Skip to content

Artifact

  • An Artifact refers to a specific data item or piece of evidence related to a security incident, used to support investigation and response efforts.
  • Artifacts can include various types of data, such as IP addresses, domains, file hashes, URLs, email addresses, etc.
  • Artifacts are attached to Alerts to help analyze and investigate security incidents.
  • Query/response/enrichment operations are typically performed on Artifacts, such as querying the owner of a hostname, looking up threat intelligence for a file hash, blocking an IP address, etc.

View

img.png

Supports multiple filtering and sorting functions.

Detail

img_1.png

Operation panel

Enrichments

img_2.png

Associated Enrichment records

Alerts

img_3.png

Associated Alert records