# Investigations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-971f8db07a7de468e2f39b7a3c3569b55289bd1d%2Fui-investigations-main.png?alt=media" alt=""><figcaption><p>The Dropzone Investigations Summary Page</p></figcaption></figure>

## What You’ll See Here

* **Investigations by priority**\
  Tabs showing Dropzone’s recommendation on what to review first:

  * **Urgent**
  * **Notable**
  * **Informational**

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>These priority levels can be influenced using <strong>Custom Strategies</strong>.</p></div>
* **Not yet processed investigation status**

  * **Queued**\
    Alerts that have been ingested by Dropzone and are waiting to be investigated.
    * This stage is used when there are already 10 investigations running at once (the current system limit).
  * **Running**\
    Alerts that are currently being investigated by your Dropzone analyst.
  * **Stopped**\
    Alerts that have been ingested but not investigated by Dropzone for a variety of reasons, such as exceeding thresholds set in **System Info** or encountering an error.

    * To investigate these alerts, click **Stopped** and then **Retry**.
    * **Stopped alerts do not count against your license.**

    <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Best practice:</strong> Want to know when an investigation is stopped? Work with your Dropzone team member to set up a notification <strong>Response Action</strong>.</p></div>
  * **Below investigation priority are filters and a search bar allowing you to narrow the view only to investigations you want to see**\
    Filters are of the following types
  * **Review Status** - Dropzone learns by reviewing investigations. This will show you how many you have reviewed.
  * **Conclusion** - The goal of Dropzone is to provide accurate conclusions. Fine tuning will allow you to influence how this happens.
  * **Insight Tag** - Insights about the content of the investigation added by the analyst during an investigation
  * **Alert Type**
  * **MITRE Tactic**
  * **Attach Surface**
  * **Source**

  <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Dropzone will save your last session upon exit. This means you will be able to continue your work where you left off instead of having to add filters every time.</p></div>
* **List of Alerts meeting filter criteria** Below the filters are all alerts matching the search criteria that have been specified. The summary of alerts shows important information about the alerts including the date/time, the title, entities involved, source of the alert, initial Conclusion, and priority.
  * **Alert Title** - The Alert Title is a link that will open the detailed view of the investigation.
  * **Conclusion** - This can be changed directly from the summary page by clicking the dropdown. This works just like changing the conclusion from the detail page.
  * **Priority** - This can be changed directly from the summary page by clicking the dropdown. This works just like changing the conclusion from the detail page.

{% hint style="warning" %}

```
You can **bulk edit** Conclusion and Priority status by selecting multiple items (Checking the box to the left of the alert) which will pop up an option to update all rows that have been selected at the same time.</div>
```

* **Full investigation write-ups**

  * Click into any investigation to see the detailed view:
    * The overall **Summary**
    * Detailed investigative context in **Findings**
    * Supporting artifacts in the **Evidence Locker**
    * Recommended **Remediations** (for *Malicious*, *Suspicious*, and *Inconclusive* alerts only)
    * A **Notes** section for team collaboration
    * A **Changelog** showing the full investigation lifecycle from ingestion to approval

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Best practice:</strong> Check out our guides on how to <a href="../best-practices/deep-dive-into-investigation-reviews">review an investigation</a> and <a href="../best-practices/context-memory">leave context memory</a>.</p></div>

{% endhint %}
