Using DFIRe

Cases

A case is the unit everything else hangs off. Every investigation, incident and forensic analysis is one.

Investigation or incident

Every case runs in one of two modes, chosen when you create it. Both carry the same tabs and the same kinds of content: evidence, files, notes, indicators, a timeline, reports and a team.

An investigation suits triage and analysis. An incident adds the machinery of active response: a declared start time, movement through phases, and a duration that runs until the incident resolves.

BehaviourInvestigationIncident
Actions checklistFirst phase onlyEvery phase
Phase workflowNoYes
Declared start and durationNoYes
CAN reportNoYes
Severity control labelledPrioritySeverity

Escalate an investigation to an incident whenever the work turns into a response. The escalation records the declaration time and moves the case onto the first phase. It also opens the rest of the checklist and adds the incident-only report sections. It removes nothing.

The shipped playbooks

A playbook gives a new case its custom fields and its action checklist, grouped by phase. DFIRe ships fifteen for common scenarios. Any of them works for either mode, because the mode belongs to the case rather than the playbook.

PlaybookIts custom fields
Accidental Data LeakData Types, Leak Source, Recipient, Records Exposed, EU Personal Data Involved
Cloud Security IncidentCloud Provider, Account ID, Compromised Identity, Resources Publicly Exposed
Critical Vulnerability ResponseCVE ID, CVSS Score, Exploited in the Wild, Assets to Patch, Patch Deadline
Distributed Denial of Service AttackDDoS Type, Targeted Asset, Peak Attack Bandwidth, ISP Ticket Reference
Financial Fraud IncidentFraud Type, Attack Method, Financial Loss Amount, Bank Recall Initiated
General Cyber Incident Under InvestigationSuspected Vector, Status, PII Involved, Estimated Systems Affected
Lost or Stolen EquipmentDevice Type, Serial Number, Device Encrypted, Contains PII, Remote Wipe Status
Malware Analysis RequestFile Hash, Requested Depth, Source System, Submitted By, Appears Targeted
Malware Infection IncidentMalware Family, Detected By, File Hash, Automated Action
Network and Perimeter CompromiseDevice Type, Exploited CVE, Internet Facing, Firmware Version
Phishing and Social Engineering CampaignSender Address, Users Targeted, Users Who Clicked, Malicious URL
Physical Security IncidentType, Site Location, Specific Zone, Assets Impacted, Police Report Number
Policy and Compliance ViolationViolation Type, Subject Employee, HR Case Reference, Legal Hold, Estimated Financial Impact
Ransomware Attack IncidentRansom Demand Amount, Ransomware Strain, Viable Offline Backups, Data Exfiltration Confirmed
Third Party and Supply Chain IncidentVendor Name, Service Type, Data Types Shared, Contract Reference

Administrators can edit these or add their own under Settings → Playbooks. See Playbooks.

Creating a case

Choose New Case on the dashboard.

  1. Pick the mode and the severity

    Investigation or incident, then one of critical, high, medium, low or info. On an investigation that control reads Priority.

  2. Name the case

    If your organization uses codenames, the button beside the title field picks an unused one. External Reference takes a ticket number from another system, and Project groups this case with others.

  3. Choose a playbook

    Required. It decides the case's custom fields and its action checklist. ENISA Category is optional and classifies the case for reporting.

  4. Fill in the playbook's fields

    When the playbook defines custom fields, DFIRe collects them on a second step before creating the case. Required ones are marked.

  5. Create it

    DFIRe assigns the case number and opens the case. With Slack enabled you can also tick Create Slack channel for this case before creating.

A new case opens with the status Open and you as its lead investigator. Add the rest of the team afterwards with Manage Team in the case header.

Working in a case

Every case carries the same nine tabs, in this order: Case Report, Timeline, Slack, Actions, Notes, Files, Evidence, IOCs and Compliance. Slack appears only when an administrator has enabled it.

The mode changes what is inside two of them. An investigation's Actions tab shows only the playbook's first phase, and its Case Report has no CAN report.

Case Report

The formal write-up. The investigation report is a sectioned document, and each section moves through three stages on its own. A section starts as Draft, becomes Ready for QA when it is finished and waiting on a reviewer, and ends as QA Completed. Which sections exist comes from the templates an administrator configures under Settings → Reporting, not from the playbook.

An incident also gets a CAN report, a situation summary in three parts. Conditions describes the current state, actions covers what is under way, and needs lists what is still outstanding. See Reports.

Timeline

A chronological record of the case: its creation and status changes, phase transitions, notes posted to it, evidence added or changed, team changes and completed actions. See Timeline.

Actions

The response checklist from the playbook, grouped by phase. Each action sits in one of five states.

  • Pending, not yet started.
  • Started, taken by an assignee and in progress.
  • Blocked, waiting on something. It applies to a pending or a started action and needs a note saying what it waits on. See Incident response.
  • Done.
  • Skipped, not applicable to this case.

The icons on action cards and in Slack are ⚪ pending, ⚡ started, ⛔ blocked, ✔️ done and 🚫 skipped. The sidebar tracks how many are complete.

With Jira connected you can raise a Jira issue from an action. A DFIRe user whose email matches a Jira account can be assigned automatically, and status changes travel in both directions.

Notes

Investigation notes in Markdown, each timestamped and attributed to its author. A note can be posted to the timeline, and with Slack enabled it reaches the case channel. Import bulk-loads notes from a CSV file and previews what it will create or update first.

IOCs

Indicators from the global registry that this case is associated with. Add existing ones, create new ones, or paste text and let DFIRe extract the addresses, domains, URLs, hashes and email addresses out of it.

Each association carries a case context field for notes that belong to this case alone. It is visible here and not in the registry.

Indicator notes are shared, case context is not. An indicator lives in the global registry and travels between cases. Keep anything case-specific or sensitive in the case context field instead of the indicator's own notes. See Indicators of compromise.

Files, Evidence and Compliance

Files holds attachments on the case itself, and Evidence holds the artifacts under examination, each with its own files and custody record. See Evidence and Storage. Compliance carries the regulatory notification timers. See Compliance timers.

Slack and chat

The Slack tab shows the case's Slack channel inside DFIRe. Create the channel, read it and post to it without leaving the case. From Slack, /dfire commands reach back, and reacting to a message with the pushpin emoji captures its file into the case. An administrator enables this under Settings → Slack Integration.

Separately, every case has its own case chat, which docks beside the case or pops out into its own window. It needs no Slack. See Case chat.

The sidebar

The collapsible panel on the right summarizes the case. It shows how many actions are complete and the state of any compliance timers, then the project, classification, reference, lead investigator, team and description. Below those sit the custom fields the playbook defined.

An incident adds two more. Incident phase shows the current phase and when it last changed. Incident duration counts from the declaration and stops when the incident reaches its final phase or the case closes. You can correct both timestamps in Edit Case.

The case team

Manage Team in the case header lists who is on the case. Search under Add User to Case to add someone. They join at the lowest access their role allows, usually view. Edit on their row grants write access, and None takes them off. Changes apply when you save, and closing the dialog with unsaved changes asks first.

The lead investigator always stays on the list. Change the lead in Edit Case.

On the caseWhat it grants
Lead investigatorWrite access, and ownership: the case is listed and filtered under this person. One per case.
InvestigatorWrite access to the case's content.
ViewerRead-only.

Being on the team is only half of it. The case team decides which cases a permission applies to. The role decides what the permission is. Someone can be an investigator on a case and still not delete it, because deleting a case is a permission their role does not hold. See Users and roles.

Global access bypasses the team. A role that can view all cases sees every case without being on it, and one that can edit all cases can work on every case. You can still add such a person to a team to record that they worked it. They join with edit, because view would not narrow what their role already allows. A role with global read but no write cannot join a case team at all.

Open, closed, archived

A case is open while people work it. Closing it makes it read-only, which prevents an accidental edit to finished work. Archiving puts it into long-term storage and out of the default views.

Change the status in Edit Case. Neither closed nor archived is final: reopen the case and it becomes editable again. An archived case has to be reopened before it can be closed.

Retention rules can archive and delete cases on a schedule. See Configuration.

Projects

A project groups cases that belong together: a large investigation spanning several devices, recurring work for one client, or a set of incidents that share context. Create one with New Project on the dashboard, then assign cases to it when you create or edit them.

Finding a case

The dashboard splits into Daily Summary, Active Cases and Archived, and filters the list by project, investigator, status, severity and mode.

The search icon in the header searches across cases, evidence, notes and more. See Search.

← Dashboard Case chat →