Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Cloud Detection and Response
  • Getting started
    • All guides
      • Overview
      • Investigation management
      • Working with the investigations list
  • KQL reference
  • Access management

In this article:

  • Getting started
  • Creating an investigation
  • Updating an investigation
  • Renaming an investigation
  • Editing a description
  • Copying an investigation
  • Deleting an investigation
  1. Step-by-step guides
  2. Investigations
  3. Investigation management

Managing investigations

Written by
Yandex Cloud
Updated at April 14, 2026
  • Getting started
  • Creating an investigation
  • Updating an investigation
    • Renaming an investigation
    • Editing a description
  • Copying an investigation
  • Deleting an investigation

Note

This feature is in the Preview stage. To get access, contact tech support or your account manager.

This section describes how to create investigations, manage their settings, and perform basic operations with them.

Getting startedGetting started

The YCDR section will appear in the Security Deck interface after the access request is approved.

You will need the ycdr.admin role to work with investigations.

Creating an investigationCreating an investigation

To create an investigation:

Security Deck UI
  1. Go to Security Deck.
  2. In the left-hand panel, select YCDR.
  3. Navigate to the Investigations tab.
  4. Click New investigation.
  5. Enter a name for your investigation in the header field.
  6. Under Description, add a description for your investigation.

Tip

Use clear names that reflect the investigation objective, e.g., Failed login analysis for February or Prod cluster suspicious activity.

Updating an investigationUpdating an investigation

Renaming an investigationRenaming an investigation

To rename an investigation:

Security Deck UI
  1. Open the investigation.
  2. At the top of the page, click the investigation name.
  3. Enter a new name.
  4. Press Enter or click outside the input field.

Editing a descriptionEditing a description

To edit an investigation description:

Security Deck UI
  1. Open an investigation.
  2. Under Information, click the Description field.
  3. Enter a new description.
  4. Press Enter or click outside the input field.

Copying an investigationCopying an investigation

To create an investigation copy:

Security Deck UI
  1. Open an investigation.
  2. In the actions menu, select Create copy.
  3. Wait until the copy is created.

The copy inherits all requests and settings of the original investigation.

Deleting an investigationDeleting an investigation

To delete an investigation:

Security Deck UI
  1. Open an investigation.
  2. In the actions menu, select Delete.
  3. Confirm the deletion.

Warning

Deleting an investigation is irreversible. All requests and results will be deleted.

See alsoSee also

  • Investigations
  • Queries
  • Working with the investigation list
  • Working with queries

Was the article helpful?

Previous
Overview
Next
Working with the investigations list
© 2026 Direct Cursus Technology L.L.C.