Watch this on-demand product training video and explore how Lumu Insights can improve your daily cybersecurity operations. This session covers dashboards, labels, personalizations, best practices, and more.
This product training video, presented by Nikki Ibarra, Product Marketing Director at Lumu, introduces the updated incident view within the Lumu portal. The portal focuses on improving operability and information accessibility for cybersecurity teams. The presenter highlights how the new interface organizes data into specific tabs—Activity, Highlights, Threat Intelligence, and MITRE ATT&CK Matrix—to provide clear context regarding threat movement and endpoint impact. This structure allows users to filter incidents by type, such as malware or phishing, and manage them directly through actions like closing, muting, or commenting.
Among the new additions to the Lumu portal is the Operation Timeline, which promotes team collaboration by logging actions taken on an incident and enabling shared comments. The portal also emphasizes data portability, offering various export options such as STIX reports and CSV files of affected endpoints and contact data. Additionally, the presentation explains how Lumu Defender can automate responses through APIs and out-of-the-box integrations, allowing real-time interventions to prevent threats from escalating within an organization.
Key Takeaways
- The new view is designed to enhance the operability and accessibility of key cybersecurity information for all users.
- The four tabs (Activity, Highlights, Threat Intelligence, MITRE ATT&CK) provide a structured and intentional context for each detected incident.
- Operation Timeline is a collaborative feature that allows team members to track actions, status, and leave comments on incidents.
- Incident data, including IOCs, affected endpoints, and STIX reports, can be exported to CSV or other formats for external record-keeping.
- Integration with Lumu Defender enables automated, real-time responses and the blocking of malicious contacts by leveraging existing cybersecurity investments.
Frequently Asked Questions
What is the purpose of the Highlights tab in the new incident view?
It visualizes how a threat moves within the organization, providing context on timelines and contact frequency between endpoints and IoCs.
How does the Operation Timeline help cybersecurity teams?
It facilitates collaboration by showing when an incident was created, who has read it, and allowing team members to log actions or comments.
Can users view specific technical data for an affected endpoint?
Yes. By clicking see more details on an asset, users can access packet data and technical collector metadata.
What type of information is found in the Threat Intelligence tab?
It includes details on malware families, related IoCs, hash files, external resources, and a specific incident response playbook.
How can organizations automate their response to detected incidents?
They can use Lumu Defender to integrate with their existing security stack via APIs or preconfigured integrations that enable real-time blocking.



