Use the tools on the Forensics tab to help you investigate.
1.
Use free-form search to search for symptomatic attributes that are associated
2.
Use content categories to filter out content that isn't relevant to the
3.
Examine suspect content that is flagged by the product.
Use Digital Impressions and visualizations to explore extended relationships of
the malicious payload, perpetrator, or target.
5.
Use data pivoting and follow data linkages to identify patient zero.
QRadar Incident Forensics User Guide
Use Surveyor to see a timeline of activities so that you can retrace an attack.