Security Operations
Help Centre
❓
Your daily workflow at a glance
01
Monitor
Dashboard & incidents
β†’
02
Triage
Alerts & evidence
β†’
03
Investigate
AI analyst + timeline
β†’
04
Hunt
KQL queries
β†’
05
Remediate
Approve & execute
β†’
06
Verify
Response pipeline
β†’
07
Report
PDF reports & audit
1. Monitor the dashboard

The dashboard is your command centre. It shows system status, integration health, incident severity, MITRE tactics, vulnerability posture, Secure Score history, active exploitation and the latest threat intelligence - all computed from real data.

  • Incidents - open Incidents to see detections grouped by severity. Click one for the full detail page: devices, users, MITRE techniques, evidence timeline and the AI analysis.
  • Alerts - Alerts lists every raw alert with per-alert triage intelligence.
  • Devices - Devices shows risk, health and exposure across your fleet; the device detail page includes network ports and response actions.
2. Triage & investigate

Open an incident and use the Investigation page (or the incident detail's AI panel) to get an attack narrative: what happened, which devices/users are involved, which MITRE ATT&CK techniques match, and what the recommended response is - with honest confidence levels. Everything is derived from evidence; the platform never claims malicious activity without proof.

πŸ’‘ Tip: run Auto Remediate from the AI report or the incident detail page. Registry-related fixes are always denied and escalated to an Administrator; updates-only fixes are queued; non-admins see a clear reason in the popup.
3. Advanced Hunting (KQL)

Advanced Hunting gives you a full KQL editor with query history, saved hunts, charts and export. Use the πŸ€– AI Query Assistant to describe what you want to find in plain language and get a ready-to-run KQL query. Sentinel hunting (Microsoft Sentinel β†’ Advanced Hunting) works the same way with its own AI prompt box.

  • Save queries and turn them into scheduled detections or automation triggers.
  • One-click "Run in Advanced Hunting" moves a Sentinel query into the main hunting page.
4. Vulnerability management & recommendations

Vulnerabilities lists CVEs with CVSS, exploit status and affected devices. Recommendations adds a πŸ› οΈ How to fix guide under each recommendation so your team knows exactly what to change. From either page you can start a remediation workflow.

5. Remediation & approvals

Remediation lists every action with its status, mode and result. The ⚑ Auto Remediation panel lets you pick an action and a device with Dry Run preview before executing. Safety rules:

  • Registry changes are always blocked with a warning popup and escalated to an Administrator - ProPera never writes the registry.
  • Updates-only fixes proceed (queued via patch management) and notify you.
  • Non-admins are blocked with the reason shown in the popup.
  • Approvals (Automation β†’ Approvals) show exactly what will change: action, target device, method, risk score and MITRE technique - so approvers decide with full context.
6. Response Pipeline

The Response Pipeline ties the whole chain together for each incident: detect β†’ enrich β†’ MITRE map β†’ risk (CVSS + EPSS + exposure) β†’ CIS/NIST controls β†’ isolate β†’ investigate β†’ remediate β†’ verify β†’ Secure Score β†’ audit/report. Open an incident, review each stage, and click Advance on the active stage to move it forward. Every advance is gated by role and registry safety checks.

7. Secure Score & reports
  • Secure Score (Secure Score) - track your Microsoft Secure Score, its history and improvement actions; use Secure Now for governed one-click remediation.
  • Reports (Reports) - Executive, SOC, Vulnerability and Compliance reports, exportable as branded PDFs.
  • Compliance (Compliance) - continuous control monitoring mapped to live evidence (ISO 27001, NIST CSF, CIS v8, Essential Eight).
  • Audit (System Logs) - every user action, approval decision and configuration change is recorded and searchable.
Roles & permissions
RoleWhat you can do
AdministratorEverything, including executing remediation and granting endpoint-remediation consent.
Security AdministratorManage integrations, settings and users; approve and execute actions.
Automation AdministratorCreate/edit automation rules, execute remediation, manage approvals.
SOC AnalystTriage, investigate, run automation and approve actions.
Security AnalystInvestigate and hunt; request remediation.
AuditorView audit logs, reports and compliance.
ViewerRead-only access to dashboards, incidents and reports.

Not sure where to start? Run the πŸ€– AI Guided Tour or read the Getting Started guide.