SOC, AI/ML, Exposure management

SOC investigations now work on an attacker’s timeline

Security teams often investigate alerts one at a time, which makes it harder to see an attack that unfolds over several days, uses different IP addresses, or triggers detections across several tools. Command Zero has introduced Throughline, a new capability that connects related security alerts into one investigation and updates the case as new evidence appears. It is part of a broader platform update focused on alert prioritization, investigation management, and response.

Throughline keeps the case active. When a new alert matches an existing investigation, the platform adds the evidence, extends the timeline, and reviews the verdict again. It can also reopen a case that was already closed.

Beyond alert correlation

Security platforms have used correlation rules for years to group related alerts.

Al Huger, co-founder and chief product officer at Command Zero, told MSSP Alert that Throughline goes further by reviewing the full case each time new information arrives.

“Correlation has existed for decades. This is the next evolution of it, what it was always meant to be but couldn't until now, because the technology constraints finally fell away. A correlation rule matches patterns someone defined in advance and files a snapshot based on point-in-time data.”

Throughline uses previous investigations, analyst notes, company policies, and asset inventories to decide whether alerts belong together.

“Throughline re-reasons: it constantly re-evaluates the details and impact of a case the way a seasoned analyst would, 24/7, grounded in your prior investigations, policies, and asset inventory. And it keeps every case alive, including closed ones. When a new alert arrives, Throughline checks it against even cases that were closed and forgotten, revives the matching one, and folds it into a single living investigation.”

The focus is on giving analysts one case that changes as the attack develops, rather than a list of separate incidents.

“Correlation clusters alerts. Throughline runs one continuous reasoning evaluating new information as it becomes available, so nothing gets closed and left behind while an adversary is still working.”

Cutting the number of verdicts analysts review

Command Zero said Throughline reduced the number of verdicts analysts had to review by as much as 41% in early testing.

Huger said the company measured the result using one month of production alerts from early-adopter customers.

“We measured it against a month of production alerts across early-adopter customers in complex environments. The metric is specific: the number of distinct verdicts an analyst had to consider fell by up to 41 percent. It's alert consolidation, not suppression, related alerts that surface today as separate cases, each with its own verdict, collapse into one living investigation with a single evolving verdict. This approach delivers the same coverage, fewer decisions for a human to pick up. The released figure is about verdict-review volume, and that's the claim we stand behind.”

The 41% figure does not mean the platform removed that share of alerts. It means related alerts were combined into fewer investigations, leaving analysts with fewer separate decisions to review.

Finding attacks across several cases

Command Zero said that Throughline also found threats that were difficult to spot when alerts were investigated separately.

In one early-adopter case, five exploitation attempts targeted the same public-facing PHP application over several days. Each attempt used a different IP address and carried a different alert and incident ID. The original security tool treated them as unrelated events.

Huger explained with examples.

“Case one: the campaign the alerting vendor missed. Five exploitation attempts hit a customer's public-facing PHP application over several days, probing the same well-known package-manager technique. Every attempt came from a different IP. Every attempt carried a different alert ID and a different incident ID from the tool that detected it. The vendor's own correlation, running on its own alerts, treated them as five unrelated events. Throughline matched them on the subjects that didn't change, the target machine and the URL under attack, and assembled one investigation telling one story: someone is working this server, and they are not giving up.”

In another case, phishing emails targeted employees across four office locations. The customer’s existing tools grouped the messages, while Throughline also connected them through the same legitimate email delivery service.

“Case two: the phishing campaign with a map. A wave of phishing emails targeted office mailboxes at a customer, and the first-party tooling did manage to group the alerts this time. Throughline matched on an additional subject the grouping missed: the legitimate email-delivery service every message rode in on. With the full set threaded together, a pattern surfaced that no single alert showed. Each phish targeted a different office location. Four cities, one campaign, one deliberate adversary mapping the org chart. That's the kind of finding that changes a response from "reset a password" to "wake up the IR lead."”

A third case involved three alerts tied to the same IP address and user account. Only one alert had an incident ID from the original tool.

“Case three: the compromise hiding in plain sight. Three alerts fired involving the same IP address and the same user account. Only one of the three carried an incident ID from the source tool. Investigated separately, the first alert was already high severity and the other two were easy to shrug off. Threaded together by Throughline, they pointed at something worse: either the original detection was confused, or the exploited account was actively in use. Both possibilities demand attention. Neither was visible one alert at a time.”

These examples show why the investigation timeline matters. An alert that looks minor on its own may carry more weight when it appears alongside earlier activity.

Putting controls around automated response

Throughline is one part of Command Zero’s wider platform update. Other planned features include automatic alert closure, alert tuning, exposure management, and more detailed role-based access controls.

The company is also adding verdict-driven response actions. These can trigger containment based on the result of an investigation rather than the severity attached to an individual alert.

Because a Throughline verdict can change as new evidence arrives, safeguards around automated response are important. Huger said response actions are set to notification-only by default and must be enabled by the customer.

“Throughline's verdicts are designed to change as evidence arrives, so the safeguards matter. Response is notify-only by default and containment fires on verdicts, not raw severity, and only when a customer deliberately enables it by policy. Verdicts evolve toward completeness, not randomness: each revision re-reasons the full case and keeps its evidence trail intact, so a change is explainable, never a black-box flip. And RBAC in our platform is granular; it controls not just which actions an agent can take, but under what conditions, and against which data sources or targets. Everything is audited, and reversible-first, and disruptive actions stay gated behind human approval.”

Command Zero is making Throughline data available through its APIs and Model Context Protocol server. SOC teams can connect case updates and revised verdicts to the SOAR playbooks, threat-hunting tools, and internal systems they already use.


An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds