Skip to main content

Responses are generated using AI and may contain mistakes.

Threat CenterThreat Center Guide

Table of Contents

Manually Associate Entities with Cases

To add additional investigation context to a case, manually add entities to and remove entities from cases.

When Threat Center groups detections into cases or alerts, it automatically associates Attack Surface Insights entities from the detections with the case or alert. However, to keep cases updated with your investigation findings and external knowledge, you may want to manually associate entities with cases.

You can only add and remove entities that aren't already automatically associated with the case via its detections.

Entities that are manually added to a case are labeled as Manually Added in the Overview tab, under Users and Devices.

Entities that are manually added to a case don't appear in watchlists. Watchlists only include entities used to group detections.

When you add or remove an entity from a case, it is recorded in the case history.

Manually Add an Entity to a Case

Manually associate an Attack Surface Insights entity with a case.

  1. In the case Overview tab:

    • Click Edit Details.

      threatcenter-case-editcasedetails.png
    • Under Users, click Edit.

      The Users section of the case Overview tab wtih the Edit action highlighted in a red rectangle.
    • Under Devices. click Edit.

      The Devices section of the case Overview tab wtih the Edit action highlighted in a red rectangle.
  2. Add user and device entities:

    • Add a user entity under Users:

      1. Click + Add User.

      2. Enter a search for a full name, username, or email address.

      3. For a user entity, click Add. You can't add an entity that is already associated with the case.

      4. (Optional) Under Reason for adding (optional), enter an explanation for why you're adding the entities to the case. The reason is shown in the case history for this action.

      5. Click Add to Case.

    • Add a device entity under Devices:

      1. Click + Add Device.

      2. Enter a search for a hostname, IP address, or MAC address.

      3. For a device entity, click Add. You can't add an entity that is already associated with the case.

      4. (Optional) Under Reason for adding (optional), enter an explanation for why you're adding the entities to the case. The reason is shown in the case history for this action.

      5. Click Add to Case.

  3. Click Update.

    This action is recorded in the case history.

Manually Remove an Entity from a Case

Remove a manually added Attack Surface Insights entity from a case.

You can only remove entities you've manually added to the case. You can't remove entities automatically associated with the case via its detections.

  1. In the case Overview tab:

    • Click Edit Details.

      threatcenter-case-editcasedetails.png
    • Under Users, click Edit.

      The Users section of the case Overview tab wtih the Edit action highlighted in a red rectangle.
    • Under Devices. click Edit.

      The Devices section of the case Overview tab wtih the Edit action highlighted in a red rectangle.
  2. Under Users or Devices, hover over the entity, then click Remove.

  3. (Optional) In Reason for removing (optional), enter a reason for why you're removing the entity from the case. The reason is shown in the case history for this action.

  4. Click Update.

    This action is recorded in the case history.