Share

Alert triage is only half of the SOC picture. The other half is understanding when multiple alerts are telling the same story. 

Here’s what happened at Radiant a few weeks ago. A software company in a POC had several software engineers compiling executables on their machines and running them. The EDR flagged each one as a non-signed binary, but every alert looked different: a different user, a different machine, a different SHA-256 hash of the executable generated. Despite those differences, Radiant merged them into a single case, because it recognized the same underlying activity: a developer on Windows using Cursor to generate and execute a non-signed binary.

These weren’t separate problems. They were one single case. Analyzing those fragmented pieces has traditionally been the analyst’s job. They open the first alert, investigate, notice a familiar artifact, pull up the second alert, confirm the connection, and manually stitch the picture. It’s a slow, non-scalable process that makes it challenging to see the bigger picture.

Radiant’s automated alert grouping solves that problem. Besides being faster than a manual process, the AI is better at understanding the depth of the threat by processing large amounts of data. Radiant identifies when alerts share significant artifacts and automatically groups them into unified Cases, reducing the volume of individual alerts an analyst reviews and enabling smarter, more informed judgment.

Automated grouping is part of Radiant’s Case Intelligence capability, reducing manual workload while improving investigation depth and response.

Reducing noise one level beyond competitors

Most approaches to reducing noise operate at the alert level – suppression rules, tuning thresholds, and filtering. That’s Layer 1 of noise reduction. Radiant was built to solve exactly that problem with alert triage as the basis. Radiant reduces false positives by up to 98% by automatically triaging alerts.

However, triage alone doesn’t address fragmentation that causes additional noise. After Layer 1 runs, what remains is a set of malicious alerts requiring human oversight, judgment, and action. Many of those alerts describe the same underlying incident.

Automated alert grouping is Layer 2. This is when related malicious alerts are automatically grouped into cases, so that analysts have fewer alerts to act on, and the threat picture is complete.

Today, various competitors only focus on automating individual alert triage. Radiant’s automated alert grouping moves to the next level – understanding how alerts relate, building the investigation automatically, and documenting it.

Automation vs analyst control

Every malicious alert that completes triage enters the grouping engine and routes to one of three outcomes: create a new case, append to an existing case, or drop as a standalone. Alerts identified by AI as benign are handled separately. They don’t create cases, but they can be appended to open cases when a matching investigation already exists, ensuring that context isn’t lost.

While grouping is automated by default, analyst control remains high. Analysts can manually create cases and add or remove alerts from them.

Beyond that, control over automated grouping itself comes in three forms: opting in or out of automated grouping at the environment level, opting out of automated grouping for a specific case, and exclusion rules that flag specific artifacts as ineligible for grouping.

The Case Intelligence philosophy

When Radiant triages a malicious alert, it evaluates whether there are significantly shared artifacts and checks whether recent alerts share those same artifacts. If there is a match, Radiant automatically groups them into a case.

The question the system answers is: what’s wrong with this device or identity? For example, three alerts from three different tools involving the same user account belong in one case, regardless of alert type, vendor, or attack stage.

Two principles shape the AI grouping decision:

  1. Rarity. Entities that appear too frequently across alerts – common infrastructure, shared service accounts – are automatically filtered. The grouping engine has to distinguish between “these alerts both involve this service” and “these alerts both involve this specific rarely-seen IP.” Only the second is a meaningful grouping signal.
  2. Investigation logic as a grouping input. Two alerts that share rare entities but are investigated with completely different logic may not belong together

Grouping anchors transparently surfaced

The logic behind each grouping decision is transparently surfaced to analysts. The detailed view shows the grouping anchors: the specific rare entities (the actual artifacts) that justified putting these alerts together.

Every AI action and human action on the case is logged. The audit shows how the investigation grew – which alerts were added, when, and why. Analysts can see the AI’s reasoning at every step. They can disagree with it, and this feedback loop will tune the AI.

Your day-to-day with Case Intelligence

The analyst’s day-to-day life becomes less manual and more accurate. By the time an analyst opens a case, the correlation work is already done.

Automated alert grouping plays a significant role in positioning the analyst as an orchestrator. By delegating the heavy lifting of correlation and documentation to AI, the analyst’s workflow shifts toward the high-value tasks of making smarter judgments, orchestrating escalation, and executing the response. 

If you’re interested in learning more about automated alert grouping, speak to our sales team.

 

Finally, an AI that
triages all your alerts

A short demo can save your team 1000s of wasted hours

See what your SOC could look like:

AI SOC platform reducing analyst alert workload with automated log triage and threat escalation

See what your SOC could look like:

Radiant Security — AI SOC platform with integrated log management

Radiant Security is an unbounded AI SOC platform built to triage every alert that hits your SOC. It automates investigation across 100% of alert types and escalates only real threats to analysts, who can then respond in one click. Radiant’s integrated log management analyzes and stores all your security logs without the SIEM tax.

© Radiant Security, Inc. 2026.