Threat Center: triage detections and FIM in one queue
From COBRA² alert to closed PSA ticket — with audit trail intact.
Subtitle: From COBRA² alert to closed PSA ticket — with audit trail intact.
Threat Center is the operational heart of Dual-Strike XISEM for MSPs running multi-client fleets. It unifies COBRA² detections, file integrity (FIM) alerts, CVE correlation items, and integration health findings into a severity-sorted queue you can assign, investigate, and close.
Queue anatomy
Column / filterOperator use SeverityCritical → informational triage order Detection typeCOBRA, FIM, CVE, integration Client orgMSP multi-tenant scope Asset / identityPivot to Asset modal StatusOpen, investigating, remediated, closed PSA linkTicket ID when outfeed enabled
FIM in Threat Center
File integrity monitoring arrives with agent 8.8.x platform support (preview noted separately). FIM alerts surface alongside traditional detections so technicians do not maintain a second queue.
Typical FIM scenarios:
Unauthorized change to
hostsor critical system filesNew scheduled task or service binary
Policy-defined paths on servers and privileged workstations
Each FIM item carries before/after hash context and asset linkage — not a raw syslog line.
PSA integration loop
Supported PSA/RMM outfeeds include ConnectWise, Autotask, Halo, SuperOps, Ninja, Syncro, and others (see Integrations wiki). Workflow:
Detection fires in Threat Center
Auto or manual ticket creation with evidence snippet
Technician remediates in client environment
Ticket closed in PSA → XISEM status sync
Daily standup ritual (5 minutes)
Sort Critical + High open items across all clients
Assign owner per ticket
Pivot any “unknown asset” rows to Inventory
Note recurring rule names for COBRA tuning this week
Route: /threat-center
Upgrade path: Agent 8.7.0.17 GA today · FIM capabilities in 8.8 release notes when promoted
Mock data only — Northwind Traders demo tenant.

