The Storytime module processes alerts from Indicators of Compromise (IOC) and Exploit Guard (EXG) that have an associated auto-triage package. Storytime analyses the auto-triage artifacts, generates a chapter file and saves it to the database. If two or three IOC or EXG alerts are generated within quick succession, Storytime generates multiple chapter files and saves them to the database. This provides the administrator with an auto-triage collection where they can investigate each individual alert and the relationship between the alerts. If the Endpoint Security (HX) Server is integrated with Helix, it streams the chapter file to Helix.
To view a graphical representation of the triage data, use the Storytime Visualization. Storytime focuses on the most relevant data from the auto-triage on the alert and shows the critical path to the event node that triggered the detection. The visualization ensures that Endpoint Security (HX) users can quickly analyze alerts and take preventive and corrective action. For more information, see Storytime System Module.