Analysts engaged in real-time monitoring of cybersecurity incidents must quickly and accurately respond to alerts generated by intrusion detection systems. The NIMBLE (Network Intrusion Management Benefiting from Learned Expertise) project explores visualization and defensible recommendations as analysis aids.