You can view characteristics and other details of a case by selecting it on the Cases page. From the main menu, select Investigate > Cases.
A number of characteristics exist for any case. The list below provides a summary of what these characteristics mean:
Status — Statuses are user-designated and can be helpful when determining and communicating the stage of an investigation. Statuses are considered open or closed.
Open statuses include the following:
Declared: When initially reviewing a case, determine whether the case shows something of concern or something that needs watching or further investigation. If so, choose Declared to recognize and validate the case.
Scoped: Assign Scoped status to a case after you have determined the full scope of the problem. For example, determine how many hosts or users are affected, or what data might have been compromised. Scoped indicates an additional level of investigation and validation has been done.
Contained: When you have taken steps to keep the problem from escalating while it's being resolved, assign the Contained status to a case. Examples of containment are cutting off the adversary C2 channels with firewall rules, disabling accounts, and turning off switch ports to compromised servers.
Closed statuses include the following:
Recovered: When you have completed whatever needs to be done to get fully back online and resolve the security problem, mark a case Recovered. Examples of actions during recovery are resetting compromised passwords or reimaging hosts.
Improved: Mark a case Improved after it is recovered and you are using the knowledge gathered during an investigation and its resolution to improve your process. Example of steps during an improved phase include doing a root cause analysis perhaps using searches and communicating the case and its resolution to stakeholders.
Created— Date the case was created.
Priority— Similarly to risks associated with alerts, a case's priority can be critical, high, medium, or low to provide an indication of the order in which the case should be examined as compared to other cases.
Severity— The severity designates the potential impact that the case could have on the organization if it is a true positive. It is calculated based on the risk of the alert.
Classification— Classification provides a mechanism for labeling the type of case and includes the following labels: testing/demonstration, unauthorized access, denial of service, malicious code, policy violation or poor practice, reconnaissance, phishing, and other.
Assigned to — The user responsible for investigating the case. Any user can be designated as the assignee. Assigning a case to one person helps avoid the situation of multiple people responding to the same issue and duplicating efforts unnecessarily.
Tabs at the bottom of the case details page provide the following information:
Events—Lets you view all events that are included in the case.
Alerts—Lists all alerts contained in the case. On this tab, you can add or remove alerts, or you can go to an alert's details page.
Revisions—Lists any changes that have been made to the case (for example, change in assignment).
Notes—Lets you add notes to the case and see any notes that were added previously.