Baseline signals

Rarity hints per host and per organization, shown on the alert page.

What they are

The platform keeps short baselines of what is common per host and per organization: which executables run, which parent-child process pairs occur, which destinations are contacted, which users log on where. When an event is rare against that baseline, the alert page shows a baseline panel saying so, with the counts behind the statement.

How to use them

Baseline signals give the analyst context at the moment of triage. Read them alongside the rule that fired: a rare parent-child pair or a first-seen destination often decides whether a match deserves a closer look. The counts are shown with every signal, so the reasoning is always visible.

Retention

Baselines cover the last few weeks and roll forward. A brand-new host builds its baseline as it runs, and the panel shows when that is still in progress.