What's open, what's stuck, what got closed
What your SOC is actively working on, and how fast you're closing things out. Open by severity, MTTR trend, source coverage, across every EDR and SIEM you run.
Why it matters
Open detections by severity, plus how many are currently under investigation. Leaders get the queue state at a glance.
Mean time to resolve over a rolling 30-day window. The trend metric that tells boards if the SOC is keeping pace.
Critical detections open past 48 hours. The single highest-signal 'is anything stuck?' number for a vCISO.
If CrowdStrike stops syncing, the numbers lie. A source-health strip flags any scanner that hasn't reported in >48h.
How it works
CrowdStrike is the primary source today. SentinelOne, Microsoft Sentinel, Splunk ES, and Sekoia plug in through the same shared writer, batched upsert, auto-resolve missing rows, refresh the stats table at sync end.
Every detection maps to one of 12 categories: malware, ransomware, phishing, suspicious_auth, impossible_travel, brute_force, exfiltration, policy_violation, host_compromise, lateral_movement, c2, behavioral_anomaly. Category segmentation drives routing.
Open Critical / Open High / Investigating / MTTR over 30 days. The four numbers a CEO scans in under 10 seconds. Backed by a single-row denormalized stats table that refreshes at the end of each sync.
The per-detection list is analyst territory. Hidden behind a toggle so the page opens on exec-level summary. Drill-in available when a leader needs to look into something specific.
Get started today
Whether you're the security lead holding it together in-house without a CISO, or a vCISO, consultant, or MSSP running client programs, Radius360 turns your stack into decisions your board and auditors trust.

We use strictly necessary cookies to make Radius360 work. With your consent, we'd also like to use analytics cookies to understand how visitors use our site so we can improve it. You can change your choice anytime. See our Privacy Policy.