Skip to content

Create and add to cases

You can create new cases from detections and events or create empty cases to add detections and events to later.

Sophos MDR requirements

For MDR customers, Investigation and Other case types require a Managed By value that determines who will manage the case. You can't change Managed By after you set it. For details, see Cases in Sophos MDR.

Create cases from individual detections or events

To create a new case from an individual detection or event, do as follows:

  1. When viewing a detection or event, click the three dots or Actions menu, then choose Add to Case.

    Create new case.

  2. Select New Case.

  3. Choose a Case Type and optional template, enter a case title, and choose a Case Severity and Case Status.

    Sophos MDR customers must also choose a Managed By value when creating Investigation and Other case types.

  4. Click the Pencil icon in the Key Findings section to add initial findings and context.

    Add to case.

  5. Click Create New Case.

Create cases from multiple detections or events

To create a new case from multiple detections or events, such as on the Detections page or in search results, do as follows:

  1. Select the checkboxes from a table of detections or events.

    Note

    You can add a maximum of 50,000 detections to a case.

  2. Click Actions > Add to Case.

    Create new case from multiple detections.

  3. Select New Case.

  4. Choose a Case Type and optional template, enter a case title, and choose a Case Severity and Case Status.

    Sophos MDR customers must also choose a Managed By value when creating Investigation and Other case types.

  5. If adding detections, choose to add just the detections you selected or to add all detections from the table.

  6. Click the Pencil icon in the Key Findings section to add initial findings and context.

    Create new case from multiple detections modal.

  7. Click Create New Case.

Note

Due to processing time, it may take a few minutes for the evidence to be visible in the case.

Create new empty cases

To create a new empty case to add to later, do as follows:

  1. Go to Security Operations > Cases.
  2. On the Cases page, click + Add New above the table.

    Add new case.

  3. Choose a Case Type and optional template, enter a case title, and choose a Case Severity and Case Status.

    Sophos MDR customers must also choose a Managed By value when creating Investigation and Other case types.

  4. Click the Pencil icon in the Key Findings section to add initial findings and context.

    Create new case.

  5. Click Submit.

Add individual detections or events to an existing case

To add an individual detection or event to an existing case, do as follows:

  1. When viewing a detection or event, click the three dots or Actions menu, then choose Add to Case.
  2. Select Existing Case and then click the menu, search for a case, and select it.

    Add detection to case.

  3. Click Save to Existing Case.

Add multiple detections or events to an existing case

To add multiple detections or events to an existing case at once, such as on the Detections page or in search results, do as follows:

  1. Select the checkboxes from a table of detections or events.
  2. Click Actions > Add to Case.
  3. Select Existing Case and then click the menu, search for a case, and select it.
  4. If adding detections, choose to add just the detections you selected or to add all detections from the table.

    Add multiple detections to case.

  5. Click Save to Existing Case.

Note

Due to processing time, it may take a few minutes for the evidence to appear in the case.