💡 A Guide to Using Tags for Enhanced Security Investigations
Overview
Tags in Qevlar AI provide quick, accurate, and actionable intelligence about investigations and observables. They help you rapidly understand threats, prioritise your response efforts, and drive automated workflows.
This guide covers:
- The two types of tags (Observable and Insight)
- The complete tag catalog by category
- How tags are applied and reverted
- How to interpret different "Malicious" situations depending on containment and user exposure
- How to use tags for prioritisation and automation
Types of Tags
Observable Tags
Observable tags appear in the Observables table within investigation reports. They are attached to specific observables (IP addresses, domains, URLs, files, email addresses, users) to provide context about what the investigation found.
Observable tags help you quickly identify:
- Risk indicators associated with specific observables
- Actions that have been taken (blocked, quarantined, removed)
- User interactions with threats (clicked, downloaded, executed)
- Contextual characteristics of the observable (country, private, trusted)
Insight Tags
Insight tags appear in the header of investigation reports and provide a high-level summary of the most important findings. They aggregate information from observable tags to give you an immediate understanding of the threat landscape.
Up to 4 insight tags are displayed, prioritised by their significance to your security posture. They help you:
- Quickly assess severity and threat type
- Understand the scope of impact (how many users, which VIPs)
- Identify critical actions that occurred (malicious URL clicked, file executed)
Tag Categories
Threat Classification Tags
These tags identify the nature and severity of threats detected in your environment.
- Malicious – Confirmed malicious through threat intelligence or analysis
- Suspicious – Exhibits suspicious characteristics warranting investigation
- Phishing – Email or URL identified as part of a phishing campaign
- Reconnaissance – Email classified as reconnaissance activity by Qevlar Eye
- Scam – Content identified as fraudulent or deceptive
- Spam – Unsolicited bulk email detected
- Marketing – Email identified as marketing/promotional content
- Grayware – Unwanted behaviour but not outright malicious
- Hacktool – Legitimate security tools that could be used maliciously
- Malware – Malware detected
- PUA – Potentially Unwanted Application
Advanced File Threat Classifications
Specialised tags from sandbox analysis identifying specific malware behaviours.
- Ransomware – Can potentially encrypt files or restrict access until a ransom is paid
- Trojan or Bot – Capable of covertly executing commands or being controlled remotely
- Spyware – May steal sensitive information and track user activity
- Banker – Monitors or modifies e-banking transactions
- Evader – Can bypass OS protections and obfuscate behaviour
- Exploiter – Exploits vulnerabilities to cause unintended code execution
- Spreading – Behaviour that could infect other devices or network systems
- Miner – Uses the host device to mine cryptocurrencies
- Adware – Potentially injects advertisements into browser results
User Interaction Tags
These tags indicate how users have interacted with potentially malicious content, helping you assess level of exposure and potential compromise.
- Clicked – A user clicked on a URL
- Visited – A URL was visited by a user
- Downloaded – A file was downloaded by a user
- Executed – A file or process was executed (Coming soon!)
- Opened – A file was opened by a user (Coming soon!)
- Replied – A recipient replied to a suspicious email
- Forwarded – A recipient forwarded a suspicious email to others
Containment Action Tags
These tags show what security controls have acted upon threats, helping you understand the current containment status.
- Blocked – Observable was blocked by a preventative security system (currently available for Email and File observables)
- Quarantined – File has been quarantined
- Removed – Email or file was removed by security systems
- Junked – Email was delivered to the junk folder
Email Authentication Tags
These tags indicate the results of email authentication checks, critical for identifying spoofed or forged emails.
- Email Authentication Failed – When any of the below is observed
- DMARC Failed – Email failed DMARC authentication
- SPF Failed – Email failed SPF authentication
- DKIM Failed – Email failed DKIM authentication
- CompAuth Failed – Email failed composite authentication
Infrastructure & Network Tags
These tags provide context about network infrastructure associated with observables.
- Country – Geographic location of the IP address
- Private – IP address is within private address space
- VPN – IP address belongs to a VPN service
- Proxy – IP address is a known proxy server
- Hosting – IP is associated with a data center or cloud provider
- Service Provider – IP belongs to a recognised service provider (Google, Amazon, etc.)
User Context Tags
These tags identify users who may require special attention due to their role or access privileges.
- VIP – User identified as a VIP (executive, board member, etc.)
- High Privileged User – User has elevated system or application privileges
Investigation Context Tags
These tags provide additional context about the investigation process and findings.
- Investigated – Observable was directly investigated and has corresponding investigation steps
- Embedded – URL was embedded within email content
- Redirection – URL was discovered as part of a redirection chain
- Attached – File was attached to an email
- QR Code – Observable was extracted from a QR code
- Typosquatting – Domain appears to be impersonating a legitimate domain
- Suspected Typosquatting – Domain exhibits characteristics suggesting potential typosquatting
- Mass Distribution – Email was sent to 500 or more recipients
- Needs Corroboration – Finding requires human validation to reach a final determination
- Missing Body – Email alert does not contain the message body
- Trusted – Domain is on your organisation's or Qevlar's trusted list
- Downloadable Content – URL is a download link
- Signed – File has been verified as signed
- Sender – Observable is associated with the email sender
- Recipient – Email address is a recipient
How Tags Are Applied and Reverted
Application
Tags are applied automatically by Qevlar AI during investigation based on:
- Threat intelligence lookups → e.g.
Malicious,Phishing,Suspicious - Sandbox analysis results → e.g.
Ransomware,Trojan,Evader - Security control signals → e.g.
Blocked,Quarantined,Removed - User activity logs → e.g.
Clicked,Downloaded,Replied - Email authentication results → e.g.
DMARC Failed,SPF Failed - Contextual enrichment → e.g.
VIP
Tags are applied at the observable level first, then aggregated into Insight tags in the report header.
Understanding "Malicious" Situations: Containment vs. Exposure
Not all Malicious tags carry the same urgency. The critical question is whether the threat was contained before user exposure or whether a user interacted with it. Use this matrix to assess the appropriate response.
| Tag Combination | Situation | Recommended Action |
|---|---|---|
Malicious only | Threat identified, exposure unclear | Verify whether any user accessed the observable |
Malicious • Blocked | Threat detected and stopped | Confirm the block is complete across all gateways; no user action required if no interaction tag is present |
Malicious • Blocked • user interaction | Threat was blocked after user interaction | Investigate the timing; assess whether the user accessed the content before the block took effect |
Malicious • Clicked | User accessed the threat | Assess credential or session risk; consider further investigation |
Malicious • Downloaded | Malicious file reached the endpoint | Initiate endpoint investigation; consider isolation |
Malicious • Downloaded • Executed | Active execution of malicious content | High-confidence compromise; initiate incident response immediately |
Malicious • VIP | High-value user targeted | Escalate to executive protection workflow |
Ransomware / Spreading | Potential propagation risk | Trigger containment playbook; check for lateral movement |
Phishing • Replied | Possible credential harvesting | Initiate credential reset for affected users |
💡 Key rule of thumb:
Malicious+Blockedwith no user interaction tag → threat was stopped.Malicious+ a user interaction tag (regardless ofBlocked) → the threat reached a user and requires active investigation.
Using Tags for Prioritisation and Automation
Rapid Triage
When managing multiple alerts, start with Insight tags in the report header. They provide the highest-level summary and help you determine priority at a glance.
Example: Malicious URL Clicked | VIP immediately signals a high-value user interacted with a confirmed threat — no need to read the full report before escalating.
Assessing Impact
The combination of threat classification tags and user interaction tags determines how far a threat has progressed:
| Scenario | Risk Level | Implication |
|---|---|---|
Malicious • Blocked (no interaction) | 🟢 Contained | Security controls were effective |
Clicked on a malicious URL | 🟠High | User accessed threat content |
Clicked • Downloaded | 🔴 Critical | Malicious file on user's system |
Downloaded • multiple file threat tags | 🔴 Critical | High-confidence threat with specific behaviour indicators |
Automation Triggers
Tags enable automated response workflows. Recommended triggers:
| Tag Combination | Recommended Automated Action |
|---|---|
Malicious • Downloaded | Isolate endpoint; open high-priority ticket |
Malicious • VIP | Page on-call team; notify security leadership |
Ransomware / Spreading | Trigger network isolation playbook |
Phishing • Mass Distribution | Block sender domain; notify all recipients |
Malicious • Blocked (no interaction) | Log and close; add to blocklist |
Needs Corroboration | Route to Tier 2 analyst queue |
Trusted | Suppress future alerts for that observable |
Authentication Failed • Mass Distribution | Trigger anti-spoofing review |
Following the Attack Chain
Use context tags to reconstruct the full delivery chain:
- Embedded + Redirection → understand how a URL was reached
- Attached → trace file delivery via email
- QR Code → identify unconventional delivery methods
- Typosquatting / Suspected Typosquatting → map impersonation infrastructure
Best Practices
Start with Insight tags. When opening a new investigation, the header tags give you immediate signal on priority and required action before reading the full report.
Check for containment first. Before acting, verify whether Blocked, Quarantined, or Removed tags are present — this determines whether a threat is already contained or still active.
Escalate on VIP + interaction combinations. Investigations combining VIP or High Privileged User with any user interaction tag should always be treated as high priority.
Use Advanced File Classifications for targeted response. Tags like Ransomware and Spreading map directly to specific IR playbooks — don't treat them as generic malware alerts.
Submit feedback to keep tags accurate. The quality feedback feature ensures that tag corrections are tracked and auditable, improving the accuracy of future investigations and your automation triggers.
Conclusion
Tags are designed to accelerate your security operations by providing immediate, actionable intelligence about threats and observables. With a clear understanding of tag lifecycle, containment vs. exposure scenarios, and the quality feedback loop, you can:
✅ Triage alerts faster and more accurately\
✅ Distinguish between contained threats and active incidents requiring immediate response\
✅ Keep investigation verdicts accurate through structured feedback\
✅ Drive reliable automations and reporting based on tag combinations\
✅ Reduce mean time to respond (MTTR) to security incidents