Hi again @forkhead, thanks for the continued interest!
- Is there a way to automatically create cases for some rule detections ?
No, there is not currently an in-app method for automatically creating a case as a rule action. This is something that we are investigating for a future release. We have heard this request from MSSP-type users, who have a SLA in place that requires them to auto-create case upon certain detections.
- Is there a way to store or create Case Templates in Cases (which then can also be attached to some detections where we want an automatic creation of a case) ?
No, there is not currently a way to do this in the SIEM app. This too is an area of investigation for future capabilities. As a partial workaround, one idea is to include the case template in the rule's advanced setting "Investigation guide." When a signal detected by the rule is investigated in the Timeline, the "Investigation guide" text is automatically populated in the Timeline Notes. When creating a case from the Timeline, the analyst can first copy the text from the Timeline Note, and then paste it into the newly opened case.
Please keep the feedback coming!