Using DFIRe
Search
One box across everything you are allowed to see.
What it searches
Open search from the icon in the header. Type a query, press Enter, and DFIRe returns results ranked by relevance with the matched words highlighted.
| Result type | What matches |
|---|---|
| Case | Title, description, case number and the custom fields the playbook defined. |
| Item | Evidence item names, descriptions and type-specific fields. |
| Note | Note content, whether the note sits on a case or on an evidence item. |
| File | File names and hashes. |
| Entity | Names of people and organizations in the directory. |
| Project | Project names and descriptions. |
| Indicator | Indicators from the IOC registry. |
| KB Page | Knowledge Base page titles and descriptions. |
| Chat | Case chat messages. |
Each result shows its type, its title, an excerpt with the matches highlighted, the date, and how strong the match is.
A Chat result opens the case with the chat window on the message that matched, marked briefly so you can pick it out of the conversation.
Narrowing the results
Buttons above the list filter by category: All, Case, Item, File, Entity, Project and Note. Each carries the number of matches in it, so you can see where your terms cluster. Notes on cases and notes on evidence items share the one Note button.
Indicator, KB Page and Chat results have no button of their own. They appear under All. To work through indicators properly, use the IOC Registry page, which filters by STIX type, TLP, classification and tags. See Indicators of compromise.
Query syntax
- Case does not matter.
Malware,malwareandMALWAREfind the same things. - Several words means all of them. Every word has to be present for a result to match.
ORbetween words widens that to either one.- A leading
-excludes a word. - Double quotes match a phrase in that exact order.
The Search Tips link on the search page carries the same reference.
What you get back
Search never widens your access. Results come only from cases you are on, unless your role holds the permission to view all cases. Legal entities are the exception: they belong to the installation rather than to a case, so everyone who can read them sees them all. Projects follow the cases. You see a project you are a member of, or one holding a case you are assigned to.
Two content types have their own gate on top of that.
- Chat messages reach only the roles that may read chat, which is a permission an administrator can withhold. A redacted message never comes back, because redaction strips its words from the index and leaves only its author.
- Knowledge Base pages reach only the roles that may read them, narrowed further by the access groups on the folder tree. Pages inside a locked folder stay out of search entirely.
Knowledge Base search reads titles and descriptions, not page bodies. A password-protected page is encrypted with a key DFIRe does not hold, so its content cannot be indexed. Writing a useful description is what keeps a protected page findable. See Knowledge base.
Indexing runs in the background and normally catches up within seconds. Nothing needs triggering by hand, and new content is usually findable straight away regardless, because search also matches titles and names directly rather than only through the index.