MITRE ATT&CK
MITRE ATT&CK maps Trisul's network detections onto the MITRE ATT&CK framework, so instead of just seeing "an alert fired" you see which known adversary technique it lines up with. There's also a companion timeline view that lays these mapped detections out chronologically, so you can see how an intrusion actually unfolded.
Click here → to view the detailed MITRE ATT&CK doc
For the chronological view specifically, see the MITRE ATT&CK Alert Timeline.