Skip to content

Commit 813aa7e

Browse files
Merge pull request #5416 from MicrosoftDocs/main
[AutoPublish] main to live - 10/30 04:28 PDT | 10/30 16:58 IST
2 parents 9380496 + 3bfad00 commit 813aa7e

File tree

7 files changed

+47
-1
lines changed

7 files changed

+47
-1
lines changed

unified-secops-platform/cases-overview.md

Lines changed: 47 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -116,7 +116,11 @@ Add tasks to manage granular components of your cases. Each task comes with its
116116

117117
*Image shows the following task statuses available: New, In progress, Failed, Partially completed, Skipped, Completed*
118118

119-
### Link incidents
119+
### Link objects
120+
121+
Linking a case to other objects in your environment helps your SecOps teams understand the broader context of a threat. You can link cases to incidents or [indicators of compromise (IoCs)](/defender-endpoint/indicators-overview).
122+
123+
#### Link incidents
120124

121125
Linking a case and an incident helps your SecOps teams collaborate in the method that works best for them. For example, a threat hunter who finds malicious activity creates an incident for the incident response (IR) team. That threat hunter links the incident to a case so it's clear they're related. Now the IR team understands the context of the hunt that found the activity.
122126

@@ -126,6 +130,18 @@ Alternatively, if the IR team needs to escalate one or more incidents to the hun
126130

127131
:::image type="content" source="media/cases-overview/link-incident-from-incident-graph.png" alt-text="Screenshot showing the link incident option from ellipses menu in the incident view.":::
128132

133+
#### Link indicators
134+
135+
Linking a case to relevant indicators of compromise (IOCs) helps your SecOps teams understand the broader context of a threat.
136+
137+
To link the case to IOCs, go to the **Linked Objects** tab in the Case page and select **Indicators**. Then, select the **Add** button and the workspace the TI Indicator is in. Select the wanted TI Indicator and click on **Link**.
138+
139+
:::image type="content" source="media/cases-overview/link-indicators.png" alt-text="Screenshot showing the linked indicators for the hypothetical burrowing attack case.":::
140+
141+
Alternatively, you can create a case and link the indicators from the Intel management indicators details page. Select your TI Indicator and then on **Link Cases**.
142+
143+
:::image type="content" source="media/cases-overview/link-indicator-from-intel-management.png" alt-text="Screenshot showing the link indicator option from the TI Indicator view.":::
144+
129145
### Activity log
130146

131147
Need to write down notes, or that key detection logic to pass along? Create rich text comments and review the audit events in the activity log. Comments are a great place to quickly add information—including such things as queries, tables, links, and structured content—to a case.
@@ -140,8 +156,38 @@ Share reports, emails, screenshots, log files, and more, all centralized in the
140156

141157
:::image type="content" source="media/cases-overview/case-attachments.png" alt-text="Screenshot of the details of the Attachments tab of a case.":::
142158

159+
You can attach up to 10 files per comment.
160+
161+
#### Add attachment to a case
162+
143163
To add attachments to your case, go to the **Case details** page, select the **Attachments** tab, select **Upload**, select your file, and wait for the upload to complete. Once uploaded, the file is scanned in the background for malware. When the scan is complete, anyone with access to the case can download the file. If the file you want to upload is actually a malware sample, you can wrap it in a password-protected ZIP file.
144164

165+
#### Add attachment to a comment
166+
167+
To add an attachment to a comment:
168+
169+
1. Go to the comment area of the *Case* page.
170+
1. Go to the text editor at the bottom of the screen, and select the paperclip icon to attach a file.
171+
1. Select the file you want to attach from your computer.
172+
1. Select **Send** to save the comment.
173+
174+
:::image type="content" source="media/cases-overview/attach-file-to-comment-send.png" alt-text="Screenshot showing the Send button to save the comment.":::
175+
176+
- To attach a screenshot to your comment, paste it into the text editor.
177+
- To delete an attached file from the comment, select the bin icon while hovering over it.
178+
179+
### Delete Case
180+
181+
To delete a case:
182+
183+
1. Open the Cases screen, select the case you want to remove, and select **Remove**.
184+
185+
:::image type="content" source="media/cases-overview/delete-case.png" alt-text="Screenshot showing the Remove option in the case details pane.":::
186+
187+
1. In the pop-up window, type *delete* and then select **Confirm**.
188+
189+
:::image type="content" source="media/cases-overview/delete-case-confirm.png" alt-text="Screenshot showing the confirmation dialog for deleting a case.":::
190+
145191
## Limitations
146192

147193
See [Case management limits](/azure/sentinel/sentinel-service-limits#case-management-limits).
35.1 KB
Loading
30.9 KB
Loading
9.73 KB
Loading
82.4 KB
Loading
122 KB
Loading
113 KB
Loading

0 commit comments

Comments
 (0)