Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Working with Investigation Canvas

The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.

By using the investigation canvas, threat analysts can effectively:

  • Map Relationships: Visualize node connections between various entities such as observables, indicators of compromise (IOCs), threat actors, attack patterns, affected assets, and more. Each object on the investigation canvas is represented by a specific color, along with its object type, node type, and status. The status reflects the object's reputation such as Suspicious, Low, or Critical for observables and other object types. Indicators are displayed with their associated threat severity to help prioritize analysis.
  • Link cases or canvases: Link a case or canvas to enhance the analysis and provide a more comprehensive view of the threat landscape within the case management.
    • The linking feature enables analysts dynamically add or remove nodes. This also populates the existing relationships between the nodes to the canvas.
    • Temporary Relationship graphs by saving relationships separately within the context of the Investigation Canvas.
  • MITRE technique associations: Associate or remove MITRE techniques with nodes directly on the canvas and provide analysis on the MITRE kill chain card.

Entry Points for the investigation canvas

  1. First entry point: New Blank Canvas: This entry point should allow the analysts to open a new and blank canvas without any nodes or links.
  2. Second Entry Point: Open Canvas in Case Investigation:

    1. This entry point opens an existing investigation case and allows to edit, modify, and rename the canvas.
    2. A new canvas with existing artifacts as nodes.
  3. Working with Actions on the Investigation Canvas
    This section describes the various actions that you can perform on the investigation canvas.

  4. Linking an existing case from Investigation Canvas
    Use this section to link an existing case from the investigation canvas.
  5. Creating a Case and Linking from Investigation Canvas
    Use this section to create and link a case(s) from an investigation canvas.
  6. Linking Canvas from a Case
    Use this section to link a canvas from a case.
  7. Creating an investigation canvas
    Create canvas to add observables from threat intelligence library.
  8. Adding a new node to the canvas
    Use this section to create and add new entities, including observables or objects, directly from the investigation canvas.
  9. Using Timeline in Investigation Canvas
    The Timeline feature of the Investigation Canvas within the Threat Intelligence Security Center (TISC) empowers analysts to visualize, create, and edit timeline events associated to entities during investigations. This capability significantly enhances the effectiveness of temporal analysis.
  10. Investigation canvas and MITRE ATT&CK
    In the Investigation Canvas, you can view the MITRE ATT&CK techniques and sub-techniques associated with all nodes currently present on the canvas.

Parent Topic:Threat Analyst Workbench

Related topics

Workbench Overview

Creating cases using Threat Analyst Workbench

Summarize a Case with Now Assist for Threat Intelligence Security Center

Creating case task using Threat Analyst Workbench

Add artifacts to case(s) or case task(s)

Run Enrichment Actions within a case

Generate a Case Report using generative AI

Generate a Case Report using a template

Create a security incident from a TISC case

Upload Secure File Attachments

Using playbooks