Investigation Workspace
Start an assisted investigation. OpenTrojan gathers and correlates published intelligence so you can assess risk and document findings — it never takes action on your systems.
Analyst-assistance boundary
OpenTrojan assists analysts with collection, correlation, assessment and documentation. It never automatically executes, scans, or fixes systems. Every disposition is a human, offline decision.
Create an investigation
Entity type
Choose the object of your investigation; each type drives dedicated collection and correlation steps.
Status flow
- Draft — Investigation is being scoped; input captured.
- In progress — Evidence is being collected and correlated.
- In review — Assessment drafted; a human reviewer verifies facts and citations.
- Done — Assessment finalized and report exported.
Four-state workflow: Draft → In progress → In review → Done. Transitions are set by humans; nothing closes automatically.
Collaboration
- Owner — A. Chen
- Participants — M. Rios, S. Patel
- Priority — high
- Notes
- Waiting on vendor advisory for patch confirmation.
- Shared draft with Threat Intel for review.
Collaboration is analyst-managed. OpenTrojan never auto-assigns, auto-closes, or acts on your systems.
AI analysis steps
- Collect — Pull published CVE/KEV/Malware/Threat-Actor facts, references and vendor advisories from the knowledge base.
- Correlate — Link entities (CVE → software → actors) and surface evidence chains from the entity graph.
- Assess — Rank risk using CVSS, KEV status and asset context; highlight open questions for the analyst.
- Document — Draft a report skeleton with citations and confidence labels for human review.
Timeline
- Scoped — Define the question, entity type and scope.
- Evidence gathered — Collect and correlate published facts and citations.
- Assessment drafted — AI drafts the assessment; analyst reviews and edits.
- Report exported — Share as Markdown/PDF/JSON for the wider team.
Export a report
- Markdown report .mdPortable written assessment with citations.
- PDF brief .pdfShareable executive summary.
- STIX / JSON snapshot .jsonStructured entities and relations for tooling.
Frequently asked
Does the investigation workspace automate response actions?
No. OpenTrojan is analyst-assistance only. It never automatically executes, scans, or fixes systems.
Which entity types can I investigate?
CVE, Malware, Software, and Threat Actor.