🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Start and Add to Investigations

investigations alerts events


You can add alerts, events, search queries, and attachments to existing investigations, or create new investigations from them, as you navigate throughout Secureworks® Taegis™ XDR.

Start a New Investigation From Alerts or Events

  1. Select Create New Investigation when viewing any alert or event. (This option may be in the Actions drop-down list.)

Tip

To add multiple alerts or events to an investigation at a time, select them using the checkmarks in the table, then choose Actions→Create New Investigation.

  1. Give the investigation a name and select a Type and Priority.
  2. Specify the Key Findings Template as blank or Security Investigation, then select OK.
  3. A direct link to the new investigation appears in a notification.

Start an Investigation

Start an Investigation

Start a New Investigation with All Alerts

You can add all alerts from the Alerts page or from search results to a new investigation. This is helpful when there are too many results to display in the table, but you want to add them quickly to an investigation.

Bulk Adding Alerts to a New Investigation

Bulk Adding Alerts to a New Investigation

  1. Select one or more results using the checkmark.
  2. Select Actions > Create New Investigation. The Add New Investigation dialog displays.
  3. Select the Add all alerts to Investigation option.
  4. Give the investigation a name and select a Type and Priority,
  5. Specify the Key Findings Template as blank or Security Investigation.
  6. Select OK. The investigation is created.

Note

There is a 50k limit for adding alerts to an investigation.

Note

Due to processing time, it may take a few minutes for the alerts to be visible in the investigation.

Create a New Empty Investigation

A new empty investigation is an investigation with no content. Create an Empty Investigation

Create a New Empty Investigation

  1. From the Secureworks® Taegis™ XDR left-hand side navigation, select Investigations.
  2. Select + Add New. The Add New Investigation dialog displays.
  3. Give the investigation a name and select a Type and Priority.
  4. Specify the Key Findings Template as blank or Security Investigation, then select OK.
  5. A direct link to the new investigation appears in a notification, and a new, empty investigation displays in the investigation table.

Add Alerts or Events to an Existing Investigation

While viewing events and alerts throughout the Secureworks® Taegis™ XDR application, select Actions → Add to Existing Investigation and choose the existing investigation you’d want to add the alert to.

Tip

To add multiple alerts or events to an investigation at a time, select them using the checkmarks in the table, then choose Actions→Create New Investigation.

Adding to Existing Investigations

Adding to Existing Investigations

Add All Alerts to an Existing Investigation

You can add all alerts from the Alerts page or from search results to an existing investigations. This is helpful when there are too many results to display in the table, but you want to add them quickly to an investigation.

Bulk Adding Alerts to an Existing Investigation

Bulk Adding Alerts to an Existing Investigation

  1. Select one or more results using the checkmark.
  2. Select Actions > Add to Existing Investigation or Create New Investigations. The Add New Investigation dialog is displayed.
  3. Select an investigation from the investigation list.
  4. Choose the Add all alerts to Investigation option.
  5. Select OK. The alerts are added to the investigation.

Note

There is a 50k limit for adding alerts to an investigation.

Note

Due to processing time, it may take a few minutes for the alerts to be visible in the investigation.

Start an Investigation With Many Alerts

Start an Investigation With Many Alerts

Linking saved search queries to an investigation adds extra context and facilitates easier hand-offs between analysts, improving the overall investigation workflow. When you do this, the investigation will include a link to the original search query.

Note

Please note that linking saved search queries does not make a copy of the search results. It also does not make a copy of the original alert or event data and does not alter the Secureworks’s data retention policy.

Adding to an Investigation from a Saved Search

Adding to an Investigation from a Saved Search

  1. Click on Advanced Search from the left-hand side navigation or open the search toolbar and select Advanced Search.
  2. Click on Saved Searches.
  3. From the Saved Searches panel select the ellipsis and choose Add to Investigation .
  4. In the pop-up modal, select whether you want to add the search query to an existing investigation or create a new investigation.
  5. Select OK.

Tip

The same search query can be added to multiple investigations.

The Searches section of an investigation displays all linked search queries.

Note

This section displays the search query name, not the search results of that query.

Running a Related Search from an Investigation

Running a Related Search from an Investigation

Attach Files to an Investigation

Share files relevant to an investigation by uploading them to an investigation.

Important

When uploading a potentially malicious file, you should embed it within a password-protected ZIP archive with infected as the password.

  1. Open an investigation.
  2. Select the Evidence tab and then the Attachments sub-tab.
  3. Choose Upload File.
  4. Drag and Drop or select browse to add one or more files.

Note

The max individual file size that can be uploaded is 2 GB.

  1. Select Close.

Add Investigation Attachment

Add Investigation Attachment

Note

Files attached to investigations are not subject to the data retention policy nor do they count towards the monthly data cap.

 

On this page: