Epic product release: Cases for unified alert investigations & response. Read more here.

Share

 

An epic product launch

We’re excited to announce that Cases, Radiant’s new way to manage related alerts and response actions in one place, is now live. This Epic launch is a major milestone in Radiant’s history, enhancing our ability to integrate directly into the analyst workflow.

Here’s why we built it

Fewer alerts don’t fix your workflow problem

AI SOC platforms that reduce false positives solve only 50% of the analyst problem.

SOC AI vendors have been obsessed with reducing noise for years, and most do a decent job at it. But here’s the thing: even with fewer alerts, your analysts are still stuck doing the same repetitive, draining work over and over.

The real problem in action

Here’s an incident you’ve probably seen a hundred times: an attacker moves laterally, triggering alerts in your EDR, firewall, and cloud security tools. Each alert lands in a separate queue. Your analyst investigates the first one, documents findings, and executes a response. Opens the second alert, realizes it’s related, starts over. Shift ends – now someone else has to pick it up and figure out where things left off.

By the time they’ve connected five related alerts, they’ve duplicated the same investigation five times. That workflow friction is exactly why we built Cases.

What Cases actually does

We’ve moved beyond treating alerts as isolated events to create a single workspace for threats.

  • Unified context — view your auto-generated case overview, including artifacts, entities, and a key details summary.
  • Assignment and ownership assign cases to analysts so teams know who’s working on what, ensure nothing gets missed, and avoid duplicate work.
  • Coordinated response actions — take coordinated response actions on artifacts within a case; all you need is to have your relevant action connectors onboarded.
  • On-hold status for dependenciesPause cases when waiting for other teams to take action, then unpause when ready.

Centralized audit trail — a centralized view of all response actions taken across cases, e.g., disable/enable user.

We’ve learned that while noise reduction matters, workflow chaos is what actually tanks analyst performance and burns people out.

If you’re interested in how to flip your workflows from frustrating to frictionless, speak to a member of our team.