nano SIEM
Case Management

Case Management

Case Management

Case Management is the central hub for SOC analysts to investigate, triage, and respond to security incidents. Inspired by Google SecOps, nano's case management system provides a case-centric workflow where alerts automatically flow into cases for streamlined investigation.

Key Features

Case-Centric Workflow

  • Alerts flow into Cases: Detection alerts are automatically grouped into cases based on configurable rules
  • Single pane of investigation: All related alerts, entities, and context in one place
  • AI-powered triage: Get AI-generated summaries and recommendations

Automatic Alert Grouping

  • Group alerts by host, user, IP, or detection rule
  • Configurable time windows prevent case fragmentation
  • Smart grouping reduces alert fatigue

Entity Extraction & Visualization

  • Automatic extraction of users, hosts, IPs, domains, and file hashes
  • Interactive entity relationship graph
  • One-click pivot to search for any entity

Integrated Investigation Notebooks

  • Every assigned case gets an investigation notebook automatically
  • Case lifecycle events (status changes, assignments, merges) are mirrored into the notebook
  • The Investigation tab shows a unified timeline — searches, notes, AI analysis, and case events in one place
  • AI summaries include case metadata for richer context

SOC Metrics & Audit Trail

  • Every case action is logged for compliance and metrics
  • Query audit events to build dashboards showing MTTD, MTTR, analyst workload
  • Full audit trail of who did what, when

Case Workflow

┌──────────────────────────────────────────────────────────────────────────┐
│                           CASE LIFECYCLE                                  │
├──────────────────────────────────────────────────────────────────────────┤
│                                                                           │
│   ┌─────────┐     ┌─────────────┐     ┌─────────┐     ┌──────────┐      │
│   │  Open   │────▶│ In Progress │────▶│ Pending │────▶│ Resolved │      │
│   └─────────┘     └─────────────┘     └─────────┘     └──────────┘      │
│        │                │                   │               │            │
│        │                │                   │               ▼            │
│        │                │                   │          ┌─────────┐       │
│        │                │                   └─────────▶│ Closed  │       │
│        │                │                              └─────────┘       │
│        │                │                                   │            │
│        │                │                                   │            │
│        └────────────────┴───────────────────────────────────┘            │
│                              (Reopen)                                     │
│                                                                           │
└──────────────────────────────────────────────────────────────────────────┘

Case Statuses

StatusDescription
OpenNew case awaiting investigation
In ProgressActively being investigated by an analyst
PendingWaiting for external input or action
ResolvedInvestigation complete, disposition assigned
ClosedCase fully closed and archived

Dispositions

When resolving or closing a case, analysts assign a disposition:

DispositionDescription
True PositiveConfirmed security incident
False PositiveDetection fired incorrectly
BenignReal activity but not malicious
InconclusiveUnable to determine with certainty

Quick Start

  1. View Cases: Navigate to Cases in the sidebar
  2. Create Case: Click New Case or press C
  3. Assign: Assign to an analyst — a notebook is auto-created for the investigation
  4. Investigate: Use the Investigation tab to search, add notes, and track entities
  5. Resolve: Set disposition and close — an AI summary is generated with full case context

Keyboard Shortcuts

nano's case management is keyboard-first for maximum efficiency:

ShortcutAction
CCreate new case
J / KNavigate down/up in list
EnterOpen selected case
VToggle table/kanban view
RRefresh cases
/Focus search
Cmd+KOpen command palette

Documentation Sections

On this page

On this page