Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Creating cases using Threat Analyst Workbench

Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.

Before you begin

Role required: sn_sec_tisc.analyst, sn_sec_tisc.admin

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click Threat Analyst Workbench icon.

  3. Go to Case Management > All Cases.

    All the cases are displayed.

  4. Click New.

  5. Fill in the fields as appropriate.

FieldDescription
Case IDA unique identifier for the case. This is system generated ID.
Short DescriptionSummary of the request or issue that is being investigated or a short description.
DescriptionA detailed description including any relevant information about the case such as background, what analysis is required, outcomes expected.
Case TypeSelect the type of case being investigated. The possible options for the investigation are:- Threat Hunting - Request for Information - Vulnerability Management Case - Compliance Case - Incident Response Case - Collaboration Case - Others
PriorityAn assessment of the severity of the request or issue.
Assignment groupThe assigned group responsible for working on the case.
StatusThe current status of the case.
Assigned toThe Analyst who is responsible for working on a case.
Due DateThe date and time that the task is due to be completed or closed.
ContributorsThe list of assignees rolled up from tasks and should be possible to add on top of it.
TLPUnique value that indicates the Data sensitivity setting per TLP.
Watch listWhen a user is added to the watchlist, the person will receive email notifications on changes to status and priority.
Enforce RestrictionSelect this check box to modify members of allowed group and allowed members. For more information, see Enforced Restrictions for case(s).
  1. Fill in the fields on the Insights section, as appropriate.

    FieldDescription
    NotesAny additional notes related to the threat investigation.
    Recommendations or ActionsAny recommendations or actions related to the threat investigation.
    Analysis and FindingsEnter the analysis and findings related to the threat investigation.
    Closure SummaryAdd the closure summary of the findings.
  2. Click Save.

    After the record has been saved, you can click the Import Intelligence tab to import the threat intelligence data using the Import Intelligence feature.

    Note: If you are importing and processing data from Case Management, then a unique is associated to the import record.

Image omitted: tisc-import-intelligence-case-management.png
Import intelligence-Case Management

Parent Topic:Threat Analyst Workbench

Related topics

Workbench Overview

Summarize a Case with Now Assist for Threat Intelligence Security Center

Creating case task using Threat Analyst Workbench

Working with Investigation Canvas

Add artifacts to case(s) or case task(s)

Run Enrichment Actions within a case

Generate a Case Report using generative AI

Generate a Case Report using a template

Create a security incident from a TISC case

Upload Secure File Attachments

Using playbooks