Investigation Guides are interactive playbooks that use machine learning to ask the right questions as an analyst would use. You can check the playbook questions and responses for each investigation to identify the root cause of a threat and reduce Mean Time To Detection (MTTD) and Mean Time To Response (MTTR).
Investigation Guides also list questions and responses based on the MITRE associated attack patterns to maximize the effectiveness of the SOC team.
identifies questions that are potentially significant to the investigation. This enables you in saving the manual effort in determining questions and reduces the time required to investigate a threat. This also helps to train new analysts on how to perform future investigations by looking at questions and responses. The responses are considered as key findings.
You can check a key finding and see supported key artifacts contributing to the finding. Key artifacts include processes, files, IP addresses, domain names, auto-start entries, network connections, user accounts, etc.
For example, select a key finding Running processes with suspicious name to check the number of suspicious processes and their associated files, and impacted endpoints associated with the suspicious process name. Also, select one of the processes and check if the process looks to be suspicious:
Prevalence - if the process has never been seen within the company and global intelligence database
Suspicious indicator – if the executable path includes a random name that is not commonly seen in Windows operating systems
Select the respective file for more details. You can see if this file is on any other endpoints in the environment. The Get other devices which have seen this file action give details if there are multiple endpoints impacted by the threat.
You can also check if the endpoint has communicated with malicious IP addresses, select an IP address and run these tasks:
Get events from SIEM containing this IP as destination — collects evidence details such as its severity, reputation, associated files and process, etc. from the other data source SIEM.
Get other devices which have NetFlow entries containing this IP – collects other endpoints impacted by this IP.
can automatically associate any similar cases based on the artifacts discovered and shows you if the threat has spread across the environment or if there is a bigger incident beyond what was initially discovered. When reviewing artifacts of an investigation, provides a graph view, summary view, and table view to visualize the attack type on endpoints.