The Investigations screen is a hub for user collaboration and case management (also referred to as “incident management” in the industry). Analysts can collaborate to review the output of automated actions or playbooks, look at ingested data from the event, and make real-time decisions on the data.
Phantom Mission Guidance
Phantom Mission Guidance is an intelligent assistant that supports security operations analysts. It offers suggestions to help investigate, contain, eradicate, and recover from a security event. It works by mapping security event data to your currently configured SOC tools and playbooks. Phantom Mission Guidance recommendations help educate newer analysts on steps to take and validate the choices of more experienced analysts.
The Activity Feed in Splunk Phantom displays all current and historical action and playbook activity that has acted on the currently displayed event. This allows you to quickly see the success, ongoing execution, and results of all automation operations for the event. The Activity Feed also provides team collaboration capabilities that are integrated inline with automation details and other data, forming a record of all relevant event information.
Case Management is fully integrated into Splunk Phantom, allowing you to easily promote a verified event to a case. It also allows continued access to all tools, features, and data available in one interface. Case Management supports case tasks that map to your defined Standard Operating Procedures (SOPs). Moreover, Case Management has full access to the Phantom Automation Engine, allowing you to launch actions and playbooks as part of a task.
Workbooks allow you to codify your SOPs into reusable templates. Phantom supports custom and industry standard workbooks, like the included NIST-800-61 template for incident response. You are able to divide tasks into phases (e.g. detection, analysis, containment, eradication, and recovery), assign tasks to team members, document work, and more. You can also embed automation actions and playbooks directly into the workbook templates that you define.