Security alerts are rarely completely new. A security analyst might see dozens of failed-login alerts, suspicious IP addresses, unusual data transfers, or large file movements. Many of these incidents resemble cases the team has already investigated. The problem is that a typical LLM starts each analysis from scratch. It can understand the alert in front of it, but it doesn't automatically know how the security team handled a similar incident last week. I built ThreatMemory to explor...