Collaboration in Iris Investigate
Iris Investigate enables team collaboration through investigation sharing, search hashes, reporting, and data export. Work together to analyze threats, share findings, and coordinate investigations.
Groups
Section titled “Groups”A Group consists of the other Iris Investigate users at your company. Groups enable:
- Shared tags: Tags are visible to all group members
- Shared investigations: Investigations can be shared with view or edit permissions
- Tag Manager: View all tags used across your group
- Collaboration: Multiple users can work on the same investigation
Share investigations
Section titled “Share investigations”By default, investigations are private to the originating user. Share investigations with your group to enable collaboration.
Share an investigation
Section titled “Share an investigation”
To share an investigation with your group:
- Open the Product Menu.
- Hover over your active investigation.
- Select Edit Investigation.
- Choose an access level for group members:
- View: Read-only access to the investigation
- Add branches: Can add new search nodes
- Delete branches: Can delete search nodes
- Select Save.
Access shared investigations
Section titled “Access shared investigations”Shared investigations appear in your investigation list in the Product Menu under the heading Investigations shared with you.
Collaboration notifications
Section titled “Collaboration notifications”When another user creates a new search node in your shared investigation:
- The node appears in Search History with a sharing icon
- You receive a browser notification
This keeps you informed of team activity in real-time.
Unshare an investigation
Section titled “Unshare an investigation”To stop sharing an investigation:
- Open the Product Menu.
- Hover over the investigation.
- Select Edit Investigation.
- Remove the sharing permissions.
- Select Save.
The investigation disappears for other group members immediately.
Search hashes
Section titled “Search hashes”Search Hashes share a specific search to anyone with Iris Investigate, including people outside of your group.
What search hashes include
Section titled “What search hashes include”Search hashes reproduce:
- Search terms and filters
- Advanced search parameters
- Field selections
What search hashes don’t include
Section titled “What search hashes don’t include”Search hashes don’t include:
- Tags
- Search notes
- Investigation context
- User-specific annotations
Export a search hash
Section titled “Export a search hash”- Hover over a search node in the search history graph.
- Select the export icon.
- The search hash copies to your clipboard.
- Share the hash with others.
Use search hashes
Section titled “Use search hashes”Recipients can:
- Paste the search hash into Iris Investigate
- Reproduce your exact search
- View the same results (subject to data updates)
The Investigate API can also use search hashes to query for the results of an advanced search first created through the Investigate web UI.
Export Pivot Engine results
Section titled “Export Pivot Engine results”Export your Pivot Engine results for analysis in external tools or sharing with stakeholders.
Export formats
Section titled “Export formats”To export your Pivot Engine results:
- Locate the DOWNLOAD button near the top of the Pivot Engine Data Panel, next to the page navigation controls.
- Select DOWNLOAD.
- Choose an export format:
- CSV: Comma-separated values for spreadsheet applications
- STIX 1.2: Structured Threat Information Expression format version 1.2
- STIX 2.0: Structured Threat Information Expression format version 2.0
Export contents
Section titled “Export contents”The export includes:
- Your full Pivot Engine table
- All visible columns
- Fields containing multiple values have repeated columns to maintain a single value per table element
Generate investigation reports
Section titled “Generate investigation reports”The Generate Investigation Report button in the Product Menu creates a PDF (Portable Document Format) containing comprehensive investigation details.
Report contents
Section titled “Report contents”Reports include:
- Title and description: Investigation metadata
- Investigation path: Tabular form with search notes
- Pivot Engine data: Tabular form matching your column configuration
- Statistics: Via the Stats Data Panel
- Visualizations: From the Visualization Data Panel
Report generation
Section titled “Report generation”The system generates reports from the viewpoint of the current selected node in your investigation.
For a complete investigation report:
- Select the final node in your search history.
- Ensure required panels are visible:
- Stats Data Panel
- Visualization Data Panel
- Pivot Engine Data Panel
- Select Generate Investigation Report from the Product Menu.
Report limitations
Section titled “Report limitations”- Pivot Engine results: For result sets over 500 domains, the report includes only the currently displayed page
- Visualizations: Large result sets may not display well; download high-res images from the Visualization Data Panel directly
- Panel visibility: Only visible panels are included in the report
Manually trigger web content updates
Section titled “Manually trigger web content updates”Multiple Iris Investigate data panels contain web-related data that the web crawler gathers.
Default web crawler behavior
Section titled “Default web crawler behavior”The web crawler:
- Gathers data upon first discovery of a domain
- For domains with a risk score of 70 or higher: Automatically gathers data every 3 months
- For domains watched in Iris Detect: Gathers data daily
Manual updates
Section titled “Manual updates”To update web-related data outside of these default settings:
- Navigate to one of the following data panels:
- Pivot Engine
- Screenshot History
- Domain Profile
- SSL Profile
- Select the Update Content button.
- The web crawler queues the domain(s) for data collection.
Web crawler data types
Section titled “Web crawler data types”The web crawler gathers:
- Screenshot
- Website title
- Website response code
- Redirect domain
- Server type
- Website trackers
- SSL certificate aspects
Best practices
Section titled “Best practices”Investigation sharing
Section titled “Investigation sharing”- Set appropriate permissions: Use “View” for stakeholders, “Add branches” for analysts.
- Document your work: Add notes before sharing so others understand your analysis.
- Name investigations clearly: Help team members identify relevant investigations.
- Regular cleanup: Unshare completed investigations to reduce clutter.
Search hashes
Section titled “Search hashes”- Export key searches: Share reproducible searches with your team.
- Document context: Explain what the search hash represents.
- Version control: Note when you exported the hash (data may change over time).
Reporting
Section titled “Reporting”- Select the right node: Generate reports from the final node for complete coverage.
- Verify panel visibility: Ensure all required panels are displayed.
- Download visualizations separately: For high-quality images in presentations.
- Add context: Include investigation description for report readers.
Data export
Section titled “Data export”- Choose the right format: CSV for analysis, STIX for threat intelligence platforms.
- Document export date: Note when data was exported for version tracking.
- Verify columns: Ensure all needed fields are visible before exporting.
Next steps
Section titled “Next steps”- Search History: Navigate and annotate investigations
- Tag Manager: Manage shared tags
- Reporting: Generate investigation reports