Using DFIRe

Case chat

Case Chat is the conversation that belongs to a case. The team writes in it, the AI assistant answers when someone addresses it, and the transcript stays with the case.

The transcript is case material

DFIRe keeps every message with the case, timestamped and attributed. The transcript is searchable and travels with a case export. DFIRe deletes nothing from it: redacting a message destroys the text and leaves a record that the message existed.

The transcript is not the formal record. Save anything worth keeping formally as a case note.

Opening the chat

Open the chat from the round button at the bottom right of a case screen. A red count on the button shows how many messages arrived since you last read the chat, your own excluded. The count follows your account, so it reads the same in every tab and window, and opening the chat clears it. Case cards on the Dashboard carry the same numbers, refreshed with the Dashboard rather than as messages arrive.

The window docks to either edge of the screen, and the case screen gives up the room it takes. Drag the inner edge to resize it, or use the arrow keys once the edge has focus. On a screen too narrow for both, the window covers the page. The header controls:

  • Dock left and Dock right move the window to the other edge.
  • Open in a new window opens the conversation in a separate browser window.
  • Close puts the window away. The transcript stays on the server.

A connection indicator sits at the right of the header. Green means the conversation is live, red means the window has lost contact. DFIRe reconnects on its own. A browser tab left in the background keeps its connection for five minutes, so switching away and back does not reload the conversation.

A separate window

Open in a new window gives the conversation an ordinary browser window, named after the case. Place and size it freely, full screen on a second monitor included. It is independent: the case screen keeps its own chat, navigation leaves the window where it is, and only you close it. Each case gets one window, and asking again brings the existing one to the front.

When the connection drops

DFIRe refuses to write to a chat it has lost contact with. It withdraws posting, replying, editing, redacting and reacting, and a notice above the transcript says so. You would write without seeing what the others said or redacted meanwhile. Reading carries on, and so do saving notes, extracting indicators and downloading the transcript.

An unsent message stays as you left it. When DFIRe reconnects, it reads back what arrived during the gap and the controls return.

Who else is here

A line above the transcript names who else has the case open, counted per person rather than per window.

Reading the transcript

Your messages sit on the right. Everyone else's, the assistant's included, sit on the left under the writer's name. Messages one person writes within five minutes of each other form a block. Inside it, every message keeps its own line, its own Edited marker and its own actions. All chat times are UTC.

A date line separates the days the conversation ran over: Today, Yesterday, or the date. Open a chat with unread messages and a New line marks the first of them. The line stays put while the window is open and is gone once you are up to date.

Scroll away from the end and a button at the foot of the transcript takes you back to the newest message. It counts what arrives while you read further up.

Writing in the chat

Write in the box at the bottom. Enter sends, Shift+Enter starts a new line, and messages are Markdown. A message can be up to 10,000 characters, and the box counts down over the last 500.

DFIRe keeps an unsent message per case and brings it back when you open that chat again, as a plain message rather than a reply.

Each message carries a menu behind the three dots at its right, holding the actions you may take on that message.

Correct your own message with Edit message. The Edited marker shows the earlier versions and when each was replaced. An edit past the 10,000-character limit says how far over it is and cannot be saved until you shorten it. DFIRe keeps up to 20 earlier versions of one message and then withdraws Edit message: post a new message instead. Nobody edits an assistant answer.

Replying to a message

A reply quotes the message it answers. The arrow beside somebody else's block answers the first message in it. Reply to message in a message's menu answers exactly that one, your own messages included.

The quoted message sits above the box while you write, with Cancel the reply beside it. The sent reply carries the quote, and selecting the quote goes to the original. DFIRe quotes the original rather than copying it: correcting a message updates every quote of it, and redacting one leaves its quotes saying so. A redacted message cannot be replied to.

The quoted author gets a notification that opens the chat on your reply, without the message text. Replying to yourself or to the assistant notifies nobody, and a reply that also names the author with @ sends one notification rather than two.

Reacting to a message

A reaction answers a message without adding a line to the transcript. The set is fixed at six: thumbs up, done, looking, important, question, and appreciated.

The face icon beside somebody else's block reacts to the first message in it. React to message in a message's menu reacts to exactly that one, your own included. Reactions appear under the message as one chip per emoji, with the count behind it and the names on hover or keyboard focus. Your own are marked. Select a chip to add your reaction or take it back.

Reacting is a write to the case: it needs the same access as posting, and a closed or archived case refuses it while the chips stay readable. A redacted message takes no new reactions and keeps the ones it had. Reactions travel with a case export.

Naming someone

Write @ and a username to address a colleague. They get a notification that opens the chat on your message, and a short pop-up unless they already have that chat open. The notification carries your name and the case, never the message text.

A mention reaches somebody only if they are on the case and their role can read chat. Only a new message notifies: adding a name while editing reaches nobody. @assistant addresses the AI assistant and never notifies a person.

Redacting a message

Redact a message that must not persist with Redact message in its menu, and confirm. Redaction is deliberate, not reversible. It clears the text and every earlier version, and removes the words from the search index. What stays is a row naming who wrote the message, when, and who redacted it. The audit log never held the text.

Redaction reaches only the transcript. A message saved as a case note before the redaction keeps its text in that note, and a case export taken earlier still carries it. To remove the words from the whole case, check the case notes as well.

The author can redact their own message. The case's lead investigator and superusers can redact any message, an assistant answer included.

Asking the assistant

Write @assistant in a message to ask about the case. The assistant reads the case and the transcript up to that point, then answers in the chat, where the whole team sees it. The answer streams to the person who asked and reaches everyone else complete. While the assistant answers your question, the box does not take another message from you. Wait for the answer to finish, or stop it with the button beside the box. Anything you typed stays there. Everyone else in the chat can write as usual.

The assistant answers only when addressed, and it cannot change anything: it has no way to create, edit or delete a record. Every answer is marked Generated and stamped with the provider and model that produced it. The marking survives an export and a case note saved from the answer.

Configure the provider in Settings → AI / LLM. Without one, @assistant is ordinary text. Questions count against the daily token budget. See AI integration.

The assistant is not an account. @assistant is a token the chat recognises, and the username dfire-ai-assistant is reserved.

Read a generated answer as a draft. The assistant reads the transcript, pasted material included. A phishing body or a ransom note can carry instructions aimed at the assistant, and an answer can be shaped by them. The assistant holds no tools and no write access, so the worst outcome is one wrong answer, clearly marked as generated. Check an answer the way you would check any other lead.

Saving chat in the case notes

The note icon beside somebody else's block files the whole block as one case note. The note names the author once, states the time span, and carries the messages in order, redacted ones left out. A block redacted down to nothing dims the icon. Save message as case note in a message's menu files that one message.

Both ask before filing and name what the note will carry. The note is headed Case chat, and an assistant answer keeps its Generated marking. Filing needs permission to add case notes and edit access to the case.

Taking indicators out of the chat

Investigators paste addresses, domains and hashes into chat as they work, and DFIRe reads them back out of the conversation.

Extract IOCs from message in a message's menu opens the case indicator review with that message already in it. Pick a classification and confidence, choose the candidates to keep, and import them. DFIRe adds nothing until you do.

Scan Case in the case's IOCs tab covers the whole conversation alongside the notes and evidence. Each candidate names the author and time of its message. DFIRe searches assistant answers too, and redacted messages contribute nothing.

Both need permission to read indicators and to read the chat, plus edit access to the case. A closed or archived case offers neither.

Who can read and write

Chat has its own permissions, so a role can hold a case without the conversation. Every shipped role reads the transcript and its reactions. Every role except View Only also writes, edits, redacts and reacts.

Remove the Case Chat view permission from a role in Settings → Access Roles to take the conversation away from it. Those users get no chat button, no transcript over the API, and no chat in search results or case exports. Editing, redacting and reacting go with it, because each reads the message back. Posting is a separate write permission. Remove that one too to withhold chat from the role entirely.

The case's own rules apply on top of the role. Reading follows case visibility. Writing, editing and redacting need edit access to the case, so someone on the case as a viewer reads the transcript and gets no message box. A change to your role or to the case team applies to an open chat without a reload.

In a closed or archived case the chat is read-only, and no permission overrides that. Reopen the case to continue the conversation. See Cases.

Search and export

Search

Chat messages appear in global search for users who may read chat, from cases they can see. A redacted message cannot be found. A chat result opens the case with the chat on the matched message, marked for a moment.

Downloading the transcript

The download button in the chat window's title bar saves the conversation as a CSV file named after the case and the time. Each row is one message: UTC time, account, person or assistant, text, and edit time. A redacted message's row adds the redaction time and redactor, with an empty text cell.

The file is for the case's lead investigator, a superuser, or a role that reads every case. Anyone else on the case reads the chat in the window and is refused the download.

Export and import

A case export carries the transcript when the exporter may read chat. Otherwise the section is absent from the file rather than empty, because an empty transcript would claim that nothing was said.

An import adds the messages the case does not already hold, with their reactions. DFIRe recognises messages it has already imported, so the same export imports once, into its own case or into a case built from it. A redacted message imports as a tombstone, and no file writes text back into one. A message from an account this installation does not have imports unattributed and is reported as unresolved. A message over the size or edit-history limits is left out whole and reported.

Importing chat takes the chat write permission, and reactions their own. Without them the import restores the rest of the case and reports what it skipped, the same as every other section of an import.

Connecting an agent to the chat

An AI agent connected over the MCP server can read a case chat and post to it. The two tools sit in the Case Chat tool group, off until a superuser switches it on in Settings → MCP Server. While it is off, no chat content reaches an agent.

An agent reads the transcript in pages of up to 100 messages, newest first, and the conversation reaches it marked as untrusted data between explicit markers. A redacted message travels as a tombstone, and an assistant answer names the model that wrote it.

An agent posts as the user whose API key it holds. The message appears in the chat like any other, notifies anyone it names, and reaches the audit trail under that user's name. @assistant posted this way summons nobody. The chat permissions and the case's own rules apply as everywhere else.

Chat content leaves DFIRe. Switching the group on sends case conversation to whatever agent an investigator has connected, and on to that agent's model provider. Switch it on when that is a trade your installation accepts.

← Cases Evidence →