Using DFIRe
Incident response
Phases to move through, a checklist to work, and a clock that runs until the incident resolves.
What incident mode adds
An incident is a case in incident mode. It carries the same tabs and content as an investigation. On top of that it adds a declared start time, movement through phases, and the full action checklist from its playbook.
Create one by choosing Incident when you make the case, or escalate an existing investigation at any point. See Cases for both.
Phases
An incident moves through an ordered set of phases. DFIRe ships seven, following the usual response lifecycle.
| Phase | What happens in it |
|---|---|
| Preparation & Immediate Actions | Assign an owner, open a channel, triage what came in, and decide whether this is really an incident. |
| Detection & Analysis | Establish what happened, how far it reached, and what it touched. |
| Containment | Stop it spreading, without destroying what you still need to examine. |
| Eradication | Remove the cause and close the way in. |
| Recovery | Restore service and confirm it is genuinely clean. |
| Post-Incident Activities | Review, report, and fix what let it happen. |
| Resolved | The final phase. Reaching it stops the incident clock. |
Administrators can rename, reorder, add and remove phases under Settings → Incident Lifecycle. Whichever phase sits last is the final one. Moving an incident into it marks the incident resolved. The name Inactive is reserved.
The action checklist
The Actions tab holds the response steps, grouped under the phase each belongs to. The playbook fills it in when you create the case. Each group collapses, so you can work one phase at a time, and DFIRe pulls actions already in progress to the top. A progress bar tracks how many are done.
Add Action adds a step the playbook did not anticipate. It lands in the current phase.
What state an action is in
| State | Meaning |
|---|---|
| Pending | Nobody has picked it up. |
| Started | An assignee has picked it up. |
| Blocked | It cannot move. See below. |
| Done | Finished. |
| Skipped | Not applicable to this incident. |
Blocking an action
Blocking marks work that cannot move, without pretending it is finished. It applies to a pending or a started action and needs a note naming what it waits on.
A blocked action keeps whatever progress it had and still counts as outstanding. It therefore holds its phase open and stays in the case's action counts. Unblocking clears the note and returns the action to pending or in progress, whichever it was, with its original start time and starter intact.
Assigning and finishing
When you start an action you can assign it to a case investigator or to a legal entity. Entities are what let you hand work to a named team, department or outside organization, rather than only to people who hold DFIRe accounts.
Marking an action done offers a completion note, and the option to post that note to the timeline.
Some actions carry a guided decision workflow instead of a single tick. Working through one records the questions and the answers you chose alongside the action.
Jira
With Jira connected, an action can become a Jira issue under the case's own issue. Status travels in both directions, a DFIRe user whose email matches a Jira account is assigned automatically, and issues can be created as actions start. See Slack and Jira.
Moving between phases
Complete every action in the current phase and DFIRe offers to advance to the next one. Take the offer, or use the phase control in the case sidebar to move whenever you decide to, including before the phase is finished. Confirmations exist for that case.
You can also go back. Returning to an earlier phase preserves the action progress already made.
The incident clock
DFIRe records when the incident was declared, meaning the moment of escalation, or the moment of creation for a case opened as an incident. It records the resolution as the moment the incident enters the final phase.
The duration in the sidebar and on reports runs between those two. If the case closes before the incident resolves, the clock stops at closure. Moving an incident back out of the final phase starts it running again.
Both timestamps are editable in Edit Case, which is what you use when the declaration or the resolution did not happen when the record says.
Time in each phase
Click the duration in the sidebar to open it. Under the total sits one line per phase the incident has been in, in the order the phases run, with the time it spent there. A phase entered more than once shows one total, and a phase the incident has never been in gets no line. The phase the case is on now counts on, and its line says so far.
The lines add up to the total above them, unless the declaration was moved to before the case was created: the time before the case existed belongs to no phase.
Both phase pickers, the one in the sidebar and the one on the Timeline tab, mark a phase the incident has been through and left. The mark is a check before the name. Those phases stay selectable, because an incident can return to one.
What the sidebar tracks
On an incident the sidebar adds three things to the usual case summary. The current phase with its colour, which is also where you change it. The duration as a live counter, with the declaration below it and the resolution once there is one, which opens onto the time spent in each phase. And the action progress, broken down into done against skipped.
It also surfaces the state of any compliance timers, and warns when one runs short.
Regulatory deadlines
Notification deadlines run as countdown timers on the case's Compliance tab. DFIRe ships templates for GDPR, NIS 2, DORA, SEC, CIRCIA, NYDFS, HIPAA and PCI DSS, each carrying its own deadline, the authority to notify and a link to the source text.
You start a timer when the triggering event happens, and you can backdate the start if the event preceded the timer. See Compliance timers.
Closing an incident
Move the incident to its final phase to mark it resolved, which stops the clock. Closing the case is separate and makes it read-only. Most teams resolve first and close once the post-incident work is filed.
A closed case can be reopened, and the Investigation Report stays editable while a case is closed. See Cases.