CaseBender home page
English
Search...
⌘K
Getting Started
Introduction
Quickstart Guide
Deployment
Deployment Overview
Deploy to Google Cloud Run
Deploy to AWS
Deploy to Azure
Deploy to DigitalOcean
Alert Management
Alert List View
Alert Detail View
Alert Observables
Alert TTPs
Similar Alerts
AI Insights
Case Management
Case Management
Creating Cases
Case Workflows
Working with Cases
Case Settings
AI Features in Case Management
Task Management
Task Management
Creating Tasks
Task Workflows
Working with Tasks
Task Settings
Task Analytics
Analytics
Analytics
Alert Analytics
Case Analytics
Task Analytics
Analyst Performance
Audits
Audit Logs
Change History
Status Tracking
Activity Logs
Compliance Monitoring
Settings
Introduction
Integrations
Workflows
AI Settings
Custom Fields
Observable Types
Attack Patterns
Alert Statuses
Case Statuses
Templates
Branding
CaseBender home page
English
Search...
⌘K
Support
Get Started
Get Started
Search...
Navigation
Alert Management
Similar Alerts
Documentation
API Reference
Documentation
API Reference
Support
Get Started
On this page
Overview
Correlation Methods
Content-based Similarity
Temporal Analysis
Contextual Correlation
Similarity Scoring
Score Components
Score Interpretation
Alert Management
Viewing Similar Alerts
Bulk Operations
Alert Comparison
Pattern Analysis
Campaign Detection
Threat Actor Analysis
Visualization
Timeline View
Relationship Graph
Best Practices
Next Steps
Alert Management
Similar Alerts
Discover and analyze related alerts
Overview
The Similar Alerts tab helps identify and analyze alerts that may be related to the current alert. This feature uses various correlation methods to find potential connections and patterns across your alert data.
Correlation Methods
Content-based Similarity
Title matching
Description analysis
Observable overlap
TTP correlation
Temporal Analysis
Time-based clustering
Frequency patterns
Sequence detection
Campaign timeline
Contextual Correlation
Source alignment
Target comparison
Attack pattern matching
Team/Organization context
Similarity Scoring
Score Components
Observable match percentage
TTP overlap
Temporal proximity
Source correlation
Target alignment
Score Interpretation
High confidence matches
Potential relationships
Weak correlations
False positives
Alert Management
Viewing Similar Alerts
Sort by similarity score
Filter by time range
Group by correlation type
Focus on specific attributes
Bulk Operations
Select multiple alerts
Create case from group
Merge alerts
Update status
Alert Comparison
Side-by-side view
Difference highlighting
Common attributes
Unique characteristics
Pattern Analysis
Campaign Detection
Alert clustering
Pattern identification
Campaign timeline
Attack progression
Threat Actor Analysis
Common TTPs
Observable patterns
Target profiles
Attack methodologies
Visualization
Timeline View
Chronological display
Frequency analysis
Pattern highlighting
Campaign mapping
Relationship Graph
Alert connections
Observable links
TTP relationships
Pattern visualization
Best Practices
Analysis Workflow
Review highest scores first
Validate relationships
Document findings
Update correlation rules
Pattern Recognition
Look for campaigns
Track progression
Note anomalies
Document insights
Alert Management
Group related alerts
Create cases appropriately
Update statuses
Document relationships
Next Steps
AI Insights
Get AI-powered analysis
Alert Rules
Configure correlation rules
Alert TTPs
AI Insights
Assistant
Responses are generated using AI and may contain mistakes.