UTMStack

Turn related alerts into one case and close it as a team

Incidents bring related alerts together so your team investigates and responds once, not alert by alert. A creation wizard, custom assignment, notifications and a board view keep everyone on the same page.

UTMStack · Incidents
The incidents table: each incident with its status, severity, owner, number of linked alerts and creation date, with tabs to filter by status and a switch to the board view.
  • Creation wizard

    A step-by-step wizard creates an incident from one or many alerts, or adds them to an incident that already exists.

  • Board and table views

    Track every incident on a board with open, in review, completed and merged columns, or switch to a table view.

  • Clear ownership

    Assign each incident to an analyst and notify the people who need to know.

  • Everything in one drawer

    Open an incident to see its alerts, notes and full history without leaving the list.

  • Respond from the incident

    Run response commands from the incident, and each action is recorded against it.

  • Opened for you

    Response flows and the AI assistant can open incidents automatically when alerts call for it.

Why incidents, not just alerts

One intrusion often raises many alerts across several systems. Grouping them into one incident gives a single place for the investigation, the decisions and the evidence. It also stops two analysts from chasing the same thing.

From alert to closed case

Create an incident from the alerts list, set its severity and owner, and the right people are notified by email. As the work moves along, change its status, update the linked alerts and add notes. When it is done, the incident holds a complete record of what happened and what you did.

Built for service providers

In multi-tenant installs, incidents are filtered by tenant, so each customer's cases stay separate. Managed service providers can be given authorized access across tenants to work on incidents for many customers from one console.

Questions buyers ask

Can one incident include alerts from different systems?

Yes. You can add alerts from any data source to an incident, and add more later as the investigation grows.

Who gets notified about a new incident?

The analyst you assign and the incident email list set in the platform settings. Response flows can also send notifications as part of an automated response.

Can I connect incidents to my ticketing system?

Yes. UTMStack can email new incidents to a ticketing inbox, or a response flow can create the ticket through your ticketing tool's application programming interface (API).

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.