> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/workbench-reference/investigations-and-incidents/understanding-investigations.md).

# Understanding Investigations

An **Investigation** is created for an Expel Alert when there is a need for more in-depth analysis to determine if the activity is malicious or benign. This is where Expel can perform additional actions (labeled [Investigative Actions](#investigative-actions)) to uncover more information and help determine the scope and nature of the activity that created the initial Expel Alert.

Every Investigation is eventually either flagged as an [Incident](/workbench-reference/investigations-and-incidents/understanding-incidents.md) because there is a potential threat to your environment, or closed as benign with no further action needed.

{% hint style="info" %}
For more information about Incidents, including suspected threat types, suspected attack vectors, and suspected attack lifecycles, see [Understanding Incidents](/workbench-reference/investigations-and-incidents/understanding-incidents.md).
{% endhint %}

<figure><img src="/files/qdSwIV32RqXAxrYk8dYW" alt=""><figcaption></figcaption></figure>

## Investigative Actions

### Verify Action

If we need more information from you about whether or not a particular activity is suspicious, we will send a **Verify Action**. You can review these in Workbench by selecting **Activity > Investigations**.&#x20;

<figure><img src="/files/iMOyUav3BXwRIk6CkRcO" alt="Image showing a list of investigations."><figcaption></figcaption></figure>

Click on any listed Investigation to see the Verify Actions.

<div align="left"><figure><img src="/files/6o457GQVIZw5h3lO7hTj" alt="Image showing the verify actions section and the available choices." width="375"><figcaption></figcaption></figure></div>

You have three options for responding to a Verify Action:

1. `Not Authorized: Incident` - the activity was not authorized by your organization and it should be investigated.&#x20;

{% hint style="info" %}
Selecting this option generally leads to the creation of an [Incident](/workbench-reference/investigations-and-incidents/understanding-incidents.md).
{% endhint %}

2. `Not Malicious: Close` - the activity was not authorized by your organization, but is not concerning and therefore the Investigation can be closed.

{% hint style="info" %}
This option is often used with **policy violations** or **IT misconfigurations**. Examples:

* A user logging into their employee email via a personal VPN, which is not normally allowed but their login activity was consistent to the user (normal geolocation, normal 2FA authentication, etc.).
* An IT admin downloading PIN testing software to practice for a certification, which is not malicious but perhaps was not formally authorized by your organization.
* A service account accessing more resources than was originally intended, due to an IT misconfiguration rather than attacker manipulation.
  {% endhint %}

3. `Authorized: Close` - the activity was authorized by your organization, so the Investigation can be closed.

{% hint style="info" %}
We continuously learn from your responses to Verify Actions. If you mark an activity as authorized, and the same authorized activity continues to happen, we may eventually create a [Suppression](/workbench-reference/expel-terminology.md#suppression) for it. If the Verify Action is for authorized activity that *you wish to continue to be notified about*, choose the `Not Malicious: Close` option instead.
{% endhint %}

### Notify Action <a href="#h_01k39a4txs2gtq2exsdmdpn6wy" id="h_01k39a4txs2gtq2exsdmdpn6wy"></a>

When we identify something that is not entirely malicious but is highly suspicious or a potential policy violation, we will send a **Notify Action** to recommend an action for you to take (such as gathering device data or uploading a file for our SOC analysts).

## Close Reasons <a href="#h_01k39a4txs2gtq2exsdmdpn6wy" id="h_01k39a4txs2gtq2exsdmdpn6wy"></a>

There are several reasons why we may close an Investigation or Expel Alert.&#x20;

{% hint style="warning" %}
The specific options you see in the dropdown menu will vary depending on your location within Workbench.
{% endhint %}

<table><thead><tr><th width="205.26171875">Reason</th><th>Meaning</th></tr></thead><tbody><tr><td>Attack failed</td><td><p></p><p>An attacker made an attempt, but no compromise occurred.</p><p><br><em>You may be advised to take additional steps to mitigate any risk posed by the failed attack, or the attack could be considered "normal" enough (e.g. web scanning) that we do not recommend any additional steps.</em></p><p></p></td></tr><tr><td>Benign</td><td>A signature fired on a specific point-in-time activity that it was looking for (i.e. webshell request or psexec activity), but the context of the activity does not represent a threat.<br><br><em>Most behavioral signatures will fall into this category.</em></td></tr><tr><td>False positive</td><td>The logic and intent of the signature did not align, and the signature needs to be reworked.<br><br><em>Examples include a login flagged as outside of the US, but the IP address is geolocated to Kentucky; or a binary flagged as malware, but the binary is a signature file.</em></td></tr><tr><td>Inconclusive</td><td>You are unable to make a strong call one way or the other because you lack sufficient evidence.</td></tr><tr><td>IT misconfiguration</td><td>Verified non-malicious activity was triggered by an IT issue, such as failed login attempts after an automated password change process.</td></tr><tr><td>Other</td><td>Any reason that does not fit into the other categories.<br><br><em>In most cases, a specific close reason is added by an analyst.</em></td></tr><tr><td>Phishing simulation</td><td>The alert or investigation was a confirmed phishing simulation. <br><br><em>This reason is unique to the Managed Phishing service.</em></td></tr><tr><td>Possible policy violation</td><td><p></p><p>Could be any of the following:</p><ul><li>Unauthorized activity that you are aware of and may have fixed/reverted (e.g. an engineer accidentally makes a resource publicly viewable, but the security team works with them to fix it).</li><li>A non-malicious file NOT identified as PUP/PUA.</li><li>Verified VPN activity, based source/destination IP or other parts of the alert (e.g. activity is on SurfShark VPN binary).</li><li>Piracy, pornography, or a productivity-impacting activity.</li></ul></td></tr><tr><td>PUP/PUA</td><td><ul><li>Non-malicious files were identified as PUP/PUA at the time of the alert.</li><li>We only categorize as PUP/PUA if <em>two</em> or more of the following vendors identify it as such: Microsoft, Sophos, F-Secure, McAfee, Malwarebytes, Kaspersky, Symantec, McAfee-GW-Edition, BitDefender.</li><li>If two or more vendors do not indicate this categorization, it will be closed as a possible policy violation.</li></ul></td></tr><tr><td>Suppressed</td><td>The alert has been automatically suppressed because it is a known benign issue.</td></tr><tr><td>Suppressed manual</td><td>The alert has been manually suppressed because it is a known benign issue.</td></tr><tr><td>Suppressed new device</td><td>The device is being <a href="/pages/uiwLDrnkYzpInTxn4IY3#device-tuning">tuned</a> and is currently suppressed while the tuning process completes.</td></tr><tr><td>Suppressed threshold exceeded</td><td>The alert has been auto-closed because you have reached the threshold of alerts that can be associated with the investigation.</td></tr><tr><td>Testing</td><td>Verified internal testing activity.</td></tr><tr><td>True positive</td><td>The investigation or incident has been confirmed by you as true malicious activity or a valid threat.</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/workbench-reference/investigations-and-incidents/understanding-investigations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
