Reading the graph

Connect the signals. Reveal the attack path.

Individual events rarely tell the whole story. Correlate activity across identities, endpoints, email, cloud, and network telemetry to uncover how an incident developed.

02Correlation

See the relationships behind the alerts.

Security investigations depend on understanding relationships, not simply reading individual alerts. Connect identity activity, endpoint behavior, email events, cloud activity, and network signals across time to determine whether separate events belong to the same incident. The platform provides the evidence and relationships. The investigation is yours.

signal domains
4
decoys seeded
on purpose
Correlation practice

Find the connection others might miss.

Identity, endpoint, email, cloud, and network events remain independent until you establish the relationship between them. Learn to move beyond individual alerts and identify the sequence, dependencies, and relationships that reveal an incident.

clickbox.io / correlation-engine
CASEGRAPHIDNIdentitysarah.chenEDREndpointSRV-DB-07MAILEmailconsent phishCLDCloudcustomers.piiNETNetwork45.86.x.x
Attack path
01Emailconsent phish
02Identitysarah.chen
03EndpointSRV-DB-07
04Cloudcustomers.pii
Signals joined
37
Sources
5
Deduplicated
94%
Time to graph
1.8s

Every edge reflects a real shared attribute — identity, device, session, network — not something wired by hand. Reading the graph, and deciding what's worth chasing, is yours.

See how a full case comes together.