Our Alerts & Triage deep dive covered how Rainier decides what deserves a human’s attention. This post covers what happens once something does: how a case gets investigated, how it gets closed, and a separate capability that turns the same analysis back on the SIEM itself.
A case that arrives already written up

When an alert escalates to an analyst, the case doesn’t start as a raw log line. Every case carries an AI-written narrative and root-cause summary, generated from the evidence the platform already gathered rather than assembled by an analyst reading through raw logs first.
Alongside the narrative, every entity in the case, IP addresses, file hashes, email addresses, endpoints, is extracted and enriched inline against threat intelligence sources automatically. And each case carries a MITRE ATT&CK technique mapping, so an analyst can see not just what happened, but where it sits in the broader pattern of adversary behavior, without looking it up separately.
Response doesn’t require leaving the case either. Isolating an endpoint, blocking a hash, or disabling a user account are actions available directly from the case view, not a separate console an analyst has to switch into.
Closing the loop without reading the thread
A meaningful share of case handling is correspondence, not analysis: a client replies to a notification confirming an incident is expected, or asking for more detail. Rainier’s client-reply handling lets an LLM read a plain-language email reply, check it against DMARC and sender authorization, and use it to close, escalate, or keep the case open, without an analyst having to read the thread first. The authentication check matters here: the system is verifying the reply actually came from an authorized sender before acting on it, not just parsing whatever text arrives.
Detection Lens: turning the same analysis on the SIEM itself
Every SOC eventually accumulates SIEM rules nobody fully trusts. Some fire constantly and get ignored. Some haven’t fired in a year and nobody remembers why they exist. Very few teams have the time to audit a rule base of any real size.
Detection Lens does that audit automatically. It snapshots a client’s SIEM rule base, in one deployment tested against roughly 3,000 rules and 1,400 building blocks, and cross-references every rule against what Rainier’s own analysis concluded about the alerts those rules actually produced. The output identifies which rules are earning their place, which are generating noise without real signal, and where coverage is genuinely missing. That last category is often the most valuable: not “which rules are loud,” but “what isn’t being watched at all.”
Watching posture, not just individual cases
Because every case and every rule audit feeds the same platform, a CISO-level view of posture is available without anyone compiling it by hand: alert volume, median MTTD and MTTR, active incidents by priority, SLA compliance across P1 through P4, a composite risk score, and MITRE ATT&CK tactic coverage shown as a heatmap across the full kill chain. Coverage gaps show up the same way rule gaps do in Detection Lens: visibly, rather than silently.
KPIs tracked without manual compilation
Case handling is measured the same way triage is, automatically:
| Metric | What it tracks |
|---|---|
| MTTD | Mean time to detect |
| MTTA | Mean time to acknowledge |
| MTTR | Mean time to respond |
| MTTC | Mean time to contain or close |
Why this matters beyond convenience
An AI-written narrative and automatic MITRE mapping save time on every single case, but Detection Lens solves a different, slower-burning problem: rule debt. Most SOCs know their rule base has drifted from what actually matters, but auditing thousands of rules manually never makes it to the top of anyone’s list. Turning that into something the platform does continuously, using its own analysis of what those rules actually catch, closes a gap that otherwise just accumulates.
Who this is for
- SOC analysts who want to start an investigation from a written narrative and enriched entities instead of raw alert data.
- SOC managers trying to reduce email and ticket overhead from routine client correspondence.
- Detection engineers who need an evidence-based answer to which SIEM rules are actually worth keeping.
- CISOs who need MITRE ATT&CK coverage and SLA compliance as a live view, not a quarterly manual exercise.
Want to see a real case narrative and a Detection Lens audit on your own rule base? Book a Rainier walkthrough.
