All In The Lab Sessions

How the Red Canary Zscaler Integration Improves Threat Investigations

cybersecurity Red Canary

Security teams do not struggle because they lack alerts. They struggle because critical context is split across tools, and blocked traffic often gets treated as resolved before anyone understands what really happened. In Alchemy’s recent live demo with Red Canary, the point was simple: adding ZIA data to threat investigations gives analysts a better path from signal to decision. For leaders trying to cut manual pivoting and improve response quality, that matters more than another dashboard.

Why blocked traffic still needs investigation

One of the clearest ideas from the session was that blocked does not always mean safe. A blocked URL, file, or connection may stop one action, but it does not automatically explain the source, the user involved, the endpoint touched, or what policy change should come next. That is where blocked traffic context becomes useful. When analysts can see ZIA data inside the same investigation flow, they get a more complete view of what happened and what still needs attention.

How Zscaler ZIA data changes the investigation path

The Red Canary Zscaler integration brings web activity into the investigation so teams can connect events across users, endpoints, identity, and response decisions in one place. In the demo, Red Canary also showed why the threat timeline matters. Instead of forcing analysts to sift through thousands of records, the timeline highlights the records that matter and explains them in context. That matters because security teams are still paying a tax every time they pivot between consoles to answer basic questions during triage.

The session also showed how response actions extend the value of that context. Teams can isolate endpoints, suspend identities, or push known bad IPs, domains, URLs, and file hashes into policy so the same issue is less likely to repeat. If you want to see that flow in action, watch the recording here: Red Canary + Zscaler live demo.

What stood out in the Red Canary approach

The demo also gave a clear view into how Red Canary thinks about threat investigations at scale. Their team described centralized detections, shared detector coverage, and threat hunting that turns what one customer sees into coverage others can benefit from as well. They also shared a concrete example of alert reduction, showing a sample environment with roughly 2,500 alerts that narrowed to 63 actual threats needing attention. That is the kind of operating improvement buyers care about because it gives the team more time for higher-value work.

At Alchemy, we see this less as a feature discussion and more as an operating question. Security leaders need to know where context is missing, where analysts lose time, and what changes will reduce risk without adding more friction. This session is useful because it shows those questions in a real workflow, not in a static slide. If that is the issue your team is working through, watch the recording and use it as a starting point for a deeper conversation with an Alchemy advisor.

Take Action: Know Your Weaknesses Before Attackers Do

Is your organization’s digital footprint exposing risks you can’t see? Alchemy’s Attack Surface Assessment maps vulnerabilities across your cloud, network, and endpoints, then delivers clear recommendations and a structured action plan to close security gaps, strengthen your Zero Trust posture, and prepare for audits with confidence. Book your Attack Surface Assessment today and take control of your exposure before attackers find it first.

Take Action Today

More Sessions