Incident Workbench
Log360 Cloud now introduces an exclusive threat investigation console for advanced contextual analytics. This console is called the 'Incident Workbench' and can be invoked from multiple dashboards of Log360 Cloud. The features include the following:
- User activity overview and AD object details
- Process analytics
This analysis comprises process spawning with parent-child process trees available in multiple graphical formats.
- Threat analytics
This analysis is offered through the integration of Log360 Cloud's Advanced Threat Analytics for in-depth risk analysis of IPs, URLs, and Domains. Along with the threat analysis, the integration of VirusTotal, one of the largest live threat feeds, is also introduced in this release and will be available in the Incident Workbench
Users can add upto 20 analytical tabs in a single instance of the Incident Workbench and can save it to Incidents as Threat Evidences.
Device summary
Log360 Cloud now introduces an analytical console to view the overall device summary events. This console can be invoked from multiple dashboards of Log360 Cloud. Users can find event summary for the selected period,device severity events, and alerts summary.