Working with Investigations

Investigations are the core organizational unit in EdgeRun.Ai. They help you track, document, and share your security research.

Creating an Investigation

1

Open the Hunter Portal

Navigate to your Hunter Portal and click the "New Investigation" button in the top navigation or dashboard.

2

Fill in Investigation Details

Provide a descriptive title and initial notes. Choose a category if applicable (Malware, Phishing, Recon, etc.).

3

Start Adding Evidence

Add IOCs, URLs, notes, and screenshots using the web portal or Chrome extension.

Investigation Components

Each investigation can contain multiple types of evidence:

Component Description How to Add
URLs Web pages related to the investigation Portal or Extension "Capture Page"
IOCs Indicators of Compromise (IPs, domains, hashes) Auto-detected or manually added
Notes Your observations and analysis Portal editor or Extension quick notes
Screenshots Visual evidence of pages or content Extension "Take Screenshot"
AI Research AI-generated analysis and reports AI Research panel in portal
Timeline Events Chronological activity log Automatically tracked

Adding Content from the Extension

The Chrome extension makes it easy to capture evidence while browsing:

Capturing a Page

  1. Navigate to the page you want to capture
  2. Click the EdgeRun.Ai extension icon
  3. Click "Capture Page"
  4. Select the investigation to add it to
  5. Add any notes (optional)
  6. Click "Save"

Taking a Screenshot

  1. Click the EdgeRun.Ai extension icon
  2. Click "Take Screenshot"
  3. Choose Visible Area or Full Page
  4. Select the investigation
  5. Click "Save Screenshot"

Adding IOCs

  1. Click the EdgeRun.Ai extension icon
  2. Click "Scan for IOCs"
  3. Review detected IOCs
  4. Select which IOCs to add
  5. Choose the investigation
  6. Click "Add Selected"

Investigation Timeline

Every investigation automatically maintains a timeline showing:

  • When each piece of evidence was added
  • Who added it (for team investigations)
  • What was added or changed
  • Activity metrics like time spent reviewing

The timeline is invaluable for:

  • Understanding the investigation progression
  • Briefing team members or management
  • Creating post-incident reports
  • Auditing investigation activities

Using AI Research

Leverage AI to accelerate your investigation:

Quick Search (Search Mode)

Best for rapid triage and basic lookups:

  1. Open your investigation
  2. Click "AI Research"
  3. Select "Search" mode
  4. Enter your query or select an IOC
  5. Review results in under 1 minute

Deep Analysis (Thinking Mode)

For connecting dots and pattern analysis:

  1. Select "Thinking" mode
  2. Provide context about what you're investigating
  3. Include relevant IOCs or URLs
  4. Wait up to 5 minutes for comprehensive analysis

Comprehensive Research (Research Mode)

For thorough intelligence gathering:

  1. Select "Research" mode
  2. Define your research objectives
  3. Include all relevant selectors
  4. The AI will conduct extensive OSINT gathering
  5. Results typically ready within 2 hours
💡 Pro Tip: Research mode results are automatically saved to your investigation and can be shared with the team. Great for selector deep-dives that everyone can benefit from!

Sharing & Collaboration

EdgeRun.Ai makes team collaboration seamless:

  • Shared Investigations - Team members can view and contribute to the same investigation
  • Real-time Updates - See changes as they happen
  • Shared IOC Libraries - Build a team knowledge base of indicators
  • Investigation Handoffs - Easily transfer ownership between analysts

Investigation Best Practices

  • Use descriptive titles - Make it easy to find investigations later
  • Add context in notes - Explain your thought process
  • Capture evidence early - Pages and content can change or disappear
  • Tag IOCs appropriately - Makes searching and correlation easier
  • Use AI modes strategically - Match the mode to your needs
  • Review timelines - They help with reports and handoffs
📖 Next: Learn about IOC Detection to understand how EdgeRun.Ai automatically finds indicators on web pages.