CASE MEMORY

Recall related history. Keep the reasons visible.

Case Memory surfaces explainable historical context so analysts can reuse relevant investigation knowledge without treating similarity as security truth.

WHY MEMORY MATTERS

Historical context should not disappear between shifts.

Case Memory compares a selected case with eligible closed, resolved or explicitly synthetic history. The model is deterministic, visible and designed for analyst interpretation.

What it compares

Observed hashes, domains, IPs, filenames, hosts, users, process lineage, MITRE techniques and supported persistence context.

What it explains

Every returned score names the matched signals, missing context, prior verdict and a recommended handling note.

What it cannot prove

Similarity does not prove maliciousness, shared ownership, campaign identity or incident scope.

SYNTHETIC VERIFIED EXAMPLE

Meaningful history, visible reasons

The approved synthetic PowerShell scenario compares against prior synthetic case EVIDRYN-2026-0001.

72/100Similarity score
HighConfidence label
EVIDRYN-2026-0001Related synthetic case
Analyst reviewRequired interpretation

Matched synthetic signals

Hash evidence, process-lineage context, hostname and username overlap are shown as explicit reasons. These values are demonstration data, not customer telemetry.

ANALYST INTERPRETATION

Use similarity to ask better questions.

Confirm whether the overlap is meaningful in endpoint, identity, DNS, proxy and SIEM telemetry. Compare chronology and prior verdict context before escalation.

Historical context, not an automatic verdict

Case Memory does not close, escalate or merge cases. It never overrides the analyst's recorded decision.