Uncover where your SOC is ready to automate, backed by your own data.
Automations is in beta. It is read only: nothing in this release takes any action on your environment. It helps you see where Qevlar's verdicts have consistently matched your analysts, so you can decide with confidence what to automate next.
At a glance
Qevlar Automations empower you to identify what to automate next, and be sure it is safe to do so - using evidence you already generate.
Because Qevlar investigates every alert and records how its verdict compares with your analysts' final decision, it can group your similar alerts together and show, for each group, how often it agreed with your team. You see the alert types where Qevlar has reliably matched your analysts, rather than guessing.
Key concepts
Alert groups
Qevlar automatically sorts your alerts into groups of similar alerts. A group is a meaningful slice of your alerts, usually built around a detection rule or an alert category. Groups form on their own from the alerts Qevlar investigates, so there is nothing to configure and no rules to write.
Each group holds alerts that share the same verdict - they are never mixed. This keeps each group consistent, which is what makes the agreement figure meaningful.
Verdict agreement
Verdict agreement is the heart of the feature. For each group, it is the percentage of alerts where Qevlar's verdict was kept by your analysts, measured over the last four weeks. A high figure means Qevlar and your team have consistently reached the same conclusion for that type of alert.
Verdict agreement is your trust signal. It tells you, per alert type and from your own data, where Qevlar has earned the confidence to act, which is the question you have to answer before automating any response.
The four week window
Agreement is calculated on a rolling four week window, so it reflects how Qevlar and your team are aligned now, not months ago. A group needs to have seen enough alerts and analyst reviews before it appears, so newer or lower volume alert types may take time to show up.
Using Automations
Open the page
Select Automations in the left navigation. The group list is the landing page.
If you manage more than one client, use the profile selector at the top of the page to choose whose alerts you are viewing. The page shows one profile at a time.
Read the group list
The list shows one row per group. By default the groups with the highest verdict agreement sit at the top, so your strongest automation candidates are the first thing you see.
Each row shows:
- Alert group: the name of the group
- Alerts in group: how many alerts it contains
- Verdict: whether the group is Malicious or Not harmful
- Verdict agreement: the percentage of alerts where Qevlar's verdict was kept, over the last four weeks
- Profile: which client the group belongs to (shown when you manage multiple profiles)
- Group created: when the group was first formed
Groups with very low agreement (below 50%) are not shown, as they are not yet useful for an automation decision.
You can search by group name and filter by verdict to focus the list.
Open a group
Select any row to open the group detail view. Here you can see:
- Group definition: the criteria Qevlar used to form the group, so you can judge whether it reflects a category that makes sense for your team.
- Matching alerts trend: a view of how many alerts matched this group over the last four weeks against your overall alert volume.
- Verdict agreement: the agreement percentage for the group, alongside the number of alerts where an analyst changed the verdict.
- Alert list: every alert in the group, with the alerts whose verdict was changed shown at the top. Select any alert to open its full investigation report in a new tab.
Tell us whether a group makes sense
On each group you can give feedback with a thumbs up or thumbs down. This tells us whether the group reflects a category that is meaningful to your team. In beta, this feedback directly shapes how Qevlar forms groups, so it is worth using.
Register interest in response actions
Today Automations shows you where you are ready to automate. It does not yet carry out any response. When response actions are available, you will be able to attach them to the groups you choose, for example closing a ticket, disabling a compromised account or notifying an affected user, either directly in Qevlar or by triggering your SOAR.
If you want early access when this lands, select Join the wait list.
Access through the API
The same group data is available through the Qevlar Public API as read only endpoints, so you can pull your automation candidates into your own reporting or feed them to your SOAR. Speak to your Qevlar contact for the API reference and credentials.
What Automations does and does not do
In this release
- Groups your similar alerts automatically, with no setup
- Shows verdict agreement per group over a rolling four week window
- Lets you drill into any group to see its definition, trend and the alerts where verdicts were changed
- Makes the same data available through the read only API
Not in this release
- No action is taken on your environment. Automations is read only.
- Response actions are not yet available. You can join the waiting list.
- You cannot yet create, merge or edit groups by hand. Groups form automatically.
Frequently asked questions
Does Automations take any action on my systems? No. This release is read only. It shows you where automation would be safe, but it does not carry out any response. Nothing happens to your environment.
Why can I not see any groups yet? Groups form automatically once Qevlar has investigated enough alerts and your analysts have reviewed enough of them for the figures to be meaningful. Newer accounts or lower volume alert types may take time to appear.
What does verdict agreement actually measure? It is the share of alerts in a group where your analysts kept Qevlar's verdict, over the last four weeks. It is a measure of how consistently Qevlar and your team reach the same conclusion for that type of alert.
Why is a group I care about showing low agreement? It means Qevlar and your analysts often reached different verdicts for that alert type recently. That is useful to know. It is usually a prompt to add context so Qevlar can align with your team, or to review the detection behind those alerts.
How often do the figures update? Groups and their agreement figures are recalculated regularly, and always reflect the last four weeks.
Can I change how alerts are grouped? Not in this release. Groups form automatically. Your thumbs up and thumbs down feedback helps us improve how groups are formed.
I manage several clients. Can I see them all at once? Not yet. Use the profile selector at the top of the page to switch between clients. A combined view across clients is not part of this release.
Giving feedback
Automations is an early beta and your input shapes it. Review the groups Qevlar has created, tell us with a thumbs up or thumbs down whether they reflect categories that make sense for your team, and share anything else through your usual Qevlar contact.