Everything you need to run FactPattern.
Concise, security-specific reference for analysts, SOC leads, MSSPs, and security buyers. Every article is written for the SOC team that will actually rely on it.
What FactPattern is, what it isn't, and how to deploy it safely.
SIEM, EDR, identity, cloud and email connectors.
How alerts are scored, evidenced and routed.
Cases, timelines, notes, handoffs and decisions.
Entities, relationships and blast radius.
Recommended actions, approvals and the kill switch.
Executive and technical write-ups.
How evidence and review decisions are collected.
Per-client isolation for managed providers.
Owner, admin, SOC lead, analyst, viewer, auditor.
Read-only mode, retention, secrets, audit.
Keys, scopes, events and delivery history.
Common questions from analysts and buyers.