CyTech AQUILA - Cyber Incident Management (CIM): Cases

Introduction

Case Management Dashboard is a tool that provides a comprehensive overview of security incidents. It offers detailed insights into active and past incidents, including their status, severity, and timeline. The dashboard facilitates investigation and response by integrating real-time alerts, threat intelligence, and collaboration features, while also tracking performance metrics and compliance. This centralized approach enhances the efficiency of managing and resolving security incidents, ensuring timely and effective responses to mitigate risks and improve overall security posture.

image.png

Workflow Stages

1. Tier 1 – Initial Triage Cases


2. Tier 2 – Investigation Cases


3. Tier 3 – Advanced Investigation / Threat Containment


4. Pending – Escalated to Vendor/Support


5. Closed – Resolved or Dismissed Cases

Operational Workflow in SOC Terms
  1. Detection → Tier 1 triages incoming alerts.

  2. Validation → Tier 2 investigates and correlates data.

  3. Escalation → Tier 3 performs deep analysis and containment.

  4. External Escalation → Pending for vendor validation/support.

  5. Closure → Closed with full documentation and resolution notes.

Search and Date Filtering

The Case Management interface provides filtering and search capabilities to streamline case navigation and improve analyst efficiency. These functions enable analysts to quickly locate specific cases or limit the view to a defined time range.

image.png

Date Filter

image.png

Create New Case and Support

The Case Management interface includes two primary action buttons located at the top-right of the screen: Create New Case and Support. These options enable analysts to initiate new investigations and provide clients with direct access to technical support resources when required.

Create New Case

Support

image.png

The Cyber Incident Management (CIM): Cases module serves as a centralized case management system that enables structured handling, tracking, and escalation of security incidents across operational tiers (Tier 1, Tier 2, and Tier 3). It facilitates seamless case transfer and collaboration between analysts, ensuring proper investigation workflows, accountability, and timely resolution.

In addition, the module functions as a comprehensive repository of historical cases, providing valuable reference data for recurring or similar incidents across different clients. This historical intelligence supports more accurate analysis, faster root cause identification, and improved response strategies.

By maintaining detailed case documentation, escalation records, and investigative findings, the CIM: Cases module enhances operational efficiency, standardizes incident response procedures, and strengthens the overall effectiveness of daily security investigations within the Security Operations Center (SOC).

Please refer to the document from the previous sub-module: CyTech AQUILA - Cyber Incident Management (CIM): Alerts

Please refer to the document for the next sub-module: CyTech AQUILA - Cyber Incident Management (CIM): Data Explorer

If you need further assistance, kindly contact our support at support@cytechint.com for prompt assistance and guidance.


Revision #6
Created 13 February 2026 01:38:11
Updated 17 April 2026 03:30:24