Case Workflow
- Upload Evidence
- Review Processing Status
- Review Threat Detections
- Review Windows Artifacts:
Inspect parsed artifact data directly when you need file-level, host-level, or source-specific context beyond detections.
- Review the Timeline
- Export Data
Add evidence containers or individual artifact files to the case. Supported Windows artifacts include EVTX event logs, Registry hives, MFT data, runtime process data, and runtime network connection data.
Track planning, discovery, processing, maintenance, and finishing tasks. Resolve failed tasks, approve pending work when auto discovery is disabled, or ignore evidence that should not be processed.
Use the Threat Detections page to review Sigma matches, filter by evidence source, and drill into detections by rule, technique, or source system.
Use the timeline to correlate events, detections, file activity, and artifact records in chronological order.
Export processed detections and case data for reporting, handoff, or follow-up analysis.