> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/best-practices/deep-dive-into-investigation-reviews.md).

# Investigation Reviews Deep Dive

New to Dropzone? We recommend starting with our overview of [The Platform](https://docs.dropzone.ai/platform), specifically the [Dashboard](https://docs.dropzone.ai/platform/dashboard) and [Investigations](https://docs.dropzone.ai/platform/investigations) sections, to familiarize yourself with how alerts flow through the system.

Once you’re comfortable, you’re ready to begin reviewing investigations.

## Overview: Investigation Reviews

**Investigation Reviews** enable SOC analysts to validate AI-completed alert investigations for accuracy and completeness. This process ensures high-quality security analysis while creating feedback loops that continuously improve Dropzone’s automated investigation capabilities.

Reviews help:

* Confirm AI conclusions align with your SOPs
* Reduce false positives
* Capture institutional knowledge
* Improve future investigation accuracy

You may follow your existing **Standard Operating Procedures (SOPs)** or use Dropzone’s built-in **Quality Assurance checklist** when reviewing investigations.

***

## What You’ll See Here

* **Investigation Queue Management**\
  Efficient filtering and prioritization of completed investigations
* **Review Interface Navigation**\
  A walkthrough of all investigation review components
* **Feedback Systems**\
  Context Memory creation and Custom Strategy development
* **Quality Assurance Workflows**\
  Structured approaches to validating investigations
* **Outcome Management**\
  Conclusion changes and investigation status updates
* **Knowledge Base Integration**\
  Leveraging reviews for long-term organizational learning

***

## How Investigation Reviews Work

### Review Process Model

1. **Investigation Completion**\
   The AI completes an automated investigation of security alerts.
2. **Review Queue**\
   Completed investigations enter the review queue with an **In Review** status.
3. **Analyst Assessment**\
   Human analysts evaluate the AI’s conclusions, evidence, and reasoning.
4. **Feedback Integration**\
   Review outcomes improve AI performance through Context Memory and strategies.
5. **Status Updates**\
   Investigations move from **In Review** to **Reviewed**.

***

## Review Components

### Investigation Data

Each investigation review provides access to:

* **Complete Alert Context**\
  Original alert details, triggering rules, and metadata
* **AI Analysis Results**\
  Investigative findings, evidence, and reasoning
* **Supporting Evidence**\
  API calls, queries, and data sources used
* **Recommended Actions**\
  Suggested follow-up steps based on the investigation outcome

### Review Tools

* **Approval Workflows**\
  Single-click approval for accurate investigations
* **Conclusion Modification**\
  Ability to change investigation outcomes with justification
* **Context Memory Creation**\
  Add organizational knowledge for future AI reference
* **Custom Strategy Development**\
  Encode reusable investigation logic for alert patterns

***

## Quality Assurance Model

Investigation reviews support structured quality assurance across several dimensions:

* **Accuracy Validation**\
  Confirm AI conclusions match evidence and organizational context
* **Completeness Assessment**\
  Ensure all relevant investigative angles were explored
* **False Positive Reduction**\
  Identify and correct misclassified benign activity
* **Knowledge Transfer**\
  Capture institutional expertise to improve future investigations

***

## Accessing Investigations

### Login and Tenant Selection

* Navigate to your Dropzone AI tenant home page (for example, `https://mycompany.dropzone.app`)
* If you have multiple tenants, use the tenant tree to navigate between environments

### Investigation Queue Access

* In the left navigation menu, click "Investigations"
* Select investigations by **Priority**:
  * Urgent
  * Notable
  * Informational
* Use filters to refine results by:
  * Conclusion
  * Interview usage
  * Source
  * And more

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-49c82f72fe97607b39a0bcc402d0a14bc0a01563%2Fui-investigations-queue-access.png?alt=media" alt=""><figcaption><p>The Investigation Summary Page - Filters</p></figcaption></figure>

***

## Investigation components

Each investigation contains multiple sections, detailed below.

#### Notes

Located in the upper right, the Notes section is a space for analyst observations and feedback to allow for team communication around the investigation.

Notes currently do not influence AI behavior directly.

#### Investigation Threads

Here you will find the AI-generated questions guiding the investigation.

Click the carrot on the right of each question to expand and view all findings derived from Evidence Locker entries, including:

* **Thread Findings**\
  A detailed view of all information used in the finding (device information, filenames, logins, user IDs, etc)
* **Sources Queried**\
  A list of all sources used in the finding
* **Additional Threads**\
  Further questions generated by the result of the finding

#### Actions

Here you will find a graph of the AI's actions throughout the investigation, grouped by stage.

You may also click the button labeled "AI Action Graph" in the Table of Contents to see this visualization.

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-d988039c0aec4b2fb14c39aded7942d34ebef60a%2Fui-investigations-header.png?alt=media" alt=""><figcaption><p>Example Investigation Header</p></figcaption></figure>

#### Alert Claim

An overview of the triggering alert and detection rule. Below is a list of **Associated Entities** (Hosts, users, IP addresses, and other related entities) involved in the alert.

Click "View All Details" to see the root code run and returned during the investigation.

#### Conclusion Reasoning

The AI-determined outcome with supporting context and confidence. Below is a list of applicable **Insight Tags** detailing the content of the investigation, such as common scams and flagged behaviors.

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-eeb38837c979951fc892e4b7ce56049481d56d5a%2Fui-investigations-summary.png?alt=media" alt=""><figcaption><p>Example Investigation Summary Section</p></figcaption></figure>

#### Key Findings

Summaries of the five most significant findings influencing the AI’s conclusion

#### Interviews Tab

{% hint style="info" %}
This feature is only available if [AI Interviewer](https://docs.dropzone.ai/platform/settings/ai-interviewer) is enabled.
{% endhint %}

Here you will find a record of all interactions with the AI interviewer involved in this investigation.

* **Interview Details**\
  State, creation time, last update, and recipient
* **Interview Question and Context**\
  The question asked and why it was generated
* **Resulting Communications**\
  Full conversation if the recipient responds
* **Approval Button**\
  Available when auto-approval is not enabled

#### Containment Actions

Here you may add containment actions based on the investigation outcome. To do so, do the following:

* Click "+ Add Actions"
* Select the action you wish to perform, e.g. "Contain Device"
* Enter the entity you wish to contain, e.g. "desktop1"
* Add actions until done
* Click "Save"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-1dcb44fc9c5cf3bdf4cf0cb38ebf1ca2b507b38b%2Fui-investigations-containment-action.png?alt=media" alt=""><figcaption><p>Example Investigation Containment Actions</p></figcaption></figure>

#### Recommendations

A list of recommended remediation actions to contain the threat. You may mark them as completed by clicking "Mark complete" on the right

{% hint style="info" %}
Remediation recommendations are not shown for investigations concluded as **Benign** or **Inconclusive**.
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-785608a5dbb498bf7db501a384557fc7bcea8632%2Fui-investigations-recommendations.png?alt=media" alt=""><figcaption><p>Example Investigation Recommendations</p></figcaption></figure>

#### Evidence Locker

A record of all evidence used in the investigation.

* **Source**\
  The external systems accessed during the investigation
* **Request**\
  The specific query and/or action performed by the AI
* **Response**\
  Click "View Response" to see the raw and processed results from each source

#### Changelog

A chronological record of all investigation events, including prior review activity and modifications.

***

## Investigation Review

### Standard Approval Process

* Verify the Conclusion aligns with your SOPs
* Select **Close** to keep the same Conclusion
* The investigation moves to **Reviewed**

### Conclusion Modification

If the conclusion does not align with your SOPs, do the following:

* Use the dropdowns in the top-right to update the Conclusion to:
  * Malicious
  * Suspicious
  * Inconclusive
  * Benign

{% hint style="info" %}
Dropzone treats **Malicious** and **Benign** as final states, but teams may use statuses however best fits their workflow.
{% endhint %}

* Add notes explaining why the Conclusion was changed

{% hint style="info" %}
These notes may be used to guide context memory if the investigation status is changed to either Malicious or Benign. To improve future Dropzone analysis, check the box labeled "Use this note to guide context memory generation."
{% endhint %}

* Click "Save" to move the investigation to **Reviewed**

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-3fc396e9f196cbf2ff44132577c9b74f15ff2d90%2Fui-investigations-edit-conclusion.png?alt=media" alt=""><figcaption><p>Example Investigation Review</p></figcaption></figure>

***

## Onboarding Recommendation

During onboarding, we recommend reviewing **10–15+ investigations per day** for the first few weeks, prioritizing:

* Urgent
* Malicious
* Suspicious

This accelerates alignment with your internal SOPs and helps tune Dropzone quickly.

***

## What’s Next?

Once you’re comfortable reviewing investigations, explore our **Best Practice guides** for:

* Building Custom Strategies
* Setting up Response Actions
* Leveraging Context Memory

{% hint style="warning" %}
Some advanced features are available to **Admins only**.
{% endhint %}
