Manage entity properties

Supported in:

This document explains how you can add or edit entity enrichment properties directly from investigation pages as part of your case investigation in Google Security Operations to work more efficiently during case analysis. You can add up to 100 entity properties to a single entity.

Entity properties

Entities are key components in Google SecOps cases, representing objects involved in security events. Understanding their properties is crucial for effective investigation.

Entities and artifacts differ in several ways:

  • Icon: Entities have black icons with a blue stroke, while artifacts have green icons.
  • Occurrence: The same entity typically appears at most twice in the same event (as a source and a destination). There is no limit on the number of artifacts of the same type in an alert.
  • Scope: Entities can be internal (inside the organization's network) or external. Artifacts are always internal.

For definitions of standard entity properties, see SOARInvolvedEntities.

You can manage properties by adding new ones, editing existing values, or adding entities to alerts. For more information, see:

Add or edit entity properties across pages

Add or edit an entity enrichment property on the following pages:

  • Investigation: In the case view, click Explore to open the Investigation page.
  • Entity Explorer: In the case view, click the Entity Highlights widget and select the relevant entity.
  • Cases (Entities Highlights): In the case view, click an entity in the Entity Highlights widget and then click View more to open a side drawer with entity properties.
  • Cases (Entities Graph): In the case view, click the Entities Graph widget and then click Entity. A side drawer opens with entity properties.

Add an entity property

As part of the investigation, include other entity keys to enrich your case investigation. Identify the kind of malware being used to better understand the threat. This example shows how to create a new entity property called Malware_family.

To add an entity property, follow these steps:

  1. Go to the Cases queue.
  2. Select the Virus Found or Security Risk Found case, and click Explore to open the Investigation page.
  3. Click add Add.
  4. Enter Malware_family as the Key and Trojan.Generic as the Value.
  5. Click Save to add the new entity property.

The new enrichment provides an additional layer of understanding during your case investigation.

Edit an entity property

This example follows a use case where a file is marked as suspicious with low confidence in a case related to a potential malware threat. After running a TI enrichment block and investigation, you're confident that the file is malicious and want to update the confidence_level from Low to High.

To edit an entity property, follow these steps:

  1. Go to the Cases page.
  2. Go to the Virus Found or security risk found case, and click Explore to open the Investigation page.
  3. Click tag File Hash Entity on the Investigation page.
  4. Hold the pointer over the confidence_level value in the side drawer.
  5. Click more_vert More and select View or edit property.
  6. In the View or Edit Entity Property dialog, change the value of Confidence_level from Low to High to highlight the potential risk of the hash entity. You can also select a display format to control how the data appears in the side drawer.
  7. Click Save.

The confidence level of the entity is updated and reflected in the side drawer.

Add new or existing entities

To add new or existing entities, follow these steps:

  1. Click more_vert Alert Options and select Add Entity.
  2. In the Add entities to alert dialog, select an entity from either Add existing entities or Add new entity.
  3. Enter an identifier and click add Add > Apply.

Need more help? Get answers from Community members and Google SecOps professionals.