Skip to main content
Projects give a team a durable workspace for an investigation or monitored environment. They keep operational context beside the Infrawatch data used to build it.

What belongs in a project

  • Investigations - Save and revisit connected infrastructure graphs.
  • Indicators - Track IP addresses, domains, and URLs relevant to the work.
  • Saved queries - Reuse InfraQL searches for Scanning or DNS.
  • Notes - Record analyst context in Markdown.
  • Activity - Review changes to investigations, saved queries, notes, and indicators.
  • External-surface inventory - Keep monitored assets and findings in the same project context.
Projects respect account permissions. A member may be able to view a project without being able to change its indicators, notes, saved queries, or settings.

A practical project workflow

1

Create or choose a project

Use a separate project when the work needs its own membership, inventory, indicators, or investigation history.
2

Add the starting indicators

Add the IP addresses, domains, or URLs that define the initial scope.
3

Save repeatable searches

Store the Scanning and DNS queries that the team expects to rerun.
4

Investigate and record decisions

Save the infrastructure graph and use notes to preserve analyst reasoning.

Investigate with InfrAI

Turn a host or report into a saved, evidence-backed investigation.

Learn InfraQL

Compose the queries the team reruns, with typed fields and time windows.