L1
L1 Analyst
SOC · New York

Correlation ExplorerBrowse pivots — shared identities, files, destinations, and devices — that link multiple cases across the dataset. Use this to spot coordinated activity or repeat behavior the per-case view can't show.

Cross-case pivots derived from every case's correlation graph. Click a row to inspect the cluster.

Total pivotsPivot nodes that appear in 2+ cases.
3
Identity linksSame user (EMP-ID) across multiple cases.
1
File linksSame document or fingerprint across cases.
1
Destination linksSame external endpoint touched by multiple cases.
1
Cases in clustersDistinct cases that share at least one pivot.
5
Sources
Min cases2+

Shared pivots (3)Each row is a node that appears in 2 or more cases. Sources column shows which QRadar SIEM / Forcepoint DLP / Forcepoint Proxy systems observed it.

PivotTypeCasesSourcesSevLast activity
mega.nz
Destination3
Proxy
Critical2026-06-08 13:22 IST
James Mitchell (EMP-4471)
Identity2
DLPProxySIEM
Critical2026-06-08 13:22 IST
Servicing_Portfolio_Q2
File2
DLPSIEM
Critical2026-06-08 13:22 IST

Cluster detailPivot node in the center with each linked case orbiting it. Open any case to inspect its full correlation graph and evidence.

Pivot
mega.nz
Same external destination touched by multiple cases — potential common exfiltration channel.
mega.nzCASE-2026-0847James MitchellCASE-2026-0849Thomas MüllerCASE-2026-0852Lucas Fernandez
Linked cases (3)
  • CASE-2026-0847Critical
    Bulk borrower-NPI egress by departing Loan Operations Analyst
    James Mitchell · EMP-4471 · risk 94
    Open
  • CASE-2026-0849Medium
    Developer hit paste-site + cross-team repo access
    Thomas Müller · EMP-3380 · risk 56
    Open
  • CASE-2026-0852Medium
    Contractor email to personal — small spreadsheet (no NPI)
    Lucas Fernandez · EMP-9921 · risk 41
    Open
Correlations are computed from the cases' shared graph nodes. AI output is advisory — analysts must validate before acting.