What Happens After an Alert Gets Flagged: Inside Rainier’s Investigate & Detect

Author
Amruta Telang

September 29, 2026

Read

ai powered soc

Key Takeaways

  • Every case arrives with an AI-written narrative and root-cause summary, not a raw alert an analyst has to interpret from scratch.
  • Entities (IPs, hashes, emails, endpoints) are extracted and enriched against threat intelligence automatically, inline in the case.
  • Every case carries a MITRE ATT&CK technique mapping, and response actions (isolate, block, disable) are available directly from the case.
  • Client-reply handling lets an LLM read a plain-language email reply, verify it against DMARC and sender authorization, and act on it, without an analyst reading the thread.
  • Detection Lens audits a SIEM’s full rule base (tested against ~3,000 rules and ~1,400 building blocks in one deployment) against what those rules actually produced, surfacing noise and real coverage gaps.
  • A CISO-level dashboard tracks alert volume, MTTD/MTTR, SLA compliance, composite risk score, and MITRE tactic coverage as a live heatmap.

Our Alerts & Triage deep dive covered how Rainier decides what deserves a human’s attention. This post covers what happens once something does: how a case gets investigated, how it gets closed, and a separate capability that turns the same analysis back on the SIEM itself.

A case that arrives already written up

Rainier investigates - soc

When an alert escalates to an analyst, the case doesn’t start as a raw log line. Every case carries an AI-written narrative and root-cause summary, generated from the evidence the platform already gathered rather than assembled by an analyst reading through raw logs first.

Alongside the narrative, every entity in the case, IP addresses, file hashes, email addresses, endpoints, is extracted and enriched inline against threat intelligence sources automatically. And each case carries a MITRE ATT&CK technique mapping, so an analyst can see not just what happened, but where it sits in the broader pattern of adversary behavior, without looking it up separately.

Response doesn’t require leaving the case either. Isolating an endpoint, blocking a hash, or disabling a user account are actions available directly from the case view, not a separate console an analyst has to switch into.

Closing the loop without reading the thread

A meaningful share of case handling is correspondence, not analysis: a client replies to a notification confirming an incident is expected, or asking for more detail. Rainier’s client-reply handling lets an LLM read a plain-language email reply, check it against DMARC and sender authorization, and use it to close, escalate, or keep the case open, without an analyst having to read the thread first. The authentication check matters here: the system is verifying the reply actually came from an authorized sender before acting on it, not just parsing whatever text arrives.

Detection Lens: turning the same analysis on the SIEM itself

 

Every SOC eventually accumulates SIEM rules nobody fully trusts. Some fire constantly and get ignored. Some haven’t fired in a year and nobody remembers why they exist. Very few teams have the time to audit a rule base of any real size.

Detection Lens does that audit automatically. It snapshots a client’s SIEM rule base, in one deployment tested against roughly 3,000 rules and 1,400 building blocks, and cross-references every rule against what Rainier’s own analysis concluded about the alerts those rules actually produced. The output identifies which rules are earning their place, which are generating noise without real signal, and where coverage is genuinely missing. That last category is often the most valuable: not “which rules are loud,” but “what isn’t being watched at all.”

Watching posture, not just individual cases

Because every case and every rule audit feeds the same platform, a CISO-level view of posture is available without anyone compiling it by hand: alert volume, median MTTD and MTTR, active incidents by priority, SLA compliance across P1 through P4, a composite risk score, and MITRE ATT&CK tactic coverage shown as a heatmap across the full kill chain. Coverage gaps show up the same way rule gaps do in Detection Lens: visibly, rather than silently.

KPIs tracked without manual compilation

Case handling is measured the same way triage is, automatically:

Metric What it tracks
MTTD Mean time to detect
MTTA Mean time to acknowledge
MTTR Mean time to respond
MTTC Mean time to contain or close

Why this matters beyond convenience

An AI-written narrative and automatic MITRE mapping save time on every single case, but Detection Lens solves a different, slower-burning problem: rule debt. Most SOCs know their rule base has drifted from what actually matters, but auditing thousands of rules manually never makes it to the top of anyone’s list. Turning that into something the platform does continuously, using its own analysis of what those rules actually catch, closes a gap that otherwise just accumulates.

Who this is for

  • SOC analysts who want to start an investigation from a written narrative and enriched entities instead of raw alert data.
  • SOC managers trying to reduce email and ticket overhead from routine client correspondence.
  • Detection engineers who need an evidence-based answer to which SIEM rules are actually worth keeping.
  • CISOs who need MITRE ATT&CK coverage and SLA compliance as a live view, not a quarterly manual exercise.

Want to see a real case narrative and a Detection Lens audit on your own rule base? Book a Rainier walkthrough.

Author

Related Tags:

FAQs 

A written root-cause summary assembled from the evidence already gathered on the case, alongside entity enrichment (IPs, hashes, emails, endpoints checked against threat intelligence) and a MITRE ATT&CK technique mapping, all without an analyst compiling it manually.
Yes, when appropriate. An LLM reads a plain-language reply, checks it against DMARC and sender authorization, and uses it to close, escalate, or keep the case open, so routine correspondence doesn't require an analyst to read the full thread.
Detection Lens audits a SIEM's rule base by comparing every rule against what Rainier's own analysis concluded about the alerts that rule actually generated, showing which rules are useful, which are noise, and where real detection coverage is missing.
In one deployment, it was tested against roughly 3,000 rules and 1,400 building blocks.
Mean time to detect (MTTD), acknowledge (MTTA), respond (MTTR), and contain or close (MTTC), compiled without manual reporting.
Yes. A CISO-level dashboard includes a MITRE ATT&CK tactic coverage heatmap across the kill chain, alongside alert volume, SLA compliance, and a composite risk score.
Table of Contents
Secure with Network Intelligence
Top