Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

SIR Workspace Orchestration

Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.

  • SIR Workspace Investigation Canvas
    Security Incident Response Workspace allows the Security Analysts to view the key information associated with the security incident during the incident remediation process. The key information also includes the related lists such as Observables, Threat Lookup Results, Sighting Search, Observable Enrichment, and so on.
  • Unified experience framework for integrations powered by Capability Framework
    In the classic UI, the experience is disjointed when performing orchestration activities such as running threat look, performing sighting search, and so on. Each capability has its own experience while executing it. In the new workspace, there is unified experience across all capabilities.

Parent Topic:Working with Security Incident Records

Related topics

Security Incident Overview section

Security Incident Details section

Security Incident Response Tasks

Security Incident Response Other Records

Security Incident Response Post Incident Review

Update information in security incident related records

TISC integration within SIR Workspace

Reports in Security Incident Response

Collaborate using conference call or chat in Security Incident Response

Viewing incident details with a relationship graph

MITRE attack and defend technique graph

View and filter the incident timeline