You can create an investigation for a threat detected by EDRF or you can also create a generic investigation and add evidence such as an endpoint, external domain, external IP, or endpoint snapshot.
To perform a threat-based investigation, navigate to the Monitoring dashboard, select a threat, and then click Actions → Create an Investigation.
When the investigation is created from the Monitoring dashboard for a threat, threat metadata is added automatically.
For device-based investigations, create an investigation from the Investigating Dashboard by clicking Create New for evidence such as an endpoint, external IP, or external domain.
For snapshot-based investigations, create an investigation from the Investigating dashboard by clicking Create New for evidence such as a device snapshot.
When the investigation is created from the Investigating dashboard, you need to add evidence details manually. For details, see Import threat related data into an existing investigation.
Note
EDRF retains the investigation case data for one year.
EDRF investigates the suspicious activity and identifies threat related data such as processes, files, network connections, etc. and shows it on graph view:
The data associated with a threat such as a file, process, IP, device, network connections, etc. are shown as artifacts.
For each investigation, EDRF creates investigation guides. These guides include questions and responses as an analyst would use. The responses are also called as key findings.
Artifacts that are part of responses or key findings are considered key artifacts.
During the investigation, if you find additional evidence such as endpoint, external domain, external IP, and device snapshot directly related to a threat, add it to an investigation. EDRF collects and processes that data based on the evidence type added. It correlates the data to check how artifacts are connected to each other and shown on the graph view. The investigation case expands as the investigation evolves.
For details about adding evidence to an existing investigation, see Add evidence to the investigation section in Import threat related data into an existing investigation.