Skip to content

GreyMatter

Integrate your Incident Register with GreyMatter. This integration automatically syncs GreyMatter incidents with real-time, asynchronous data flow.

  • Source: Managed Detection and Response (MDR)
  • Opened By: “Greymatter Integration”

The integration can be enabled directly from your Adversarial tenant via Settings > Integrations. The API Key Access needs to have read permissions for incidents.

GreyMatter integration configuration

Once the GreyMatter AI reviews and accepts a new incident, a record is created in Adversarial with Status = “New”. Occurred Date and Detected Date are brought over from GreyMatter.

GreyMatter StateAdversarial StatusNotes
NEWNot importedExcluded — incidents may disappear due to deduplication
IN_PROGRESSIn ProgressOccurred Date and Detected Date carried over
PENDING_CUSTOMERIn Progress or ReviewIn Progress by default; Review if the incident was previously resolved and re-opened
RESOLVEDReviewContained Date carried over if populated in GreyMatter
CLOSEDClosed

GreyMatter severity values do not influence the assigned severity value in Adversarial. Adversarial assigns severity one of two ways:

  1. Deterministic SEV-5 — if the incident is closed in GreyMatter with a close code indicating it was benign, it is imported as SEV-5 with the close note used as the severity reasoning.

    GreyMatter Close CodeAdversarial Severity
    CUSTOMER_FALSE_POSITIVESEV-5
    CUSTOMER_SECURITY_CONTROL_TESTINGSEV-5
    FALSE_POSITIVE_CREATE_TUNING_TICKETSEV-5
    FALSE_POSITIVE_NO_ESCALATIONSEV-5
    ANOMALOUS_SAFE_NO_ESCALATIONSEV-5
  2. AI or manual scoring — for all other incidents, no severity is assigned on import. Users can AI Score or assign severity manually.

GreyMatter FieldAdversarial FieldNotes
display_titleTitle
(multiple fields)DescriptionAssembled from incident details; updated if changed in GreyMatter
originator_created_atDetected DateFalls back to created_at
originator_created_atOccurred Date
escalated_atResponded Date
resolved_atContained DateSet when the incident enters RESOLVED; remains populated through CLOSED
closeCodeDescriptionResolution category; appended to the description on close
closeNoteDescriptionAnalyst’s resolution notes; appended to the description on close
(static)SourceAlways “Managed Detection and Response (MDR)”