A structured form for sharing context with Qevlar
Your analysts know things Qevlar doesn't. Now they can share them properly: internal registries, legitimate service accounts, weird emails that are actually fine.
Until now, they typed free text and hoped the AI understood. Now it's a structured form: pick the observable, set the scope, say if it's legitimate, and explain why. Qevlar gets it right.
All analysts can submit new context from an investigation or from the context page. New context items go to your admin for approval before they're applied. How this work
Also available via APIs. More on how to share context with Qevlar here
Turn analyst feedback into reusable context
Before: analysts disagreed with a verdict, wrote why in free text, and hoped Qevlar understood what they meant. Sometimes it did. Sometimes the important detail got lost.
Now, when analysts disagree with a verdict, they can turn that feedback directly into a context item. They explain the reasoning, Qevlar drafts the context automatically, and the analyst can quickly review or tweak it before submitting.
So next time a similar alert appears, Qevlar reliably uses the analyst's knowledge.
Available in the UI.
Pull historical context from ITSM into your investigations
Your SOC's closed-case history is finally working for you. Qevlar now pulls relevant past ServiceNow cases directly into live investigations, using them as evidence to refine verdicts, and letting our agents look up the prior history of any user or device in an alert.
The result: more accurate decisions, fewer inconclusive outcomes, and less time spent handholding the AI. Head to the Integration Center to set it up. Here's how
Investigation Reasoning tab redesigned
Findings now lead each step, with malicious and suspicious findings highlighted. You also get more transparency into investigation speed and any newly discovered observables. Less scrolling, faster verdict review.
Available in the UI.
New Connectors:
- Splunk — agentic integration that adapts to each customer's data setup, so investigations can run across any index in your environment.
- Mimecast — expands coverage of email security telemetry.