Investigations
A structured case management module for security incidents and digital forensics investigations — bringing together evidence, IOCs, OSINT intelligence, analyst notes, timelines, and response checklists into a single, auditable case file.
Investigations
Security & forensics case management
Key capabilities
Structured Case Management
Create and manage security and forensics investigations with severity, status, type, and analyst assignment — tracked from first alert through to closure.
IOC Tracking
Record and classify Indicators of Compromise — IPs, domains, hashes, email addresses, URLs, filenames, and user accounts — with threat levels and source attribution.
OSINT & Forensics Toolkit
13 built-in intelligence tools: IP geolocation, domain DNS/WHOIS, hash analysis, email header parsing, SSL inspection, URL scanning, AlienVault OTX, threat feed aggregation, CVE lookup, MITRE ATT&CK, Wayback Machine, network WHOIS/RDAP, and Shodan.
Automatic Case Timeline
Every evidence item, IOC, note, OSINT result, and completed checklist action is automatically stitched into a reverse-chronological timeline for auditing and reporting.
Response Checklists
Build custom response checklists per case, import tasks directly from Playbooks, and track completion with timestamps and analyst attribution.
One-Click Case Reports
Generate formatted investigation reports from any case — including summary, IOC tables, evidence log, and analyst notes — printable and exportable for stakeholder briefings.
Why Investigations?
- Purpose-built for incident response and digital forensics workflows
- 13 integrated OSINT tools — all accessible within the case record
- Full evidence chain of custody with module source tracking
- MITRE ATT&CK and CVE (NIST NVD) lookups built in
- Playbook integration — import response tasks directly into any investigation
- Printable case reports for executives, auditors, and legal
Investigations is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.
See Investigations in action
Request a personalised demo and we'll show you exactly how Investigations works within your environment.