> For the complete documentation index, see [llms.txt](https://docs.threatdefence.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.threatdefence.com/soc-analyst-guide/platform-navigation.md).

# Platform Navigation

## Dashboards

The **Security Detections** dashboard is the main triage hub, consolidating alerts from all data sources. Analysts use it to review, prioritize, and manage detections across the environment.

Other dashboards provide **forensic visibility into specific data sources**. These are useful not only for detecting breaches but also for validating security controls, proving systems are uncompromised, and supporting incident response.

### Dashboards Menu

* **Customer Portal** – High-level reporting and summaries.
* **My SOC** – Preconfigured views for common SOC needs, such as tracking emerging threats and SOC statistics.
* **Endpoint** – Data from DFIR endpoint agents (Windows/Mac/Linux), including system event logs, network connections, logons, and benchmarks (e.g., CIS checks).
* **Cloud** – Audit and assessment events from cloud environments like O365, AWS, and GCP.
* **Network** – Data from ThreatDefence NDR sensors, including flow visibility and network intrusion detections.

<figure><img src="https://4191868192-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOlFHF8fl339QOw3Og8L7%2Fuploads%2Fgit-blob-3962f13cb0bc8820febf0ff691a2778efb640689%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

***

## Navigation & Filtering

Dashboards include filters and search controls to refine alerts and focus investigations.

### Dashboard Filters and Views

* **Time Range** – Defaults to *Last 24 hours*. Adjust via **Show dates** for custom ranges (e.g., last 30 days).

  ![](https://threatdefence.gitbook.io/threatdefence-docs/~gitbook/image?url=https%3A%2F%2F4191868192-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FOlFHF8fl339QOw3Og8L7%252Fuploads%252FKZJIqcZUD9nXxwokV5ms%252Fimage.png%3Falt%3Dmedia%26token%3D3c942aa6-53a0-438c-82b0-15103ec69cc8\&width=300\&dpr=4\&quality=100\&sign=8948c36c\&sv=2)
* **Menu Filters** – Predefined options for narrowing down alerts, including:

  * Alert Status (Open, Closed, In Progress)
  * Tenant (e.g., threatdefence, tdsoc, acme)
  * Data Source (e.g., Keycloak, O365, NDR, Dark Web, Mailgun, google\_workspace.drive)
  * Technique (e.g., Indicator, Exploit Public-Facing, Valid Accounts)
  * AI Outcome, MSP, Severity, Tags

  ![](https://threatdefence.gitbook.io/threatdefence-docs/~gitbook/image?url=https%3A%2F%2F4191868192-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FOlFHF8fl339QOw3Og8L7%252Fuploads%252FEZ0y1y0HQcXUo9NjJaSN%252Fimage.png%3Falt%3Dmedia%26token%3D82d15649-4468-48d1-9b73-164d1de9c16f\&width=768\&dpr=4\&quality=100\&sign=7243b38d\&sv=2)
* **Manual Filters** – Click on visualizations to filter interactively. For complex queries or automation, use text-based Lucene queries.

  ![](https://threatdefence.gitbook.io/threatdefence-docs/~gitbook/image?url=https%3A%2F%2F4191868192-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FOlFHF8fl339QOw3Og8L7%252Fuploads%252F8wAW0NP0iqR4pSnG8cSo%252Fimage.png%3Falt%3Dmedia%26token%3D90884a45-7f34-435d-afde-b0b69f3d8411\&width=768\&dpr=4\&quality=100\&sign=7ed5b758\&sv=2)

***

## Key Sections

* **Security Detections Table** – Lists alerts by name and severity. Analysts can sort, filter, and drill into specific alerts.

  ![](https://threatdefence.gitbook.io/threatdefence-docs/~gitbook/image?url=https%3A%2F%2F4191868192-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FOlFHF8fl339QOw3Og8L7%252Fuploads%252FTDJoih4HF4xpOCSp5DDW%252Fimage.png%3Falt%3Dmedia%26token%3D02a09555-d42b-48c0-a310-b90093fbd0a0\&width=768\&dpr=4\&quality=100\&sign=be2f06e5\&sv=2)
* **Charts & Aggregations** – Visual breakdowns including:
  * Anomalies (e.g., open high-risk alerts)
  * Detection Types (spikes, informational, indicators)
  * Techniques (e.g., LOGIN\_ERROR, persistence)
  * Impacted Sites/Tenants
  * Indicators (IPs, domains, geo locations)
  * Detection Sources by Severity
  * **Top 5 Entities** – Most frequent hosts or users
* **Detections Feed** – A paginated log of all alerts, expandable for full context, interactions, and investigation options.

***

This structured navigation lets analysts move quickly from **high-level monitoring** to **detailed investigations**, reducing response times and improving situational awareness.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.threatdefence.com/soc-analyst-guide/platform-navigation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
