Product tour
Seven steps through demonstration case NW-IR-041. A 4–7 minute narrated video will use this same case when published. Analysts still write findings; CaseScope carries the record.
1. Create the case
Action: create Northwind Holdings / NW-IR-041 with timezone America/New_York and analyst M. Ortiz. Result: a case record before files arrive.
2. Add collected evidence
Action: attach kape_ws14.zip, huntress_ws14.csv, and northwind_edge.csv. Result: evidence listed on the case with lanes assigned.
3. Process supported artifacts
Action: run ingest to published generation. Result: counts and status, not a half-built hunt surface.
4. Review and search
Action: hunt WS-14 / j.hale around 18:14. Result: EVTX and Huntress rows in one grid.
5. Record an analyst decision
Action: accept IOC 10.8.4.21; reject 10.0.0.15 as internal. Result: dispositions by the analyst. AI off.
6. Promote evidence into a finding
Action: name “Suspicious remote access on WS-14” and attach supporting events. Result: a finding with sources and an explicit gap (no memory image).
7. Assemble the report
Action: generate the case report package. Result: cover, scope, findings, and limitations. CaseScope assembled the record; the analyst authored the conclusion.