The case moves, but ownership of the next step is unclear.
Assignment, owner and next action are visible in the same case.
HODHODIncident, case and response operations management
Every incident needs a clear path. Hodhod keeps triage, ownership, response time, actions and evidence in one case, from the first signal to the recorded outcome.
Source: monitoring alert · Sample environment
Alert reference and asset information
Proposed priority recorded for expert review.
A closer look
The story behind Hodhod
O hoopoe of the morning breeze, I send you to ShebaSee from where, and to where, I send you
Hafez, Ghazal 90 ↗
In the story of Solomon and the Queen of Sheba, the hoopoe returns with news from a distant land. It then carries Solomon’s letter and is asked to observe the response. Delivering a message is the start of a connection; its value lies in the response that opens the way to dialogue and decisions.
A signal is noticed. Information reaches the team. Between receiving it and finding an answer, there is an essential journey: understanding the issue, getting it to the right person, and staying with it until the outcome is clear. The hoopoe inspires this connection between information, action, and follow-through.
In Hodhod, every request and incident has a clear path: its information and evidence stay together, ownership and the next step are clear, and progress is tracked until the outcome is recorded. Messages stay in view as they move between people, and every response becomes a lesson for a better response next time.
Hear the news. Coordinate the response. Follow through to the outcome.The story of Solomon and the hoopoe; Surah An-Naml, verses 22–44 ↗Hodhod at a glance
Hodhod is Faraconesh’s request and incident management system. It unifies information, roles, SLAs, actions, evidence and case history in a traceable, auditable flow.
When do you need Hodhod?
Assignment, owner and next action are visible in the same case.
SLA status and stalled stages become operational insight.
Handling information and history stay with the case.
CERT and CSIRT, SOCs, information security, network operations and organizational service teams in banks, operators, critical infrastructure and organizations with operational cases.
Response lifecycle
Handling is configured to the organization’s approved process. This cycle illustrates the main control points in incident management.
Register a request, incident or alert
Initial review and information completion
Appropriate category, severity and SLA
Assignment and evidence collection
Playbook and response coordination
Oversight or escalation when needed
Record and evaluate the outcome
Report and retain response experience
One case, all incident context
This case is fictional; access and fields are configured for your organizational process.
Key capabilities
States, transitions, authorized roles and mandatory stage information are configured within the deployment scope.
Defined processes; controlled transitionsSee the current owner, response time, stalled cases and delay risks to clarify the next step.
Assignment, follow-up and escalationActions are recorded with owners and results. In CERT, playbooks help organize the response.
From instructions to action outcomesFiles, log references and technical notes remain alongside status changes and decisions so handling can be reconstructed.
Who, when and with which evidenceCase status, team performance, SLAs and time spent in stages become usable reports.
From one case to process bottlenecksOutcomes, effective actions and case reports are retained; Intelligence Pack adds knowledge and similar-incident retrieval.
Every response informs the nextEditions and add-on
Desk handles general requests and cases; CERT supports specialist incident response. Intelligence Pack is available for both.
Selecting an edition highlights its details.
| Comparison criterion | Hodhod Desk | Hodhod CERT |
|---|---|---|
| Primary need | General request and case management | Security incident response operations management |
| Operating team | Service, IT and organizational operations teams | CERT, CSIRT, SOC and incident response teams |
| Starting point | A request, form or actionable case | A security incident, alert or investigation referral |
| Workflow | States, roles and assignments aligned to organizational processes | Specialist incident lifecycle, severity, oversight and escalation |
| Action and handling | Record and track actions, owners and results | Response actions, playbooks and specialist investigation coordination |
| Records and evidence | Case records, attachments and activity history | Decision-linked evidence and an auditable timeline |
| Output | A handled request and process performance report | A managed incident, post-incident report and lessons learned |
Intelligence alongside the expert
Intelligence Pack turns authorized organizational history and knowledge into daily support, reducing reading and helping find relevant context and prepare decisions.
Suggestions can be approved, edited or rejected. Sensitive decisions and final actions remain with authorized users.
“Access outside the usual pattern has been reported for a service. The reason and impact remain unclear; specialist investigation is required.”
Compare the service access report against approved permissions and record the findings in the case.
Case description + sample access review guide
Sensitive decisions and actions require an authorized user’s approval.
Hodhod in practice
A detection alert becomes a case with triage, ownership, SLA and action.
The next analyst sees the timeline, actions and decisions; the intelligent add-on can prepare a handover summary.
Specialists, service owners and reviewers collaborate in one case; comments, assignments and action outcomes are recorded.
Track requests from registration to response using forms, roles, workflows and SLAs aligned to your processes.
Deployment and integration
Hodhod deploys independently in organizational infrastructure or a private environment. Forms, workflows, roles and reports are configured to local operational needs.
Environment differences can shape processes and access levels; the product edition follows the type of problem.
Forms, categories, workflows and roles are configured for requests and incidents involving IT users, services and systems.
IT and OM are operational profiles; the edition choice is between Desk and CERT.
Between detection and action
Integration with SIEM, detection systems, Jira, knowledge sources and other tools uses APIs and connectors suited to the organizational architecture.
Integrations are complementary; each connector’s scope and readiness are determined during project review.
Before choosing
No. Hodhod Desk manages general requests and cases. Hodhod CERT provides a specialist security incident lifecycle for CERT, CSIRT, SOC and response teams.
Next step
Let’s review your challenge, current process and team needs to choose Desk or CERT and define the intelligent add-on’s scope.