One incident per attack. Finally.
One alert rarely tells the full story. That’s why we’re introducing Incidents: related malicious activity is now automatically correlated into a single investigation, prioritized using the full context of your environment. Result: one incident per attack.
Inside every incident: correlated alerts, contextual severity scoring, attack narrative, impacted users, and devices
For the builders: The Investigations API now returns an incident_id, a purely additive field that shows when an alert belongs to a wider incident.
- A new
GET /v2/incidentendpoint returns full incident details in JSON. - A new
GET /v2/incidents/{incident_id}/htmlendpoint returns an HTML report for a specific incident, ready to embed in your existing workflows
Details in the help center.
Context that builds itself over time
Good investigations depend on relevant, up-to-date context. Qevlar now proactively generates context for you by detecting recurring patterns across closed investigations and surfacing them as review-ready context candidates.
Once approved by admins, future investigations automatically use this knowledge. So your context stays in sync with what’s happening in your environment.
You can find AI-generated context candidates in the Organizational Context tab or directly inside investigations
Result: higher-quality investigations aligned with relevant, up-to-date context.
Available in the UI and via APIs for admin users. See more details in the help center.
Validate context before it changes investigations
Every context item impacts how Qevlar investigates alerts. A context item that's too broad can unintentionally change investigation verdicts. Before deploying a new one, test it against the last five days of real alerts to see exactly which verdicts would change and why. Catch unintended consequences before they reach production and deploy context with confidence.
The test runs in about 10 minutes. Review the results, then approve, edit, or discard the draft.