Creating a case
Cases are created by escalating an alert or a correlation, from a playbook's escalate action, or by hand from Cases › New. Escalation carries over the alert's notes, events, hosts, indicators and any staged responses.
Categories
Each case has a category, chosen at creation from the list in Settings › Case categories. A category carries a write-up structure and a task template, so a "credential theft" case opens with the tasks a credential theft needs. See Case categories.
Panels
| Panel | What it holds |
|---|---|
| Timeline | Alerts, events, notes, actions and status changes in order. Live toggle for ongoing incidents. |
| Tasks | The checklist from the category template plus anything you add. The case cannot close over an open task. |
| Evidence | Fields and values gathered from the alerts and by hand, with provenance. |
| Artifacts | Indicators found in the case, checked against everything else the organization has seen. A hit elsewhere is shown here. |
| War room | Conversation among the people on the case, with @-mentions and roles (owner, responder, observer). |
| Attachments | Images and files, for when the evidence needs a picture. |
| Linked alerts | Every alert in the case, with one click back to each. |
| Status | Severity, state (open, contained, resolved), owner, SLA. |
Closing
Set the state to resolved, complete or waive every task with a reason, choose a closing disposition and write the closing note. Closing is audited and freezes the case; it can be reopened by a lead.
Reporting
From a closed case, Generate report starts a report from the category's template with the case attached. See Reports.