Incident Workbench in Log360 Cloud
What is Incident Workbench ?
- The Incident workbench is Log360 Cloud's investigation console that unifies analytics of the core entities such as users, processes, and external threat sources.
- This feature facilitates users to add, compare, and analyze data with enriched integrations like Advanced Threat Analytics.
- Utilize the contextual assessment with risk based profiling, conduct faster root cause analysis by probing the process trees, and minimize the overall time taken to investigate and resolve threats.
Primary use cases:
- Guided threat investigation to reduce the mean time taken to resolve security incidents
- Proactive threat hunting
- Contextual security analytics and risk assessment
- Evidence building for security incidents
- Process tree hunting - finding anomalous process spawning
- External traffic source analysis through risk score from threat feed integrations

Features:
Here are the entities you can analyze using the Incident Workbench:
- Users
Analytics offered: User activity overview and user details.
- Process
Analytics offered: Process hunting tree with parent-child relationships and event timeline.
- Threat sources
Analytics offered: Risk analysis from security vendors using Advanced Threat Analytics integration.
Access and usability:
- Roles and restrictions:
- Operator and guest role members have no access to the Incident Workbench.
- Access: The Incident Workbench can be invoked from multiple dashboards of Log360 Cloud such as reports, log search, compliance, alerts, and more.
- Users can add upto 20 tabs in a single instance of the Incident Workbench and save it to an existing incident or create a new incident.