The short version
- What's new: Throughline turns every Command Zero investigation into a living case. New alerts join existing investigations, the time window extends, every question re-runs, and the verdict gets re-examined. Automatically.
- Why it matters: Every other approach we've seen investigates an alert at a point in time, files the report, and moves on. Sophisticated attackers don't work that way. They hide their tactics for stealth and run persistent attacks over time. Real intrusions unfold over days and weeks, one boring alert at a time
- The proof: In testing across customer environments, Throughline cuts verdict volume by up to 41 percent. It also connected attack campaigns that the tools generating the alerts (such as CrowdStrike, Entra ID and AWS) had left as scattered, unrelated events. Early adopters discovered persistent attacks that were initially overlooked as low severity. They also gained complete visibility of threats across their stack.
- The bigger idea: Your best analyst never forgets a subject. Now your platform doesn't either.
The current wave of AI in the SOC has a flaw nobody puts on a slide: almost all of it takes photographs.
An alert fires. An AI agent picks it up, gathers context, renders a verdict, writes a tidy summary, and closes the ticket. This is efficient analysis done fast. But it can’t connect the dots and it delivers verdicts based on data on a point-in-time snapshot. The moment that verdict lands, it starts going stale.
Attackers don't produce photographs. They produce films. A scan on Tuesday. A failed exploit on Thursday. A successful login the following week from infrastructure you've never seen. Each frame looks unremarkable on its own. Any tool judging frames one at a time will call most of them benign, and it will be right about the frame and wrong about the film.
I've lived this from the analyst chair. You close a low-severity ticket on Monday knowing, somewhere in the back of your mind, that you might be closing the first chapter of something. But the queue is long and the alert is thin, so you move on. When chapter three arrives ten days later, nobody connects it to chapter one. The connection existed. The memory didn't.
That memory gap is what we built Throughline to close.

Introducing Throughline: Living SOC Investigations
Throughline changes the fundamental unit of work in the SOC. The unit is no longer the alert. It's the investigation, and the investigation stays alive.
When a new alert arrives, Command Zero examines its subjects (the users, machines, IPs, and domains an analyst would actually chase) and matches them against recent investigations. Then one of three things happens:
- The alert is a duplicate. We suppress it. No new work created.
- The alert is related but new. It joins the existing investigation. The investigation's time window extends to cover the new alert. Every planned question re-executes across the full window, against the data where it lives. Then our autonomous engine reconsiders the verdict with all evidence on the table.
- The alert is genuinely novel. It starts a fresh investigation, which becomes the anchor for whatever comes next.
Closed cases are not safe from this process, and that's the point. A resolved investigation reopens the moment new evidence ties back to it. The verdict you signed off on last week gets re-litigated by this week's facts.
The result is an investigation with a narrative arc. It can open as a low-interest note on routine reconnaissance, grow to medium interest when someone attempts exploitation, and escalate to high interest when a breach lands. One case, one evolving verdict, one throughline running through every alert, every domain, and every day of the attack.
No rule engine does this. Correlation rules match patterns someone predicted in advance. Throughline reasons about subjects the way a senior analyst does, and senior analysts don't need a rule to remember they've seen this machine before.
What happened when we pointed it at customer environments
We tested subject matching against a month of production alert data across three customer environments. The question was simple: how many verdicts would collapse into living investigations?
Customer | Alerts (30 days) | Verdict reduction, strict matching | Verdict reduction, broad matching |
|---|---|---|---|
Customer A | 306 | 27% | 41% |
Customer B | 129 | 15% | 38% |
Customer C | 1,373 | 18% | 37% |
The percentages are intriguing, yet technical details of these individual cases are better. Three sample anonymized cases below:
Case one: the campaign the alerting vendor missed. Five exploitation attempts hit a customer's public-facing PHP application over several days, probing the same well-known package-manager technique. Every attempt came from a different IP. Every attempt carried a different alert ID and a different incident ID from the tool that detected it. The vendor's own correlation, running on its own alerts, treated them as five unrelated events. Throughline matched them on the subjects that didn't change, the target machine and the URL under attack, and assembled one investigation telling one story: someone is working this server, and they are not giving up.
Case two: the phishing campaign with a map. A wave of phishing emails targeted office mailboxes at a customer, and the first-party tooling did manage to group the alerts this time. Throughline matched on an additional subject the grouping missed: the legitimate email-delivery service every message rode in on. With the full set threaded together, a pattern surfaced that no single alert showed. Each phish targeted a different office location. Four cities, one campaign, one deliberate adversary mapping the org chart. That's the kind of finding that changes a response from "reset a password" to "wake up the IR lead."
Case three: the compromise hiding in plain sight. Three alerts fired involving the same IP address and the same user account. Only one of the three carried an incident ID from the source tool. Investigated separately, the first alert was already high severity and the other two were easy to shrug off. Threaded together by Throughline, they pointed at something worse: either the original detection was confused, or the exploited account was actively in use. Both possibilities demand attention. Neither was visible one alert at a time.
An honest note about who benefits
Here's something you won't often read in a launch post: this feature will not reduce verdict counts for every team.
If your SOC fully keeps up with its queue, resolving investigations as fast as they arrive, Throughline won't hand you fewer verdicts. What it hands you is something we'd argue matters more: pattern awareness. The knowledge that these five alerts are one campaign. The escalation signal when a dormant case springs back to life. The verdict that corrects itself when the evidence changes.
And if your SOC is behind on its queue, and let's be honest, most are, you get both the awareness and the 15 to 41 percent reduction in verdicts your team must consider.
Glass box, as always
Everything Throughline does is inspectable, because a living investigation you can't audit is just a black box with a pulse. When an alert joins an investigation, you see which subjects matched. When the window extends and questions re-run, you see every question and every answer. When the verdict changes, you see exactly what changed it. If a user has started their review of a case, Throughline stands down; we never rewrite a verdict out from under a human.
This is the same principle that runs through everything we build. The AI does the work. You can check the work. Both halves are non-negotiable.
The case is never really closed
The industry spent the last two years teaching AI to triage alerts faster. Worthy work. But triage speed doesn't fix the deeper flaw, which is that our tools have no memory and attackers have all the patience in the world.
Throughline gives your investigations memory. It remembers every subject and connects every chapter. When the story changes, so does the conclusion. Living investigations, running on the platform your analysts already trust.
The slow, patient, low-and-slow attack has been the industry's blind spot for twenty-five years. It just lost its best hiding place: time.
Throughline is rolling out to Command Zero customers now. Book a demo and bring your messiest month of alerts. We'll show you the throughline.



