Using DFIRe

Incident response

Phases to move through, a checklist to work, and a clock that runs until the incident resolves.

What incident mode adds

An incident is a case in incident mode. It carries the same tabs and content as an investigation. On top of that it adds a declared start time, movement through phases, and the full action checklist from its playbook.

Create one by choosing Incident when you make the case, or escalate an existing investigation at any point. See Cases for both.

Phases

An incident moves through an ordered set of phases. DFIRe ships seven, following the usual response lifecycle.

PhaseWhat happens in it
Preparation & Immediate ActionsAssign an owner, open a channel, triage what came in, and decide whether this is really an incident.
Detection & AnalysisEstablish what happened, how far it reached, and what it touched.
ContainmentStop it spreading, without destroying what you still need to examine.
EradicationRemove the cause and close the way in.
RecoveryRestore service and confirm it is genuinely clean.
Post-Incident ActivitiesReview, report, and fix what let it happen.
ResolvedThe final phase. Reaching it stops the incident clock.

Administrators can rename, reorder, add and remove phases under Settings → Incident Lifecycle. Whichever phase sits last is the final one. Moving an incident into it marks the incident resolved. The name Inactive is reserved.

The action checklist

The Actions tab holds the response steps, grouped under the phase each belongs to. The playbook fills it in when you create the case. Each group collapses, so you can work one phase at a time, and DFIRe pulls actions already in progress to the top. A progress bar tracks how many are done.

Add Action adds a step the playbook did not anticipate. It lands in the current phase.

What state an action is in

StateMeaning
PendingNobody has picked it up.
StartedAn assignee has picked it up.
BlockedIt cannot move. See below.
DoneFinished.
SkippedNot applicable to this incident.

Blocking an action

Blocking marks work that cannot move, without pretending it is finished. It applies to a pending or a started action and needs a note naming what it waits on.

A blocked action keeps whatever progress it had and still counts as outstanding. It therefore holds its phase open and stays in the case's action counts. Unblocking clears the note and returns the action to pending or in progress, whichever it was, with its original start time and starter intact.

Assigning and finishing

When you start an action you can assign it to a case investigator or to a legal entity. Entities are what let you hand work to a named team, department or outside organization, rather than only to people who hold DFIRe accounts.

Marking an action done offers a completion note, and the option to post that note to the timeline.

Some actions carry a guided decision workflow instead of a single tick. Working through one records the questions and the answers you chose alongside the action.

Jira

With Jira connected, an action can become a Jira issue under the case's own issue. Status travels in both directions, a DFIRe user whose email matches a Jira account is assigned automatically, and issues can be created as actions start. See Slack and Jira.

Moving between phases

Complete every action in the current phase and DFIRe offers to advance to the next one. Take the offer, or use the phase control in the case sidebar to move whenever you decide to, including before the phase is finished. Confirmations exist for that case.

You can also go back. Returning to an earlier phase preserves the action progress already made.

The incident clock

DFIRe records when the incident was declared, meaning the moment of escalation, or the moment of creation for a case opened as an incident. It records the resolution as the moment the incident enters the final phase.

The duration in the sidebar and on reports runs between those two. If the case closes before the incident resolves, the clock stops at closure. Moving an incident back out of the final phase starts it running again.

Both timestamps are editable in Edit Case, which is what you use when the declaration or the resolution did not happen when the record says.

Time in each phase

Click the duration in the sidebar to open it. Under the total sits one line per phase the incident has been in, in the order the phases run, with the time it spent there. A phase entered more than once shows one total, and a phase the incident has never been in gets no line. The phase the case is on now counts on, and its line says so far.

The lines add up to the total above them, unless the declaration was moved to before the case was created: the time before the case existed belongs to no phase.

Both phase pickers, the one in the sidebar and the one on the Timeline tab, mark a phase the incident has been through and left. The mark is a check before the name. Those phases stay selectable, because an incident can return to one.

What the sidebar tracks

On an incident the sidebar adds three things to the usual case summary. The current phase with its colour, which is also where you change it. The duration as a live counter, with the declaration below it and the resolution once there is one, which opens onto the time spent in each phase. And the action progress, broken down into done against skipped.

It also surfaces the state of any compliance timers, and warns when one runs short.

Regulatory deadlines

Notification deadlines run as countdown timers on the case's Compliance tab. DFIRe ships templates for GDPR, NIS 2, DORA, SEC, CIRCIA, NYDFS, HIPAA and PCI DSS, each carrying its own deadline, the authority to notify and a link to the source text.

You start a timer when the triggering event happens, and you can backdate the start if the event preceded the timer. See Compliance timers.

Closing an incident

Move the incident to its final phase to mark it resolved, which stops the clock. Closing the case is separate and makes it read-only. Most teams resolve first and close once the post-incident work is filed.

A closed case can be reopened, and the Investigation Report stays editable while a case is closed. See Cases.

← Evidence Timeline →