Z-Insights: Investigate Security Incident
Keywords
security incident, threat investigation, cyber incident, malware detected, phishing, threat analytics, incident response, shadow IT, threat trends, firewall blocks, web traffic anomaly, security analytics
Overview
Investigate security incidents by correlating multiple Z-Insights data sources: threat categories, cyber incident logs, firewall actions, web traffic patterns, and shadow IT discovery. This skill builds a timeline and context around security events to support incident response and threat hunting.
Use this skill when: A security analyst needs to investigate detected threats, analyze incident trends, understand the scope of a security event, or review shadow IT and CASB findings.
Workflow
Follow this 6-step process to investigate a security incident.
Step 1: Understand the Incident Scope
Gather from the analyst:
- What type of event? (malware, phishing, data exfiltration, policy violation, anomalous traffic)
- When did it occur or when was it detected?
- Specific user, location, or application involved?
- Alert or ticket reference number?
Step 2: Check Threat Analytics
Get threat super categories:

