Cases
Cases let you group investigation findings across multiple perimeters, alerts, and analysts, and share results with your end-users in a structured and traceable way. You can create a case from an existing alert or add alerts to a case at any point during your investigation.
What cases contain
A case consolidates the following elements into a single investigation workspace:
| Element | Description |
|---|---|
| Alerts | One or more alerts that triggered the investigation. |
| Tasks | Manual actions to track and assign across your team. |
| Events | Raw security events raised by the alerts or added directly. |
| Graph investigation | A visual map of observables, relationships, and threat intelligence objects. |
| Comments | A timestamped timeline of analyst notes. |
| Custom fields | Structured metadata fields attached to the case to capture investigation-specific data such as impacted mailbox, campaign ID, or incident category. |
| Notebook | A structured investigation document for recording analysis, findings, and conclusions. |
| Case template | A reusable bundle of custom fields, tasks, and a notebook template that structures a case automatically on creation or application. |
Custom statuses, verdicts and priorities
Cases support the same custom status and verdict system as alerts, enabling consistent terminology and workflows across your SOC. A status belongs to one of three stages, Open, In progress or Closed, and you can enable it for cases only, for alerts only, or for both. Case priorities are configured in the same place, and apply to cases only.
You configure all three in Settings > Custom Statuses.
Status history
Case history preserves the original status name even if a custom status is modified later. Historical records always reflect the status names that were in use at the time of each change.
Case templates
A case template is a reusable configuration bundle that instantly structures a case with predefined custom fields, tasks, and a notebook template. You can select a template when creating a case or apply one to an existing case at any point during your investigation.
Templates help enforce consistent processes across incident types: a phishing case, a ransomware case, and an insider-threat case can each open with the exact fields, steps, and documentation structure your team expects, without manual setup.
For more details, see Case templates.
Related articles
- Custom statuses: What custom statuses are, the three stages, and how one status serves both alerts and cases.
- Manage custom statuses: How to create, edit, reorder and enable custom statuses.
- Migrate custom statuses: How to disable or delete a status that alerts and cases already use.
- Custom verdicts: How to standardize the classification of case and alert outcomes.
-
Custom priorities: How case priority levels are configured and ordered.
-
Create a case: Step-by-step instructions to open a new case and configure its initial properties.
- Manage cases: How to filter, sort, and perform bulk actions on cases from the listing page.
- Case details: Reference for every tab and field available on the case details page.
- Graph investigation: How to use the interactive graph to correlate observables and threat intelligence.
- Custom fields: How to extend alerts and cases with structured, typed metadata fields.
- AI Cases: How Sekoia.io automatically correlates alerts into cases using AI.
- Alerts: How alerts are created and how to manage them before grouping them into cases.
- Case templates: Overview of what case templates are and how they work.
- Create a case template: How to build and configure a reusable template in Settings.
- Apply a case template to a case: How to apply a template at case creation or on an existing case.