Alert Refinery

One of the world’s largest MDRs was overrun.

The problem

The detections work. The queue is the problem. At this volume, triage becomes a question of what gets skipped.

17.9B raw events crossed their customer telemetry. That produced more than 375,000 incidents in a single month. More than 1,000 analysts and engineers were already on staff to work them.

17.9B
Events across customer telemetry
375,000+
Incidents generated in one month
1,000+
Analysts and engineers on staff
56.9%
Incidents cleared as duplicate or benign

The approach

Alert Refinery labels the queue first. Duplicates and known-benign patterns get labeled with their evidence and set aside. Nothing is deleted. Every decision stays reviewable.

  1. Ingest live alerts. Connects straight to the existing pipeline. No detector changes, no new rules.
  2. Label statistically. Scores each alert against the wider population.
  3. Clear with evidence. Analysts open a queue of what’s left. Every clearance is auditable.

The result

56.9%
of incidents cleared as duplicate or benign, measured over one month of production volume.

This was already a highly-tuned environment. An unoptimized pipeline would likely see this number climb higher. And it scales to any MDR, no matter how big, with no detector retuning required.

Why this worked

They had already tried an AI SOC platform. It was too expensive to run at their scale and couldn’t keep up with the volume of alerts coming through. It never made it past the first eval.

What worked instead: a cheaper solution built for this scale, able to run on 375,000+ incidents a month without the infrastructure cost of a full AI SOC platform.

Contact us for a 30-day POV
on your own alert pipeline.

Book a Demo
Or reach us directly at hello@alphalevelsec.com  ·  alphalevel.ai