Using DFIRe
Dashboard
Where you land after signing in: every case you can reach, what moved since yesterday, and what is still outstanding.
Your account and roles
The line under the Dashboard heading names your account and the roles it holds. Roles decide what you can see and change throughout DFIRe, so this is the quickest way to confirm your own access without opening Settings. An account with no roles reads No roles assigned, and a superuser reads System Root. See Users and roles.
The case list
Each case is a card. It carries the case number, title and description, the severity badge and the status. Below those sit the project and playbook, the lead investigator and team size, and counts of evidence and files. An open case has a green tint across the top of the card. A closed or archived one has a grey tint, with its severity greyed out too.
An incident card also shows the current phase and a progress bar for its response actions. An investigation card gives its creation date more prominence instead.
Three things on a card are worth knowing about.
- Chat count. How many messages the case chat holds, with a red count of the ones you have not read. A case nobody has written in shows nothing. These load and refresh with the Dashboard rather than as messages arrive. A message written while you read the list therefore appears on the next refresh. Reading the chat clears the red count here too. See Case chat.
- Compliance countdown. Time left on any active deadline.
- Retention countdown. When retention rules are configured, the footer shows how long before the case is archived or deleted automatically. See Configuration.
Collapsing cards
The caret at the right of a card's top bar folds the card down to that bar alone. The bar then carries the case title alongside the severity, case number and status. Collapse all and Expand all above the list do the same to every case listed, which turns a long list into one line per case. Cards open expanded.
Filtering and tabs
Dropdowns above the list filter by project, investigator, status and severity. A toggle beside them narrows to investigations or incidents, or leaves both showing.
The three tabs
Tabs at the top of the list switch between the Dashboard's three views:
- Daily Summary - An operational digest of what moved in the last 24 hours and what is outstanding. See Daily Summary below
- Active Cases - Cases that are currently open or closed but not archived
- Archived - Cases that have been archived and are no longer actively worked on. This tab is shown only to users whose role allows viewing archived cases
Summary statistics
A statistics bar is displayed above the case list, providing a high-level overview of your caseload. The statistics shown include:
- Total cases - The total number of cases matching the current filters
- Open count - Number of cases with Open status
- Closed count - Number of cases with Closed status
- Archived count - Number of archived cases
- Investigation / Incident split - Breakdown of cases by mode
- Severity donut chart - A visual chart showing the distribution of cases across severity levels
- MTTR (Mean Time To Resolve) - The average time from declaration to resolution across resolved incidents
The summary statistics update dynamically as you apply or change filters. This means the numbers and charts always reflect the currently visible subset of cases, not the entire case database.
Daily Summary
The Daily Summary tab answers one question: what happened since yesterday, and what still needs doing. It is built for a shift handover or a morning standup, where you need the shape of the whole caseload before you open any single case. Everything on it is derived from the cases you have access to. Relevant case activity refreshes the Daily Summary in real time, including changes to active blockers.
The severity cutoff
The digest starts at High severity and above. Use the cutoff control to widen or narrow it: each stop admits that severity and everything more serious. Every stop carries the number of open cases it would bring in, so you can see whether widening would gain you anything before you click.
The project, investigator, status and severity dropdowns are replaced by this control on the Daily Summary tab, because the digest always reports on current work. The All / Investigations / Incidents mode toggle still applies.
Active cases
This section lists the open cases at or above the cutoff, plus any case closed in the last 24 hours. A case that closed yesterday is still part of the day's story. Cases still open are listed first, then by severity, then by whichever changed most recently. A case opened in the last 24 hours is marked New < 24h and one closed in that window is marked Closed.
Each case shows a summary you can read without opening anything:
- The first line carries the case number, its severity, any movement marker, and the title.
- The second line carries the current phase and the lead investigator. A sentence after them says how much activity the case saw in the last 24 hours, how many actions remain open in its current phase, and how many are blocked.
Select a case to expand it. Activity in the last 24 hours lists everything that happened, in full: a busy day is itself worth seeing, so nothing is hidden behind a count. Open actions lists the unresolved work in the case's current phase, each with its own state, and a blocked action names what it is waiting on. Pointing at an action highlights the matching activity entry and the other way round, tying what happened to what is outstanding. Use Expand all and Collapse all to open or close every case at once, and the arrow at the end of a case to go to the case itself.
Compliance deadlines
A case whose compliance timer needs attention is outlined and carries a badge beside its severity:
- Timer breached, in red. A deadline has been missed.
- Timer warning, in amber. A deadline is approaching. The case is still inside its deadline, but it warrants attention now so that it does not become a breach.
A missed deadline always outranks an approaching one, so a case with both is marked as breached. The marking clears once the timer it refers to is completed, and closed cases are never marked. An active warning or breach remains marked even when it began more than 24 hours ago; only the activity list is limited to the rolling 24-hour window. See Incidents for compliance timers themselves.
All active blockers
Below the cases, a single table lists every blocked action across the open cases you can see, most severe case first. Each row names the action, what it is waiting on, and who owns it, and the case number takes you straight to that case's Actions tab. This is the standup list: the work that cannot move until someone clears the way.
Blocked actions in closed cases are not listed. Closing a case settles its outstanding work, so those blockers remain on the case as a record rather than appearing here as live.
The AI brief
When an AI provider is configured, AI summary writes the whole digest up as a short prose brief you could read aloud in two minutes. It covers the shape of the day, every case in the current focus list, and anything blocked. The brief is written only from the digest, so it cannot mention a case you would not otherwise see.
Once written, the brief offers Copy for pasting into an email or a chat, Print for a shareable one-page sheet, Regenerate to write it again over current data, and Dismiss to clear it.
The brief describes a rolling 24-hour window, so it starts ageing the moment it is written. It states how long ago it was generated and its border warms as it gets older. Changing the Daily controls turns the border amber immediately to show that the brief snapshots a different view. A brief more than a day old is discarded rather than shown as current. It is kept in your own browser, so it is visible only to you and only on that machine.
Configuring a provider is covered in AI Integration. Without one, the Daily Summary works exactly as described above, without the brief.
Creating and importing
Three buttons sit at the top of the page. New Case opens the case creation dialog, and New Project creates a grouping for related cases. Both are covered in Cases.
Importing a case
Import Case reads a case file exported from this or another DFIRe installation. The dialog lets you map users, and re-attributes any author it cannot map to you.
An import brings across the case details, the evidence items with their runbook progress, notes, timeline events, indicators, compliance timers, reports and the chat transcript. It sends no outbound webhooks, so ingesting a case cannot flood connected systems with notifications about work that happened elsewhere.
Each part of an import asks for the permission for what it writes. Importing a case does not grant you what your role withholds. A role that cannot add notes, evidence, custody records, timeline entries, indicators, reports or compliance timers does not acquire them this way. The rest of the case still arrives, and the summary names what it left out. Every shipped role that can import holds all of these, so a standard installation sees no difference.
The chat transcript follows the same rule, and adds one of its own. An export carries it only when the person exporting may read chat. An import writes it only when they may write chat, and reports it as skipped otherwise. An unmapped chat author stays unattributed rather than re-attributed, because a chat message is a quotation rather than a record someone filed. See Case chat.
A case export does not contain uploaded files, and is not a backup. It carries case information only: no attachment file contents, and no encryption keys. Attachment keys live in the database, so an export cannot decrypt anything even if you still have the encrypted files.
This matters most when deleting a case. Deleting a case deletes its attachment files from storage. Exporting the case first does not preserve them, and importing that file afterwards will not bring them back: the files are gone and the keys that decrypted them went with the case. An export is not a way to archive a case before removing it.
Protecting against data loss is a separate job, and it needs two things backed up: the database, which holds the attachment encryption keys, and the attachment storage, which holds the encrypted files. Neither covers the other, and DFIRe's integrated backup covers only the first. Your platform's own backups should be doing both. See Backup & Recovery.
Getting around
The header bar carries the same links from every page, in this order: Dashboard, Entities directory, IOC Registry, Knowledge Base and Global Search. The Knowledge Base link appears only for roles that may read it.
To the right sit a live server clock, which switches between UTC and your local time when you select it, and the user avatar menu holding your profile, Settings for administrators, and sign-out.
Personal preferences
The user avatar menu holds two display settings that affect only your own view of DFIRe:
- Theme - Choose System, Light or Dark. This setting is stored with your account, so it follows you to any browser you sign in from.
- Background - Choose Off or Aurora. Aurora draws a slow, soft colour wash behind the application. It is off until you turn it on. The choice sticks to the browser you set it in rather than to your account, so you can enable it on your own machine without it following you onto a shared or remote one. If your operating system is set to reduce motion, the wash is drawn as a still image.