The **Investigation** feature allows multiple analysts to collaborate on a single security incident.
You can add notable events, raw logs, action histories, and manual notes to an investigation timeline.
This establishes an audit trail and timeline of the attacker's actions from initial access to data exfiltration.