · Problems
- [Access Request Triage](/Problems/Access_Request_Triage) — similar · Problems
- [Component Vulnerability Scoring](/Problems/Component_Vulnerability_Scoring) — similar · Problems
- [Alarm System Rationalization](/Problems/Alarm_System_Rationalization) — similar · Problems

### Similar Metrics

- [Time To Escalate Breaches](/Metrics/Time_To_Escalate_Breaches) — similar · Metrics

### Similar Startups

- [Triagestar](/Startups/Triagestar) — similar · Startups
