Threat Analyst Workbench
The Threat Analyst Workbench page consists of cases and case tasks that are under Threat Analysts and their team.
Use the Case Management feature to create and track the threat investigations and analysis activities.
During the threat investigations the analysts collect the data from internal intelligence records such as observables, threat actors, campaigns, and so on.
- Workbench Overview
The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team. - Creating cases using Threat Analyst Workbench
Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task. - Summarize a Case with Now Assist for Threat Intelligence Security Center
Use Now Assist for Threat Intelligence Security Center to generate a concise summary of a case, including its key findings and recommended next steps. - Creating case task using Threat Analyst Workbench
Create case tasks to associate with case(s). - Working with Investigation Canvas
The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities. - Add artifacts to case(s) or case task(s)
After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case. - Run Enrichment Actions within a case
Use this section to understand how enrichments actions are performed on case(s). - Generate a Case Report using generative AI
Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution. - Generate a Case Report using a template
Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report. - Create a security incident from a TISC case
Create security incidents and associate observables to the security incidents from a TISC case. - Upload Secure File Attachments
Use this section to understand on how to upload the secure file attachments to the case(s). - Using playbooks
Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.