What it compares
Observed hashes, domains, IPs, filenames, hosts, users, process lineage, MITRE techniques and supported persistence context.
CASE MEMORY
Case Memory surfaces explainable historical context so analysts can reuse relevant investigation knowledge without treating similarity as security truth.
WHY MEMORY MATTERS
Case Memory compares a selected case with eligible closed, resolved or explicitly synthetic history. The model is deterministic, visible and designed for analyst interpretation.
Observed hashes, domains, IPs, filenames, hosts, users, process lineage, MITRE techniques and supported persistence context.
Every returned score names the matched signals, missing context, prior verdict and a recommended handling note.
Similarity does not prove maliciousness, shared ownership, campaign identity or incident scope.
SYNTHETIC VERIFIED EXAMPLE
The approved synthetic PowerShell scenario compares against prior synthetic case EVIDRYN-2026-0001.
Hash evidence, process-lineage context, hostname and username overlap are shown as explicit reasons. These values are demonstration data, not customer telemetry.
ANALYST INTERPRETATION
Confirm whether the overlap is meaningful in endpoint, identity, DNS, proxy and SIEM telemetry. Compare chronology and prior verdict context before escalation.
Case Memory does not close, escalate or merge cases. It never overrides the analyst's recorded decision.