Case Management (CASE)
case management is the primary analyst workspace in current ai soc packages ingestion creates records here with tracking prefix case use case analysis and related tabs for triage, hero ai, evidence, and lifecycle actions open case management navigate to application records → case management open a record from the list case analysis tab the case analysis tab is the main workspace for investigating each alert or case from here you identify the record, run quick actions, and review key fields in one place identification and quick actions at the top of the record you can claim assign the record to yourself as the current owner use this when you are ready to start investigating claiming also sets the time assigned timestamp for tracking unclaim un assign the case so another analyst can claim it (orchestration action unclaim case ) sustained investigation uses this case management record status (for example in progress ), investigation comments, evidence, and routing rules escalated may be set when pending case resolution and your tenant rules apply (see operations and guidance / /operations and guidance md ) you will also see the tracking id (for example, case 21 ) with an option to copy the link, timestamps for when the record was created and last updated (and by whom), and sla status when sla is configured (for example, how much sla time has been used, with visual indication as you approach the limit) key fields on the record the record shows essential information about origin and current state time of first evidence when the first piece of evidence was collected helps you understand the investigation timeline first created / last updated when the record was created and last modified useful for tracking how long it has been in the queue current owner who is responsible for investigating this record empty means unassigned organization which organizational unit owns this record helps with multi tenant environments signal type whether the case represents an alert, phishing email, or triage record different types may have different workflows signal source which system generated the alert (for example, splunk, crowdstrike, email gateway) helps you understand the alert origin and reliability intelligence verdict the aggregated threat intelligence verdict (malicious, suspicious, benign, unknown) based on observable enrichment calculated from your ti providers and gives you an immediate risk assessment status and classification fields these fields help you classify and prioritize manual verdict your final assessment after investigation (malicious, suspicious, benign, unknown) the ai verdict is a recommendation; your manual verdict is the authoritative decision status current workflow state (processing, new, in progress, blocked, escalated, closed) use this to track where the record is in your investigation process priority urgency level (p0–p4) p0 is most urgent set this based on severity and business impact severity technical severity (critical, high, medium, low, informational, unknown) reflects the technical risk level of the threat classification final disposition (true positive, false positive, unknown) use this to track whether the alert was valid and to improve future detection if your layout uses a linked record for part of the workflow, some fields on this record may be read only; edit manual verdict , status , priority , severity , and classification where your form allows, or on the linked record when that is how your organization configured the application ai analysis widget (ai alert analysis) the ai analysis widget on the layout drives the ai alert analysis experience on the record—ai powered analysis and investigation guidance section what you see common actions signal summary signal name, investigation summary, confidence score, ai verdict, verdict analysis, threat intelligence analysis, mitre analysis reanalyze (manual) or re investigate (autonomous); generate remediation plan ; regenerate remediation plan (when a plan exists) agent investigation analysis agent reasoning narrative, step completion indicators, and status badge ( not started , in progress , complete , failed , cancelled ) visible when analysis mode is autonomous ; expand step groups to see component runs investigation plan preparation, analysis, and determination stages generate plan or generate investigation plan , regenerate investigation plan , review , run , run all steps , + add additional step automation triage rules and playbooks from the current case; playbook run details when a routing playbook has run and no investigation plan exists yet (typical for n+1 cases) create a triage rule , create a playbook , recreate playbook ; expand steps in playbook run details to review collected execution data during generate plan or regenerate investigation plan , progress detail messages stream in the panel until the plan is ready or you cancel agentic investigation (autonomous mode) when analysis mode is autonomous , the analysis agent investigates without an analyst running plan steps set analysis mode on the case metadata column ( case analysis ) or on support (under agentic investigation data ), then click re investigate in the signal summary area of ai alert analysis what the agent does reads case details and threat intelligence already linked to the record summarizes the alert (signal type, parties, observables, intelligence verdict) searches tenant components marked visible to hero ai (for example, url analysis, email enrichment, ip reputation) executes enrichment and analysis steps; each group shows how many steps completed compiles a verdict with confidence, key evidence, and recommended actions; results are written to the record agent investigation panel below signal summary , the agent investigation section streams the agent's reasoning while a run is active, the status badge shows in progress when the run finishes, the badge shows complete (or failed / cancelled ) before the first run starts, the badge shows not started and the panel may show that no reasoning details are available yet after investigation review investigation summary , confidence, and verdict in signal summary use verdict analysis , threat intelligence analysis , and mitre analysis for deeper views use generate remediation plan and automation ( create a triage rule , create a playbook ) when you are ready to operationalize the pattern re investigate click re investigate in signal summary to start a new autonomous run or run again after evidence or kbas change a confirmation dialog appears the agent will re do the investigation all current progress and the associated data will be removed case verdict will be reset to the initial verdict these changes cannot be reverted to give the agent new guidelines before a re run, update the linked knowledge base articles first, then click re investigate and confirm agentic investigation on the record open the record, set analysis mode to autonomous , then click re investigate in ai alert analysis monitor the agent investigation panel component inputs, outputs, and attachments are stored on the record automation action purpose create a triage rule route similar signals automatically create a playbook / recreate playbook convert the investigation into an investigation playbook for signal routing rules build in orchestration create or duplicate investigation playbooks and associate them on a rule — see building routing rule playbooks /operations and guidance/building routing rule playbooks md create a playbook does not pull recovery steps from generate remediation plan into the generated playbook (by design), so automated containment is not immediately undone use reusable recovery playbooks or your standard process after containment see getting started / /getting started md and troubleshooting / /troubleshooting md the ai uses threat intelligence, knowledge base articles, and historical patterns to generate relevant investigation steps you can modify the plan, add steps, remove steps, or run steps in any order evidence areas knowledge base articles linked articles that match observable patterns or alert characteristics threat intelligence enrichment results for observables extracted from the record if add observable receives an invalid observable, the notification includes the case management tracking id select the notification to open that case, then expand its threat intelligence area to review the failure correlation related records that may be part of the same incident rules which routing rules processed this record and what actions were taken mitre att\&ck references mapped tactics and techniques select a tactic or technique name or id to open its page on the mitre att\&ck website other tabs routing rule which routing rules evaluated this record and their results the tab includes rule processed reference , rule processing status , rule matched , rule last processed , and playbook run id knowledge base quick access to linked kb articles without leaving the record metrics performance metrics and summaries timeline milestones in the lifecycle (for example, threat intel returned, correlation completed, priority set, resolution) informational; clicking a milestone does not trigger an action linked cases parent and child case relationships, with actions to synchronize selected fields between linked records audit change history showing who did what and when support manual actions and troubleshooting tools playbook run id for the default routing rule playbook run id can be blank when the default routing rule matches a case this field is populated when an associated investigation playbook writes its current run id to the case (for example, with $run id ) a blank value for the default rule does not by itself indicate that rule processing failed; review rule processing status , rule matched , rule last processed , and rule processed reference for the routing result link parent and child cases use the linked cases tab to represent related investigations as a parent and child hierarchy parent case references one parent case management record child cases references one or more child case management records after linking records, use the synchronization action that matches the direction you need sync from parent case copies classification , manual verdict , status , and current owner from the selected parent to the current case sync to child cases copies those fields from the current case to every selected child case synchronization updates the selected fields; it does not merge all evidence or investigation data review the linked records before running an action because existing values in the destination cases are replaced record types and lifecycle signal type can be alert, phishing, or triage new records often move from processing to new , then progress through workflow states as they are claimed and resolved automated case lifecycle (flows and buttons) after case records are created, several flows and buttons automate evaluation and lifecycle signal routing rules routing rules run associated playbooks when case records meet configured conditions test batch routing from a routing rule record using run rule against pending signals on that rule's support tab case evaluation automated applies default logic based on threat intelligence, correlation, and case fields run rules engine re evaluates routing rules for the current record ( support tab button; component ai soc run rules engine against current case record ) pending case resolution / case prioritization / update case metrics background flows that set resolution outcomes, priority, and dashboard metrics once evaluation and rules have run use these together to keep case triage, escalation, and reporting consistent across alert and phishing pipelines processing status processing means threat intel enrichment and evaluation (correlation, kb linking, hero ai analysis) have not yet completed when both complete, the pending resolution flow may set the record to new , closed , or escalated do not expect generate plan or an ai verdict until the record has left processing threat intelligence status shows whether enrichments are pending or complete rule processing status indicates whether routing rules have been evaluated correlation status shows if correlation is pending, processing, or complete; correlation runs on a schedule through ai soc main (there is no manual correlation action on support ) correlation timing correlation runs on a schedule (every 10 minutes by default) and evaluates older records in batches records are typically eligible for correlation after a short delay (about 5 minutes) so ingestion and enrichment can complete first each run evaluates the oldest eligible records in a batch (up to 100 at a time) to avoid reprocessing newer records support tab agentic investigation data (expand on support ) analysis mode manual ( ai assisted investigation with generate plan ) or autonomous (agentic investigation via re investigate in ai alert analysis ) the field appears in the case metadata column on case analysis and under agentic investigation data on support analysis status not started , in progress , completed , failed , or cancelled for ai soc trigger analysis agent runs component runs file attachments from agent component runs during autonomous investigation analysis agent request id and analysis agent session track on record re investigate runs and routing rule analysis runs previous ai verdict , previous ai verdict confidence , and previous ai verdict analysis prior ai verdict captured before re investigate resets the case verdict manual actions (expand manual actions on support ) ai case analysis run hero ai analysis (for example, to refresh verdict or summary) check threat intelligence results refresh or open ti enrichment for observables run rules engine re run routing rule evaluation on this record claim case assign ownership when starting investigation unclaim case un assign ownership other support tab options read only prevents accidental edits while reviewing visibility toggles for sections such as signal data , case metadata , hero ai features , alert data , and phishing email data ai alert analysis configuration (rbac) configure role based options on applications & applets → case management → form layout → case analysis tab → select the ai analysis widget → edit widget each option can be enabled or disabled and limited to specific roles (use to allow all roles) summary section, plan section, remediation section, automation section generate plan , modify plan, execute plan, marketplace components remediation without malicious verdict (optional) where to look first confirm signal source , severity , and classification validate intelligence verdict and observables use generate plan (manual mode) or re investigate in ai alert analysis (when analysis mode is autonomous on support ) to start investigation detailed workflow start with metadata and triage fields to confirm status, ownership, and severity review evidence areas in order knowledge base → threat intelligence → correlation → rules if a routing rule already ran ai soc trigger analysis agent via routing rule , plan and verdict fields may already be populated investigate using one path ai assisted investigation use generate plan , run preparation and analysis steps, then generate a verdict in determination agentic investigation on the record set analysis mode to autonomous on support , click re investigate in ai alert analysis , then review results in the agent investigation panel review after routing a signal routing rule already ran agentic investigation—review plan and verdict on the record set manual verdict and status per your process ( escalated may be set by automated pending resolution when configured) use regenerate investigation plan or regenerate remediation plan when evidence or verdicts change if the pattern repeats, use create a triage rule , create a playbook , or recreate playbook in automation