Threat Center: triage detections and FIM in one queue
Threat Center is the operational heart of Dual-Strike XISEM for MSPs running multi-client fleets. It unifies COBRA² detections, file integrity (FIM) alerts, CVE correlation items, and integration health findings into a severity-sorted queue you can assign, investigate, and close.
Queue anatomy
• Severity — Critical → informational triage order
• Detection type — COBRA, FIM, CVE, integration
• Client org — MSP multi-tenant scope
• Asset / identity — Pivot to Asset modal
• Status — Open, investigating, remediated, closed
• PSA link — Ticket ID when outfeed enabled
FIM in Threat Center
File integrity monitoring arrives with agent 8.8.x platform support (preview noted separately). FIM alerts surface alongside traditional detections so technicians do not maintain a second queue.
Typical FIM scenarios:
• Unauthorized change to hosts or critical system files
• New scheduled task or service binary
• Policy-defined paths on servers and privileged workstations
Each FIM item carries before/after hash context and asset linkage — not a raw syslog line.
PSA integration loop
Supported PSA/RMM outfeeds include ConnectWise, Autotask, Halo, SuperOps, Ninja, Syncro, and others (see Integrations wiki). Workflow:
1. Detection fires in Threat Center
2. Auto or manual ticket creation with evidence snippet
3. Technician remediates in client environment
4. Ticket closed in PSA → XISEM status sync
Daily standup ritual (5 minutes)
1. Sort Critical + High open items across all clients
2. Assign owner per ticket
3. Pivot any “unknown asset” rows to Inventory
4. Note recurring rule names for COBRA tuning this week
Route: /threat-center
Upgrade path: Agent 8.7.0.17 GA today · FIM capabilities in 8.8 release notes when promoted
Mock data only — Northwind Traders demo tenant.


