Using DFIRe
Cases
A case is the unit everything else hangs off. Every investigation, incident and forensic analysis is one.
Investigation or incident
Every case runs in one of two modes, chosen when you create it. Both carry the same tabs and the same kinds of content: evidence, files, notes, indicators, a timeline, reports and a team.
An investigation suits triage and analysis. An incident adds the machinery of active response: a declared start time, movement through phases, and a duration that runs until the incident resolves.
| Behaviour | Investigation | Incident |
|---|---|---|
| Actions checklist | First phase only | Every phase |
| Phase workflow | No | Yes |
| Declared start and duration | No | Yes |
| CAN report | No | Yes |
| Severity control labelled | Priority | Severity |
Escalate an investigation to an incident whenever the work turns into a response. The escalation records the declaration time and moves the case onto the first phase. It also opens the rest of the checklist and adds the incident-only report sections. It removes nothing.
The shipped playbooks
A playbook gives a new case its custom fields and its action checklist, grouped by phase. DFIRe ships fifteen for common scenarios. Any of them works for either mode, because the mode belongs to the case rather than the playbook.
| Playbook | Its custom fields |
|---|---|
| Accidental Data Leak | Data Types, Leak Source, Recipient, Records Exposed, EU Personal Data Involved |
| Cloud Security Incident | Cloud Provider, Account ID, Compromised Identity, Resources Publicly Exposed |
| Critical Vulnerability Response | CVE ID, CVSS Score, Exploited in the Wild, Assets to Patch, Patch Deadline |
| Distributed Denial of Service Attack | DDoS Type, Targeted Asset, Peak Attack Bandwidth, ISP Ticket Reference |
| Financial Fraud Incident | Fraud Type, Attack Method, Financial Loss Amount, Bank Recall Initiated |
| General Cyber Incident Under Investigation | Suspected Vector, Status, PII Involved, Estimated Systems Affected |
| Lost or Stolen Equipment | Device Type, Serial Number, Device Encrypted, Contains PII, Remote Wipe Status |
| Malware Analysis Request | File Hash, Requested Depth, Source System, Submitted By, Appears Targeted |
| Malware Infection Incident | Malware Family, Detected By, File Hash, Automated Action |
| Network and Perimeter Compromise | Device Type, Exploited CVE, Internet Facing, Firmware Version |
| Phishing and Social Engineering Campaign | Sender Address, Users Targeted, Users Who Clicked, Malicious URL |
| Physical Security Incident | Type, Site Location, Specific Zone, Assets Impacted, Police Report Number |
| Policy and Compliance Violation | Violation Type, Subject Employee, HR Case Reference, Legal Hold, Estimated Financial Impact |
| Ransomware Attack Incident | Ransom Demand Amount, Ransomware Strain, Viable Offline Backups, Data Exfiltration Confirmed |
| Third Party and Supply Chain Incident | Vendor Name, Service Type, Data Types Shared, Contract Reference |
Administrators can edit these or add their own under Settings → Playbooks. See Playbooks.
Creating a case
Choose New Case on the dashboard.
-
Pick the mode and the severity
Investigation or incident, then one of critical, high, medium, low or info. On an investigation that control reads Priority.
-
Name the case
If your organization uses codenames, the button beside the title field picks an unused one. External Reference takes a ticket number from another system, and Project groups this case with others.
-
Choose a playbook
Required. It decides the case's custom fields and its action checklist. ENISA Category is optional and classifies the case for reporting.
-
Fill in the playbook's fields
When the playbook defines custom fields, DFIRe collects them on a second step before creating the case. Required ones are marked.
-
Create it
DFIRe assigns the case number and opens the case. With Slack enabled you can also tick Create Slack channel for this case before creating.
A new case opens with the status Open and you as its lead investigator. Add the rest of the team afterwards with Manage Team in the case header.
Working in a case
Every case carries the same nine tabs, in this order: Case Report, Timeline, Slack, Actions, Notes, Files, Evidence, IOCs and Compliance. Slack appears only when an administrator has enabled it.
The mode changes what is inside two of them. An investigation's Actions tab shows only the playbook's first phase, and its Case Report has no CAN report.
Case Report
The formal write-up. The investigation report is a sectioned document, and each section moves through three stages on its own. A section starts as Draft, becomes Ready for QA when it is finished and waiting on a reviewer, and ends as QA Completed. Which sections exist comes from the templates an administrator configures under Settings → Reporting, not from the playbook.
An incident also gets a CAN report, a situation summary in three parts. Conditions describes the current state, actions covers what is under way, and needs lists what is still outstanding. See Reports.
Timeline
A chronological record of the case: its creation and status changes, phase transitions, notes posted to it, evidence added or changed, team changes and completed actions. See Timeline.
Actions
The response checklist from the playbook, grouped by phase. Each action sits in one of five states.
- Pending, not yet started.
- Started, taken by an assignee and in progress.
- Blocked, waiting on something. It applies to a pending or a started action and needs a note saying what it waits on. See Incident response.
- Done.
- Skipped, not applicable to this case.
The icons on action cards and in Slack are ⚪ pending, ⚡ started, ⛔ blocked, ✔️ done and 🚫 skipped. The sidebar tracks how many are complete.
With Jira connected you can raise a Jira issue from an action. A DFIRe user whose email matches a Jira account can be assigned automatically, and status changes travel in both directions.
Notes
Investigation notes in Markdown, each timestamped and attributed to its author. A note can be posted to the timeline, and with Slack enabled it reaches the case channel. Import bulk-loads notes from a CSV file and previews what it will create or update first.
IOCs
Indicators from the global registry that this case is associated with. Add existing ones, create new ones, or paste text and let DFIRe extract the addresses, domains, URLs, hashes and email addresses out of it.
Each association carries a case context field for notes that belong to this case alone. It is visible here and not in the registry.
Indicator notes are shared, case context is not. An indicator lives in the global registry and travels between cases. Keep anything case-specific or sensitive in the case context field instead of the indicator's own notes. See Indicators of compromise.
Files, Evidence and Compliance
Files holds attachments on the case itself, and Evidence holds the artifacts under examination, each with its own files and custody record. See Evidence and Storage. Compliance carries the regulatory notification timers. See Compliance timers.
Slack and chat
The Slack tab shows the case's Slack channel inside DFIRe. Create the channel, read it and post to it without leaving the case. From Slack, /dfire commands reach back, and reacting to a message with the pushpin emoji captures its file into the case. An administrator enables this under Settings → Slack Integration.
Separately, every case has its own case chat, which docks beside the case or pops out into its own window. It needs no Slack. See Case chat.
The sidebar
The collapsible panel on the right summarizes the case. It shows how many actions are complete and the state of any compliance timers, then the project, classification, reference, lead investigator, team and description. Below those sit the custom fields the playbook defined.
An incident adds two more. Incident phase shows the current phase and when it last changed. Incident duration counts from the declaration and stops when the incident reaches its final phase or the case closes. You can correct both timestamps in Edit Case.
The case team
Manage Team in the case header lists who is on the case. Search under Add User to Case to add someone. They join at the lowest access their role allows, usually view. Edit on their row grants write access, and None takes them off. Changes apply when you save, and closing the dialog with unsaved changes asks first.
The lead investigator always stays on the list. Change the lead in Edit Case.
| On the case | What it grants |
|---|---|
| Lead investigator | Write access, and ownership: the case is listed and filtered under this person. One per case. |
| Investigator | Write access to the case's content. |
| Viewer | Read-only. |
Being on the team is only half of it. The case team decides which cases a permission applies to. The role decides what the permission is. Someone can be an investigator on a case and still not delete it, because deleting a case is a permission their role does not hold. See Users and roles.
Global access bypasses the team. A role that can view all cases sees every case without being on it, and one that can edit all cases can work on every case. You can still add such a person to a team to record that they worked it. They join with edit, because view would not narrow what their role already allows. A role with global read but no write cannot join a case team at all.
Open, closed, archived
A case is open while people work it. Closing it makes it read-only, which prevents an accidental edit to finished work. Archiving puts it into long-term storage and out of the default views.
Change the status in Edit Case. Neither closed nor archived is final: reopen the case and it becomes editable again. An archived case has to be reopened before it can be closed.
Retention rules can archive and delete cases on a schedule. See Configuration.
Projects
A project groups cases that belong together: a large investigation spanning several devices, recurring work for one client, or a set of incidents that share context. Create one with New Project on the dashboard, then assign cases to it when you create or edit them.
Finding a case
The dashboard splits into Daily Summary, Active Cases and Archived, and filters the list by project, investigator, status, severity and mode.
The search icon in the header searches across cases, evidence, notes and more. See Search.