Skip to main content
Observables refer to data that indicates a system may have been infiltrated by a cyber threat. They provide cybersecurity teams with crucial knowledge after a data breach or another breach in security. In this section, you can create and manage Observables for your Cases.
To learn more about Observables and their role in Alerts and Case Management, please refer to our detailed guide available here.

Types of Observables

  1. Unknown
  2. Hostname
  3. IP Address
  4. MAC Address
  5. URL String
  6. Username
  7. Email Address
  8. URL String
  9. File Name
  10. Hash
  11. Process Name
  12. Resource UID
  13. Port
  14. Subnet
  15. Command Line
  16. Country
  17. Process ID
  18. HTTP User Agent
  19. CWE Object : uid
  20. CVE Object: uid
  21. User Credential ID
  22. Endpoint
  23. User
  24. Email
  25. Uniform Resource Locator
  26. File
  27. Process
  28. Geo Location
  29. Container
  30. Registry Key
  31. Registry Value
  32. Fingerprint
  33. Other

Creating a New Observable

Note:
  • You can assign multiple observables to a single case or a single observable to many cases.
  • You can also create observables directly from the main Observable table. Simply navigate to the Observable table and click on the ‘New Observable’ button located in the top-right corner and fill out the required parameters.
1

Navigate to the 'Observables' tab

To attach an Observable to a Case, first double-click on the desired Case. In the overview section of the selected Case, go to the ‘Observables’ tab. Then, click the “New Record” button in the top-right corner.
2

Open the New Record Form

3

Fill in all the necessary fields

4

Save and add the Observable

Once completed, select the Add Observables button in the bottom-right corner.

Observable Relations

Hover over the ‘Linked Alerts’ column in the observables table to see the relations associated with each observable.
Please note, you cannot make any changes directly to the relations, via the ‘Linked Alerts’ column in the observable table. To make any changes, you can do so via the Add or Update Observable Relation action.

Editing Observables

NOTE Please note that you can also Edit Observable(s) directly within the table tab of a case overview. Simply double-click on the table row to make any necessary changes. Once you have completed your edits, click anywhere on the screen to save the changes.
1

Select an Observable to Edit

Select the Observables you would like to edit and click on it.
2

Make Changes and Save

The ‘Edit Record’ Form will appear. Make any necessary changes to the fields, then click ‘Save’ in the bottom-right corner. The changes you made will be reflected in the selected observables.

Deleting an Observable

1

Select an Observable to Delete

Navigate to the observable you want to delete and select icon.

2

Delete the Observable

The delete option will appear. Click ‘Delete’, and the selected observable will be removed from your existing observables.