Cisco Threat Response Casebook (beta)

Cisco Threat Response Casebook (beta)

Casebook and Investigation Widgets

What is Cisco Threat Response Casebook (beta)?
Cisco Threat Response Casebook (beta) is a chrome extension provided by Threat Response. It's a powerful tool that aids in saving, sharing, and enriching data in the course of threat analysis. It functions by allowing users to track notes and details as they unravel leads in Threat Response. Added to its features, users can inspect observables from the browser's context menu and initiate a swift investigation on a single observable through simple commands in the URL bar.
Merlin
Stats
By: Cisco XDR
Users: 2,000+
Rating: 4.70 (53)
Version: 0.9.6 (Last updated: 2020-10-01)
Creation date: 2020-01-30
Risk impact: High risk impact
Risk likelihood: Low risk likelihood
Manifest version: 2
Permissions:
  • activeTab
  • contextMenus
  • storage
  • https://visibility.int.iroh.site/
  • https://private.intel.int.iroh.site/
  • https://visibility.test.iroh.site/
  • https://private.intel.test.iroh.site/
  • https://visibility.apjc.amp.cisco.com/
  • https://private.intel.apjc.amp.cisco.com/
  • https://visibility.eu.amp.cisco.com/
  • See more
Size: 392.19K
Stats date:

Other platforms

Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions? Install Chrome-Stats extension to view Chrome-Stats data as you browse the Chrome Web Store.
Chrome-Stats extension
Merlin
Summary

Once installed, please visit your region's Threat Response API Clients page to create Casebook client credentials. In order for the casebook extension to function, you must select ALL SCOPES when adding your new API Client.

The Cisco Threat Response Casebook is a powerful and convenient tool provided by Threat Response for saving, sharing, and enriching your threat analysis. Use cases for tracking notes and other bits and pieces of information as you follow leads in Threat Response. You can add observables and notes as you pursue your quarry.

Along with the Casebook, you'll be able to find and inspect observables through the browser's context menu. Select text on a page, or select a single observable, open the context menu and choose the Cisco Threat Response menu option. The selection will be inspected for observables and you'll be presented with information and actions to help with your investigations.

You can also launch an investigation on a single observable quickly by typing "ctr [space]" in the URL bar then typing or pasting an observable.

User reviews
User reviews summary
These summaries are automatically generated weekly using AI based on recent user reviews. Chrome Web Store does not verify user reviews, so some user reviews may be inaccurate, spammy, or outdated.
Pros
  • Easy to use
  • Improves security
  • Useful for threat hunting
Cons
  • Still in beta
  • Needs more testing
  • Some reviews mention promise but current unknown effectiveness
Most mentioned
  • Threat minimization
  • Cisco
  • Security enhancement
Recent reviews
Ease of use. Saves time in search of threats and is very efficient
by Shannon LR Shannon LR, 2019-10-03

Great quality of life extension
by Emily Burjaw Emily Burjaw, 2019-05-07

Awesome tool! Easy to use. Makes grabbing IoCs a painless task.
by Maul “Roc” Maul “Roc”, 2020-01-30
View all user reviews
Safety
Risk impact

Cisco Threat Response Casebook (beta) is risky to use as it requires a number of sensitive permissions that can potentially harm your browser and steal your data. Exercise caution when installing this extension. Review carefully before installing. We recommend that you only install Cisco Threat Response Casebook (beta) if you trust the publisher.

Risk likelihood

Cisco Threat Response Casebook (beta) has earned a fairly good reputation and likely can be trusted.

Upgrade to see risk analysis details
Screenshots
Similar extensions

Here are some Chrome extensions that are similar to Cisco Threat Response Casebook (beta):