Using DFIRe

Search

One box across everything you are allowed to see.

What it searches

Open search from the icon in the header. Type a query, press Enter, and DFIRe returns results ranked by relevance with the matched words highlighted.

Result typeWhat matches
CaseTitle, description, case number and the custom fields the playbook defined.
ItemEvidence item names, descriptions and type-specific fields.
NoteNote content, whether the note sits on a case or on an evidence item.
FileFile names and hashes.
EntityNames of people and organizations in the directory.
ProjectProject names and descriptions.
IndicatorIndicators from the IOC registry.
KB PageKnowledge Base page titles and descriptions.
ChatCase chat messages.

Each result shows its type, its title, an excerpt with the matches highlighted, the date, and how strong the match is.

A Chat result opens the case with the chat window on the message that matched, marked briefly so you can pick it out of the conversation.

Narrowing the results

Buttons above the list filter by category: All, Case, Item, File, Entity, Project and Note. Each carries the number of matches in it, so you can see where your terms cluster. Notes on cases and notes on evidence items share the one Note button.

Indicator, KB Page and Chat results have no button of their own. They appear under All. To work through indicators properly, use the IOC Registry page, which filters by STIX type, TLP, classification and tags. See Indicators of compromise.

Query syntax

  • Case does not matter. Malware, malware and MALWARE find the same things.
  • Several words means all of them. Every word has to be present for a result to match.
  • OR between words widens that to either one.
  • A leading - excludes a word.
  • Double quotes match a phrase in that exact order.

The Search Tips link on the search page carries the same reference.

What you get back

Search never widens your access. Results come only from cases you are on, unless your role holds the permission to view all cases. Legal entities are the exception: they belong to the installation rather than to a case, so everyone who can read them sees them all. Projects follow the cases. You see a project you are a member of, or one holding a case you are assigned to.

Two content types have their own gate on top of that.

  • Chat messages reach only the roles that may read chat, which is a permission an administrator can withhold. A redacted message never comes back, because redaction strips its words from the index and leaves only its author.
  • Knowledge Base pages reach only the roles that may read them, narrowed further by the access groups on the folder tree. Pages inside a locked folder stay out of search entirely.

Knowledge Base search reads titles and descriptions, not page bodies. A password-protected page is encrypted with a key DFIRe does not hold, so its content cannot be indexed. Writing a useful description is what keeps a protected page findable. See Knowledge base.

Indexing runs in the background and normally catches up within seconds. Nothing needs triggering by hand, and new content is usually findable straight away regardless, because search also matches titles and names directly rather than only through the index.

← Reports Knowledge base →