CaseBender home page
English
Search...
⌘K
Getting Started
Introduction
Quickstart Guide
Deployment
Deployment Overview
Deploy to Google Cloud Run
Deploy to AWS
Deploy to Azure
Deploy to DigitalOcean
Alert Management
Alert List View
Alert Detail View
Alert Observables
Alert TTPs
Similar Alerts
AI Insights
Case Management
Case Management
Creating Cases
Case Workflows
Working with Cases
Case Settings
AI Features in Case Management
Task Management
Task Management
Creating Tasks
Task Workflows
Working with Tasks
Task Settings
Task Analytics
Analytics
Analytics
Alert Analytics
Case Analytics
Task Analytics
Analyst Performance
Audits
Audit Logs
Change History
Status Tracking
Activity Logs
Compliance Monitoring
Settings
Introduction
Integrations
Workflows
AI Settings
Custom Fields
Observable Types
Attack Patterns
Alert Statuses
Case Statuses
Templates
Branding
CaseBender home page
English
Search...
⌘K
Support
Get Started
Get Started
Search...
Navigation
Alert Management
Alert Observables
Documentation
API Reference
Documentation
API Reference
Support
Get Started
On this page
Overview
Observable Types
Network Indicators
File Indicators
System Indicators
Custom Indicators
Managing Observables
Adding Observables
Bulk Operations
Observable Properties
Observable Enrichment
Automatic Enrichment
Manual Analysis
Visualization
List View
Relationship View
Best Practices
Next Steps
Alert Management
Alert Observables
Manage indicators and observables associated with alerts
Overview
The Observables tab allows you to track and manage various types of indicators associated with an alert. These observables can include IP addresses, domains, file hashes, and other relevant technical artifacts.
Observable Types
Network Indicators
IP Addresses
Domain Names
URLs
Email Addresses
Network Services
File Indicators
File Hashes (MD5, SHA1, SHA256)
File Names
File Paths
File Types
System Indicators
Registry Keys
Process Names
System Commands
User Accounts
Custom Indicators
Custom Observable Types
Organization-specific Indicators
Industry-specific Artifacts
Managing Observables
Adding Observables
Click “Add Observable” button
Select observable type
Enter observable value
Add optional description
Set TLP/PAP levels if applicable
Bulk Operations
Import multiple observables
Export observable list
Bulk update TLP/PAP
Bulk delete observables
Observable Properties
Type classification
Value
Description
TLP (Traffic Light Protocol) level
PAP (Permissible Actions Protocol) level
First/Last seen timestamps
Source information
Observable Enrichment
Automatic Enrichment
Reputation data
Geolocation information
WHOIS data
Historical context
Related indicators
Manual Analysis
Add analysis notes
Link to external sources
Document investigation findings
Tag related observables
Visualization
List View
Sortable columns
Quick filters
Type indicators
Enrichment status
Relationship View
Observable connections
Related alerts
Common patterns
Timeline visualization
Best Practices
Data Quality
Validate observable format
Remove false positives
Document context
Maintain consistent format
Enrichment
Review enrichment data
Update stale information
Document findings
Link related data
Organization
Use consistent naming
Group related observables
Tag effectively
Document relationships
Next Steps
TTPs
Explore tactics and procedures
Similar Alerts
Find related alerts
Alert Detail View
Alert TTPs
Assistant
Responses are generated using AI and may contain mistakes.