Blog

Short notes about detection work and security operations.

Notes, lessons learned, and technical write-ups from hands-on security work.

April 18, 20264 min read

Reducing Manual Triage With Enrichment

The bottleneck was not the monitoring platform itself. The real issue was using tools that could not route incidents cleanly and lacked the metadata needed for ownership, which forced manual incident creation until enrichment made automation possible.

AutomationMetadataIncident Routing