> ## Documentation Index
> Fetch the complete documentation index at: https://docs.contraforce.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Entity Insights

> Enrich your investigations with detailed entity insights. View sign-in logs, audit trails, threat intelligence, and related incidents for users, devices, IPs, and more.

Entity Insights provide rich context during incident investigations. Instead of switching between tools to gather information about affected users, devices, or IP addresses, ContraForce surfaces relevant data directly within the incident view.

<Info>
  Available insights vary by entity type and your connected data sources. The more integrations you have enabled, the richer your entity insights will be.
</Info>

## Why Entity Insights Matter

<CardGroup cols={3}>
  <Card title="Faster Investigations" icon="bolt">
    Access critical context without leaving ContraForce
  </Card>

  <Card title="Complete Picture" icon="magnifying-glass-chart">
    See related incidents, logs, and threat intel in one place
  </Card>

  <Card title="Better Decisions" icon="brain">
    Make informed response choices with full entity context
  </Card>
</CardGroup>

***

## Available Insights by Entity Type

ContraForce provides different insights depending on the entity type associated with an incident.

<Tabs>
  <Tab title="User">
    **User entities** include accounts, identities, and mailboxes.

    | Insight               | Description                                                             |
    | --------------------- | ----------------------------------------------------------------------- |
    | **Related Incidents** | Other incidents involving this user                                     |
    | **Sign-In Logs**      | Authentication history including locations, devices, and outcomes       |
    | **Audit Logs**        | Administrative actions and changes made by or to this user              |
    | **User Insights**     | Account details, group memberships, risk score, and profile information |

    *Use cases: Investigating compromised accounts, tracking lateral movement, understanding user behavior patterns*
  </Tab>

  <Tab title="Device">
    **Device entities** include endpoints, servers, and mobile devices.

    | Insight               | Description                                                  |
    | --------------------- | ------------------------------------------------------------ |
    | **Timeline**          | Chronological view of events and activities on the device    |
    | **Related Incidents** | Other incidents involving this device                        |
    | **Device Insights**   | Hardware details, OS version, security state, exposure level |

    *Use cases: Tracking malware spread, understanding attack chains, assessing device health*
  </Tab>

  <Tab title="IP Address">
    **IP entities** include source and destination addresses from network activity.

    | Insight               | Description                                           |
    | --------------------- | ----------------------------------------------------- |
    | **Related Incidents** | Other incidents involving this IP address             |
    | **IP Insight Logs**   | Geolocation, reputation, ASN, and historical activity |

    *Use cases: Identifying malicious infrastructure, tracking C2 communications, investigating data exfiltration*
  </Tab>

  <Tab title="Email">
    **Email entities** include messages, attachments, and sender/recipient information.

    | Insight               | Description                                                     |
    | --------------------- | --------------------------------------------------------------- |
    | **Email Insights**    | Message details, headers, attachments, and delivery information |
    | **Related Incidents** | Other incidents involving this email or sender                  |

    *Use cases: Investigating phishing campaigns, tracking malicious attachments, analyzing email-based attacks*
  </Tab>

  <Tab title="File">
    **File entities** include executables, documents, scripts, and their hashes.

    | Insight               | Description                                                           |
    | --------------------- | --------------------------------------------------------------------- |
    | **Related Incidents** | Other incidents involving this file or hash                           |
    | **File Insights**     | File metadata, hash values, detection ratios, and threat intelligence |

    *Use cases: Tracking malware variants, identifying suspicious files, correlating file-based IOCs*
  </Tab>

  <Tab title="URL">
    **URL entities** include web addresses and domains involved in incidents.

    | Insight               | Description                                                      |
    | --------------------- | ---------------------------------------------------------------- |
    | **Related Incidents** | Other incidents involving this URL or domain                     |
    | **URL Insights**      | Domain reputation, registration details, and threat intelligence |

    *Use cases: Investigating phishing links, blocking malicious domains, tracking web-based threats*
  </Tab>
</Tabs>

***

## Accessing Entity Insights

Follow these steps to view insights for any entity in an incident.

<Steps>
  <Step title="Open the Incident">
    From the Command Page, click the **Incident ID** in the Incidents table to open the compact incident overview
  </Step>

  <Step title="Expand to Detailed View">
    Click the **diagonal arrows** icon (next to the X) in the top right corner to open the detailed incident view
  </Step>

  <Step title="Select Entities Tab">
    Click the **Entities** tab to see all associated entities
  </Step>

  <Step title="Open Entity Menu">
    Click the **three dots (⋮)** on any entity row to see available insights
  </Step>

  <Step title="Select Insight Type">
    Choose the insight you want to view from the dropdown menu
  </Step>
</Steps>

<Frame>
  <img src="https://mintcdn.com/contraforce/Azjy3b-qdR3SefWt/entityinsights.png?fit=max&auto=format&n=Azjy3b-qdR3SefWt&q=85&s=793c83091674a3817333bc0edfe966cc" alt="Entity insights menu for a user" width="2296" height="970" data-path="entityinsights.png" />
</Frame>

***

## Working with Insights

### Multiple Insights

You can open multiple insights simultaneously:

* Each insight opens in its own **tab** within the popup window
* Switch between tabs to compare information
* The popup window can be **resized** for better viewing

<Frame>
  <img src="https://mintcdn.com/contraforce/Azjy3b-qdR3SefWt/entityinsightdrawer.png?fit=max&auto=format&n=Azjy3b-qdR3SefWt&q=85&s=30e70127ea49b87385179512ef04a527" alt="Multiple entity insight tabs" width="3188" height="858" data-path="entityinsightdrawer.png" />
</Frame>

### Insight Details

Each insight type displays relevant information in an organized format:

<AccordionGroup>
  <Accordion title="Sign-In Logs">
    **Columns typically include:**

    * Timestamp
    * Sign-in status (Success/Failure)
    * IP address and location
    * Device and browser information
    * Conditional access results
    * Risk level

    **Filter by:** Date range, status, location, risk level
  </Accordion>

  <Accordion title="Audit Logs">
    **Columns typically include:**

    * Timestamp
    * Activity type
    * Target resource
    * Initiated by (user/service)
    * Result (Success/Failure)

    **Filter by:** Date range, activity type, target
  </Accordion>

  <Accordion title="User Insights">
    **Information displayed:**

    * Display name and UPN
    * Job title and department
    * Manager
    * Group memberships
    * Account status
    * Risk score
    * Last sign-in
  </Accordion>

  <Accordion title="Device Insights">
    **Information displayed:**

    * Device name and ID
    * OS platform and version
    * Health state
    * Exposure level
    * Last seen timestamp
    * Compliance status
    * Logged-on users
  </Accordion>

  <Accordion title="IP Insight Logs">
    **Information displayed:**

    * Geolocation (country, city)
    * ASN and ISP
    * Reputation score
    * Associated domains
    * Historical activity
    * Threat intelligence matches
  </Accordion>

  <Accordion title="File Insights">
    **Information displayed:**

    * File name and path
    * SHA256, SHA1, MD5 hashes
    * File size
    * First/last seen
    * Detection ratio
    * Threat intelligence enrichment
  </Accordion>
</AccordionGroup>

***

## Related Incidents

The **Related Incidents** insight is available for all entity types and shows other incidents where the same entity appears.

### Why This Matters

* **Pattern Detection** — Identify if an entity is repeatedly involved in security events
* **Attack Chain Analysis** — Understand how an attacker moved through your environment
* **Scope Assessment** — Determine the full impact of a compromise
* **False Positive Identification** — Recognize legitimate activity that triggers multiple alerts

### Using Related Incidents

| Column          | Description                        |
| --------------- | ---------------------------------- |
| **Incident ID** | Click to open the related incident |
| **Title**       | Brief description of the incident  |
| **Severity**    | High, Medium, Low, Informational   |
| **Status**      | Current state of the incident      |
| **Created**     | When the incident was detected     |

<Tip>
  If you see the same entity in multiple high-severity incidents, prioritize investigating that entity—it may indicate an active compromise.
</Tip>

***

## Threat Intelligence Enrichment

Some entity insights include threat intelligence from integrated sources.

### Supported Enrichments

| Entity Type    | Threat Intel Data                                        |
| -------------- | -------------------------------------------------------- |
| **IP Address** | Reputation, malicious activity history, blocklist status |
| **File/Hash**  | VirusTotal detections, malware family, first seen date   |
| **URL/Domain** | Reputation, phishing indicators, domain age              |
| **User**       | Compromised credential alerts, risk indicators           |

<Info>
  Threat intelligence enrichment requires integration with tools like VirusTotal or Microsoft Defender Threat Intelligence. Contact your administrator to enable additional enrichment sources.
</Info>

***

## Integration-Specific Insights

Available insights depend on which integrations are connected to your workspace.

### Microsoft Defender for Endpoint

* Device timeline and alerts
* User sign-in and audit logs
* Email trace and threat detection
* File and URL analysis

### Microsoft Sentinel

* Log Analytics query results
* Custom entity enrichments
* Watchlist matches
* Threat intelligence indicators

### Third-Party Integrations

Additional insights may be available based on your connected tools:

* **CrowdStrike** — Device details, detection history
* **SentinelOne** — Agent status, threat indicators
* **QRadar** — Offense correlation, log data

***

## Best Practices

<AccordionGroup>
  <Accordion title="Start with Related Incidents">
    Always check Related Incidents first. If an entity appears in multiple incidents, it may be the key to understanding the attack scope.
  </Accordion>

  <Accordion title="Correlate sign-in anomalies">
    Compare sign-in logs with the incident timeline. Look for unusual locations, impossible travel, or authentication failures before the incident.
  </Accordion>

  <Accordion title="Use audit logs for privilege escalation">
    When investigating compromised accounts, review audit logs for privilege changes, group membership modifications, or unusual administrative actions.
  </Accordion>

  <Accordion title="Check device timeline for malware">
    For device-based incidents, the timeline shows the sequence of events leading to detection—crucial for understanding initial access and lateral movement.
  </Accordion>

  <Accordion title="Document key findings">
    Copy important insight data to incident comments for team visibility and post-incident documentation.
  </Accordion>
</AccordionGroup>

***

## Troubleshooting

### Common Issues

| Issue                     | Possible Cause                      | Solution                                               |
| ------------------------- | ----------------------------------- | ------------------------------------------------------ |
| **No insights available** | Entity type not supported           | Check the Capabilities Matrix for supported entities   |
| **Missing sign-in logs**  | Entra ID integration not connected  | Verify Azure AD/Entra ID connector status              |
| **Empty device timeline** | Defender for Endpoint not onboarded | Confirm MDE integration is enabled                     |
| **No threat intel data**  | Enrichment source not configured    | Contact admin to enable VirusTotal or other TI sources |

***

## Related Guides

<CardGroup cols={2}>
  <Card title="Incident Management Guide" icon="book" href="/guides/getting-started/incident-management">
    Complete incident investigation workflow
  </Card>

  <Card title="Security Workbench" icon="screwdriver-wrench" href="/guides/getting-started/workbench-overview">
    Deep dive investigation interface
  </Card>

  <Card title="Gamebooks" icon="bolt" href="/guides/getting-started/what-are-gamebooks">
    Take action on entities after investigation
  </Card>
</CardGroup>

***

<Note>
  Questions about entity insights? Contact us at [support@contraforce.com](mailto:support@contraforce.com).
</Note>
