Observables
Observables refer to data that indicates a system may have been infiltrated by a cyber threat. They provide cybersecurity teams with crucial knowledge after a data breach or another breach in security. In this section, you can create and manage Observables for your Cases.
Please note that you can assign multiple Observables to a single Case or a single Observable to many Cases.
Types of Observables
- Unknown
- Hostname
- IP Address
- MAC Address
- URL String
- Username
- Email Address
- URL String
- File Name
- Hash
- Process Name
- Resource UID
- Port
- Subnet
- Command Line
- Country
- Process ID
- HTTP User Agent
- CWE Object : uid
- CVE Object: uid
- User Credential ID
- Endpoint
- User
- Uniform Resource Locator
- File
- Process
- Geo Location
- Container
- Registry Key
- Registry Value
- Fingerprint
- Other
If you wish to edit the Observable type, simply go to the Observable table, locate the icon next to the Observable Type table heading, and proceed to remove the desired Observable types by clicking the X button, followed by the Save button.
Creating a New Observable
Please note, you can also create Observables directly from the main Observable table . Simply navigate to the Observable table and click on the "New Observable" button located in the top-right corner and fill out the required parameters.
- Double click on the Case you want to attach the Observable(s) to, navigate to the Table Tab in the Overview Section of the selected Case, and in the top-right conner select the New Record button.
- A dialog box for creating a new record will appear.
- Fill in all the necessary fields.
Fields | Description |
---|---|
Name | The name of the Observable. |
Observable Type | The type of the Observable. |
Content Type | The content value of the Observable |
Description (Optional) | A written description for the Observable |
Verdict Type | Unknown, Benign,Suspicious, Malicious |
Enrichment Data | The enrichment data that provides additional information and context on the Observable |
Linked Cases | The Name and ID of the Case(s) you want to link to this current Observable. |
Linked Attachments | The Name and ID of the Attachment(s) you want to link to this current Observable. |
Linked Tasks | The Name and ID of the Task(s) you want to link to this current Observable. |
Linked Alerts | The Name and ID of the Alerts(s) you want to link to this current Observable. |
Linked Observables | The Name and ID of the Observable(s) you want to link to this current Observable. |
- Once completed, select the Add Observables button in the bottom-right corner.