Investigation Workspace

Start an assisted investigation. OpenTrojan gathers and correlates published intelligence so you can assess risk and document findings — it never takes action on your systems.

Analyst-assistance boundary

OpenTrojan assists analysts with collection, correlation, assessment and documentation. It never automatically executes, scans, or fixes systems. Every disposition is a human, offline decision.

Create an investigation

Entity type

  • CVE
  • Malware
  • Software
  • Threat Actor

Choose the object of your investigation; each type drives dedicated collection and correlation steps.

Status flow

  1. Draft — Investigation is being scoped; input captured.
  2. In progress — Evidence is being collected and correlated.
  3. In review — Assessment drafted; a human reviewer verifies facts and citations.
  4. Done — Assessment finalized and report exported.

Four-state workflow: Draft → In progress → In review → Done. Transitions are set by humans; nothing closes automatically.

Collaboration

  • Owner — A. Chen
  • Participants — M. Rios, S. Patel
  • Priorityhigh
  • Notes
    • Waiting on vendor advisory for patch confirmation.
    • Shared draft with Threat Intel for review.

Collaboration is analyst-managed. OpenTrojan never auto-assigns, auto-closes, or acts on your systems.

AI analysis steps

  1. Collect — Pull published CVE/KEV/Malware/Threat-Actor facts, references and vendor advisories from the knowledge base.
  2. Correlate — Link entities (CVE → software → actors) and surface evidence chains from the entity graph.
  3. Assess — Rank risk using CVSS, KEV status and asset context; highlight open questions for the analyst.
  4. Document — Draft a report skeleton with citations and confidence labels for human review.

Timeline

  1. Scoped — Define the question, entity type and scope.
  2. Evidence gathered — Collect and correlate published facts and citations.
  3. Assessment drafted — AI drafts the assessment; analyst reviews and edits.
  4. Report exported — Share as Markdown/PDF/JSON for the wider team.

Export a report

Frequently asked

Does the investigation workspace automate response actions?
No. OpenTrojan is analyst-assistance only. It never automatically executes, scans, or fixes systems.

Which entity types can I investigate?
CVE, Malware, Software, and Threat Actor.