Manage evidence
Overview
During your investigation, you can save relevant fragments from logs and IP addresses as evidence for later use in the Evidence collection section.
Example of how to use evidence: You can create filters for your query. For details, see Filter by evidence.
Add evidence
There are two ways to add evidence: manually, from the Evidence collection section, or from the query results table.
In the evidence collection
- In the Evidence collection section, select next to the evidence list where you want to add your evidence.
- Select Add.
Different evidence items are distinguished by a line break: every piece of evidence is on a separate line.
In the query results
- In the query results table, right-click on a field.
- In the Add to evidence list section, select where you want to add the evidence.
You can also add multiple items at once to the evidence list or create a new list from the selection.
Strings (partial or full value of fields) can go in the IoC preset string list or in custom string lists created by you.
IPs can go in preset IP lists (Suspicious, Safe) or in custom IP lists created by you.
There is no limitation on the number of lists you can create or of items (strings or IPs) you can add to a list in your evidence collection.
Besides IPv4 addresses, you can also add as evidence IPv6 addresses or subnet masks. Filtering by evidence containing a subnet mask displays all IPs within that subnet, which simplifies your queries.
Create custom lists
You can create custom evidence lists from the query results table.
- Right-click on a field.
- In the Add to evidence list section, select New list.
Delete evidence
You can delete items in your evidence list individually or in bulk.
-
In the Evidence collection section, select next to the evidence list where you want to delete evidence.
-
Select Manage.
-
Select the items you want to delete.
-
Select Delete.
Rename and delete lists
In Evidence collection you can
-
Rename preset and custom evidence lists
- Select next to the evidence list that you want to rename.
- Select Rename.
-
Delete custom lists
- Select next to the evidence list that you want to delete.
- Select Delete.