A security analyst is investigating a critical incident and needs to quickly add a new piece of information, 'External Threat Actor Group,' to the incident record. This information is unique to this specific incident and may not be relevant for all other incidents of the same type. However, they want this field to be available for future use if similar incidents occur. What is the most efficient way to add this information to the incident without modifying global configurations or incident types?
- AModify the incident's associated playbook to include a task for this field.
- BCreate a new entry in the War Room with the threat actor group information.
- CUpdate the incident layout to temporarily display a new field.
- DAdd a new custom field directly to the incident via the 'Add Field' option in the War Room.
Show answer & explanationAnswer & explanation
Correct answer: D. Add a new custom field directly to the incident via the 'Add Field' option in the War Room.
Cortex XSOAR allows analysts to add new custom fields directly to an incident from the War Room or incident details page. This creates the field and adds it to the current incident without requiring changes to the incident type or global configurations, making it available for future use. This is often referred to as 'ad-hoc field creation'.
Why the other options are wrong
- A. Modifying a playbook dictates *how* a field is populated or used, not its initial creation or availability for ad-hoc input.
- B. A War Room entry is a log of activity or a comment, not a structured incident field for data storage and analysis.
- C. Updating the incident layout is about *displaying* existing fields or fields defined in the incident type, not creating a new field itself.
XSOAR Ad-hoc Custom Fields
Cortex XSOAR allows users to create new custom fields directly from an incident's context (e.g., War Room or Incident Info tab), making them immediately available for that incident and for future use without pre-defining them in the incident type.
- Provides flexibility for capturing unforeseen data points during an investigation.
- The created field is then available for all incident types.
- Useful for dynamic incident response where new data requirements emerge.
Memory trick: Add field from War Room, for data to bloom.