L1
L1 Analyst
SOC · New York

Correlation ExplorerBrowse pivots — shared identities, files, destinations, and devices — that link multiple cases across the dataset. Use this to spot coordinated activity or repeat behavior the per-case view can't show.

Cross-case pivots derived from every case's correlation graph. Click a row to inspect the cluster.

Total pivotsPivot nodes that appear in 2+ cases.
3
Identity linksSame user (EMP-ID) across multiple cases.
1
File linksSame document or fingerprint across cases.
1
Destination linksSame external endpoint touched by multiple cases.
1
Cases in clustersDistinct cases that share at least one pivot.
6
Sources
Min cases2+

Shared pivots (3)Each row is a node that appears in 2 or more cases. Sources column shows which QRadar SIEM / Forcepoint DLP / Forcepoint Proxy systems observed it.

PivotTypeCasesSourcesSevLast activity
James Mitchell (EMP-4471)
Identity3
DLPProxySIEM
Critical2026-06-08 13:22 IST
mega.nz
Destination3
Proxy
Critical2026-06-08 13:22 IST
Servicing_Portfolio_Q2
File2
DLPSIEM
Critical2026-06-08 13:22 IST

Cluster detailPivot node in the center with each linked case orbiting it. Open any case to inspect its full correlation graph and evidence.

Pivot
James Mitchell (EMP-4471)
Same identity appears across multiple cases — possible coordinated insider activity or repeat behavior.
James Mitchell (EMP-4471)CASE-2026-0847James MitchellCASE-2026-0854James MitchellCASE-2026-0855James Mitchell
Linked cases (3)
  • CASE-2026-0847Critical
    Bulk borrower-NPI egress by departing Loan Operations Analyst
    James Mitchell · EMP-4471 · risk 94
    Open
  • CASE-2026-0854Medium
    AI external enrichment BLOCKED — IOC contained borrower PII
    James Mitchell · EMP-4471 · risk 38
    Open
  • CASE-2026-0855Low
    Detokenization request DENIED — L1 attempted Reveal on SSN
    James Mitchell · EMP-4471 · risk 22
    Open
Correlations are computed from the cases' shared graph nodes. AI output is advisory — analysts must validate before acting.