Security Operations

Investigations

A structured case management module for security incidents and digital forensics investigations — bringing together evidence, IOCs, OSINT intelligence, analyst notes, timelines, and response checklists into a single, auditable case file.

Investigations

Security & forensics case management

What it does

Key capabilities

Structured Case Management

Create and manage security and forensics investigations with severity, status, type, and analyst assignment — tracked from first alert through to closure.

IOC Tracking

Record and classify Indicators of Compromise — IPs, domains, hashes, email addresses, URLs, filenames, and user accounts — with threat levels and source attribution.

OSINT & Forensics Toolkit

13 built-in intelligence tools: IP geolocation, domain DNS/WHOIS, hash analysis, email header parsing, SSL inspection, URL scanning, AlienVault OTX, threat feed aggregation, CVE lookup, MITRE ATT&CK, Wayback Machine, network WHOIS/RDAP, and Shodan.

Automatic Case Timeline

Every evidence item, IOC, note, OSINT result, and completed checklist action is automatically stitched into a reverse-chronological timeline for auditing and reporting.

Response Checklists

Build custom response checklists per case, import tasks directly from Playbooks, and track completion with timestamps and analyst attribution.

One-Click Case Reports

Generate formatted investigation reports from any case — including summary, IOC tables, evidence log, and analyst notes — printable and exportable for stakeholder briefings.

Highlights

Why Investigations?

  • Purpose-built for incident response and digital forensics workflows
  • 13 integrated OSINT tools — all accessible within the case record
  • Full evidence chain of custody with module source tracking
  • MITRE ATT&CK and CVE (NIST NVD) lookups built in
  • Playbook integration — import response tasks directly into any investigation
  • Printable case reports for executives, auditors, and legal
Included in OneView

Investigations is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

Investigations includes 13 integrated intelligence tools: IP geolocation, domain DNS and WHOIS lookup, file hash analysis (VirusTotal), email header parsing, SSL certificate inspection, URL scanning, AlienVault OTX threat feed lookup, CVE lookup against NIST NVD, MITRE ATT&CK technique lookup, Wayback Machine, network WHOIS/RDAP, and Shodan.

Every piece of evidence added to a case — IOC, OSINT result, file attachment, analyst note, or checklist action — is automatically timestamped and attributed to the analyst who added it. The case timeline stitches all actions into a reverse-chronological audit trail that cannot be altered, preserving chain of custody for legal proceedings.

Yes. Investigations integrates directly with the Playbooks module. Analysts can import any saved playbook as a structured checklist into an active investigation — tasks appear with completion tracking and analyst attribution, giving you both the structured response workflow and the investigation record in one case file.

Investigation reports can be generated as formatted documents directly from any case. The report includes an executive summary, full IOC table with threat levels, evidence log with timestamps, completed and pending checklist items, and analyst notes — ready for briefing stakeholders, legal teams, or regulators.

See Investigations in action

Request a personalised demo and we'll show you exactly how Investigations works within your environment.