Switch to the Detailed View to see a breakdown of case information in a table-based format.
The Detailed View in the case card provides a table-based format and custom layouts, ensuring full backward compatibility. You can switch between the Overview and the Detailed View based on your workflow preferences.
The Detailed View supports deep inspection and manual analysis while maintaining access to the same underlying case data. It includes the following tabs:
Tab | Description |
|---|---|
Issues & Insights | Displays a list of issues and insights linked to the case. Click on an issue or insight to open the issue card. |
Key Assets & Artifacts | Displays asset and artifact information of the key artifacts, hosts, and users associated with the case. Hover over an icon for more information, or click the more options icon to see the available views and actions. For more information about investigating key assets and artifacts, see Investigate artifacts and assets. |
Timeline | Displays a chronological representation of issues and actions relating to the case. Each timeline entry represents a type of action that was triggered in the issue. Issues that include the same artifacts are grouped into one timeline entry and display the common artifact in an interactive link. Click on an entry to view additional details in the Details pane. You can also filter the timeline by action type. Depending on the type of action, you can select the entry to further investigate and take action on it. |
Case War Room | The Case War Room is a collection of the Active Response investigation actions, artifacts, and collaboration pieces for an issue or case. It is a chronological journal of the case investigation. You can run commands and playbooks from the War Room and filter the entries for easier viewing. The War Room facilitates real-time investigation. Powered by ChatOps, the War Room helps you perform different tasks related to their case investigation using CLI commands. For example, running real-time security actions through the CLI, without switching consoles, and running security playbooks, scripts, and commands. For more information, see Use the War Room in an investigation |
Executions | Displays the causality chains associated with the case. On this tab, you can investigate a causality chain and take actions on a host. For more information, see Causality view. |