Case Management Agent

The Case Management Agent brings the results of your security investigation together in one place—a case. After an incident is escalated to a case, the agent collects related incidents, alerts, detections, evidence, threat intelligence, and analyst notes to build a complete view of the activity. See Security Operations Overview for an overview of the agentic SOC Operations workflow.

The agent does not perform a new investigation. Instead, it consolidates and enriches the investigation already completed, tracing activity from the original detection through related alerts and incidents, building a chronological timeline, and organizing the available evidence.

The Case Management Agent can provide:

  • Executive summary of the case.

  • Attack narrative describing how the activity progressed based on the available evidence.

  • Timeline and sequence of relevant events.

  • Entities of interest, such as users, machines, applications, IP addresses, domains, and files involved in the investigation.

  • Threat intelligence assessment that connects relevant indicators to available ThreatStream intelligence, including known threat actors, malware families, campaigns, and TTPs when supported by the evidence.

  • MITRE ATT&CK tactics and techniques identified or represented by the available evidence.

  • Risk and scope assessment based on factors such as severity, affected entities, potential data exposure, and operational impact.

  • Recommended actions based on the investigation findings and supporting evidence.

The agent does not automatically execute external response actions. Recommended response actions are presented for you to review in the Response Workbook on case details pages. See Using the Response Workbook for details.

To learn more about case details, see Viewing Case Details.

For details on monitoring and managing activity of the Case Management Agent, refer to Monitoring Status and Activity of Individual Agents.