Incident Response Workspace

Local Case

Overview

Track the live state of the incident and capture the current analyst view.

Opened
Updated

Triage

Capture the first-response state: detection source, scope, containment, and critical first actions.

Evidence

Record artifacts, hashes, storage locations, and collection metadata in one place.

Workflows

Jump into the right workflow based on the evidence type and what the handbooks emphasize.

Timeline

Track actions, findings, and decisions in reverse chronological order.

Report

Generate a structured handoff-ready incident summary from the live case state.