Creating and managing cases
Incident response cases are the space where you can manage security incidents. Here, you can create cases in several ways:
- Manually
- Automatized
- Based on playbooks
In this part, we will cover the creation of new cases manually.
Log in to the main page of TheHive using the credentials of the new user created:
- Username:
investigator@gosecurity.ninja
- Password:
L34rn1ng!
When starting the session, you will see the main panel with the list of added cases. In this case, none will appear because you have just created the organization, as shown in the following screenshot:
The scenario for our case is that the Security Operation Center SOC detected a new ransomware attack in one of the branches around the world. You will open a new case to start with the procedures related to this security incident.
To create a new case for this incident,...