Cases

The investigation workspace: timeline, tasks, artifacts, war room, attachments, closure.

A case with its timeline, evidence table, status panel, linked alerts and tasks.
A case with its timeline, evidence table, status panel, linked alerts and tasks.

Creating a case

Cases are created by escalating an alert or a correlation, from a playbook's escalate action, or by hand from Cases › New. Escalation carries over the alert's notes, events, hosts, indicators and any staged responses.

Categories

Each case has a category, chosen at creation from the list in Settings › Case categories. A category carries a write-up structure and a task template, so a "credential theft" case opens with the tasks a credential theft needs. See Case categories.

Panels

PanelWhat it holds
TimelineAlerts, events, notes, actions and status changes in order. Live toggle for ongoing incidents.
TasksThe checklist from the category template plus anything you add. The case cannot close over an open task.
EvidenceFields and values gathered from the alerts and by hand, with provenance.
ArtifactsIndicators found in the case, checked against everything else the organization has seen. A hit elsewhere is shown here.
War roomConversation among the people on the case, with @-mentions and roles (owner, responder, observer).
AttachmentsImages and files, for when the evidence needs a picture.
Linked alertsEvery alert in the case, with one click back to each.
StatusSeverity, state (open, contained, resolved), owner, SLA.

Closing

Set the state to resolved, complete or waive every task with a reason, choose a closing disposition and write the closing note. Closing is audited and freezes the case; it can be reopened by a lead.

Reporting

From a closed case, Generate report starts a report from the category's template with the case attached. See Reports.