6. Incident Analysis

Cyber Triage offers several methods to analyze incident-level data from the hosts that were added to it. You can find these features from the Incident Dashboard when you open an incident.

../../_images/inc_analysis_dash.png

6.1. Hosts Table

The hosts table shows all hosts that have been added to the incident, their status, and number of bad items.

You can use this table when analyzing an incident to focus on hosts that have not yet been reviewed and that have high numbers of bad or suspicious. items.

6.2. Bad Items

The “Bad Items” table on the right-hand side shows the unique bad items in the incident. If the same item is in multiple hosts, it will be shown only once.

You can use this table to get an idea of what types of bad things are known so far in the incident.

Pressing the “View Items” button there will bring you to the “Notable Items” view that shows each bad item.

../../_images/inc_analysis_notable.png

From here, you can use filters on the left to include suspicious items, remove noisy hosts, and data types.

You can also sort here (the default) to create a timeline of bad items across the incident.

From this view, you can press “Open Host” to see more about what happened on the host. That brings you to the UIs that were shown in Analyzing The Host Data.