As you work on a case it is important to document your findings. This allows for easy collaboration if more than one analyst is working on a case, if the case has to be escalated to a more senior analyst, and so on. Case management allows you to add more detail and provide context about each action you took on the Notes tab. Otherwise, you would have to use a different tool to store this information, which could lead to important information being lost. You can associate a note with an event, artifact, or alert, or you can add a more general comment.
Case management automatically keeps a record of all changes to a case on the History tab. Such changes include the addition of new events or alerts, or user activity. You cannot edit or delete case history information, which ensures that an accurate record of the work done by each SOC analyst is available. You can search and filter the table and export it in CSV or JSON format.
This workflow includes the following tasks:
Create a case from the Alerts or Cases page. For more information, see Creating a case.
Investigate the cause of the alerts. For more information, see Understanding the cause and impact of an attack.
Document your findings. For more information, see Documenting and tracking case activity.