Casebook App

The Cisco XDR casebook app in the ribbon or ribbon extension is a powerful and convenient tool for creating, saving, editing, and sharing your cases across the Cisco Secure portfolio and anywhere you go in your browser.

A case is a data structure that allows you to gather and group observables and related analyst notes in one place from across multiple products for easy retrieval and further actions. For example, you can group a list of observables known to be associated with a specific reported threat or a list of observables known to be associated with an endpoint of interest. You can then retrieve that case later and have the set of observables and your records immediately at hand.

A case does not include dispositions, sightings, or other temporal or enrichment-based information. It is primarily a container for observables so that all of the observables in the case can be investigated quickly or added to incidents. You can optionally include any analyst notes to the case as you follow leads during your threat investigation.

From within the casebook app you can see current dispositions on the observables in the case and launch investigations or take other research or response actions on them, as provided by your Cisco XDR integrations.

Casebook App

All panels in the casebook app are collapsible to customize your view of the selected case.