Investigations: build the case narrative
Alerts expire. Investigations persist. Dual-Strike XISEM Investigations workspace lets analysts assemble a case narrative: linked detections, assets, identities, browser sessions, timeline notes, and outbound actions — without exporting screenshots to a shared drive.
Route: /investigations
When to open an investigation vs. a ticket
• Single known issue, fix today — PSA ticket from Threat Center
• Multi-asset lateral movement suspicion — Investigation
• Audit request spanning 30 days — Investigation + Report
• Client exec asks “what happened?” — Investigation narrative export
Investigation building blocks
1. Seed — detection, asset, user, or manual case
2. Attach evidence — pivot from Asset modal, Browsing Insights, identity events
3. Annotate — analyst notes with timestamps (who did what)
4. Assign — owner and client org (MSP scope)
5. Resolve — outcome + link closed PSA ticket(s)
Collaboration patterns for MSPs
• Tier 1 creates investigation from Critical detection, attaches initial timeline
• Tier 2 adds identity and browsing pivots, documents root cause
• vCISO exports summary for client QBR (redacted)
• Account manager never needs console access — PDF or scheduled report
Quality bar
A closed investigation should answer:
• What was the initial signal?
• What evidence confirmed or refuted the hypothesis?
• What changed in the environment?
• What control or detection was tuned afterward?
If you cannot answer all four, the case stays open.
Integrations
Gateway destinations can reference investigation ID in ticket custom fields (per integration capabilities). Identity and EDR Gateways continue appending to open cases while active.
Docs: Support wiki → Investigations & remediation workflows
Investigations interpret evidence — they do not execute enforcement on endpoints.


