Create a new investigation - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2024-05-15
Category
Administrator Guide
Abstract

Learn how to create a forensics investigation. This includes adding a collection, exporting the data collection, managing alerts and key assets & artifacts.

Create a forensics investigation that includes all the forensics data relevant to the investigation. This includes adding collections (hunts and triages), exporting the data collections, managing alerts and evaluating key assets & artifacts.

  1. In Cortex XSIAM, select Incident ResponseInvestigationForensicsForensics Investigations.

  2. Click New Investigation.

  3. Enter a unique name and optional description for the investigation.

  4. In the Permissions table. select the users that can access the data of the investigation.

    Note

    Scope-Based Access Control (SBAC) must be enabled for you to set up user permissions.

    Refer to User permissions for detailed information on permissions.

  5. Click Save to save the investigation in the Forensics Investigations table or click Save & Start A Collection to start the process of adding collections.

  6. In the New Collection widget, select Triage orHunt.

  7. The investigation is saved to the forensic investigation table.