Skip to main content

Responses are generated using AI and may contain mistakes.

Threat CenterThreat Center Guide

Manually Create a Case

Create a case to start tracking your response to a threat and assign the case to the person responsible for responding.

You can also create a case automatically using Correlation Rules or Automation Management playbooks or convert an alert to a case.

  1. In the Cases tab, click + Create case.

    threatcenter-cases-createcase.png
  2. Enter information about the case:

    • Name – Enter a case name.

    • Briefly explain this alert – Enter a case description. To better communicate your message, you can also format the text.

    • Stage – Select a case stage. If you select CLOSED, in Type a reason, enter why you're closing the case. To better communicate your message, you can also format the text.

    • Queue – Assign the case to the queue responsible for responding.

    • Assignee – Assign the case to the person responsible for responding.

    • Priority – Select the case priority: Low, Medium, High, or Critical. The case priority determines the case risk score:

      • Low – The case is assigned a risk score of 25.

      • Medium – The case is assigned a risk score of 50.

      • High – The case is assigned a risk score of 75.

      • Critical – The case is assigned a risk score 100.

    • Users – Manually add user entities to the case:

      1. Click + Add User.

      2. Enter a search for a full name, username, or email address.

      3. For a user entity, click Add. You can't add an entity that is already associated with the case.

      4. (Optional) Under Reason for adding (optional), enter an explanation for why you're adding the entities to the case. The reason is shown in the case history for this action.

      5. Click Add to Case.

    • Devices – Manually add device entities to the case:

      1. Click + Add Device.

      2. Enter a search for a hostname, IP address, or MAC address.

      3. For a device entity, click Add. You can't add an entity that is already associated with the case.

      4. (Optional) Under Reason for adding (optional), enter an explanation for why you're adding the entities to the case. The reason is shown in the case history for this action.

      5. Click Add to Case.

    • MITRE TTPs – Select the MITRE ATT&CK® techniques that best describe the case.[5]

    • Use Cases – Select the use cases that best describe the case.

    • Custom Tags – Select or create relevant tags.

  3. Click Create Case.




[5] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.