Cases
Designed to simplify threat hunting and forensic analysis, cases enable to you to investigate potential risks across your network.
In the FortiDLP Console, a case represents a group of suspicious events and detections. By building a case, you can proactively flag events and detections requiring investigation and then collaborate with other operators for more informed decision-making and rapid response.
The Cases module displays three categories of cases:
- The Open cases panel shows cases being actively investigated by operators within your organization.
- The Closed cases panel shows cases that were previously investigated by operators within your organization or Fortinet Cyber Analysts.
- The By Fortinet Cyber Analysts panel shows cases being actively investigated by Fortinet Cyber Analysts.
By clicking a case, you can navigate to the corresponding Case details page, where you can view and manage the case.
To learn more, see: