Tracecat’s case management system is designed to help you manage and track security incidents. It’s design is inspired by Rapid7’s SMAC (status, malice, action, context) methodology and the alert management system at Brex bank.Documentation Index
Fetch the complete documentation index at: https://tracecat-docs-core-features.mintlify.app/llms.txt
Use this file to discover all available pages before exploring further.
Open case
Use the Open Case Action in a workflow to open a new case.View cases
Go to theCases tab to view all cases.
Cases are displayed in a table with the following columns:
Payload
A JSON object containing information about the case.
Status
Is the case
open, closed, reported, escalated, or resolved?Malice
Is the case payload indicative of malicious activity?
There are only two options avaiable:
malicious or benign.Action
What steps can I take to move towards closing or resolving this case?
Context
Context represents information not already captured in the case payload.
Best Practices
Tracecat automatically fills the case context with the following MITRE ATT&CK labels (if applicable).For example:You can disable this AI feature in
settings.Add evidence
Coming soonMulti-media evidence can be added to a case from the side panel.
Tracecat supports the following evidence types:
- Text
- Images
- Video
- Audio
Close case
Select the case you want to close in the case table. The case side panel will open. Use the case status dropdown menu to change the case status toClosed.