MSSP SOC - How to ByPass "Cases"

Hi @austinsonger!

Thank you for your feedback. It is very valuable to us and it is always taken into consideration. This PR enabled the Jira, ServiceNow, and IBM Resilient actions for detections. This means that you can create an issue when an alert is being fired.

About cases, we are working in this direction to provide a unified workflow between cases and detections. Specifically, this PR will allow you to manually attach an alert to a case and sync cases statuses with alerts statuses. We are working on the automatic version to be available in the future.

Thank you for your feedback again!

Best,
Christos

1 Like