Use the Work Plan in an investigation
Use a Work Plan to organize investigation tasks and progress.
The Work Plan is a visual representation of the running playbook assigned to the issue. Playbooks enable you to automate many security processes, such as managing your investigations and handling tickets. Work Plans enable you to monitor and manage a playbook workflow, and add new tasks to tailor the playbook to a specific investigation.
In an investigation, when you open the Work Plan tab you can see the playbook, the playbook name, and navigation tools.
By default, the Follow checkbox is checked, which allows you to see the playbook executing in real-time. The playbook moves when a task is completed.
Work Plan actions
Change the default playbook
On the left-hand side of the window, select the playbook you want to run. When changing the playbook, all completed tasks are removed and the new playbook will run.
Rerun the playbook
When changing the playbook, select the current playbook to run again.
View inputs and outputs
View the inputs and outputs of each task that has run. You can't view inputs and outputs of any task that hasn't run.
Manage tasks
View, create, and edit a playbook task. Designate tasks as complete, assign an owner, set a due date, and add comments and completed notes. You can manage these tasks in the CLI by using the /task command.
Export to a PNG
Export the Work plan to a PNG format for easy analysis.
The color coding and symbols in the Work Plan help you to easily troubleshoot errors or respond to manual steps.
Last updated
Was this helpful?
