Smarter Week

How to automate it

How to automate “triage security alerts and false positives”

Here are 2 ways to spend less time on this, best first. Each comes with steps you can follow today.

90 min
typically, every day
50%
of the time can be automated
Some setup
to set up

Fix 1 of 2

Software featureBest fix

Use your security platform's AI to triage and summarize alerts

Microsoft Security Copilot, Google Security Operations with Gemini, CrowdStrike Charlotte AI and SentinelOne Purple AI can investigate an alert, gather context and suggest a verdict, so analysts start from a summary.

Typically saves about 35% of the time2 h to set up
  1. 1Check which AI features your SIEM or EDR license already includes.
  2. 2Turn on automatic alert triage or summaries for your highest-volume alert types.
  3. 3Ask follow-up questions in plain language ("show other sign-ins from this IP in the last 7 days").
  4. 4Track how often you agree with its verdicts before trusting it for auto-closing.

Tools: Microsoft Security Copilot · Google Security Operations with Gemini · CrowdStrike Charlotte AI · SentinelOne Purple AI

Fix 2 of 2

Automation

Automate enrichment and routine responses with playbooks

Playbooks look up IPs, domains and users, check reported phishing emails and close obvious false positives before an analyst sees them.

Typically saves about 55% of the time6 h to set up
  1. 1Pick the alert type that eats the most time, often reported phishing.
  2. 2Build a playbook in Tines, Torq, Microsoft Sentinel or Google SecOps: enrich, check sandboxes and reputation, decide.
  3. 3Have it auto-close clear false positives, quarantine clear phish across mailboxes, and reply to the reporter.
  4. 4Send only unclear cases to an analyst with the evidence attached.

Tools: Tines · Torq · Microsoft Sentinel playbooks · Google SecOps · Microsoft Defender for Office 365 automated investigation

Quick wins

Have you tried…

Have you used the AI built into your security tools to investigate alerts?
Security Copilot, Google SecOps Gemini, Charlotte AI and Purple AI gather the context on an alert and summarize it, so you start from a summary instead of raw logs.

Who does this task

Roles in our library that list this as one of their common tasks. Each guide covers the rest of that role’s week.

HourLeak · the 8-minute work audit

How many hours does this cost you?

The free 8-minute check works out where your week goes and gives you your top fixes. The team scan does the same for everyone and adds it up, so you know which leaks to fix first.

Answers are anonymous. Leaders only see team totals.

Other common tasks for Security analysts