Investigation management journey

Supported in:

A case is a collaborative workspace used by security analysts to investigate and resolve potential security incidents. Rather than forcing security analysts to look at thousands of individual alerts, the Google SecOps platform groups related activity into a single "threat-centric" case.

Cases can be created in two different ways:

  • Reactive: these cases bundle security findings and supporting data to facilitate rapid investigation and resolution.
  • Proactive: these cases are initiated by hypotheses or hunting tasks. They act as containers for exploratory investigations that may be closed if no incident is verified.

You can sort and filter the cases from the Cases page. The URL for each case is "sticky", allowing you to share it with other users who will see the same sorting or filtering you have selected.

The Cases list displays the following columns (which can be sorted, according to your requirements).

  • ID: Each case has a unique ID number.
  • Name: Name given to the case.
  • Assignee: Can be a SOC role or an individual user.
  • Stage: The following is a list of the default stages. You can add or delete new ones through the SOAR settings.
    • Triage: This is the initial phase when a case is created and is the default stage.
    • Assessment: The case is escalated to the next tier for evaluation.
    • Investigation: The case is assigned an active investigation of alerts and entities.
    • Improvement: The case is flagged for refining SOC detection rules or for a follow-up review.
    • Research: The case is assigned a deeper investigation into external access or threat behavior within your organization.
    • Incident: This is the final case stage for critical events.
  • Findings: Security findings include Alerts, Detections and Events.
  • Case SLA: Service Level Agreement (SLA) for a case. This is either set from the Settings or by automation.
  • Risk score: A case risk score is a numerical value that represents the overall risk associated with a particular security case. It is calculated based on the risk scores of the entities involved in the case and the findings (alerts and detections) related to those entities. You can edit and manage these from the Entity Risk score page in the SIEM Settings.
  • Tags: All tags associated with a case.
  • Priority: The following options are available: Low, Medium, High, Critical and Informative. Google recommends setting and changing priority at the alert level. This is because the case automatically inherits the highest priority of all grouped alerts.
  • Description: Case description. Can be added manually or part of Gemini summary case description.
  • Creation time: Date and time the case was created.
  • Last modified time: Date and time the case was last modified - whether manually or by a playbook.
  • Playbook status: If a playbook was attached to one of the case alerts, this column indicates if the playbook ran successfully. Note that if several playbooks were attached and one failed. this column shows a failure status.
  • Environment: Lists the environment the case is associated with.
  • Status: Displays the status of the case. For example, opened, closed.

What can I do on the Cases List page?

  • Switch from seeing the cases in a list view to displaying cases in a side-by-side view. The side-by-side view provides an indepth look at a case and its alerts. It lets you look at a case in parallel to the cases queue, so you can see the new cases added to the queue while investigating the current case.
  • Filter cases
  • Create a manual case
  • Simulate cases
  • See case findings. You can click the downward arrow next to each case to display information on each finding. Once opened, drill down to the detection level by clicking the findings name. The detections level displays widgets that were defined in the New default alert view option in SOAR Settings. For more information see List of alert widgets. From here, you can also access the Events tab, Playbooks tab and Graphs tabs.
  • See a summary of the case by clicking the Case Preview icon in the case row. This opens up a side drawer with more information.

Click the case ID or name to drill down into the case:

The case details page contains the following tabs:

  • Overview: The Overview tab contains a list of widgets that display a deep-dive analysis of that case. These widgets are managed in the New default alert view or New default case view in the SOAR Settings. For more information on widgets, see List of case widgets.

  • Case wall: The Case Wall tab is a repository of all event logs related to a case, from its creation until it is closed. It displays activities taken by a user or a playbook's action.

  • Detections - The Detections tab contains both alerts and the curated detections generated from the SIEM side of the platform. For more information on alerts, see Working with alerts. For more information on detections, see Curated Detections.

Need more help? Get answers from Community members and Google SecOps professionals.